Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
PDFizer.exe

Overview

General Information

Sample name:PDFizer.exe
Analysis ID:1637530
MD5:aa2835ff9b90e17b4362705e3985cc0a
SHA1:317c681a1f31f183de1fd50e3ea1b9fbe88bd7a0
SHA256:07ed5f11b4320fbb24125495f3d43bd6c4cd739ef19ce0219008724252247443
Tags:exeHUDDAFOODSSMC-PRIVATELIMITEDuser-SquiblydooBlog
Infos:

Detection

Score:42
Range:0 - 100
Confidence:100%

Compliance

Score:34
Range:0 - 100

Signatures

System process connects to network (likely due to code injection or exploit)
Installs Task Scheduler Managed Wrapper
Joe Sandbox ML detected suspicious sample
Adds / modifies Windows certificates
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
EXE planting / hijacking vulnerabilities found
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Stores large binary data to the registry
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • PDFizer.exe (PID: 6384 cmdline: "C:\Users\user\Desktop\PDFizer.exe" MD5: AA2835FF9B90E17B4362705E3985CC0A)
    • msiexec.exe (PID: 3624 cmdline: "C:\Windows\system32\msiexec.exe" /i "C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer_no_update.msi" AI_SETUPEXEPATH=C:\Users\user\Desktop\PDFizer.exe SETUPEXEDIR=C:\Users\user\Desktop\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1741883784 " AI_EUIMSI="" MD5: 9D09DC1EDA745A5F87553048E57620CF)
  • msiexec.exe (PID: 5800 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 4196 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding C1441A68662C83CBC2DBCF5DC54D3A87 C MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 5612 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 1B86529AE1BEBF6BE14F0F9F26157CFB MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • rundll32.exe (PID: 3912 cmdline: rundll32.exe "C:\Windows\Installer\MSIC6B7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3983125 2 RequestSender!RequestSender.CustomActions.Start MD5: 889B99C52A60DD49227C5E485A016679)
      • rundll32.exe (PID: 7336 cmdline: rundll32.exe "C:\Windows\Installer\MSID289.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3986140 43 RequestSender!RequestSender.CustomActions.OpenUrl MD5: 889B99C52A60DD49227C5E485A016679)
        • msedge.exe (PID: 7384 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://pdf-izer.com/thankyou.html MD5: 69222B8101B0601CC6663F8381E7E00F)
          • msedge.exe (PID: 7584 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1764,i,11800840707593110290,11208548828072256965,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
      • rundll32.exe (PID: 7620 cmdline: rundll32.exe "C:\Windows\Installer\MSID970.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3987906 47 RequestSender!RequestSender.CustomActions.Finish MD5: 889B99C52A60DD49227C5E485A016679)
  • msedge.exe (PID: 7608 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate https://pdf-izer.com/thankyou.html MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 7972 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:3 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 9052 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6716 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 9064 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6760 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 9048 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=price_comparison_service.mojom.DataProcessor --lang=en-GB --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=7872 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
    • msedge.exe (PID: 8852 cmdline: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=7632 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8 MD5: 69222B8101B0601CC6663F8381E7E00F)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: Submited SampleIntegrated Neural Analysis Model: Matched 97.3% probability
Source: C:\Windows\System32\msiexec.exeEXE: C:\Users\user\AppData\Roaming\Microsoft\Installer\{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}\app.exeJump to behavior
Source: C:\Windows\System32\msiexec.exeEXE: C:\Users\user\AppData\Roaming\PDFizer\PDFizer.exeJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeEXE: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer.exeJump to behavior

Compliance

barindex
Source: C:\Windows\System32\msiexec.exeEXE: C:\Users\user\AppData\Roaming\Microsoft\Installer\{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}\app.exeJump to behavior
Source: C:\Windows\System32\msiexec.exeEXE: C:\Users\user\AppData\Roaming\PDFizer\PDFizer.exeJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeEXE: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer.exeJump to behavior
Source: PDFizer.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDFizer 1.0.0Jump to behavior
Source: PDFizer.exeStatic PE information: certificate valid
Source: unknownHTTPS traffic detected: 169.150.247.38:443 -> 192.168.2.8:49686 version: TLS 1.2
Source: PDFizer.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: d:\a01\_work\43\s\\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, msvcp140_2.dll.0.dr
Source: Binary string: D:\a01\_work\6\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, vcruntime140.dll.2.dr, vcruntime140.dll.0.dr
Source: Binary string: wininet.pdb source: PDFizer.exe, 00000000.00000003.921992019.0000000005023000.00000004.00000020.00020000.00000000.sdmp, shiC0FA.tmp.0.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdbg source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: d:\a01\_work\43\s\\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, msvcp140_1.dll.0.dr
Source: Binary string: WixToolset.Dtf.WindowsInstaller.pdbSHA256 source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr
Source: Binary string: C:\Users\dahal\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net45\Microsoft.Win32.TaskScheduler.pdbSHA256 source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Win32.TaskScheduler.dll.8.dr, Microsoft.Win32.TaskScheduler.dll.12.dr, Microsoft.Win32.TaskScheduler.dll.6.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\Prereq.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSIC8EF.tmp.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdbj source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: wininet.pdbUGP source: PDFizer.exe, 00000000.00000003.921992019.0000000005023000.00000004.00000020.00020000.00000000.sdmp, shiC0FA.tmp.0.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\lzmaextractor.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\FileOperations.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSICCE9.tmp.2.dr, 3cc3f8.msi.2.dr, MSICDD4.tmp.2.dr
Source: Binary string: WixToolset.Dtf.WindowsInstaller.pdb source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSIC813.tmp.2.dr, MSIC871.tmp.2.dr, MSIC274.tmp.0.dr, MSIC188.tmp.0.dr, MSIC6C7.tmp.2.dr, MSIC736.tmp.2.dr, 3cc3f8.msi.2.dr, MSIC244.tmp.0.dr, MSIC7F2.tmp.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\stubs\x86\ExternalUi.pdb source: PDFizer.exe
Source: Binary string: D:\a01\_work\6\s\\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, vcruntime140_1.dll.0.dr
Source: Binary string: D:\a\wix\wix\build\dtf\Release\x86\SfxCA.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005365000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSID289.tmp.2.dr, 3cc3f8.msi.2.dr, MSIC6B7.tmp.2.dr
Source: Binary string: d:\a01\_work\43\s\\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, msvcp140.dll.2.dr, msvcp140.dll.0.dr
Source: Binary string: C:\Users\dahal\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net45\Microsoft.Win32.TaskScheduler.pdb source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Win32.TaskScheduler.dll.8.dr, Microsoft.Win32.TaskScheduler.dll.12.dr, Microsoft.Win32.TaskScheduler.dll.6.dr
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeFile opened: c:
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: a:Jump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002F2170 ReadFile,FindFirstFileW,CloseHandle,CreateEventW,CreateThread,WaitForSingleObject,GetExitCodeThread,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,0_2_002F2170
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C2290 FindClose,PathIsUNCW,FindFirstFileW,GetFullPathNameW,GetFullPathNameW,FindClose,SetLastError,_wcsrchr,_wcsrchr,PathIsUNCW,0_2_001C2290
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002CB7D0 FindFirstFileW,GetFileAttributesW,SetFileAttributesW,GetFileAttributesW,FindNextFileW,0_2_002CB7D0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002CBDA0 FindFirstFileW,GetLastError,FindClose,0_2_002CBDA0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00310C90 FindFirstFileW,FindNextFileW,FindFirstFileW,FindNextFileW,FindNextFileW,FindClose,0_2_00310C90
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002CB440 _wcsrchr,FindFirstFileW,FindFirstFileW,FindFirstFileW,FindClose,FindClose,0_2_002CB440

Networking

barindex
Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 169.150.247.38 443Jump to behavior
Source: Joe Sandbox ViewIP Address: 138.199.40.58 138.199.40.58
Source: Joe Sandbox ViewIP Address: 23.57.90.145 23.57.90.145
Source: Joe Sandbox ViewIP Address: 2.22.242.11 2.22.242.11
Source: Joe Sandbox ViewIP Address: 169.150.247.38 169.150.247.38
Source: Joe Sandbox ViewIP Address: 169.150.247.38 169.150.247.38
Source: Joe Sandbox ViewASN Name: SPIRITTEL-ASUS SPIRITTEL-ASUS
Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: global trafficHTTP traffic detected: GET /thankyou.html HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: OPTIONS /api/report?cat=bingbusiness HTTP/1.1Host: bzib.nelreports.netConnection: keep-aliveOrigin: https://business.bing.comAccess-Control-Request-Method: POSTAccess-Control-Request-Headers: content-typeUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /assets/pdf-izer-icons/pdf_izer_logo.png HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://pdf-izer.com/thankyou.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /assets/pdf-izer-icons/check-circle.svg HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://pdf-izer.com/thankyou.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /crx/blobs/Ad_brx23lef_cW590ESOTTAroOhZ9si0XFJIUC52j2ILHW1VLB5ou6c0RgLWwGr1aRJJZ0WPNyiPBYgIpWfykvhKW-6BLzMRsp9ykw5f6ReBQmPpO6WB9pcSJPfykLTHDjYAxlKa5bf72z8tHS5eXuTavTP1h4WZBjSs/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_89_1_0.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://pdf-izer.com/thankyou.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: POST /api/report?cat=bingbusiness HTTP/1.1Host: bzib.nelreports.netConnection: keep-aliveContent-Length: 471Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: OPTIONS /api/report?cat=bingbusiness HTTP/1.1Host: bzib.nelreports.netConnection: keep-aliveOrigin: https://business.bing.comAccess-Control-Request-Method: POSTAccess-Control-Request-Headers: content-typeUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: POST /api/report?cat=bingbusiness HTTP/1.1Host: bzib.nelreports.netConnection: keep-aliveContent-Length: 466Content-Type: application/reports+jsonUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 23.60.201.147
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.63
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.99
Source: unknownTCP traffic detected without corresponding DNS query: 142.250.185.99
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.90
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.90
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.90
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.90
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.90
Source: unknownTCP traffic detected without corresponding DNS query: 104.18.20.226
Source: unknownTCP traffic detected without corresponding DNS query: 104.18.20.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.219.150.101
Source: unknownTCP traffic detected without corresponding DNS query: 104.18.20.226
Source: unknownTCP traffic detected without corresponding DNS query: 104.18.20.226
Source: unknownTCP traffic detected without corresponding DNS query: 23.219.150.101
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.90
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.42.65.90
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.253.72
Source: unknownTCP traffic detected without corresponding DNS query: 13.107.253.72
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: unknownTCP traffic detected without corresponding DNS query: 138.199.40.58
Source: unknownTCP traffic detected without corresponding DNS query: 138.199.40.58
Source: unknownTCP traffic detected without corresponding DNS query: 138.199.40.58
Source: unknownTCP traffic detected without corresponding DNS query: 138.199.40.58
Source: unknownTCP traffic detected without corresponding DNS query: 138.199.40.58
Source: unknownTCP traffic detected without corresponding DNS query: 138.199.40.58
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: unknownTCP traffic detected without corresponding DNS query: 23.57.90.73
Source: global trafficHTTP traffic detected: GET /thankyou.html HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /assets/pdf-izer-icons/pdf_izer_logo.png HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://pdf-izer.com/thankyou.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /assets/pdf-izer-icons/check-circle.svg HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://pdf-izer.com/thankyou.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /crx/blobs/Ad_brx23lef_cW590ESOTTAroOhZ9si0XFJIUC52j2ILHW1VLB5ou6c0RgLWwGr1aRJJZ0WPNyiPBYgIpWfykvhKW-6BLzMRsp9ykw5f6ReBQmPpO6WB9pcSJPfykLTHDjYAxlKa5bf72z8tHS5eXuTavTP1h4WZBjSs/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_89_1_0.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: pdf-izer.comConnection: keep-alivesec-ch-ua: "Microsoft Edge";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36 Edg/117.0.2045.47sec-ch-ua-platform: "Windows"Accept: image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://pdf-izer.com/thankyou.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-GB,en;q=0.9,en-US;q=0.8
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: PDFizer.exe, 00000000.00000000.909489405.000000000040C000.00000002.00000001.01000000.00000003.sdmp, PDFizer.exe, 00000000.00000002.1325335211.000000000040C000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: 0FlashWindowExFlashWindowGetPackagePathhttp://www.google.comTESTtin9999.tmphttp://www.yahoo.comhttp://www.example.com.part= "GETattachmentDLD123filenamecharsetutf-16ISO-8859-1POSTutf-8Local Network ServerFTP ServerUS-ASCIIAdvancedInstallerRange: bytes=%u- equals www.yahoo.com (Yahoo)
Source: PDFizer.exeString found in binary or memory: VFlashWindowExFlashWindowGetPackagePathhttp://www.google.comTESTtin9999.tmphttp://www.yahoo.comhttp://www.example.com.part= "GETattachmentDLD123filenamecharsetutf-16ISO-8859-1POSTutf-8Local Network ServerFTP ServerUS-ASCIIAdvancedInstallerRange: bytes=%u- equals www.yahoo.com (Yahoo)
Source: global trafficDNS traffic detected: DNS query: l.pdf-izer.com
Source: global trafficDNS traffic detected: DNS query: pdf-izer.com
Source: global trafficDNS traffic detected: DNS query: bzib.nelreports.net
Source: global trafficDNS traffic detected: DNS query: clients2.googleusercontent.com
Source: global trafficDNS traffic detected: DNS query: chrome.cloudflare-dns.com
Source: unknownHTTP traffic detected: POST /dns-query HTTP/1.1Host: chrome.cloudflare-dns.comConnection: keep-aliveContent-Length: 128Accept: application/dns-messageAccept-Language: *User-Agent: ChromeAccept-Encoding: identityContent-Type: application/dns-message
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Thu, 13 Mar 2025 16:38:13 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: closeVary: Accept-EncodingServer: BunnyCDN-DE1-1082CDN-PullZone: 3384463CDN-Uid: 0cd3b962-5916-48ec-9131-ebbbf42c9facCDN-RequestCountryCode: USCache-Control: no-cacheCDN-StorageServer: DE-636CDN-ProxyVer: 1.22CDN-RequestPullSuccess: TrueCDN-RequestPullCode: 404CDN-CachedAt: 03/13/2025 16:38:13CDN-EdgeStorageId: 1081CDN-Status: 404CDN-RequestTime: 1CDN-RequestId: fa19d8b3fe552d2b6d873e1df3c7e9c5CDN-Cache: MISS
Source: shiC0FA.tmp.0.drString found in binary or memory: http://.css
Source: shiC0FA.tmp.0.drString found in binary or memory: http://.jpg
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr, 3cc3f8.msi.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E
Source: PDFizer.exe, 00000000.00000003.1324548818.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1323924012.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326129371.0000000000CDB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTru
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320883544.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr, 3cc3f8.msi.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320883544.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0
Source: PDFizer.exe, 3cc3fb.msi.2.dr, PDFizer.exe.0.dr, 3cc3f8.msi.2.dr, PDFizer.exe.2.drString found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U
Source: PDFizer.exe, 3cc3fb.msi.2.dr, PDFizer.exe.0.dr, 3cc3f8.msi.2.dr, PDFizer.exe.2.drString found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr, 3cc3f8.msi.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.c
Source: PDFizer.exe, 00000000.00000003.1324548818.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1323924012.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320883544.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326129371.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320883544.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0=
Source: shiC0FA.tmp.0.drString found in binary or memory: http://html4/loose.dtd
Source: rundll32.exe, 00000006.00000002.1255823881.0000000004698000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://l.pdf-izer.com
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320883544.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://ocsp.digicert.com0A
Source: PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr, 3cc3f8.msi.2.drString found in binary or memory: http://ocsp.digicert.com0C
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://ocsp.digicert.com0O
Source: PDFizer.exe, 00000000.00000003.1324548818.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321964438.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327001843.00000000057E0000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917689705.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322384061.0000000000D16000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1323924012.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320883544.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326129371.0000000000CDB000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322750521.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1326327221.0000000000D1B000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, WixToolset.Dtf.WindowsInstaller.dll.12.drString found in binary or memory: http://ocsp.digicert.com0X
Source: PDFizer.exe, 00000000.00000002.1326129371.0000000000CDB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.globalsign.com/code
Source: PDFizer.exe, 3cc3fb.msi.2.dr, PDFizer.exe.0.dr, 3cc3f8.msi.2.dr, PDFizer.exe.2.drString found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F
Source: PDFizer.exe, 3cc3fb.msi.2.dr, PDFizer.exe.0.dr, 3cc3f8.msi.2.dr, PDFizer.exe.2.drString found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
Source: rundll32.exe, 00000006.00000002.1255823881.0000000004698000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pdf-izer-d.b-cdn.net
Source: PDFizer.exe, 00000000.00000003.917647408.0000000000D30000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.921450228.0000000005ADD000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.916579600.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322693470.0000000005A5C000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.921279579.0000000005AD2000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.916841357.0000000000D00000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327079000.0000000005A50000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.drString found in binary or memory: http://schemas.micro
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.1255823881.0000000004611000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.0000000005251000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: PDFizer.exe, 3cc3fb.msi.2.dr, PDFizer.exe.0.dr, 3cc3f8.msi.2.dr, PDFizer.exe.2.drString found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
Source: PDFizer.exe, 3cc3fb.msi.2.dr, PDFizer.exe.0.dr, 3cc3f8.msi.2.dr, PDFizer.exe.2.drString found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: http://www.digicert.com/CPS0
Source: PDFizer.exe.2.drString found in binary or memory: http://www.marksimonson.comProxima
Source: MSICDD4.tmp.2.drString found in binary or memory: http://www.winimage.com/zLibDll
Source: Reporting and NEL.13.drString found in binary or memory: https://bzib.nelreports.net/api/report?cat=bingbusiness
Source: service_worker_bin_prod.js.11.dr, offscreendocument_main.js.11.drString found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/mathjax/
Source: Web Data.11.drString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
Source: Web Data.11.drString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
Source: manifest.json0.11.drString found in binary or memory: https://chrome.google.com/webstore/
Source: manifest.json0.11.drString found in binary or memory: https://chromewebstore.google.com/
Source: 32deb3aa-21f9-4654-a4de-259bb0948be5.tmp.13.dr, d0f0a336-ff51-4ec7-b89c-313b88c88b93.tmp.13.drString found in binary or memory: https://clients2.google.com
Source: manifest.json.11.drString found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 32deb3aa-21f9-4654-a4de-259bb0948be5.tmp.13.drString found in binary or memory: https://clients2.googleusercontent.com
Source: Reporting and NEL.13.drString found in binary or memory: https://deff.nelreports.net/api/report?cat=msn
Source: manifest.json.11.drString found in binary or memory: https://docs.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-autopush.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-daily-0.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-daily-1.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-daily-2.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-daily-3.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-daily-4.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-daily-5.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-daily-6.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-preprod.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive-staging.corp.google.com/
Source: manifest.json.11.drString found in binary or memory: https://drive.google.com/
Source: Web Data.11.drString found in binary or memory: https://duckduckgo.com/ac/?q=
Source: Web Data.11.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
Source: Web Data.11.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
Source: 000003.log0.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?assetgroup=Arbit
Source: 000003.log0.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_M365_light.png/1.7.32/asset
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_action_center_maximal_light.png/1.2.1/as
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_edrop_maximal_light.png/1.1.12/asset
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_games_maximal_light.png/1.7.1/asset
Source: 000003.log0.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_manifest_gz/4.7.107/asset?assetgroup=Sho
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_outlook_light.png/1.9.10/asset
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_search_maximal_light.png/1.3.6/asset
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_shopping_maximal_light.png/1.4.0/asset
Source: HubApps Icons.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/edge_hub_apps_toolbox_maximal_light.png/1.5.13/asset
Source: 000003.log1.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/product_category_en/1.0.0/asset?assetgroup=ProductCate
Source: 000003.log0.11.drString found in binary or memory: https://edgeassetservice.azureedge.net/assets/signal_triggers/1.13.3/asset?sv=2017-07-29&sr=c&sig=Nt
Source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Win32.TaskScheduler.dll.8.dr, Microsoft.Win32.TaskScheduler.dll.12.dr, Microsoft.Win32.TaskScheduler.dll.6.drString found in binary or memory: https://github.com/dahall/taskscheduler
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-iz
Source: rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.1255823881.0000000004611000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.0000000005251000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com
Source: PDFizer.exe, 00000000.00000003.1324291885.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327468689.0000000005AF9000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321899247.0000000005AF8000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320693288.0000000005AF7000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324367428.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com/
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//
Source: rundll32.exe, 0000000C.00000002.1317987005.0000000005251000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//finish
Source: rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//finishL
Source: rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//finishLRQr
Source: rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//finishh2P
Source: rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//finisht
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//start
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//startLRQrP
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com//startt
Source: rundll32.exe, 0000000C.00000003.1013103854.00000000032CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com/D
Source: rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://l.pdf-izer.com/LRQr
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.drString found in binary or memory: https://l.pdf-izer.com/ThankYouURLhttps://pdf-izer.com/thankyou.htmlButtonText_Install&InstallIAgree
Source: rundll32.exe, 0000000C.00000002.1316850989.00000000032D3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://learn.microso
Source: 000003.log4.11.drString found in binary or memory: https://pdf-izer.com/
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, Core.dll.2.dr, Core.dll.0.drString found in binary or memory: https://pdf-izer.com/download/jre.zip
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, Core.dll.2.dr, Core.dll.0.drString found in binary or memory: https://pdf-izer.com/download/pdfjar.zip
Source: rundll32.exe, 00000008.00000002.982545442.00000000045E1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.H
Source: Session_13386357486330984.11.drString found in binary or memory: https://pdf-izer.com/thankyou.html
Source: PDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.html...
Source: Session_13386357486330984.11.drString found in binary or memory: https://pdf-izer.com/thankyou.html0
Source: PDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.html6A
Source: PDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.htmlB6
Source: rundll32.exe, 00000008.00000002.976120298.0000000002855000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.htmlC:
Source: PDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.htmlEQS
Source: rundll32.exe, 00000008.00000002.982545442.00000000045E1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.htmlLRQrx
Source: History.11.drString found in binary or memory: https://pdf-izer.com/thankyou.htmlPDF-IZER
Source: History.11.drString found in binary or memory: https://pdf-izer.com/thankyou.htmlPDF-IZER/
Source: WebAssistDatabase.11.drString found in binary or memory: https://pdf-izer.com/thankyou.htmlPDF-IZERg
Source: PDFizer.exe, 00000000.00000003.917008114.0000000000CE7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.htmle
Source: PDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.htmleUz
Source: rundll32.exe, 00000008.00000002.976366792.0000000002A08000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pdf-izer.com/thankyou.htmlmy
Source: rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drString found in binary or memory: https://wixtoolset.org/
Source: PDFizer.exe, 3cc3fb.msi.2.dr, PDFizer.exe.0.dr, 3cc3f8.msi.2.dr, PDFizer.exe.2.drString found in binary or memory: https://www.globalsign.com/repository/0
Source: content_new.js.11.dr, content.js.11.drString found in binary or memory: https://www.google.com/chrome
Source: Web Data.11.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49686 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49682 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49686
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49682
Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49673
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
Source: unknownHTTPS traffic detected: 169.150.247.38:443 -> 192.168.2.8:49686 version: TLS 1.2
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002889F0 GetSystemDirectoryW,LoadLibraryExW,NtdllDefWindowProc_W,0_2_002889F0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_003129C0 NtdllDefWindowProc_W,0_2_003129C0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C00C0 IsWindow,GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W,0_2_001C00C0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001B6670 SysFreeString,SysAllocString,GetWindowLongW,GetWindowLongW,GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W,GetWindowLongW,SetWindowTextW,GlobalAlloc,GlobalLock,GlobalUnlock,SetWindowLongW,SysFreeString,NtdllDefWindowProc_W,SysFreeString,0_2_001B6670
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002689B0 NtdllDefWindowProc_W,0_2_002689B0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001B8C40 GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W,DestroyWindow,0_2_001B8C40
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001B6CD0 NtdllDefWindowProc_W,0_2_001B6CD0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001D6FE0 NtdllDefWindowProc_W,0_2_001D6FE0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001B9360 NtdllDefWindowProc_W,0_2_001B9360
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C9430 NtdllDefWindowProc_W,0_2_001C9430
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002177A0 GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W,0_2_002177A0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001B9920 NtdllDefWindowProc_W,0_2_001B9920
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C3E40 GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W,DeleteCriticalSection,0_2_001C3E40
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001B5F50 GetWindowLongW,GetWindowLongW,GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W,GetWindowLongW,SetWindowTextW,GlobalAlloc,GlobalLock,GlobalUnlock,SetWindowLongW,NtdllDefWindowProc_W,0_2_001B5F50
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001BFF50 NtdllDefWindowProc_W,0_2_001BFF50
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3cc3f8.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6B7.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6C7.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC736.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC7F2.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC813.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC871.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC8EF.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB13.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICCE9.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICDD4.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID085.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3cc3fb.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3cc3fb.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID289.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID970.tmpJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699Jump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\RequestSender.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\WixToolset.Dtf.WindowsInstaller.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.resources.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\CustomAction.configJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282Jump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\RequestSender.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\WixToolset.Dtf.WindowsInstaller.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.resources.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\CustomAction.configJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\RequestSender.dll
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.dll
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\WixToolset.Dtf.WindowsInstaller.dll
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.resources.dll
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\CustomAction.config
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSIC6C7.tmpJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002F21700_2_002F2170
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C22900_2_001C2290
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0030AF400_2_0030AF40
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002D3DC00_2_002D3DC0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002E5E600_2_002E5E60
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002DE0600_2_002DE060
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_003260D00_2_003260D0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0039830B0_2_0039830B
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C05000_2_001C0500
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001D86300_2_001D8630
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001CA8200_2_001CA820
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0038891C0_2_0038891C
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002AA9B00_2_002AA9B0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001DCBB00_2_001DCBB0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001D0C800_2_001D0C80
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0039CD890_2_0039CD89
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0021ADE00_2_0021ADE0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0039AE620_2_0039AE62
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001CCE410_2_001CCE41
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001A30000_2_001A3000
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_003A31740_2_003A3174
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001CF4100_2_001CF410
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001A76200_2_001A7620
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001D97100_2_001D9710
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C9AD00_2_001C9AD0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002D1C400_2_002D1C40
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001A5C820_2_001A5C82
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C5CE00_2_001C5CE0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0038FF600_2_0038FF60
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0031FFA00_2_0031FFA0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C9FF00_2_001C9FF0
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_3_045664C86_3_045664C8
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_3_04565BD86_3_04565BD8
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 6_3_045658886_3_04565888
Source: C:\Users\user\Desktop\PDFizer.exeCode function: String function: 001AA830 appears 52 times
Source: C:\Users\user\Desktop\PDFizer.exeCode function: String function: 001AA2A0 appears 51 times
Source: C:\Users\user\Desktop\PDFizer.exeCode function: String function: 001A8300 appears 52 times
Source: C:\Users\user\Desktop\PDFizer.exeCode function: String function: 001A8DB0 appears 226 times
Source: PDFizer.exe, 00000000.00000003.921992019.0000000005023000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamewininet.dllD vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelzmaextractor.dllF vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameAICustAct.dllF vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamePrereq.dllF vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameFileOperations.dllF vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameRequestSender.dll< vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSfxCA.dll8 vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameDataUploader.dllF vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamePowerShellScriptLauncher.dllF vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameCore.dll* vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140.dllT vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140_1.dllT vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsvcp140_2.dllT vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs PDFizer.exe
Source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140_1.dllT vs PDFizer.exe
Source: PDFizer.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: PDFizer.exe.0.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: PDFizer.exe.2.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: PDFizer.exe.0.dr, Util.csCryptographic APIs: 'CreateDecryptor'
Source: PDFizer.exe.2.dr, Util.csCryptographic APIs: 'CreateDecryptor'
Source: RequestSender.dll.6.dr, CustomActions.csTask registration methods: 'CreateScheduledTask'
Source: PDFizer.exe.2.dr, JREDownload.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
Source: PDFizer.exe.2.dr, JREDownload.csSecurity API names: System.IO.DirectoryInfo.GetAccessControl()
Source: PDFizer.exe.2.dr, JREDownload.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
Source: RequestSender.dll.6.dr, CustomActions.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: PDFizer.exe.0.dr, JREDownload.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
Source: PDFizer.exe.0.dr, JREDownload.csSecurity API names: System.IO.DirectoryInfo.GetAccessControl()
Source: PDFizer.exe.0.dr, JREDownload.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
Source: shiC0FA.tmp.0.drBinary string: \Device\NameResTrk\RecordNrtCloneOpenPacket
Source: classification engineClassification label: mal42.evad.winEXE@64/327@13/11
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002CEF90 FormatMessageW,GetLastError,0_2_002CEF90
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002FE970 GetDiskFreeSpaceExW,0_2_002FE970
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00316E40 CoCreateInstance,0_2_00316E40
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001AA160 LoadResource,LockResource,SizeofResource,0_2_001AA160
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizerJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeMutant created: NULL
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Local\Temp\shiC0FA.tmpJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeCommand line argument: q:0_2_003A7140
Source: PDFizer.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\PDFizer.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIC6B7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3983125 2 RequestSender!RequestSender.CustomActions.Start
Source: C:\Users\user\Desktop\PDFizer.exeFile read: C:\Users\user\Desktop\PDFizer.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\PDFizer.exe "C:\Users\user\Desktop\PDFizer.exe"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding C1441A68662C83CBC2DBCF5DC54D3A87 C
Source: C:\Users\user\Desktop\PDFizer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\msiexec.exe" /i "C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer_no_update.msi" AI_SETUPEXEPATH=C:\Users\user\Desktop\PDFizer.exe SETUPEXEDIR=C:\Users\user\Desktop\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1741883784 " AI_EUIMSI=""
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 1B86529AE1BEBF6BE14F0F9F26157CFB
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIC6B7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3983125 2 RequestSender!RequestSender.CustomActions.Start
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID289.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3986140 43 RequestSender!RequestSender.CustomActions.OpenUrl
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://pdf-izer.com/thankyou.html
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1764,i,11800840707593110290,11208548828072256965,262144 /prefetch:3
Source: unknownProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --flag-switches-begin --flag-switches-end --disable-nacl --do-not-de-elevate https://pdf-izer.com/thankyou.html
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID970.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3987906 47 RequestSender!RequestSender.CustomActions.Finish
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:3
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6716 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6760 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=price_comparison_service.mojom.DataProcessor --lang=en-GB --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=7872 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=7632 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Users\user\Desktop\PDFizer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\msiexec.exe" /i "C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer_no_update.msi" AI_SETUPEXEPATH=C:\Users\user\Desktop\PDFizer.exe SETUPEXEDIR=C:\Users\user\Desktop\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1741883784 " AI_EUIMSI=""Jump to behavior
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding C1441A68662C83CBC2DBCF5DC54D3A87 CJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 1B86529AE1BEBF6BE14F0F9F26157CFBJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSIC6B7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3983125 2 RequestSender!RequestSender.CustomActions.StartJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID289.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3986140 43 RequestSender!RequestSender.CustomActions.OpenUrlJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSID970.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_3987906 47 RequestSender!RequestSender.CustomActions.FinishJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://pdf-izer.com/thankyou.htmlJump to behavior
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1764,i,11800840707593110290,11208548828072256965,262144 /prefetch:3
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:3
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-GB --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=6716 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-GB --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=6760 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=price_comparison_service.mojom.DataProcessor --lang=en-GB --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=7872 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-GB --service-sandbox-type=search_indexer --message-loop-type-ui --mojo-platform-channel-handle=7632 --field-trial-handle=2020,i,16943720030170939545,6511014849182141754,262144 /prefetch:8
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exeProcess created: unknown unknown
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: msi.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: usp10.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: davhlpr.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: lpk.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: msihnd.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: riched20.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: atlthunk.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: msisip.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeSection loaded: taskschd.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
Source: PDFizer.lnk.2.drLNK file: ..\..\..\..\PDFizer\PDFizer.exe
Source: PDFizer.lnk0.2.drLNK file: ..\AppData\Roaming\PDFizer\PDFizer.exe
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\SysWOW64\rundll32.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PDFizer 1.0.0Jump to behavior
Source: PDFizer.exeStatic PE information: certificate valid
Source: PDFizer.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: PDFizer.exeStatic file information: File size 5926464 > 1048576
Source: PDFizer.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x26ae00
Source: PDFizer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: PDFizer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: PDFizer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: PDFizer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: PDFizer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: PDFizer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: PDFizer.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: PDFizer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: d:\a01\_work\43\s\\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, msvcp140_2.dll.0.dr
Source: Binary string: D:\a01\_work\6\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, vcruntime140.dll.2.dr, vcruntime140.dll.0.dr
Source: Binary string: wininet.pdb source: PDFizer.exe, 00000000.00000003.921992019.0000000005023000.00000004.00000020.00020000.00000000.sdmp, shiC0FA.tmp.0.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdbg source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: d:\a01\_work\43\s\\binaries\amd64ret\bin\amd64\\msvcp140_1.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, msvcp140_1.dll.0.dr
Source: Binary string: WixToolset.Dtf.WindowsInstaller.pdbSHA256 source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr
Source: Binary string: C:\Users\dahal\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net45\Microsoft.Win32.TaskScheduler.pdbSHA256 source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Win32.TaskScheduler.dll.8.dr, Microsoft.Win32.TaskScheduler.dll.12.dr, Microsoft.Win32.TaskScheduler.dll.6.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\Prereq.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSIC8EF.tmp.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdbj source: PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: wininet.pdbUGP source: PDFizer.exe, 00000000.00000003.921992019.0000000005023000.00000004.00000020.00020000.00000000.sdmp, shiC0FA.tmp.0.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\lzmaextractor.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\FileOperations.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSICCE9.tmp.2.dr, 3cc3f8.msi.2.dr, MSICDD4.tmp.2.dr
Source: Binary string: WixToolset.Dtf.WindowsInstaller.pdb source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSIC813.tmp.2.dr, MSIC871.tmp.2.dr, MSIC274.tmp.0.dr, MSIC188.tmp.0.dr, MSIC6C7.tmp.2.dr, MSIC736.tmp.2.dr, 3cc3f8.msi.2.dr, MSIC244.tmp.0.dr, MSIC7F2.tmp.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\stubs\x86\ExternalUi.pdb source: PDFizer.exe
Source: Binary string: D:\a01\_work\6\s\\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, vcruntime140_1.dll.0.dr
Source: Binary string: D:\a\wix\wix\build\dtf\Release\x86\SfxCA.pdb source: PDFizer.exe, 00000000.00000003.915806084.0000000005365000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, MSID289.tmp.2.dr, 3cc3f8.msi.2.dr, MSIC6B7.tmp.2.dr
Source: Binary string: d:\a01\_work\43\s\\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: PDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, msvcp140.dll.2.dr, msvcp140.dll.0.dr
Source: Binary string: C:\Users\dahal\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net45\Microsoft.Win32.TaskScheduler.pdb source: rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Win32.TaskScheduler.dll.8.dr, Microsoft.Win32.TaskScheduler.dll.12.dr, Microsoft.Win32.TaskScheduler.dll.6.dr
Source: PDFizer.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: PDFizer.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: PDFizer.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: PDFizer.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: PDFizer.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: PDFizer.exe.0.drStatic PE information: 0xD5343CB7 [Sat May 8 02:53:43 2083 UTC]
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002E0F60 SHGetFolderPathW,GetSystemDirectoryW,GetWindowsDirectoryW,GetWindowsDirectoryW,GetModuleFileNameW,SHGetSpecialFolderLocation,__Init_thread_footer,LoadLibraryW,GetProcAddress,SHGetPathFromIDListW,SHGetMalloc,0_2_002E0F60
Source: vcruntime140.dll.0.drStatic PE information: section name: _RDATA
Source: shiC0FA.tmp.0.drStatic PE information: section name: .wpp_sf
Source: shiC0FA.tmp.0.drStatic PE information: section name: .didat
Source: vcruntime140.dll.2.drStatic PE information: section name: _RDATA
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_3_05A8FD31 push esp; retf 0_3_05A8FD32
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_3_05A8FD31 push esp; retf 0_3_05A8FD32
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_3_00C8B4C8 push ss; retf 0_3_00C8B4DE
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_3_00C8B4E1 push ss; retf 0_3_00C8B4E2
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_3_00C88F88 push eax; retf 0_3_00C88F89
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001CC63B push ds; ret 0_2_001CC63F
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0038086C push ecx; ret 0_2_0038087F
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002AB2C0 push ecx; mov dword ptr [esp], 3F800000h0_2_002AB3F6
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001BD310 push ecx; mov dword ptr [esp], ecx0_2_001BD311
Source: PDFizer.exe.0.drStatic PE information: section name: .text entropy: 7.858495962490361
Source: PDFizer.exe.2.drStatic PE information: section name: .text entropy: 7.858495962490361
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC871.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICDD4.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\vcruntime140_1.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer.exeJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC8EF.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\Core.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC736.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\msvcp140_2.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6C7.tmpJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Local\Temp\shiC0FA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC7F2.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140_1.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\vcruntime140_1.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\RequestSender.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\msvcp140.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Local\Temp\MSIC188.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID085.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID289.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140_2.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID970.tmpJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\PDFizer\msvcp140_1.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Local\Temp\MSIC244.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB13.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\RequestSender.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeFile created: C:\Users\user\AppData\Local\Temp\MSIC274.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\RequestSender.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6B7.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC813.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC871.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICDD4.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC8EF.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC736.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6C7.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC7F2.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\RequestSender.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID085.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID289.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID970.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICB13.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\RequestSender.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\RequestSender.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC6B7.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC813.tmpJump to dropped file

Boot Survival

barindex
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.dllJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.dll
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDFizer.lnkJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EFC31460C619ECAE59C1BCE2C008036D94C84B8 BlobJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC871.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSICDD4.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\vcruntime140_1.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\Core.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC8EF.tmpJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC736.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC6C7.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\msvcp140_2.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\shiC0FA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC7F2.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140_1.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\vcruntime140_1.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\RequestSender.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\msvcp140.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSIC188.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSID085.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSID289.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140_2.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSID970.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\vcruntime140.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\PDFizer\msvcp140_1.dllJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSICB13.tmpJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSIC244.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\RequestSender.dllJump to dropped file
Source: C:\Users\user\Desktop\PDFizer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSIC274.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\RequestSender.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC6B7.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC813.tmpJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exe TID: 5356Thread sleep count: 179 > 30Jump to behavior
Source: C:\Windows\SysWOW64\rundll32.exe TID: 6888Thread sleep time: -30000s >= -30000sJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exe TID: 8452Thread sleep count: 187 > 30
Source: C:\Windows\SysWOW64\rundll32.exe TID: 8004Thread sleep time: -30000s >= -30000s
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\Users\user\AppData\Roaming FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeFile Volume queried: C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002F2170 ReadFile,FindFirstFileW,CloseHandle,CreateEventW,CreateThread,WaitForSingleObject,GetExitCodeThread,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,CloseHandle,0_2_002F2170
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001C2290 FindClose,PathIsUNCW,FindFirstFileW,GetFullPathNameW,GetFullPathNameW,FindClose,SetLastError,_wcsrchr,_wcsrchr,PathIsUNCW,0_2_001C2290
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002CB7D0 FindFirstFileW,GetFileAttributesW,SetFileAttributesW,GetFileAttributesW,FindNextFileW,0_2_002CB7D0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002CBDA0 FindFirstFileW,GetLastError,FindClose,0_2_002CBDA0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00310C90 FindFirstFileW,FindNextFileW,FindFirstFileW,FindNextFileW,FindNextFileW,FindClose,0_2_00310C90
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002CB440 _wcsrchr,FindFirstFileW,FindFirstFileW,FindFirstFileW,FindClose,FindClose,0_2_002CB440
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0037D0F2 VirtualQuery,GetSystemInfo,0_2_0037D0F2
Source: Web Data.11.drBinary or memory string: ms.portal.azure.comVMware20,11696494690
Source: Web Data.11.drBinary or memory string: discord.comVMware20,11696494690f
Source: Web Data.11.drBinary or memory string: AMC password management pageVMware20,11696494690
Source: Web Data.11.drBinary or memory string: outlook.office.comVMware20,11696494690s
Source: Web Data.11.drBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696494690p
Source: Web Data.11.drBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696494690
Source: Web Data.11.drBinary or memory string: Interactive Brokers - EU WestVMware20,11696494690n
Source: Web Data.11.drBinary or memory string: interactivebrokers.comVMware20,11696494690
Source: Web Data.11.drBinary or memory string: netportal.hdfcbank.comVMware20,11696494690
Source: Web Data.11.drBinary or memory string: interactivebrokers.co.inVMware20,11696494690d
Source: Web Data.11.drBinary or memory string: account.microsoft.com/profileVMware20,11696494690u
Source: Web Data.11.drBinary or memory string: outlook.office365.comVMware20,11696494690t
Source: rundll32.exe, 00000008.00000002.976366792.0000000002A08000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
Source: Web Data.11.drBinary or memory string: www.interactivebrokers.comVMware20,11696494690}
Source: Web Data.11.drBinary or memory string: microsoft.visualstudio.comVMware20,11696494690x
Source: Web Data.11.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696494690^
Source: Web Data.11.drBinary or memory string: Test URL for global passwords blocklistVMware20,11696494690
Source: rundll32.exe, 0000000C.00000002.1316850989.0000000003264000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: Web Data.11.drBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696494690z
Source: Web Data.11.drBinary or memory string: trackpan.utiitsl.comVMware20,11696494690h
Source: Web Data.11.drBinary or memory string: tasks.office.comVMware20,11696494690o
Source: Web Data.11.drBinary or memory string: www.interactivebrokers.co.inVMware20,11696494690~
Source: Web Data.11.drBinary or memory string: Interactive Brokers - COM.HKVMware20,11696494690
Source: Web Data.11.drBinary or memory string: dev.azure.comVMware20,11696494690j
Source: Web Data.11.drBinary or memory string: global block list test formVMware20,11696494690
Source: rundll32.exe, 00000006.00000002.1254632698.00000000027F8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll4
Source: Web Data.11.drBinary or memory string: turbotax.intuit.comVMware20,11696494690t
Source: Web Data.11.drBinary or memory string: bankofamerica.comVMware20,11696494690x
Source: Web Data.11.drBinary or memory string: Canara Transaction PasswordVMware20,11696494690}
Source: Web Data.11.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696494690
Source: Web Data.11.drBinary or memory string: Interactive Brokers - HKVMware20,11696494690]
Source: Web Data.11.drBinary or memory string: Canara Transaction PasswordVMware20,11696494690x
Source: Web Data.11.drBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696494690
Source: Web Data.11.drBinary or memory string: secure.bankofamerica.comVMware20,11696494690|UE
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00384FE3 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00384FE3
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00300290 GetLocalTime,CreateFileW,GetLastError,OutputDebugStringW,OutputDebugStringW,SetFilePointer,FlushFileBuffers,WriteFile,WriteFile,FlushFileBuffers,WriteFile,FlushFileBuffers,WriteFile,FlushFileBuffers,WriteFile,FlushFileBuffers,0_2_00300290
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002E0F60 SHGetFolderPathW,GetSystemDirectoryW,GetWindowsDirectoryW,GetWindowsDirectoryW,GetModuleFileNameW,SHGetSpecialFolderLocation,__Init_thread_footer,LoadLibraryW,GetProcAddress,SHGetPathFromIDListW,SHGetMalloc,0_2_002E0F60
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0039A04C mov eax, dword ptr fs:[00000030h]0_2_0039A04C
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0039A090 mov eax, dword ptr fs:[00000030h]0_2_0039A090
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0038B54A mov ecx, dword ptr fs:[00000030h]0_2_0038B54A
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0037F896 mov esi, dword ptr fs:[00000030h]0_2_0037F896
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0037F902 GetProcessHeap,HeapAlloc,GetProcessHeap,HeapFree,0_2_0037F902
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001DC5D0 __set_se_translator,SetUnhandledExceptionFilter,0_2_001DC5D0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00380424 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00380424
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001DEF30 __set_se_translator,SetUnhandledExceptionFilter,0_2_001DEF30
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00384FE3 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00384FE3
Source: C:\Windows\SysWOW64\rundll32.exeMemory allocated: page read and write | page guardJump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\SysWOW64\rundll32.exeNetwork Connect: 169.150.247.38 443Jump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" https://pdf-izer.com/thankyou.htmlJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "c:\windows\system32\msiexec.exe" /i "c:\users\user\appdata\roaming\pdfizer\pdfizer 1.0.0\install\cb21b6a\pdfizer_no_update.msi" ai_setupexepath=c:\users\user\desktop\pdfizer.exe setupexedir=c:\users\user\desktop\ exe_cmd_line="/exenoupdates /forcecleanup /wintime 1741883784 " ai_euimsi=""
Source: C:\Users\user\Desktop\PDFizer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "c:\windows\system32\msiexec.exe" /i "c:\users\user\appdata\roaming\pdfizer\pdfizer 1.0.0\install\cb21b6a\pdfizer_no_update.msi" ai_setupexepath=c:\users\user\desktop\pdfizer.exe setupexedir=c:\users\user\desktop\ exe_cmd_line="/exenoupdates /forcecleanup /wintime 1741883784 " ai_euimsi=""Jump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_002C72E0 GetCurrentProcess,OpenProcessToken,GetLastError,GetTokenInformation,GetTokenInformation,GetLastError,GetTokenInformation,AllocateAndInitializeSid,EqualSid,FreeSid,GetLastError,CloseHandle,0_2_002C72E0
Source: C:\Users\user\Desktop\PDFizer.exeCode function: GetLocaleInfoW,GetLocaleInfoW,0_2_002F60E0
Source: C:\Users\user\Desktop\PDFizer.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\WixToolset.Dtf.WindowsInstaller.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\RequestSender.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\WixToolset.Dtf.WindowsInstaller.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\RequestSender.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\WixToolset.Dtf.WindowsInstaller.dll VolumeInformation
Source: C:\Windows\SysWOW64\rundll32.exeQueries volume information: C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\RequestSender.dll VolumeInformation
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0030C610 CreateNamedPipeW,CreateFileW,0_2_0030C610
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_00300290 GetLocalTime,CreateFileW,GetLastError,OutputDebugStringW,OutputDebugStringW,SetFilePointer,FlushFileBuffers,WriteFile,WriteFile,FlushFileBuffers,WriteFile,FlushFileBuffers,WriteFile,FlushFileBuffers,WriteFile,FlushFileBuffers,0_2_00300290
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_0030AF40 GetUserNameW,GetUserNameW,GetLastError,GetUserNameW,GetEnvironmentVariableW,GetEnvironmentVariableW,RegDeleteValueW,RegCloseKey,RegQueryInfoKeyW,RegCloseKey,RegCloseKey,RegDeleteKeyW,RegCloseKey,RegCloseKey,RegDeleteValueW,RegCloseKey,0_2_0030AF40
Source: C:\Users\user\Desktop\PDFizer.exeCode function: 0_2_001A7620 GetVersionExW,GetVersionExW,GetVersionExW,IsProcessorFeaturePresent,0_2_001A7620
Source: C:\Windows\SysWOW64\rundll32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: C:\Users\user\Desktop\PDFizer.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EFC31460C619ECAE59C1BCE2C008036D94C84B8 BlobJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
1
Native API
1
DLL Side-Loading
1
DLL Side-Loading
11
Disable or Modify Tools
OS Credential Dumping1
System Time Discovery
Remote Services11
Archive Collected Data
3
Ingress Tool Transfer
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts12
Command and Scripting Interpreter
1
DLL Search Order Hijacking
1
DLL Search Order Hijacking
11
Deobfuscate/Decode Files or Information
LSASS Memory11
Peripheral Device Discovery
Remote Desktop ProtocolData from Removable Media11
Encrypted Channel
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts11
Scheduled Task/Job
1
Windows Service
1
Windows Service
3
Obfuscated Files or Information
Security Account Manager1
Account Discovery
SMB/Windows Admin SharesData from Network Shared Drive4
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCron11
Scheduled Task/Job
112
Process Injection
2
Software Packing
NTDS2
File and Directory Discovery
Distributed Component Object ModelInput Capture15
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchd1
Registry Run Keys / Startup Folder
11
Scheduled Task/Job
1
Timestomp
LSA Secrets27
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC Scripts1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
Cached Domain Credentials31
Security Software Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
DLL Search Order Hijacking
DCSync1
Virtualization/Sandbox Evasion
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
File Deletion
Proc Filesystem1
Process Discovery
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt21
Masquerading
/etc/passwd and /etc/shadow1
System Owner/User Discovery
Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron1
Modify Registry
Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd1
Virtualization/Sandbox Evasion
Input CaptureSystem Network Connections DiscoverySoftware Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
Gather Victim Org InformationDNS ServerCompromise Software Supply ChainWindows Command ShellScheduled TaskScheduled Task112
Process Injection
KeyloggingProcess DiscoveryTaint Shared ContentScreen CaptureDNSExfiltration Over Physical MediumResource Hijacking
Determine Physical LocationsVirtual Private ServerCompromise Hardware Supply ChainUnix ShellSystemd TimersSystemd Timers1
Rundll32
GUI Input CapturePermission Groups DiscoveryReplication Through Removable MediaEmail CollectionProxyExfiltration over USBNetwork Denial of Service
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1637530 Sample: PDFizer.exe Startdate: 13/03/2025 Architecture: WINDOWS Score: 42 82 pdf-izer-d.b-cdn.net 2->82 84 l.pdf-izer.com 2->84 96 Joe Sandbox ML detected suspicious sample 2->96 10 msiexec.exe 121 70 2->10         started        13 PDFizer.exe 39 2->13         started        15 msedge.exe 2->15         started        signatures3 process4 dnsIp5 64 C:\Windows\Installer\MSID970.tmp, PE32 10->64 dropped 66 C:\Windows\Installer\MSID289.tmp, PE32 10->66 dropped 68 C:\Windows\Installer\MSID085.tmp, PE32 10->68 dropped 76 16 other files (15 malicious) 10->76 dropped 18 msiexec.exe 10->18         started        20 msiexec.exe 10->20         started        70 C:\Users\user\AppData\...\vcruntime140_1.dll, PE32+ 13->70 dropped 72 C:\Users\user\AppData\...\vcruntime140.dll, PE32+ 13->72 dropped 74 C:\Users\user\AppData\...\msvcp140_2.dll, PE32+ 13->74 dropped 78 8 other files (3 malicious) 13->78 dropped 22 msiexec.exe 2 13->22         started        92 192.168.2.8, 138, 443, 49673 unknown unknown 15->92 94 239.255.255.250 unknown Reserved 15->94 24 msedge.exe 15->24         started        27 msedge.exe 15->27         started        29 msedge.exe 15->29         started        31 2 other processes 15->31 file6 process7 dnsIp8 33 rundll32.exe 15 10 18->33         started        38 rundll32.exe 8 18->38         started        40 rundll32.exe 18->40         started        86 pdf-izer-website.b-cdn.net 169.150.247.39, 443, 49692, 49697 SPIRITTEL-ASUS United States 24->86 88 138.199.40.58, 443, 49766, 49767 ORANGE-BUSINESS-SERVICES-IPSN-ASNFR European Union 24->88 90 14 other IPs or domains 24->90 process9 dnsIp10 80 pdf-izer-d.b-cdn.net 169.150.247.38, 443, 49686 SPIRITTEL-ASUS United States 33->80 62 4 other malicious files 33->62 dropped 98 System process connects to network (likely due to code injection or exploit) 33->98 100 Installs Task Scheduler Managed Wrapper 33->100 46 C:\...\WixToolset.Dtf.WindowsInstaller.dll, PE32 38->46 dropped 48 C:\Windows\Installer\...\RequestSender.dll, PE32 38->48 dropped 50 Microsoft.Win32.Ta...duler.resources.dll, PE32 38->50 dropped 52 C:\...\Microsoft.Win32.TaskScheduler.dll, PE32 38->52 dropped 42 msedge.exe 38->42         started        54 C:\...\WixToolset.Dtf.WindowsInstaller.dll, PE32 40->54 dropped 56 C:\Windows\Installer\...\RequestSender.dll, PE32 40->56 dropped 58 Microsoft.Win32.Ta...duler.resources.dll, PE32 40->58 dropped 60 C:\...\Microsoft.Win32.TaskScheduler.dll, PE32 40->60 dropped file11 signatures12 process13 process14 44 msedge.exe 42->44         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
PDFizer.exe3%VirustotalBrowse
PDFizer.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\MSIC188.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\MSIC244.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\MSIC274.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\shiC0FA.tmp0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\Core.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\Core.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\PDFizer.exe11%ReversingLabsWin32.Trojan.Generic
C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140_1.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\msvcp140_2.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\vcruntime140.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\PDFizer 1.0.0\install\CB21B6A\vcruntime140_1.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\PDFizer.exe11%ReversingLabsWin32.Trojan.Generic
C:\Users\user\AppData\Roaming\PDFizer\msvcp140.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\msvcp140_1.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\msvcp140_2.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\vcruntime140.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\PDFizer\vcruntime140_1.dll0%ReversingLabs
C:\Windows\Installer\MSIC6B7.tmp0%ReversingLabs
C:\Windows\Installer\MSIC6C7.tmp0%ReversingLabs
C:\Windows\Installer\MSIC736.tmp0%ReversingLabs
C:\Windows\Installer\MSIC7F2.tmp0%ReversingLabs
C:\Windows\Installer\MSIC813.tmp0%ReversingLabs
C:\Windows\Installer\MSIC871.tmp0%ReversingLabs
C:\Windows\Installer\MSIC8EF.tmp0%ReversingLabs
C:\Windows\Installer\MSICB13.tmp0%ReversingLabs
C:\Windows\Installer\MSICDD4.tmp0%ReversingLabs
C:\Windows\Installer\MSID085.tmp0%ReversingLabs
C:\Windows\Installer\MSID289.tmp0%ReversingLabs
C:\Windows\Installer\MSID970.tmp0%ReversingLabs
C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.dll0%ReversingLabs
C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\Microsoft.Win32.TaskScheduler.resources.dll0%ReversingLabs
C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\RequestSender.dll0%ReversingLabs
C:\Windows\Installer\SFXCAA639CEB36F4CBB6A1EA07D4CE2294699\WixToolset.Dtf.WindowsInstaller.dll0%ReversingLabs
C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.dll0%ReversingLabs
C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\Microsoft.Win32.TaskScheduler.resources.dll0%ReversingLabs
C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\RequestSender.dll0%ReversingLabs
C:\Windows\Installer\SFXCABDBF1C2CFC4EBA49779218F5B3683282\WixToolset.Dtf.WindowsInstaller.dll0%ReversingLabs
C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.dll0%ReversingLabs
C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\Microsoft.Win32.TaskScheduler.resources.dll0%ReversingLabs
C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\RequestSender.dll0%ReversingLabs
C:\Windows\Installer\SFXCAE1D6181A2F484F1B96EB7A3B5A1C9CEC\WixToolset.Dtf.WindowsInstaller.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://pdf-izer.com/thankyou.html...0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmleUz0%Avira URL Cloudsafe
https://pdf-izer.com/0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlPDF-IZER/0%Avira URL Cloudsafe
https://l.pdf-izer.com//finishh2P0%Avira URL Cloudsafe
https://l.pdf-izer.com//finish0%Avira URL Cloudsafe
https://l.pdf-izer.com//startt0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlLRQrx0%Avira URL Cloudsafe
http://pdf-izer-d.b-cdn.net0%Avira URL Cloudsafe
https://pdf-izer.com/download/jre.zip0%Avira URL Cloudsafe
https://l.pdf-izer.com//finisht0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.html0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlC:0%Avira URL Cloudsafe
https://l.pdf-izer.com0%Avira URL Cloudsafe
https://l.pdf-izer.com//startLRQrP0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.H0%Avira URL Cloudsafe
https://learn.microso0%Avira URL Cloudsafe
https://pdf-izer.com/favicon.ico0%Avira URL Cloudsafe
https://l.pdf-iz0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.html6A0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlPDF-IZER0%Avira URL Cloudsafe
http://l.pdf-izer.com0%Avira URL Cloudsafe
https://l.pdf-izer.com//0%Avira URL Cloudsafe
https://pdf-izer.com/assets/pdf-izer-icons/pdf_izer_logo.png0%Avira URL Cloudsafe
https://l.pdf-izer.com//start0%Avira URL Cloudsafe
https://l.pdf-izer.com/0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmle0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlB60%Avira URL Cloudsafe
https://l.pdf-izer.com//finishLRQr0%Avira URL Cloudsafe
https://l.pdf-izer0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlEQS0%Avira URL Cloudsafe
https://pdf-izer.com/download/pdfjar.zip0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.html00%Avira URL Cloudsafe
https://pdf-izer.com/assets/pdf-izer-icons/check-circle.svg0%Avira URL Cloudsafe
https://l.pdf-izer.com/LRQr0%Avira URL Cloudsafe
https://l.pdf-izer.com//finishL0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlPDF-IZERg0%Avira URL Cloudsafe
https://l.pdf-izer.com/ThankYouURLhttps://pdf-izer.com/thankyou.htmlButtonText_Install&InstallIAgree0%Avira URL Cloudsafe
https://pdf-izer.com/thankyou.htmlmy0%Avira URL Cloudsafe
https://l.pdf-izer.com/D0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
pdf-izer-website.b-cdn.net
169.150.247.39
truefalse
    unknown
    chrome.cloudflare-dns.com
    172.64.41.3
    truefalse
      high
      pdf-izer-d.b-cdn.net
      169.150.247.38
      truetrue
        unknown
        s-part-0041.t-0009.t-msedge.net
        13.107.246.69
        truefalse
          high
          a416.dscd.akamai.net
          2.22.242.11
          truefalse
            high
            ssl.bingadsedgeextension-prod-europe.azurewebsites.net
            94.245.104.56
            truefalse
              high
              googlehosted.l.googleusercontent.com
              142.250.185.161
              truefalse
                high
                l.pdf-izer.com
                unknown
                unknownfalse
                  unknown
                  clients2.googleusercontent.com
                  unknown
                  unknownfalse
                    high
                    bzib.nelreports.net
                    unknown
                    unknownfalse
                      high
                      pdf-izer.com
                      unknown
                      unknownfalse
                        unknown
                        NameMaliciousAntivirus DetectionReputation
                        https://pdf-izer.com/thankyou.htmlfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://pdf-izer.com/favicon.icofalse
                        • Avira URL Cloud: safe
                        unknown
                        https://pdf-izer.com/assets/pdf-izer-icons/pdf_izer_logo.pngfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://clients2.googleusercontent.com/crx/blobs/Ad_brx23lef_cW590ESOTTAroOhZ9si0XFJIUC52j2ILHW1VLB5ou6c0RgLWwGr1aRJJZ0WPNyiPBYgIpWfykvhKW-6BLzMRsp9ykw5f6ReBQmPpO6WB9pcSJPfykLTHDjYAxlKa5bf72z8tHS5eXuTavTP1h4WZBjSs/GHBMNNJOOEKPMOECNNNILNNBDLOLHKHI_1_89_1_0.crxfalse
                          high
                          https://bzib.nelreports.net/api/report?cat=bingbusinessfalse
                            high
                            https://chrome.cloudflare-dns.com/dns-queryfalse
                              high
                              https://pdf-izer.com/assets/pdf-izer-icons/check-circle.svgfalse
                              • Avira URL Cloud: safe
                              unknown
                              NameSourceMaliciousAntivirus DetectionReputation
                              http://html4/loose.dtdshiC0FA.tmp.0.drfalse
                                high
                                https://duckduckgo.com/chrome_newtabWeb Data.11.drfalse
                                  high
                                  https://duckduckgo.com/ac/?q=Web Data.11.drfalse
                                    high
                                    https://pdf-izer.com/000003.log4.11.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://l.pdf-izer.com//finishrundll32.exe, 0000000C.00000002.1317987005.0000000005251000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://pdf-izer.com/thankyou.htmlLRQrxrundll32.exe, 00000008.00000002.982545442.00000000045E1000.00000004.00000800.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://pdf-izer.com/thankyou.htmlPDF-IZER/History.11.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    http://pdf-izer-d.b-cdn.netrundll32.exe, 00000006.00000002.1255823881.0000000004698000.00000004.00000800.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://pdf-izer.com/thankyou.htmleUzPDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://l.pdf-izer.com//starttrundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=Web Data.11.drfalse
                                      high
                                      https://pdf-izer.com/thankyou.html...PDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      https://deff.nelreports.net/api/report?cat=msnReporting and NEL.13.drfalse
                                        high
                                        http://.cssshiC0FA.tmp.0.drfalse
                                          high
                                          http://schemas.microPDFizer.exe, 00000000.00000003.917647408.0000000000D30000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.921450228.0000000005ADD000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.917586424.0000000000D27000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.916579600.0000000000CF5000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1322693470.0000000005A5C000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.915806084.0000000005371000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.921279579.0000000005AD2000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.916841357.0000000000D00000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327079000.0000000005A50000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.drfalse
                                            high
                                            https://pdf-izer.com/download/jre.zipPDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, Core.dll.2.dr, Core.dll.0.drfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://docs.google.com/manifest.json.11.drfalse
                                              high
                                              https://l.pdf-izer.com//finishh2Prundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://l.pdf-izer.com//finishtrundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://drive-staging.corp.google.com/manifest.json.11.drfalse
                                                high
                                                https://drive.google.com/manifest.json.11.drfalse
                                                  high
                                                  https://l.pdf-izrundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://l.pdf-izer.comrundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.1255823881.0000000004611000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.0000000005251000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchWeb Data.11.drfalse
                                                    high
                                                    http://www.marksimonson.comProximaPDFizer.exe.2.drfalse
                                                      high
                                                      https://pdf-izer.com/thankyou.htmlC:rundll32.exe, 00000008.00000002.976120298.0000000002855000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namerundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.1255823881.0000000004611000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.0000000005251000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                        high
                                                        http://.jpgshiC0FA.tmp.0.drfalse
                                                          high
                                                          https://l.pdf-izer.com//startLRQrPrundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          • Avira URL Cloud: safe
                                                          unknown
                                                          https://www.google.com/images/branding/product/ico/googleg_lodp.icoWeb Data.11.drfalse
                                                            high
                                                            https://pdf-izer.com/thankyou.Hrundll32.exe, 00000008.00000002.982545442.00000000045E1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://learn.microsorundll32.exe, 0000000C.00000002.1316850989.00000000032D3000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://pdf-izer.com/thankyou.html6APDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://pdf-izer.com/thankyou.htmlPDF-IZERHistory.11.drfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            http://l.pdf-izer.comrundll32.exe, 00000006.00000002.1255823881.0000000004698000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            • Avira URL Cloud: safe
                                                            unknown
                                                            https://cdnjs.cloudflare.com/ajax/libs/mathjax/service_worker_bin_prod.js.11.dr, offscreendocument_main.js.11.drfalse
                                                              high
                                                              https://drive-daily-2.corp.google.com/manifest.json.11.drfalse
                                                                high
                                                                https://drive-autopush.corp.google.com/manifest.json.11.drfalse
                                                                  high
                                                                  https://drive-daily-4.corp.google.com/manifest.json.11.drfalse
                                                                    high
                                                                    https://l.pdf-izer.com//rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    • Avira URL Cloud: safe
                                                                    unknown
                                                                    https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=Web Data.11.drfalse
                                                                      high
                                                                      https://l.pdf-izer.com//finishLRQrrundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://pdf-izer.com/thankyou.htmlePDFizer.exe, 00000000.00000003.917008114.0000000000CE7000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://l.pdf-izer.com//startrundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://pdf-izer.com/thankyou.htmlB6PDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://l.pdf-izer.com/PDFizer.exe, 00000000.00000003.1324291885.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321640349.0000000000CFA000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000002.1327468689.0000000005AF9000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1321899247.0000000005AF8000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1320693288.0000000005AF7000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324367428.0000000000CFB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      • Avira URL Cloud: safe
                                                                      unknown
                                                                      https://drive-daily-1.corp.google.com/manifest.json.11.drfalse
                                                                        high
                                                                        https://l.pdf-izerrundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://drive-daily-5.corp.google.com/manifest.json.11.drfalse
                                                                          high
                                                                          https://pdf-izer.com/thankyou.htmlEQSPDFizer.exe, 00000000.00000003.1321243238.0000000005B14000.00000004.00000020.00020000.00000000.sdmp, PDFizer.exe, 00000000.00000003.1324836725.0000000005B17000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          • Avira URL Cloud: safe
                                                                          unknown
                                                                          https://pdf-izer.com/download/pdfjar.zipPDFizer.exe, 00000000.00000003.947017689.00000000053EE000.00000004.00000020.00020000.00000000.sdmp, Core.dll.2.dr, Core.dll.0.drfalse
                                                                          • Avira URL Cloud: safe
                                                                          unknown
                                                                          https://pdf-izer.com/thankyou.html0Session_13386357486330984.11.drfalse
                                                                          • Avira URL Cloud: safe
                                                                          unknown
                                                                          https://www.google.com/chromecontent_new.js.11.dr, content.js.11.drfalse
                                                                            high
                                                                            https://drive-daily-6.corp.google.com/manifest.json.11.drfalse
                                                                              high
                                                                              https://drive-daily-0.corp.google.com/manifest.json.11.drfalse
                                                                                high
                                                                                https://pdf-izer.com/thankyou.htmlmyrundll32.exe, 00000008.00000002.976366792.0000000002A08000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                • Avira URL Cloud: safe
                                                                                unknown
                                                                                https://chromewebstore.google.com/manifest.json0.11.drfalse
                                                                                  high
                                                                                  https://l.pdf-izer.com/LRQrrundll32.exe, 00000006.00000002.1255823881.000000000467B000.00000004.00000800.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                  • Avira URL Cloud: safe
                                                                                  unknown
                                                                                  https://wixtoolset.org/rundll32.exe, 00000006.00000003.940350988.0000000002790000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969824841.00000000029EF000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988939262.000000000324F000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, WixToolset.Dtf.WindowsInstaller.dll.12.dr, WixToolset.Dtf.WindowsInstaller.dll.6.dr, WixToolset.Dtf.WindowsInstaller.dll.8.drfalse
                                                                                    high
                                                                                    https://l.pdf-izer.com/ThankYouURLhttps://pdf-izer.com/thankyou.htmlButtonText_Install&InstallIAgreePDFizer.exe, 00000000.00000003.915806084.0000000005122000.00000004.00000020.00020000.00000000.sdmp, 3cc3fb.msi.2.dr, 3cc3f8.msi.2.drfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://www.winimage.com/zLibDllMSICDD4.tmp.2.drfalse
                                                                                      high
                                                                                      https://drive-preprod.corp.google.com/manifest.json.11.drfalse
                                                                                        high
                                                                                        https://clients2.googleusercontent.com32deb3aa-21f9-4654-a4de-259bb0948be5.tmp.13.drfalse
                                                                                          high
                                                                                          https://pdf-izer.com/thankyou.htmlPDF-IZERgWebAssistDatabase.11.drfalse
                                                                                          • Avira URL Cloud: safe
                                                                                          unknown
                                                                                          https://chrome.google.com/webstore/manifest.json0.11.drfalse
                                                                                            high
                                                                                            https://l.pdf-izer.com//finishLrundll32.exe, 0000000C.00000002.1317987005.00000000052BB000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            https://github.com/dahall/taskschedulerrundll32.exe, 00000006.00000003.939972386.00000000043BB000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000008.00000003.969713198.000000000440D000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 0000000C.00000003.988803808.0000000004EAF000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Win32.TaskScheduler.dll.8.dr, Microsoft.Win32.TaskScheduler.dll.12.dr, Microsoft.Win32.TaskScheduler.dll.6.drfalse
                                                                                              high
                                                                                              https://drive-daily-3.corp.google.com/manifest.json.11.drfalse
                                                                                                high
                                                                                                https://l.pdf-izer.com/Drundll32.exe, 0000000C.00000003.1013103854.00000000032CD000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                • Avira URL Cloud: safe
                                                                                                unknown
                                                                                                • No. of IPs < 25%
                                                                                                • 25% < No. of IPs < 50%
                                                                                                • 50% < No. of IPs < 75%
                                                                                                • 75% < No. of IPs
                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                138.199.40.58
                                                                                                unknownEuropean Union
                                                                                                51964ORANGE-BUSINESS-SERVICES-IPSN-ASNFRfalse
                                                                                                23.57.90.145
                                                                                                unknownUnited States
                                                                                                35994AKAMAI-ASUSfalse
                                                                                                2.22.242.11
                                                                                                a416.dscd.akamai.netEuropean Union
                                                                                                20940AKAMAI-ASN1EUfalse
                                                                                                169.150.247.38
                                                                                                pdf-izer-d.b-cdn.netUnited States
                                                                                                2711SPIRITTEL-ASUStrue
                                                                                                169.150.247.39
                                                                                                pdf-izer-website.b-cdn.netUnited States
                                                                                                2711SPIRITTEL-ASUSfalse
                                                                                                162.159.61.3
                                                                                                unknownUnited States
                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                23.57.90.73
                                                                                                unknownUnited States
                                                                                                35994AKAMAI-ASUSfalse
                                                                                                239.255.255.250
                                                                                                unknownReserved
                                                                                                unknownunknownfalse
                                                                                                142.250.185.161
                                                                                                googlehosted.l.googleusercontent.comUnited States
                                                                                                15169GOOGLEUSfalse
                                                                                                172.64.41.3
                                                                                                chrome.cloudflare-dns.comUnited States
                                                                                                13335CLOUDFLARENETUSfalse
                                                                                                IP
                                                                                                192.168.2.8
                                                                                                Joe Sandbox version:42.0.0 Malachite
                                                                                                Analysis ID:1637530
                                                                                                Start date and time:2025-03-13 17:36:57 +01:00
                                                                                                Joe Sandbox product:CloudBasic
                                                                                                Overall analysis duration:0h 10m 15s
                                                                                                Hypervisor based Inspection enabled:false
                                                                                                Report type:full
                                                                                                Cookbook file name:default.jbs
                                                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                Run name:Run with higher sleep bypass
                                                                                                Number of analysed new started processes analysed:33
                                                                                                Number of new started drivers analysed:0
                                                                                                Number of existing processes analysed:0
                                                                                                Number of existing drivers analysed:0
                                                                                                Number of injected processes analysed:0
                                                                                                Technologies:
                                                                                                • HCA enabled
                                                                                                • EGA enabled
                                                                                                • AMSI enabled
                                                                                                Analysis Mode:default
                                                                                                Analysis stop reason:Timeout
                                                                                                Sample name:PDFizer.exe
                                                                                                Detection:MAL
                                                                                                Classification:mal42.evad.winEXE@64/327@13/11
                                                                                                EGA Information:
                                                                                                • Successful, ratio: 25%
                                                                                                HCA Information:
                                                                                                • Successful, ratio: 62%
                                                                                                • Number of executed functions: 140
                                                                                                • Number of non-executed functions: 143
                                                                                                Cookbook Comments:
                                                                                                • Found application associated with file extension: .exe
                                                                                                • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
                                                                                                • Sleep loops longer than 100000000ms are bypassed. Single calls with delay of 100000000ms and higher are ignored
                                                                                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, sppsvc.exe, RuntimeBroker.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                                                                • Excluded IPs from analysis (whitelisted): 13.107.21.239, 204.79.197.239, 142.250.184.206, 13.107.6.158, 13.107.42.16, 172.211.159.152, 184.86.251.14, 184.86.251.10, 184.86.251.21, 184.86.251.22, 184.86.251.13, 184.86.251.11, 184.86.251.15, 184.86.251.23, 184.86.251.12, 48.209.144.71, 199.232.214.172, 199.232.210.172, 142.250.188.227, 172.217.14.67, 142.250.189.3, 142.250.72.131, 142.251.40.35, 94.245.104.56, 40.126.31.129, 52.149.20.212, 104.40.82.182, 13.107.246.69, 23.57.90.70, 23.199.214.10
                                                                                                • Excluded domains from analysis (whitelisted): nav-edge.smartscreen.microsoft.com, edge-domain.trafficmanager.net, config.edge.skype.com.trafficmanager.net, slscr.update.microsoft.com, data-edge.smartscreen.microsoft.com, edgeassetservice.afd.azureedge.net, clients2.google.com, e86303.dscx.akamaiedge.net, www.bing.com.edgekey.net, login.live.com, config-edge-skype.l-0007.l-msedge.net, msedge.b.tlu.dl.delivery.mp.microsoft.com, prod-agic-we-7.westeurope.cloudapp.azure.com, www.gstatic.com, l-0007.l-msedge.net, c.pki.goog, config.edge.skype.com, www.bing.com, edge-microsoft-com.dual-a-0036.a-msedge.net, fs.microsoft.com, bingadsedgeextension-prod.trafficmanager.net, api.edgeoffer.microsoft.com, ctldl.windowsupdate.com, b-0005.b-msedge.net, prod-atm-wds-edge.trafficmanager.net, www-www.bing.com.trafficmanager.net, edge.microsoft.com, business-bing-com.b-0005.b-msedge.net, fe3cr.delivery.mp.microsoft.com, l-0007.config.skype.com, edgeassetservice.azureedge.net, azureedge-t-prod.trafficmanager.net, business.bing.co
                                                                                                • Execution Graph export aborted for target rundll32.exe, PID 3912 because it is empty
                                                                                                • Execution Graph export aborted for target rundll32.exe, PID 7336 because it is empty
                                                                                                • Execution Graph export aborted for target rundll32.exe, PID 7620 because it is empty
                                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                                • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                                • Report size getting too big, too many NtOpenFile calls found.
                                                                                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                                                                                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                No simulations
                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                138.199.40.58anuwhqTXGt.dllGet hashmaliciousUnknownBrowse
                                                                                                • 4o985rhikfsof.b-cdn.net/license_1.28.763.1.dat
                                                                                                anuwhqTXGt.dllGet hashmaliciousUnknownBrowse
                                                                                                • 4o985rhikfsof.b-cdn.net/license_1.28.763.1.dat
                                                                                                http://0365-encrypyted.b-cdn.net#dGh1bnRAbW9vZy5jb20=Get hashmaliciousHTMLPhisherBrowse
                                                                                                • 0365-encrypyted.b-cdn.net/
                                                                                                23.57.90.145Tokenova.exeGet hashmaliciousVidarBrowse
                                                                                                  nbyiksfthaed.exeGet hashmaliciousVidarBrowse
                                                                                                    vXn4pan2US.exeGet hashmaliciousUnknownBrowse
                                                                                                      JA7cOAGHym.exeGet hashmaliciousVidarBrowse
                                                                                                        file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                          file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                                                                                                            2.22.242.11pid.kvai.exeGet hashmaliciousUnknownBrowse
                                                                                                              TEDGRQXB.exeGet hashmaliciousVidarBrowse
                                                                                                                f1215469392.dllGet hashmaliciousUnknownBrowse
                                                                                                                  Sryxen-Built.exeGet hashmaliciousUnknownBrowse
                                                                                                                    thUKanu6GD.lnkGet hashmaliciousHTMLPhisher, MalLnkBrowse
                                                                                                                      https://www.flipsnack.com/859EECFF8D6/distribution-agreement/full-view.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                        https://zsharepointonlinems.mysteriousroutes.it.com/kOPeS/#fuck@you.comGet hashmaliciousUnknownBrowse
                                                                                                                          09.msiGet hashmaliciousRedLineBrowse
                                                                                                                            95.msiGet hashmaliciousRedLineBrowse
                                                                                                                              SecuriteInfo.com.Trojan.Inject5.17530.4675.11921.exeGet hashmaliciousUnknownBrowse
                                                                                                                                169.150.247.38obs.dll.dllGet hashmaliciousUnknownBrowse
                                                                                                                                • emarketstats.com/front.php?a=UHuMrM0mQEjZR8S&id=0
                                                                                                                                obs.dll.dllGet hashmaliciousUnknownBrowse
                                                                                                                                • emarketstats.com/front.php?a=FPAshxuZlTP6xst&id=0
                                                                                                                                eodJLLo3Px.lnkGet hashmaliciousUnknownBrowse
                                                                                                                                • fonts.bunny.net/css?family=Rubik:300,400,500,700,900
                                                                                                                                https://trk.pmifunds.com/y.z?l=http://security1.b-cdn.net&j=375634604&e=3028&p=1&t=h&D6EBE0CCEBB74CE191551D6EE653FA1EGet hashmaliciousUnknownBrowse
                                                                                                                                • security1.b-cdn.net/
                                                                                                                                http://gbapk.cc/Get hashmaliciousUnknownBrowse
                                                                                                                                • gbapk.cc/
                                                                                                                                EBAbsk8ydv.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • xn--ypd.dssdhome.xyz/11/ip.bin
                                                                                                                                https://softworldinc.wpengine.comGet hashmaliciousUnknownBrowse
                                                                                                                                • cdn.rawgit.com/michalsnik/aos/2.1.1/dist/aos.js
                                                                                                                                rPRESSUREREDUCINGVALVE_pdf.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                • www.openlend.lat/aw8o/?-wkb=JwP18BaQn2gAMbwzAk/tzHq1rHqPkgowxzXz/N2AVg5llpqPoDBUT4Fbw9qJesVKC8w5QoNuWE8SYi183Rf2cdVRH8sDFcjA1Q==&_-=axSpBNXszGs9cCrW
                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                pdf-izer-d.b-cdn.netPDFizer_no_update.msiGet hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                s-part-0041.t-0009.t-msedge.netBank Details.DocxGet hashmaliciousMicrosoft PhishingBrowse
                                                                                                                                • 13.107.246.69
                                                                                                                                https://pascohh.com/see-the-difference/Get hashmaliciousUnknownBrowse
                                                                                                                                • 13.107.246.69
                                                                                                                                https://procurementmcfs.powerappsportals.com/en-US/Register?returnUrl=%2fen-US%2fGet hashmaliciousUnknownBrowse
                                                                                                                                • 13.107.246.69
                                                                                                                                MacKeeper.6.7.1.pkgGet hashmaliciousUnknownBrowse
                                                                                                                                • 13.107.246.69
                                                                                                                                https://linko.page/usloomisGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                • 13.107.246.69
                                                                                                                                chrome.cloudflare-dns.comDocument25.xlsmGet hashmaliciousScreenConnect Tool, AsyncRAT, StormKitty, VenomRATBrowse
                                                                                                                                • 172.64.41.3
                                                                                                                                PSAP Toolkit 2.8.0.07 (XML 6.76) Setup.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 162.159.61.3
                                                                                                                                aXeuKjNXAK.ps1Get hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                • 162.159.61.3
                                                                                                                                9ua5N7dcBZ.exeGet hashmaliciousAmadey, RHADAMANTHYSBrowse
                                                                                                                                • 162.159.61.3
                                                                                                                                pid.kvai.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 172.64.41.3
                                                                                                                                TEDGRQXB.exeGet hashmaliciousVidarBrowse
                                                                                                                                • 162.159.61.3
                                                                                                                                SecuriteInfo.com.Trojan.InstallCore.4099.24415.17034.exeGet hashmaliciousPrivateLoaderBrowse
                                                                                                                                • 162.159.61.3
                                                                                                                                f1215887448.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 172.64.41.3
                                                                                                                                f468369488.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 162.159.61.3
                                                                                                                                f492136216_mpengine_dllGet hashmaliciousUnknownBrowse
                                                                                                                                • 172.64.41.3
                                                                                                                                a416.dscd.akamai.netDocument25.xlsmGet hashmaliciousScreenConnect Tool, AsyncRAT, StormKitty, VenomRATBrowse
                                                                                                                                • 2.22.242.105
                                                                                                                                pid.kvai.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 2.22.242.11
                                                                                                                                TEDGRQXB.exeGet hashmaliciousVidarBrowse
                                                                                                                                • 2.22.242.11
                                                                                                                                f468369488.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 2.16.164.33
                                                                                                                                f1215469392.dllGet hashmaliciousUnknownBrowse
                                                                                                                                • 2.22.242.11
                                                                                                                                Sryxen-Built.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 2.22.242.105
                                                                                                                                Sryxen-Built.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 2.22.242.11
                                                                                                                                thUKanu6GD.lnkGet hashmaliciousHTMLPhisher, MalLnkBrowse
                                                                                                                                • 2.22.242.11
                                                                                                                                file.exeGet hashmaliciousVidarBrowse
                                                                                                                                • 2.22.242.105
                                                                                                                                LtCPevm69G.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Poverty Stealer, PureLog Stealer, Stealc, VidarBrowse
                                                                                                                                • 2.22.242.105
                                                                                                                                ssl.bingadsedgeextension-prod-europe.azurewebsites.netthUKanu6GD.lnkGet hashmaliciousHTMLPhisher, MalLnkBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                file.exeGet hashmaliciousVidarBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                LtCPevm69G.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Poverty Stealer, PureLog Stealer, Stealc, VidarBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                ADFoyxP.exeGet hashmaliciousKeyLogger, StormKitty, VenomRATBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                https://www.flipsnack.com/859EECFF8D6/distribution-agreement/full-view.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                https://zsharepointonlinems.mysteriousroutes.it.com/kOPeS/#fuck@you.comGet hashmaliciousUnknownBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                q3na5Mc.exeGet hashmaliciousVidarBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                ESVoO7ywn5.exeGet hashmaliciousVidarBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                SecuriteInfo.com.Trojan.Inject5.17530.4675.11921.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                Payment_Activity_0079_2025-2-23.vbsGet hashmaliciousUnknownBrowse
                                                                                                                                • 94.245.104.56
                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                AKAMAI-ASUSCopy of 1- GCP Vendor Information Smart Form Stepan.xlsmGet hashmaliciousUnknownBrowse
                                                                                                                                • 23.60.203.209
                                                                                                                                https://forms.monday.com/forms/67029d93936d7b64a3fbc15a7475ec8f?r=use1&c=E,1,THyo-S_P-0CHHa3uXfs0rZtMLjz4isIKq-YhZ2FY003H81dQx2Z7djFM4nGnHUOiGJjWoebTuzdCYhK-vDoAPt4JkzhGXkWP2d80wF2ep4EW&typo=1Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                • 2.19.224.32
                                                                                                                                https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071aGet hashmaliciousUnknownBrowse
                                                                                                                                • 23.37.54.34
                                                                                                                                https://digimobil-recrgar.comGet hashmaliciousUnknownBrowse
                                                                                                                                • 23.196.243.195
                                                                                                                                FW_ Remittance Address.msgGet hashmaliciousUnknownBrowse
                                                                                                                                • 23.196.243.195
                                                                                                                                file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 104.73.234.102
                                                                                                                                file.exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 104.73.234.102
                                                                                                                                file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                • 104.73.234.102
                                                                                                                                file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                • 104.73.234.102
                                                                                                                                file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                • 104.73.234.102
                                                                                                                                SPIRITTEL-ASUSPDFizer_no_update.msiGet hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                https://ipfs.io/ipfs/bafybeifbvu36kut5mx2cahzdxelyzulfz3gn6ptz5ul63rbub7ljlt3pjyGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                • 169.150.247.39
                                                                                                                                http://support.ringcentral.coGet hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.255.181
                                                                                                                                CryptocommSetup.msiGet hashmaliciousBumbleBeeBrowse
                                                                                                                                • 169.150.247.37
                                                                                                                                Online Notification.pdfGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                • 169.150.255.180
                                                                                                                                https://0utl00k_secure_pdfsharing.wesendit.com/dl/9WeFG1R9WGJTbgaCO/a3Jpc3RhbC5wbGFpc3RlZEBzb2RleG8uY29t__;!!P5FZM7ryyeY!UznDjsW7gO6EJncqNmJhgeM1Zawk4R__aUyCoG6Jb-mYlr-79K2gn3tFm6bOpnkuKuN_n69fA8HZASZsr-9bQyk$Get hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                https://0utl00k_secure_pdfsharing.wesendit.com/dl/9WeFG1R9WGJTbgaCO/a3Jpc3RhbC5wbGFpc3RlZEBzb2RleG8uY29t__;!!P5FZM7ryyeY!UznDjsW7gO6EJncqNmJhgeM1Zawk4R__aUyCoG6Jb-mYlr-79K2gn3tFm6bOpnkuKuN_n69fA8HZASZsr-9bQyk$Get hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.39
                                                                                                                                https://cdn-facxxx.b-cdn.net/Get hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.39
                                                                                                                                https://cdn-facxxx.b-cdn.net/Get hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.39
                                                                                                                                jklx86.elfGet hashmaliciousUnknownBrowse
                                                                                                                                • 165.167.207.27
                                                                                                                                ORANGE-BUSINESS-SERVICES-IPSN-ASNFRSecuriteInfo.com.Trojan.InstallCore.4099.24415.17034.exeGet hashmaliciousPrivateLoaderBrowse
                                                                                                                                • 138.199.168.42
                                                                                                                                SecuriteInfo.com.Trojan.InstallCore.4099.24415.17034.exeGet hashmaliciousPrivateLoaderBrowse
                                                                                                                                • 138.199.168.42
                                                                                                                                cbr.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                                                                                • 196.27.59.208
                                                                                                                                cbr.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                • 196.27.59.252
                                                                                                                                cbr.mpsl.elfGet hashmaliciousMiraiBrowse
                                                                                                                                • 57.79.73.241
                                                                                                                                jklmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                                                                • 57.98.102.192
                                                                                                                                CryptocommSetup.msiGet hashmaliciousBumbleBeeBrowse
                                                                                                                                • 138.199.36.11
                                                                                                                                spc.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                                                • 57.105.78.176
                                                                                                                                splspc.elfGet hashmaliciousUnknownBrowse
                                                                                                                                • 57.89.145.199
                                                                                                                                nklmpsl.elfGet hashmaliciousUnknownBrowse
                                                                                                                                • 57.74.47.202
                                                                                                                                AKAMAI-ASN1EUhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071aGet hashmaliciousUnknownBrowse
                                                                                                                                • 23.43.60.131
                                                                                                                                https://digimobil-recrgar.comGet hashmaliciousUnknownBrowse
                                                                                                                                • 2.19.96.146
                                                                                                                                FW_ Remittance Address.msgGet hashmaliciousUnknownBrowse
                                                                                                                                • 88.221.110.227
                                                                                                                                file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                • 23.197.127.21
                                                                                                                                file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                • 23.197.127.21
                                                                                                                                file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                • 23.197.127.21
                                                                                                                                file.exeGet hashmaliciousLummaC StealerBrowse
                                                                                                                                • 23.197.127.21
                                                                                                                                http://app.plangrid.com/projects/bcb97291-5564-5612-9970-d1b139dcb62d/staple/b1fc2804-67d4-470e-9780-d2d4344b3b93Get hashmaliciousUnknownBrowse
                                                                                                                                • 2.19.96.120
                                                                                                                                Peo Retention Memo Reff No2.pdfGet hashmaliciousUnknownBrowse
                                                                                                                                • 172.235.37.241
                                                                                                                                Bank_Statement.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                • 2.18.98.164
                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                3b5074b1b5d032e5620f69f9f700ff0ePDFizer_no_update.msiGet hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                f40b7a79ed8433ee4d221f3553f422e9.ps1Get hashmaliciousLummaC StealerBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                DHL-Documento de env#U00edo.exeGet hashmaliciousDarkCloudBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                file.exeGet hashmaliciousFallen Miner, XmrigBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                nude.jpg.exe.bin.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                nude.jpg.exe.bin.exeGet hashmaliciousDiscord RatBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                XClient.exe.bin.exeGet hashmaliciousXWormBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                NavaioSecurityTest (2).exeGet hashmaliciousUnknownBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                notyhkkadaw.exe1.exeGet hashmaliciousLummaC Stealer, XmrigBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                Arly.exe1.exeGet hashmaliciousLummaC Stealer, XmrigBrowse
                                                                                                                                • 169.150.247.38
                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                C:\Users\user\AppData\Local\Temp\MSIC188.tmpPDFizer_no_update.msiGet hashmaliciousUnknownBrowse
                                                                                                                                  Let's_20Compress.exeGet hashmaliciousUnknownBrowse
                                                                                                                                    recibatt- 533152.msiGet hashmaliciousUnknownBrowse
                                                                                                                                      SecuriteInfo.com.BScope.Trojan.Agentb.20481.11202.msiGet hashmaliciousUnknownBrowse
                                                                                                                                        NF84.jsGet hashmaliciousUnknownBrowse
                                                                                                                                          nf963-5d-qns6-w812.msiGet hashmaliciousUnknownBrowse
                                                                                                                                            ScreenBeam_Conference_Windows_1.0.5.9.msiGet hashmaliciousUnknownBrowse
                                                                                                                                              1eSOBjseu2.msiGet hashmaliciousCobaltStrikeBrowse
                                                                                                                                                2024.0198840 298135.msiGet hashmaliciousUnknownBrowse
                                                                                                                                                  hForm.0198840 739798.msiGet hashmaliciousUnknownBrowse
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):659312
                                                                                                                                                    Entropy (8bit):6.61237700938228
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:Zb/iY94rNLit8tpySmt42WyXlQwDIA0iYkWTkU59s+M+bxh:RiY94rNLiyE42Wy1Qw8YQTkU5q+M+bj
                                                                                                                                                    MD5:EA191CC388D407A442772B151E965162
                                                                                                                                                    SHA1:FE8C3A0B0240E3041969EA3998DFAC491246E644
                                                                                                                                                    SHA-256:ABD827D2A191549C29ADBEAB37141ECA14DB52767F530A845B5AD0536CF2D463
                                                                                                                                                    SHA-512:7A16FFB6D57A489AFDECED4BAFE313D43B0A12D40C325AAC94FE898CA77B1C531E82F7822157B4E77649C540DF7D8902764E52429810DECD02505351EE8300EE
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...@IXOS.@.....@.dmZ.@.....@.....@.....@.....@.....@......&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}..PDFizer..PDFizer_no_update.msi.@.....@.....@.....@......app.exe..&.{E208B6F4-6C16-4D61-B0F4-A4B9E318FAE8}.....@.....@.....@.....@.......@.....@.....@.......@......PDFizer......Rollback..Rolling back action:....RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{254C838C-98A9-4C30-994B-35D38E8B1550}&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}.@......&.{8442C7F6-AA55-4A80-84DC-AAF0B98EE300}&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}.@......&.{C65B17F1-F062-400A-A474-DA5AA80A822D}&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}.@......&.{1920ABFC-2501-4D4A-8B32-8A8E7F1998DC}&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}.@......&.{14F78F97-EA3A-4C45-A622-7DF6A8D86CCB}&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}.@......&.{CB27F34A-D325-4C6C-871C-65CD6E8424FE}&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}.@......&.{6ABF3F76-FC8A-41DB-B565-BB01D8673FB1}&.{70C01104-9C1A-
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:CSV text
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):651
                                                                                                                                                    Entropy (8bit):5.343677015075984
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:Q3La/KDLI4MWuPTAOKbbDLI4MWuPJKAVKhaOK9eDLI4MNJK9P/JNTK9yiv:ML9E4KlKDE4KhKiKhPKIE4oKNzKoM
                                                                                                                                                    MD5:7EEF860682F76EC7D541A8C1A3494E3D
                                                                                                                                                    SHA1:58D759A845D2D961A5430E429EF777E60C48C87E
                                                                                                                                                    SHA-256:65E958955AC5DBB7D7AD573EB4BB36BFF4A1DC52DD16CF79A5F7A0FA347727F1
                                                                                                                                                    SHA-512:BF7767D55F624B8404240953A726AA616D0CE60EC1B3027710B919D6838EFF7281A79B49B22AB8B065D8CA921EF4D09017A0991CB4A21DAF09B3B43E6698CB04
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):42819
                                                                                                                                                    Entropy (8bit):6.084073709594317
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:mMkbJ6eg6KzhXRLtkCKt5iLmZxpobQKVyPOwZbsamC1oKwWE7RTupzKscDX//Nq2:mMk16zRRSCKdRsamIoKoRTuiB
                                                                                                                                                    MD5:81AE348E539E4D86413705C0DB2144F3
                                                                                                                                                    SHA1:BDD4EE2609A69C048789A40BF238894EEA8D95A0
                                                                                                                                                    SHA-256:5592E2DE2C9464C9A3D4093AEB8A7269CF44670F238E879E0318CD8BED945C7C
                                                                                                                                                    SHA-512:4D0C8CD5236921BF22BE5B5B4A28BAD5B2250B3604A120812225F2727E993C67E19F4F69A88AAD21DA97BF69E79F1789C8BE7849F2FBF4F7075DC97F98767CF7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm3rXSyzABnWdKBG+Ijlx7hEE4QTzo+AB6fnDLLJBpo7PKv8Ob367/KjUg
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):42742
                                                                                                                                                    Entropy (8bit):6.084192277339455
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:mMkbJ6eg6KzhXRLtkVXt5iLmZdpobQKVyPOwZbsamC1oKwWE7RTupzKscDX//Nq2:mMk16zRRSVXVRsamIoKoRTuiB
                                                                                                                                                    MD5:9C7381F0DD38E79E2F1C6B60BDE2C32E
                                                                                                                                                    SHA1:FA61AFF9D3181CC1BAE67B1FFE832340911C1925
                                                                                                                                                    SHA-256:9FCC143BF06DD55B6846ED2B91955323D415D237FDC6BBE710E66A6162C0D089
                                                                                                                                                    SHA-512:AFF7550551606FD5FD80AE5DE8F400E8F1CAD618925742E274D2BD801C88A277B14EACC36E02B5CAFA359D18520D81E7314834C9917DAB90FDB0EAE279775A9F
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm3rXSyzABnWdKBG+Ijlx7hEE4QTzo+AB6fnDLLJBpo7PKv8Ob367/KjUg
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):107893
                                                                                                                                                    Entropy (8bit):4.64013178578393
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7B:fwUQC5VwBIiElEd2K57P7B
                                                                                                                                                    MD5:4534E13AE50BA33B19D3D3C5792108BD
                                                                                                                                                    SHA1:673B117572D45A867B2EDA0B137273EE571B9068
                                                                                                                                                    SHA-256:C1DF2A2CC038B6895860E1F5CE7128393EF389A59075392521C93A05FC2EEC43
                                                                                                                                                    SHA-512:A1F2833BD20E4163332035CD6D695AA8F2342D0C7B1E0F92659DB40DEF57F1CB7B6BFAFAAECC7DB6F78FD3C6B9340C9BEAC94AD69709CF2BF3B6D897EAB271E7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):107893
                                                                                                                                                    Entropy (8bit):4.64013178578393
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:B/lv4EsQMNeQ9s5VwB34PsiaR+tjvYArQdW+Iuh57P7B:fwUQC5VwBIiElEd2K57P7B
                                                                                                                                                    MD5:4534E13AE50BA33B19D3D3C5792108BD
                                                                                                                                                    SHA1:673B117572D45A867B2EDA0B137273EE571B9068
                                                                                                                                                    SHA-256:C1DF2A2CC038B6895860E1F5CE7128393EF389A59075392521C93A05FC2EEC43
                                                                                                                                                    SHA-512:A1F2833BD20E4163332035CD6D695AA8F2342D0C7B1E0F92659DB40DEF57F1CB7B6BFAFAAECC7DB6F78FD3C6B9340C9BEAC94AD69709CF2BF3B6D897EAB271E7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"sites":[{"url":"24video.be"},{"url":"7dnifutbol.bg"},{"url":"6tv.dk"},{"url":"9kefa.com"},{"url":"aculpaedoslb.blogspot.pt"},{"url":"aek-live.gr"},{"url":"arcadepunk.co.uk"},{"url":"acidimg.cc"},{"url":"aazah.com"},{"url":"allehensbeverwijk.nl"},{"url":"amateurgonewild.org"},{"url":"aindasoudotempo.blogspot.com"},{"url":"anorthosis365.com"},{"url":"autoreview.bg"},{"url":"alivefoot.us"},{"url":"arbitro10.com"},{"url":"allhard.org"},{"url":"babesnude.info"},{"url":"aysel.today"},{"url":"animepornx.com"},{"url":"bahisideal20.com"},{"url":"analyseindustrie.nl"},{"url":"bahis10line.org"},{"url":"apoel365.net"},{"url":"bahissitelerisikayetleri.com"},{"url":"bambusratte.com"},{"url":"banzaj.pl"},{"url":"barlevegas.com"},{"url":"baston.info"},{"url":"atomcurve.com"},{"url":"atascadocherba.com"},{"url":"astrologer.gr"},{"url":"adultpicz.com"},{"url":"alleporno.com"},{"url":"beaver-tube.com"},{"url":"beachbabes.info"},{"url":"bearworldmagazine.com"},{"url":"bebegimdensonra.com"},{"url":"autoy
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3::
                                                                                                                                                    MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
                                                                                                                                                    SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
                                                                                                                                                    SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
                                                                                                                                                    SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3::
                                                                                                                                                    MD5:B5CFA9D6C8FEBD618F91AC2843D50A1C
                                                                                                                                                    SHA1:2BCCBD2F38F15C13EB7D5A89FD9D85F595E23BC3
                                                                                                                                                    SHA-256:BB9F8DF61474D25E71FA00722318CD387396CA1736605E1248821CC0DE3D3AF8
                                                                                                                                                    SHA-512:BD273BF4E10ED6E305ECB7B781CB065545FCE9BE9F1E2968DF22C3A98F82D719855AAFE5FF303D14EA623A5C55E51E924E10033A92A7A6B07725D7E9692B74F5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                    Entropy (8bit):0.04634071404290079
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:0qCvFy08YiNtmNnOAQzYUJPi6VBK/72qtX3egIGYohvJNELIPvmRQczMgIHn8y0d:0qYFy0Mt2YYRFhxrO8gO08T2RGOD
                                                                                                                                                    MD5:0920BB711E361EFEE78BDD6C6CE6D17C
                                                                                                                                                    SHA1:AB43386F1E5ECE16C5B686741FF31A450D7CED18
                                                                                                                                                    SHA-256:F91D5851BF29CF84EFACAA2EF1F4BEDC4C4A79F67A2046DE661CC32193FF0284
                                                                                                                                                    SHA-512:704D25A9BDB486977ACBC4219D471C902193019763E789A7261A0C700E484249C980238F2150CF078C44D0F9292F989FF6CC3FEB23542F3542CBD7DF8DC2043C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...@..@...@.....C.].....@................f...V..............`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?......".udatul20,1(.0..8..B.......2.:.M..BU..Be...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@..............!......................w..U.>.........."....."...24.."."h5wmA/c+VK/+HCTGwU1TrwNY52XBTo9O05htSkjnNRA="*.:............B)..1.3.177.11.. .*.RegKeyNotFound2.windowsR...Z...V.-../Q@..$...SF@.......Y@.......4@.......Y@........?........?.........................Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......4@.......Y@................Y@.......Y@.......Y@........?........?2................ .2................. .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4194304
                                                                                                                                                    Entropy (8bit):0.4574537886521642
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:3s/fcKOZGrwnaHYwbv9jo8cql6M45aHf:krwaVr9j5
                                                                                                                                                    MD5:8A33CF3F8B6A61513825F67E51364594
                                                                                                                                                    SHA1:FCA0FFA379FD9E953C762419C7C59959162C8EF7
                                                                                                                                                    SHA-256:0F536B92CC5ADD25596751260A38439A9556B338A4651B7331620DEAD2B0BE0C
                                                                                                                                                    SHA-512:A7834F936E39FE0DCA590D75207D37EFAED1F2DFC0226AEC83A3E57F5AD5DA2F196DB9E5CA8B2A978F4B122CEEB15F9469850B218FF3E2271CA330BDBB1B7061
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...@..@...@.....C.].....@................M...M..............`... ...i.y.........BrowserMetrics......i.y..Yd. .......A...................v.0.....UV&K.k<................UV&K.k<................UMA.PersistentHistograms.InitResult.....8...i.y.[".................................................i.y.Pq.30..............117.0.2045.47-64..".en-GB*...Windows NT..10.0.190452l..x86_64..?......".udatul20,1(.0..8..B.......2.:.M..BU..Be...?j...GenuineIntel... .. ..........x86_64...J....k..^o..J..l.zL.^o..J....\.^o..J.....f.^o..J....?.^o..P.Z...b.INBXj....... .8.@..............!......................w..U?:K..>.........."....."...24.."."h5wmA/c+VK/+HCTGwU1TrwNY52XBTo9O05htSkjnNRA="*.:............B)..1.3.177.11.. .*.RegKeyNotFound2.windowsR...Z...V.-../Q@..$...SF@.......Y@.......4@.......Y@........?........?.........................Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......Y@.......4@.......Y@................Y@.......Y@.......Y@........?........?2................ .`2..........I.....
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):280
                                                                                                                                                    Entropy (8bit):4.195531555605597
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:FiWWltlMpKoKuNoDZbkDURSHxig5ABVP/Sh/JzvNKIUBUhX9USWXQPD1:o1GVKCoD4Hxi2ABVsJDZYeulX+
                                                                                                                                                    MD5:CB96875405C5F49B31935D6A2C98BDB4
                                                                                                                                                    SHA1:960AB5C41162A5424187E1834F09D7722AD5313F
                                                                                                                                                    SHA-256:9511F9283D8CCF8FB16DA5194781EA5B9819EEFD5404AE6004879D8C65F271E0
                                                                                                                                                    SHA-512:A08DE7230019B5FED971DFFEAFFA9F75A4344E775474ECE079D3962089325996808C3C9FD75FEA026E0296D6CB03B651F648D8CA1519FC88CC56CD5E609B2D12
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:sdPC.........................TJ.[Y....."h5wmA/c+VK/+HCTGwU1TrwNY52XBTo9O05htSkjnNRA="..................................................................................47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=....................ecadf109-1d88-4bd2-8ebf-85346832b43e............
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):13191
                                                                                                                                                    Entropy (8bit):5.268213104878489
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRJ99QTryDigabatSuygsjUIa3414bka3I88bV+FGaBQA47Oyf7NIoPqYJ:stRPGKSuLsjUXsJbG3BQx7Xf7NIO
                                                                                                                                                    MD5:2203A49234B92CC001CEE6A271062A90
                                                                                                                                                    SHA1:AB889B7B6DA74291A10F1D65D8674F0815E5A48D
                                                                                                                                                    SHA-256:52A1A0B32511BFE5E0791B0481ACD061463B129B17318910CB72458AF2EBD324
                                                                                                                                                    SHA-512:73F1D749497AB54716CBEBDA49E22962FAB387B3F161A340806C5800B439747005AF211C21A637CFF3005810B6A92A03EB7F369B49F2D8C0D668081B36A66ADC
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):25012
                                                                                                                                                    Entropy (8bit):5.566856295147486
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:sXI4xjWPRBfnu8F1+UoAYDCx9Tuqh0VfUC9xbog/OV1UX4IrwOYpctuV:sXI4xjWPRBfnuu1jaYY4ZO7tC
                                                                                                                                                    MD5:B81A0E4E204628C38C3388DE1147F8D3
                                                                                                                                                    SHA1:B9F4B1BCA119AFEFA789F2F92609E12D8867C802
                                                                                                                                                    SHA-256:827BD96D6FBD94B1EBB43ECFAB527E2EBBBA7C92C11D584F407F9C44BA7BE987
                                                                                                                                                    SHA-512:91F527F04687B9D1E8D020E48E093055DA4E117D34DF2E349E44741CD819D95F99D605FACD74AB6A3184E4266143559042E881689EF95770DA30BCC185CEED41
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13386357483832412","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13386357483832412","location":5,"ma
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):13191
                                                                                                                                                    Entropy (8bit):5.268210883583256
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRJ99QTryDigabatSuygsjUIa3414bka3I88bV+FGaBQA48Oyf7NIoPqYJ:stRPGKSuLsjUXsJbG3BQx8Xf7NIO
                                                                                                                                                    MD5:C1D20B976679AF37934F6C1AAF6B7E6B
                                                                                                                                                    SHA1:D81BF309253281854F43CD1DD699F770D9BA0642
                                                                                                                                                    SHA-256:45BD1C674E20DBFC3FE6C9184F506E2A44E8611FCCB9A8401CC417F54B7D10B1
                                                                                                                                                    SHA-512:138F46976A6F55428A479DC2D5E3FA6F3219A2C8843DC85FB25C7B7E81FE30DE24247811B8E6C95E6211D1D391EA01E7111F78FAD2F3C6DFA2AEC8EE905CF89C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16
                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):33
                                                                                                                                                    Entropy (8bit):3.5394429593752084
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:iWstvhYNrkUn:iptAd
                                                                                                                                                    MD5:F27314DD366903BBC6141EAE524B0FDE
                                                                                                                                                    SHA1:4714D4A11C53CF4258C3A0246B98E5F5A01FBC12
                                                                                                                                                    SHA-256:68C7AD234755B9EDB06832A084D092660970C89A7305E0C47D327B6AC50DD898
                                                                                                                                                    SHA-512:07A0D529D9458DE5E46385F2A9D77E0987567BA908B53DDB1F83D40D99A72E6B2E3586B9F79C2264A83422C4E7FC6559CAC029A6F969F793F7407212BB3ECD51
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...m.................DB_VERSION.1
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16
                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):309
                                                                                                                                                    Entropy (8bit):5.266750188299276
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPb5QlFm81CHhJ23oH+Tcwtp3hBtB2KLl4PbN+q2PCHhJ23oH+Tcwtp3hBWsIg:7GscQYebp3dFLCkvBYebp3eFUv
                                                                                                                                                    MD5:06442988A4FBD36A71508AE5452CBBB4
                                                                                                                                                    SHA1:97A6BEAAAF2A88A6C3369DC3D71B37381D64AF93
                                                                                                                                                    SHA-256:E54E0566606F97D98099C1994A61C11A390E18FF71596AADA25480C7A6CAAED2
                                                                                                                                                    SHA-512:652729C61EDA168F768FB5D5AEB6F60B8A076C5DE2525708ECCF3D00D2D5D14DFA66C4977D69846DF1ADD75D83DFA2CA3230FB5874E518486C1C1E626460D689
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:09.759 1e98 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db since it was missing..2025/03/13-12:38:09.802 1e98 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\AdPlatform/auto_show_data.db/MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41
                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):1764710
                                                                                                                                                    Entropy (8bit):5.138096528276863
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24576:hKPOfKfgXaHbMhFQlmADAbpENUdifYOBHbc2r:hKWfqJmcx
                                                                                                                                                    MD5:537C72F84DFB4E2B4F35D35CB43ED360
                                                                                                                                                    SHA1:29F4F33436278EEE9BFF958B542846FE8E741C06
                                                                                                                                                    SHA-256:15BE8E4A364E1DB1627A50C2E5CAC0E131BDFF65771B294F963BC3EF54BC2F6A
                                                                                                                                                    SHA-512:D8489D02FBDBD663257D28F76989B11993B0B2BD163C4436468CC379796914830714AF6622C1361EAF7706D7A3C3F0EDA512A3BC90E1A53BE2148E9175CB417D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...m.................DB_VERSION.1.Go..................QUERY_TIMESTAMP:arbitration_priority_list4.*.*.13340967444415546.$QUERY:arbitration_priority_list4.*.*..[{"name":"arbitration_priority_list","url":"https://edgeassetservice.azureedge.net/assets/arbitration_priority_list/4.0.5/asset?sv=2017-07-29&sr=c&sig=NtPyTqjbjPElpw2mWa%2FwOk1no4JFJEK8%2BwO4xQdDJO4%3D&st=2021-01-01T00%3A00%3A00Z&se=2023-12-30T00%3A00%3A00Z&sp=r&assetgroup=ArbitrationService","version":{"major":4,"minor":0,"patch":5},"hash":"N0MkrPHaUyfTgQSPaiVpHemLMcVgqoPh/xUYLZyXayg=","size":11749}]...................'ASSET_VERSION:arbitration_priority_list.4.0.5..ASSET:arbitration_priority_list.[{. "configVersion": 32,. "PrivilegedExperiences": [. "ShorelinePrivilegedExperienceID",. "SHOPPING_AUTO_SHOW_COUPONS_CHECKOUT",. "SHOPPING_AUTO_SHOW_LOWER_PRICE_FOUND",. "SHOPPING_AUTO_SHOW_BING_SEARCH",. "SHOPPING_AUTO_SHOW_REBATES",. "SHOPPING_AUTO_SHOW_REBATES_CONFIRMATION",. "SHOPPING_AUTO_SHOW_REBATES_DEACTI
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):336
                                                                                                                                                    Entropy (8bit):5.165969052395931
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPb7Sv+q2PCHhJ23oH+Tcwt9Eh1tIFUtoPb7Sw0ZmwCPb52Od3VkwOCHhJ23of:7G/TvBYeb9Eh16FUto/b0/CJ56Yeb9Er
                                                                                                                                                    MD5:0F214927AF8F23D563C18BAA301E0DA7
                                                                                                                                                    SHA1:F239B53A9C442DCEFD89BFD5A4703C639BABE303
                                                                                                                                                    SHA-256:FAA18AAA226438863531524042C4A4C9B9F5D0B226D68C223065E3AE421B068C
                                                                                                                                                    SHA-512:2DCE6F33D9F6A428F2A634CA9ADAA1399B145BC314462327A610DB0EADB632BFD72B78362CFD7EAE4271185037D08F8FF53DEB01744E26D43F34A34D5B99EAEF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:09.575 23b8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.2025/03/13-12:38:09.577 23b8 Recovering log #3.2025/03/13-12:38:09.709 23b8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):336
                                                                                                                                                    Entropy (8bit):5.165969052395931
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPb7Sv+q2PCHhJ23oH+Tcwt9Eh1tIFUtoPb7Sw0ZmwCPb52Od3VkwOCHhJ23of:7G/TvBYeb9Eh16FUto/b0/CJ56Yeb9Er
                                                                                                                                                    MD5:0F214927AF8F23D563C18BAA301E0DA7
                                                                                                                                                    SHA1:F239B53A9C442DCEFD89BFD5A4703C639BABE303
                                                                                                                                                    SHA-256:FAA18AAA226438863531524042C4A4C9B9F5D0B226D68C223065E3AE421B068C
                                                                                                                                                    SHA-512:2DCE6F33D9F6A428F2A634CA9ADAA1399B145BC314462327A610DB0EADB632BFD72B78362CFD7EAE4271185037D08F8FF53DEB01744E26D43F34A34D5B99EAEF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:09.575 23b8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/MANIFEST-000001.2025/03/13-12:38:09.577 23b8 Recovering log #3.2025/03/13-12:38:09.709 23b8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Asset Store\assets.db/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x3, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):28672
                                                                                                                                                    Entropy (8bit):0.4661690105291414
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:TLi5YFQq3qh7z3WMYziciNW9WkZ96UwOfB/8:TouQq3qh7z3bY2LNW9WMcUvBk
                                                                                                                                                    MD5:D97845F902DB03AC2428787A10279720
                                                                                                                                                    SHA1:8FB39DF617F3E68A574BCB29FFFFF8DEF3337BC8
                                                                                                                                                    SHA-256:F5FA4FA138BF3DE2C48357F2F0D841B1EDADB1EA16E3A0D77E42211D98D1748B
                                                                                                                                                    SHA-512:3CA26FB48788C8275173851D10D8B59731B58B91DA95BAFA7C1938DFBF45B55C7F2E4927113E4BDABDA9F70A00CA847B4C9754CB1672839FCED7FA2437EAC1E9
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g.....8...n................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 5, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 5
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):10240
                                                                                                                                                    Entropy (8bit):0.8708334089814068
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:LBtW4mqsmvEFUU30dZV3lY7+YNbr1dj3BzA2ycFUxOUDaazMvbKGxiTUwZ79GV:LLaqEt30J2NbDjfy6UOYMvbKGxjgm
                                                                                                                                                    MD5:92F9F7F28AB4823C874D79EDF2F582DE
                                                                                                                                                    SHA1:2D4F1B04C314C79D76B7FF3F50056ECA517C338B
                                                                                                                                                    SHA-256:6318FCD9A092D1F5B30EBD9FB6AEC30B1AEBD241DC15FE1EEED3B501571DA3C7
                                                                                                                                                    SHA-512:86FEF0E05F871A166C3FAB123B0A4B95870DCCECBE20B767AF4BDFD99653184BBBFE4CE1EDF17208B7700C969B65B8166EE264287B613641E7FDD55A6C09E6D4
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...v... .. .....M....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):668385
                                                                                                                                                    Entropy (8bit):6.015455092865534
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:OT7/oc9h6AFZdawJqJXj6VQnGzMQ+/RNCfvkRJcMryXsHiZa:oMzSawJq3nGzW/RNgvE
                                                                                                                                                    MD5:EE597CEFEA50E5AA753FE8DC76C1D6AB
                                                                                                                                                    SHA1:CA057AC262065CE99A6F41041DB0A52F6322F4CB
                                                                                                                                                    SHA-256:16B0769264F3BFECD96D01ADD0772BDF34F931302A72FB06EFAC1B327ED6AA1A
                                                                                                                                                    SHA-512:068B3E217467D9472089A2D35FD8F5BD6C6234EDAAE1781E8B42FEB7A4A4A90E21CE79E5025489C01E5E7E76FBBB19E3D7AD9632874ED3E8779E2EB62FDD834E
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...m.................DB_VERSION.1=9..................BLOOM_FILTER:..({"numberOfHashFunctions":8,"shiftBase":6,"bloomFilterArraySize":3958873,"primeBases":[5381,5381,5381,5381],"supportedDomains":"JkxozzrWv6SFUdqNSjGK0ChWeaVwtDF8u9UOZVoMoglBJMhUBBbhP8E4ABmwu4czGEf9rvoKLfFkhny30mtSWV0vA2U/aEsoMoQgRA2lK6kFs4gP8/B/otYL7hNyILBJZeP8gkt4JyoC7uuyMHwbQlWgH9bePmpSiwEkWv9ngHVX7Hqz4C6SyTAXCN0IDfMIqjGrf5QyaIR7NbfoAySSKQURiqIMANFAHHJ5H/X2arGoNbK8YqWxEo6AVZRvEFqtVhNcdiu4+8pl+n2MQfJUs1N4UhjwwP7SEsP5Vhw+SjFRtwxjzseWTN2I6ncUhIrFVNoe2/Sl56nbQrU4fYs+WCgkp6VKXYfWILm1YzwUrOJqcZW1JNuEZ/MnO1PC4t7Bhjf2tE7NNQn8nweg8GwD0KWDKzflWQUZCLUVbhYux5C4+CT2DfFChmOIL3GHp5vL58gMGoAYGj1LdOLRQb0K+2IgU5SNmVzRqV5iijMhYZh2qcEZmNrafuOAwpJsQJUz1NmdPhILhDz9cTHkR/RgCBIivIfV4ZVBZzfkl7ICHHNpJyFE72jNIdYa9ZlogR6YaXD36OfDYV53fIPrF4PzJ+n2TSa59luK76cz4ZLe8To0kc5wapJ9jX5mpQnItrQoEX0ckuoK0fXZtoPd4VBzBXz4II4NgUbxtXYwYfYW1kGkN2eMUAhCgfa+o7JJwSabN2xdUjZjDKxlMDv8cQomqGpWHZ8Y5DfWBxlr9KE6wrZezq0eWWEokf/Cv1BNj1dOuv0JQWDsZITcMOG2s7HTZuFdqIbn3dDcYud
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):142
                                                                                                                                                    Entropy (8bit):4.9878542637371925
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:zkm//38E28xp4m3rscUSRUleF+jlf+nETPxpK2x7L8KFPSEnQzVfSn:zf38D8xSEsIRgB+n0PxEWHFfnQzVfSn
                                                                                                                                                    MD5:9BEFB99C8A836D8A9C809AA9A31A00D3
                                                                                                                                                    SHA1:8954FEC9FF4B83B563B8F2EE842A634DC0B38ED8
                                                                                                                                                    SHA-256:B0775F970304027029D6E73643985A936B5BE38BB916110D2D38C44231A09D13
                                                                                                                                                    SHA-512:00F28088CCABF860F20EAEB72AB46E6DABF7BE46B87A61AD3C0E122C0584A67D4BADABC6C6D14EABEE4C835331718135F09B79126965FF1B4AE7C3448E0E5741
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:7.o.9................BLOOM_FILTER_EXPIRY_TIME:.1741970292.376405.E.SG................BLOOM_FILTER_LAST_MODIFIED:.Thu, 13 Mar 2025 14:50:27 GMT
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):668353
                                                                                                                                                    Entropy (8bit):6.0149125817602185
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:xTk/oc9hxOWZdawgqJsj6YnnGVaA+BUNHfvkRJc/rytswieo:l7mhawgqqnGVuBUN/v3
                                                                                                                                                    MD5:D685FF9C63A884445DF0812B339AA544
                                                                                                                                                    SHA1:4C2FF65D4333D5849E0D4D8EF2DC5CB968E797C4
                                                                                                                                                    SHA-256:7C15AB114B31E71218DFBFD5AE5FB6CFF28D70A337BFDC5909237A7CF74A7D90
                                                                                                                                                    SHA-512:1FCEDB3D000F6CA4C719DF9D753155B5E89B6CE051DC67CCE421C7E2D0C1F7BC4E9A1CDF3AB15659A34569F6E4B5F7684C985679D938A33D00129FFABD85E46B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:....(BLOOM_FILTER:........{"numberOfHashFunctions":8,"shiftBase":6,"bloomFilterArraySize":3958873,"primeBases":[5381,5381,5381,5381],"supportedDomains":"JkxozzrWv6SFUdqNSjGK0ChWeaVwtDF8u9UOZVoMoglBJMhUBBbhP8E4ABmwu4czGEf9rvoKLfFkhny30mtSWV0vA2U/aEsoMoQgRA2lK6kFs4gP8/B/otYL7hNyILBJZeP8gkt4JyoC7uuyMHwbQlWgH9bePmpSiwEkWv9ngHVX7Hqz4C6SyTAXCN0IDfMIqjGrf5QyaIR7NbfoAySSKQURiqIMANFAHHJ5H/X2arGoNbK8YqWxEo6AVZRvEFqtVhNcdiu4+8pl+n2MQfJUs1N4UhjwwP7SEsP5Vhw+SjFRtwxjzseWTN2I6ncUhIrFVNoe2/Sl56nbQrU4fYs+WCgkp6VKXYfWILm1YzwUrOJqcZW1JNuEZ/MnO1PC4t7Bhjf2tE7NNQn8nweg8GwD0KWDKzflWQUZCLUVbhYux5C4+CT2DfFChmOIL3GHp5vL58gMGoAYGj1LdOLRQb0K+2IgU5SNmVzRqV5iijMhYZh2qcEZmNrafuOAwpJsQJUz1NmdPhILhDz9cTHkR/RgCBIivIfV4ZVBZzfkl7ICHHNpJyFE72jNIdYa9ZlogR6YaXD36OfDYV53fIPrF4PzJ+n2TSa59luK76cz4ZLe8To0kc5wapJ9jX5mpQnItrQoEX0ckuoK0fXZtoPd4VBzBXz4II4NgUbxtXYwYfYW1kGkN2eMUAhCgfa+o7JJwSabN2xdUjZjDKxlMDv8cQomqGpWHZ8Y5DfWBxlr9KE6wrZezq0eWWEokf/Cv1BNj1dOuv0JQWDsZITcMOG2s7HTZuFdqIbn3dDcYudRi0oz2nTzzvB2sVaO5K426HX0lVZgkcUQpKv2RBeAbcK
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):512
                                                                                                                                                    Entropy (8bit):5.196760348274679
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7GsvBYebn9GFUtoD1/Cj56Yebn95Z9QN0bf0C0PKfu02h:77BYeb9ig+66Yeb9zeth
                                                                                                                                                    MD5:49BCC4D12C0ECD6747B746EFED5B435B
                                                                                                                                                    SHA1:6960B24E45E8352B380AF6DB3C17509E589A9E78
                                                                                                                                                    SHA-256:26B888A59ADC62CB56E5FCFFE99D611971EB3FEBF7CB793659C1503A10D36B87
                                                                                                                                                    SHA-512:F183584D670EECC3C4CFD274B70787939629DB74006666BB7F89733A872BD7AD33A9155C9F73606842CF5159D5093D5A9D9B770296166D58FC48F81DA05BC737
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.839 1ea0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.2025/03/13-12:38:03.840 1ea0 Recovering log #3.2025/03/13-12:38:03.840 1ea0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/000003.log .2025/03/13-12:38:12.403 1e9c Level-0 table #5: started.2025/03/13-12:38:12.428 1e9c Level-0 table #5: 668353 bytes OK.2025/03/13-12:38:12.430 1e9c Delete type=0 #3.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):512
                                                                                                                                                    Entropy (8bit):5.196760348274679
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7GsvBYebn9GFUtoD1/Cj56Yebn95Z9QN0bf0C0PKfu02h:77BYeb9ig+66Yeb9zeth
                                                                                                                                                    MD5:49BCC4D12C0ECD6747B746EFED5B435B
                                                                                                                                                    SHA1:6960B24E45E8352B380AF6DB3C17509E589A9E78
                                                                                                                                                    SHA-256:26B888A59ADC62CB56E5FCFFE99D611971EB3FEBF7CB793659C1503A10D36B87
                                                                                                                                                    SHA-512:F183584D670EECC3C4CFD274B70787939629DB74006666BB7F89733A872BD7AD33A9155C9F73606842CF5159D5093D5A9D9B770296166D58FC48F81DA05BC737
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.839 1ea0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/MANIFEST-000001.2025/03/13-12:38:03.840 1ea0 Recovering log #3.2025/03/13-12:38:03.840 1ea0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EdgeCoupons/coupons_data.db/000003.log .2025/03/13-12:38:12.403 1e9c Level-0 table #5: started.2025/03/13-12:38:12.428 1e9c Level-0 table #5: 668353 bytes OK.2025/03/13-12:38:12.430 1e9c Delete type=0 #3.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):103
                                                                                                                                                    Entropy (8bit):5.267898014713841
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjRG4uThinh2TxFxN3erkEtl:scoBY7jRzuQh2TxFDkHl
                                                                                                                                                    MD5:F9EC2C3DE46ACF7B603428C3F20BE45D
                                                                                                                                                    SHA1:D6668C3BADCC552884E9A2715FCAB05CF89A7CDD
                                                                                                                                                    SHA-256:45F3CCC6842BDE04DD5FFBB3CFC39A46BE303D9CEA1B145BEC8342FDA8FECAB9
                                                                                                                                                    SHA-512:B91706B100E201367819E8F521BBD394F186164E31D6C6B2A7E1F2CF1467790872FCACF2D856791E0E68F3CA8732D2FDA71AFD29D75C7516F5720D4723D95473
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......-.#.7...............(.BLOOM_FILTER:.........DB_VERSION........
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 5, cookie 0x5, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):20480
                                                                                                                                                    Entropy (8bit):0.6131475008605264
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:TLapR+DDNzWjJ0npnyXKUO8+j9jopDrmL:TO8D4jJ/6Up+x2I
                                                                                                                                                    MD5:369D9DE20BB167DF88ADA26BEAC5FF1B
                                                                                                                                                    SHA1:11D1710BB70574B4D086080F5C63A20C91C390BF
                                                                                                                                                    SHA-256:8921A8DBACA9787512EC3C870B49D1753855F2BD7EF8DC35F01F04A5E202564D
                                                                                                                                                    SHA-512:30C3BD1E5D27CAC35F43B9E3D972667493E30ADD549D298EBDED436FC8E1012589539E23D4F663FB72FE2CFB9FEE6708D689371478C36E629ECABBF0773857D6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j...%.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16
                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):375520
                                                                                                                                                    Entropy (8bit):5.354120173584873
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:ZA/imBpx6WdPSxKWcHu5MURacq49QxxPnyEndBuHltBfdK5WNbsVEziP/CfXtLPz:ZFdMyq49tEndBuHltBfdK5WNbsVEziPU
                                                                                                                                                    MD5:31911ACB6587CCF277C236FB5395D9BE
                                                                                                                                                    SHA1:1CB51ACC3C280F0B86BE6319F775124086E78825
                                                                                                                                                    SHA-256:131E01A6F8066740642975299EDD68EAA25DB0C047ED5F3EFEDE8071FE1B676C
                                                                                                                                                    SHA-512:294434B6023AEDA5C2BDC0777B0954CA6305B7F7475603DE0868C933621B1C69C01B4A009BDAB7663CA673D2EBC4FAA5365172BC86F4D22CF66A01EF6BD66A60
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...m.................DB_VERSION.1.L.Hq...............&QUERY_TIMESTAMP:domains_config_gz2.*.*.13386357493061755..QUERY:domains_config_gz2.*.*..[{"name":"domains_config_gz","url":"https://edgeassetservice.azureedge.net/assets/domains_config_gz/2.8.76/asset?assetgroup=EntityExtractionDomainsConfig","version":{"major":2,"minor":8,"patch":76},"hash":"78Xsq/1H+MXv88uuTT1Rx79Nu2ryKVXh2J6ZzLZd38w=","size":374872}]..*.`~...............ASSET_VERSION:domains_config_gz.2.8.76..ASSET:domains_config_gz...{"config": {"token_limit": 1600, "page_cutoff": 4320, "default_locale_map": {"bg": "bg-bg", "bs": "bs-ba", "el": "el-gr", "en": "en-us", "es": "es-mx", "et": "et-ee", "cs": "cs-cz", "da": "da-dk", "de": "de-de", "fa": "fa-ir", "fi": "fi-fi", "fr": "fr-fr", "he": "he-il", "hr": "hr-hr", "hu": "hu-hu", "id": "id-id", "is": "is-is", "it": "it-it", "ja": "ja-jp", "ko": "ko-kr", "lv": "lv-lv", "lt": "lt-lt", "mk": "mk-mk", "nl": "nl-nl", "nb": "nb-no", "no": "no-no", "pl": "pl-pl", "pt": "pt-pt", "ro": "
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16
                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):311
                                                                                                                                                    Entropy (8bit):5.211891661071314
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPb7WX44M1CHhJ23oH+Tcwtk2WwnvB2KLl4Pb5GIq2PCHhJ23oH+Tcwtk2Wwnp:7G/Q44AYebkxwnvFLCIIvBYebkxwnQF2
                                                                                                                                                    MD5:CC3A8FEA69156D998A0C06A775252F9B
                                                                                                                                                    SHA1:A62EA7997EDC612D8BEF060BF3819926DAE9662D
                                                                                                                                                    SHA-256:1B1638C8C194CD06BDFB548020A5FBCB3B2DBE6AEB77DDEE27A2AE40D0D9E7A1
                                                                                                                                                    SHA-512:CF22EFCE33C896A751EF23CD5916BBB0C11B8187D733472050A16F72DE24CEFD3622DC29CA3258052035AACFE196D256B2EDE2E760C5DAA9113E6BC6816DCC88
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:09.532 23d4 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db since it was missing..2025/03/13-12:38:09.724 23d4 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\EntityExtractionAssetStore.db/MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41
                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):358860
                                                                                                                                                    Entropy (8bit):5.324620980103532
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:CgimBVvUrsc6rRA81b/18jyJNjfvrfM6R2:C1gAg1zfv+
                                                                                                                                                    MD5:E7778052702676FF03E3B225D99EA75A
                                                                                                                                                    SHA1:8090D668EFA420FE9FA26816F51223CACC566505
                                                                                                                                                    SHA-256:4050FBA84F95CBA7E1DF1B0D73CA68D726510C61D7D3AC0979AB2819F07E1F27
                                                                                                                                                    SHA-512:5F85D1CED7B7AB2D8876A28CAC4D4231AE1E98A511BB0199C3BDF4E9E772FBE9C3E2A0850452657FBD9BEF22EBB8A4969581E79DC5F1373DE07F3E74460F715D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aee_config":{"ar":{"price_regex":{"ae":"(((ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(ae|aed|\\x{062F}\\x{0660}\\x{0625}\\x{0660}|\\x{062F}\\.\\x{0625}|dhs|dh)))","dz":"(((dzd|da|\\x{062F}\\x{062C})\\s*\\d{1,3})|(\\d{1,3}\\s*(dzd|da|\\x{062F}\\x{062C})))","eg":"(((e\\x{00a3}|egp)\\s*\\d{1,3})|(\\d{1,3}\\s*(e\\x{00a3}|egp)))","ma":"(((mad|dhs|dh)\\s*\\d{1,3})|(\\d{1,3}\\s*(mad|dhs|dh)))","sa":"((\\d{1,3}\\s*(sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633}))|((sar\\s*\\x{fdfc}|sar|sr|\\x{fdfc}|\\.\\x{0631}\\.\\x{0633})\\s*\\d{1,3}))"},"product_terms":"((\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{0639}\\x{0631}\\x{0628}\\x{0629})|(\\x{0623}\\x{0636}\\x{0641}\\s*\\x{0625}\\x{0644}\\x{0649}\\s*\\x{0627}\\x{0644}\\x{062D}\\x{0642}\\x{064A}\\x{0628}\\x{0629})|(\\x{0627}\\x{0634}\\x{062A}\\x{0631}\\x{064A}\\s*\\x{0627}\\x{0644}\\x{0622}\\x{0646})|(\\x{062E}\\x{064A}\\x{0627}\\x{0631}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):418
                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:qTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCT:qWWWWWWWWWWWWWWWWWWWWW
                                                                                                                                                    MD5:BF097D724FDF1FCA9CF3532E86B54696
                                                                                                                                                    SHA1:4039A5DD607F9FB14018185F707944FE7BA25EF7
                                                                                                                                                    SHA-256:1B8B50A996172C16E93AC48BCB94A3592BEED51D3EF03F87585A1A5E6EC37F6B
                                                                                                                                                    SHA-512:31857C157E5B02BCA225B189843CE912A792A7098CEA580B387977B29E90A33C476DF99AD9F45AD5EB8DA1EFFD8AC3A78870988F60A32D05FA2DA8F47794FACE
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.161557975307519
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbovlyq2PCHhJ23oH+Tcwt8aPrqIFUtoPbdQC+Fz1ZmwCPbdQqRkwOCHhJ230:7GUIvBYebL3FUtopa1/Cpz56YebQJ
                                                                                                                                                    MD5:AA30850EF97E053739719B2E65DDD89A
                                                                                                                                                    SHA1:462166A89AF6E97D877CF383A5E0CF174253D1F1
                                                                                                                                                    SHA-256:EDD2225AF928315D6D22B0D8D19EB545E468C48339AB98AA6C5CCA90953CA890
                                                                                                                                                    SHA-512:45B2654DD996E70038EFE20DD1FE7FF36664A146239A6F9B50ECDC8A6BE032F65E3F6ECE87440E542A35FFD8FAFA998F39E60F540B853CC491E8A24989518EDA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.858 1ea0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.2025/03/13-12:38:03.953 1ea0 Recovering log #3.2025/03/13-12:38:03.954 1ea0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.161557975307519
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbovlyq2PCHhJ23oH+Tcwt8aPrqIFUtoPbdQC+Fz1ZmwCPbdQqRkwOCHhJ230:7GUIvBYebL3FUtopa1/Cpz56YebQJ
                                                                                                                                                    MD5:AA30850EF97E053739719B2E65DDD89A
                                                                                                                                                    SHA1:462166A89AF6E97D877CF383A5E0CF174253D1F1
                                                                                                                                                    SHA-256:EDD2225AF928315D6D22B0D8D19EB545E468C48339AB98AA6C5CCA90953CA890
                                                                                                                                                    SHA-512:45B2654DD996E70038EFE20DD1FE7FF36664A146239A6F9B50ECDC8A6BE032F65E3F6ECE87440E542A35FFD8FAFA998F39E60F540B853CC491E8A24989518EDA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.858 1ea0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/MANIFEST-000001.2025/03/13-12:38:03.953 1ea0 Recovering log #3.2025/03/13-12:38:03.954 1ea0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Rules/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):418
                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:qTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCT:qWWWWWWWWWWWWWWWWWWWWW
                                                                                                                                                    MD5:BF097D724FDF1FCA9CF3532E86B54696
                                                                                                                                                    SHA1:4039A5DD607F9FB14018185F707944FE7BA25EF7
                                                                                                                                                    SHA-256:1B8B50A996172C16E93AC48BCB94A3592BEED51D3EF03F87585A1A5E6EC37F6B
                                                                                                                                                    SHA-512:31857C157E5B02BCA225B189843CE912A792A7098CEA580B387977B29E90A33C476DF99AD9F45AD5EB8DA1EFFD8AC3A78870988F60A32D05FA2DA8F47794FACE
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):328
                                                                                                                                                    Entropy (8bit):5.1697168268327935
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbt0Ulyq2PCHhJ23oH+Tcwt865IFUtoPbtk1ZmwCPbtyRkwOCHhJ23oH+Tcwx:7GYvBYeb/WFUtoW1/C456Yeb/+SJ
                                                                                                                                                    MD5:B4E50ECD9EB06C9BDBADF0E874D19A31
                                                                                                                                                    SHA1:5BBB420E0D852736F4AAC67AB35AD8AC390760FB
                                                                                                                                                    SHA-256:8EBBE54741AE1600CC2B90C74240B757C9134BBB46BFC1A4A01AACF0E91BBC39
                                                                                                                                                    SHA-512:ED83C6C5A39D911B4723E9CA9A017ADB71476C962D5A77C2442B885DA9DD63F54AF8E75588AE3287E032E028C82608FE3CC9F1EAB93AE2D08F3AD2BE9B524F52
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.061 1ea0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.2025/03/13-12:38:04.062 1ea0 Recovering log #3.2025/03/13-12:38:04.062 1ea0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):328
                                                                                                                                                    Entropy (8bit):5.1697168268327935
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbt0Ulyq2PCHhJ23oH+Tcwt865IFUtoPbtk1ZmwCPbtyRkwOCHhJ23oH+Tcwx:7GYvBYeb/WFUtoW1/C456Yeb/+SJ
                                                                                                                                                    MD5:B4E50ECD9EB06C9BDBADF0E874D19A31
                                                                                                                                                    SHA1:5BBB420E0D852736F4AAC67AB35AD8AC390760FB
                                                                                                                                                    SHA-256:8EBBE54741AE1600CC2B90C74240B757C9134BBB46BFC1A4A01AACF0E91BBC39
                                                                                                                                                    SHA-512:ED83C6C5A39D911B4723E9CA9A017ADB71476C962D5A77C2442B885DA9DD63F54AF8E75588AE3287E032E028C82608FE3CC9F1EAB93AE2D08F3AD2BE9B524F52
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.061 1ea0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/MANIFEST-000001.2025/03/13-12:38:04.062 1ea0 Recovering log #3.2025/03/13-12:38:04.062 1ea0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension Scripts/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1254
                                                                                                                                                    Entropy (8bit):1.8784775129881184
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:qWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWA:
                                                                                                                                                    MD5:826B4C0003ABB7604485322423C5212A
                                                                                                                                                    SHA1:6B8EF07391CD0301C58BB06E8DEDCA502D59BCB4
                                                                                                                                                    SHA-256:C56783C3A6F28D9F7043D2FB31B8A956369F25E6CE6441EB7C03480334341A63
                                                                                                                                                    SHA-512:0474165157921EA84062102743EE5A6AFE500F1F87DE2E87DBFE36C32CFE2636A0AE43D8946342740A843D5C2502EA4932623C609B930FE8511FE7356D4BAA9C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5........
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.19329073534674
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbt30+q2PCHhJ23oH+Tcwt8NIFUtoPbtUWZmwCPbtUSVkwOCHhJ23oH+Tcwt2:7G50+vBYebpFUtoH/CnV56YebqJ
                                                                                                                                                    MD5:D3FE90CE5F57F0332262B31103E97519
                                                                                                                                                    SHA1:349A79C3219D6920AF5972017BF29444918F1501
                                                                                                                                                    SHA-256:D774B58C3958BD2FBCFF4F8C76925197166E9E60F4705B9E3B5BA7F997F537AF
                                                                                                                                                    SHA-512:89DBCB7804062F18809F72F52A8D576A6BDAC66FE2A267AE7D4F354EF85D2A9371AEFDB482DFAD7D97C99FA6C4A8680FA64D1A4742824A3AC057DB8E4F1D36E1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.829 1e9c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2025/03/13-12:38:04.831 1e9c Recovering log #3.2025/03/13-12:38:04.831 1e9c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.19329073534674
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbt30+q2PCHhJ23oH+Tcwt8NIFUtoPbtUWZmwCPbtUSVkwOCHhJ23oH+Tcwt2:7G50+vBYebpFUtoH/CnV56YebqJ
                                                                                                                                                    MD5:D3FE90CE5F57F0332262B31103E97519
                                                                                                                                                    SHA1:349A79C3219D6920AF5972017BF29444918F1501
                                                                                                                                                    SHA-256:D774B58C3958BD2FBCFF4F8C76925197166E9E60F4705B9E3B5BA7F997F537AF
                                                                                                                                                    SHA-512:89DBCB7804062F18809F72F52A8D576A6BDAC66FE2A267AE7D4F354EF85D2A9371AEFDB482DFAD7D97C99FA6C4A8680FA64D1A4742824A3AC057DB8E4F1D36E1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.829 1e9c Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/MANIFEST-000001.2025/03/13-12:38:04.831 1e9c Recovering log #3.2025/03/13-12:38:04.831 1e9c Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Extension State/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):429
                                                                                                                                                    Entropy (8bit):5.809210454117189
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:Y8U0vEjrAWT0VAUD9lpMXO4SrqiweVHUSENjrAWT0HQQ9/LZyVMQ3xqiweVHlrSQ:Y8U5j0pqCjJA7tNj0pHx/LZ4hcdQ
                                                                                                                                                    MD5:5D1D9020CCEFD76CA661902E0C229087
                                                                                                                                                    SHA1:DCF2AA4A1C626EC7FFD9ABD284D29B269D78FCB6
                                                                                                                                                    SHA-256:B829B0DF7E3F2391BFBA70090EB4CE2BA6A978CCD665EEBF1073849BDD4B8FB9
                                                                                                                                                    SHA-512:5F6E72720E64A7AC19F191F0179992745D5136D41DCDC13C5C3C2E35A71EB227570BD47C7B376658EF670B75929ABEEBD8EF470D1E24B595A11D320EC1479E3C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"file_hashes":[{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","6RbL+qKART8FehO4s7U0u67iEI8/jaN+8Kg3kII+uy4=","CuN6+RcZAysZCfrzCZ8KdWDkQqyaIstSrcmsZ/c2MVs="],"block_size":4096,"path":"content.js"},{"block_hashes":["OdZL4YFLwCTKbdslekC6/+U9KTtDUk+T+nnpVOeRzUc=","UL53sQ5hOhAmII/Yx6muXikzahxM+k5gEmVOh7xJ3Rw=","u6MdmVNzBUfDzMwv2LEJ6pXR8k0nnvpYRwOL8aApwP8="],"block_size":4096,"path":"content_new.js"}],"version":2}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 2, database pages 38, cookie 0x1f, schema 4, UTF-8, version-valid-for 2
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):155648
                                                                                                                                                    Entropy (8bit):0.5624448922890185
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:+3HWyejzH+bDoYysX0IxQzZkHtpVJNlYDLjGQLBE3CeE0kEh6:+GhH+bDo3iN0Z2TVJkXBBE3yb3
                                                                                                                                                    MD5:103E9FEAE416AF38509058646C6CDE06
                                                                                                                                                    SHA1:D1DD2A9516DEE40B70C9F8D0E445960C7B1F0162
                                                                                                                                                    SHA-256:495896FE18DF158A36B1DF94991C6A1DA930CA2C3503BA47BDAE0B23C4E3A695
                                                                                                                                                    SHA-512:1759CBCA305D3350FCB5B10804BCD403AFAA4DE8ADCC5066101E2E5008025D5EFBF0558E18C2F8B9F5927F7630169B63EF2363C55CB0DC69D9A6765FA836318B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ .......&..................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):8720
                                                                                                                                                    Entropy (8bit):0.2191763562065486
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:IjlntFlljq7A/mhWJFuQ3yy7IOWUKbCl/dweytllrE9SFcTp4AGbNCV9RUItl:b75fOCCl/d0Xi99pEYd
                                                                                                                                                    MD5:C23FE204CE048E8771CEC19ACD5C0559
                                                                                                                                                    SHA1:D7C0C3652F72ABE7FC3194534C3BF9F544C64336
                                                                                                                                                    SHA-256:6293EF5FB9CF9458EF903F7DC08E0B73BE9001004545D417949F7583052BB3C0
                                                                                                                                                    SHA-512:14A96076E23067FA030C2B2608740099C454FB0F03D720CE464E00521DE5DDA4D368AC456193F27C63D4F838F1312F7F2AB07ECF82B4C210758AB0499F0929AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:............/}.....&....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):115717
                                                                                                                                                    Entropy (8bit):5.183660917461099
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                    MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                    SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                    SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                    SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 6, database pages 11, cookie 0x3, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):45056
                                                                                                                                                    Entropy (8bit):3.91832282763231
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:384:jj9P0ogam6IoP/KbtH773pLDcqjlqQkQerORKToaADhf:jdgYP/27O4lqe2ORKc39
                                                                                                                                                    MD5:A897B0D2091EFFB395C53AE9BDEB4928
                                                                                                                                                    SHA1:EE3F01FD0C1455CBC1B02EEA9541157C3FC4AA4E
                                                                                                                                                    SHA-256:82FA72305ABD7EB3A4CACB603233B559BD60B7BC36CBCAC6F03D2C20E5AE215C
                                                                                                                                                    SHA-512:E06BF049E23303CFCEBF7F017F60FBC5E1B8D9451E54B34E0BD70AE7C775D3D95C2F79E76F6B2FC0EC66859BE59A2A731738528EBFA9D92BABE842567BF7202F
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...:.8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):408
                                                                                                                                                    Entropy (8bit):5.299049745124013
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7GivBYeb8rcHEZrELFUtoh1/Ch56Yeb8rcHEZrEZSJ:7dBYeb8nZrExgQ86Yeb8nZrEZe
                                                                                                                                                    MD5:F8546966A4C1508B1452370D56B44EBC
                                                                                                                                                    SHA1:AA37B177E40EE079DF151F0E88021A57DD5A0099
                                                                                                                                                    SHA-256:2278F1F1756C84B6BEC96B0D024C6CA2285D1B5F56CBD578238BB706EA1E2EE3
                                                                                                                                                    SHA-512:C1A2DAE680971D40A671D140B86FA39E5879F03118CDEC614464BC60A7E58635F0F036BC4AC1ECD159DF444DB840DAD6FF550F191C1607A1DEC1E074E90DDE00
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:09.088 1e94 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2025/03/13-12:38:09.088 1e94 Recovering log #3.2025/03/13-12:38:09.088 1e94 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):408
                                                                                                                                                    Entropy (8bit):5.299049745124013
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7GivBYeb8rcHEZrELFUtoh1/Ch56Yeb8rcHEZrEZSJ:7dBYeb8nZrExgQ86Yeb8nZrEZe
                                                                                                                                                    MD5:F8546966A4C1508B1452370D56B44EBC
                                                                                                                                                    SHA1:AA37B177E40EE079DF151F0E88021A57DD5A0099
                                                                                                                                                    SHA-256:2278F1F1756C84B6BEC96B0D024C6CA2285D1B5F56CBD578238BB706EA1E2EE3
                                                                                                                                                    SHA-512:C1A2DAE680971D40A671D140B86FA39E5879F03118CDEC614464BC60A7E58635F0F036BC4AC1ECD159DF444DB840DAD6FF550F191C1607A1DEC1E074E90DDE00
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:09.088 1e94 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/MANIFEST-000001.2025/03/13-12:38:09.088 1e94 Recovering log #3.2025/03/13-12:38:09.088 1e94 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Extension Settings\jdiccldimpdaibmpdkjnbmckianbfold/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):336
                                                                                                                                                    Entropy (8bit):5.157808790466952
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbtEe3+q2PCHhJ23oH+Tcwt8a2jMGIFUtoPbt5ZmwCPbtHVkwOCHhJ23oH+Tg:7G+vBYeb8EFUtor/Cv56Yeb8bJ
                                                                                                                                                    MD5:3B9F1FE90BB1F08F3CCE5B3EA7E1060C
                                                                                                                                                    SHA1:1E8F9F78DA18D8F25C4C88EB4BE78D7EED9621DB
                                                                                                                                                    SHA-256:51405932CA7A57C7F2FA913C37E6A99971EFCA43275BE8CF86007211516146D4
                                                                                                                                                    SHA-512:DE2A9B4D80184BD25AA8E09BC67CD4E3234C6520CE296BFD53DB54447E1CFD3B30B4A07F4B41BEC8CE4E81D91741CBC246FFF893F4D9B0126764D81C1DF37E07
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.219 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2025/03/13-12:38:04.220 1fa8 Recovering log #3.2025/03/13-12:38:04.222 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):336
                                                                                                                                                    Entropy (8bit):5.157808790466952
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbtEe3+q2PCHhJ23oH+Tcwt8a2jMGIFUtoPbt5ZmwCPbtHVkwOCHhJ23oH+Tg:7G+vBYeb8EFUtor/Cv56Yeb8bJ
                                                                                                                                                    MD5:3B9F1FE90BB1F08F3CCE5B3EA7E1060C
                                                                                                                                                    SHA1:1E8F9F78DA18D8F25C4C88EB4BE78D7EED9621DB
                                                                                                                                                    SHA-256:51405932CA7A57C7F2FA913C37E6A99971EFCA43275BE8CF86007211516146D4
                                                                                                                                                    SHA-512:DE2A9B4D80184BD25AA8E09BC67CD4E3234C6520CE296BFD53DB54447E1CFD3B30B4A07F4B41BEC8CE4E81D91741CBC246FFF893F4D9B0126764D81C1DF37E07
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.219 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2025/03/13-12:38:04.220 1fa8 Recovering log #3.2025/03/13-12:38:04.222 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Local Storage\leveldb/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):1155
                                                                                                                                                    Entropy (8bit):5.29413223509647
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:YXsM/4yZVMdBsQZFRudFGcsPnZ6ma3yeebsPOXoZCO4iMH/sbS7n7:YXsUV8sQfcdsPZleebsPOoCpH/sbc
                                                                                                                                                    MD5:D9FFB8C8FBDA703D3D97CB5553F9C239
                                                                                                                                                    SHA1:0FB26BEC1D83F03E784752B0BE77B7349C516D34
                                                                                                                                                    SHA-256:8D16614523BC2099EEACCE698DC151B9C314F7C82B53A24322B70B8DF046310D
                                                                                                                                                    SHA-512:07D562453ED1A7160D9BA8E31968173C5B73C833BD93991D49B71F0C3ADEA1306651D5D8AFDE26228DCC33C606B93304B9EE99A7BD68DD309F563384F1B4AD8A
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13388949487916026","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13388949493143542","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13386451096257285","port":443,"protocol_str":"quic"}],"anonymization":["HAAAABUAAABodHRwczovL21pY3Jvc29mdC5jb20AAAA=",false],"server":"https://msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13386451091298067","port":443,"protocol_str":"quic"}],"anonymization":["FAAAABAAAABodHRwczovL2JpbmcuY29t",false],"network_stats":{"srtt":1311095},"s
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):40
                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):111
                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):111
                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):111
                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):111
                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 7, database pages 9, cookie 0x4, schema 4, UTF-8, version-valid-for 7
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):36864
                                                                                                                                                    Entropy (8bit):1.1139160417089315
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:TFkIopKWurJNVr1GJmA8pv82pfurJNVrdHXuccaurJN2VrJ1n4n1GmzNGU1cSBu+:JkIEumQv8m1ccnvS67m2cI9MN1a
                                                                                                                                                    MD5:26EF30573D316B3A4870224CDA98A728
                                                                                                                                                    SHA1:5EEE5223A4E303CA689ECD2A29852063672FDBE2
                                                                                                                                                    SHA-256:D332A05A87F82C76BF3DB3F636E1E44BC9BEFC04A99AA47756C33F988F776E19
                                                                                                                                                    SHA-512:B7CDFAAE4DEA5D24090D6F1199D39F9EA73230E0A6EC7C91B01EBCB17938784F43AD86BF70C84C7A332B5808A4042ED8C181721B4D5497F48E5320E5CED51611
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...D.........7............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):40
                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1122
                                                                                                                                                    Entropy (8bit):5.2975736242153655
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:YXsM/4yZVMdBsPOXoZCO4iYlsQZFRudFGcsPnZ6ma3yeevbS7n7:YXsUV8sPOoC5sQfcdsPZleevbc
                                                                                                                                                    MD5:A848CDFB4CEC9E302688D3BB0C9C3104
                                                                                                                                                    SHA1:3EFC50290304835D78C706607CADE3369E07E107
                                                                                                                                                    SHA-256:BCA675E2E98F0882016D9016DFB7D448244AA3A8E2BF8218AE9D98E40B69E62E
                                                                                                                                                    SHA-512:78C05668BEB868CEF819DE40CF1F85FE2C8EA79A69DA9726EC9F0ACBEC25B5D511905F3924B045236053C18655297749864484B0FE3C724AA9B1AD9C74B482B8
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13388949487916026","port":443,"protocol_str":"quic"}],"anonymization":["GAAAABIAAABodHRwczovL2dvb2dsZS5jb20AAA==",false],"server":"https://clients2.google.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13386451091298067","port":443,"protocol_str":"quic"}],"anonymization":["FAAAABAAAABodHRwczovL2JpbmcuY29t",false],"server":"https://www.bing.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13388949493143542","port":443,"protocol_str":"quic"}],"anonymization":["JAAAAB0AAABodHRwczovL2dvb2dsZXVzZXJjb250ZW50LmNvbQAAAA==",false],"server":"https://clients2.googleusercontent.com"},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13386451096257285","port":443,"protocol_str":"quic"}],"anonymization":["HAAAABUAAABodHRwczovL21pY3Jvc29mdC5jb20AAAA=",false],"server":"https://msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com"}],"
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 3, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 3
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):20480
                                                                                                                                                    Entropy (8bit):0.8307038620100359
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:TLSOUOq0afDdWec9sJlAz7Nm2z8ZI7J5fc:T+OUzDbg3eAzA2ztc
                                                                                                                                                    MD5:B18967139991D9CA13DF7E493540A358
                                                                                                                                                    SHA1:97411C14A8503C11248BE7404C9A79BA5146D40C
                                                                                                                                                    SHA-256:CCC36F21951B4CB357C57DA0CCA1FFF3B4C7027230C10FD8BCB72C0AFF66141F
                                                                                                                                                    SHA-512:473AE1B215B181785EA65F87E34155D5976C7AD1FA487B025E1C8711BFD127E99066990105CDA8D6F4804459118361217455AB1644803D22E6ECB164EEEFD630
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9659
                                                                                                                                                    Entropy (8bit):5.101009042837891
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRkdgsjUIa34Hka3I88bV+FGaBQA4hJq7NIoPqYJ:stRDsjUX3bG3BQxh07NIO
                                                                                                                                                    MD5:24662A78EA226D720B006031A56CC67E
                                                                                                                                                    SHA1:3A6ACE37ABDB4751ED1C12923A002F67D98227BA
                                                                                                                                                    SHA-256:678653E6BEDB1B5A44823C2E0D7EFC18645E6AA3541710E68E0C217B614AF27A
                                                                                                                                                    SHA-512:9B2AE4335C2940D4869A260A702358E962657E3A1752F2EF11C725D010572F1A7CC939C17CD1991F13D2D673AB612DD3FAC982C27E509631075454954C444801
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"li
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9659
                                                                                                                                                    Entropy (8bit):5.101009042837891
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRkdgsjUIa34Hka3I88bV+FGaBQA4hJq7NIoPqYJ:stRDsjUX3bG3BQxh07NIO
                                                                                                                                                    MD5:24662A78EA226D720B006031A56CC67E
                                                                                                                                                    SHA1:3A6ACE37ABDB4751ED1C12923A002F67D98227BA
                                                                                                                                                    SHA-256:678653E6BEDB1B5A44823C2E0D7EFC18645E6AA3541710E68E0C217B614AF27A
                                                                                                                                                    SHA-512:9B2AE4335C2940D4869A260A702358E962657E3A1752F2EF11C725D010572F1A7CC939C17CD1991F13D2D673AB612DD3FAC982C27E509631075454954C444801
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"li
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9659
                                                                                                                                                    Entropy (8bit):5.101009042837891
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRkdgsjUIa34Hka3I88bV+FGaBQA4hJq7NIoPqYJ:stRDsjUX3bG3BQxh07NIO
                                                                                                                                                    MD5:24662A78EA226D720B006031A56CC67E
                                                                                                                                                    SHA1:3A6ACE37ABDB4751ED1C12923A002F67D98227BA
                                                                                                                                                    SHA-256:678653E6BEDB1B5A44823C2E0D7EFC18645E6AA3541710E68E0C217B614AF27A
                                                                                                                                                    SHA-512:9B2AE4335C2940D4869A260A702358E962657E3A1752F2EF11C725D010572F1A7CC939C17CD1991F13D2D673AB612DD3FAC982C27E509631075454954C444801
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"li
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9659
                                                                                                                                                    Entropy (8bit):5.101009042837891
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRkdgsjUIa34Hka3I88bV+FGaBQA4hJq7NIoPqYJ:stRDsjUX3bG3BQxh07NIO
                                                                                                                                                    MD5:24662A78EA226D720B006031A56CC67E
                                                                                                                                                    SHA1:3A6ACE37ABDB4751ED1C12923A002F67D98227BA
                                                                                                                                                    SHA-256:678653E6BEDB1B5A44823C2E0D7EFC18645E6AA3541710E68E0C217B614AF27A
                                                                                                                                                    SHA-512:9B2AE4335C2940D4869A260A702358E962657E3A1752F2EF11C725D010572F1A7CC939C17CD1991F13D2D673AB612DD3FAC982C27E509631075454954C444801
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"li
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9659
                                                                                                                                                    Entropy (8bit):5.101009042837891
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRkdgsjUIa34Hka3I88bV+FGaBQA4hJq7NIoPqYJ:stRDsjUX3bG3BQxh07NIO
                                                                                                                                                    MD5:24662A78EA226D720B006031A56CC67E
                                                                                                                                                    SHA1:3A6ACE37ABDB4751ED1C12923A002F67D98227BA
                                                                                                                                                    SHA-256:678653E6BEDB1B5A44823C2E0D7EFC18645E6AA3541710E68E0C217B614AF27A
                                                                                                                                                    SHA-512:9B2AE4335C2940D4869A260A702358E962657E3A1752F2EF11C725D010572F1A7CC939C17CD1991F13D2D673AB612DD3FAC982C27E509631075454954C444801
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"li
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16
                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):83572
                                                                                                                                                    Entropy (8bit):5.6642042826828725
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:gL0/Ry7vm2lhq4ljc+PjfOzBu+RMDVogUlcPCcBjjmny8dLA8j7baD7:gL6yLm2fq4pc+rCAogU2CcBjj3YAg7mn
                                                                                                                                                    MD5:06C52945363E5E4CE6A3FFCB0E2AE20F
                                                                                                                                                    SHA1:6EBAF23153409BBEEA5EAF08F53ACCD3950BEE5D
                                                                                                                                                    SHA-256:2476FDA4C3365FF023952C7ED709662B7EE86D1B80D74945C3C9C9973CD5882D
                                                                                                                                                    SHA-512:5B1D08C8C5B0DD24ABFE42817AEB62F775A140D354FFACDB5D77F2051FE08BFD6AC4EA0815CD02F0DF33CF3CE14FE9D6AE2B42CB46491BEA7FF8275D02D3C14B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...m.................DB_VERSION.1]..|j...............(QUERY_TIMESTAMP:product_category_en1.*.*.13386357500050000..QUERY:product_category_en1.*.*..[{"name":"product_category_en","url":"https://edgeassetservice.azureedge.net/assets/product_category_en/1.0.0/asset?assetgroup=ProductCategories","version":{"major":1,"minor":0,"patch":0},"hash":"r2jWYy3aqoi3+S+aPyOSfXOCPeLSy5AmAjNHvYRv9Hg=","size":82989}]...yg~..............!ASSET_VERSION:product_category_en.1.0.0..ASSET:product_category_en...."..3....Car & Garage..Belts & Hoses.#..+....Sports & Outdoors..Air Pumps.!.."....Car & Garage..Body Styling.4..5./..Gourmet Food & Chocolate..Spices & Seasonings.'..,."..Sports & Outdoors..Sleeping Gear.!..6....Lawn & Garden..Hydroponics.9.a.5..Books & Magazines. Gay & Lesbian Interest Magazines....+....Office Products..Pins.,..3.'..Kitchen & Housewares..Coffee Grinders.$..#....Computing..Enterprise Servers.#..&....Home Furnishings..Footboards.6...2..Books & Magazines..Computer & Internet Magazines.)..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):16
                                                                                                                                                    Entropy (8bit):3.2743974703476995
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:1sjgWIV//Uv:1qIFUv
                                                                                                                                                    MD5:46295CAC801E5D4857D09837238A6394
                                                                                                                                                    SHA1:44E0FA1B517DBF802B18FAF0785EEEA6AC51594B
                                                                                                                                                    SHA-256:0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
                                                                                                                                                    SHA-512:8969402593F927350E2CEB4B5BC2A277F3754697C1961E3D6237DA322257FBAB42909E1A742E22223447F3A4805F8D8EF525432A7C3515A549E984D3EFF72B23
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):307
                                                                                                                                                    Entropy (8bit):5.226835596254317
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGP0R1CHhJ23oH+TcwtgctZQInvB2KLl4P2q+q2PCHhJ23oH+TcwtgctZQInvIg:7GcNYebgGZznvFLCOLvBYebgGZznQFUv
                                                                                                                                                    MD5:92860AA5831A44C52EAD4ED782FC0C83
                                                                                                                                                    SHA1:11932A86E838977B0AC4F63AEF46A1015B5C3586
                                                                                                                                                    SHA-256:475EABCB8A8D0C8C49F6FB871BC0AD4FA931256931CAC7B1A3508004E014EE1A
                                                                                                                                                    SHA-512:81E8DC6FE50B0A4B18839B7E7E41B9CCE53515690BAA0621B261F6A8895286E54718F8E7A5402680EF0FC2A4F76598860BBA33D2BE08CCCC2AA065DC5FB0F41A
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:17.170 968 Creating DB C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\PriceComparisonAssetStore.db since it was missing..2025/03/13-12:38:17.210 968 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\PriceComparisonAssetStore.db/MANIFEST-000001.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:OpenPGP Secret Key
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41
                                                                                                                                                    Entropy (8bit):4.704993772857998
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:scoBAIxQRDKIVjn:scoBY7jn
                                                                                                                                                    MD5:5AF87DFD673BA2115E2FCF5CFDB727AB
                                                                                                                                                    SHA1:D5B5BBF396DC291274584EF71F444F420B6056F1
                                                                                                                                                    SHA-256:F9D31B278E215EB0D0E9CD709EDFA037E828F36214AB7906F612160FEAD4B2B4
                                                                                                                                                    SHA-512:DE34583A7DBAFE4DD0DC0601E8F6906B9BC6A00C56C9323561204F77ABBC0DC9007C480FFE4092FF2F194D54616CAF50AECBD4A1E9583CAE0C76AD6DD7C2375B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.|.."....leveldb.BytewiseComparator......
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):25012
                                                                                                                                                    Entropy (8bit):5.566856295147486
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:sXI4xjWPRBfnu8F1+UoAYDCx9Tuqh0VfUC9xbog/OV1UX4IrwOYpctuV:sXI4xjWPRBfnuu1jaYY4ZO7tC
                                                                                                                                                    MD5:B81A0E4E204628C38C3388DE1147F8D3
                                                                                                                                                    SHA1:B9F4B1BCA119AFEFA789F2F92609E12D8867C802
                                                                                                                                                    SHA-256:827BD96D6FBD94B1EBB43ECFAB527E2EBBBA7C92C11D584F407F9C44BA7BE987
                                                                                                                                                    SHA-512:91F527F04687B9D1E8D020E48E093055DA4E117D34DF2E349E44741CD819D95F99D605FACD74AB6A3184E4266143559042E881689EF95770DA30BCC185CEED41
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13386357483832412","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13386357483832412","location":5,"ma
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):25012
                                                                                                                                                    Entropy (8bit):5.566856295147486
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:sXI4xjWPRBfnu8F1+UoAYDCx9Tuqh0VfUC9xbog/OV1UX4IrwOYpctuV:sXI4xjWPRBfnuu1jaYY4ZO7tC
                                                                                                                                                    MD5:B81A0E4E204628C38C3388DE1147F8D3
                                                                                                                                                    SHA1:B9F4B1BCA119AFEFA789F2F92609E12D8867C802
                                                                                                                                                    SHA-256:827BD96D6FBD94B1EBB43ECFAB527E2EBBBA7C92C11D584F407F9C44BA7BE987
                                                                                                                                                    SHA-512:91F527F04687B9D1E8D020E48E093055DA4E117D34DF2E349E44741CD819D95F99D605FACD74AB6A3184E4266143559042E881689EF95770DA30BCC185CEED41
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13386357483832412","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13386357483832412","location":5,"ma
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):319
                                                                                                                                                    Entropy (8bit):4.061655670212498
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:S85aEFljljljljlz/llaLuTFUUfFyQfYH5EEE:S+a8ljljljljlxguWUfLfYH
                                                                                                                                                    MD5:6711DB923AC6198D60FD2117D0A611AD
                                                                                                                                                    SHA1:646EA318A8305DC7B90616D5DC75056725C4AA32
                                                                                                                                                    SHA-256:B273C06709E09831108BCC7396F7AB9E4E3E24CBC50956958B29C9CBCA522129
                                                                                                                                                    SHA-512:91ED2A5CD2EF054C340BA4EB5A73356B2C1970622B44B3D490F14855125A4968B12DB4DF3DB0FE8166C8D078A5EA83CBCC04844ED45BEFC1B73E22F604E7B764
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:*...#................version.1..namespace-..&f.................&f.................&f.................&f.................&f..................,c................next-map-id.1.Dnamespace-cb875b98_3eea_4f37_88bc_d7ef83ec717f-https://pdf-izer.com/.0V.e................V.e................V.e................V.e................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.167681778142896
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbtl+q2PCHhJ23oH+TcwtrQMxIFUtoPbt7ZmwCPbteV3VkwOCHhJ23oH+TcwJ:7G6vBYebCFUtop/CAz56YebtJ
                                                                                                                                                    MD5:52A78341BD762C878B46EA772127A9E5
                                                                                                                                                    SHA1:7E3924850458D61F31BF8074128CDC90F957E6B6
                                                                                                                                                    SHA-256:39644AB13012288B29E2AC7A2EE552F71E69B6A047F005D542563243E5194E29
                                                                                                                                                    SHA-512:3B85FA019733F9234806A61E45DA0C698688876210E3ED637B3520831797703C4795B2767CB144C3EE2E722260FE6B07E554C20C47C263911325CDB751AF3C78
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.880 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2025/03/13-12:38:04.886 1fa8 Recovering log #3.2025/03/13-12:38:04.890 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.167681778142896
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbtl+q2PCHhJ23oH+TcwtrQMxIFUtoPbt7ZmwCPbteV3VkwOCHhJ23oH+TcwJ:7G6vBYebCFUtop/CAz56YebtJ
                                                                                                                                                    MD5:52A78341BD762C878B46EA772127A9E5
                                                                                                                                                    SHA1:7E3924850458D61F31BF8074128CDC90F957E6B6
                                                                                                                                                    SHA-256:39644AB13012288B29E2AC7A2EE552F71E69B6A047F005D542563243E5194E29
                                                                                                                                                    SHA-512:3B85FA019733F9234806A61E45DA0C698688876210E3ED637B3520831797703C4795B2767CB144C3EE2E722260FE6B07E554C20C47C263911325CDB751AF3C78
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.880 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/MANIFEST-000001.2025/03/13-12:38:04.886 1fa8 Recovering log #3.2025/03/13-12:38:04.890 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1207
                                                                                                                                                    Entropy (8bit):3.542326231491013
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:342vFPd3UfvDbNGtIZjJTdlLfYxYFUP3+jObJEwYvZOl7XIlk4rpLfYxq:3Tvpt9KLkR3+jQPYBOZX541Lk
                                                                                                                                                    MD5:81CDC66F81C6445EEBB23890EFA6E001
                                                                                                                                                    SHA1:B8CAE492FA3C3561DEE5C6B76C08AD9393BA8969
                                                                                                                                                    SHA-256:4EE0B83C5D14E2255FB95754F18A3659E515C969F672B3BA24450D6968D9EBAB
                                                                                                                                                    SHA-512:40F2E2CC6F7D2929F7F4E4DA3C6C75F5684ED7CBC4C0AF9EB60AD7A33E390E2EA57122C93B7747191E28A879DD4B091A1B62D945E0A369AD8292050B7C9FF645
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SNSS........[y............[y......".[y............[y........[y........[y........[y....!...[y................................[y.[y1..,....[y$...cb875b98_3eea_4f37_88bc_d7ef83ec717f....[y........[y.....7..........[y....[y........................[y....................5..0....[y&...{C81239B7-C2EC-4765-BA59-62829EE7E719}......[y........[y...........................[y....1..,....[y...."...https://pdf-izer.com/thankyou.html......|...x...!...p...................................................................................................9.a.;0..:.a.;0..........0...............(.......................................................L..."...h.t.t.p.s.:././.p.d.f.-.i.z.e.r...c.o.m./.t.h.a.n.k.y.o.u...h.t.m.l.....................................8.......0.......8....................................................................... .......................................................P...$...6.1.2.5.e.2.6.5.-.a.e.6.0.-.4.d.5.c.-.9.b.b.1.-.1.9.7.9.3.1.c.7.e.9.f.4..........
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 5, cookie 0x2, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):20480
                                                                                                                                                    Entropy (8bit):0.44194574462308833
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:TLiNCcUMskMVcIWGhWxBzEXx7AAQlvsdFxOUwa5qgufTJpbZ75fOS:TLisVMnYPhIY5Qlvsd6UwccNp15fB
                                                                                                                                                    MD5:B35F740AA7FFEA282E525838EABFE0A6
                                                                                                                                                    SHA1:A67822C17670CCE0BA72D3E9C8DA0CE755A3421A
                                                                                                                                                    SHA-256:5D599596D116802BAD422497CF68BE59EEB7A9135E3ED1C6BEACC48F73827161
                                                                                                                                                    SHA-512:05C0D33516B2C1AB6928FB34957AD3E03CB0A8B7EEC0FD627DD263589655A16DEA79100B6CC29095C3660C95FD2AFB2E4DD023F0597BD586DD664769CABB67F8
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g....."....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):352
                                                                                                                                                    Entropy (8bit):5.099295584967302
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbdOEq2PCHhJ23oH+Tcwt7Uh2ghZIFUtoPbdpXZmwCPbdEzkwOCHhJ23oH+T8:7GpOEvBYebIhHh2FUtopl/CpEz56Yebs
                                                                                                                                                    MD5:E8159B2410B48841B85E959D3DD4536F
                                                                                                                                                    SHA1:0979B6973A476D4A5B0549E382DCBC15682EDC32
                                                                                                                                                    SHA-256:0F21877AD88D58CFBFFE4188F539706EE07C612F4E9AB2FE69D6473102E2F2CE
                                                                                                                                                    SHA-512:A71391CCEAE2297CF902E59D0B61E74594BBE2E0634FE34E72E7C71942F23F2511BE125C76BCBFC00046974BA981F60661852CA71E9133DACA6EFEE887F8D094
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.922 1ec0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2025/03/13-12:38:03.923 1ec0 Recovering log #3.2025/03/13-12:38:03.924 1ec0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):352
                                                                                                                                                    Entropy (8bit):5.099295584967302
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbdOEq2PCHhJ23oH+Tcwt7Uh2ghZIFUtoPbdpXZmwCPbdEzkwOCHhJ23oH+T8:7GpOEvBYebIhHh2FUtopl/CpEz56Yebs
                                                                                                                                                    MD5:E8159B2410B48841B85E959D3DD4536F
                                                                                                                                                    SHA1:0979B6973A476D4A5B0549E382DCBC15682EDC32
                                                                                                                                                    SHA-256:0F21877AD88D58CFBFFE4188F539706EE07C612F4E9AB2FE69D6473102E2F2CE
                                                                                                                                                    SHA-512:A71391CCEAE2297CF902E59D0B61E74594BBE2E0634FE34E72E7C71942F23F2511BE125C76BCBFC00046974BA981F60661852CA71E9133DACA6EFEE887F8D094
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.922 1ec0 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/MANIFEST-000001.2025/03/13-12:38:03.923 1ec0 Recovering log #3.2025/03/13-12:38:03.924 1ec0 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Site Characteristics Database/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):270336
                                                                                                                                                    Entropy (8bit):0.0018238520723782249
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zEjp1:/M/xT02z81
                                                                                                                                                    MD5:6E12601699E9692B5364D847893AA719
                                                                                                                                                    SHA1:7BCE3B6FE4FDB3D6427D2C4D5AE35262A4835131
                                                                                                                                                    SHA-256:46AA85A4D1EE44E1F01FF64D7D06B6328E8F8A9AD274C95DC272AD6A1E3EE829
                                                                                                                                                    SHA-512:89D08E23185B0D04D215AB57725057C228820F6B7135D5D376F20ABE40669D08D66DC220C1780E2309D092499B4963C01431FD0119249A56A28B805B4A47E32E
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):270336
                                                                                                                                                    Entropy (8bit):0.0012471779557650352
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                    MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                    SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                    SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                    SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):270336
                                                                                                                                                    Entropy (8bit):0.0012471779557650352
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:MsEllllkEthXllkl2zE:/M/xT02z
                                                                                                                                                    MD5:F50F89A0A91564D0B8A211F8921AA7DE
                                                                                                                                                    SHA1:112403A17DD69D5B9018B8CEDE023CB3B54EAB7D
                                                                                                                                                    SHA-256:B1E963D702392FB7224786E7D56D43973E9B9EFD1B89C17814D7C558FFC0CDEC
                                                                                                                                                    SHA-512:BF8CDA48CF1EC4E73F0DD1D4FA5562AF1836120214EDB74957430CD3E4A2783E801FA3F4ED2AFB375257CAEED4ABE958265237D6E0AACF35A9EDE7A2E8898D58
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):434
                                                                                                                                                    Entropy (8bit):5.2497481272299655
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7G2AVvBYebvqBQFUtoAJAg/CACAI56YebvqBvJ:7tA5BYebvZgJJA2CAS6Yebvk
                                                                                                                                                    MD5:C8CF53D83C4143631BC0E9C541A90210
                                                                                                                                                    SHA1:1F53D04C8E30CA7128782A5CB16CBF6695DE2AA3
                                                                                                                                                    SHA-256:DE00BE8C695390C1BFAD5E10093A7C8EEFD630F073BE77E616413B33A5C0DB4D
                                                                                                                                                    SHA-512:BEFC3E2AB27616BCD7246B095DE740F1B5858786EF9B61A780839DDDD1F59DF317465BF774BE470E7126E2E85A163B05E02ACE67BE68922EF468841A5D2E08C3
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.886 1fb8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2025/03/13-12:38:04.891 1fb8 Recovering log #3.2025/03/13-12:38:04.894 1fb8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):434
                                                                                                                                                    Entropy (8bit):5.2497481272299655
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7G2AVvBYebvqBQFUtoAJAg/CACAI56YebvqBvJ:7tA5BYebvZgJJA2CAS6Yebvk
                                                                                                                                                    MD5:C8CF53D83C4143631BC0E9C541A90210
                                                                                                                                                    SHA1:1F53D04C8E30CA7128782A5CB16CBF6695DE2AA3
                                                                                                                                                    SHA-256:DE00BE8C695390C1BFAD5E10093A7C8EEFD630F073BE77E616413B33A5C0DB4D
                                                                                                                                                    SHA-512:BEFC3E2AB27616BCD7246B095DE740F1B5858786EF9B61A780839DDDD1F59DF317465BF774BE470E7126E2E85A163B05E02ACE67BE68922EF468841A5D2E08C3
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.886 1fb8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/MANIFEST-000001.2025/03/13-12:38:04.891 1fb8 Recovering log #3.2025/03/13-12:38:04.894 1fb8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Local Storage\leveldb/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):111
                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):111
                                                                                                                                                    Entropy (8bit):4.718418993774295
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YLb9N+eAXRfHDH2LS7PMVKJq0nMb1KKqk1Yn:YHpoeS7PMVKJTnMRKXk1Yn
                                                                                                                                                    MD5:807419CA9A4734FEAF8D8563A003B048
                                                                                                                                                    SHA1:A723C7D60A65886FFA068711F1E900CCC85922A6
                                                                                                                                                    SHA-256:AA10BF07B0D265BED28F2A475F3564D8DDB5E4D4FFEE0AB6F3A0CC564907B631
                                                                                                                                                    SHA-512:F10D496AE75DB5BA412BD9F17BF0C7DA7632DB92A3FABF7F24071E40F5759C6A875AD8F3A72BAD149DA58B3DA3B816077DF125D0D9F3544ADBA68C66353D206C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"net":{"http_server_properties":{"servers":[],"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"3G"}}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2
                                                                                                                                                    Entropy (8bit):1.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:H:H
                                                                                                                                                    MD5:D751713988987E9331980363E24189CE
                                                                                                                                                    SHA1:97D170E1550EEE4AFC0AF065B78CDA302A97674C
                                                                                                                                                    SHA-256:4F53CDA18C2BAA0C0354BB5F9A3ECBE5ED12AB4D8E11BA873C2F11161202B945
                                                                                                                                                    SHA-512:B25B294CB4DEB69EA00A4C3CF3113904801B6015E5956BD019A8570B1FE1D6040E944EF3CDEE16D0A46503CA6E659A25F21CF9CEDDC13F352A3C98138C15D6AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[]
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):40
                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 4, database pages 9, cookie 0x7, schema 4, UTF-8, version-valid-for 4
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):36864
                                                                                                                                                    Entropy (8bit):0.3886039372934488
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:TLqEeWOT/kIAoDJ84l5lDlnDMlRlyKDtM6UwccWfp15fBIe:T2EeWOT/nDtX5nDOvyKDhU1cSB
                                                                                                                                                    MD5:DEA619BA33775B1BAEEC7B32110CB3BD
                                                                                                                                                    SHA1:949B8246021D004B2E772742D34B2FC8863E1AAA
                                                                                                                                                    SHA-256:3669D76771207A121594B439280A67E3A6B1CBAE8CE67A42C8312D33BA18854B
                                                                                                                                                    SHA-512:7B9741E0339B30D73FACD4670A9898147BE62B8F063A59736AFDDC83D3F03B61349828F2AE88F682D42C177AE37E18349FD41654AEBA50DDF10CD6DC70FA5879
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g...}.....$.X..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):40
                                                                                                                                                    Entropy (8bit):4.1275671571169275
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:Y2ktGMxkAXWMSN:Y2xFMSN
                                                                                                                                                    MD5:20D4B8FA017A12A108C87F540836E250
                                                                                                                                                    SHA1:1AC617FAC131262B6D3CE1F52F5907E31D5F6F00
                                                                                                                                                    SHA-256:6028BD681DBF11A0A58DDE8A0CD884115C04CAA59D080BA51BDE1B086CE0079D
                                                                                                                                                    SHA-512:507B2B8A8A168FF8F2BDAFA5D9D341C44501A5F17D9F63F3D43BD586BC9E8AE33221887869FA86F845B7D067CB7D2A7009EFD71DDA36E03A40A74FEE04B86856
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"SDCH":{"dictionaries":{},"version":2}}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):80
                                                                                                                                                    Entropy (8bit):3.4921535629071894
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:S8ltHlS+QUl1ASEGhTFljl:S85aEFljl
                                                                                                                                                    MD5:69449520FD9C139C534E2970342C6BD8
                                                                                                                                                    SHA1:230FE369A09DEF748F8CC23AD70FD19ED8D1B885
                                                                                                                                                    SHA-256:3F2E9648DFDB2DDB8E9D607E8802FEF05AFA447E17733DD3FD6D933E7CA49277
                                                                                                                                                    SHA-512:EA34C39AEA13B281A6067DE20AD0CDA84135E70C97DB3CDD59E25E6536B19F7781E5FC0CA4A11C3618D43FC3BD3FBC120DD5C1C47821A248B8AD351F9F4E6367
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:*...#................version.1..namespace-..&f.................&f...............
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):422
                                                                                                                                                    Entropy (8bit):5.230425252528348
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7GhxvBYebvqBZFUtoh+c/Chx56YebvqBaJ:7q9BYebvygAej6YebvL
                                                                                                                                                    MD5:E8EF50BCB48FC5BD9D83847C632B50CA
                                                                                                                                                    SHA1:1D0D13E72FEA84124FD0EA76DDF444DCF7E8E9F5
                                                                                                                                                    SHA-256:033E224119E20243312EEC9990FF8554288709655E286BFCF2805AAE17913C83
                                                                                                                                                    SHA-512:E3FD516B27405CD729DB1BAF9E66DF84706EF1848B3E7F8DE089A1422A44370CD00DF947891A4DACFB832C5CB64EC8339E0CC9DBB55B4CC8BE5CAF523547FBED
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:23.244 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2025/03/13-12:38:23.245 1fa8 Recovering log #3.2025/03/13-12:38:23.249 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):422
                                                                                                                                                    Entropy (8bit):5.230425252528348
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:7GhxvBYebvqBZFUtoh+c/Chx56YebvqBaJ:7q9BYebvygAej6YebvL
                                                                                                                                                    MD5:E8EF50BCB48FC5BD9D83847C632B50CA
                                                                                                                                                    SHA1:1D0D13E72FEA84124FD0EA76DDF444DCF7E8E9F5
                                                                                                                                                    SHA-256:033E224119E20243312EEC9990FF8554288709655E286BFCF2805AAE17913C83
                                                                                                                                                    SHA-512:E3FD516B27405CD729DB1BAF9E66DF84706EF1848B3E7F8DE089A1422A44370CD00DF947891A4DACFB832C5CB64EC8339E0CC9DBB55B4CC8BE5CAF523547FBED
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:23.244 1fa8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/MANIFEST-000001.2025/03/13-12:38:23.245 1fa8 Recovering log #3.2025/03/13-12:38:23.249 1fa8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Storage\ext\ihmafllikibpmigkcoadcmckbfhibefp\def\Session Storage/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):328
                                                                                                                                                    Entropy (8bit):5.200925057113766
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbKzN+q2PCHhJ23oH+TcwtpIFUtoPbFXZmwCPbF3VkwOCHhJ23oH+Tcwta/Wd:7GmzIvBYebmFUtoBX/CBF56YebaUJ
                                                                                                                                                    MD5:B3E6296ED7C109770E5594CF2278F01F
                                                                                                                                                    SHA1:E53D7D6FD805C5DA2FF39523F66180EA4E75AF64
                                                                                                                                                    SHA-256:BE365C0B4946E9834A8C5FB4F3DF8C225386A63305F8AD17B838E33159D31296
                                                                                                                                                    SHA-512:CE2F1CB6D1512B9B5BEBD193848DA04BF1FD4D95C1EB77817D64CF9C0C22D7E78E9E0198FEE72F7D8ED9ACFA7A5D41B124F574DFCECDFE2D0005818F44C26C51
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.857 1ef8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2025/03/13-12:38:03.858 1ef8 Recovering log #3.2025/03/13-12:38:03.858 1ef8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):328
                                                                                                                                                    Entropy (8bit):5.200925057113766
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbKzN+q2PCHhJ23oH+TcwtpIFUtoPbFXZmwCPbF3VkwOCHhJ23oH+Tcwta/Wd:7GmzIvBYebmFUtoBX/CBF56YebaUJ
                                                                                                                                                    MD5:B3E6296ED7C109770E5594CF2278F01F
                                                                                                                                                    SHA1:E53D7D6FD805C5DA2FF39523F66180EA4E75AF64
                                                                                                                                                    SHA-256:BE365C0B4946E9834A8C5FB4F3DF8C225386A63305F8AD17B838E33159D31296
                                                                                                                                                    SHA-512:CE2F1CB6D1512B9B5BEBD193848DA04BF1FD4D95C1EB77817D64CF9C0C22D7E78E9E0198FEE72F7D8ED9ACFA7A5D41B124F574DFCECDFE2D0005818F44C26C51
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:03.857 1ef8 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2025/03/13-12:38:03.858 1ef8 Recovering log #3.2025/03/13-12:38:03.858 1ef8 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):131072
                                                                                                                                                    Entropy (8bit):0.0033769341339387224
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:ImtVuiv3e/l//DTL:IiVuivGb
                                                                                                                                                    MD5:7847B25B16B2A10AC150E0FCD36612BA
                                                                                                                                                    SHA1:5BD4FFC3D9EC134AA470502DFBED4D467ACA7D9F
                                                                                                                                                    SHA-256:F30597A072BE984AAE0E95FBD1579DFC37A48A7ECDC7B675DC8588CC4F45BDCE
                                                                                                                                                    SHA-512:593498F1BD2F2A5DE9D6A629393DC2ABEAFEC53DB954CD3C5ADDD6B5FE8A6331985496CFBD4BFA714783EE24B505DBA45D78DA7CBD9E28EB3E9AC341219D30AA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:VLnk.....?.........S{...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 10, database pages 91, cookie 0x36, schema 4, UTF-8, version-valid-for 10
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):196608
                                                                                                                                                    Entropy (8bit):1.265015599824541
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:384:8/2qOB1nxCkM8SAELyKOMq+8QTQKC+CVumG:Bq+n0J89ELyKOMq+8Q7t
                                                                                                                                                    MD5:A884D308E6AC75D0F9804F43ABA86233
                                                                                                                                                    SHA1:E5CF8BCEF54250419F8FAD76D31D8178CC055435
                                                                                                                                                    SHA-256:7B4E675C11B8A75C3AC72D57759F969FEA74933F4E3A92F2F489BF5AAF519FB1
                                                                                                                                                    SHA-512:9DC56294675243CDFF230DC810B15705E1DC7D5B669AB0199DCF3B0437B30BCF4788F27D407F0725CC1F4F0C348E9E1B2AF0079EC4AEECAD0E2BCDFFDB17A367
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ .......[...........6......................................................j............W........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 11, database pages 7, cookie 0xb, schema 4, UTF-8, version-valid-for 11
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):14336
                                                                                                                                                    Entropy (8bit):0.881692373900278
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:LL0jLuxhK3thdkSdj5QjUsEGcGBXp22iSBgwRrxjgm:fK3tjkSdj5IUltGhp22iSBgwR1j/
                                                                                                                                                    MD5:F880B690887A3EEE354C9C989BFEB735
                                                                                                                                                    SHA1:072B9C739D13F27A5FF258054FCD5DC0FF755B52
                                                                                                                                                    SHA-256:37467D0CF022FCF1221C770E660B21FF45977915FBE9AC6336226D13FB527E3B
                                                                                                                                                    SHA-512:70125E75EB09880FBEE68272E12039F9101E70E71D7D1EBAFCB50D7F343F9116204A0DC9F4FAA649677BD7326012F803C4EBC40FCF7EBA7634BC1D7191459352
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..................n..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 10, cookie 0x7, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):40960
                                                                                                                                                    Entropy (8bit):0.41235120905181716
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:Tnj7dojKsKmjKZKAsjZNOjAhts3N8g1j3UcB:v7doKsKuKZKlZNmu46yjx
                                                                                                                                                    MD5:981F351994975A68A0DD3ECE5E889FD0
                                                                                                                                                    SHA1:080D3386290A14A68FCE07709A572AF98097C52D
                                                                                                                                                    SHA-256:3F0C0B2460E0AA2A94E0BF79C8944F2F4835D2701249B34A13FD200F7E5316D7
                                                                                                                                                    SHA-512:C5930797C46EEC25D356BAEB6CFE37E9F462DEE2AE8866343B2C382DBAD45C1544EF720D520C4407F56874596B31EFD6822B58A9D3DAE6F85E47FF802DBAA20B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j.......w..g...........M...w..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with very long lines (3951), with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):11755
                                                                                                                                                    Entropy (8bit):5.190465908239046
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:hH4vrmqRBB4W4PoiUDNaxvR5FCHFcoaSbqGEDI:hH4vrmUB6W4jR3GaSbqGEDI
                                                                                                                                                    MD5:07301A857C41B5854E6F84CA00B81EA0
                                                                                                                                                    SHA1:7441FC1018508FF4F3DBAA139A21634C08ED979C
                                                                                                                                                    SHA-256:2343C541E095E1D5F202E8D2A0807113E69E1969AF8E15E3644C51DB0BF33FBF
                                                                                                                                                    SHA-512:00ADE38E9D2F07C64648202F1D5F18A2DFB2781C0517EAEBCD567D8A77DBB7CB40A58B7C7D4EC03336A63A20D2E11DD64448F020C6FF72F06CA870AA2B4765E0
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "DefaultCohort": {.. "21f3388b-c2a5-4791-8f6e-a4cad6d17f4f.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.BingHomePage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Covid.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Finance.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Jobs.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.KnowledgeCard.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Local.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NTP3PCLICK.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.NotifySearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Recipe.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.SearchPage.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Sports.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Travel.Bubble": 1,.. "2354565a-f412-4654-b89c-f92eaa9dbd20.Weather.Bubble": 1,.. "2cb2db96-3bd0-403e-abe2-9269b3761041.Bubble": 1,.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):40504
                                                                                                                                                    Entropy (8bit):5.561538794761135
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:sKy4Be7pLGLxtjWPRBfmu8F1+UoAYDCx9Tuqh0VfUC9xbog/OVSajUXTIrw+u7ev:sKy4BecxtjWPRBfmuu1jaXajYTZ+u7bm
                                                                                                                                                    MD5:330B045FF0A886950F79A1097C536979
                                                                                                                                                    SHA1:9515F4B0EC760283BD4153A431680975C6B49CD2
                                                                                                                                                    SHA-256:FF93A1EC58D854032BC3F43D3F8837F11EC67977419A1C3ADD642F446D9428EC
                                                                                                                                                    SHA-512:B812F85BC24F7AAE644D2DA445B7E7C4827A60443086437F05FAFFBB12DB5031F4E609847A21E3358267E91CCF4793696411EEE383C02A23288F23EB5B06EFA1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"edge_fundamentals_appdefaults":{"ess_lightweight_version":101},"ess_kv_states":{"restore_on_startup":{"closed_notification":false,"decrypt_success":true,"key":"restore_on_startup","notification_popup_count":0},"startup_urls":{"closed_notification":false,"decrypt_success":true,"key":"startup_urls","notification_popup_count":0},"template_url_data":{"closed_notification":false,"decrypt_success":true,"key":"template_url_data","notification_popup_count":0}},"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"explicit_host":[],"manifest_permissions":[],"scriptable_host":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"first_install_time":"13386357483832412","from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"last_update_time":"13386357483832412","location":5,"ma
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with very long lines (1597), with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):115717
                                                                                                                                                    Entropy (8bit):5.183660917461099
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:utDURN77GZqW3v6PD/469IxVBmB22q7LRks3swn0:utAaE2Jt0
                                                                                                                                                    MD5:3D8183370B5E2A9D11D43EBEF474B305
                                                                                                                                                    SHA1:155AB0A46E019E834FA556F3D818399BFF02162B
                                                                                                                                                    SHA-256:6A30BADAD93601FC8987B8239D8907BCBE65E8F1993E4D045D91A77338A2A5B4
                                                                                                                                                    SHA-512:B7AD04F10CD5DE147BDBBE2D642B18E9ECB2D39851BE1286FDC65FF83985EA30278C95263C98999B6D94683AE1DB86436877C30A40992ACA1743097A2526FE81
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "current_locale": "en-GB",.. "hub_apps": [ {.. "auto_show": {.. "enabled": true,.. "fre_notification": {.. "enabled": true,.. "header": "Was opening this pane helpful to you?",.. "show_count": 2,.. "text": "Was opening this pane helpful to you?".. },.. "settings_description": "We'll automatically open Bing Chat in the sidebar to show you relevant web experiences alongside your web content",.. "settings_title": "Automatically open Bing Chat in the sidebar",.. "triggering_configs|flight:msHubAppsMsnArticleAutoShowTriggering": [ {.. "show_count_basis": "signal",.. "signal_name": "IsMsnArticleAutoOpenFromP1P2",.. "signal_threshold": 0.5.. } ],.. "triggering_configs|flight:msUndersidePersistentChat": [ {.. "signal_name": "IsUndersidePersistentChatLink",.. "signal_threshold": 0.5.. } ],.. "triggering_co
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):13235
                                                                                                                                                    Entropy (8bit):5.266385288733429
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRJ99QTryDigabatSuygsFUIa3414bka3I88bV+FGaBQA48Oyf7NIoPqYJ:stRPGKSuLsFUXsJbG3BQx8Xf7NIO
                                                                                                                                                    MD5:A757554B1694D3CF5C90F2C8CE4E291A
                                                                                                                                                    SHA1:F16D750B46E4D7287681D5D63F6614A2A080FC54
                                                                                                                                                    SHA-256:E3A1EBD880D66555239BC5B7C1803F4DA61EB2EC6A63C3B0B77282A25E40809B
                                                                                                                                                    SHA-512:2E54D659B3B7F5730DC878D94BF43024FC450C24F1903A6DEA1C83FD3005B441843129F1F6EF36C52371EA72FDFD8D700991492A60DC640F65C7043698C673EA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite 3.x database, last written using SQLite version 3042000, file counter 1, database pages 7, cookie 0x4, schema 4, UTF-8, version-valid-for 1
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):28672
                                                                                                                                                    Entropy (8bit):0.3410017321959524
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:TLiqi/nGb0EiDFIlTSFbyrKZb9YwFOqAyl+FxOUwa5qgufTJpbZ75fOSG:TLiMNiD+lZk/Fj+6UwccNp15fBG
                                                                                                                                                    MD5:98643AF1CA5C0FE03CE8C687189CE56B
                                                                                                                                                    SHA1:ECADBA79A364D72354C658FD6EA3D5CF938F686B
                                                                                                                                                    SHA-256:4DC3BF7A36AB5DA80C0995FAF61ED0F96C4DE572F2D6FF9F120F9BC44B69E444
                                                                                                                                                    SHA-512:68B69FCE8EF5AB1DDA2994BA4DB111136BD441BC3EFC0251F57DC20A3095B8420669E646E2347EAB7BAF30CACA4BCF74BD88E049378D8DE57DE72E4B8A5FF74B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:SQLite format 3......@ ..........................................................................j..........g.....P....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):13026
                                                                                                                                                    Entropy (8bit):5.270569186098695
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRJ99QTryDigabatSuygsjUIa3414bka3I88bV+FGaBQA4hJq7NIoPqYJ:stRPGKSuLsjUXsJbG3BQxh07NIO
                                                                                                                                                    MD5:93C9DD1D5108BADAA693169ED1C46D0D
                                                                                                                                                    SHA1:B2C21BC5E355E28E8BA3CD66024A8DCA848E0852
                                                                                                                                                    SHA-256:926125EF330196B509DA83AA60EC1B346E74E351CE67E0A3B58DF7D118849542
                                                                                                                                                    SHA-512:8F1A496E6A6CE735F3812A417824EA12B8DF47EE3AA31CEB487A6F49BCAE4D6FF8055EFB18C1628F0C6E7F599BBAB1707BE04A6EC61182609CA7A89F465A745D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"history_in_shoreline_activated":true,"hub_app_non_synced_preferences":{"apps":{"06be1ebe-f23a-4bea-ae45-3120ad86cfea":{"last_path":""},"0c835d2d-9592-4c7a-8d0a-0e283c9ad3cd":{"last_path":""},"168a2510-04d5-473e-b6a0-828815a7ca5f":{"last_path":""},"1ec8a5a9-971c-4c82-a104-5e1a259456b8":{"last_path":""},"2354565a-f412-4654-b89c-f92eaa9dbd20":{"last_path":""},"25fe2d1d-e934-482a-a62f-ea1705db905d":{"last_path":""},"2caf0cf4-ea42-4083-b928-29b39da1182b":{"last_path":""},"2cb2db96-3bd0-403e-abe2-9269b3761041":{"last_path":""},"35a43603-bb38-4b53-ba20-932cb9117
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9659
                                                                                                                                                    Entropy (8bit):5.101009042837891
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:stRkdgsjUIa34Hka3I88bV+FGaBQA4hJq7NIoPqYJ:stRDsjUX3bG3BQxh07NIO
                                                                                                                                                    MD5:24662A78EA226D720B006031A56CC67E
                                                                                                                                                    SHA1:3A6ACE37ABDB4751ED1C12923A002F67D98227BA
                                                                                                                                                    SHA-256:678653E6BEDB1B5A44823C2E0D7EFC18645E6AA3541710E68E0C217B614AF27A
                                                                                                                                                    SHA-512:9B2AE4335C2940D4869A260A702358E962657E3A1752F2EF11C725D010572F1A7CC939C17CD1991F13D2D673AB612DD3FAC982C27E509631075454954C444801
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"aadc_info":{"age_group":0},"account_tracker_service_last_update":"13386357484449963","alternate_error_pages":{"backup":true},"apps":{"shortcuts_arch":"","shortcuts_version":0},"arbitration_experiences":{},"arbitration_local_nsat_reset_time":"13340968290017037","arbitration_using_experiment_config":false,"autocomplete":{"retention_policy_last_version":117},"browser":{"available_dark_theme_options":"All","has_seen_welcome_page":false,"should_reset_check_default_browser":false,"toolbar_extensions_hub_button_visibility":0,"underside_chat_bing_signed_in_status":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"browser_content_container_height":914,"browser_content_container_width":1236,"browser_content_container_x":0,"browser_content_container_y":70,"continuous_migration":{"ci_correction_for_holdout_treatment_state":1},"countryid_at_install":17224,"custom_links":{"li
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):32768
                                                                                                                                                    Entropy (8bit):0.05385464667923755
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:GtStutosCzt1StutosCz1R9XCChslotGLNl0ml/Vl/XoQXEl:Mt8trt81LpEjVl/PvoQ
                                                                                                                                                    MD5:B8C32A08C21D37F73B8EA6622F86BA7A
                                                                                                                                                    SHA1:BAAC3EFB2BF5A2436B948E986E10D0115BAABEAC
                                                                                                                                                    SHA-256:880791F2AE8A03718F244796FF8311C26532B4EA164EB3FDE440CFAEAE603243
                                                                                                                                                    SHA-512:3BAD79516451CF6C5CAA23B4FEAB52FCB854B24B6281E8784A4F9C0B267DB368C6091A8574961C84A3EA816D856A276BF1AF209C3920C5A757E91534EE80ED8F
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:..-.....................zYTI`..b.XE6.:.....@Y....-.....................zYTI`..b.XE6.:.....@Y..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:SQLite Write-Ahead Log, version 3007000
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):86552
                                                                                                                                                    Entropy (8bit):0.8699221626116067
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:9jUx1uT/r8ZNsZzMNsDKO5NszeRNsdtfYqMxqsm2:kmztFSyMbT5b2
                                                                                                                                                    MD5:867A24278798D91C776839361E552F81
                                                                                                                                                    SHA1:7DA0A2AA12E7D9404686BD5498A83E6A257E0779
                                                                                                                                                    SHA-256:B56640C409A5EC582917568AD0DE493BBCC51F229341146B0958D22024C181F2
                                                                                                                                                    SHA-512:50DE6074F1D69B8B33AA24F22CAFAE072EEBE2D6AE7BC3CEC0F95C9E45F044A2B609085CD2CC6AFD96819657CC992771BED12B60A3E3E1D056AB15EE86B2036D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:7....-...........XE6.:...,\...n..........XE6.:...^.J.~.SQLite format 3......@ ..........................................................................j.............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):514
                                                                                                                                                    Entropy (8bit):3.568668162657648
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:/XntM+dll3sedhO38WrOuuuuuuuuuuuuB9sedhOTEEEE:lllc8zWrOuuuuuuuuuuuuI8m
                                                                                                                                                    MD5:FCEF290D753BA88BE60DAFAE32C053D8
                                                                                                                                                    SHA1:EF8AE87B4B5B84135C20EA933E5C32BF8920E706
                                                                                                                                                    SHA-256:03492CD7E55E1F4BD5B39635C9DB8058FD233F32921578385D8390BAB23485B5
                                                                                                                                                    SHA-512:F8E37D051DCFB467DCF3E9154935943C4CC38FDFD952B26CF136D43D643925B15FE38A8D2C9910FE3F1169790F497020ADF976F915AAA51274BBB4EE42F11A6C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:A..r.................20_1_1...1.,U.................20_1_1...1....0................39_config..........6.....n ....1u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...............u}.=...................0................39_config..........6.....n ...1V.e................V.e................V.e................V.e................V.e................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.238679949605754
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbtQpryq2PCHhJ23oH+TcwtfrK+IFUtoPbtQ1U91ZmwCPbtQ1UrRkwOCHhJ2R:7GjvBYeb23FUto391/C3d56Yeb3J
                                                                                                                                                    MD5:33438508A5431347871B0CB4CF16D31A
                                                                                                                                                    SHA1:242B5C3E884B01403A23E9A2828C8B9145BCE778
                                                                                                                                                    SHA-256:EF4727526BCDC93D635FFC16AED3DA3A44F08B743B35C5840CA11B6FFF5EB9B4
                                                                                                                                                    SHA-512:9F7382AAB21E7FFC971454A01709F3393666FF0B14728AFE612BFC1226B9F46867295F073FBDB74F5CCC60191FC912D52775E93459A44FF1FDA90B6CD0E404FB
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.507 1e94 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.2025/03/13-12:38:04.508 1e94 Recovering log #3.2025/03/13-12:38:04.508 1e94 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):324
                                                                                                                                                    Entropy (8bit):5.238679949605754
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbtQpryq2PCHhJ23oH+TcwtfrK+IFUtoPbtQ1U91ZmwCPbtQ1UrRkwOCHhJ2R:7GjvBYeb23FUto391/C3d56Yeb3J
                                                                                                                                                    MD5:33438508A5431347871B0CB4CF16D31A
                                                                                                                                                    SHA1:242B5C3E884B01403A23E9A2828C8B9145BCE778
                                                                                                                                                    SHA-256:EF4727526BCDC93D635FFC16AED3DA3A44F08B743B35C5840CA11B6FFF5EB9B4
                                                                                                                                                    SHA-512:9F7382AAB21E7FFC971454A01709F3393666FF0B14728AFE612BFC1226B9F46867295F073FBDB74F5CCC60191FC912D52775E93459A44FF1FDA90B6CD0E404FB
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.507 1e94 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/MANIFEST-000001.2025/03/13-12:38:04.508 1e94 Recovering log #3.2025/03/13-12:38:04.508 1e94 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):787
                                                                                                                                                    Entropy (8bit):4.059252238767438
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:G0nYUtTNop//z3p/Uz0RuWlJhC+lvBavRtin01zvZDEtlkyBrgxvB1ys:G0nYUtypD3RUovhC+lvBOL+t3IvB8s
                                                                                                                                                    MD5:D8D8899761F621B63AD5ED6DF46D22FE
                                                                                                                                                    SHA1:23E6A39058AB3C1DEADC0AF2E0FFD0D84BB7F1BE
                                                                                                                                                    SHA-256:A5E0A78EE981FB767509F26021E1FA3C506F4E86860946CAC1DC4107EB3B3813
                                                                                                                                                    SHA-512:4F89F556138C0CF24D3D890717EB82067C5269063C84229E93F203A22028782902FA48FB0154F53E06339F2FDBE35A985CE728235EA429D8D157090D25F15A4E
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.h.6.................__global... .t...................__global... .9..b.................33_..........................33_........v.................21_.....vuNX.................21_.....<...................20_.....,.1..................19_.....QL.s.................18_.....<.J|.................37_...... .A.................38_..........................39_........].................20_.....Owa..................20_.....`..N.................19_.....D8.X.................18_......`...................37_..........................38_......\e..................39_.....dz.|.................9_.....'\c..................9_.......f-.................__global... .|.&R.................__global... ./....................__global... ..T...................__global... ...G..................__global... .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):342
                                                                                                                                                    Entropy (8bit):5.213039064944344
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbt6Upyq2PCHhJ23oH+TcwtfrzAdIFUtoPbt6U/1ZmwCPbtQBWlRkwOCHhJ2a:7GkZvBYeb9FUtokS1/CBz56Yeb2J
                                                                                                                                                    MD5:210D31AFA31299A2BB2D79A94956E276
                                                                                                                                                    SHA1:DFEC6143D106C50129E9F345A95960A7CD73449F
                                                                                                                                                    SHA-256:F0FF1FA0380C68FEEF3DEE1729AED71E606FB649EBF373F977A73EBAFC064A0F
                                                                                                                                                    SHA-512:37D1B01C68F83A6DC81D60C90B842D497A2555EEC463ADDEF06015ABA83073DCF07F776BE7AA0EDD8CFF8D07496B183565CD741BD9BAC25D120563997E1A3FFF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.492 1e94 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2025/03/13-12:38:04.492 1e94 Recovering log #3.2025/03/13-12:38:04.504 1e94 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):342
                                                                                                                                                    Entropy (8bit):5.213039064944344
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:iOGPbt6Upyq2PCHhJ23oH+TcwtfrzAdIFUtoPbt6U/1ZmwCPbtQBWlRkwOCHhJ2a:7GkZvBYeb9FUtokS1/CBz56Yeb2J
                                                                                                                                                    MD5:210D31AFA31299A2BB2D79A94956E276
                                                                                                                                                    SHA1:DFEC6143D106C50129E9F345A95960A7CD73449F
                                                                                                                                                    SHA-256:F0FF1FA0380C68FEEF3DEE1729AED71E606FB649EBF373F977A73EBAFC064A0F
                                                                                                                                                    SHA-512:37D1B01C68F83A6DC81D60C90B842D497A2555EEC463ADDEF06015ABA83073DCF07F776BE7AA0EDD8CFF8D07496B183565CD741BD9BAC25D120563997E1A3FFF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:2025/03/13-12:38:04.492 1e94 Reusing MANIFEST C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2025/03/13-12:38:04.492 1e94 Recovering log #3.2025/03/13-12:38:04.504 1e94 Reusing old log C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\shared_proto_db\metadata/000003.log .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):120
                                                                                                                                                    Entropy (8bit):3.32524464792714
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:tbloIlrJFlXnpQoWcNylRjlgbYnPdJiG6R7lZAUAl:tbdlrYoWcV0n1IGi7kBl
                                                                                                                                                    MD5:A397E5983D4A1619E36143B4D804B870
                                                                                                                                                    SHA1:AA135A8CC2469CFD1EF2D7955F027D95BE5DFBD4
                                                                                                                                                    SHA-256:9C70F766D3B84FC2BB298EFA37CC9191F28BEC336329CC11468CFADBC3B137F4
                                                                                                                                                    SHA-512:4159EA654152D2810C95648694DD71957C84EA825FCCA87B36F7E3282A72B30EF741805C610C5FA847CA186E34BDE9C289AAA7B6931C5B257F1D11255CD2A816
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t.\.E.d.g.e.\.A.p.p.l.i.c.a.t.i.o.n.\.m.s.e.d.g.e...e.x.e.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):13
                                                                                                                                                    Entropy (8bit):2.7192945256669794
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:NYLFRQI:ap2I
                                                                                                                                                    MD5:BF16C04B916ACE92DB941EBB1AF3CB18
                                                                                                                                                    SHA1:FA8DAEAE881F91F61EE0EE21BE5156255429AA8A
                                                                                                                                                    SHA-256:7FC23C9028A316EC0AC25B09B5B0D61A1D21E58DFCF84C2A5F5B529129729098
                                                                                                                                                    SHA-512:F0B7DF5517596B38D57C57B5777E008D6229AB5B1841BBE74602C77EEA2252BF644B8650C7642BD466213F62E15CC7AB5A95B28E26D3907260ED1B96A74B65FB
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:117.0.2045.47
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41715
                                                                                                                                                    Entropy (8bit):6.091785595894941
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4kcZLmZ9eo4Yq5ewWE7RTupzKscDX//NPC1ou:z/Ps+wsI7ynLoRTuiVIou
                                                                                                                                                    MD5:138E19A877DC35DF2A6BA646E8DD0631
                                                                                                                                                    SHA1:DA8CD12FCFBC862C1990874BC02225BDBF40285E
                                                                                                                                                    SHA-256:9E61D818F7165155EE86999F639A8FCC38B439A84F0DF0E766071CABC4A6BD43
                                                                                                                                                    SHA-512:3A8DED1CA51B0F12DA60B6FAA0B3F3B8E7BE7C73A3258985917290CE724345B434AC2C2B629684C95B88CD0C58A05FDD82B6017667F3A786B44ACBE17D6F8BEA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):47
                                                                                                                                                    Entropy (8bit):4.3818353308528755
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:2jRo6jhM6ceYcUtS2djIn:5I2uxUt5Mn
                                                                                                                                                    MD5:48324111147DECC23AC222A361873FC5
                                                                                                                                                    SHA1:0DF8B2267ABBDBD11C422D23338262E3131A4223
                                                                                                                                                    SHA-256:D8D672F953E823063955BD9981532FC3453800C2E74C0CC3653D091088ABD3B3
                                                                                                                                                    SHA-512:E3B5DB7BA5E4E3DE3741F53D91B6B61D6EB9ECC8F4C07B6AE1C2293517F331B716114BAB41D7935888A266F7EBDA6FABA90023EFFEC850A929986053853F1E02
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:customSettings_F95BA787499AB4FA9EFFF472CE383A14
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):35
                                                                                                                                                    Entropy (8bit):4.014438730983427
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YDMGA2ADH/AYKEqsYq:YQXT/bKE1F
                                                                                                                                                    MD5:BB57A76019EADEDC27F04EB2FB1F1841
                                                                                                                                                    SHA1:8B41A1B995D45B7A74A365B6B1F1F21F72F86760
                                                                                                                                                    SHA-256:2BAE8302F9BD2D87AE26ACF692663DF1639B8E2068157451DA4773BD8BD30A2B
                                                                                                                                                    SHA-512:A455D7F8E0BE9A27CFB7BE8FE0B0E722B35B4C8F206CAD99064473F15700023D5995CC2C4FAFDB8FBB50F0BAB3EC8B241E9A512C0766AAAE1A86C3472C589FFD
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"forceServiceDetermination":false}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):81
                                                                                                                                                    Entropy (8bit):4.3439888556902035
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:kDnaV6bVsFUIMf1HDOWg3djTHXoSWDSQ97P:kDYaoUIe1HDM3oskP
                                                                                                                                                    MD5:177F4D75F4FEE84EF08C507C3476C0D2
                                                                                                                                                    SHA1:08E17AEB4D4066AC034207420F1F73DD8BE3FAA0
                                                                                                                                                    SHA-256:21EE7A30C2409E0041CDA6C04EEE72688EB92FE995DC94487FF93AD32BD8F849
                                                                                                                                                    SHA-512:94FC142B3CC4844BF2C0A72BCE57363C554356C799F6E581AA3012E48375F02ABD820076A8C2902A3C6BE6AC4D8FA8D4F010D4FF261327E878AF5E5EE31038FB
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:edgeSettings_2.0-48b11410dc937a1723bf4c5ad33ecdb286d8ec69544241bc373f753e64b396c1
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):130439
                                                                                                                                                    Entropy (8bit):3.80180718117079
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:RlIyFAMrwvaGbyLWzDr6PDofI8vsUnPRLz+PMh:weWGP7Eh
                                                                                                                                                    MD5:EB75CEFFE37E6DF9C171EE8380439EDA
                                                                                                                                                    SHA1:F00119BA869133D64E4F7F0181161BD47968FA23
                                                                                                                                                    SHA-256:48B11410DC937A1723BF4C5AD33ECDB286D8EC69544241BC373F753E64B396C1
                                                                                                                                                    SHA-512:044C5113D877CE2E3B42CF07670620937ED7BE2D8B3BF2BAB085C43EF4F64598A7AC56328DDBBE7F0F3CFB9EA49D38CA332BB4ECBFEDBE24AE53B14334A30C8E
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "geoidMaps": {.. "au": "https://australia.smartscreen.microsoft.com/",.. "ch": "https://switzerland.smartscreen.microsoft.com/",.. "eu": "https://europe.smartscreen.microsoft.com/",.. "ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "in": "https://india.smartscreen.microsoft.com/",.. "test": "https://eu-9.smartscreen.microsoft.com/",.. "uk": "https://unitedkingdom.smartscreen.microsoft.com/",.. "us": "https://unitedstates.smartscreen.microsoft.com/",.. "gw_au": "https://australia.smartscreen.microsoft.com/",.. "gw_ch": "https://switzerland.smartscreen.microsoft.com/",.. "gw_eu": "https://europe.smartscreen.microsoft.com/",.. "gw_ffl4": "https://unitedstates1.ss.wd.microsoft.us/",.. "gw_ffl4mod": "https://unitedstates4.ss.wd.microsoft.us/",.. "gw_ffl5": "https://unitedstates2.ss.wd.microsoft.us/",.. "gw_in": "https
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):40
                                                                                                                                                    Entropy (8bit):4.346439344671015
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:kfKbUPVXXMVQX:kygV5
                                                                                                                                                    MD5:6A3A60A3F78299444AACAA89710A64B6
                                                                                                                                                    SHA1:2A052BF5CF54F980475085EEF459D94C3CE5EF55
                                                                                                                                                    SHA-256:61597278D681774EFD8EB92F5836EB6362975A74CEF807CE548E50A7EC38E11F
                                                                                                                                                    SHA-512:C5D0419869A43D712B29A5A11DC590690B5876D1D95C1F1380C2F773CA0CB07B173474EE16FE66A6AF633B04CC84E58924A62F00DCC171B2656D554864BF57A4
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:synchronousLookupUris_638343870221005468
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):57
                                                                                                                                                    Entropy (8bit):4.556488479039065
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:GSCIPPlzYxi21goD:bCWBYx99D
                                                                                                                                                    MD5:3A05EAEA94307F8C57BAC69C3DF64E59
                                                                                                                                                    SHA1:9B852B902B72B9D5F7B9158E306E1A2C5F6112C8
                                                                                                                                                    SHA-256:A8EF112DF7DAD4B09AAA48C3E53272A2EEC139E86590FD80E2B7CBD23D14C09E
                                                                                                                                                    SHA-512:6080AEF2339031FAFDCFB00D3179285E09B707A846FD2EA03921467DF5930B3F9C629D37400D625A8571B900BC46021047770BAC238F6BAC544B48FB3D522FB0
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:9.......murmur3.............,M.h...Z...8.\..<&Li.H..[.?m
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):29
                                                                                                                                                    Entropy (8bit):4.030394788231021
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:0xXeZUSXkcVn:0Re5kcV
                                                                                                                                                    MD5:52E2839549E67CE774547C9F07740500
                                                                                                                                                    SHA1:B172E16D7756483DF0CA0A8D4F7640DD5D557201
                                                                                                                                                    SHA-256:F81B7B9CE24F5A2B94182E817037B5F1089DC764BC7E55A9B0A6227A7E121F32
                                                                                                                                                    SHA-512:D80E7351E4D83463255C002D3FDCE7E5274177C24C4C728D7B7932D0BE3EBCFEB68E1E65697ED5E162E1B423BB8CDFA0864981C4B466D6AD8B5E724D84B4203B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:topTraffic_638004170464094982
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):575056
                                                                                                                                                    Entropy (8bit):7.999649474060713
                                                                                                                                                    Encrypted:true
                                                                                                                                                    SSDEEP:12288:fXdhUG0PlM/EXEBQlbk19RrH76Im4u8C1jJodha:Ji80e9Rb7Tm4u8CnR
                                                                                                                                                    MD5:BE5D1A12C1644421F877787F8E76642D
                                                                                                                                                    SHA1:06C46A95B4BD5E145E015FA7E358A2D1AC52C809
                                                                                                                                                    SHA-256:C1CE928FBEF4EF5A4207ABAFD9AB6382CC29D11DDECC215314B0522749EF6A5A
                                                                                                                                                    SHA-512:FD5B100E2F192164B77F4140ADF6DE0322F34D7B6F0CF14AED91BACAB18BB8F195F161F7CF8FB10651122A598CE474AC4DC39EDF47B6A85C90C854C2A3170960
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...._+jE.`..}....S..1....G}s..E....y".Wh.^.W.H...-...#.A...KR...9b........>k......bU.IVo...D......Y..[l.yx.......'c=..I0.....E.d...-...1 ....m../C...OQ.........qW..<:N.....38.u..X-..s....<..U.,Mi..._.......`.Y/.........^..,.E..........j@..G8..N.... ..Ea...4.+.79k.!T.-5W..!..@+..!.P..LDG.....V."....L.... .(#..$..&......C.....%A.T}....K_.S..'Q.".d....s....(j.D!......Ov..)*d0)."(..%..-..G..L.}....i.....m9;.....t.w..0....f?..-..M.c.3.....N7K.T..D>.3.x...z..u$5!..4..T.....U.O^L{.5..=E..'..;.}(|.6.:..f!.>...?M.8......P.D.J.I4.<...*.y.E....>....i%.6..Y.@..n.....M..r..C.f.;..<..0.H...F....h.......HB1]1....u..:...H..k....B.Q..J...@}j~.#...'Y.J~....I...ub.&..L[z..1.W/.Ck....M.......[.......N.F..z*.{nZ~d.V.4.u.K.V.......X.<p..cz..>*....X...W..da3(..g..Z$.L4.j=~.p.l.\.[e.&&.Y ...U)..._.^r0.,.{_......`S..[....(.\..p.bt.g..%.$+....f.....d....Im..f...W ......G..i_8a..ae..7....pS.....z-H..A.s.4.3..O.r.....u.S......a.}..v.-/..... ...a.x#./:...sS&U.().xL...pg
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:raw G3 (Group 3) FAX, byte-padded
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):460992
                                                                                                                                                    Entropy (8bit):7.999625908035124
                                                                                                                                                    Encrypted:true
                                                                                                                                                    SSDEEP:12288:KaRwcD8XXTZGZJHXBjOVX3xFttENr4+3eGPnKvJWXrydqb:KaR5oZ2MBFt8r4+3eG/URdqb
                                                                                                                                                    MD5:E9C502DB957CDB977E7F5745B34C32E6
                                                                                                                                                    SHA1:DBD72B0D3F46FA35A9FE2527C25271AEC08E3933
                                                                                                                                                    SHA-256:5A6B49358772DB0B5C682575F02E8630083568542B984D6D00727740506569D4
                                                                                                                                                    SHA-512:B846E682427CF144A440619258F5AA5C94CAEE7612127A60E4BD3C712F8FF614DA232D9A488E27FC2B0D53FD6ACF05409958AEA3B21EA2C1127821BD8E87A5CA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...2lI.5.<C.;.{....._+jE.`..}....-...#.A...KR...l.M0,s...).9..........x.......F.b......jU....y.h'....L<...*..Z..*%.*..._...g.4yu...........'c=..I0..........qW..<:N....<..U.,Mi..._......'(..U.9.!........u....7...4. ..Ea...4.+.79k.!T.-5W..!..@+..$..t|1.E..7F...+..xf....z&_Q...-.B...)8R.c....0.......B.M.Z...0....&v..<..H...3.....N7K.T..D>.8......P.D.J.I4.B.H.VHy...@.Wc.Cl..6aD..j.....E..*4..mI..X]2.GH.G.L...E.F.=.J...@}j~.#...'Y.L[z..1.W/.Ck....L..X........J.NYd........>...N.F..z*.{nZ~d.N..../..6.\L...Q...+.w..p...>.S.iG...0]..8....S..)`B#.v..^.*.T.?...Z.rz.D'.!.T.w....S..8....V.4.u.K.V.......W.6s...Y.).[.c.X.S..........5.X7F...tQ....z.L.X..(3#j...8...i.[..j$.Q....0...]"W.c.H..n..2Te.ak...c..-F(..W2.b....3.]......c.d|.../....._...f.....d....Im..g.b..R.q.<x*x...i2..r.I()Iat..b.j.r@K.+5..C.....nJ.>*P,.V@.....s.4.3..O.r.....smd7...L.....].u&1../t.*.......uXb...=@.....wv......]....#.{$.w......i.....|.....?....E7...}$+..t).E.U..Q..~.`.)..Y@.6.h.......%(
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9
                                                                                                                                                    Entropy (8bit):3.169925001442312
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:CMzOn:CM6
                                                                                                                                                    MD5:B6F7A6B03164D4BF8E3531A5CF721D30
                                                                                                                                                    SHA1:A2134120D4712C7C629CDCEEF9DE6D6E48CA13FA
                                                                                                                                                    SHA-256:3D6F3F8F1456D7CE78DD9DFA8187318B38E731A658E513F561EE178766E74D39
                                                                                                                                                    SHA-512:4B473F45A5D45D420483EA1D9E93047794884F26781BBFE5370A554D260E80AD462E7EEB74D16025774935C3A80CBB2FD1293941EE3D7B64045B791B365F2B63
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:uriCache_
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):179
                                                                                                                                                    Entropy (8bit):5.0150699476095815
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YTyLSmafBoTfIOXq9J2ADozRLuLgfGBkGAeekVy8HfzXNPIAciR7abY:YWLSGTILr2ADo9LuLgfGBPAzkVj/T82X
                                                                                                                                                    MD5:22EC7F571064A479A80D50F5CB538BA2
                                                                                                                                                    SHA1:70E2623AFA1CD5F952217246D5C9C18099A8ED48
                                                                                                                                                    SHA-256:D3E3F4CC4614056784CF115D3EBD3490CDE0A6B7086FA1598DB57809637822DF
                                                                                                                                                    SHA-512:5574DBC94208B9F4BC650728ADDD2B1D196B47092EB2F8327E5BE7D4F926B102B50F1903FE2159C6C2369C56704E650B1D6EE0736C58A6F5D99857AA20EF28C3
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"version":1,"cache_data":[{"file_hash":"04b10122f6b8ecf9","server_context":"1;f94c025f-7523-6972-b613-ce2c246c55ce;unkn:100;0.01","result":1,"expiration_time":1741984688969719}]}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):86
                                                                                                                                                    Entropy (8bit):4.3751917412896075
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:YQ3JYq9xSs0dMEJAELJ2rjozQan:YQ3Kq9X0dMgAEwjM
                                                                                                                                                    MD5:961E3604F228B0D10541EBF921500C86
                                                                                                                                                    SHA1:6E00570D9F78D9CFEBE67D4DA5EFE546543949A7
                                                                                                                                                    SHA-256:F7B24F2EB3D5EB0550527490395D2F61C3D2FE74BB9CB345197DAD81B58B5FED
                                                                                                                                                    SHA-512:535F930AFD2EF50282715C7E48859CC2D7B354FF4E6C156B94D5A2815F589B33189FFEDFCAF4456525283E993087F9F560D84CFCF497D189AB8101510A09C472
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"user_experience_metrics.stability.exited_cleanly":false,"variations_crash_streak":0}
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):41771
                                                                                                                                                    Entropy (8bit):6.091130751407088
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:zDXzgWPsj/qlGJqIY8GB4xMZLmZdpobQKVyPOYwWE7RTupzKscDX//NPC1ou:z/Ps+wsI7yOXoRTuiVIou
                                                                                                                                                    MD5:8BA61F494EF0EC3A5A92BB9FC2044935
                                                                                                                                                    SHA1:F4C1F3DE647FA48B6A08FDB2F977B1C943356CA8
                                                                                                                                                    SHA-256:679FB556E8B967D49402B297B5CC8094317473407F8C8180EAF7EBA43AC6513D
                                                                                                                                                    SHA-512:AF8A0BB0E3A490A7151D084473372763D4C2D5A7BB73B4B6709969583B940DD080E3476B9BCA195DDF609C7C7021D03D18797843DA6ABFF6A1B64204E1F6371D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"229EC35087C81534A88F41A12F3A505F330A0BE57C43F6CEB29F4718042EFC4F\"","desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL19a4/cNpboXzH60+4gRbvbrzj7aTbj2Ql2MhlkswhwF4MGRVISWxQp81FVqkH++z2HUrXbLkndh51dBHba1XX4PDzvxz+v+P76VjipxG2teExe3YpWie7W7ZX3Wqqr7/55xYfBaMGjdjZcffc/8wdK3g4OPh+vvrv6aYg/pXj1zZV0PdcWPrEq1kYfmXD91W/fUEBCTFK7MEH+45urDKHVNLPlvXoIHMcB//3H/fX3uIk/T3v4HrcwfweHgL0EWPzVd9e/fXMlZE/dnTXjx+Pggvq74ePPisvx4bqD0bbZ2Og99K8w415b9RA4usTivgSy50f4WTHYRQE0r0TxkvcMIVQpvOHvmY4lkMdaWx3H0okPPIoWVi/cFl5uDqEbWICCMbxrAKlKh6lMUiL5PY4UWn5ggpcM0yp8Ynv4jYve2dLVCA978oD/ouXWKlM6jo08toiSpffjDoNXQdkYBpOKD3ffHgufVJtMKp0Vvs4+JS06uJShdJA/6dD+0Y6HVnm1TQAXSdJMDfEjnz/CJVxAPJh4Brj/5JJYZtZAI5d/gW/+WP9F7UWmyTTSsQFstY3KSrd5MJfw8x4ffriwzR5P5lZboOXq2cwPcaHxvO+5N1vU6gKw18K74OqIVMGrwcGWi+B3/fhgiJ2sSYzY4W5ZcE8FcFZJr/eKGfyLMJOray0KIOCL4cFk21LCwm0jIsXbWhuge7fO3sKot+GggT0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):42819
                                                                                                                                                    Entropy (8bit):6.084067416983097
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:mMkbJ6eg6KzhXRLtkCXt5iLmZeJpobQKVyPOwZbsamC1oKwWE7RTupzKscDX//N/:mMk16zRRSCX4rRsamIoKoRTuiB
                                                                                                                                                    MD5:D50B0C5EF56854A614EE9D9D7A8E5035
                                                                                                                                                    SHA1:A28F6A80ECEEFE36687289FD2CBC74799C25357C
                                                                                                                                                    SHA-256:E2FABEE74F247EC45A78EFA5361790539B09D526B1ED79BA84D780857BFF7DD1
                                                                                                                                                    SHA-512:574E54245B8C59C7963C6DDF5C6115F2D6ECAB6123EBE8A2C4F5AAB4CB66169EDE913FFFD5558B0A3ADF6D062FA95A1604B4FBF61A2103668B6C47A1088F1895
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm3rXSyzABnWdKBG+Ijlx7hEE4QTzo+AB6fnDLLJBpo7PKv8Ob367/KjUg
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):42819
                                                                                                                                                    Entropy (8bit):6.084073543106639
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:768:mMkbJ6eg6KzhXRLtkCXt5iLmZxpobQKVyPOwZbsamC1oKwWE7RTupzKscDX//Nq2:mMk16zRRSCXdRsamIoKoRTuiB
                                                                                                                                                    MD5:28997D8D5969986F525214EB944AEA40
                                                                                                                                                    SHA1:C81B1656CBD32B6C58D01CDAACB4CB717DCE0E62
                                                                                                                                                    SHA-256:F43A73FCA79EE6C6078EB4930A492FAD18B59DE0B85C35C5DB1D9AEA26F24190
                                                                                                                                                    SHA-512:46D44578EE95A4C848C4015087342DEFD65854B4FF1985D7F369CD535BC3BB0B2E3B22EB5F0584CE113F8FE15AB5D80A005AB8DD1A4B0C0559E8007FEB2FCD69
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"abusive_adblocker_etag":"\"5E25271B8190D943537AD3FDB50874FC133E8B4A00380E2A6A888D63386F728B\"","browser":{"browser_build_version":"117.0.2045.47","browser_version_of_last_seen_whats_new":"117.0.2045.47","last_seen_whats_new_page_version":"117.0.2045.47"},"desktop_mode":{"clear_prefs_once_applied":true,"is_on":false,"is_on_by_default_applied":true,"is_search_only_on_by_default_applied":true},"domain_actions_config":"H4sIAAAAAAAAAL1dWZPktpH+KxP9ZDtU6GMujfykHY9txVpHyHIoYh2ODhBEkWiCAAdHVbEc/u+bCVb1dE8RqEqOdh806mbzw8VEXshM/PuKb27vha2luF9LHqKT96KVoru3G+mcquXVN/++4sOgleBBWeOvvvnn4YGs7wcLz8erb65+HMKPMVx9dVXbnisDT4wMa612TNj+6j9fUSA+xFpZPyH/9dVVQig59Wx4L5+Cwzjg799ubt/jJP48zeE9TuHwDjYBc/Ew+Ktvbv/z1ZWoe+rsjB4/7Abr5U+ajz9LXo9Px+21Mk1hoo/oX6HHjTLyKTjYyMJmCbLnO/hZMpjFAjSvxOIhbxgi5FK85m+ZCkuQu7UyKoxLO97yIFoYvbAluiw2oRoYgIQ2nG2AqJY2U+koRXQbbMm3fMsEX9JMK3GLbeAvNjhrlo5GOJiTA/oXLTdG6qXtmMBDiyS59PvY7eCklyb4QcfFi7tpdwu3VBt1XNorvM4+RiU6+CjD0kb+pHz7rRm3rXSyzABnWdKBG+Ijlx7hEE4QTzo+AB6fnDLLJBpo7PKv8Ob367/KjUg
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2278
                                                                                                                                                    Entropy (8bit):3.8546029751196103
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:uiTrlKxrgxGUxl9Il8uDkfb0tenBhAvHcEDACLG2nd1rc:mjoYSb0gg9DXKr
                                                                                                                                                    MD5:4721FDB4868A3CB27295179F15F81E0D
                                                                                                                                                    SHA1:8A086521A0A655F6C22E3375E431E78B1E8BA9CF
                                                                                                                                                    SHA-256:DB0479808E9CE1FE3A73D8A1A529438C9FFEBB0843088FA4B2F385335C1F3E58
                                                                                                                                                    SHA-512:633A723D2F3D8283784A87FD313CE2E24C03DA45B2F8F59F9372BA15E909ADF783271C723F7A7E8FCCA83A704BA5B69BFD454EED9E1F9905ED5748024E21263E
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".W.i.p.w.W.M.+.N.H.l.b.C.D.m.s.Z.p.8.S.O.s.j.h.t.F.B.s.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".g.O.l.B.r.j.6.U.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.g.S.v.8.f.J.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4622
                                                                                                                                                    Entropy (8bit):4.005158727022975
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:jRYRm1oGEanKvd6g/IiMtwM66wVA6wAThr:VSHGEYU/Z69BE
                                                                                                                                                    MD5:37E5A8D713B22068C7A0292C7F532AE1
                                                                                                                                                    SHA1:52A160AF27D1EFCC4315D9DD2B95ABDE33183D6B
                                                                                                                                                    SHA-256:027226C8D3ED32E397149E32237EFF9D3BCEC13484CE3249C775AE846496984D
                                                                                                                                                    SHA-512:88CB9564B4D350B1FC87146562733310849B50CA28EDE0365B085038FB49165372928E65A5273312E191448C38DD1995C02FFD6432A4D921D9D732846188D6D7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".z.3.U.T.q.T.b.3.7./.u.z.h.i.f.l.b.4.0.f.z.h.D.r.E.s.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.F.e.l.D.a.U.2.w.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.g.S.v.8.f.J.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2684
                                                                                                                                                    Entropy (8bit):3.9023424113897898
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:uiTrlKx68Wa7xjxl9Il8uD9rBQApsixiOLylSVd/vc:a9YXriWsixfylSU
                                                                                                                                                    MD5:F85E3DAF05FEB139B4C2C881C5AD5410
                                                                                                                                                    SHA1:455C2C7E8AF5ADE05638926DD794D38466EAFA7D
                                                                                                                                                    SHA-256:65DC5B1B547D7A25EBDE84512E3D77BAFB6D996A59DFC678F8F144F1E6B64A47
                                                                                                                                                    SHA-512:2F8D47E9C8112AC374CA3E29FE3E5E7E14894376AA77655FEF484C255FCF3E2C56D9BA2338714329C5C503B8354AFC2BF333BEFBEACCF21BB55CCF00FEE343BF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".6.N.3.U.y.9.n.A.U.E.q.s.5.u.9.6.E./.o.g.0.E./.V.J.A.g.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.f.Y.h.x.Q.e.z.3.A.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.g.S.v.8.f.J.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):154545
                                                                                                                                                    Entropy (8bit):7.839678617100523
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:zZH5WPD5SqCJryow8AWTtwGrasOQNHjWRKnvXTwL:zpIPFCXjAWTtwGusOWmMvjwL
                                                                                                                                                    MD5:EAE462C55EBA847A1A8B58E58976B253
                                                                                                                                                    SHA1:4D7C9D59D6AE64EB852BD60B48C161125C820673
                                                                                                                                                    SHA-256:EBCDA644BCFBD0C9300227BAFDE696E8923DDB004B4EE619D7873E8A12EAE2AD
                                                                                                                                                    SHA-512:494481A98AB6C83B16B4E8D287D85BA66499501545DA45458ACC395DA89955971CF2A14E83C2DA041C79C580714B92B9409AA14017A16D0B80A7FF3D91BAD2A3
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[...................h...|..=.Ih.\...T.....}..u0...HVND......R....~D.H$9w._2.3.2...5.H.V.@....k;..c.V.7s....9o`_3qP{}....*.G....5.:.m..]..:.w|'..lG.../..,...G....g...O..}....K.Hk......T>..F7G.!n..h.j...J...XzbG..*..kK]!z..;.K.U.......1:..7w.....6...N.I!....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...H0F.!...j9%2/.....(-.C.....].=....I.a..!......k..,i.....T.m.xM.W4.)`0..6R".%............m..8.....|.#......`..L0~..F-....B%.Bh.......H....R..~...Z....7Q...y....?.....[......t........J.R^....o....?.%....3h...8.....e..0.v..33.Si...._....3.d.S...Y....b.....O.s$......~...)l..g._.);.S.......yn@.....3iG.).I76.]..].t_..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 135363
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):76326
                                                                                                                                                    Entropy (8bit):7.9961120748813075
                                                                                                                                                    Encrypted:true
                                                                                                                                                    SSDEEP:1536:hS5Vvm808scZeEzFrSpzBUl4MZIGM/iysAGz8vBBrYunau6wp:GdS8scZNzFrMa4M+lKqeu/nr
                                                                                                                                                    MD5:01E352D35675990A139199DD86B38AAC
                                                                                                                                                    SHA1:E16163C81E5F36B3B819AA0A63BFA63D88548A91
                                                                                                                                                    SHA-256:148CDE42D38C62C1A1E8B8D3D4BD8830F0F8C2DC684E3C59B0A510E31011CA4A
                                                                                                                                                    SHA-512:75A58FFAD6E3E0546268CC863AE382B5429795D8BCED64BAE2D06BCEEB6C2E37BD656A3E335EB61B521888B76913F2D0281F8C9C081FF8637307AE5934D98C8B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...........m{..(.}...7.\...N.D*.w..m..q....%XfL.*I.ql..;/.....s...E...0....`..A..[o^.^Y...F_.'.*.."L...^.......Y..W..l...E0..YY...:.&.u?....J..U<.q."...p.ib:.g.*.^.q.mr.....^&.{.E.....,EAp.q.......=.=.....z^.,d.^..J.R..zI4..2b?.-D5/.^...+.G..Y..?5..k........i.,.T#........_DV....P..d2......b\..L....o....Z.}../....CU.$.-..D9`..~......=....._.2O..?....b.{...7IY.L..q....K....T..5m.d.s.4.^... ..~<..7~6OS..b...^>.......s..n....k."..G.....L...z.U...... ... .ZY...,...kU1..N...(..V.r\$..s...X.It...x.mr..W....g........9DQR....*d......;L.S.....G... .._D.{.=.zI.g.Y~...`T..p.yO..4......8$..v.J..I.%..._.d.[..du5._._...?\..8.c.....U...fy.t....q.t....T@.......:zu..\,.!.I..AN_.....FeX..h.c.i.W.......(.....Y..F...R%.\..@.. 2(e,&.76..F+...l.t.$..`...........Wi.{.U.&(.b}...}.i..,...k....!..%...&.c..D-."..SQ.......q9....)j....7.".N....AX...).d./giR....uk.....s.....^...........:...~......(hP..K.@.&..?.E0:+D|9...U.q.cu..)t{.e...X...{.....z......LL&I6.=.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):11185
                                                                                                                                                    Entropy (8bit):7.951995436832936
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                    MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                    SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                    SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                    SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:false
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Joe Sandbox View:
                                                                                                                                                    • Filename: PDFizer_no_update.msi, Detection: malicious, Browse
                                                                                                                                                    • Filename: Let's_20Compress.exe, Detection: malicious, Browse
                                                                                                                                                    • Filename: recibatt- 533152.msi, Detection: malicious, Browse
                                                                                                                                                    • Filename: SecuriteInfo.com.BScope.Trojan.Agentb.20481.11202.msi, Detection: malicious, Browse
                                                                                                                                                    • Filename: NF84.js, Detection: malicious, Browse
                                                                                                                                                    • Filename: nf963-5d-qns6-w812.msi, Detection: malicious, Browse
                                                                                                                                                    • Filename: ScreenBeam_Conference_Windows_1.0.5.9.msi, Detection: malicious, Browse
                                                                                                                                                    • Filename: 1eSOBjseu2.msi, Detection: malicious, Browse
                                                                                                                                                    • Filename: 2024.0198840 298135.msi, Detection: malicious, Browse
                                                                                                                                                    • Filename: hForm.0198840 739798.msi, Detection: malicious, Browse
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:false
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:false
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1366x720, components 3
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):206855
                                                                                                                                                    Entropy (8bit):7.983996634657522
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:5WcDW3D2an0GMJGqJCj+1ZxdmdopHjHTFYPQyairiVoo4XSWrPoiXvJddppWmEI5:l81Lel7E6lEMVo/S01fDpWmEgD
                                                                                                                                                    MD5:788DF0376CE061534448AA17288FEA95
                                                                                                                                                    SHA1:C3B9285574587B3D1950EE4A8D64145E93842AEB
                                                                                                                                                    SHA-256:B7FB1D3C27E04785757E013EC1AC4B1551D862ACD86F6888217AB82E642882A5
                                                                                                                                                    SHA-512:3AA9C1AA00060753422650BBFE58EEEA308DA018605A6C5287788C3E2909BE876367F83B541E1D05FE33F284741250706339010571D2E2D153A5C5A107D35001
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:......Exif..II*.................Ducky.......2......Adobe.d...........................................................#"""#''''''''''..................................................!! !!''''''''''........V.."....................................................................................!1..AQ..aq."2....R..T....Br.#S.U..b..3Cs...t6.c.$D.5uV...4d.E&....%F......................!1..AQaq....."2......BRbr3CS....#..4.............?......1f.n..T......TP....E...........P.....@.........E..@......E.P........@........E.....P.P..A@@.E..@.P.P..AP.P..AP..@....T..AP.E..P.Z .. ....."... .....7.H...w.....t.....T....M.."... P..n.n..t5..*B.P..*(.................*.....................( ..................*.. .".... .".......(.. .".....*.. ....o......E.6... ..*..."........."J......Ah......@.@@....:@{6..wCp..3...((.(......................*...@..(...."....................*......*.. ........T.......@.@@........AP.P..@.E@....E@.d.E@.@@..@.P.T..@..@..P.D...@M........EO..."...=.wCp.....R......P.@......
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1420
                                                                                                                                                    Entropy (8bit):5.390998455125411
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:YJxF5sQ5szAW01Rp5yK10YO5qv70VhQu5Fa02GMLA5nGM2c002GMfr5M:YJxF5sQ5sEW01X5y60YO5qD0VH5Fa0hH
                                                                                                                                                    MD5:4D339BEB662161F82D42AE17E1C216D4
                                                                                                                                                    SHA1:E49FFDF98F60D668BC7AD54A966CC12A2D3E6D18
                                                                                                                                                    SHA-256:8DDB6669872750384CCBCE6F4F855A418C66B9D90F9A5E4D60D68C693759DDA1
                                                                                                                                                    SHA-512:B8F3FE92962D04D475F083D2C5EB76BA12AC30A08E44F1EF3D0E3A52DE2D56CCB4EFB4317A5B3AC9DD667BA3F76C4A3D6994680108EDB96700E2D6C920DA9176
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"logTime": "1005/081724", "correlationVector":"2/PmMr7SOFFRIqTwW+HesJ","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/081729", "correlationVector":"mBsci4p0IuAlecFQAh3IDU","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/081729", "correlationVector":"EFCCE5F7ECC74238A0D17C500D8EB81C","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1005/083130", "correlationVector":"jkXXrPbML/1ucIa5c7okZ6","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/083130", "correlationVector":"CECEB17551BE48CCBF3DD12E07118D84","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1005/083241", "correlationVector":"WUtA7xoJfeUJPFSRRtPAng","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/083242", "correlationVector":"B7F67C44DD3147F7BE748158D3F8E7B5","action":"FETCH_UX_CONFIG", "result":""}.{"logTime": "1005/083444", "correlationVector":"6kKZpL8SvSsrBcj/Fl+tva","action":"EXTENSION_UPDATER", "result":""}.{"logTime": "1005/083445", "correlationVector":"94D95442
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:very short file (no magic)
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:L:L
                                                                                                                                                    MD5:5058F1AF8388633F609CADB75A75DC9D
                                                                                                                                                    SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                                                                                                                                    SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                                                                                                                                    SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:PNG image data, 228 x 53, 8-bit/color RGBA, non-interlaced
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3589
                                                                                                                                                    Entropy (8bit):7.939061221715785
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:iY+hL7M8ZSwuuRuP8tv7uhiqX9KmxESyHqvjqRP:QBGAuHKmnra
                                                                                                                                                    MD5:141CA9177FB1E0937705238260A0C0C5
                                                                                                                                                    SHA1:1B607D5FF95A359A4FEBF4A64B7E9FE7205FF29E
                                                                                                                                                    SHA-256:5AAD8DCF975AFF28E19EA4FE7BF7319B00284458239442F068DA086E42475B97
                                                                                                                                                    SHA-512:AEC5DE1895DD3E8D8BBFCD39C5A1377DE194AF7B8C18ED3C273F49C1EE45AC7F8295892D5039D8E19AD34482803F1BA2A8047EBF8BADCA0C3DD257A6006CD3FF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.PNG........IHDR.......5.....Q5G.....IDATx..]A....}8...O.......l......'...\>.o.`pp.io.X....p.f..(U..R.SJ..L...h.RYU(S..TV.t:.[......................W|.t.-.F.'.F.nI.....`<.tY.x.w....q5.....a..&..X._.+r.....>.t[..}..j~,....+......-.?.....`<%...x2...._M..PD.u....M . ..~.0.o...u....0..;..t.D.Yl....QN2}..i..b..0......M..b[).TX......gh.... .@.a...#..p...t....:n..2w...P..~.......a.F.H.=.x.....4.B..<}..?...#h^....i|.G4.(_Pjh.3........o....j..`.*G.n...{.n...Yl'.F.a.i.O...b..4.O..)x.Q..f.C..O.....a..~a....`<...&_.;.?u.....P.....?...A..|cI..v.0%....vF.K..8Wr..j...dM.]X...Ih@.;........=z..yC.L.z<....}b~.;...7Hy.{..`.......D .......X.F6...O(.y.h.'.&X1.k(.W..r......X...`^WH..}Hc...q.2....w..........j.T.3.%....YlU.U:q.Yl..~S..|.,....s|.....1..!4.8G.@.W...>...".$.....M...g.:..{.2<3Y...M.Cs.....H....e$.A....:R...(....B....K.'.0.0A9.l.w.......'.0...[......Yl...E...m.p.,~.$?...bx~../?C..+.!.H..........xg.{MW\..&.......ug..@.{24.~K.A.]Pr.....|.-...Q..H ..f.*
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):11185
                                                                                                                                                    Entropy (8bit):7.951995436832936
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:YEKh1jNlwQbamjq6Bcykrs3kAVg55GzVQM5F+XwsxNv7/lsoltBq0WG4ZeJTmrRb:fKT/BAzA05Gn5F+XV7NNltrWG4kJTm1b
                                                                                                                                                    MD5:78E47DDA17341BED7BE45DCCFD89AC87
                                                                                                                                                    SHA1:1AFDE30E46997452D11E4A2ADBBF35CCE7A1404F
                                                                                                                                                    SHA-256:67D161098BE68CD24FEBC0C7B48F515F199DDA72F20AE3BBB97FCF2542BB0550
                                                                                                                                                    SHA-512:9574A66D3756540479DC955C4057144283E09CAE11CE11EBCE801053BB48E536E67DC823B91895A9E3EE8D3CB27C065D5E9030C39A26CBF3F201348385B418A5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........N.......E#......9e.u.q...VYY..@.+.C..k.O..bK.`..6.G..%.....3Z...e _.6....F..1p..K.Z......./ .3...OT..`..0...Y...FT..43.th.y...}....p.L...2S.&i.`..o...f.oH.....N..:..ijT.3.F{.0.,.f?'f.CQt;b_"Pc.. ..~S.I.c.8Z.;.....{G.a......k...>.`.o..%.$>;.....g.............jg?.R..@.:..........&..{...x@.Py..;kT....%F".S..w...N....9...A..@X.t!i.@..1;......1E..X.....[.~$....J......;=T.;)k..Y...$......S......M.P..P..>..=..u.....2p...w.9..1qw.a\A..Vj .C.....A..Cf1.r6.A...L. _m...[..l.Wr_../.. .B..9!.!+..ZG.K.......0.."0...*.H.............0.........^SUd%Q.L].......Cl2o...\[.....'*...;R=....N.C5....d. .....J.C>u.kr..Y..syJC.XS.q..E.n?....(G.5..)2.G..!.M.SS.{..U....!.EE..M[.#qs.A.1...g)nQ.c..G....Bd..7... .O.BI..KXQ..4.d.K.0......g.....-p....Z.E{...M&.~n.TE7..{0....5.#.C+3.y)pd9.e.........@..3.9..B.....I....2nX........2.?.~..S....]G.N.....Lr.O.Ve....9..D1.G..W)...P.?=.#..7.R.lz..a.wX.e..h.h.~....v..RP.@X....d.G
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1753
                                                                                                                                                    Entropy (8bit):5.8889033066924155
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:Pxpr7Xka2NXDpfsBJODI19Kg1JqcJW9O//JE3ZBDcpu/x:L3XgNSz9/4kIO3u3Xgpq
                                                                                                                                                    MD5:738E757B92939B24CDBBD0EFC2601315
                                                                                                                                                    SHA1:77058CBAFA625AAFBEA867052136C11AD3332143
                                                                                                                                                    SHA-256:D23B2BA94BA22BBB681E6362AE5870ACD8A3280FA9E7241B86A9E12982968947
                                                                                                                                                    SHA-512:DCA3E12DD5A9F1802DB6D11B009FCE2B787E79B9F730094367C9F26D1D87AF1EA072FF5B10888648FB1231DD83475CF45594BB0C9915B655EE363A3127A5FFC2
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[.. {.. "description": "treehash per file",.. "signed_content": {.. "payload": "eyJpdGVtX2lkIjoiam1qZmxnanBjcGVwZWFmbW1nZHBma29na2doY3BpaGEiLCJpdGVtX3ZlcnNpb24iOiIxLjIuMSIsInByb3RvY29sX3ZlcnNpb24iOjEsImNvbnRlbnRfaGFzaGVzIjpbeyJmb3JtYXQiOiJ0cmVlaGFzaCIsImRpZ2VzdCI6InNoYTI1NiIsImJsb2NrX3NpemUiOjQwOTYsImhhc2hfYmxvY2tfc2l6ZSI6NDA5NiwiZmlsZXMiOlt7InBhdGgiOiJjb250ZW50LmpzIiwicm9vdF9oYXNoIjoiQS13R1JtV0VpM1lybmxQNktneUdrVWJ5Q0FoTG9JZnRRZGtHUnBEcnp1QSJ9LHsicGF0aCI6ImNvbnRlbnRfbmV3LmpzIiwicm9vdF9oYXNoIjoiVU00WVRBMHc5NFlqSHVzVVJaVTFlU2FBSjFXVENKcHhHQUtXMGxhcDIzUSJ9LHsicGF0aCI6Im1hbmlmZXN0Lmpzb24iLCJyb290X2hhc2giOiJKNXYwVTkwRmN0ejBveWJMZmZuNm5TbHFLU0h2bHF2YkdWYW9FeWFOZU1zIn1dfV19",.. "signatures": [.. {.. "header": {.. "kid": "publisher".. },.. "protected": "eyJhbGciOiJSUzI1NiJ9",.. "signature": "UglEEilkOml5P1W0X6wc-_dB87PQB73uMir11923av57zPKujb4IUe_lbGpn7cRZsy6x-8i9eEKxAW7L2TSmYqrcp4XtiON6ppcf27FWACXOUJDax9wlMr-EOtyZhykCnB9vR
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (8031), with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9815
                                                                                                                                                    Entropy (8bit):6.1716321262973315
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3zEScQZBMX:+ThBVq3npozftROQIyVfjRZGB365Ey97
                                                                                                                                                    MD5:3D20584F7F6C8EAC79E17CCA4207FB79
                                                                                                                                                    SHA1:3C16DCC27AE52431C8CDD92FBAAB0341524D3092
                                                                                                                                                    SHA-256:0D40A5153CB66B5BDE64906CA3AE750494098F68AD0B4D091256939EEA243643
                                                                                                                                                    SHA-512:315D1B4CC2E70C72D7EB7D51E0F304F6E64AC13AE301FD2E46D585243A6C936B2AD35A0964745D291AE9B317C316A29760B9B9782C88CC6A68599DB531F87D59
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:Unicode text, UTF-8 text, with very long lines (8604), with no line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):10388
                                                                                                                                                    Entropy (8bit):6.174387413738973
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:+ThBV4L3npstQp6VRtROQGZ0UyVg4jq4HWeGBnUi65Ep4HdlyKyjFN3EbmE1F4fn:+ThBVq3npozftROQIyVfjRZGB365Ey9+
                                                                                                                                                    MD5:3DE1E7D989C232FC1B58F4E32DE15D64
                                                                                                                                                    SHA1:42B152EA7E7F31A964914F344543B8BF14B5F558
                                                                                                                                                    SHA-256:D4AA4602A1590A4B8A1BCE8B8D670264C9FB532ADC97A72BC10C43343650385A
                                                                                                                                                    SHA-512:177E5BDF3A1149B0229B6297BAF7B122602F7BD753F96AA41CCF2D15B2BCF6AF368A39BB20336CCCE121645EC097F6BEDB94666C74ACB6174EB728FBFC43BC2A
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:(()=>{"use strict";var e={1:(e,o)=>{Object.defineProperty(o,"__esModule",{value:!0}),o.newCwsPromotionalButtonCta=o.chromeToEdgeCwsButtonCtaMapping=void 0,o.chromeToEdgeCwsButtonCtaMapping={"...... ... Chrome":"...... ....","........ .. Chrome":".....",........:"..........",".......... .. Chrome":"..........","Chrome . .....":"...","Chrome .... ....":"....","Afegeix a Chrome":"Obt.n","Suprimeix de Chrome":"Suprimeix","P.idat do Chromu":"Z.skat","Odstranit z Chromu":"Odebrat","F.j til Chrome":"F.","Fjern fra Chrome":"Fjerne",Hinzuf.gen:"Abrufen","Aus Chrome entfernen":"Entfernen","Add to Chrome":"Get","Remove from Chrome":"Remove","A.adir a Chrome":"Obtener",Desinstalar:"Quitar","Agregar a Chrome":"Obtener","Eliminar de Chrome":"Quitar","Lisa Chrome'i":"Hangi","Chrome'ist eemaldamine":"Eemalda",.......H:"........","......... ... .. Chr
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):962
                                                                                                                                                    Entropy (8bit):5.698567446030411
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1Hg9+D3DRnbuF2+sUrzUu+Y9VwE+Fg41T1O:NBqY+6E+F7JO
                                                                                                                                                    MD5:E805E9E69FD6ECDCA65136957B1FB3BE
                                                                                                                                                    SHA1:2356F60884130C86A45D4B232A26062C7830E622
                                                                                                                                                    SHA-256:5694C91F7D165C6F25DAF0825C18B373B0A81EA122C89DA60438CD487455FD6A
                                                                                                                                                    SHA-512:049662EF470D2B9E030A06006894041AE6F787449E4AB1FBF4959ADCB88C6BB87A957490212697815BB3627763C01B7B243CF4E3C4620173A95795884D998A75
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "content_scripts": [ {.. "js": [ "content.js" ],.. "matches": [ "https://chrome.google.com/webstore/*" ].. }, {.. "js": [ "content_new.js" ],.. "matches": [ "https://chromewebstore.google.com/*" ].. } ],.. "description": "Edge relevant text changes on select websites to improve user experience and precisely surfaces the action they want to take.",.. "key": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAu06p2Mjoy6yJDUUjCe8Hnqvtmjll73XqcbylxFZZWe+MCEAEK+1D0Nxrp0+IuWJL02CU3jbuR5KrJYoezA36M1oSGY5lIF/9NhXWEx5GrosxcBjxqEsdWv/eDoOOEbIvIO0ziMv7T1SUnmAA07wwq8DXWYuwlkZU/PA0Mxx0aNZ5+QyMfYqRmMpwxkwPG8gyU7kmacxgCY1v7PmmZo1vSIEOBYrxl064w5Q6s/dpalSJM9qeRnvRMLsszGY/J2bjQ1F0O2JfIlBjCOUg/89+U8ZJ1mObOFrKO4um8QnenXtH0WGmsvb5qBNrvbWNPuFgr2+w5JYlpSQ+O8zUCb8QZwIDAQAB",.. "manifest_version": 3,.. "name": "Edge relevant text changes",.. "update_url": "https://edge.microsoft.com/extensionwebstorebase/v1/crx",.. "version": "1.2.1"..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:Google Chrome extension, version 3
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):154545
                                                                                                                                                    Entropy (8bit):7.839678617100523
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:zZH5WPD5SqCJryow8AWTtwGrasOQNHjWRKnvXTwL:zpIPFCXjAWTtwGusOWmMvjwL
                                                                                                                                                    MD5:EAE462C55EBA847A1A8B58E58976B253
                                                                                                                                                    SHA1:4D7C9D59D6AE64EB852BD60B48C161125C820673
                                                                                                                                                    SHA-256:EBCDA644BCFBD0C9300227BAFDE696E8923DDB004B4EE619D7873E8A12EAE2AD
                                                                                                                                                    SHA-512:494481A98AB6C83B16B4E8D287D85BA66499501545DA45458ACC395DA89955971CF2A14E83C2DA041C79C580714B92B9409AA14017A16D0B80A7FF3D91BAD2A3
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:Cr24..............0.."0...*.H.............0.........^...1"...w.g..t..2J.G1.)X4..=&.?[j,Lz..j.u.e[I.q*Ba/X...P.h..L.....2%3_o.......H.)'.=.e...?.......j..3UH.|.X.M..u..s[.*..?$....F%....I....)..,-./.e5).f..O.q.^........9..(.._.ph2..^.YBPXf_8....h[.v...S.*1`.#..5.SF.:f-.#.65.i..b.]9...y2.'....k[...................h...|..=.Ih.\...T.....}..u0...HVND......R....~D.H$9w._2.3.2...5.H.V.@....k;..c.V.7s....9o`_3qP{}....*.G....5.:.m..]..:.w|'..lG.../..,...G....g...O..}....K.Hk......T>..F7G.!n..h.j...J...XzbG..*..kK]!z..;.K.U.......1:..7w.....6...N.I!....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...H0F.!...j9%2/.....(-.C.....].=....I.a..!......k..,i.....T.m.xM.W4.)`0..6R".%............m..8.....|.#......`..L0~..F-....B%.Bh.......H....R..~...Z....7Q...y....?.....[......t........J.R^....o....?.%....3h...8.....e..0.v..33.Si...._....3.d.S...Y....b.....O.s$......~...)l..g._.);.S.......yn@.....3iG.).I76.]..].t_..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4982
                                                                                                                                                    Entropy (8bit):7.929761711048726
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:L7Rf7U1ylWb3KfyEfOXE+PIcvBirQFiAql1ZwKREkXCSAk:pTvWqfD+gl0sAql1u7kySAk
                                                                                                                                                    MD5:913064ADAAA4C4FA2A9D011B66B33183
                                                                                                                                                    SHA1:99EA751AC2597A080706C690612AEEEE43161FC1
                                                                                                                                                    SHA-256:AFB4CE8882EF7AE80976EBA7D87F6E07FCDDC8E9E84747E8D747D1E996DEA8EB
                                                                                                                                                    SHA-512:162BF69B1AD5122C6154C111816E4B87A8222E6994A72743ED5382D571D293E1467A2ED2FC6CC27789B644943CF617A56DA530B6A6142680C5B2497579A632B5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.PNG........IHDR..............>a....=IDATx..]}...U..;...O.Q..QH.I(....v..E....GUb*..R[.4@%..hK..B..(.B..". ....&)U#.%...jZ...JC.8.....{.cfvgf.3;.....}ow.....{...P.B...*T.P.B...*Tx...=.Q..wv.w.....|.e.1.$.P.?..l_\.n.}...~.g.....Q...A.f....m.....{,...C2 %..X.......FE.1.N..f...Q..D.K87.....:g..Q.{............3@$.8.....{.....q....G.. .....5..y......)XK..F...D.......... ."8...J#.eM.i....H.E.....a.RIP.`......)..T.....! .[p`X.`..L.a....e. .T..2.....H..p$..02...j....\..........s{...Ymm~.a........f.$./.[.{..C.2:.0..6..]....`....NW.....0..o.T..$;k.2......_...k..{,.+........{..6...L..... .dw...l$..}...K...EV....0......P...e....k....+Go....qw.9.1...X2\..qfw0v.....N...{...l.."....f.A..I..+#.v....'..~E.N-k.........{...l.$..ga..1...$......x$X=}.N..S..B$p..`..`.ZG:c..RA.(.0......Gg.A.I..>...3u.u........_..KO.m.........C...,..c.......0...@_..m...-..7.......4LZ......j@.......\..'....u. QJ.:G..I`.w'B0..w.H..'b.0- ......|..}./.....e..,.K.1........W.u.v. ...\.o
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):908
                                                                                                                                                    Entropy (8bit):4.512512697156616
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgMTCBxNB+kCIww3v+BBJ/wjsV8lCBxeBeRiGTCSU8biHULaBg/4srCBhUJJ:1HAkkJ+kCIwEg/wwbw0PXa22QLWmSDg
                                                                                                                                                    MD5:12403EBCCE3AE8287A9E823C0256D205
                                                                                                                                                    SHA1:C82D43C501FAE24BFE05DB8B8F95ED1C9AC54037
                                                                                                                                                    SHA-256:B40BDE5B612CFFF936370B32FB0C58CC205FC89937729504C6C0B527B60E2CBA
                                                                                                                                                    SHA-512:153401ECDB13086D2F65F9B9F20ACB3CEFE5E2AEFF1C31BA021BE35BF08AB0634812C33D1D34DA270E5693A8048FC5E2085E30974F6A703F75EA1622A0CA0FFD
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SKEP NUWE".. },.. "explanationofflinedisabled": {.. "message": "Jy is vanlyn. As jy Google Dokumente sonder 'n internetverbinding wil gebruik, moet jy die volgende keer as jy aan die internet gekoppel is na instellings op die Google Dokumente-tuisblad gaan en vanlynsinkronisering aanskakel.".. },.. "explanationofflineenabled": {.. "message": "Jy is vanlyn, maar jy kan nog steeds beskikbare l.ers redigeer of nuwes skep.".. },.. "extdesc": {.. "message": "Skep, wysig en bekyk jou dokumente, sigblaaie en aanbiedings . alles sonder toegang tot die internet.".. },.. "extname": {.. "message": "Google Vanlyn Dokumente".. },.. "learnmore": {.. "message": "Kom meer te wete".. },.. "popuphelptext": {.. "message": "Skryf, redigeer en werk saam, waar jy ook al is, met of sonder 'n internetverbinding.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1285
                                                                                                                                                    Entropy (8bit):4.702209356847184
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAn6bfEpxtmqMI91ivWjm/6GcCIoToCZzlgkX/Mj:W6bMt3MITFjm/Pcd4oCZhg6k
                                                                                                                                                    MD5:9721EBCE89EC51EB2BAEB4159E2E4D8C
                                                                                                                                                    SHA1:58979859B28513608626B563138097DC19236F1F
                                                                                                                                                    SHA-256:3D0361A85ADFCD35D0DE74135723A75B646965E775188F7DCDD35E3E42DB788E
                                                                                                                                                    SHA-512:FA3689E8663565D3C1C923C81A620B006EA69C99FB1EB15D07F8F45192ED9175A6A92315FA424159C1163382A3707B25B5FC23E590300C62CBE2DACE79D84871
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... ...".. },.. "explanationofflinedisabled": {.. "message": "..... .. .... Google ..... ........ ..... ..... .Google .... ... .. .. .. ..... .... ....... .. ....... ... .. .. ..... .. ..... ....".. },.. "explanationofflineenabled": {.. "message": "..... .. .... ... .. .... .... ..... .... ... ..... .... .....".. },.. "extdesc": {.. "message": "...... ..... .... ... .. ..... ...... ..... .... .. ..... . .... .. ...... .....".. },.. "extname": {.. "message": "..... .. Goog
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1244
                                                                                                                                                    Entropy (8bit):4.5533961615623735
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgPCBxNhieFTr9ogjIxurIyJCCBxeh6wAZKn7uCSUhStuysUm+WCBhSueW1Y:1HAgJzoaC6VEn7Css8yoXzzd
                                                                                                                                                    MD5:3EC93EA8F8422FDA079F8E5B3F386A73
                                                                                                                                                    SHA1:24640131CCFB21D9BC3373C0661DA02D50350C15
                                                                                                                                                    SHA-256:ABD0919121956AB535E6A235DE67764F46CFC944071FCF2302148F5FB0E8C65A
                                                                                                                                                    SHA-512:F40E879F85BC9B8120A9B7357ED44C22C075BF065F45BEA42BD5316AF929CBD035D5D6C35734E454AEF5B79D378E51A77A71FA23F9EBD0B3754159718FCEB95C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ....".. },.. "explanationofflinedisabled": {.. "message": "... ... ...... ........ ....... Google ... ..... .......... ..... ... ......... .. ...... ........ ........ Google ..... ........ ... ..... .. ..... ....... .... .... .... ..........".. },.. "explanationofflineenabled": {.. "message": "... ... ...... .... .. .... ....... ..... ....... ....... .. ..... ..... ......".. },.. "extdesc": {.. "message": "..... ......... ...... ........ ....... ......... ........ ....... .. ... ... ..... .........".. },.. "extname": {.. "message": "....... Google ... ......".. },.. "learnmore": {.. "messa
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):977
                                                                                                                                                    Entropy (8bit):4.867640976960053
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAWNjbwlmyuAoW32Md+80cVLdUSERHtRo3SjX:J3wlzs42m+8TV+S4H0CjX
                                                                                                                                                    MD5:9A798FD298008074E59ECC253E2F2933
                                                                                                                                                    SHA1:1E93DA985E880F3D3350FC94F5CCC498EFC8C813
                                                                                                                                                    SHA-256:628145F4281FA825D75F1E332998904466ABD050E8B0DC8BB9B6A20488D78A66
                                                                                                                                                    SHA-512:9094480379F5AB711B3C32C55FD162290CB0031644EA09A145E2EF315DA12F2E55369D824AF218C3A7C37DD9A276AEEC127D8B3627D3AB45A14B0191ED2BBE70
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "YEN.S.N. YARADIN".. },.. "explanationofflinedisabled": {.. "message": "Oflayns.n.z. Google S.n.di internet ba.lant.s. olmadan istifad. etm.k ist.yirsinizs., Google S.n.din .sas s.hif.sind. ayarlara gedin v. n.vb.ti d.f. internet. qo.ulanda oflayn sinxronizasiyan. aktiv edin.".. },.. "explanationofflineenabled": {.. "message": "Oflayns.n.z, amma m.vcud fayllar. redakt. ed. v. yenil.rini yarada bil.rsiniz.".. },.. "extdesc": {.. "message": "S.n.d, c.dv.l v. t.qdimatlar.n ham.s.n. internet olmadan redakt. edin, yarad.n v. bax.n.".. },.. "extname": {.. "message": "Google S.n.d Oflayn".. },.. "learnmore": {.. "message": ".trafl. M.lumat".. },.. "popuphelptext": {.. "message": "Harda olma..n.zdan v. internet. qo.ulu olub-olmad...n.zdan as.l. olmayaraq, yaz.n, redakt. edin v. .m.kda.l.q edin.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3107
                                                                                                                                                    Entropy (8bit):3.535189746470889
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:YOWdTQ0QRk+QyJQAy6Qg4QWSe+QECTQLHQlQIfyQ0fnWQjQDrTQik+QvkZTQ+89b:GdTbyRvwgbCTEHQhyVues9oOT3rOCkV
                                                                                                                                                    MD5:68884DFDA320B85F9FC5244C2DD00568
                                                                                                                                                    SHA1:FD9C01E03320560CBBB91DC3D1917C96D792A549
                                                                                                                                                    SHA-256:DDF16859A15F3EB3334D6241975CA3988AC3EAFC3D96452AC3A4AFD3644C8550
                                                                                                                                                    SHA-512:7FF0FBD555B1F9A9A4E36B745CBFCAD47B33024664F0D99E8C080BE541420D1955D35D04B5E973C07725573E592CD0DD84FDBB867C63482BAFF6929ADA27CCDE
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u0421\u0422\u0412\u0410\u0420\u042b\u0426\u042c \u041d\u041e\u0412\u042b"},"explanationofflinedisabled":{"message":"\u0412\u044b \u045e \u043f\u0430\u0437\u0430\u0441\u0435\u0442\u043a\u0430\u0432\u044b\u043c \u0440\u044d\u0436\u044b\u043c\u0435. \u041a\u0430\u0431 \u043a\u0430\u0440\u044b\u0441\u0442\u0430\u0446\u0446\u0430 \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u043c\u0456 Google \u0431\u0435\u0437 \u043f\u0430\u0434\u043a\u043b\u044e\u0447\u044d\u043d\u043d\u044f \u0434\u0430 \u0456\u043d\u0442\u044d\u0440\u043d\u044d\u0442\u0443, \u043f\u0435\u0440\u0430\u0439\u0434\u0437\u0456\u0446\u0435 \u0434\u0430 \u043d\u0430\u043b\u0430\u0434 \u043d\u0430 \u0433\u0430\u043b\u043e\u045e\u043d\u0430\u0439 \u0441\u0442\u0430\u0440\u043e\u043d\u0446\u044b \u0414\u0430\u043a\u0443\u043c\u0435\u043d\u0442\u0430\u045e Google \u0456 \u045e\u043a\u043b\u044e\u0447\u044b\u0446\u0435 \u0441\u0456\u043d\u0445\u0440\u0430\u043d\u0456\u0437\u0430\u0446\u044b\u044e
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1389
                                                                                                                                                    Entropy (8bit):4.561317517930672
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAp1DQqUfZ+Yann08VOeadclUZbyMzZzsYvwUNn7nOyRK8/nn08V7:g1UTfZ+Ya08Uey3tflCRE08h
                                                                                                                                                    MD5:2E6423F38E148AC5A5A041B1D5989CC0
                                                                                                                                                    SHA1:88966FFE39510C06CD9F710DFAC8545672FFDCEB
                                                                                                                                                    SHA-256:AC4A8B5B7C0B0DD1C07910F30DCFBDF1BCB701CFCFD182B6153FD3911D566C0E
                                                                                                                                                    SHA-512:891FCDC6F07337970518322C69C6026896DD3588F41F1E6C8A1D91204412CAE01808F87F9F2DEA1754458D70F51C3CEF5F12A9E3FC011165A42B0844C75EC683
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. .. .......... Google ......... ... ........ ......, ........ ........... . ......... ........ .. Google ......... . ........ ...... .............. ......... ..., ...... ..... ...... . .........".. },.. "explanationofflineenabled": {.. "message": "...... ..., .. ... ...... .. ........... ......... ....... ... .. ......... .....".. },.. "extdesc": {.. "message": "............, .......... . ............ ...... ........., .......... ....... . ........... . ...... .... ... ...... .. .........".. },..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1763
                                                                                                                                                    Entropy (8bit):4.25392954144533
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HABGtNOtIyHmVd+q+3X2AFl2DhrR7FAWS9+SMzI8QVAEq8yB0XtfOyvU7D:oshmm/+H2Ml2DrFPS9+S99EzBd7D
                                                                                                                                                    MD5:651375C6AF22E2BCD228347A45E3C2C9
                                                                                                                                                    SHA1:109AC3A912326171D77869854D7300385F6E628C
                                                                                                                                                    SHA-256:1DBF38E425C5C7FC39E8077A837DF0443692463BA1FBE94E288AB5A93242C46E
                                                                                                                                                    SHA-512:958AA7CF645FAB991F2ECA0937BA734861B373FB1C8BCC001599BE57C65E0917F7833A971D93A7A6423C5F54A4839D3A4D5F100C26EFA0D2A068516953989F9D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .... ....".. },.. "explanationofflinedisabled": {.. "message": ".... ....... ....... .... ......... ..... ..... Google ........ ....... ...., Google .......... ........ ....... ... ... .... ... .... ... ........... .... ....... .... ... ...... ..... .... .....".. },.. "explanationofflineenabled": {.. "message": ".... ....... ......, ...... .... .... ...... .......... ........ .... .. .... .... .... .... .......".. },.. "extdesc":
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):930
                                                                                                                                                    Entropy (8bit):4.569672473374877
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvggoSCBxNFT0sXuqgEHQ2fTq9blUJYUJaw9CBxejZFPLOjCSUuE44pMiiDat:1HAtqs+BEHGpURxSp1iUPWCAXtRKe
                                                                                                                                                    MD5:D177261FFE5F8AB4B3796D26835F8331
                                                                                                                                                    SHA1:4BE708E2FFE0F018AC183003B74353AD646C1657
                                                                                                                                                    SHA-256:D6E65238187A430FF29D4C10CF1C46B3F0FA4B91A5900A17C5DFD16E67FFC9BD
                                                                                                                                                    SHA-512:E7D730304AED78C0F4A78DADBF835A22B3D8114FB41D67B2B26F4FE938B572763D3E127B7C1C81EBE7D538DA976A7A1E7ADC40F918F88AFADEA2201AE8AB47D0
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREA'N UN DE NOU".. },.. "explanationofflinedisabled": {.. "message": "No tens connexi.. Per utilitzar Documents de Google sense connexi. a Internet, ves a la configuraci. de la p.gina d'inici d'aquest servei i activa l'opci. per sincronitzar-se sense connexi. la propera vegada que estiguis connectat a la xarxa.".. },.. "explanationofflineenabled": {.. "message": "Tot i que no tens connexi., pots editar o crear fitxers.".. },.. "extdesc": {.. "message": "Edita, crea i consulta documents, fulls de c.lcul i presentacions, tot sense acc.s a Internet.".. },.. "extname": {.. "message": "Documents de Google sense connexi.".. },.. "learnmore": {.. "message": "M.s informaci.".. },.. "popuphelptext": {.. "message": "Escriu text, edita fitxers i col.labora-hi siguis on siguis, amb o sense connexi. a Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):913
                                                                                                                                                    Entropy (8bit):4.947221919047
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgdsbCBxNBmobXP15Dxoo60n40h6qCBxeBeGG/9jZCSUKFPDLZ2B2hCBhPLm:1HApJmoZ5e50nzQhwAd7dvYB2kDSGGKs
                                                                                                                                                    MD5:CCB00C63E4814F7C46B06E4A142F2DE9
                                                                                                                                                    SHA1:860936B2A500CE09498B07A457E0CCA6B69C5C23
                                                                                                                                                    SHA-256:21AE66CE537095408D21670585AD12599B0F575FF2CB3EE34E3A48F8CC71CFAB
                                                                                                                                                    SHA-512:35839DAC6C985A6CA11C1BFF5B8B5E59DB501FCB91298E2C41CB0816B6101BF322445B249EAEA0CEF38F76D73A4E198F2B6E25EEA8D8A94EA6007D386D4F1055
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "VYTVO.IT".. },.. "explanationofflinedisabled": {.. "message": "Jste offline. Pokud chcete Dokumenty Google pou..vat bez p.ipojen. k.internetu, a. budete p...t. online, p.ejd.te do nastaven. na domovsk. str.nce Dokument. Google a.zapn.te offline synchronizaci.".. },.. "explanationofflineenabled": {.. "message": "Jste offline, ale st.le m..ete upravovat dostupn. soubory nebo vytv..et nov..".. },.. "extdesc": {.. "message": "Upravujte, vytv..ejte a.zobrazujte sv. dokumenty, tabulky a.prezentace . v.e bez p..stupu k.internetu.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Dal.. informace".. },.. "popuphelptext": {.. "message": "Pi.te, upravujte a.spolupracujte kdekoli, s.p.ipojen.m k.internetu i.bez n.j.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):806
                                                                                                                                                    Entropy (8bit):4.815663786215102
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:YGo35xMxy6gLr4Dn1eBVa1xzxyn1VFQB6FDVgdAJex9QH7uy+XJEjENK32J21j:Y735+yoeeRG54uDmdXx9Q7u3r83Xj
                                                                                                                                                    MD5:A86407C6F20818972B80B9384ACFBBED
                                                                                                                                                    SHA1:D1531CD0701371E95D2A6BB5EDCB79B949D65E7C
                                                                                                                                                    SHA-256:A482663292A913B02A9CDE4635C7C92270BF3C8726FD274475DC2C490019A7C9
                                                                                                                                                    SHA-512:D9FBF675514A890E9656F83572208830C6D977E34D5744C298A012515BC7EB5A17726ADD0D9078501393BABD65387C4F4D3AC0CC0F7C60C72E09F336DCA88DE7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"CREU NEWYDD"},"explanationofflinedisabled":{"message":"Rydych chi all-lein. I ddefnyddio Dogfennau Google heb gysylltiad \u00e2'r rhyngrwyd, ewch i'r gosodiadau ar dudalen hafan Dogfennau Google a throi 'offine sync' ymlaen y tro nesaf y byddwch wedi'ch cysylltu \u00e2'r rhyngrwyd."},"explanationofflineenabled":{"message":"Rydych chi all-lein, ond gallwch barhau i olygu'r ffeiliau sydd ar gael neu greu rhai newydd."},"extdesc":{"message":"Gallwch olygu, creu a gweld eich dogfennau, taenlenni a chyflwyniadau \u2013 i gyd heb fynediad i'r rhyngrwyd."},"extname":{"message":"Dogfennau Google All-lein"},"learnmore":{"message":"DYSGU MWY"},"popuphelptext":{"message":"Ysgrifennwch, golygwch a chydweithiwch lle bynnag yr ydych, gyda chysylltiad \u00e2'r rhyngrwyd neu hebddo."}}.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):883
                                                                                                                                                    Entropy (8bit):4.5096240460083905
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA4EFkQdUULMnf1yo+9qgpukAXW9bGJTvDyqdr:zEFkegfw9qwAXWNs/yu
                                                                                                                                                    MD5:B922F7FD0E8CCAC31B411FC26542C5BA
                                                                                                                                                    SHA1:2D25E153983E311E44A3A348B7D97AF9AAD21A30
                                                                                                                                                    SHA-256:48847D57C75AF51A44CBF8F7EF1A4496C2007E58ED56D340724FDA1604FF9195
                                                                                                                                                    SHA-512:AD0954DEEB17AF04858DD5EC3D3B3DA12DFF7A666AF4061DEB6FD492992D95DB3BAF751AB6A59BEC7AB22117103A93496E07632C2FC724623BB3ACF2CA6093F3
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "OPRET NYT".. },.. "explanationofflinedisabled": {.. "message": "Du er offline. Hvis du vil bruge Google Docs uden en internetforbindelse, kan du g. til indstillinger p. startsiden for Google Docs og aktivere offlinesynkronisering, n.ste gang du har internetforbindelse.".. },.. "explanationofflineenabled": {.. "message": "Du er offline, men du kan stadig redigere tilg.ngelige filer eller oprette nye.".. },.. "extdesc": {.. "message": "Rediger, opret og se dine dokumenter, regneark og pr.sentationer helt uden internetadgang.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "F. flere oplysninger".. },.. "popuphelptext": {.. "message": "Skriv, rediger og samarbejd, uanset hvor du er, og uanset om du har internetforbindelse.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1031
                                                                                                                                                    Entropy (8bit):4.621865814402898
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA6sZnqWd77ykJzCkhRhoe1HMNaAJPwG/p98HKpy2kX/R:WZqWxykJzthRhoQma+tpyHX2O/R
                                                                                                                                                    MD5:D116453277CC860D196887CEC6432FFE
                                                                                                                                                    SHA1:0AE00288FDE696795CC62FD36EABC507AB6F4EA4
                                                                                                                                                    SHA-256:36AC525FA6E28F18572D71D75293970E0E1EAD68F358C20DA4FDC643EEA2C1C5
                                                                                                                                                    SHA-512:C788C3202A27EC220E3232AE25E3C855F3FDB8F124848F46A3D89510C564641A2DFEA86D5014CEA20D3D2D3C1405C96DBEB7CCAD910D65C55A32FDCA8A33FDD4
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "NEU ERSTELLEN".. },.. "explanationofflinedisabled": {.. "message": "Sie sind offline. Um Google Docs ohne Internetverbindung zu verwenden, gehen Sie auf der Google Docs-Startseite auf \"Einstellungen\" und schalten die Offlinesynchronisierung ein, wenn Sie das n.chste Mal mit dem Internet verbunden sind.".. },.. "explanationofflineenabled": {.. "message": "Sie sind offline, aber k.nnen weiterhin verf.gbare Dateien bearbeiten oder neue Dateien erstellen.".. },.. "extdesc": {.. "message": "Mit der Erweiterung k.nnen Sie Dokumente, Tabellen und Pr.sentationen bearbeiten, erstellen und aufrufen.. ganz ohne Internetverbindung.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Weitere Informationen".. },.. "popuphelptext": {.. "message": "Mit oder ohne Internetverbindung: Sie k.nnen von .berall Dokumente erstellen, .ndern und zusammen mit anderen
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1613
                                                                                                                                                    Entropy (8bit):4.618182455684241
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAJKan4EITDZGoziRAc2Z8eEfkTJfLhGX7b0UBNoAcGpVyhxefSmuq:SKzTD0IK85JlwsGOUyaSk
                                                                                                                                                    MD5:9ABA4337C670C6349BA38FDDC27C2106
                                                                                                                                                    SHA1:1FC33BE9AB4AD99216629BC89FBB30E7AA42B812
                                                                                                                                                    SHA-256:37CA6AB271D6E7C9B00B846FDB969811C9CE7864A85B5714027050795EA24F00
                                                                                                                                                    SHA-512:8564F93AD8485C06034A89421CE74A4E719BBAC865E33A7ED0B87BAA80B7F7E54B240266F2EDB595DF4E6816144428DB8BE18A4252CBDCC1E37B9ECC9F9D7897
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".......... ....".. },.. "explanationofflinedisabled": {.. "message": "..... ..... ......... ... .. ............... .. ....... Google ..... ....... ... ........., ......... .... ......... .... ...... ...... ... ........ Google ... ............. ... ........... ..... ........ ... ....... .... ... .. ..... ............ ... ..........".. },.. "explanationofflineenabled": {.. "message": "..... ..... ........ .... ........ .. .............. .. ......... ...... . .. ............. ... .......".. },.. "extdesc": {.. "message": ".............., ............ ... ..... .. ......., .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):851
                                                                                                                                                    Entropy (8bit):4.4858053753176526
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                    MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                    SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                    SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                    SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):851
                                                                                                                                                    Entropy (8bit):4.4858053753176526
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3Pj1NzXW6iFryCBxesJGceKCSUuvNn3AwCBhUufz1tHaXRdAv:1HA3dj/BNzXviFrpj4sNQXJezAa6
                                                                                                                                                    MD5:07FFBE5F24CA348723FF8C6C488ABFB8
                                                                                                                                                    SHA1:6DC2851E39B2EE38F88CF5C35A90171DBEA5B690
                                                                                                                                                    SHA-256:6895648577286002F1DC9C3366F558484EB7020D52BBF64A296406E61D09599C
                                                                                                                                                    SHA-512:7ED2C8DB851A84F614D5DAF1D5FE633BD70301FD7FF8A6723430F05F642CEB3B1AD0A40DE65B224661C782FFCEC69D996EBE3E5BB6B2F478181E9A07D8CD41F6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn More".. },.. "popuphelptext": {.. "message": "Write, edit, and collaborate wherever you are, with or without an internet connection.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):848
                                                                                                                                                    Entropy (8bit):4.494568170878587
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgg4eCBxNdN3vRyc1NzXW6iFrSCBxesJGceKCSUuvlvOgwCBhUufz1tnaXrQ:1HA3djfR3NzXviFrJj4sJXJ+bA6RM
                                                                                                                                                    MD5:3734D498FB377CF5E4E2508B8131C0FA
                                                                                                                                                    SHA1:AA23E39BFE526B5E3379DE04E00EACBA89C55ADE
                                                                                                                                                    SHA-256:AB5CDA04013DCE0195E80AF714FBF3A67675283768FFD062CF3CF16EDB49F5D4
                                                                                                                                                    SHA-512:56D9C792954214B0DE56558983F7EB7805AC330AF00E944E734340BE41C68E5DD03EDDB17A63BC2AB99BDD9BE1F2E2DA5BE8BA7C43D938A67151082A9041C7BA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREATE NEW".. },.. "explanationofflinedisabled": {.. "message": "You're offline. To use Google Docs without an Internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the Internet.".. },.. "explanationofflineenabled": {.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extdesc": {.. "message": "Edit, create and view your documents, spreadsheets and presentations . all without Internet access.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Learn more".. },.. "popuphelptext": {.. "message": "Write, edit and collaborate wherever you are, with or without an Internet connection.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1425
                                                                                                                                                    Entropy (8bit):4.461560329690825
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA6Krbbds5Kna/BNzXviFrpsCxKU4irpNQ0+qWK5yOJAaCB7MAa6:BKrbBs5Kna/BNzXvi3sCxKZirA0jWK5m
                                                                                                                                                    MD5:578215FBB8C12CB7E6CD73FBD16EC994
                                                                                                                                                    SHA1:9471D71FA6D82CE1863B74E24237AD4FD9477187
                                                                                                                                                    SHA-256:102B586B197EA7D6EDFEB874B97F95B05D229EA6A92780EA8544C4FF1E6BC5B1
                                                                                                                                                    SHA-512:E698B1A6A6ED6963182F7D25AC12C6DE06C45D14499DDC91E81BDB35474E7EC9071CFEBD869B7D129CB2CD127BC1442C75E408E21EB8E5E6906A607A3982B212
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createNew": {.. "description": "Text shown in the extension pop up for creating a new document",.. "message": "CREATE NEW".. },.. "explanationOfflineDisabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is disabled.",.. "message": "You're offline. To use Google Docs without an internet connection, go to settings on the Google Docs homepage and turn on offline sync the next time you're connected to the internet.".. },.. "explanationOfflineEnabled": {.. "description": "Text shown in the extension popup when the user is offline and offline is enabled.",.. "message": "You're offline, but you can still edit available files or create new ones.".. },.. "extDesc": {.. "description": "Extension description",.. "message": "Edit, create, and view your documents, spreadsheets, and presentations . all without internet access.".. },.. "extName": {.. "description": "Extension name",..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):961
                                                                                                                                                    Entropy (8bit):4.537633413451255
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvggeCBxNFxcw2CVcfamedatqWCCBxeFxCF/m+rWAaFQbCSUuExqIQdO06stp:1HAqn0gcfa9dc/5mCpmIWck02USfWmk
                                                                                                                                                    MD5:F61916A206AC0E971CDCB63B29E580E3
                                                                                                                                                    SHA1:994B8C985DC1E161655D6E553146FB84D0030619
                                                                                                                                                    SHA-256:2008F4FAAB71AB8C76A5D8811AD40102C380B6B929CE0BCE9C378A7CADFC05EB
                                                                                                                                                    SHA-512:D9C63B2F99015355ACA04D74A27FD6B81170750C4B4BE7293390DC81EF4CD920EE9184B05C61DC8979B6C2783528949A4AE7180DBF460A2620DBB0D3FD7A05CF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a Configuraci.n en la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que te conectes a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n. Aun as., puedes crear archivos o editar los que est.n disponibles.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones; todo ello, sin acceso a Internet.".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe o edita contenido y colabora con otras personas desde cualquier lugar, con o sin conexi.n a Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):959
                                                                                                                                                    Entropy (8bit):4.570019855018913
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HARn05cfa9dcDmQOTtSprj0zaGUSjSGZ:+n0CfMcDmQOTQprj4qpC
                                                                                                                                                    MD5:535331F8FB98894877811B14994FEA9D
                                                                                                                                                    SHA1:42475E6AFB6A8AE41E2FC2B9949189EF9BBE09FB
                                                                                                                                                    SHA-256:90A560FF82605DB7EDA26C90331650FF9E42C0B596CEDB79B23598DEC1B4988F
                                                                                                                                                    SHA-512:2CE9C69E901AB5F766E6CFC1E592E1AF5A07AA78D154CCBB7898519A12E6B42A21C5052A86783ABE3E7A05043D4BD41B28960FEDDB30169FF7F7FE7208C8CFE9
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR NUEVO".. },.. "explanationofflinedisabled": {.. "message": "No tienes conexi.n. Para usar Documentos de Google sin conexi.n a Internet, ve a la configuraci.n de la p.gina principal de Documentos de Google y activa la sincronizaci.n sin conexi.n la pr.xima vez que est.s conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "No tienes conexi.n, pero a.n puedes modificar los archivos disponibles o crear otros nuevos.".. },.. "extdesc": {.. "message": "Edita, crea y consulta tus documentos, hojas de c.lculo y presentaciones aunque no tengas acceso a Internet".. },.. "extname": {.. "message": "Documentos de Google sin conexi.n".. },.. "learnmore": {.. "message": "M.s informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, modifica y colabora dondequiera que est.s, con conexi.n a Internet o sin ella.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):968
                                                                                                                                                    Entropy (8bit):4.633956349931516
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA5WG6t306+9sihHvMfdJLjUk4NJPNczGr:mWGY0cOUdJODPmzs
                                                                                                                                                    MD5:64204786E7A7C1ED9C241F1C59B81007
                                                                                                                                                    SHA1:586528E87CD670249A44FB9C54B1796E40CDB794
                                                                                                                                                    SHA-256:CC31B877238DA6C1D51D9A6155FDE565727A1956572F466C387B7E41C4923A29
                                                                                                                                                    SHA-512:44FCF93F3FB10A3DB68D74F9453995995AB2D16863EC89779DB451A4D90F19743B8F51095EEC3ECEF5BD0C5C60D1BF3DFB0D64DF288DCCFBE70C129AE350B2C6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "LOO UUS".. },.. "explanationofflinedisabled": {.. "message": "Teil ei ole v.rgu.hendust. Teenuse Google.i dokumendid kasutamiseks ilma Interneti-.henduseta avage j.rgmine kord, kui olete Internetiga .hendatud, teenuse Google.i dokumendid avalehel seaded ja l.litage sisse v.rgu.henduseta s.nkroonimine.".. },.. "explanationofflineenabled": {.. "message": "Teil ei ole v.rgu.hendust, kuid saate endiselt saadaolevaid faile muuta v.i uusi luua.".. },.. "extdesc": {.. "message": "Saate luua, muuta ja vaadata oma dokumente, arvustustabeleid ning esitlusi ilma Interneti-.henduseta.".. },.. "extname": {.. "message": "V.rgu.henduseta Google.i dokumendid".. },.. "learnmore": {.. "message": "Lisateave".. },.. "popuphelptext": {.. "message": "Kirjutage, muutke ja tehke koost..d .ksk.ik kus olenemata sellest, kas teil on Interneti-.hendus.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):838
                                                                                                                                                    Entropy (8bit):4.4975520913636595
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:YnmjggqTWngosqYQqE1kjO39m7OddC0vjWQMmWgqwgQ8KLcxOb:Ynmsgqyngosq9qxTOs0vjWQMbgqchb
                                                                                                                                                    MD5:29A1DA4ACB4C9D04F080BB101E204E93
                                                                                                                                                    SHA1:2D0E4587DDD4BAC1C90E79A88AF3BD2C140B53B1
                                                                                                                                                    SHA-256:A41670D52423BA69C7A65E7E153E7B9994E8DD0370C584BDA0714BD61C49C578
                                                                                                                                                    SHA-512:B7B7A5A0AA8F6724B0FA15D65F25286D9C66873F03080CBABA037BDEEA6AADC678AC4F083BC52C2DB01BEB1B41A755ED67BBDDB9C0FE4E35A004537A3F7FC458
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"SORTU"},"explanationofflinedisabled":{"message":"Ez zaude konektatuta Internetera. Google Dokumentuak konexiorik gabe erabiltzeko, joan Google Dokumentuak zerbitzuaren orri nagusiko ezarpenetara eta aktibatu konexiorik gabeko sinkronizazioa Internetera konektatzen zaren hurrengoan."},"explanationofflineenabled":{"message":"Ez zaude konektatuta Internetera, baina erabilgarri dauden fitxategiak edita ditzakezu, baita beste batzuk sortu ere."},"extdesc":{"message":"Editatu, sortu eta ikusi dokumentuak, kalkulu-orriak eta aurkezpenak Interneteko konexiorik gabe."},"extname":{"message":"Google Dokumentuak konexiorik gabe"},"learnmore":{"message":"Lortu informazio gehiago"},"popuphelptext":{"message":"Edonon zaudela ere, ez duzu zertan konektatuta egon idatzi, editatu eta lankidetzan jardun ahal izateko."}}.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1305
                                                                                                                                                    Entropy (8bit):4.673517697192589
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAX9yM7oiI99Rwx4xyQakJbfAEJhmq/RlBu92P7FbNcgYVJ0:JM7ovex4xyQaKjAEyq/p7taX0
                                                                                                                                                    MD5:097F3BA8DE41A0AAF436C783DCFE7EF3
                                                                                                                                                    SHA1:986B8CABD794E08C7AD41F0F35C93E4824AC84DF
                                                                                                                                                    SHA-256:7C4C09D19AC4DA30CC0F7F521825F44C4DFBC19482A127FBFB2B74B3468F48F1
                                                                                                                                                    SHA-512:8114EA7422E3B20AE3F08A3A64A6FFE1517A7579A3243919B8F789EB52C68D6F5A591F7B4D16CEE4BD337FF4DAF4057D81695732E5F7D9E761D04F859359FADB
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ... ....".. },.. "explanationofflinedisabled": {.. "message": "...... ...... .... ....... .. ....... Google .... ..... ........ .... ... .. .. ....... ... ..... .. ....... .. .... .... ....... Google ..... . .......... ...... .. .... .....".. },.. "explanationofflineenabled": {.. "message": "...... ..... ... ...... ......... ......... .. .. .. ..... ..... ...... .... .. ........ ..... ..... .....".. },.. "extdesc": {.. "message": "...... ............ . ........ .. ....... ..... . ...... .... . ... ... ..... .... ...... .. ........".. },.. "extname": {.. "message": "....... Google .
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):911
                                                                                                                                                    Entropy (8bit):4.6294343834070935
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvguCBxNMME2BESA7gPQk36xCBxeMMcXYBt+CSU1pfazCBhUunV1tLaX5GI2N:1HAVioESAsPf36O3Xst/p3J8JeEY
                                                                                                                                                    MD5:B38CBD6C2C5BFAA6EE252D573A0B12A1
                                                                                                                                                    SHA1:2E490D5A4942D2455C3E751F96BD9960F93C4B60
                                                                                                                                                    SHA-256:2D752A5DBE80E34EA9A18C958B4C754F3BC10D63279484E4DF5880B8FD1894D2
                                                                                                                                                    SHA-512:6E65207F4D8212736059CC802C6A7104E71A9CC0935E07BD13D17EC46EA26D10BC87AD923CD84D78781E4F93231A11CB9ED8D3558877B6B0D52C07CB005F1C0C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "LUO UUSI".. },.. "explanationofflinedisabled": {.. "message": "Olet offline-tilassa. Jos haluat k.ytt.. Google Docsia ilman internetyhteytt., siirry Google Docsin etusivulle ja ota asetuksissa k.ytt..n offline-synkronointi, kun seuraavan kerran olet yhteydess. internetiin.".. },.. "explanationofflineenabled": {.. "message": "Olet offline-tilassa. Voit kuitenkin muokata k.ytett.viss. olevia tiedostoja tai luoda uusia.".. },.. "extdesc": {.. "message": "Muokkaa, luo ja katso dokumentteja, laskentataulukoita ja esityksi. ilman internetyhteytt..".. },.. "extname": {.. "message": "Google Docsin offline-tila".. },.. "learnmore": {.. "message": "Lis.tietoja".. },.. "popuphelptext": {.. "message": "Kirjoita, muokkaa ja tee yhteisty.t. paikasta riippumatta, my.s ilman internetyhteytt..".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):939
                                                                                                                                                    Entropy (8bit):4.451724169062555
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAXbH2eZXn6sjLITdRSJpGL/gWFJ3sqixO:ubHfZqsHIT/FLL3qO
                                                                                                                                                    MD5:FCEA43D62605860FFF41BE26BAD80169
                                                                                                                                                    SHA1:F25C2CE893D65666CC46EA267E3D1AA080A25F5B
                                                                                                                                                    SHA-256:F51EEB7AAF5F2103C1043D520E5A4DE0FA75E4DC375E23A2C2C4AFD4D9293A72
                                                                                                                                                    SHA-512:F66F113A26E5BCF54B9AAFA69DAE3C02C9C59BD5B9A05F829C92AF208C06DC8CCC7A1875CBB7B7CE425899E4BA27BFE8CE2CDAF43A00A1B9F95149E855989EE0
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "GUMAWA NG BAGO".. },.. "explanationofflinedisabled": {.. "message": "Naka-offline ka. Upang magamit ang Google Docs nang walang koneksyon sa internet, pumunta sa mga setting sa homepage ng Google Docs at i-on ang offline na pag-sync sa susunod na nakakonekta ka sa internet.".. },.. "explanationofflineenabled": {.. "message": "Naka-offline ka, ngunit maaari mo pa ring i-edit ang mga available na file o gumawa ng mga bago.".. },.. "extdesc": {.. "message": "I-edit, gawin, at tingnan ang iyong mga dokumento, spreadsheet, at presentation . lahat ng ito nang walang access sa internet.".. },.. "extname": {.. "message": "Google Docs Offline".. },.. "learnmore": {.. "message": "Matuto Pa".. },.. "popuphelptext": {.. "message": "Magsulat, mag-edit at makipag-collaborate nasaan ka man, nang mayroon o walang koneksyon sa internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):977
                                                                                                                                                    Entropy (8bit):4.622066056638277
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAdy42ArMdsH50Jd6Z1PCBolXAJ+GgNHp0X16M1J1:EyfArMS2Jd6Z1PCBolX2+vNmX16Y1
                                                                                                                                                    MD5:A58C0EEBD5DC6BB5D91DAF923BD3A2AA
                                                                                                                                                    SHA1:F169870EEED333363950D0BCD5A46D712231E2AE
                                                                                                                                                    SHA-256:0518287950A8B010FFC8D52554EB82E5D93B6C3571823B7CECA898906C11ABCC
                                                                                                                                                    SHA-512:B04AFD61DE490BC838354E8DC6C22BE5C7AC6E55386FFF78489031ACBE2DBF1EAA2652366F7A1E62CE87CFCCB75576DA3B2645FEA1645B0ECEB38B1FA3A409E8
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour pouvoir utiliser Google.Docs sans connexion Internet, acc.dez aux param.tres de la page d'accueil de Google.Docs et activez la synchronisation hors connexion lors de votre prochaine connexion . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez quand m.me modifier les fichiers disponibles ou cr.er des fichiers.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez des documents, feuilles de calcul et pr.sentations, sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Docs hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": "R.digez des documents, modifiez-les et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):972
                                                                                                                                                    Entropy (8bit):4.621319511196614
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAdyg2pwbv1V8Cd61PC/vT2fg3YHDyM1J1:EyHpwbpd61C/72Y3YOY1
                                                                                                                                                    MD5:6CAC04BDCC09034981B4AB567B00C296
                                                                                                                                                    SHA1:84F4D0E89E30ED7B7ACD7644E4867FFDB346D2A5
                                                                                                                                                    SHA-256:4CAA46656ECC46A420AA98D3307731E84F5AC1A89111D2E808A228C436D83834
                                                                                                                                                    SHA-512:160590B6EC3DCF48F3EA7A5BAA11A8F6FA4131059469623E00AD273606B468B3A6E56D199E97DAA0ECB6C526260EBAE008570223F2822811F441D1C900DC33D6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CR.ER".. },.. "explanationofflinedisabled": {.. "message": "Vous .tes hors connexion. Pour utiliser Google.Documents sans connexion Internet, acc.dez aux param.tres sur la page d'accueil Google.Documents et activez la synchronisation hors ligne la prochaine fois que vous .tes connect. . Internet.".. },.. "explanationofflineenabled": {.. "message": "Vous .tes hors connexion, mais vous pouvez toujours modifier les fichiers disponibles ou en cr.er.".. },.. "extdesc": {.. "message": "Modifiez, cr.ez et consultez vos documents, vos feuilles de calcul et vos pr.sentations, le tout sans acc.s . Internet.".. },.. "extname": {.. "message": "Google.Documents hors connexion".. },.. "learnmore": {.. "message": "En savoir plus".. },.. "popuphelptext": {.. "message": ".crivez, modifiez et collaborez o. que vous soyez, avec ou sans connexion Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):990
                                                                                                                                                    Entropy (8bit):4.497202347098541
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvggECBxNbWVqMjlMgaPLqXPhTth0CBxebWbMRCSUCjAKFCSIj0tR7tCBhP1l:1HACzWsMlajIhJhHKWbFKFC0tR8oNK5
                                                                                                                                                    MD5:6BAAFEE2F718BEFBC7CD58A04CCC6C92
                                                                                                                                                    SHA1:CE0BDDDA2FA1F0AD222B604C13FF116CBB6D02CF
                                                                                                                                                    SHA-256:0CF098DFE5BBB46FC0132B3CF0C54B06B4D2C8390D847EE2A65D20F9B7480F4C
                                                                                                                                                    SHA-512:3DA23E74CD6CF9C0E2A0C4DBA60301281D362FB0A2A908F39A55ABDCA4CC69AD55638C63CC3BEFD44DC032F9CBB9E2FDC1B4C4ABE292917DF8272BA25B82AF20
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est.s sen conexi.n. Para utilizar Documentos de Google sen conexi.n a Internet, accede .s opci.ns de configuraci.n na p.xina de inicio de Documentos de Google e activa a sincronizaci.n sen conexi.n a pr.xima vez que esteas conectado a Internet.".. },.. "explanationofflineenabled": {.. "message": "Est.s sen conexi.n. A.nda podes editar os ficheiros dispo.ibles ou crear outros novos.".. },.. "extdesc": {.. "message": "Modifica, crea e consulta os teus documentos, follas de c.lculo e presentaci.ns sen necesidade de acceder a Internet.".. },.. "extname": {.. "message": "Documentos de Google sen conexi.n".. },.. "learnmore": {.. "message": "M.is informaci.n".. },.. "popuphelptext": {.. "message": "Escribe, edita e colabora esteas onde esteas, tanto se tes conexi.n a Internet como se non a tes.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1658
                                                                                                                                                    Entropy (8bit):4.294833932445159
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA3k3FzEVeXWuvLujNzAK11RiqRC2sA0O3cEiZ7dPRFFOPtZdK0A41yG3BczKT3:Q4pE4rCjNjw6/0y+5j8ZHA4PBSKr
                                                                                                                                                    MD5:BC7E1D09028B085B74CB4E04D8A90814
                                                                                                                                                    SHA1:E28B2919F000B41B41209E56B7BF3A4448456CFE
                                                                                                                                                    SHA-256:FE8218DF25DB54E633927C4A1640B1A41B8E6CB3360FA386B5382F833B0B237C
                                                                                                                                                    SHA-512:040A8267D67DB05BBAA52F1FAC3460F58D35C5B73AA76BBF17FA78ACC6D3BFB796A870DD44638F9AC3967E35217578A20D6F0B975CEEEEDBADFC9F65BE7E72C9
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .....".. },.. "explanationofflinedisabled": {.. "message": "... ...... ... ........ ....... ... Google .......... ..... .... ...., ... .... .... ...... ........ .... ...... ... ...... Google ........ ...... .. ........ .. ... ... ...... ....... .... ....".. },.. "explanationofflineenabled": {.. "message": "... ...... .., ..... ... ... .. ...... ..... ....... ... ... .. .... ... ..... ... ...".. },.. "extdesc": {.. "message": "..... ........., ..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1672
                                                                                                                                                    Entropy (8bit):4.314484457325167
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:46G2+ymELbLNzGVx/hXdDtxSRhqv7Qm6/7Lm:4GbxzGVzXdDtx+qzU/7C
                                                                                                                                                    MD5:98A7FC3E2E05AFFFC1CFE4A029F47476
                                                                                                                                                    SHA1:A17E077D6E6BA1D8A90C1F3FAF25D37B0FF5A6AD
                                                                                                                                                    SHA-256:D2D1AFA224CDA388FF1DC8FAC24CDA228D7CE09DE5D375947D7207FA4A6C4F8D
                                                                                                                                                    SHA-512:457E295C760ABFD29FC6BBBB7FC7D4959287BCA7FB0E3E99EB834087D17EED331DEF18138838D35C48C6DDC8A0134AFFFF1A5A24033F9B5607B355D3D48FDF88
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... .....".. },.. "explanationofflinedisabled": {.. "message": ".. ...... .... ....... ....... .. .... Google ........ .. ..... .... .. ..., .... ... ....... .. ...... .... .. Google ........ .. ........ .. ...... ... .... .. ...... ....... .... .....".. },.. "explanationofflineenabled": {.. "message": ".. ...... ..., ..... .. .. .. ...... ...... ..... .. .... ... .. .. ...... ... .... ....".. },.. "extdesc": {.. "message": ".... .... ....... ...... ..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):935
                                                                                                                                                    Entropy (8bit):4.6369398601609735
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA7sR5k/I+UX/hrcySxG1fIZ3tp/S/d6Gpb+D:YsE/I+UX/hVSxQ03f/Sj+D
                                                                                                                                                    MD5:25CDFF9D60C5FC4740A48EF9804BF5C7
                                                                                                                                                    SHA1:4FADECC52FB43AEC084DF9FF86D2D465FBEBCDC0
                                                                                                                                                    SHA-256:73E6E246CEEAB9875625CD4889FBF931F93B7B9DEAA11288AE1A0F8A6E311E76
                                                                                                                                                    SHA-512:EF00B08496427FEB5A6B9FB3FE2E5404525BE7C329D9DD2A417480637FD91885837D134A26980DCF9F61E463E6CB68F09A24402805807E656AF16B116A75E02C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "IZRADI NOVI".. },.. "explanationofflinedisabled": {.. "message": "Vi ste izvan mre.e. Da biste koristili Google dokumente bez internetske veze, idite na postavke na po.etnoj stranici Google dokumenata i uklju.ite izvanmre.nu sinkronizaciju sljede.i put kada se pove.ete s internetom.".. },.. "explanationofflineenabled": {.. "message": "Vi ste izvan mre.e, no i dalje mo.ete ure.ivati dostupne datoteke i izra.ivati nove.".. },.. "extdesc": {.. "message": "Uredite, izradite i pregledajte dokumente, prora.unske tablice i prezentacije . sve bez pristupa internetu.".. },.. "extname": {.. "message": "Google dokumenti izvanmre.no".. },.. "learnmore": {.. "message": "Saznajte vi.e".. },.. "popuphelptext": {.. "message": "Pi.ite, ure.ujte i sura.ujte gdje god se nalazili, povezani s internetom ili izvanmre.no.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1065
                                                                                                                                                    Entropy (8bit):4.816501737523951
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA6J54gEYwFFMxv4gvyB9FzmxlsN147g/zJcYwJgrus4QY2jom:NJ54gEYwUmgKHFzmsG7izJcYOgKgYjm
                                                                                                                                                    MD5:8930A51E3ACE3DD897C9E61A2AEA1D02
                                                                                                                                                    SHA1:4108506500C68C054BA03310C49FA5B8EE246EA4
                                                                                                                                                    SHA-256:958C0F664FCA20855FA84293566B2DDB7F297185619143457D6479E6AC81D240
                                                                                                                                                    SHA-512:126B80CD3428C0BC459EEAAFCBE4B9FDE2541A57F19F3EC7346BAF449F36DC073A9CF015594A57203255941551B25F6FAA6D2C73C57C44725F563883FF902606
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".J L.TREHOZ.SA".. },.. "explanationofflinedisabled": {.. "message": "Jelenleg offline .llapotban van. Ha a Google Dokumentumokat internetkapcsolat n.lk.l szeretn. haszn.lni, a legk.zelebbi internethaszn.lata sor.n nyissa meg a Google Dokumentumok kezd.oldal.n tal.lhat. be.ll.t.sokat, .s tiltsa le az offline szinkroniz.l.s be.ll.t.st.".. },.. "explanationofflineenabled": {.. "message": "Offline .llapotban van, de az el.rhet. f.jlokat .gy is szerkesztheti, valamint l.trehozhat .jakat.".. },.. "extdesc": {.. "message": "Szerkesszen, hozzon l.tre .s tekintsen meg dokumentumokat, t.bl.zatokat .s prezent.ci.kat . ak.r internetkapcsolat n.lk.l is.".. },.. "extname": {.. "message": "Google Dokumentumok Offline".. },.. "learnmore": {.. "message": "Tov.bbi inform.ci.".. },.. "popuphelptext": {.. "message": ".rjon, szerkesszen .s dolgozzon egy.tt m.sokkal
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2771
                                                                                                                                                    Entropy (8bit):3.7629875118570055
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:Y0Fx+eiYZBZ7K1ZZ/5QQxTuDLoFZaIZSK7lq0iC0mlMO6M3ih1oAgC:lF2BTz6N/
                                                                                                                                                    MD5:55DE859AD778E0AA9D950EF505B29DA9
                                                                                                                                                    SHA1:4479BE637A50C9EE8A2F7690AD362A6A8FFC59B2
                                                                                                                                                    SHA-256:0B16E3F8BD904A767284345AE86A0A9927C47AFE89E05EA2B13AD80009BDF9E4
                                                                                                                                                    SHA-512:EDAB2FCC14CABB6D116E9C2907B42CFBC34F1D9035F43E454F1F4D1F3774C100CBADF6B4C81B025810ED90FA91C22F1AEFE83056E4543D92527E4FE81C7889A8
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u054d\u054f\u0535\u0542\u053e\u0535\u053c \u0546\u0548\u0550"},"explanationofflinedisabled":{"message":"Google \u0553\u0561\u057d\u057f\u0561\u0569\u0572\u0569\u0565\u0580\u0568 \u0576\u0561\u0587 \u0561\u0576\u0581\u0561\u0576\u0581 \u057c\u0565\u056a\u056b\u0574\u0578\u0582\u0574 \u0585\u0563\u057f\u0561\u0563\u0578\u0580\u056e\u0565\u056c\u0578\u0582 \u0570\u0561\u0574\u0561\u0580 \u0574\u056b\u0561\u0581\u0565\u0584 \u0570\u0561\u0574\u0561\u0581\u0561\u0576\u0581\u056b\u0576, \u0562\u0561\u0581\u0565\u0584 \u056e\u0561\u057c\u0561\u0575\u0578\u0582\u0569\u0575\u0561\u0576 \u0563\u056c\u056d\u0561\u057e\u0578\u0580 \u0567\u057b\u0568, \u0561\u0576\u0581\u0565\u0584 \u056f\u0561\u0580\u0563\u0561\u057e\u0578\u0580\u0578\u0582\u0574\u0576\u0565\u0580 \u0587 \u0574\u056b\u0561\u0581\u0580\u0565\u0584 \u0561\u0576\u0581\u0561\u0576\u0581 \u0570\u0561\u0574\u0561\u056a\u0561\u0574\u0561\u0581\u0578\u0582\u0574\u0568:"},"explanationofflineenabled":{"message":"\u
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):858
                                                                                                                                                    Entropy (8bit):4.474411340525479
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgJX4CBxNpXemNOAJRFqjRpCBxedIdjTi92OvbCSUuoi01uRwCBhUuvz1thK:1HARXzhXemNOQWGcEoeH1eXJNvT2
                                                                                                                                                    MD5:34D6EE258AF9429465AE6A078C2FB1F5
                                                                                                                                                    SHA1:612CAE151984449A4346A66C0A0DF4235D64D932
                                                                                                                                                    SHA-256:E3C86DDD2EFEBE88EED8484765A9868202546149753E03A61EB7C28FD62CFCA1
                                                                                                                                                    SHA-512:20427807B64A0F79A6349F8A923152D9647DA95C05DE19AD3A4BF7DB817E25227F3B99307C8745DD323A6591B515221BD2F1E92B6F1A1783BDFA7142E84601B1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "BUAT BARU".. },.. "explanationofflinedisabled": {.. "message": "Anda sedang offline. Untuk menggunakan Google Dokumen tanpa koneksi internet, buka setelan di beranda Google Dokumen dan aktifkan sinkronisasi offline saat terhubung ke internet.".. },.. "explanationofflineenabled": {.. "message": "Anda sedang offline, namun Anda masih dapat mengedit file yang tersedia atau membuat file baru.".. },.. "extdesc": {.. "message": "Edit, buat, dan lihat dokumen, spreadsheet, dan presentasi . tanpa perlu akses internet.".. },.. "extname": {.. "message": "Google Dokumen Offline".. },.. "learnmore": {.. "message": "Pelajari Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit, dan gabungkan di mana saja, dengan atau tanpa koneksi internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):954
                                                                                                                                                    Entropy (8bit):4.6457079159286545
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:YGXU2rOcxGe+J97M9TP2DBX9tMfxqbTMvOfWWgdraqlifVpm0Ekf95Mw89KkJ+je:YwBrD2g2DBLMfFuWvdpY94viDO+uh
                                                                                                                                                    MD5:CAEB37F451B5B5E9F5EB2E7E7F46E2D7
                                                                                                                                                    SHA1:F917F9EAE268A385A10DB3E19E3CC3ACED56D02E
                                                                                                                                                    SHA-256:943E61988C859BB088F548889F0449885525DD660626A89BA67B2C94CFBFBB1B
                                                                                                                                                    SHA-512:A55DEC2404E1D7FA5A05475284CBECC2A6208730F09A227D75FDD4AC82CE50F3751C89DC687C14B91950F9AA85503BD6BF705113F2F1D478E728DF64D476A9EE
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"B\u00daA TIL N\u00ddTT"},"explanationofflinedisabled":{"message":"\u00de\u00fa ert \u00e1n nettengingar. Til a\u00f0 nota Google-skj\u00f6l \u00e1n nettengingar skaltu opna stillingarnar \u00e1 heimas\u00ed\u00f0u Google skjala og virkja samstillingu \u00e1n nettengingar n\u00e6st \u00feegar \u00fe\u00fa tengist netinu."},"explanationofflineenabled":{"message":"Engin nettenging. \u00de\u00fa getur samt sem \u00e1\u00f0ur breytt tilt\u00e6kum skr\u00e1m e\u00f0a b\u00fai\u00f0 til n\u00fdjar."},"extdesc":{"message":"Breyttu, b\u00fa\u00f0u til og sko\u00f0a\u00f0u skj\u00f6lin \u00fe\u00edn, t\u00f6flureikna og kynningar \u2014 allt \u00e1n nettengingar."},"extname":{"message":"Google-skj\u00f6l \u00e1n nettengingar"},"learnmore":{"message":"Frekari uppl\u00fdsingar"},"popuphelptext":{"message":"Skrifa\u00f0u, breyttu og starfa\u00f0u me\u00f0 \u00f6\u00f0rum hvort sem nettenging er til sta\u00f0ar e\u00f0a ekki."}}.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):899
                                                                                                                                                    Entropy (8bit):4.474743599345443
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvggrCBxNp8WJOJJrJ3WytVCBxep3bjP5CSUCjV8AgJJm2CBhr+z1tWgjqEOW:1HANXJOTBFtKa8Agju4NB3j
                                                                                                                                                    MD5:0D82B734EF045D5FE7AA680B6A12E711
                                                                                                                                                    SHA1:BD04F181E4EE09F02CD53161DCABCEF902423092
                                                                                                                                                    SHA-256:F41862665B13C0B4C4F562EF1743684CCE29D4BCF7FE3EA494208DF253E33885
                                                                                                                                                    SHA-512:01F305A280112482884485085494E871C66D40C0B03DE710B4E5F49C6A478D541C2C1FDA2CEAF4307900485946DEE9D905851E98A2EB237642C80D464D1B3ADA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREA NUOVO".. },.. "explanationofflinedisabled": {.. "message": "Sei offline. Per utilizzare Documenti Google senza una connessione Internet, apri le impostazioni nella home page di Documenti Google e attiva la sincronizzazione offline la prossima volta che ti colleghi a Internet.".. },.. "explanationofflineenabled": {.. "message": "Sei offline, ma puoi comunque modificare i file disponibili o crearne di nuovi.".. },.. "extdesc": {.. "message": "Modifica, crea e visualizza documenti, fogli di lavoro e presentazioni, senza accesso a Internet.".. },.. "extname": {.. "message": "Documenti Google offline".. },.. "learnmore": {.. "message": "Ulteriori informazioni".. },.. "popuphelptext": {.. "message": "Scrivi, modifica e collabora ovunque ti trovi, con o senza una connessione Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2230
                                                                                                                                                    Entropy (8bit):3.8239097369647634
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:YIiTVLrLD1MEzMEH82LBLjO5YaQEqLytLLBm3dnA5LcqLWAU75yxFLcx+UxWRJLI:YfTFf589rZNgNA12Qzt4/zRz2vc
                                                                                                                                                    MD5:26B1533C0852EE4661EC1A27BD87D6BF
                                                                                                                                                    SHA1:18234E3ABAF702DF9330552780C2F33B83A1188A
                                                                                                                                                    SHA-256:BBB81C32F482BA3216C9B1189C70CEF39CA8C2181AF3538FFA07B4C6AD52F06A
                                                                                                                                                    SHA-512:450BFAF0E8159A4FAE309737EA69CA8DD91CAAFD27EF662087C4E7716B2DCAD3172555898E75814D6F11487F4F254DE8625EF0CFEA8DF0133FC49E18EC7FD5D2
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u05d9\u05e6\u05d9\u05e8\u05ea \u05d7\u05d3\u05e9"},"explanationofflinedisabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8. \u05db\u05d3\u05d9 \u05dc\u05d4\u05e9\u05ea\u05de\u05e9 \u05d1-Google Docs \u05dc\u05dc\u05d0 \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d1\u05d4\u05ea\u05d7\u05d1\u05e8\u05d5\u05ea \u05d4\u05d1\u05d0\u05d4 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e8\u05e0\u05d8, \u05d9\u05e9 \u05dc\u05e2\u05d1\u05d5\u05e8 \u05dc\u05e7\u05d8\u05e2 \u05d4\u05d4\u05d2\u05d3\u05e8\u05d5\u05ea \u05d1\u05d3\u05e3 \u05d4\u05d1\u05d9\u05ea \u05e9\u05dc Google Docs \u05d5\u05dc\u05d4\u05e4\u05e2\u05d9\u05dc \u05e1\u05e0\u05db\u05e8\u05d5\u05df \u05d1\u05de\u05e6\u05d1 \u05d0\u05d5\u05e4\u05dc\u05d9\u05d9\u05df."},"explanationofflineenabled":{"message":"\u05d0\u05d9\u05df \u05dc\u05da \u05d7\u05d9\u05d1\u05d5\u05e8 \u05dc\u05d0\u05d9\u05e0\u05d8\u05e
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1160
                                                                                                                                                    Entropy (8bit):5.292894989863142
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAoc3IiRF1viQ1RF3CMP3rnicCCAFrr1Oo0Y5ReXCCQkb:Dc3zF7F3CMTnOCAFVLHXCFb
                                                                                                                                                    MD5:15EC1963FC113D4AD6E7E59AE5DE7C0A
                                                                                                                                                    SHA1:4017FC6D8B302335469091B91D063B07C9E12109
                                                                                                                                                    SHA-256:34AC08F3C4F2D42962A3395508818B48CA323D22F498738CC9F09E78CB197D73
                                                                                                                                                    SHA-512:427251F471FA3B759CA1555E9600C10F755BC023701D058FF661BEC605B6AB94CFB3456C1FEA68D12B4D815FFBAFABCEB6C12311DD1199FC783ED6863AF97C0F
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ............................... Google .............. [..] .......[.......] ...........".. },.. "explanationofflineenabled": {.. "message": ".............................................".. },.. "extdesc": {.. "message": ".........................................................".. },.. "extname": {.. "message": "Google ..... ......".. },.. "learnmore": {.. "message": "..".. },.. "popuphelp
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3264
                                                                                                                                                    Entropy (8bit):3.586016059431306
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:YGFbhVhVn0nM/XGbQTvxnItVJW/476CFdqaxWNlR:HFbhV/n0MfGbw875FkaANlR
                                                                                                                                                    MD5:83F81D30913DC4344573D7A58BD20D85
                                                                                                                                                    SHA1:5AD0E91EA18045232A8F9DF1627007FE506A70E0
                                                                                                                                                    SHA-256:30898BBF51BDD58DB397FF780F061E33431A38EF5CFC288B5177ECF76B399F26
                                                                                                                                                    SHA-512:85F97F12AD4482B5D9A6166BB2AE3C4458A582CF575190C71C1D8E0FB87C58482F8C0EFEAD56E3A70EDD42BED945816DB5E07732AD27B8FFC93F4093710DD58F
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u10d0\u10ee\u10da\u10d8\u10e1 \u10e8\u10d4\u10e5\u10db\u10dc\u10d0"},"explanationofflinedisabled":{"message":"\u10d7\u10e5\u10d5\u10d4\u10dc \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10ee\u10d0\u10e0\u10d7. Google Docs-\u10d8\u10e1 \u10d8\u10dc\u10e2\u10d4\u10e0\u10dc\u10d4\u10e2\u10d7\u10d0\u10dc \u10d9\u10d0\u10d5\u10e8\u10d8\u10e0\u10d8\u10e1 \u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10d2\u10d0\u10db\u10dd\u10e1\u10d0\u10e7\u10d4\u10dc\u10d4\u10d1\u10da\u10d0\u10d3 \u10d2\u10d0\u10d3\u10d0\u10d3\u10d8\u10d7 \u10de\u10d0\u10e0\u10d0\u10db\u10d4\u10e2\u10e0\u10d4\u10d1\u10d6\u10d4 Google Docs-\u10d8\u10e1 \u10db\u10d7\u10d0\u10d5\u10d0\u10e0 \u10d2\u10d5\u10d4\u10e0\u10d3\u10d6\u10d4 \u10d3\u10d0 \u10e9\u10d0\u10e0\u10d7\u10d4\u10d7 \u10ee\u10d0\u10d6\u10d2\u10d0\u10e0\u10d4\u10e8\u10d4 \u10e1\u10d8\u10dc\u10e5\u10e0\u10dd\u10dc\u10d8\u10d6\u10d0\u10ea\u10d8\u10d0, \u10e0\u10dd\u10d3\u10d4\u10e1\u10d0\u10ea \u10e8\u10d4\u10db\u10d3\u10d2\u10dd\u10
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3235
                                                                                                                                                    Entropy (8bit):3.6081439490236464
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:H3E+6rOEAbeHTln2EQ77Uayg45RjhCSj+OyRdM7AE9qdV:HXcR/nQXUayYV
                                                                                                                                                    MD5:2D94A58795F7B1E6E43C9656A147AD3C
                                                                                                                                                    SHA1:E377DB505C6924B6BFC9D73DC7C02610062F674E
                                                                                                                                                    SHA-256:548DC6C96E31A16CE355DC55C64833B08EF3FBA8BF33149031B4A685959E3AF4
                                                                                                                                                    SHA-512:F51CC857E4CF2D4545C76A2DCE7D837381CE59016E250319BF8D39718BE79F9F6EE74EA5A56DE0E8759E4E586D93430D51651FC902376D8A5698628E54A0F2D8
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u0416\u0410\u04a2\u0410\u0421\u042b\u041d \u0416\u0410\u0421\u0410\u0423"},"explanationofflinedisabled":{"message":"\u0421\u0456\u0437 \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u043d\u0434\u0435\u0441\u0456\u0437. Google Docs \u049b\u043e\u043b\u0434\u0430\u043d\u0431\u0430\u0441\u044b\u043d \u0436\u0435\u043b\u0456 \u0431\u0430\u0439\u043b\u0430\u043d\u044b\u0441\u044b\u043d\u0441\u044b\u0437 \u049b\u043e\u043b\u0434\u0430\u043d\u0443 \u04af\u0448\u0456\u043d, \u043a\u0435\u043b\u0435\u0441\u0456 \u0436\u043e\u043b\u044b \u0436\u0435\u043b\u0456\u0433\u0435 \u049b\u043e\u0441\u044b\u043b\u0493\u0430\u043d\u0434\u0430, Google Docs \u043d\u0435\u0433\u0456\u0437\u0433\u0456 \u0431\u0435\u0442\u0456\u043d\u0435\u043d \u043f\u0430\u0440\u0430\u043c\u0435\u0442\u0440\u043b\u0435\u0440 \u0431\u04e9\u043b\u0456\u043c\u0456\u043d \u043a\u0456\u0440\u0456\u043f, \u043e\u0444\u043b\u0430\u0439\u043d \u0440\u0435\u0436\u0438\u043c\u0456\u
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3122
                                                                                                                                                    Entropy (8bit):3.891443295908904
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:/OOrssRU6Bg7VSdL+zsCfoZiWssriWqo2gx7RRCos2sEeBkS7Zesg:H5GRZlXsGdo
                                                                                                                                                    MD5:B3699C20A94776A5C2F90AEF6EB0DAD9
                                                                                                                                                    SHA1:1F9B968B0679A20FA097624C9ABFA2B96C8C0BEA
                                                                                                                                                    SHA-256:A6118F0A0DE329E07C01F53CD6FB4FED43E54C5F53DB4CD1C7F5B2B4D9FB10E6
                                                                                                                                                    SHA-512:1E8D15B8BFF1D289434A244172F9ED42B4BB6BCB6372C1F300B01ACEA5A88167E97FEDABA0A7AE3BEB5E24763D1B09046AE8E30745B80E2E2FE785C94DF362F6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u1794\u1784\u17d2\u1780\u17be\u178f\u200b\u1790\u17d2\u1798\u17b8"},"explanationofflinedisabled":{"message":"\u17a2\u17d2\u1793\u1780\u200b\u1782\u17d2\u1798\u17b6\u1793\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f\u17d4 \u178a\u17be\u1798\u17d2\u1794\u17b8\u200b\u1794\u17d2\u179a\u17be Google \u17af\u1780\u179f\u17b6\u179a\u200b\u1794\u17b6\u1793\u200b\u200b\u178a\u17c4\u1799\u200b\u200b\u1798\u17b7\u1793\u1798\u17b6\u1793\u200b\u200b\u200b\u17a2\u17ca\u17b8\u1793\u1792\u17ba\u178e\u17b7\u178f \u179f\u17bc\u1798\u200b\u200b\u1791\u17c5\u200b\u1780\u17b6\u1793\u17cb\u200b\u1780\u17b6\u179a\u200b\u1780\u17c6\u178e\u178f\u17cb\u200b\u1793\u17c5\u200b\u179b\u17be\u200b\u1782\u17c1\u17a0\u1791\u17c6\u1796\u17d0\u179a Google \u17af\u1780\u179f\u17b6\u179a \u1793\u17b7\u1784\u200b\u1794\u17be\u1780\u200b\u1780\u17b6\u179a\u1792\u17d2\u179c\u17be\u200b\u179f\u1798\u1780\u17b6\u179b\u1780\u1798\u17d2\u1798\u200b\u200b\u200b\u1782\u17d2\u1798\u17b6\u1793
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1895
                                                                                                                                                    Entropy (8bit):4.28990403715536
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:SHYGuEETiuF6OX5tCYFZt5GurMRRevsY4tVZIGnZRxlKT6/U0WG:yYG8iuF6yTCYFH5GjLPtVZVZRxOZ0J
                                                                                                                                                    MD5:38BE0974108FC1CC30F13D8230EE5C40
                                                                                                                                                    SHA1:ACF44889DD07DB97D26D534AD5AFA1BC1A827BAD
                                                                                                                                                    SHA-256:30078EF35A76E02A400F03B3698708A0145D9B57241CC4009E010696895CF3A1
                                                                                                                                                    SHA-512:7BDB2BADE4680801FC3B33E82C8AA4FAC648F45C795B4BACE4669D6E907A578FF181C093464884C0E00C9762E8DB75586A253D55CD10A7777D281B4BFFAFE302
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "........ .....".. },.. "explanationofflinedisabled": {.. "message": ".... ..................... ......... ............. Google ...... ....., Google ...... ............ ............... .... ..... ...... .... .... ............ ............. ........ ..... ... .....".. },.. "explanationofflineenabled": {.. "message": ".... ...................., .... .... .... ......... ........... ............ .... ........ .........."..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1042
                                                                                                                                                    Entropy (8bit):5.3945675025513955
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAWYsF4dqNfBQH49Hk8YfIhYzTJ+6WJBtl/u4s+6:ZF4wNfvm87mX4LF6
                                                                                                                                                    MD5:F3E59EEEB007144EA26306C20E04C292
                                                                                                                                                    SHA1:83E7BDFA1F18F4C7534208493C3FF6B1F2F57D90
                                                                                                                                                    SHA-256:C52D9B955D229373725A6E713334BBB31EA72EFA9B5CF4FBD76A566417B12CAC
                                                                                                                                                    SHA-512:7808CB5FF041B002CBD78171EC5A0B4DBA3E017E21F7E8039084C2790F395B839BEE04AD6C942EED47CCB53E90F6DE818A725D1450BF81BA2990154AFD3763AF
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".. ...".. },.. "explanationofflinedisabled": {.. "message": ".... ...... ... .. .. Google Docs. ..... Google Docs .... .... .... .... .... ..... . .... .... ..... ......".. },.. "explanationofflineenabled": {.. "message": ".... ...... ... .. ... ... ..... ... ... .. . .....".. },.. "extdesc": {.. "message": ".... .... ... .., ...... . ....... .., .., ......".. },.. "extname": {.. "message": "Google Docs ....".. },.. "learnmore": {.. "message": "... ....".. },.. "popuphelptext": {.. "message": "... .. ... .... ..... .... .... .....
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2535
                                                                                                                                                    Entropy (8bit):3.8479764584971368
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:YRcHe/4raK1EIlZt1wg62FIOg+xGaF8guI5EP9I2yC:+cs4raK1xlZtOgviOfGaF8RI5EP95b
                                                                                                                                                    MD5:E20D6C27840B406555E2F5091B118FC5
                                                                                                                                                    SHA1:0DCECC1A58CEB4936E255A64A2830956BFA6EC14
                                                                                                                                                    SHA-256:89082FB05229826BC222F5D22C158235F025F0E6DF67FF135A18BD899E13BB8F
                                                                                                                                                    SHA-512:AD53FC0B153005F47F9F4344DF6C4804049FAC94932D895FD02EEBE75222CFE77EEDD9CD3FDC4C88376D18C5972055B00190507AA896488499D64E884F84F093
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u0eaa\u0ec9\u0eb2\u0e87\u0ec3\u0edd\u0ec8"},"explanationofflinedisabled":{"message":"\u0e97\u0ec8\u0eb2\u0e99\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ea2\u0eb9\u0ec8. \u0ec0\u0e9e\u0eb7\u0ec8\u0ead\u0ec3\u0e8a\u0ec9 Google Docs \u0ec2\u0e94\u0e8d\u0e9a\u0ecd\u0ec8\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94, \u0ec3\u0eab\u0ec9\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e81\u0eb2\u0e99\u0e95\u0eb1\u0ec9\u0e87\u0e84\u0ec8\u0eb2\u0ec3\u0e99\u0edc\u0ec9\u0eb2 Google Docs \u0ec1\u0ea5\u0ec9\u0ea7\u0ec0\u0e9b\u0eb5\u0e94\u0ec3\u0e8a\u0ec9\u0e81\u0eb2\u0e99\u0e8a\u0eb4\u0ec9\u0e87\u0ec1\u0e9a\u0e9a\u0ead\u0ead\u0e9a\u0ea5\u0eb2\u0e8d\u0ec3\u0e99\u0ec0\u0e97\u0eb7\u0ec8\u0ead\u0e95\u0ecd\u0ec8\u0ec4\u0e9b\u0e97\u0eb5\u0ec8\u0e97\u0ec8\u0eb2\u0e99\u0ec0\u0e8a\u0eb7\u0ec8\u0ead\u0ea1\u0e95\u0ecd\u0ec8\u0ead\u0eb4\u0e99\u0ec0\u0e95\u0eb5\u0ec0\u0e99\u0eb1\u0e94."},"explanationofflineenabled":{"message":"\u0e97\u0ec
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1028
                                                                                                                                                    Entropy (8bit):4.797571191712988
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAivZZaJ3Rje394+k7IKgpAJjUpSkiQjuRBMd:fZZahBeu7IKgqeMg
                                                                                                                                                    MD5:970544AB4622701FFDF66DC556847652
                                                                                                                                                    SHA1:14BEE2B77EE74C5E38EBD1DB09E8D8104CF75317
                                                                                                                                                    SHA-256:5DFCBD4DFEAEC3ABE973A78277D3BD02CD77AE635D5C8CD1F816446C61808F59
                                                                                                                                                    SHA-512:CC12D00C10B970189E90D47390EEB142359A8D6F3A9174C2EF3AE0118F09C88AB9B689D9773028834839A7DFAF3AAC6747BC1DCB23794A9F067281E20B8DC6EA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SUKURTI NAUJ.".. },.. "explanationofflinedisabled": {.. "message": "Esate neprisijung.. Jei norite naudoti .Google. dokumentus be interneto ry.io, pagrindiniame .Google. dokument. puslapyje eikite . nustatym. skilt. ir .junkite sinchronizavim. neprisijungus, kai kit. kart. b.site prisijung. prie interneto.".. },.. "explanationofflineenabled": {.. "message": "Esate neprisijung., bet vis tiek galite redaguoti pasiekiamus failus arba sukurti nauj..".. },.. "extdesc": {.. "message": "Redaguokite, kurkite ir per.i.r.kite savo dokumentus, skai.iuokles ir pristatymus . visk. darykite be prieigos prie interneto.".. },.. "extname": {.. "message": ".Google. dokumentai neprisijungus".. },.. "learnmore": {.. "message": "Su.inoti daugiau".. },.. "popuphelptext": {.. "message": "Ra.ykite, redaguokite ir bendradarbiaukite bet kurioje vietoje naudodami interneto ry.. arba
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):994
                                                                                                                                                    Entropy (8bit):4.700308832360794
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAaJ7a/uNpoB/Y4vPnswSPkDzLKFQHpp//BpPDB:7J7a/uzQ/Y4vvswhDzDr/LDB
                                                                                                                                                    MD5:A568A58817375590007D1B8ABCAEBF82
                                                                                                                                                    SHA1:B0F51FE6927BB4975FC6EDA7D8A631BF0C1AB597
                                                                                                                                                    SHA-256:0621DE9161748F45D53052ED8A430962139D7F19074C7FFE7223ECB06B0B87DB
                                                                                                                                                    SHA-512:FCFBADEC9F73975301AB404DB6B09D31457FAC7CCAD2FA5BE348E1CAD6800F87CB5B56DE50880C55BBADB3C40423351A6B5C2D03F6A327D898E35F517B1C628C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "IZVEIDOT JAUNU".. },.. "explanationofflinedisabled": {.. "message": "J.s esat bezsaist.. Lai lietotu pakalpojumu Google dokumenti bez interneta savienojuma, n.kamaj. reiz., kad ir izveidots savienojums ar internetu, atveriet Google dokumentu s.kumlapas iestat.jumu izv.lni un iesl.dziet sinhroniz.ciju bezsaist..".. },.. "explanationofflineenabled": {.. "message": "J.s esat bezsaist., ta.u varat redi..t pieejamos failus un izveidot jaunus.".. },.. "extdesc": {.. "message": "Redi..jiet, veidojiet un skatiet savus dokumentus, izkl.jlapas un prezent.cijas, neizmantojot savienojumu ar internetu.".. },.. "extname": {.. "message": "Google dokumenti bezsaist.".. },.. "learnmore": {.. "message": "Uzziniet vair.k".. },.. "popuphelptext": {.. "message": "Rakstiet, redi..jiet un sadarbojieties ar interneta savienojumu vai bez t. neatkar.gi no t., kur atrodaties.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2091
                                                                                                                                                    Entropy (8bit):4.358252286391144
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAnHdGc4LtGxVY6IuVzJkeNL5kP13a67wNcYP8j5PIaSTIjPU4ELFPCWJjMupV/:idGcyYPVtkAUl7wqziBsg9DbpN6XoN/
                                                                                                                                                    MD5:4717EFE4651F94EFF6ACB6653E868D1A
                                                                                                                                                    SHA1:B8A7703152767FBE1819808876D09D9CC1C44450
                                                                                                                                                    SHA-256:22CA9415E294D9C3EC3384B9D08CDAF5164AF73B4E4C251559E09E529C843EA6
                                                                                                                                                    SHA-512:487EAB4938F6BC47B1D77DD47A5E2A389B94E01D29849E38E96C95CABC7BD98679451F0E22D3FEA25C045558CD69FDDB6C4FEF7C581141F1C53C4AA17578D7F7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....... ............".. },.. "explanationofflinedisabled": {.. "message": "...... ........... ........... ............. ..... Google ....... ..........., Google ....... .......... ............. .... ...... ...... ... ............... .................... '.......... ................' .........".. },.. "explanationofflineenabled": {.. "message": "................., .......... ......... ....... ...... ..............
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2778
                                                                                                                                                    Entropy (8bit):3.595196082412897
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:Y943BFU1LQ4HwQLQ4LQhlmVQL3QUm6H6ZgFIcwn6Rs2ShpQ3IwjGLQSJ/PYoEQj8:I43BCymz8XNcfuQDXYN2sum
                                                                                                                                                    MD5:83E7A14B7FC60D4C66BF313C8A2BEF0B
                                                                                                                                                    SHA1:1CCF1D79CDED5D65439266DB58480089CC110B18
                                                                                                                                                    SHA-256:613D8751F6CC9D3FA319F4B7EA8B2BD3BED37FD077482CA825929DD7C12A69A8
                                                                                                                                                    SHA-512:3742E24FFC4B5283E6EE496813C1BDC6835630D006E8647D427C3DE8B8E7BF814201ADF9A27BFAB3ABD130B6FEC64EBB102AC0EB8DEDFE7B63D82D3E1233305D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u0428\u0418\u041d\u0418\u0419\u0413 \u04ae\u04ae\u0421\u0413\u042d\u0425"},"explanationofflinedisabled":{"message":"\u0422\u0430 \u043e\u0444\u043b\u0430\u0439\u043d \u0431\u0430\u0439\u043d\u0430. Google \u0414\u043e\u043a\u044b\u0433 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u0433\u04af\u0439\u0433\u044d\u044d\u0440 \u0430\u0448\u0438\u0433\u043b\u0430\u0445\u044b\u043d \u0442\u0443\u043b\u0434 \u0434\u0430\u0440\u0430\u0430\u0433\u0438\u0439\u043d \u0443\u0434\u0430\u0430 \u0438\u043d\u0442\u0435\u0440\u043d\u044d\u0442\u044d\u0434 \u0445\u043e\u043b\u0431\u043e\u0433\u0434\u043e\u0445\u0434\u043e\u043e Google \u0414\u043e\u043a\u044b\u043d \u043d\u04af\u04af\u0440 \u0445\u0443\u0443\u0434\u0430\u0441\u043d\u0430\u0430\u0441 \u0442\u043e\u0445\u0438\u0440\u0433\u043e\u043e \u0434\u043e\u0442\u043e\u0440\u0445 \u043e\u0444\u043b\u0430\u0439\u043d \u0441\u0438\u043d\u043a\u0438\u0439\u0433 \u0438\u0434\u044d\u0432\u0445\u0436\u04af\u04af\u043b\u043d\u0
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1719
                                                                                                                                                    Entropy (8bit):4.287702203591075
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:65/5EKaDMw6pEf4I5+jSksOTJqQyrFO8C:65/5EKaAw6pEf4I5+vsOVqQyFO8C
                                                                                                                                                    MD5:3B98C4ED8874A160C3789FEAD5553CFA
                                                                                                                                                    SHA1:5550D0EC548335293D962AAA96B6443DD8ABB9F6
                                                                                                                                                    SHA-256:ADEB082A9C754DFD5A9D47340A3DDCC19BF9C7EFA6E629A2F1796305F1C9A66F
                                                                                                                                                    SHA-512:5139B6C6DF9459C7B5CDC08A98348891499408CD75B46519BA3AC29E99AAAFCC5911A1DEE6C3A57E3413DBD0FAE72D7CBC676027248DCE6364377982B5CE4151
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... .... ...".. },.. "explanationofflinedisabled": {.. "message": "...... ...... ..... ......... ....... ....... ..... Google ....... ............, Google ....... .............. .......... .. ... ..... .... ...... ......... ...... ...... ...... .... .... ....".. },.. "explanationofflineenabled": {.. "message": "...... ...... ...., ..... ...... ...... ...... .... ....... ... ..... .... .... ... .....".. },.. "extdesc": {.. "message": "..... ..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):936
                                                                                                                                                    Entropy (8bit):4.457879437756106
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HARXIqhmemNKsE27rhdfNLChtyo2JJ/YgTgin:iIqFC7lrDfNLCIBRzn
                                                                                                                                                    MD5:7D273824B1E22426C033FF5D8D7162B7
                                                                                                                                                    SHA1:EADBE9DBE5519BD60458B3551BDFC36A10049DD1
                                                                                                                                                    SHA-256:2824CF97513DC3ECC261F378BFD595AE95A5997E9D1C63F5731A58B1F8CD54F9
                                                                                                                                                    SHA-512:E5B611BBFAB24C9924D1D5E1774925433C65C322769E1F3B116254B1E9C69B6DF1BE7828141EEBBF7524DD179875D40C1D8F29C4FB86D663B8A365C6C60421A7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "BUAT BAHARU".. },.. "explanationofflinedisabled": {.. "message": "Anda berada di luar talian. Untuk menggunakan Google Docs tanpa sambungan Internet, pergi ke tetapan di halaman utama Google Docs dan hidupkan penyegerakan luar talian apabila anda disambungkan ke Internet selepas ini.".. },.. "explanationofflineenabled": {.. "message": "Anda berada di luar talian, tetapi anda masih boleh mengedit fail yang tersedia atau buat fail baharu.".. },.. "extdesc": {.. "message": "Edit, buat dan lihat dokumen, hamparan dan pembentangan anda . kesemuanya tanpa akses Internet.".. },.. "extname": {.. "message": "Google Docs Luar Talian".. },.. "learnmore": {.. "message": "Ketahui Lebih Lanjut".. },.. "popuphelptext": {.. "message": "Tulis, edit dan bekerjasama di mana-mana sahaja anda berada, dengan atau tanpa sambungan Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3830
                                                                                                                                                    Entropy (8bit):3.5483353063347587
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:Ya+Ivxy6ur1+j3P7Xgr5ELkpeCgygyOxONHO3pj6H57ODyOXOVp6:8Uspsj3P3ty2a66xl09
                                                                                                                                                    MD5:342335A22F1886B8BC92008597326B24
                                                                                                                                                    SHA1:2CB04F892E430DCD7705C02BF0A8619354515513
                                                                                                                                                    SHA-256:243BEFBD6B67A21433DCC97DC1A728896D3A070DC20055EB04D644E1BB955FE7
                                                                                                                                                    SHA-512:CD344D060E30242E5A4705547E807CE3CE2231EE983BB9A8AD22B3E7598A7EC87399094B04A80245AD51D039370F09D74FE54C0B0738583884A73F0C7E888AD8
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u1021\u101e\u1005\u103a \u1015\u103c\u102f\u101c\u102f\u1015\u103a\u101b\u1014\u103a"},"explanationofflinedisabled":{"message":"\u101e\u1004\u103a \u1021\u1031\u102c\u1037\u1016\u103a\u101c\u102d\u102f\u1004\u103a\u1038\u1016\u103c\u1005\u103a\u1014\u1031\u1015\u102b\u101e\u100a\u103a\u104b \u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u1019\u103e\u102f \u1019\u101b\u103e\u102d\u1018\u1032 Google Docs \u1000\u102d\u102f \u1021\u101e\u102f\u1036\u1038\u1015\u103c\u102f\u101b\u1014\u103a \u1014\u1031\u102c\u1000\u103a\u1010\u1005\u103a\u1000\u103c\u102d\u1019\u103a \u101e\u1004\u103a\u1021\u1004\u103a\u1010\u102c\u1014\u1000\u103a\u1001\u103b\u102d\u1010\u103a\u1006\u1000\u103a\u101e\u100a\u1037\u103a\u1021\u1001\u102b Google Docs \u1015\u1004\u103a\u1019\u1005\u102c\u1019\u103b\u1000\u103a\u1014\u103e\u102c\u101b\u103e\u102d \u1006\u1000\u103a\u1010\u1004\u103a\u1019\u103b\u102c\u1038\u101e\u102d\u102f\u1037\u1
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1898
                                                                                                                                                    Entropy (8bit):4.187050294267571
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAmQ6ZSWfAx6fLMr48tE/cAbJtUZJScSIQoAfboFMiQ9pdvz48YgqG:TQ6W6MbkcAltUJxQdfbqQ9pp0gqG
                                                                                                                                                    MD5:B1083DA5EC718D1F2F093BD3D1FB4F37
                                                                                                                                                    SHA1:74B6F050D918448396642765DEF1AD5390AB5282
                                                                                                                                                    SHA-256:E6ED0A023EF31705CCCBAF1E07F2B4B2279059296B5CA973D2070417BA16F790
                                                                                                                                                    SHA-512:7102B90ABBE2C811E8EE2F1886A73B1298D4F3D5D05F0FFDB57CF78B9A49A25023A290B255BAA4895BB150B388BAFD9F8432650B8C70A1A9A75083FFFCD74F1A
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".... ....... .........".. },.. "explanationofflinedisabled": {.. "message": "..... ...... .......... .... ........ .... .... Google ........ ...... .... ..... ..... ... .......... ....... .... Google ........ .......... ..... .......... .. ...... ..... .... ..... ......... .. ..........".. },.. "explanationofflineenabled": {.. "message": "..... ...... ........., .. ..... ... ... ...... ....... ....... .. .... ....... ....
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):914
                                                                                                                                                    Entropy (8bit):4.513485418448461
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgFARCBxNBv52/fXjOXl6W6ICBxeBvMzU1CSUJAO6SFAIVIbCBhZHdb1tvz+:1HABJx4X6QDwEzlm2uGvYzKU
                                                                                                                                                    MD5:32DF72F14BE59A9BC9777113A8B21DE6
                                                                                                                                                    SHA1:2A8D9B9A998453144307DD0B700A76E783062AD0
                                                                                                                                                    SHA-256:F3FE1FFCB182183B76E1B46C4463168C746A38E461FD25CA91FF2A40846F1D61
                                                                                                                                                    SHA-512:E0966F5CCA5A8A6D91C58D716E662E892D1C3441DAA5D632E5E843839BB989F620D8AC33ED3EDBAFE18D7306B40CD0C4639E5A4E04DA2C598331DACEC2112AAD
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "NIEUW MAKEN".. },.. "explanationofflinedisabled": {.. "message": "Je bent offline. Wil je Google Documenten zonder internetverbinding gebruiken, ga dan de volgende keer dat je verbinding met internet hebt naar 'Instellingen' op de homepage van Google Documenten en zet 'Offline synchronisatie' aan.".. },.. "explanationofflineenabled": {.. "message": "Je bent offline, maar je kunt nog wel beschikbare bestanden bewerken of nieuwe bestanden maken.".. },.. "extdesc": {.. "message": "Bewerk, maak en bekijk je documenten, spreadsheets en presentaties. Allemaal zonder internettoegang.".. },.. "extname": {.. "message": "Offline Documenten".. },.. "learnmore": {.. "message": "Meer informatie".. },.. "popuphelptext": {.. "message": "Overal schrijven, bewerken en samenwerken, met of zonder internetverbinding.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):878
                                                                                                                                                    Entropy (8bit):4.4541485835627475
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAqwwrJ6wky68uk+NILxRGJwBvDyrj9V:nwwQwky6W+NwswVyT
                                                                                                                                                    MD5:A1744B0F53CCF889955B95108367F9C8
                                                                                                                                                    SHA1:6A5A6771DFF13DCB4FD425ED839BA100B7123DE0
                                                                                                                                                    SHA-256:21CEFF02B45A4BFD60D144879DFA9F427949A027DD49A3EB0E9E345BD0B7C9A8
                                                                                                                                                    SHA-512:F55E43F14514EECB89F6727A0D3C234149609020A516B193542B5964D2536D192F40CC12D377E70C683C269A1BDCDE1C6A0E634AA84A164775CFFE776536A961
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "OPPRETT NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du er uten nett. For . bruke Google Dokumenter uten internettilkobling, g. til innstillingene p. Google Dokumenter-nettsiden og sl. p. synkronisering uten nett neste gang du er koblet til Internett.".. },.. "explanationofflineenabled": {.. "message": "Du er uten nett, men du kan likevel endre tilgjengelige filer eller opprette nye.".. },.. "extdesc": {.. "message": "Rediger, opprett og se dokumentene, regnearkene og presentasjonene dine . uten nettilgang.".. },.. "extname": {.. "message": "Google Dokumenter uten nett".. },.. "learnmore": {.. "message": "Finn ut mer".. },.. "popuphelptext": {.. "message": "Skriv, rediger eller samarbeid uansett hvor du er, med eller uten internettilkobling.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2766
                                                                                                                                                    Entropy (8bit):3.839730779948262
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:YEH6/o0iZbNCbDMUcipdkNtQjsGKIhO9aBjj/nxt9o5nDAj3:p6wbZbEbvJ8jQkIhO9aBjb/90Ab
                                                                                                                                                    MD5:97F769F51B83D35C260D1F8CFD7990AF
                                                                                                                                                    SHA1:0D59A76564B0AEE31D0A074305905472F740CECA
                                                                                                                                                    SHA-256:BBD37D41B7DE6F93948FA2437A7699D4C30A3C39E736179702F212CB36A3133C
                                                                                                                                                    SHA-512:D91F5E2D22FC2D7F73C1F1C4AF79DB98FCFD1C7804069AE9B2348CBC729A6D2DFF7FB6F44D152B0BDABA6E0D05DFF54987E8472C081C4D39315CEC2CBC593816
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u0a28\u0a35\u0a3e\u0a02 \u0a2c\u0a23\u0a3e\u0a13"},"explanationofflinedisabled":{"message":"\u0a24\u0a41\u0a38\u0a40\u0a02 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a39\u0a4b\u0964 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a15\u0a28\u0a48\u0a15\u0a36\u0a28 \u0a26\u0a47 \u0a2c\u0a3f\u0a28\u0a3e\u0a02 Google Docs \u0a28\u0a42\u0a70 \u0a35\u0a30\u0a24\u0a23 \u0a32\u0a08, \u0a05\u0a17\u0a32\u0a40 \u0a35\u0a3e\u0a30 \u0a1c\u0a26\u0a4b\u0a02 \u0a24\u0a41\u0a38\u0a40\u0a02 \u0a07\u0a70\u0a1f\u0a30\u0a28\u0a48\u0a71\u0a1f \u0a26\u0a47 \u0a28\u0a3e\u0a32 \u0a15\u0a28\u0a48\u0a15\u0a1f \u0a39\u0a4b\u0a35\u0a4b \u0a24\u0a3e\u0a02 Google Docs \u0a2e\u0a41\u0a71\u0a16 \u0a2a\u0a70\u0a28\u0a47 '\u0a24\u0a47 \u0a38\u0a48\u0a1f\u0a3f\u0a70\u0a17\u0a3e\u0a02 \u0a35\u0a3f\u0a71\u0a1a \u0a1c\u0a3e\u0a13 \u0a05\u0a24\u0a47 \u0a06\u0a2b\u0a3c\u0a32\u0a3e\u0a08\u0a28 \u0a38\u0a3f\u0a70\u0a15 \u0a28\u0a42\u0a70 \u0a1a\u0a3e\u0a32\u0a42 \u0a15\u0a30\u0a4b\u0964"},"expla
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):978
                                                                                                                                                    Entropy (8bit):4.879137540019932
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HApiJiRelvm3wi8QAYcbm24sK+tFJaSDD:FJMx3whxYcbNp
                                                                                                                                                    MD5:B8D55E4E3B9619784AECA61BA15C9C0F
                                                                                                                                                    SHA1:B4A9C9885FBEB78635957296FDDD12579FEFA033
                                                                                                                                                    SHA-256:E00FF20437599A5C184CA0C79546CB6500171A95E5F24B9B5535E89A89D3EC3D
                                                                                                                                                    SHA-512:266589116EEE223056391C65808255EDAE10EB6DC5C26655D96F8178A41E283B06360AB8E08AC3857D172023C4F616EF073D0BEA770A3B3DD3EE74F5FFB2296B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "UTW.RZ NOWY".. },.. "explanationofflinedisabled": {.. "message": "Jeste. offline. Aby korzysta. z Dokument.w Google bez po..czenia internetowego, otw.rz ustawienia na stronie g..wnej Dokument.w Google i w..cz synchronizacj. offline nast.pnym razem, gdy b.dziesz mie. dost.p do internetu.".. },.. "explanationofflineenabled": {.. "message": "Jeste. offline, ale nadal mo.esz edytowa. dost.pne pliki i tworzy. nowe.".. },.. "extdesc": {.. "message": "Edytuj, tw.rz i wy.wietlaj swoje dokumenty, arkusze kalkulacyjne oraz prezentacje bez konieczno.ci ..czenia si. z internetem.".. },.. "extname": {.. "message": "Dokumenty Google offline".. },.. "learnmore": {.. "message": "Wi.cej informacji".. },.. "popuphelptext": {.. "message": "Pisz, edytuj i wsp..pracuj, gdziekolwiek jeste. . niezale.nie od tego, czy masz po..czenie z internetem.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):907
                                                                                                                                                    Entropy (8bit):4.599411354657937
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgU30CBxNd6GwXOK1styCJ02OK9+4KbCBxed6X4LBAt4rXgUCSUuYDHIIQka:1HAcXlyCJ5+Tsz4LY4rXSw/Q+ftkC
                                                                                                                                                    MD5:608551F7026E6BA8C0CF85D9AC11F8E3
                                                                                                                                                    SHA1:87B017B2D4DA17E322AF6384F82B57B807628617
                                                                                                                                                    SHA-256:A73EEA087164620FA2260D3910D3FBE302ED85F454EDB1493A4F287D42FC882F
                                                                                                                                                    SHA-512:82F52F8591DB3C0469CC16D7CBFDBF9116F6D5B5D2AD02A3D8FA39CE1378C64C0EA80AB8509519027F71A89EB8BBF38A8702D9AD26C8E6E0F499BF7DA18BF747
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Voc. est. off-line. Para usar o Documentos Google sem conex.o com a Internet, na pr.xima vez que se conectar, acesse as configura..es na p.gina inicial do Documentos Google e ative a sincroniza..o off-line.".. },.. "explanationofflineenabled": {.. "message": "Voc. est. off-line, mas mesmo assim pode editar os arquivos dispon.veis ou criar novos arquivos.".. },.. "extdesc": {.. "message": "Edite, crie e veja seus documentos, planilhas e apresenta..es sem precisar de acesso . Internet.".. },.. "extname": {.. "message": "Documentos Google off-line".. },.. "learnmore": {.. "message": "Saiba mais".. },.. "popuphelptext": {.. "message": "Escreva, edite e colabore onde voc. estiver, com ou sem conex.o com a Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):914
                                                                                                                                                    Entropy (8bit):4.604761241355716
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAcXzw8M+N0STDIjxX+qxCjKw5BKriEQFMJXkETs:zXzw0pKXbxqKw5BKri3aNY
                                                                                                                                                    MD5:0963F2F3641A62A78B02825F6FA3941C
                                                                                                                                                    SHA1:7E6972BEAB3D18E49857079A24FB9336BC4D2D48
                                                                                                                                                    SHA-256:E93B8E7FB86D2F7DFAE57416BB1FB6EE0EEA25629B972A5922940F0023C85F90
                                                                                                                                                    SHA-512:22DD42D967124DA5A2209DD05FB6AD3F5D0D2687EA956A22BA1E31C56EC09DEB53F0711CD5B24D672405358502E9D1C502659BB36CED66CAF83923B021CA0286
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CRIAR NOVO".. },.. "explanationofflinedisabled": {.. "message": "Est. offline. Para utilizar o Google Docs sem uma liga..o . Internet, aceda .s defini..es na p.gina inicial do Google Docs e ative a sincroniza..o offline da pr.xima vez que estiver ligado . Internet.".. },.. "explanationofflineenabled": {.. "message": "Est. offline, mas continua a poder editar os ficheiros dispon.veis ou criar novos ficheiros.".. },.. "extdesc": {.. "message": "Edite, crie e veja os documentos, as folhas de c.lculo e as apresenta..es, tudo sem precisar de aceder . Internet.".. },.. "extname": {.. "message": "Google Docs offline".. },.. "learnmore": {.. "message": "Saber mais".. },.. "popuphelptext": {.. "message": "Escreva edite e colabore onde quer que esteja, com ou sem uma liga..o . Internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):937
                                                                                                                                                    Entropy (8bit):4.686555713975264
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA8dC6e6w+uFPHf2TFMMlecFpweWV4RE:pC6KvHf4plVweCx
                                                                                                                                                    MD5:BED8332AB788098D276B448EC2B33351
                                                                                                                                                    SHA1:6084124A2B32F386967DA980CBE79DD86742859E
                                                                                                                                                    SHA-256:085787999D78FADFF9600C9DC5E3FF4FB4EB9BE06D6BB19DF2EEF8C284BE7B20
                                                                                                                                                    SHA-512:22596584D10707CC1C8179ED3ABE46EF2C314CF9C3D0685921475944B8855AAB660590F8FA1CFDCE7976B4BB3BD9ABBBF053F61F1249A325FD0094E1C95692ED
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "CREEAZ. UN DOCUMENT".. },.. "explanationofflinedisabled": {.. "message": "E.ti offline. Pentru a utiliza Documente Google f.r. conexiune la internet, intr. .n set.rile din pagina principal. Documente Google .i activeaz. sincronizarea offline data viitoare c.nd e.ti conectat(.) la internet.".. },.. "explanationofflineenabled": {.. "message": "E.ti offline, dar po.i .nc. s. editezi fi.ierele disponibile sau s. creezi altele.".. },.. "extdesc": {.. "message": "Editeaz., creeaz. .i acceseaz. documente, foi de calcul .i prezent.ri - totul f.r. acces la internet.".. },.. "extname": {.. "message": "Documente Google Offline".. },.. "learnmore": {.. "message": "Afl. mai multe".. },.. "popuphelptext": {.. "message": "Scrie, editeaz. .i colaboreaz. oriunde ai fi, cu sau f.r. conexiune la internet.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1337
                                                                                                                                                    Entropy (8bit):4.69531415794894
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HABEapHTEmxUomjsfDVs8THjqBK8/hHUg41v+Lph5eFTHQ:I/VdxUomjsre8Kh4Riph5eFU
                                                                                                                                                    MD5:51D34FE303D0C90EE409A2397FCA437D
                                                                                                                                                    SHA1:B4B9A7B19C62D0AA95D1F10640A5FBA628CCCA12
                                                                                                                                                    SHA-256:BE733625ACD03158103D62BC0EEF272CA3F265AC30C87A6A03467481A177DAE3
                                                                                                                                                    SHA-512:E8670DED44DC6EE30E5F41C8B2040CF8A463CD9A60FC31FA70EB1D4C9AC1A3558369792B5B86FA761A21F5266D5A35E5C2C39297F367DAA84159585C19EC492A
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".......".. },.. "explanationofflinedisabled": {.. "message": "..... ............ Google ......... ... ........., ............ . .... . ......... ............. . ......-...... . .......... .. ......... .........".. },.. "explanationofflineenabled": {.. "message": "... ........... . .......... .. ...... ......... ..... ..... . ............. .., . ....... ........ ......-.......".. },.. "extdesc": {.. "message": ".........., .............. . ............ ........., ....... . ........... ... ....... . ..........".. },.. "extname": {.. "message": "Google.......... ......".. },.. "learnmore": {.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2846
                                                                                                                                                    Entropy (8bit):3.7416822879702547
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:YWi+htQTKEQb3aXQYJLSWy7sTQThQTnQtQTrEmQ6kiLsegQSJFwsQGaiPn779I+S:zhiTK5b3tUGVjTGTnQiTryOLpyaxYf/S
                                                                                                                                                    MD5:B8A4FD612534A171A9A03C1984BB4BDD
                                                                                                                                                    SHA1:F513F7300827FE352E8ECB5BD4BB1729F3A0E22A
                                                                                                                                                    SHA-256:54241EBE651A8344235CC47AFD274C080ABAEBC8C3A25AFB95D8373B6A5670A2
                                                                                                                                                    SHA-512:C03E35BFDE546AEB3245024EF721E7E606327581EFE9EAF8C5B11989D9033BDB58437041A5CB6D567BAA05466B6AAF054C47F976FD940EEEDF69FDF80D79095B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u0db1\u0dc0 \u0dbd\u0dda\u0d9b\u0db1\u0dba\u0d9a\u0dca \u0dc3\u0dcf\u0daf\u0db1\u0dca\u0db1"},"explanationofflinedisabled":{"message":"\u0d94\u0db6 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2\u0dba. \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd \u0dc3\u0db8\u0dca\u0db6\u0db1\u0dca\u0db0\u0dad\u0dcf\u0dc0\u0d9a\u0dca \u0db1\u0ddc\u0db8\u0dd0\u0dad\u0dd2\u0dc0 Google Docs \u0db7\u0dcf\u0dc0\u0dd2\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8\u0da7, Google Docs \u0db8\u0dd4\u0dbd\u0dca \u0db4\u0dd2\u0da7\u0dd4\u0dc0 \u0db8\u0dad \u0dc3\u0dd0\u0d9a\u0dc3\u0dd3\u0db8\u0dca \u0dc0\u0dd9\u0dad \u0d9c\u0ddc\u0dc3\u0dca \u0d94\u0db6 \u0d8a\u0dc5\u0d9f \u0d85\u0dc0\u0dc3\u0dca\u0dae\u0dcf\u0dc0\u0dda \u0d85\u0db1\u0dca\u0dad\u0dbb\u0dca\u0da2\u0dcf\u0dbd\u0dba\u0da7 \u0dc3\u0db6\u0dd0\u0db3\u0dd2 \u0dc0\u0dd2\u0da7 \u0db1\u0ddc\u0db6\u0dd0\u0db3\u0dd2 \u0dc3\u0db8\u0db8\u0dd4\u0dc4\u0dd4\u0dbb\u0dca\u0dad \u0d9a\u0dd2\u0dbb\u0dd3\u0db8 \u0d9a\u0dca\u200d\u0dbb\u0dd2\u0dba\u0dc
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):934
                                                                                                                                                    Entropy (8bit):4.882122893545996
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAF8pMv1RS4LXL22IUjdh8uJwpPqLDEtxKLhSS:hyv1RS4LXx38u36QsS
                                                                                                                                                    MD5:8E55817BF7A87052F11FE554A61C52D5
                                                                                                                                                    SHA1:9ABDC0725FE27967F6F6BE0DF5D6C46E2957F455
                                                                                                                                                    SHA-256:903060EC9E76040B46DEB47BBB041D0B28A6816CB9B892D7342FC7DC6782F87C
                                                                                                                                                    SHA-512:EFF9EC7E72B272DDE5F29123653BC056A4BC2C3C662AE3C448F8CB6A4D1865A0679B7E74C1B3189F3E262109ED6BC8F8D2BDE14AEFC8E87E0F785AE4837D01C7
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "VYTVORI. NOV.".. },.. "explanationofflinedisabled": {.. "message": "Ste offline. Ak chcete pou.i. Dokumenty Google bez pripojenia na internet, po najbli..om pripojen. na internet prejdite do nastaven. na domovskej str.nke Dokumentov Google a.zapnite offline synchroniz.ciu.".. },.. "explanationofflineenabled": {.. "message": "Ste offline, no st.le m..ete upravova. dostupn. s.bory a.vytv.ra. nov..".. },.. "extdesc": {.. "message": ".prava, tvorba a.zobrazenie dokumentov, tabuliek a.prezent.ci.. To v.etko bez pr.stupu na internet.".. },.. "extname": {.. "message": "Dokumenty Google v re.ime offline".. },.. "learnmore": {.. "message": ".al.ie inform.cie".. },.. "popuphelptext": {.. "message": "P..te, upravujte a.spolupracuje, kdeko.vek ste, a.to s.pripojen.m na internet aj bez neho.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):963
                                                                                                                                                    Entropy (8bit):4.6041913416245
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgfECBxNFCEuKXowwJrpvPwNgEcPJJJEfWOCBxeFCJuGuU4KYXCSUXKDxX4A:1HAXMKYw8VYNLcaeDmKYLdX2zJBG5
                                                                                                                                                    MD5:BFAEFEFF32813DF91C56B71B79EC2AF4
                                                                                                                                                    SHA1:F8EDA2B632610972B581724D6B2F9782AC37377B
                                                                                                                                                    SHA-256:AAB9CF9098294A46DC0F2FA468AFFF7CA7C323A1A0EFA70C9DB1E3A4DA05D1D4
                                                                                                                                                    SHA-512:971F2BBF5E9C84DE3D31E5F2A4D1A00D891A2504F8AF6D3F75FC19056BFD059A270C4C9836AF35258ABA586A1888133FB22B484F260C1CBC2D1D17BC3B4451AA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "USTVARI NOVO".. },.. "explanationofflinedisabled": {.. "message": "Nimate vzpostavljene povezave. .e .elite uporabljati Google Dokumente brez internetne povezave, odprite nastavitve na doma.i strani Google Dokumentov in vklopite sinhronizacijo brez povezave, ko naslednji. vzpostavite internetno povezavo.".. },.. "explanationofflineenabled": {.. "message": "Nimate vzpostavljene povezave, vendar lahko .e vedno urejate razpolo.ljive datoteke ali ustvarjate nove.".. },.. "extdesc": {.. "message": "Urejajte, ustvarjajte in si ogledujte dokumente, preglednice in predstavitve . vse to brez internetnega dostopa.".. },.. "extname": {.. "message": "Google Dokumenti brez povezave".. },.. "learnmore": {.. "message": "Ve. o tem".. },.. "popuphelptext": {.. "message": "Pi.ite, urejajte in sodelujte, kjer koli ste, z internetno povezavo ali brez nje.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1320
                                                                                                                                                    Entropy (8bit):4.569671329405572
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HArg/fjQg2JwrfZtUWTrw1P4epMnRGi5TBmuPDRxZQ/XtiCw/Rwh/Q9EVz:ogUg2JwDZe6rwKI8VTP9xK1CwhI94
                                                                                                                                                    MD5:7F5F8933D2D078618496C67526A2B066
                                                                                                                                                    SHA1:B7050E3EFA4D39548577CF47CB119FA0E246B7A4
                                                                                                                                                    SHA-256:4E8B69E864F57CDDD4DC4E4FAF2C28D496874D06016BC22E8D39E0CB69552769
                                                                                                                                                    SHA-512:0FBAB56629368EEF87DEEF2977CA51831BEB7DEAE98E02504E564218425C751853C4FDEAA40F51ECFE75C633128B56AE105A6EB308FD5B4A2E983013197F5DBA
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "....... ....".. },.. "explanationofflinedisabled": {.. "message": "...... .... .. ..... ......... Google ......... ... ........ ...., ..... . .......... .. ........ ........ Google .......... . ........ ...... .............. ... ....... ... ...... ........ .. ...........".. },.. "explanationofflineenabled": {.. "message": "...... ..., ... . .... ...... .. ....... ...... . ........ ........ ... .. ....... .....".. },.. "extdesc": {.. "message": "....... . ........... ........., ...... . ............ . ....... ...... . ... . ... .. ... ........ .........".. },.. "extname": {.. "message
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):884
                                                                                                                                                    Entropy (8bit):4.627108704340797
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HA0NOYT/6McbnX/yzklyOIPRQrJlvDymvBd:vNOcyHnX/yg0P4Bymn
                                                                                                                                                    MD5:90D8FB448CE9C0B9BA3D07FB8DE6D7EE
                                                                                                                                                    SHA1:D8688CAC0245FD7B886D0DEB51394F5DF8AE7E84
                                                                                                                                                    SHA-256:64B1E422B346AB77C5D1C77142685B3FF7661D498767D104B0C24CB36D0EB859
                                                                                                                                                    SHA-512:6D58F49EE3EF0D3186EA036B868B2203FE936CE30DC8E246C32E90B58D9B18C624825419346B62AF8F7D61767DBE9721957280AA3C524D3A5DFB1A3A76C00742
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "SKAPA NYTT".. },.. "explanationofflinedisabled": {.. "message": "Du .r offline. Om du vill anv.nda Google Dokument utan internetuppkoppling, .ppna inst.llningarna p. Google Dokuments startsida och aktivera offlinesynkronisering n.sta g.ng du .r ansluten till internet.".. },.. "explanationofflineenabled": {.. "message": "Du .r offline, men det g.r fortfarande att redigera tillg.ngliga filer eller skapa nya.".. },.. "extdesc": {.. "message": "Redigera, skapa och visa dina dokument, kalkylark och presentationer . helt utan internet.tkomst.".. },.. "extname": {.. "message": "Google Dokument Offline".. },.. "learnmore": {.. "message": "L.s mer".. },.. "popuphelptext": {.. "message": "Skriv, redigera och samarbeta .verallt, med eller utan internetanslutning.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):980
                                                                                                                                                    Entropy (8bit):4.50673686618174
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgNHCBxNx1HMHyMhybK7QGU78oCuafIvfCBxex6EYPE5E1pOCSUJqONtCBh8:1HAGDQ3y0Q/Kjp/zhDoKMkeAT6dBaX
                                                                                                                                                    MD5:D0579209686889E079D87C23817EDDD5
                                                                                                                                                    SHA1:C4F99E66A5891973315D7F2BC9C1DAA524CB30DC
                                                                                                                                                    SHA-256:0D20680B74AF10EF8C754FCDE259124A438DCE3848305B0CAF994D98E787D263
                                                                                                                                                    SHA-512:D59911F91ED6C8FF78FD158389B4D326DAF4C031B940C399569FE210F6985E23897E7F404B7014FC7B0ACEC086C01CC5F76354F7E5D3A1E0DEDEF788C23C2978
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "FUNGUA MPYA".. },.. "explanationofflinedisabled": {.. "message": "Haupo mtandaoni. Ili uweze kutumia Hati za Google bila muunganisho wa intaneti, wakati utakuwa umeunganishwa kwenye intaneti, nenda kwenye sehemu ya mipangilio kwenye ukurasa wa kwanza wa Hati za Google kisha uwashe kipengele cha usawazishaji nje ya mtandao.".. },.. "explanationofflineenabled": {.. "message": "Haupo mtandaoni, lakini bado unaweza kubadilisha faili zilizopo au uunde mpya.".. },.. "extdesc": {.. "message": "Badilisha, unda na uangalie hati, malahajedwali na mawasilisho yako . yote bila kutumia muunganisho wa intaneti.".. },.. "extname": {.. "message": "Hati za Google Nje ya Mtandao".. },.. "learnmore": {.. "message": "Pata Maelezo Zaidi".. },.. "popuphelptext": {.. "message": "Andika hati, zibadilishe na ushirikiane na wengine popote ulipo, iwe una muunganisho wa intaneti au huna.".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1941
                                                                                                                                                    Entropy (8bit):4.132139619026436
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAoTZwEj3YfVLiANpx96zjlXTwB4uNJDZwq3CP1B2xIZiIH1CYFIZ03SoFyxrph:JCEjWiAD0ZXkyYFyPND1L/I
                                                                                                                                                    MD5:DCC0D1725AEAEAAF1690EF8053529601
                                                                                                                                                    SHA1:BB9D31859469760AC93E84B70B57909DCC02EA65
                                                                                                                                                    SHA-256:6282BF9DF12AD453858B0B531C8999D5FD6251EB855234546A1B30858462231A
                                                                                                                                                    SHA-512:6243982D764026D342B3C47C706D822BB2B0CAFFA51F0591D8C878F981EEF2A7FC68B76D012630B1C1EB394AF90EB782E2B49329EB6538DD5608A7F0791FDCF5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ....... .........".. },.. "explanationofflinedisabled": {.. "message": ".......... ........... .... ....... ..... Google ......... .........., ...... .... ........... ......... ...., Google ... ................... ................ ......, ........ ......... ..........".. },.. "explanationofflineenabled": {.. "message": ".......... ..........., .......... .......... .......... ......... ........... ...... .....
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1969
                                                                                                                                                    Entropy (8bit):4.327258153043599
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:R7jQrEONienBcFNBNieCyOBw0/kCcj+sEf24l+Q+u1LU4ljCj55ONipR41ssrNix:RjQJN1nBcFNBNlCyGcj+RXl+Q+u1LU4s
                                                                                                                                                    MD5:385E65EF723F1C4018EEE6E4E56BC03F
                                                                                                                                                    SHA1:0CEA195638A403FD99BAEF88A360BD746C21DF42
                                                                                                                                                    SHA-256:026C164BAE27DBB36A564888A796AA3F188AAD9E0C37176D48910395CF772CEA
                                                                                                                                                    SHA-512:E55167CB5638E04DF3543D57C8027B86B9483BFCAFA8E7C148EDED66454AEBF554B4C1CF3C33E93EC63D73E43800D6A6E7B9B1A1B0798B6BDB2F699D3989B052
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..... ...... ........ ......".. },.. "explanationofflinedisabled": {.. "message": ".... ........... ........ ......... ........ ....... Google Docs... .............., .... ............ ....... ..... ...... .... Google Docs .... ...... ............. ......, ........ ........ ... .......".. },.. "explanationofflineenabled": {.. "message": ".... ........... ......., .... .... ........ .......... .... ....... ..... ....... .... ..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1674
                                                                                                                                                    Entropy (8bit):4.343724179386811
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:fcGjnU3UnGKD1GeU3pktOggV1tL2ggG7Q:f3jnDG1eUk0g6RLE
                                                                                                                                                    MD5:64077E3D186E585A8BEA86FF415AA19D
                                                                                                                                                    SHA1:73A861AC810DABB4CE63AD052E6E1834F8CA0E65
                                                                                                                                                    SHA-256:D147631B2334A25B8AA4519E4A30FB3A1A85B6A0396BC688C68DC124EC387D58
                                                                                                                                                    SHA-512:56DD389EB9DD335A6214E206B3BF5D63562584394D1DE1928B67D369E548477004146E6CB2AD19D291CB06564676E2B2AC078162356F6BC9278B04D29825EF0C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".........".. },.. "explanationofflinedisabled": {.. "message": ".............. ............. Google .................................... ............................... Google ...... .................................................................".. },.. "explanationofflineenabled": {.. "message": "................................................................".. },.. "extdesc": {.. "message": "..... ..... ........
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1063
                                                                                                                                                    Entropy (8bit):4.853399816115876
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAowYuBPgoMC4AGehrgGm7tJ3ckwFrXnRs5m:GYsPgrCtGehkGc3cvXr
                                                                                                                                                    MD5:76B59AAACC7B469792694CF3855D3F4C
                                                                                                                                                    SHA1:7C04A2C1C808FA57057A4CCEEE66855251A3C231
                                                                                                                                                    SHA-256:B9066A162BEE00FD50DC48C71B32B69DFFA362A01F84B45698B017A624F46824
                                                                                                                                                    SHA-512:2E507CA6874DE8028DC769F3D9DFD9E5494C268432BA41B51568D56F7426F8A5F2E5B111DDD04259EB8D9A036BB4E3333863A8FC65AAB793BCEF39EDFE41403B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "YEN. OLU.TUR".. },.. "explanationofflinedisabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Google Dok.manlar'. .nternet ba.lant.s. olmadan kullanmak i.in, .nternet'e ba.lanabildi.inizde Google Dok.manlar ana sayfas.nda Ayarlar'a gidin ve .evrimd... senkronizasyonu etkinle.tirin.".. },.. "explanationofflineenabled": {.. "message": ".nternet'e ba.l. de.ilsiniz. Ancak, yine de mevcut dosyalar. d.zenleyebilir veya yeni dosyalar olu.turabilirsiniz.".. },.. "extdesc": {.. "message": "Dok.man, e-tablo ve sunu olu.turun, bunlar. d.zenleyin ve g.r.nt.leyin. T.m bu i.lemleri internet eri.imi olmadan yapabilirsiniz.".. },.. "extname": {.. "message": "Google Dok.manlar .evrimd...".. },.. "learnmore": {.. "message": "Daha Fazla Bilgi".. },.. "popuphelptext": {.. "message": ".nternet ba.lant.n.z olsun veya olmas.n, nerede olursan.z olun yaz.n, d.zenl
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1333
                                                                                                                                                    Entropy (8bit):4.686760246306605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAk9oxkm6H4KyGGB9GeGoxPEYMQhpARezTtHUN97zlwpEH7:VKU1GB9GeBc/OARETt+9/WCb
                                                                                                                                                    MD5:970963C25C2CEF16BB6F60952E103105
                                                                                                                                                    SHA1:BBDDACFEEE60E22FB1C130E1EE8EFDA75EA600AA
                                                                                                                                                    SHA-256:9FA26FF09F6ACDE2457ED366C0C4124B6CAC1435D0C4FD8A870A0C090417DA19
                                                                                                                                                    SHA-512:1BED9FE4D4ADEED3D0BC8258D9F2FD72C6A177C713C3B03FC6F5452B6D6C2CB2236C54EA972ECE7DBFD756733805EB2352CAE44BAB93AA8EA73BB80460349504
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "........".. },.. "explanationofflinedisabled": {.. "message": ".. . ...... ....... ... ............. Google ........... ... ......... . .........., ......... . ............ .. ........ ........ Google .......... . ......... ......-............., .... ...... . .......".. },.. "explanationofflineenabled": {.. "message": ".. . ...... ......, ..... ... .... ...... .......... ........ ..... ... .......... .....".. },.. "extdesc": {.. "message": "........., ......... . ............ ........., .......... ....... .. ........... ... ....... .. ..........".. },.. "extname": {.. "message": "Goo
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1263
                                                                                                                                                    Entropy (8bit):4.861856182762435
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAl3zNEUhN3mNjkSIkmdNpInuUVsqNtOJDhY8Dvp/IkLzx:e3uUhQKvkmd+s11Lp1F
                                                                                                                                                    MD5:8B4DF6A9281333341C939C244DDB7648
                                                                                                                                                    SHA1:382C80CAD29BCF8AAF52D9A24CA5A6ECF1941C6B
                                                                                                                                                    SHA-256:5DA836224D0F3A96F1C5EB5063061AAD837CA9FC6FED15D19C66DA25CF56F8AC
                                                                                                                                                    SHA-512:FA1C015D4EA349F73468C78FDB798D462EEF0F73C1A762298798E19F825E968383B0A133E0A2CE3B3DF95F24C71992235BFC872C69DC98166B44D3183BF8A9E5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "... ......".. },.. "explanationofflinedisabled": {.. "message": ".. .. .... .... Google Docs .. .... ....... ..... ....... .... ..... .... ... .. .. ....... .. ..... ... .. Google Docs ... ... .. ....... .. ..... ... .. .... ...... ..... .. .. .....".. },.. "explanationofflineenabled": {.. "message": ".. .. .... ... .... .. ... ... ...... ..... ... ..... .. .... ... .. ... ..... ... .... ....".. },.. "extdesc": {.. "message": ".......... .......... ... ....... . .... ... ....... .. ..... .. .... ...... ..... .... ... ..... .......".. },.. "extname": {.. "message": "Google Docs .. ....".. },.. "learnmore": {..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1074
                                                                                                                                                    Entropy (8bit):5.062722522759407
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HAhBBLEBOVUSUfE+eDFmj4BLErQ7e2CIer32KIxqJ/HtNiE5nIGeU+KCVT:qHCDheDFmjDQgX32/S/hI9jh
                                                                                                                                                    MD5:773A3B9E708D052D6CBAA6D55C8A5438
                                                                                                                                                    SHA1:5617235844595D5C73961A2C0A4AC66D8EA5F90F
                                                                                                                                                    SHA-256:597C5F32BC999746BC5C2ED1E5115C523B7EB1D33F81B042203E1C1DF4BBCAFE
                                                                                                                                                    SHA-512:E5F906729E38B23F64D7F146FA48F3ABF6BAED9AAFC0E5F6FA59F369DC47829DBB4BFA94448580BD61A34E844241F590B8D7AEC7091861105D8EBB2590A3BEE9
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "T.O M.I".. },.. "explanationofflinedisabled": {.. "message": "B.n .ang ngo.i tuy.n. .. s. d.ng Google T.i li.u m. kh.ng c.n k.t n.i Internet, .i ..n c.i ..t tr.n trang ch. c.a Google T.i li.u v. b.t ..ng b. h.a ngo.i tuy.n v.o l.n ti.p theo b.n ...c k.t n.i v.i m.ng Internet.".. },.. "explanationofflineenabled": {.. "message": "B.n .ang ngo.i tuy.n, tuy nhi.n b.n v.n c. th. ch.nh s.a c.c t.p c. s.n ho.c t.o c.c t.p m.i.".. },.. "extdesc": {.. "message": "Ch.nh s.a, t.o v. xem t.i li.u, b.ng t.nh v. b.n tr.nh b.y . t.t c. m. kh.ng c.n truy c.p Internet.".. },.. "extname": {.. "message": "Google T.i li.u ngo.i tuy.n".. },.. "learnmore": {.. "message": "Ti.m hi..u th.m".. },.. "popuphelptext": {.. "message": "Vi.t, ch.nh s.a v. c.ng t.c
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):879
                                                                                                                                                    Entropy (8bit):5.7905809868505544
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgteHCBxNtSBXuetOrgIkA2OrWjMOCBxetSBXK01fg/SOiCSUEQ27e1CBhUj:1HAFsHtrIkA2jqldI/727eggcLk9pf
                                                                                                                                                    MD5:3E76788E17E62FB49FB5ED5F4E7A3DCE
                                                                                                                                                    SHA1:6904FFA0D13D45496F126E58C886C35366EFCC11
                                                                                                                                                    SHA-256:E72D0BB08CC3005556E95A498BD737E7783BB0E56DCC202E7D27A536616F5EE0
                                                                                                                                                    SHA-512:F431E570AB5973C54275C9EEF05E49E6FE2D6C17000F98D672DD31F9A1FAD98E0D50B5B0B9CF85D5BBD3B655B93FD69768C194C8C1688CB962AA75FF1AF9BDB6
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": "..".. },.. "explanationofflinedisabled": {.. "message": "....................... Google ................ Google ....................".. },.. "explanationofflineenabled": {.. "message": ".............................".. },.. "extdesc": {.. "message": "...................... - ........".. },.. "extname": {.. "message": "Google .......".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "...............................".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1205
                                                                                                                                                    Entropy (8bit):4.50367724745418
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:YWvqB0f7Cr591AhI9Ah8U1F4rw4wtB9G976d6BY9scKUrPoAhNehIrI/uIXS1:YWvl7Cr5JHrw7k7u6BY9trW+rHR
                                                                                                                                                    MD5:524E1B2A370D0E71342D05DDE3D3E774
                                                                                                                                                    SHA1:60D1F59714F9E8F90EF34138D33FBFF6DD39E85A
                                                                                                                                                    SHA-256:30F44CFAD052D73D86D12FA20CFC111563A3B2E4523B43F7D66D934BA8DACE91
                                                                                                                                                    SHA-512:D2225CF2FA94B01A7B0F70A933E1FDCF69CDF92F76C424CE4F9FCC86510C481C9A87A7B71F907C836CBB1CA41A8BEBBD08F68DBC90710984CA738D293F905272
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"\u5efa\u7acb\u65b0\u9805\u76ee"},"explanationofflinedisabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\u3002\u5982\u8981\u5728\u6c92\u6709\u4e92\u806f\u7db2\u9023\u7dda\u7684\u60c5\u6cc1\u4e0b\u4f7f\u7528\u300cGoogle \u6587\u4ef6\u300d\uff0c\u8acb\u524d\u5f80\u300cGoogle \u6587\u4ef6\u300d\u9996\u9801\u7684\u8a2d\u5b9a\uff0c\u4e26\u5728\u4e0b\u6b21\u9023\u63a5\u4e92\u806f\u7db2\u6642\u958b\u555f\u96e2\u7dda\u540c\u6b65\u529f\u80fd\u3002"},"explanationofflineenabled":{"message":"\u60a8\u8655\u65bc\u96e2\u7dda\u72c0\u614b\uff0c\u4f46\u60a8\u4ecd\u53ef\u4ee5\u7de8\u8f2f\u53ef\u7528\u6a94\u6848\u6216\u5efa\u7acb\u65b0\u6a94\u6848\u3002"},"extdesc":{"message":"\u7de8\u8f2f\u3001\u5efa\u7acb\u53ca\u67e5\u770b\u60a8\u7684\u6587\u4ef6\u3001\u8a66\u7b97\u8868\u548c\u7c21\u5831\uff0c\u5b8c\u5168\u4e0d\u9700\u4f7f\u7528\u4e92\u806f\u7db2\u3002"},"extname":{"message":"\u300cGoogle \u6587\u4ef6\u300d\u96e2\u7dda\u7248"},"learnmore":{"message":"\u77ad\u89e3\u8a
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):843
                                                                                                                                                    Entropy (8bit):5.76581227215314
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:1HASvgmaCBxNtBtA24ZOuAeOEHGOCBxetBtMHQIJECSUnLRNocPNy6CBhU5OGg1O:1HAEfQkekYyLvRmcPGgzcL2kx5U
                                                                                                                                                    MD5:0E60627ACFD18F44D4DF469D8DCE6D30
                                                                                                                                                    SHA1:2BFCB0C3CA6B50D69AD5745FA692BAF0708DB4B5
                                                                                                                                                    SHA-256:F94C6DDEDF067642A1AF18D629778EC65E02B6097A8532B7E794502747AEB008
                                                                                                                                                    SHA-512:6FF517EED4381A61075AC7C8E80C73FAFAE7C0583BA4FA7F4951DD7DBE183C253702DEE44B3276EFC566F295DAC1592271BE5E0AC0C7D2C9F6062054418C7C27
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "createnew": {.. "message": ".....".. },.. "explanationofflinedisabled": {.. "message": ".................. Google ................ Google .................".. },.. "explanationofflineenabled": {.. "message": ".........................".. },.. "extdesc": {.. "message": ".............................".. },.. "extname": {.. "message": "Google .....".. },.. "learnmore": {.. "message": "....".. },.. "popuphelptext": {.. "message": "................................".. }..}..
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):912
                                                                                                                                                    Entropy (8bit):4.65963951143349
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:YlMBKqLnI7EgBLWFQbTQIF+j4h3OadMJzLWnCieqgwLeOvKrCRPE:YlMBKqjI7EQOQb0Pj4heOWqeyaBrMPE
                                                                                                                                                    MD5:71F916A64F98B6D1B5D1F62D297FDEC1
                                                                                                                                                    SHA1:9386E8F723C3F42DA5B3F7E0B9970D2664EA0BAA
                                                                                                                                                    SHA-256:EC78DDD4CCF32B5D76EC701A20167C3FBD146D79A505E4FB0421FC1E5CF4AA63
                                                                                                                                                    SHA-512:30FA4E02120AF1BE6E7CC7DBB15FAE5D50825BD6B3CF28EF21D2F2E217B14AF5B76CFCC165685C3EDC1D09536BFCB10CA07E1E2CC0DA891CEC05E19394AD7144
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{"createnew":{"message":"DALA ENTSHA"},"explanationofflinedisabled":{"message":"Awuxhunyiwe ku-inthanethi. Ukuze usebenzise i-Google Amadokhumenti ngaphandle koxhumano lwe-inthanethi, iya kokuthi izilungiselelo ekhasini lasekhaya le-Google Amadokhumenti bese uvula ukuvumelanisa okungaxhunyiwe ku-inthanethi ngesikhathi esilandelayo lapho uxhunywe ku-inthanethi."},"explanationofflineenabled":{"message":"Awuxhunyiwe ku-inthanethi, kodwa usangakwazi ukuhlela amafayela atholakalayo noma udale amasha."},"extdesc":{"message":"Hlela, dala, futhi ubuke amadokhumenti akho, amaspredishithi, namaphrezentheshini \u2014 konke ngaphandle kokufinyelela kwe-inthanethi."},"extname":{"message":"I-Google Amadokhumenti engaxhumekile ku-intanethi"},"learnmore":{"message":"Funda kabanzi"},"popuphelptext":{"message":"Bhala, hlela, futhi hlanganyela noma yikuphi lapho okhona, unalo noma ungenalo uxhumano lwe-inthanethi."}}.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):11280
                                                                                                                                                    Entropy (8bit):5.757003753691263
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:RBG1G1UPkUj/86Op//Ier/2nsNLJtwg+K8HNnswuHEIIMuuqd7CKqvlcp7xpHsUy:m8IEI4u8R039y
                                                                                                                                                    MD5:8F99E1EF2AFC5F73D9391C248A0390AA
                                                                                                                                                    SHA1:DD15DCD68FFB7CBA69C6BBA010DF57A75390C64C
                                                                                                                                                    SHA-256:D57215628AF1ECD1ECD8F83DA69245161E4E0A2CE24846B2FFF6B35DA232709B
                                                                                                                                                    SHA-512:8F4AA8CE2EA90958BEC430CD46F1E76D8E7617C0735D8AB896F4DA1F84F3220920CCA6CA2DA2D7559355423EC115342183615F7E62E72EE6168A5930A078948B
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:[{"description":"treehash per file","signed_content":{"payload":"eyJjb250ZW50X2hhc2hlcyI6W3siYmxvY2tfc2l6ZSI6NDA5NiwiZGlnZXN0Ijoic2hhMjU2IiwiZmlsZXMiOlt7InBhdGgiOiIxMjgucG5nIiwicm9vdF9oYXNoIjoiZ2NWZy0xWWgySktRNVFtUmtjZGNmamU1dzVIc1JNN1ZCTmJyaHJ4eGZ5ZyJ9LHsicGF0aCI6Il9sb2NhbGVzL2FmL21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJxaElnV3hDSFVNLWZvSmVFWWFiWWlCNU9nTm9ncUViWUpOcEFhZG5KR0VjIn0seyJwYXRoIjoiX2xvY2FsZXMvYW0vbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IlpPQWJ3cEs2THFGcGxYYjh4RVUyY0VkU0R1aVY0cERNN2lEQ1RKTTIyTzgifSx7InBhdGgiOiJfbG9jYWxlcy9hci9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiUjJVaEZjdTVFcEJfUUZtU19QeGstWWRrSVZqd3l6WEoxdURVZEMyRE9BSSJ9LHsicGF0aCI6Il9sb2NhbGVzL2F6L21lc3NhZ2VzLmpzb24iLCJyb290X2hhc2giOiJZVVJ3Mmp4UU5Lem1TZkY0YS1xcTBzbFBSSFc4eUlXRGtMY2g4Ry0zdjJRIn0seyJwYXRoIjoiX2xvY2FsZXMvYmUvbWVzc2FnZXMuanNvbiIsInJvb3RfaGFzaCI6IjNmRm9XYUZmUHJNelRXSkJsMXlqbUlyRDZ2dzlsa1VxdzZTdjAyUk1oVkEifSx7InBhdGgiOiJfbG9jYWxlcy9iZy9tZXNzYWdlcy5qc29uIiwicm9vdF9oYXNoIjoiSXJ3M3RIem9xREx6bHdGa0hjTllOWFoyNmI0WWVwT2t4ZFN
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):854
                                                                                                                                                    Entropy (8bit):4.284628987131403
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:ont+QByTwnnGNcMbyWM+Q9TZldnnnGGxlF/S0WOtUL0M0r:vOrGe4dDCVGOjWJ0nr
                                                                                                                                                    MD5:4EC1DF2DA46182103D2FFC3B92D20CA5
                                                                                                                                                    SHA1:FB9D1BA3710CF31A87165317C6EDC110E98994CE
                                                                                                                                                    SHA-256:6C69CE0FE6FAB14F1990A320D704FEE362C175C00EB6C9224AA6F41108918CA6
                                                                                                                                                    SHA-512:939D81E6A82B10FF73A35C931052D8D53D42D915E526665079EEB4820DF4D70F1C6AEBAB70B59519A0014A48514833FEFD687D5A3ED1B06482223A168292105D
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{. "type": "object",. "properties": {. "allowedDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Allow users to enable Docs offline for the specified managed domains.",. "description": "Users on managed devices will be able to enable docs offline if they are part of the specified managed domains.". },. "autoEnabledDocsOfflineDomains": {. "type": "array",. "items": {. "type": "string". },. "title": "Auto enable Docs offline for the specified managed domains in certain eligible situations.",. "description": "Users on managed devices, in certain eligible situations, will be able to automatically access and edit recent files offline for the managed domains set in this property. They can still disable it from Drive settings.". }. }.}.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:JSON data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2525
                                                                                                                                                    Entropy (8bit):5.417833205646285
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:1HEZ4WPoolELb/KxktGw3VwELb/4iL2QDkUpvdz1xxy/Atj1h9yiVvQe:WdP5aLTKQGwlTLT4oRvvxs/APhgiVb
                                                                                                                                                    MD5:C1650B58FA1935045570AA3BF642D50D
                                                                                                                                                    SHA1:8ECD9726D379A2B638DC6E0F31B1438BF824D845
                                                                                                                                                    SHA-256:FEA4B4152B884F3BF1675991AED9449B29253D1323CAD1B5523E63BC4932D944
                                                                                                                                                    SHA-512:65217E0EB8613326228F6179333926A68D7DA08BE65C63BD84AEC0B8075194706029583E0B86331E7EEEC4B7167E5BC51BCA4A53CE624CB41CF000C647B74880
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:{.. "author": {.. "email": "docs-hosted-app-own@google.com".. },.. "background": {.. "service_worker": "service_worker_bin_prod.js".. },.. "content_capabilities": {.. "matches": [ "https://docs.google.com/*", "https://drive.google.com/*", "https://drive-autopush.corp.google.com/*", "https://drive-daily-0.corp.google.com/*", "https://drive-daily-1.corp.google.com/*", "https://drive-daily-2.corp.google.com/*", "https://drive-daily-3.corp.google.com/*", "https://drive-daily-4.corp.google.com/*", "https://drive-daily-5.corp.google.com/*", "https://drive-daily-6.corp.google.com/*", "https://drive-preprod.corp.google.com/*", "https://drive-staging.corp.google.com/*" ],.. "permissions": [ "clipboardRead", "clipboardWrite", "unlimitedStorage" ].. },.. "content_security_policy": {.. "extension_pages": "script-src 'self'; object-src 'self'".. },.. "default_locale": "en_US",.. "description": "__MSG_extDesc__",.. "externally_connectable": {.. "ma
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:HTML document, ASCII text
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):97
                                                                                                                                                    Entropy (8bit):4.862433271815736
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3:PouV7uJL5XL/oGLvLAAJR90bZNGXIL0Hac4NGb:hxuJL5XsOv0EmNV4HX4Qb
                                                                                                                                                    MD5:B747B5922A0BC74BBF0A9BC59DF7685F
                                                                                                                                                    SHA1:7BF124B0BE8EE2CFCD2506C1C6FFC74D1650108C
                                                                                                                                                    SHA-256:B9FA2D52A4FFABB438B56184131B893B04655B01F336066415D4FE839EFE64E7
                                                                                                                                                    SHA-512:7567761BE4054FCB31885E16D119CD4E419A423FFB83C3B3ED80BFBF64E78A73C2E97AAE4E24AB25486CD1E43877842DB0836DB58FBFBCEF495BC53F9B2A20EC
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:<!DOCTYPE html>.<html>.<body>. <script src="offscreendocument_main.js"></script>.</body>.</html>
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with very long lines (4882)
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):122162
                                                                                                                                                    Entropy (8bit):5.444710692772984
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:mKgC9lwS3skucsAHnA5Ayc/XzyEW8WW9Y1G6WIMctANlKIkk0ToyxecN9Bu1/9a:0UsMXz7b81tANlKr5oyPBuza
                                                                                                                                                    MD5:01984DBFE92DF14DBD118C381A3D48F4
                                                                                                                                                    SHA1:F85DB8A14D3F8A2F66AE153C56D37FAA68EFE8E3
                                                                                                                                                    SHA-256:3A78B6FBC16F9FB27CE3ED650ABC31174263D762B71C028CC5D8F5427CBAB082
                                                                                                                                                    SHA-512:91A575EC15BD3B37254623F5039B3F437A8EDED7761D1FADF8FD0D5B06247589AC055EEFD8F6627C5F6843663A90330E7603E00315D91D8D7B43F6C87D9D2888
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:'use strict';function aa(){return function(a){return a}}function k(){return function(){}}function n(a){return function(){return this[a]}}function ba(a){return function(){return a}}var q;function ca(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function fa(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var ha=fa(this);function r(a,b){if(b)a:{var c=ha;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new T
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with very long lines (337)
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):338
                                                                                                                                                    Entropy (8bit):4.678465166211649
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6:2LGX86tj66rU8j6D3bWq2un/XBtzHrH9Mnj63LK6ALY6WHXt3:2Q8KVqb2u/Rt3OnjNkdd
                                                                                                                                                    MD5:0396274AAF2EAE8917E5EB52CF69DFA4
                                                                                                                                                    SHA1:96F53CFB2D6980E12AACEDC6D91759E7F5CA1718
                                                                                                                                                    SHA-256:13E1562CD07FC06D692FDF1AA471E3CEAE3CF7C1E42C5345D430A947139A24D5
                                                                                                                                                    SHA-512:091212DD84FCE06E0D47C6E26E0959A660B36B53D7AADE1DAC5CA2795E44B4D81AB271213DAE68E70A04EE2BDE9BCE4A63587580EC06B3FBBB7A2576B62ABD16
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:(function(){window._docs_chrome_extension_exists=!0;window._docs_chrome_extension_features_version=2;window._docs_chrome_extension_permissions="alarms clipboardRead clipboardWrite storage unlimitedStorage offscreen".split(" ");window._docs_chrome_extension_manifest_version=3;window._docs_chrome_extension_version="1.89.1";}).call(this);.
                                                                                                                                                    Process:C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
                                                                                                                                                    File Type:ASCII text, with very long lines (4884)
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):130889
                                                                                                                                                    Entropy (8bit):5.42886594885059
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:6EO+9lhvoaEAoAf0OliS9XbrrJQiFZcBaw7ILYzEVKOAKa4q32O1I5Z+dOOXW+xi:DoE9Xb9ZevcKOAKaN2O1IwOOJxX9U
                                                                                                                                                    MD5:BC4DBD5B20B1FA15F1F1BC4A428343C9
                                                                                                                                                    SHA1:A1C471D6838B3B72AA75624326FC6F57CA533291
                                                                                                                                                    SHA-256:DFAD2626B0EAB3ED2F1DD73FE0AF014F60F29A91B50315995681CEAAEE5C9EA6
                                                                                                                                                    SHA-512:27CB7BD81ED257594E3C5717D9DC917F96E26E226EFB5995795BB742233991C1CB17D571B1CE4A59B482AF914A8E03DEA9CF2E50B96E4C759419AE1D4D85F60A
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:'use strict';function aa(){return function(a){return a}}function k(){return function(){}}function n(a){return function(){return this[a]}}function ba(a){return function(){return a}}var q;function ca(a){var b=0;return function(){return b<a.length?{done:!1,value:a[b++]}:{done:!0}}}var da=typeof Object.defineProperties=="function"?Object.defineProperty:function(a,b,c){if(a==Array.prototype||a==Object.prototype)return a;a[b]=c.value;return a};.function ea(a){a=["object"==typeof globalThis&&globalThis,a,"object"==typeof window&&window,"object"==typeof self&&self,"object"==typeof global&&global];for(var b=0;b<a.length;++b){var c=a[b];if(c&&c.Math==Math)return c}throw Error("Cannot find global object");}var fa=ea(this);function r(a,b){if(b)a:{var c=fa;a=a.split(".");for(var d=0;d<a.length-1;d++){var e=a[d];if(!(e in c))break a;c=c[e]}a=a[a.length-1];d=c[a];b=b(d);b!=d&&b!=null&&da(c,a,{configurable:!0,writable:!0,value:b})}}.r("Symbol",function(a){function b(f){if(this instanceof b)throw new T
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):5038592
                                                                                                                                                    Entropy (8bit):6.043058205786219
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:49152:vVkDvLSkqdbEsuV+ebMh8w+/H8pF/bmlEyGjWvcP1xQ+X7TqVAMPLfQyim8kznsY:2Ll+Mn0WHl9VA2ic/
                                                                                                                                                    MD5:11F7419009AF2874C4B0E4505D185D79
                                                                                                                                                    SHA1:451D8D0470CEDB268619BA1E7AE78ADAE0EBA692
                                                                                                                                                    SHA-256:AC24CCE72F82C3EBBE9E7E9B80004163B9EED54D30467ECE6157EE4061BEAC95
                                                                                                                                                    SHA-512:1EABBBFDF579A93BBB055B973AA3321FC8DC8DA1A36FDE2BA9A4D58E5751DC106A4A1BBC4AD1F425C082702D6FBB821AA1078BC5ADC6B2AD1B5CE12A68058805
                                                                                                                                                    Malicious:false
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......e.D!...!...!...(.V.C...5..."...5...&...5...)...!......5...:...5... ...5...R...5.:. ...5... ...Rich!...................PE..d...p............." .........D...............................................`M.....'.M...`A........................................@.H.L&....I......@K.H.....I..............@M.....`J:.p.......................(....%..............@.......$.H......................text...4B.......D.................. ..`.wpp_sf.....`.......H.............. ..`.rdata...L*......N*.................@..@.data...hD...PI......*I.............@....pdata........I......2I.............@..@.didat.......0K.......J.............@....rsrc...H....@K.......J.............@..@.reloc.......@M.. ....L.............@..B........................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:MS Windows icon resource - 1 icon, 33x33, 32 bits/pixel
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):4682
                                                                                                                                                    Entropy (8bit):4.001778892391777
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:BR4ggggggggggggggggggggggggggggggagggggggggggggggggggggggggggggG:BRNLmR1WSi6VM65xoDi
                                                                                                                                                    MD5:C8C63C416759C5275D5129724DCD7CE6
                                                                                                                                                    SHA1:08DCACD44213903046A6FD8CC9BCDB6C20E02E8B
                                                                                                                                                    SHA-256:354318226A7DAB3C659D4CFF9337719FCCB81872CD2F92EA5092035440F3BE59
                                                                                                                                                    SHA-512:27B9CFF3DA8D6B4B9DA20EF2BB1BF886FF0446A1323555CE6D65EA934A3ED1ABC59F82D596494D2734D7DCB508CE60AA7E41C91C04226838625433C3F0E1D396
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:......!!.... .4.......(...!...B..... .............................................................................................................................................................?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9......?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9......?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9......?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9......?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9......?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9..?9......?9..?9..?9..?9
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon Feb 24 17:24:31 2025, mtime=Thu Mar 13 15:38:00 2025, atime=Mon Feb 24 17:24:31 2025, length=1150744, window=hide
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):951
                                                                                                                                                    Entropy (8bit):4.946786844017151
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:8mT7144SnlSkCh9Y//6BpLe/IFV3lgZjAAHyR4aBMJKtzlyCJlyC3mV:8mjY3l0e+V3lgdAn41ozkCJkC3m
                                                                                                                                                    MD5:3042B3DF07190586052BD71676EB33CA
                                                                                                                                                    SHA1:9B4C3F3E6F2253EFBE67C9F8235DC6BEEFDADB70
                                                                                                                                                    SHA-256:8C54DE13163362AD362EF52658148B96DD4D7E427AB0CFFAEEE05BA3CDBCCE9E
                                                                                                                                                    SHA-512:A299DA0861348EB246117998AF9BB78B5C759E2C5EB1CF58DFC66C31DCA2DAC604FAEA445D2FC495473732D8E6CCE979844512284EC9B998FFE74CCFD43D3D58
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:L..................F.... ...N..X...y.{H6...N..X.............................:..DG..Yr?.D..U..k0.&...&.......y.Yd......?6....?.H6.......t...CFSF..1.....EW)B..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW)BmZ............................d...A.p.p.D.a.t.a...B.V.1.....mZ....Roaming.@......EW)BmZ.............................o..R.o.a.m.i.n.g.....V.1.....mZ....PDFizer.@......mZ..mZ............................m...P.D.F.i.z.e.r.....b.2.....XZ.. .PDFizer.exe.H......XZ..mZ......3#......................W.P.D.F.i.z.e.r...e.x.e.......b...............-.......a...........]..y.....C:\Users\user\AppData\Roaming\PDFizer\PDFizer.exe........\.....\.....\.....\.P.D.F.i.z.e.r.\.P.D.F.i.z.e.r...e.x.e.(.C.:.\.U.s.e.r.s.\.h.u.b.e.r.t.\.A.p.p.D.a.t.a.\.R.o.a.m.i.n.g.\.P.D.F.i.z.e.r.\.`.......X.......818225...........hT..CrF.f4... .h.S.Y....0...E...hT..CrF.f4... .h.S.Y....0...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9216
                                                                                                                                                    Entropy (8bit):4.632720755580814
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:JXsWDx/dBd5tYuMdeu6xKjPGIVj479fSyvtew7TMB08iTcC8KIkYp9ciVvTW:JXTt1BnyDdeWj3Vj4Bvt17YucC8JVva
                                                                                                                                                    MD5:3829A541B06CC0277F6C9E12B1338FF7
                                                                                                                                                    SHA1:7F89CC8E6CF0F880E0F1C820D9871A792771C738
                                                                                                                                                    SHA-256:54BBBCE10DA880D334678E00771B25D85393B6EF5AA6B6EE4186ED630C32A011
                                                                                                                                                    SHA-512:E15132C8DF78DD9B00A6CDC731AAA98D0FAA9B7BEB14AE304E1AB7E88B1385D3C69945BC3E0141D2A3FF7192EA9843A7B7F0BD7CA08C4FC9AD1D5114A64D17F2
                                                                                                                                                    Malicious:false
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...m[............" ..0.............Z:... ...@....... ....................................`..................................:..O....@..X....................`.......9............................................... ............... ..H............text...`.... ...................... ..`.rsrc...X....@......................@..@.reloc.......`......."..............@..B................<:......H.......P$...............................................................~....*.~....*.~....*.~....*.~....*.~....*.......*.~....*.~....*.......*.......%.(.....%.r...p.%.(.....%.r...p.%...(....*....0..-.................o.........r...p.....r+..p.....rC..p.....r[..p.....r...p.....r...p.....r...p(....%-.&r...p.......(.........r...p(....%-.&r...p.....r=..p(....%-.&rc..p.....r...p(....%-.&r...p.....r...p(....%-.&r...p.....r_..p(....%-.&ru..p.....r...p(....%-.&r...p.....~.........~.
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9216
                                                                                                                                                    Entropy (8bit):4.632720755580814
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:96:JXsWDx/dBd5tYuMdeu6xKjPGIVj479fSyvtew7TMB08iTcC8KIkYp9ciVvTW:JXTt1BnyDdeWj3Vj4Bvt17YucC8JVva
                                                                                                                                                    MD5:3829A541B06CC0277F6C9E12B1338FF7
                                                                                                                                                    SHA1:7F89CC8E6CF0F880E0F1C820D9871A792771C738
                                                                                                                                                    SHA-256:54BBBCE10DA880D334678E00771B25D85393B6EF5AA6B6EE4186ED630C32A011
                                                                                                                                                    SHA-512:E15132C8DF78DD9B00A6CDC731AAA98D0FAA9B7BEB14AE304E1AB7E88B1385D3C69945BC3E0141D2A3FF7192EA9843A7B7F0BD7CA08C4FC9AD1D5114A64D17F2
                                                                                                                                                    Malicious:false
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...m[............" ..0.............Z:... ...@....... ....................................`..................................:..O....@..X....................`.......9............................................... ............... ..H............text...`.... ...................... ..`.rsrc...X....@......................@..@.reloc.......`......."..............@..B................<:......H.......P$...............................................................~....*.~....*.~....*.~....*.~....*.~....*.......*.~....*.~....*.......*.......%.(.....%.r...p.%.(.....%.r...p.%...(....*....0..-.................o.........r...p.....r+..p.....rC..p.....r[..p.....r...p.....r...p.....r...p(....%-.&r...p.......(.........r...p(....%-.&r...p.....r=..p(....%-.&rc..p.....r...p(....%-.&r...p.....r...p(....%-.&r...p.....r_..p(....%-.&ru..p.....r...p(....%-.&r...p.....~.........~.
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1150744
                                                                                                                                                    Entropy (8bit):7.850751415843771
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24576:I/DsWdhvOuLEKtXTdENvJyYP/m9WIuEmr4EyaTznDoabn8Ss:I/VdhmuLE2TkgEXr4g0h
                                                                                                                                                    MD5:7267C5FFAE5D5595EE360CA9637A1B59
                                                                                                                                                    SHA1:803DB607659C172DDDAC9FBDA30EC8FB1FF30386
                                                                                                                                                    SHA-256:53EAB8DDD907CFB2C7042ADD86F372829E6D1A1235EB00FE95A8061E5B8FE21B
                                                                                                                                                    SHA-512:ADF5238D472A9930059BD3F6FBB26E6AD8D8EDA5CF123BF1594A66E62A924B521CCC5088588743370114D51DA49A0E6B2BBFB6F6DC7C3BA09FA70144D4D9E8E3
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 11%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....<4..........."...0..J...........h... ........@.. ..............................qg....`..................................g..O.......t............h...'...........g............................................... ............... ..H............text....H... ...J.................. ..`.rsrc...t............L..............@..@.reloc...............f..............@..B.................g......H...................q....................................................~....*.~....*.~....*.~....*.~....*.......*.~....*.......*.~....*.~....*.0......................(&...r...po'........(&...rC..po'..........((........ .%l......re..p..... ........r...p.....()........r...p(..........#((........*...0..Z........(*....s+...}.....s,...}....(-............o....&(y...&~.....~/...r...p.(0.....r...p.(....*:.{......o1...*....0..?.........(2...}.......}.......}.......}......|......(..
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1451
                                                                                                                                                    Entropy (8bit):5.091993295224499
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:JdErNlM2ZmaBQXghymmKnk3Jc3J4YH33JyME4OqsJ+J4YHKJyME4OOT:3ErNSlaC8ymmKnKS4YHJyMHLsJ+J4YHO
                                                                                                                                                    MD5:2196986DBC0835C8AED7B04BDC929DB4
                                                                                                                                                    SHA1:1BAD268B38A836F1813AA71423B5E9838394C298
                                                                                                                                                    SHA-256:9B86902EEEBA026408798C6E1B04711F5AA3499A69C1CA2B3D769B7A3555A28C
                                                                                                                                                    SHA-512:756662DEA9196930E42ED25C3EEAD5DDF727FD5790B89E7D307FA2C81867034F18902720BE4B379402A66AA6F247A6F7388C823AD483A7DFFBFC8B3D258DC2C4
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.8" />.. </startup>.. <appSettings>.. <add key="ConvertedDirectoryPath" value="Default" />.. <add key="lastConversionComplete" value="1" />.. <add key="lastToConvertFilePaths" value="" />.. <add key="lastConvertedFilePaths" value="" />.. <add key="jreDownloaded" value="0" />.. <add key="appVersion" value="1.0.0" /> 06b7236f -->.. .<add key="downloadJAR" value="" />.. <add key="downloadJRE" value="" />.. <add key="ClientSettingsProvider.ServiceUri" value="" />.. </appSettings>.. <system.web>.. <membership defaultProvider="ClientAuthenticationMembershipProvider">.. <providers>.. <add name="ClientAuthenticationMembershipProvider" type="System.Web.ClientServices.Providers.ClientFormsAuthenticationMembershipProvider, System.Web.Extensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 15:06:51 2020, Security: 0, Code page: 1252, Revision Number: {E208B6F4-6C16-4D61-B0F4-A4B9E318FAE8}, Number of Words: 8, Subject: PDFizer, Author: PDFizer, Name of Creating Application: PDFizer, Template: ;1033, Comments: This installer database contains the logic and data required to install PDFizer., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Mon Feb 24 18:24:35 2025, Number of Pages: 200
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3910656
                                                                                                                                                    Entropy (8bit):6.638123131828586
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:98304:oK3+XTQyj1s9wPoxe1Qw4QFgBOnn/8/Z:ov5SwQxeX/i
                                                                                                                                                    MD5:FCEC997931F7ED8AE4B114A72138A088
                                                                                                                                                    SHA1:665B232066CC8AB47E171098BA90867AD9422039
                                                                                                                                                    SHA-256:26F199D390CA7D8AFF6008CE490EAA357269DDDB624CF04690E8FB473BCFD42A
                                                                                                                                                    SHA-512:541EBCA6D58F7F5D0B204002468D960D8FDB425B36F993483CE6B896694C8526EDF05127AAE05CE64EDD5698660B506F5030502C6FDF2CC0F1B8A4E911AB9B64
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:......................>...................<...................................v.......p.......................................@...A...B...C...D...E...F...G...H...I...J...K...................................................................U...V...W...X...Y...Z...M...N...O...P...Q...R...S...T...U...V...j...........................................................................................................................................................................................................................R...............'...>........................................................................................... ...!..."...#...$...%...&...2...3...)...*...+...,...-......./...0...1.......4...5...6...<...7...8...9...:...;...?...=...F...J...@...A...B...C...D...E.......G...H...I...P...K...L...M...N...O.......Q...S.......T...U...V...W.......Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...........x...y...z...
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):571824
                                                                                                                                                    Entropy (8bit):6.488736556088798
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:CZ+jZpQfIwKnkdmZJUbi7I0QfxK+pdd+cOj6LbndDrUw2K1fQEKZm+jWodEEVJaP:CEtmrdcK1fQEKZm+jWodEEb
                                                                                                                                                    MD5:BF78C15068D6671693DFCDFA5770D705
                                                                                                                                                    SHA1:4418C03C3161706A4349DFE3F97278E7A5D8962A
                                                                                                                                                    SHA-256:A88B8C1C8F27BF90FE960E0E8BD56984AD48167071AF92D96EC1051F89F827FB
                                                                                                                                                    SHA-512:5B6B0AB4E82CC979EAA619D387C6995198FD19AA0C455BEF44BD37A765685575D57448B3B4ACCD70D3BD20A6CD408B1F518EDA0F6DAE5AA106F225BEE8291372
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.................$......:.............................O.........V.........Rich..........................PE..d...%.2..........." .....J...b......@5...............................................e....`A.........................................H..h...."..,...............,:.......'......8...p...p...........................0...@............`...............................text...<I.......J.................. ..`.rdata..R....`.......N..............@..@.data...`:...@.......*..............@....pdata..,:.......<...H..............@..@.rsrc...............................@..@.reloc..8...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):24440
                                                                                                                                                    Entropy (8bit):5.918207814659551
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:384:31vZL9tTSu0Y0nGWcg5gWBDKLHRN7y/hlIg:3pntTSu05nX/AG
                                                                                                                                                    MD5:3E567BD78BBFD8B8FEDF4AE2A6330C2A
                                                                                                                                                    SHA1:F33B8C5FD4A7E09844F2F8B29346F353BDD8725D
                                                                                                                                                    SHA-256:09DF8A8D74500A21A2A84DA237E6A1D2ACFB8239E9B0EAC150030B8E1F798984
                                                                                                                                                    SHA-512:E9002E61B113EC1D00601D6FE3B919A171D5EF2B52C8C8881C3C5E5531D95C425209FD36B3C686565588C2F6D6E04718A715715082C93F66069297C27EA0E756
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........D..y*.y*.y*.H.+.y*....y*.....y*...).y*.y+.y*...+.y*.../.y*...*.y*.....y*...(.y*.Rich.y*.................PE..d...|6$..........." .........&............................................................`A.........................................@..L...LA..x....p.......`.......<..x#...........4..p...........................`3..@............0..8............................text............................... ..`.rdata..B....0......................@..@.data........P......................@....pdata.......`.......2..............@..@.rsrc........p.......6..............@..@.reloc...............:..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):187304
                                                                                                                                                    Entropy (8bit):6.547654635879257
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:7p7IsDQtnEzmvmebbqU0KGGYU0ZnEsInNgo82lfRrU/9a7DvFfyMQyvq:7VrDAEGjbqUXJEnEuCA4jFf2yC
                                                                                                                                                    MD5:7FB55C5887227AC0EF3BF095D35260D7
                                                                                                                                                    SHA1:8FA8273EFBAB06508490AB4D10BE0645A5127E48
                                                                                                                                                    SHA-256:4D764131E6D865DBFEBD21EC74DE417D231AC16C01E15B4B318A9077A3BB5BCA
                                                                                                                                                    SHA-512:05874F0CBC663BA7ABA21387C059EE3EE809E8965B8ADAEB7D054F0CE3AA49A727B42C50F99A2EB66827CF8CD637633C56A5E7F19A759898FE51DA6A6F9CBC71
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........7..jd..jd..jd".ke..jd..d..jd..ne..jd..ie..jd..kd..jd..ke..jd..oe..jd..je..jd...d..jd..he..jdRich..jd........PE..d......k.........." ................................................................2.....`A........................................p....................................'...........]..p............................[..@...............P............................text...{........................... ..`.rdata..............................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):102704
                                                                                                                                                    Entropy (8bit):6.575917309180155
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:bS6NH9M7vShoxXqYGZLAy10i5XNS83NT/sM9MYDiRecbbVKKoBpiC0i:bFRmxXqX0yvX7mHYWRecbb8l9
                                                                                                                                                    MD5:A1EC4B345106421470D44A5BF9025C3C
                                                                                                                                                    SHA1:DA9FDBD68E1734C5E2AE915BEEC0513B98B8A567
                                                                                                                                                    SHA-256:579BE9FE4DFBE655970B9DDCA02F75F3682E517E9DD80AE90C26A6AE2FFF40CB
                                                                                                                                                    SHA-512:2C161758F80FBC0544F598FB9B1A8332F998722A69787BD274D57F2D7C03492B55A913A374C995102EF13F499B953169C8020C473DFFE1B7B2BE6C9AA2A0D652
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......(r%Ml.K.l.K.l.K....n.K.ek..g.K.l.J.@.K..bH.a.K..bO.|.K..bN.s.K..bK.m.K..b..m.K..bI.m.K.Richl.K.........................PE..d...".._.........." .........^............................................................`A.........................................1..4....9.......p.......P.......L..0E..........H...T...............................8............................................text............................... ..`.rdata...?.......@..................@..@.data...@....@.......4..............@....pdata.......P.......8..............@..@_RDATA.......`.......D..............@..@.rsrc........p.......F..............@..@.reloc...............J..............@..B................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):45360
                                                                                                                                                    Entropy (8bit):6.627382251558996
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:384:jiWe6RE3c6lqst5nZvS05fJjPXR51RWmbzw+XfeDky85xHrwB2BWrYKW8dHRN7WH:wt3csN7xPXdRdP/ve6HrEUeePzvbH/p
                                                                                                                                                    MD5:2D4A5E1E503A5BA3D3A1E3B49436B00E
                                                                                                                                                    SHA1:884E2185BCE2239AFDF2D651A47F45C00D01A6C4
                                                                                                                                                    SHA-256:01D686D5122102189C04244F7CE37D8AB86213AE27588E88073EBBE54BCF1452
                                                                                                                                                    SHA-512:25877DEDC89B89189D4026A8D6F8853CF9D86F1E6733C8BD6D1CCD88626B41005B08135E612B70043050D3A105185D8ED2A9BF89D8C2AD7133282C4C1CA5696C
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................].l...W................W.....W.....W.....W.....W.|...W.....Rich..........PE..d...&.._.........." .....:...4......pA....................................................`A.........................................k......,l..x....................l..0E......<...(b..T............................b..8............P..X............................text....9.......:.................. ..`.rdata..@!...P..."...>..............@..@.data... ............`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..<............j..............@..B................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Users\user\Desktop\PDFizer.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):2093043
                                                                                                                                                    Entropy (8bit):0.0
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3::
                                                                                                                                                    MD5:148EF4987679F06700719A9952278F17
                                                                                                                                                    SHA1:B9DB9CDBDDDA2F625A6FF099DF8F0BEC29CDFF71
                                                                                                                                                    SHA-256:D7C4C306D9661008B3C25081095636DD93972D1A648DFDBD5D98368F476A6785
                                                                                                                                                    SHA-512:74E112405F87851C3875F005192E9F3FDA5D21F031A4DA49335D98BC2291CF489B6FC511CFF09E33CD3E2A89795A513B859C7FECF9E66BBF8B16063CC0A08774
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1150744
                                                                                                                                                    Entropy (8bit):7.850751415843771
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24576:I/DsWdhvOuLEKtXTdENvJyYP/m9WIuEmr4EyaTznDoabn8Ss:I/VdhmuLE2TkgEXr4g0h
                                                                                                                                                    MD5:7267C5FFAE5D5595EE360CA9637A1B59
                                                                                                                                                    SHA1:803DB607659C172DDDAC9FBDA30EC8FB1FF30386
                                                                                                                                                    SHA-256:53EAB8DDD907CFB2C7042ADD86F372829E6D1A1235EB00FE95A8061E5B8FE21B
                                                                                                                                                    SHA-512:ADF5238D472A9930059BD3F6FBB26E6AD8D8EDA5CF123BF1594A66E62A924B521CCC5088588743370114D51DA49A0E6B2BBFB6F6DC7C3BA09FA70144D4D9E8E3
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 11%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....<4..........."...0..J...........h... ........@.. ..............................qg....`..................................g..O.......t............h...'...........g............................................... ............... ..H............text....H... ...J.................. ..`.rsrc...t............L..............@..@.reloc...............f..............@..B.................g......H...................q....................................................~....*.~....*.~....*.~....*.~....*.......*.~....*.......*.~....*.~....*.0......................(&...r...po'........(&...rC..po'..........((........ .%l......re..p..... ........r...p.....()........r...p(..........#((........*...0..Z........(*....s+...}.....s,...}....(-............o....&(y...&~.....~/...r...p.(0.....r...p.(....*:.{......o1...*....0..?.........(2...}.......}.......}.......}......|......(..
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1451
                                                                                                                                                    Entropy (8bit):5.091993295224499
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:JdErNlM2ZmaBQXghymmKnk3Jc3J4YH33JyME4OqsJ+J4YHKJyME4OOT:3ErNSlaC8ymmKnKS4YHJyMHLsJ+J4YHO
                                                                                                                                                    MD5:2196986DBC0835C8AED7B04BDC929DB4
                                                                                                                                                    SHA1:1BAD268B38A836F1813AA71423B5E9838394C298
                                                                                                                                                    SHA-256:9B86902EEEBA026408798C6E1B04711F5AA3499A69C1CA2B3D769B7A3555A28C
                                                                                                                                                    SHA-512:756662DEA9196930E42ED25C3EEAD5DDF727FD5790B89E7D307FA2C81867034F18902720BE4B379402A66AA6F247A6F7388C823AD483A7DFFBFC8B3D258DC2C4
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.8" />.. </startup>.. <appSettings>.. <add key="ConvertedDirectoryPath" value="Default" />.. <add key="lastConversionComplete" value="1" />.. <add key="lastToConvertFilePaths" value="" />.. <add key="lastConvertedFilePaths" value="" />.. <add key="jreDownloaded" value="0" />.. <add key="appVersion" value="1.0.0" /> 06b7236f -->.. .<add key="downloadJAR" value="" />.. <add key="downloadJRE" value="" />.. <add key="ClientSettingsProvider.ServiceUri" value="" />.. </appSettings>.. <system.web>.. <membership defaultProvider="ClientAuthenticationMembershipProvider">.. <providers>.. <add name="ClientAuthenticationMembershipProvider" type="System.Web.ClientServices.Providers.ClientFormsAuthenticationMembershipProvider, System.Web.Extensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35"
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):571824
                                                                                                                                                    Entropy (8bit):6.488736556088798
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:CZ+jZpQfIwKnkdmZJUbi7I0QfxK+pdd+cOj6LbndDrUw2K1fQEKZm+jWodEEVJaP:CEtmrdcK1fQEKZm+jWodEEb
                                                                                                                                                    MD5:BF78C15068D6671693DFCDFA5770D705
                                                                                                                                                    SHA1:4418C03C3161706A4349DFE3F97278E7A5D8962A
                                                                                                                                                    SHA-256:A88B8C1C8F27BF90FE960E0E8BD56984AD48167071AF92D96EC1051F89F827FB
                                                                                                                                                    SHA-512:5B6B0AB4E82CC979EAA619D387C6995198FD19AA0C455BEF44BD37A765685575D57448B3B4ACCD70D3BD20A6CD408B1F518EDA0F6DAE5AA106F225BEE8291372
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.................$......:.............................O.........V.........Rich..........................PE..d...%.2..........." .....J...b......@5...............................................e....`A.........................................H..h...."..,...............,:.......'......8...p...p...........................0...@............`...............................text...<I.......J.................. ..`.rdata..R....`.......N..............@..@.data...`:...@.......*..............@....pdata..,:.......<...H..............@..@.rsrc...............................@..@.reloc..8...........................@..B................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):24440
                                                                                                                                                    Entropy (8bit):5.918207814659551
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:384:31vZL9tTSu0Y0nGWcg5gWBDKLHRN7y/hlIg:3pntTSu05nX/AG
                                                                                                                                                    MD5:3E567BD78BBFD8B8FEDF4AE2A6330C2A
                                                                                                                                                    SHA1:F33B8C5FD4A7E09844F2F8B29346F353BDD8725D
                                                                                                                                                    SHA-256:09DF8A8D74500A21A2A84DA237E6A1D2ACFB8239E9B0EAC150030B8E1F798984
                                                                                                                                                    SHA-512:E9002E61B113EC1D00601D6FE3B919A171D5EF2B52C8C8881C3C5E5531D95C425209FD36B3C686565588C2F6D6E04718A715715082C93F66069297C27EA0E756
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........D..y*.y*.y*.H.+.y*....y*.....y*...).y*.y+.y*...+.y*.../.y*...*.y*.....y*...(.y*.Rich.y*.................PE..d...|6$..........." .........&............................................................`A.........................................@..L...LA..x....p.......`.......<..x#...........4..p...........................`3..@............0..8............................text............................... ..`.rdata..B....0......................@..@.data........P......................@....pdata.......`.......2..............@..@.rsrc........p.......6..............@..@.reloc...............:..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):187304
                                                                                                                                                    Entropy (8bit):6.547654635879257
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:7p7IsDQtnEzmvmebbqU0KGGYU0ZnEsInNgo82lfRrU/9a7DvFfyMQyvq:7VrDAEGjbqUXJEnEuCA4jFf2yC
                                                                                                                                                    MD5:7FB55C5887227AC0EF3BF095D35260D7
                                                                                                                                                    SHA1:8FA8273EFBAB06508490AB4D10BE0645A5127E48
                                                                                                                                                    SHA-256:4D764131E6D865DBFEBD21EC74DE417D231AC16C01E15B4B318A9077A3BB5BCA
                                                                                                                                                    SHA-512:05874F0CBC663BA7ABA21387C059EE3EE809E8965B8ADAEB7D054F0CE3AA49A727B42C50F99A2EB66827CF8CD637633C56A5E7F19A759898FE51DA6A6F9CBC71
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........7..jd..jd..jd".ke..jd..d..jd..ne..jd..ie..jd..kd..jd..ke..jd..oe..jd..je..jd...d..jd..he..jdRich..jd........PE..d......k.........." ................................................................2.....`A........................................p....................................'...........]..p............................[..@...............P............................text...{........................... ..`.rdata..............................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):102704
                                                                                                                                                    Entropy (8bit):6.575917309180155
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:bS6NH9M7vShoxXqYGZLAy10i5XNS83NT/sM9MYDiRecbbVKKoBpiC0i:bFRmxXqX0yvX7mHYWRecbb8l9
                                                                                                                                                    MD5:A1EC4B345106421470D44A5BF9025C3C
                                                                                                                                                    SHA1:DA9FDBD68E1734C5E2AE915BEEC0513B98B8A567
                                                                                                                                                    SHA-256:579BE9FE4DFBE655970B9DDCA02F75F3682E517E9DD80AE90C26A6AE2FFF40CB
                                                                                                                                                    SHA-512:2C161758F80FBC0544F598FB9B1A8332F998722A69787BD274D57F2D7C03492B55A913A374C995102EF13F499B953169C8020C473DFFE1B7B2BE6C9AA2A0D652
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......(r%Ml.K.l.K.l.K....n.K.ek..g.K.l.J.@.K..bH.a.K..bO.|.K..bN.s.K..bK.m.K..b..m.K..bI.m.K.Richl.K.........................PE..d...".._.........." .........^............................................................`A.........................................1..4....9.......p.......P.......L..0E..........H...T...............................8............................................text............................... ..`.rdata...?.......@..................@..@.data...@....@.......4..............@....pdata.......P.......8..............@..@_RDATA.......`.......D..............@..@.rsrc........p.......F..............@..@.reloc...............J..............@..B................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):45360
                                                                                                                                                    Entropy (8bit):6.627382251558996
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:384:jiWe6RE3c6lqst5nZvS05fJjPXR51RWmbzw+XfeDky85xHrwB2BWrYKW8dHRN7WH:wt3csN7xPXdRdP/ve6HrEUeePzvbH/p
                                                                                                                                                    MD5:2D4A5E1E503A5BA3D3A1E3B49436B00E
                                                                                                                                                    SHA1:884E2185BCE2239AFDF2D651A47F45C00D01A6C4
                                                                                                                                                    SHA-256:01D686D5122102189C04244F7CE37D8AB86213AE27588E88073EBBE54BCF1452
                                                                                                                                                    SHA-512:25877DEDC89B89189D4026A8D6F8853CF9D86F1E6733C8BD6D1CCD88626B41005B08135E612B70043050D3A105185D8ED2A9BF89D8C2AD7133282C4C1CA5696C
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................].l...W................W.....W.....W.....W.....W.|...W.....Rich..........PE..d...&.._.........." .....:...4......pA....................................................`A.........................................k......,l..x....................l..0E......<...(b..T............................b..8............P..X............................text....9.......:.................. ..`.rdata..@!...P..."...>..............@..@.data... ............`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..<............j..............@..B................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon Feb 24 17:24:31 2025, mtime=Thu Mar 13 15:38:00 2025, atime=Mon Feb 24 17:24:31 2025, length=1150744, window=hide
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):965
                                                                                                                                                    Entropy (8bit):4.9374959192436245
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:8mT0L144SnlSkCh9Y//6BpLe/Is17V3lgZjAAHSMJCaBMJKtzlyCJlyC3mV:8mYY3l0e/VV3lgdAks1ozkCJkC3m
                                                                                                                                                    MD5:456CE1C8369FE8D26121ECC4BC7A3DDC
                                                                                                                                                    SHA1:EF2793E84CC5FA617466A2B9CCEA62C35FA67C78
                                                                                                                                                    SHA-256:DCADD57809B12F432CA98CE52EADCF70FB6DAD3F5A9E0D46C7772A288EDE06F2
                                                                                                                                                    SHA-512:5151CF17657DE4C402C4246716DECC7D13628D578288EA73BCFB97769520E6634470006819B1BB09BD3CF28DB7AE74AD980EA508CC1F5A1E5CC905C5B4ED13C5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:L..................F.... ...N..X......H6...N..X.............................:..DG..Yr?.D..U..k0.&...&.......y.Yd......?6....?.H6.......t...CFSF..1.....EW)B..AppData...t.Y^...H.g.3..(.....gVA.G..k...@......EW)BmZ............................d...A.p.p.D.a.t.a...B.V.1.....mZ....Roaming.@......EW)BmZ.............................o..R.o.a.m.i.n.g.....V.1.....mZ....PDFizer.@......mZ..mZ................................P.D.F.i.z.e.r.....b.2.....XZ.. .PDFizer.exe.H......XZ..mZ......3#......................W.P.D.F.i.z.e.r...e.x.e.......b...............-.......a...........]..y.....C:\Users\user\AppData\Roaming\PDFizer\PDFizer.exe..&.....\.A.p.p.D.a.t.a.\.R.o.a.m.i.n.g.\.P.D.F.i.z.e.r.\.P.D.F.i.z.e.r...e.x.e.(.C.:.\.U.s.e.r.s.\.h.u.b.e.r.t.\.A.p.p.D.a.t.a.\.R.o.a.m.i.n.g.\.P.D.F.i.z.e.r.\.`.......X.......818225...........hT..CrF.f4... .h.S.Y....0...E...hT..CrF.f4... .h.S.Y....0...E..E.......9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 15:06:51 2020, Security: 0, Code page: 1252, Revision Number: {E208B6F4-6C16-4D61-B0F4-A4B9E318FAE8}, Number of Words: 8, Subject: PDFizer, Author: PDFizer, Name of Creating Application: PDFizer, Template: ;1033, Comments: This installer database contains the logic and data required to install PDFizer., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Mon Feb 24 18:24:35 2025, Number of Pages: 200
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3910656
                                                                                                                                                    Entropy (8bit):6.638123131828586
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:98304:oK3+XTQyj1s9wPoxe1Qw4QFgBOnn/8/Z:ov5SwQxeX/i
                                                                                                                                                    MD5:FCEC997931F7ED8AE4B114A72138A088
                                                                                                                                                    SHA1:665B232066CC8AB47E171098BA90867AD9422039
                                                                                                                                                    SHA-256:26F199D390CA7D8AFF6008CE490EAA357269DDDB624CF04690E8FB473BCFD42A
                                                                                                                                                    SHA-512:541EBCA6D58F7F5D0B204002468D960D8FDB425B36F993483CE6B896694C8526EDF05127AAE05CE64EDD5698660B506F5030502C6FDF2CC0F1B8A4E911AB9B64
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:......................>...................<...................................v.......p.......................................@...A...B...C...D...E...F...G...H...I...J...K...................................................................U...V...W...X...Y...Z...M...N...O...P...Q...R...S...T...U...V...j...........................................................................................................................................................................................................................R...............'...>........................................................................................... ...!..."...#...$...%...&...2...3...)...*...+...,...-......./...0...1.......4...5...6...<...7...8...9...:...;...?...=...F...J...@...A...B...C...D...E.......G...H...I...P...K...L...M...N...O.......Q...S.......T...U...V...W.......Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...........x...y...z...
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 15:06:51 2020, Security: 0, Code page: 1252, Revision Number: {E208B6F4-6C16-4D61-B0F4-A4B9E318FAE8}, Number of Words: 8, Subject: PDFizer, Author: PDFizer, Name of Creating Application: PDFizer, Template: ;1033, Comments: This installer database contains the logic and data required to install PDFizer., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Mon Feb 24 18:24:35 2025, Number of Pages: 200
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):3910656
                                                                                                                                                    Entropy (8bit):6.638123131828586
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:98304:oK3+XTQyj1s9wPoxe1Qw4QFgBOnn/8/Z:ov5SwQxeX/i
                                                                                                                                                    MD5:FCEC997931F7ED8AE4B114A72138A088
                                                                                                                                                    SHA1:665B232066CC8AB47E171098BA90867AD9422039
                                                                                                                                                    SHA-256:26F199D390CA7D8AFF6008CE490EAA357269DDDB624CF04690E8FB473BCFD42A
                                                                                                                                                    SHA-512:541EBCA6D58F7F5D0B204002468D960D8FDB425B36F993483CE6B896694C8526EDF05127AAE05CE64EDD5698660B506F5030502C6FDF2CC0F1B8A4E911AB9B64
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:......................>...................<...................................v.......p.......................................@...A...B...C...D...E...F...G...H...I...J...K...................................................................U...V...W...X...Y...Z...M...N...O...P...Q...R...S...T...U...V...j...........................................................................................................................................................................................................................R...............'...>........................................................................................... ...!..."...#...$...%...&...2...3...)...*...+...,...-......./...0...1.......4...5...6...<...7...8...9...:...;...?...=...F...J...@...A...B...C...D...E.......G...H...I...P...K...L...M...N...O.......Q...S.......T...U...V...W.......Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...........x...y...z...
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):427642
                                                                                                                                                    Entropy (8bit):7.101182335359889
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:1qEahS/QQqdwKHvieehP7LoraiElXrF59XWQh:jQXdjPixP7krdQh
                                                                                                                                                    MD5:965A559B59B7BECDBCD4A3C5F773CAA0
                                                                                                                                                    SHA1:96048EE7A0EF7A56C8A2BA7995848D354B5EC65C
                                                                                                                                                    SHA-256:96966285BACEA14B52BBDDFA8AA063BA0F065588F6A819F9A9652366E74B39E3
                                                                                                                                                    SHA-512:5DD7669ED078FABC78246465B966DE9796DA9C531B55CE5D9225549B889F4DE220A2FB8CB03B120E77D8BDE2981EA6738B9782AD2D017A2D8529A9839FDD5470
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........y.?...l...l...l.`.m...l.`.m>..l...m...l...m...l...m...l.`.m...l.`.m...l...l...l...m...l...m...l..{l...l...l...l...m...lRich...l........................PE..L....a.g...........!...).............V.......................................P............@A........................ ....*........... .......................0.........T...............................@............................................text.............................. ..`.rdata..t_.......`..................@..@.data...$...........................@....rsrc........ ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):753984
                                                                                                                                                    Entropy (8bit):6.461872633696775
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:sXWV44ngBNmhAzLUhfVdrjpuG1PE0I7+avw4UbY6t5rXf63Rfklet:KWV4zHzLUdVB1n1PE0Yw4Ubz5rXf63hL
                                                                                                                                                    MD5:8DD026145833182777A182A646DF81F3
                                                                                                                                                    SHA1:4F5CB840193EEA97DF088C83A794FB6E8F67AB07
                                                                                                                                                    SHA-256:3071AF6BE43A2611DB45205F0D3F1F25ABA05ACF5F70992FCE2FFFD63EE9C85D
                                                                                                                                                    SHA-512:F6C860BF563A24C046A7D76A6BC1E2F6BBFC80A87AC4513DE331049F35198DCBBDBB5BE7F5D49100E1D1C8AB680ECF3EAAA4FDB8F744C9FD5479A1BA64079391
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......':r.c[.Tc[.Tc[.T.).Un[.T.).U.[.T.%.Ur[.T.%.U{[.T.).Uz[.T.%.U=[.T.).Ub[.T.).Ut[.Tc[.T.Z.Tz$.U([.Tz$.Ub[.Tz$.Tb[.Tc[.Tb[.Tz$.Ub[.TRichc[.T................PE..L....=.d.........."!...$.>..........+........P............................................@.........................`..................h............D..@=.......r.....p............................e..@............P..........@....................text....=.......>.................. ..`.rdata...q...P...r...B..............@..@.data...H(..........................@....rsrc...h...........................@..@.reloc...r.......t..................@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):602432
                                                                                                                                                    Entropy (8bit):6.469389454249605
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:6144:QaFYTdIO9QmvIeVKVhaxkSBULBA4tKSM3BZC4o4AOl+mN9ysU5pvs8g73E:pYL9HXVW0xOA+KlZC4vc55s8g73E
                                                                                                                                                    MD5:B7A6A99CBE6E762C0A61A8621AD41706
                                                                                                                                                    SHA1:92F45DD3ED3AAEAAC8B488A84E160292FF86281E
                                                                                                                                                    SHA-256:39FD8D36F8E5D915AD571EA429DB3C3DE6E9C160DBEA7C3E137C9BA4B7FD301D
                                                                                                                                                    SHA-512:A17E4512D906599B7F004EBB2F19EE2566EE93C2C18114AC05B0A0115A8C481592788F6B97DA008795D5C31FB8D819AC82A5097B1792248319139C3FACE45642
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............u..u..u.n.v..u.n.p...u...q..u...v..u...p...u.n.q..u.n.s..u.n.t..u..t...u.|...u.u..u....u.....u.w..u.Rich..u.........................PE..L....=.d.........."!...$.>...........Y.......P...............................0.......4....@.........................`X..d....a..,.......................@=.......h.....p...................@...........@............P..h............................text....=.......>.................. ..`.rdata...,...P.......B..............@..@.data...8%...........p..............@....rsrc...............................@..@.reloc...h.......j..................@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:data
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):1303481
                                                                                                                                                    Entropy (8bit):6.602139067569385
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24576:/XiY94rNLiyE42Wy1Qw8YQTkU5q+M+bCiY94rNLiyE42Wy1Qw8YQTkU5q+M+b4:/j94xxEN1QwDQT15q+M+bA94xxEN1QwZ
                                                                                                                                                    MD5:7021D93EECB188172EDD038AC24F88C6
                                                                                                                                                    SHA1:3054226F12FDAA8854CBF7A796872853AF7C1BB0
                                                                                                                                                    SHA-256:761F217CFE1F923EE6167480B4A01F7E8D922973C1EDC66E821685E149A707BC
                                                                                                                                                    SHA-512:1DFA4AA1E41BE751374EFB821D54950008B0F0BF1726DC4732B65C688782F22B265F27051AF7E28F9EC8F882D0C95CFE32EF1BEAAD7E2E9BE26F34ADE024354C
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:...@IXOS.@.....@.dmZ.@.....@.....@.....@.....@.....@......&.{70C01104-9C1A-4CA5-9EEA-03CFFCB21B6A}..PDFizer..PDFizer_no_update.msi.@.....@.....@.....@......app.exe..&.{E208B6F4-6C16-4D61-B0F4-A4B9E318FAE8}.....@.....@.....@.....@.......@.....@.....@.......@......PDFizer......Rollback..Rolling back action:....RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@.....@.....@.]....&.{254C838C-98A9-4C30-994B-35D38E8B1550}(.C:\Users\user\AppData\Roaming\PDFizer\.@.......@.....@.....@......&.{8442C7F6-AA55-4A80-84DC-AAF0B98EE300}Q.21:\Software\Microsoft\Windows\CurrentVersion\Uninstall\PDFizer 1.0.0\DisplayName.@.......@.....@.....@......&.{C65B17F1-F062-400A-A474-DA5AA80A822D}N.01:\Software\Microsoft\Windows\CurrentVersion\Uninstall\PDFizer 1.0.0\NoModify.@.......@.....@.....@......&.{1920ABFC-2501-4D4A-8B32-8A8E7F1998DC}4.C:\Users\user\AppData\Roaming\PDFizer\msvcp140.dll.@.......@.....@.....@......&.{14F78F97-EA3A-4
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):645952
                                                                                                                                                    Entropy (8bit):6.596494291240824
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:lb/iY94rNLit8tpySmt42WyXlQwDIA0iYkWTkU59s+M+bx5:ViY94rNLiyE42Wy1Qw8YQTkU5q+M+bD
                                                                                                                                                    MD5:CE54EDD73936BABC1063484DB5473E94
                                                                                                                                                    SHA1:39E37CCC28B7A56C51A91029B1207049F0D3CA81
                                                                                                                                                    SHA-256:16C72945A548B51F9CD4F1C9AC9E8C0209A1220DAFE0A5760944DB883B892313
                                                                                                                                                    SHA-512:4E1FC9057EDFE3126D0C095AFBFD31F909F1474CF5BC09834664872EE0A402BB0ECADF6F15046529C92B342EAF9081A7C605DF6E64D67C93CCDAE8BD2A88F1C0
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........3XA.].A.].A.]...^.L.]...X...]...Y.P.]...^.Y.]...X...].X.^.@.]...Y.V.]...\.X.].A.\.z.].X.T...].X.].@.].X..@.].A...@.].X._.@.].RichA.].................PE..L...b=.d.........."!...$.4..........I........P...............................0............@..........................3..D....5..........................@=.......W..0}..p....................}......p|..@............P..8............................text....3.......4.................. ..`.rdata.......P.......8..............@..@.data...`a...P......................@....rsrc................@..............@..@.reloc...W.......X...F..............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):645952
                                                                                                                                                    Entropy (8bit):6.596494291240824
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:lb/iY94rNLit8tpySmt42WyXlQwDIA0iYkWTkU59s+M+bx5:ViY94rNLiyE42Wy1Qw8YQTkU5q+M+bD
                                                                                                                                                    MD5:CE54EDD73936BABC1063484DB5473E94
                                                                                                                                                    SHA1:39E37CCC28B7A56C51A91029B1207049F0D3CA81
                                                                                                                                                    SHA-256:16C72945A548B51F9CD4F1C9AC9E8C0209A1220DAFE0A5760944DB883B892313
                                                                                                                                                    SHA-512:4E1FC9057EDFE3126D0C095AFBFD31F909F1474CF5BC09834664872EE0A402BB0ECADF6F15046529C92B342EAF9081A7C605DF6E64D67C93CCDAE8BD2A88F1C0
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........3XA.].A.].A.]...^.L.]...X...]...Y.P.]...^.Y.]...X...].X.^.@.]...Y.V.]...\.X.].A.\.z.].X.T...].X.].@.].X..@.].A...@.].X._.@.].RichA.].................PE..L...b=.d.........."!...$.4..........I........P...............................0............@..........................3..D....5..........................@=.......W..0}..p....................}......p|..@............P..8............................text....3.......4.................. ..`.rdata.......P.......8..............@..@.data...`a...P......................@....rsrc................@..............@..@.reloc...W.......X...F..............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):427642
                                                                                                                                                    Entropy (8bit):7.101182335359889
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:1qEahS/QQqdwKHvieehP7LoraiElXrF59XWQh:jQXdjPixP7krdQh
                                                                                                                                                    MD5:965A559B59B7BECDBCD4A3C5F773CAA0
                                                                                                                                                    SHA1:96048EE7A0EF7A56C8A2BA7995848D354B5EC65C
                                                                                                                                                    SHA-256:96966285BACEA14B52BBDDFA8AA063BA0F065588F6A819F9A9652366E74B39E3
                                                                                                                                                    SHA-512:5DD7669ED078FABC78246465B966DE9796DA9C531B55CE5D9225549B889F4DE220A2FB8CB03B120E77D8BDE2981EA6738B9782AD2D017A2D8529A9839FDD5470
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........y.?...l...l...l.`.m...l.`.m>..l...m...l...m...l...m...l.`.m...l.`.m...l...l...l...m...l...m...l..{l...l...l...l...m...lRich...l........................PE..L....a.g...........!...).............V.......................................P............@A........................ ....*........... .......................0.........T...............................@............................................text.............................. ..`.rdata..t_.......`..................@..@.data...$...........................@....rsrc........ ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
                                                                                                                                                    Category:modified
                                                                                                                                                    Size (bytes):427642
                                                                                                                                                    Entropy (8bit):7.101182335359889
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12288:1qEahS/QQqdwKHvieehP7LoraiElXrF59XWQh:jQXdjPixP7krdQh
                                                                                                                                                    MD5:965A559B59B7BECDBCD4A3C5F773CAA0
                                                                                                                                                    SHA1:96048EE7A0EF7A56C8A2BA7995848D354B5EC65C
                                                                                                                                                    SHA-256:96966285BACEA14B52BBDDFA8AA063BA0F065588F6A819F9A9652366E74B39E3
                                                                                                                                                    SHA-512:5DD7669ED078FABC78246465B966DE9796DA9C531B55CE5D9225549B889F4DE220A2FB8CB03B120E77D8BDE2981EA6738B9782AD2D017A2D8529A9839FDD5470
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........y.?...l...l...l.`.m...l.`.m>..l...m...l...m...l...m...l.`.m...l.`.m...l...l...l...m...l...m...l..{l...l...l...l...m...lRich...l........................PE..L....a.g...........!...).............V.......................................P............@A........................ ....*........... .......................0.........T...............................@............................................text.............................. ..`.rdata..t_.......`..................@..@.data...$...........................@....rsrc........ ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):959
                                                                                                                                                    Entropy (8bit):4.847324835573595
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:TMHd413VymhsSRyxrybPYp0IRRXhqR+iLqY8GRKJiSMkgOsa6YEvTDHdtz2dLRRb:2dZmhscPY6IyLnKJbs0EvTjH6j5nrt
                                                                                                                                                    MD5:EE9A8381338B060D86C58E2415F481F3
                                                                                                                                                    SHA1:200F3ED7C773F50C80644F3976E09E876F45993F
                                                                                                                                                    SHA-256:7E1096D6F39EBE04D6E38BC714983AF05ED92CC2BB4D3365ED4C85E733CB145C
                                                                                                                                                    SHA-512:26B9108B9522574E08560BC45A6470F85CA149317BD763F3A357040E0F0E743FD7BFC05E0CE2D9FB52BF89E22C61D221DDF8A7163F5143848717CA3D56847EF1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <startup useLegacyV2RuntimeActivationPolicy="true">.. .. Use supportedRuntime tags to explicitly specify the version(s) of the .NET Framework runtime that.. the custom action should run on. If no versions are specified, the chosen version of the runtime.. will be the "best" match to what WixToolset.Dtf.CustomAction.dll was built against..... WARNING: leaving the version unspecified is dangerous as it introduces a risk of compatibility.. problems with future versions of the .NET Framework runtime. It is highly recommended that you specify.. only the version(s) of the .NET Framework runtime that you have tested against..... For more information https://learn.microsoft.com/en-us/dotnet/framework/configure-apps/file-schema/startup/startup-element.. -->.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.7.2" />.. </startup>..</configuration>..
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):332800
                                                                                                                                                    Entropy (8bit):6.0966953677547275
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:QJA5RylsHmDFin8nhWvGzOJ1mYAFeYXxCJIrkp9TD6qaXn69aKCax8weCycJ5Dfa:ZHmDxnhWvGSJYRFeYXEee9TWqa369An
                                                                                                                                                    MD5:0616EA42B68A8F5F2F01BCD985BDCBC7
                                                                                                                                                    SHA1:88D6AAE1F17B00F4391E0E7B17E98C494BE73BA1
                                                                                                                                                    SHA-256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A
                                                                                                                                                    SHA-512:CE4657908615C4837084C75D806C083B8F7E63965A2E7866B8C96DE7C0278A0857235B74CD9443769968165DB250EBA042A5B05927FEBFF5BB70BEBB7DCBD814
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ..............................o.....`.................................2)..O....@.......................`......,(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................f)......H.......<...0U..........l...@....'........................................{....*..{....*V.(......}......}....*...0..A........u2.......4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. ..<. )UU.Z(.....{....o....X )UU.Z(.....{....o....X*...0..b........r...p......%..{.......%q5....5...-.&.+...5...o.....%..{.......%q6....6...-.&.+...6...o.....(....*..{....*..{....*..{....*r.(......}......}......}....*..0..Y........u7.......L.,G(.....{.....{....o....,/(.....{.....{....o....
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9728
                                                                                                                                                    Entropy (8bit):4.5545266828490805
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:OiWWNv/jzSENtqcadVl8PandjJUf7ZJSqSi/ufXg1v5rxX0XWr:11Nvb5adVl8P2djJMZJSGu/a5rxX0XWr
                                                                                                                                                    MD5:C9B4EAED07EF72E5ED0F9ECB3E9FFB66
                                                                                                                                                    SHA1:154BF2E5EEC4C08E8954B229439E03A1FB5CD0E8
                                                                                                                                                    SHA-256:B2996E6B102FE829B5683936DD7197F26F375EA16499CC4E6AF88E78538B9FF1
                                                                                                                                                    SHA-512:0482B7328C0C5E82E82ABA033BA6DD5F1800BA0FCEF1522A4CEDF3C212156796738C8C4AB580375B77D90C7CEBC4723D35518F990B836AA64F5CE173D1195FE5
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....>2f...........!.................9... ...@....... ...................................@..................................9..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`.......$..............@..B.................9......H........4............... ......P ......................................A~h....r}.......x...._...^xi(e|..A.+{0.38S'3..X..cw.gd..j=<.)Q~>yP0..7r.0.%A(..g..].& .a..@..=.....e.....U.O2.h.}.<..B.`................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....G.......PADPADP..7...7....\.....`.Q......!...........:oH..S....c...........L.}..>.. 2...3...5......:...
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):14336
                                                                                                                                                    Entropy (8bit):5.257505758329955
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:Uzt2G73y2jDpCRbzwpOMzGlU7+LghfoFMfBzyj9LmqDFzTufIe9rDE/Y:UZDi2jDp0wpfGmEghfcwCmEFReRUY
                                                                                                                                                    MD5:4D4A5C35CFEC5F348096F4BF3D897C18
                                                                                                                                                    SHA1:68D502D42EA4455F931C2F90869E4D592AF1BD88
                                                                                                                                                    SHA-256:51EBB6EFBC0D2CCDBFECB01BCF08103D62D1DC998CD613903362A284714E8E7E
                                                                                                                                                    SHA-512:A5F8936A55971E3BA60903FA3C7BE487967606502A61FF18F1153BC333838A63B5115AD5140AC56EC7E85470824E599F9192AA8F37F457C3AFCEA08D1B166EDF
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....xx..........." ..0..0...........O... ...`....... ....................................`..................................O..O....`...............................O............................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............6..............@..B.................O......H........*...$..........................................................2.r...p(....*r..r...po....r-..p(....(....*. .'..(......r...po....rM..p.r_..po....(....(....*...r...po....r...p.r_..po....(....(....*...r...po....r...p.r_..po....(....(....*2.r...p(....*2.r...p(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...po....r#..p(....(....*r..r...po....rM..p(....(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):198416
                                                                                                                                                    Entropy (8bit):6.572189329266532
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:8Of7tVL+l4lj19l4uDHYHj69UgoTqdda7CnfKlRUjW01KytaljYqCDPC:8gQQx54Hj6jomdrzalMqb
                                                                                                                                                    MD5:EF8D5785AC8669F5FD54E22F52770E6B
                                                                                                                                                    SHA1:4C94AE7EF233BE33A56C0A5D9B8E2211D5D5792C
                                                                                                                                                    SHA-256:A614884EA627DA1925131EBF41E8AE202CAEAC0FE543B86384F5EB2BFAF1AA75
                                                                                                                                                    SHA-512:AB3B140BD6531F22E994606820E6511442C23D9015B1E1A38AAED43AA42BA29A996511151D0B3A383C05C2B11F670E52CDD7F507AD1A1AD8CEBEA57FB22ADE5A
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Z............." ..0.............:.... ........... .......................@......".....@.....................................O......................../... ......d...p............................................ ............... ..H............text...@.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H...........@H...............z...........................................(;....-.r...ps<...z..s=...}....*..(;....-.r...ps<...z..(....}....*2.{....o>...*..*...2...{....o>.../..{.....o?...*r...ps@...z..0..[........(A...,.r3..ps<...z.{....oB....+..oC.....o.....(D...,......o....-....,..o.....r3..ps@...z.*.........%D.......sE...z.sE...z:..(..........*6..o....(....*..0..F........(A...,.r3..ps<...z..+..{.....o?...o.....(D...,..*......{....o>...2..*r.-.rI..ps<...z.{......oF...*.sE..
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):959
                                                                                                                                                    Entropy (8bit):4.847324835573595
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:TMHd413VymhsSRyxrybPYp0IRRXhqR+iLqY8GRKJiSMkgOsa6YEvTDHdtz2dLRRb:2dZmhscPY6IyLnKJbs0EvTjH6j5nrt
                                                                                                                                                    MD5:EE9A8381338B060D86C58E2415F481F3
                                                                                                                                                    SHA1:200F3ED7C773F50C80644F3976E09E876F45993F
                                                                                                                                                    SHA-256:7E1096D6F39EBE04D6E38BC714983AF05ED92CC2BB4D3365ED4C85E733CB145C
                                                                                                                                                    SHA-512:26B9108B9522574E08560BC45A6470F85CA149317BD763F3A357040E0F0E743FD7BFC05E0CE2D9FB52BF89E22C61D221DDF8A7163F5143848717CA3D56847EF1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <startup useLegacyV2RuntimeActivationPolicy="true">.. .. Use supportedRuntime tags to explicitly specify the version(s) of the .NET Framework runtime that.. the custom action should run on. If no versions are specified, the chosen version of the runtime.. will be the "best" match to what WixToolset.Dtf.CustomAction.dll was built against..... WARNING: leaving the version unspecified is dangerous as it introduces a risk of compatibility.. problems with future versions of the .NET Framework runtime. It is highly recommended that you specify.. only the version(s) of the .NET Framework runtime that you have tested against..... For more information https://learn.microsoft.com/en-us/dotnet/framework/configure-apps/file-schema/startup/startup-element.. -->.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.7.2" />.. </startup>..</configuration>..
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):332800
                                                                                                                                                    Entropy (8bit):6.0966953677547275
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:QJA5RylsHmDFin8nhWvGzOJ1mYAFeYXxCJIrkp9TD6qaXn69aKCax8weCycJ5Dfa:ZHmDxnhWvGSJYRFeYXEee9TWqa369An
                                                                                                                                                    MD5:0616EA42B68A8F5F2F01BCD985BDCBC7
                                                                                                                                                    SHA1:88D6AAE1F17B00F4391E0E7B17E98C494BE73BA1
                                                                                                                                                    SHA-256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A
                                                                                                                                                    SHA-512:CE4657908615C4837084C75D806C083B8F7E63965A2E7866B8C96DE7C0278A0857235B74CD9443769968165DB250EBA042A5B05927FEBFF5BB70BEBB7DCBD814
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ..............................o.....`.................................2)..O....@.......................`......,(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................f)......H.......<...0U..........l...@....'........................................{....*..{....*V.(......}......}....*...0..A........u2.......4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. ..<. )UU.Z(.....{....o....X )UU.Z(.....{....o....X*...0..b........r...p......%..{.......%q5....5...-.&.+...5...o.....%..{.......%q6....6...-.&.+...6...o.....(....*..{....*..{....*..{....*r.(......}......}......}....*..0..Y........u7.......L.,G(.....{.....{....o....,/(.....{.....{....o....
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9728
                                                                                                                                                    Entropy (8bit):4.5545266828490805
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:OiWWNv/jzSENtqcadVl8PandjJUf7ZJSqSi/ufXg1v5rxX0XWr:11Nvb5adVl8P2djJMZJSGu/a5rxX0XWr
                                                                                                                                                    MD5:C9B4EAED07EF72E5ED0F9ECB3E9FFB66
                                                                                                                                                    SHA1:154BF2E5EEC4C08E8954B229439E03A1FB5CD0E8
                                                                                                                                                    SHA-256:B2996E6B102FE829B5683936DD7197F26F375EA16499CC4E6AF88E78538B9FF1
                                                                                                                                                    SHA-512:0482B7328C0C5E82E82ABA033BA6DD5F1800BA0FCEF1522A4CEDF3C212156796738C8C4AB580375B77D90C7CEBC4723D35518F990B836AA64F5CE173D1195FE5
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....>2f...........!.................9... ...@....... ...................................@..................................9..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`.......$..............@..B.................9......H........4............... ......P ......................................A~h....r}.......x...._...^xi(e|..A.+{0.38S'3..X..cw.gd..j=<.)Q~>yP0..7r.0.%A(..g..].& .a..@..=.....e.....U.O2.h.}.<..B.`................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....G.......PADPADP..7...7....\.....`.Q......!...........:oH..S....c...........L.}..>.. 2...3...5......:...
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):14336
                                                                                                                                                    Entropy (8bit):5.257505758329955
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:Uzt2G73y2jDpCRbzwpOMzGlU7+LghfoFMfBzyj9LmqDFzTufIe9rDE/Y:UZDi2jDp0wpfGmEghfcwCmEFReRUY
                                                                                                                                                    MD5:4D4A5C35CFEC5F348096F4BF3D897C18
                                                                                                                                                    SHA1:68D502D42EA4455F931C2F90869E4D592AF1BD88
                                                                                                                                                    SHA-256:51EBB6EFBC0D2CCDBFECB01BCF08103D62D1DC998CD613903362A284714E8E7E
                                                                                                                                                    SHA-512:A5F8936A55971E3BA60903FA3C7BE487967606502A61FF18F1153BC333838A63B5115AD5140AC56EC7E85470824E599F9192AA8F37F457C3AFCEA08D1B166EDF
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....xx..........." ..0..0...........O... ...`....... ....................................`..................................O..O....`...............................O............................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............6..............@..B.................O......H........*...$..........................................................2.r...p(....*r..r...po....r-..p(....(....*. .'..(......r...po....rM..p.r_..po....(....(....*...r...po....r...p.r_..po....(....(....*...r...po....r...p.r_..po....(....(....*2.r...p(....*2.r...p(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...po....r#..p(....(....*r..r...po....rM..p(....(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):198416
                                                                                                                                                    Entropy (8bit):6.572189329266532
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:8Of7tVL+l4lj19l4uDHYHj69UgoTqdda7CnfKlRUjW01KytaljYqCDPC:8gQQx54Hj6jomdrzalMqb
                                                                                                                                                    MD5:EF8D5785AC8669F5FD54E22F52770E6B
                                                                                                                                                    SHA1:4C94AE7EF233BE33A56C0A5D9B8E2211D5D5792C
                                                                                                                                                    SHA-256:A614884EA627DA1925131EBF41E8AE202CAEAC0FE543B86384F5EB2BFAF1AA75
                                                                                                                                                    SHA-512:AB3B140BD6531F22E994606820E6511442C23D9015B1E1A38AAED43AA42BA29A996511151D0B3A383C05C2B11F670E52CDD7F507AD1A1AD8CEBEA57FB22ADE5A
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Z............." ..0.............:.... ........... .......................@......".....@.....................................O......................../... ......d...p............................................ ............... ..H............text...@.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H...........@H...............z...........................................(;....-.r...ps<...z..s=...}....*..(;....-.r...ps<...z..(....}....*2.{....o>...*..*...2...{....o>.../..{.....o?...*r...ps@...z..0..[........(A...,.r3..ps<...z.{....oB....+..oC.....o.....(D...,......o....-....,..o.....r3..ps@...z.*.........%D.......sE...z.sE...z:..(..........*6..o....(....*..0..F........(A...,.r3..ps<...z..+..{.....o?...o.....(D...,..*......{....o>...2..*r.-.rI..ps<...z.{......oF...*.sE..
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):959
                                                                                                                                                    Entropy (8bit):4.847324835573595
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:12:TMHd413VymhsSRyxrybPYp0IRRXhqR+iLqY8GRKJiSMkgOsa6YEvTDHdtz2dLRRb:2dZmhscPY6IyLnKJbs0EvTjH6j5nrt
                                                                                                                                                    MD5:EE9A8381338B060D86C58E2415F481F3
                                                                                                                                                    SHA1:200F3ED7C773F50C80644F3976E09E876F45993F
                                                                                                                                                    SHA-256:7E1096D6F39EBE04D6E38BC714983AF05ED92CC2BB4D3365ED4C85E733CB145C
                                                                                                                                                    SHA-512:26B9108B9522574E08560BC45A6470F85CA149317BD763F3A357040E0F0E743FD7BFC05E0CE2D9FB52BF89E22C61D221DDF8A7163F5143848717CA3D56847EF1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <startup useLegacyV2RuntimeActivationPolicy="true">.. .. Use supportedRuntime tags to explicitly specify the version(s) of the .NET Framework runtime that.. the custom action should run on. If no versions are specified, the chosen version of the runtime.. will be the "best" match to what WixToolset.Dtf.CustomAction.dll was built against..... WARNING: leaving the version unspecified is dangerous as it introduces a risk of compatibility.. problems with future versions of the .NET Framework runtime. It is highly recommended that you specify.. only the version(s) of the .NET Framework runtime that you have tested against..... For more information https://learn.microsoft.com/en-us/dotnet/framework/configure-apps/file-schema/startup/startup-element.. -->.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.7.2" />.. </startup>..</configuration>..
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):332800
                                                                                                                                                    Entropy (8bit):6.0966953677547275
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:QJA5RylsHmDFin8nhWvGzOJ1mYAFeYXxCJIrkp9TD6qaXn69aKCax8weCycJ5Dfa:ZHmDxnhWvGSJYRFeYXEee9TWqa369An
                                                                                                                                                    MD5:0616EA42B68A8F5F2F01BCD985BDCBC7
                                                                                                                                                    SHA1:88D6AAE1F17B00F4391E0E7B17E98C494BE73BA1
                                                                                                                                                    SHA-256:EA27C65491119EEE5C8E87CE3D470783580DB8FC5BD141C496768D7D0CCE779A
                                                                                                                                                    SHA-512:CE4657908615C4837084C75D806C083B8F7E63965A2E7866B8C96DE7C0278A0857235B74CD9443769968165DB250EBA042A5B05927FEBFF5BB70BEBB7DCBD814
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............)... ...@....... ..............................o.....`.................................2)..O....@.......................`......,(..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................f)......H.......<...0U..........l...@....'........................................{....*..{....*V.(......}......}....*...0..A........u2.......4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. ..<. )UU.Z(.....{....o....X )UU.Z(.....{....o....X*...0..b........r...p......%..{.......%q5....5...-.&.+...5...o.....%..{.......%q6....6...-.&.+...6...o.....(....*..{....*..{....*..{....*r.(......}......}......}....*..0..Y........u7.......L.,G(.....{.....{....o....,/(.....{.....{....o....
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):9728
                                                                                                                                                    Entropy (8bit):4.5545266828490805
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:OiWWNv/jzSENtqcadVl8PandjJUf7ZJSqSi/ufXg1v5rxX0XWr:11Nvb5adVl8P2djJMZJSGu/a5rxX0XWr
                                                                                                                                                    MD5:C9B4EAED07EF72E5ED0F9ECB3E9FFB66
                                                                                                                                                    SHA1:154BF2E5EEC4C08E8954B229439E03A1FB5CD0E8
                                                                                                                                                    SHA-256:B2996E6B102FE829B5683936DD7197F26F375EA16499CC4E6AF88E78538B9FF1
                                                                                                                                                    SHA-512:0482B7328C0C5E82E82ABA033BA6DD5F1800BA0FCEF1522A4CEDF3C212156796738C8C4AB580375B77D90C7CEBC4723D35518F990B836AA64F5CE173D1195FE5
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....>2f...........!.................9... ...@....... ...................................@..................................9..O....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`.......$..............@..B.................9......H........4............... ......P ......................................A~h....r}.......x...._...^xi(e|..A.+{0.38S'3..X..cw.gd..j=<.)Q~>yP0..7r.0.%A(..g..].& .a..@..=.....e.....U.O2.h.}.<..B.`................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....G.......PADPADP..7...7....\.....`.Q......!...........:oH..S....c...........L.}..>.. 2...3...5......:...
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):14336
                                                                                                                                                    Entropy (8bit):5.257505758329955
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:192:Uzt2G73y2jDpCRbzwpOMzGlU7+LghfoFMfBzyj9LmqDFzTufIe9rDE/Y:UZDi2jDp0wpfGmEghfcwCmEFReRUY
                                                                                                                                                    MD5:4D4A5C35CFEC5F348096F4BF3D897C18
                                                                                                                                                    SHA1:68D502D42EA4455F931C2F90869E4D592AF1BD88
                                                                                                                                                    SHA-256:51EBB6EFBC0D2CCDBFECB01BCF08103D62D1DC998CD613903362A284714E8E7E
                                                                                                                                                    SHA-512:A5F8936A55971E3BA60903FA3C7BE487967606502A61FF18F1153BC333838A63B5115AD5140AC56EC7E85470824E599F9192AA8F37F457C3AFCEA08D1B166EDF
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....xx..........." ..0..0...........O... ...`....... ....................................`..................................O..O....`...............................O............................................... ............... ..H............text..../... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............6..............@..B.................O......H........*...$..........................................................2.r...p(....*r..r...po....r-..p(....(....*. .'..(......r...po....rM..p.r_..po....(....(....*...r...po....r...p.r_..po....(....(....*...r...po....r...p.r_..po....(....(....*2.r...p(....*2.r...p(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...po....r#..p(....(....*r..r...po....rM..p(....(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...po....r...p(....(....*r..r...
                                                                                                                                                    Process:C:\Windows\SysWOW64\rundll32.exe
                                                                                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):198416
                                                                                                                                                    Entropy (8bit):6.572189329266532
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:3072:8Of7tVL+l4lj19l4uDHYHj69UgoTqdda7CnfKlRUjW01KytaljYqCDPC:8gQQx54Hj6jomdrzalMqb
                                                                                                                                                    MD5:EF8D5785AC8669F5FD54E22F52770E6B
                                                                                                                                                    SHA1:4C94AE7EF233BE33A56C0A5D9B8E2211D5D5792C
                                                                                                                                                    SHA-256:A614884EA627DA1925131EBF41E8AE202CAEAC0FE543B86384F5EB2BFAF1AA75
                                                                                                                                                    SHA-512:AB3B140BD6531F22E994606820E6511442C23D9015B1E1A38AAED43AA42BA29A996511151D0B3A383C05C2B11F670E52CDD7F507AD1A1AD8CEBEA57FB22ADE5A
                                                                                                                                                    Malicious:true
                                                                                                                                                    Antivirus:
                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Z............." ..0.............:.... ........... .......................@......".....@.....................................O......................../... ......d...p............................................ ............... ..H............text...@.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H...........@H...............z...........................................(;....-.r...ps<...z..s=...}....*..(;....-.r...ps<...z..(....}....*2.{....o>...*..*...2...{....o>.../..{.....o?...*r...ps@...z..0..[........(A...,.r3..ps<...z.{....oB....+..oC.....o.....(D...,......o....-....,..o.....r3..ps@...z.*.........%D.......sE...z.sE...z:..(..........*6..o....(....*..0..F........(A...,.r3..ps<...z..+..{.....o?...o.....(D...,..*......{....o>...2..*r.-.rI..ps<...z.{......oF...*.sE..
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):20480
                                                                                                                                                    Entropy (8bit):1.4596653656797138
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:24:JoTNI6wEhoYlc8Y/M+djc4Gyy76rLd8cHFLl:kHwEaYlgU+dvHyGr5
                                                                                                                                                    MD5:B72182FF3A0D9E0E2DE8C4023D9D7FD7
                                                                                                                                                    SHA1:722F8D111072974AF45091C39F2D51AB3669471E
                                                                                                                                                    SHA-256:0D4448FE3D914D089B38301BE567617B68605212265FA49C72352869319E5447
                                                                                                                                                    SHA-512:BE63E6D1F27BA7A8D2F6D329F55CB0D4CCB8F8C53096D1E06235ABFEC5A028A0D1326F80883C63D4695818A22A86EE5C1BAAC70243F1DFB89E4D3736032CF6E5
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):20480
                                                                                                                                                    Entropy (8bit):1.7239320191081242
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:48:X8PheuRc06WX4onT5cGZgWS2AEkCyfFDvaDu9xPxGaUS8T8xG:Whe1YnTzzEvCAwMxJAM
                                                                                                                                                    MD5:34EB53B1487DCCA5CBEDA78931EC6736
                                                                                                                                                    SHA1:E4C9E7196799B84FE7FC1975F194EC04D65BB8BA
                                                                                                                                                    SHA-256:C7B08184F8AFF1A816F27CDB9B26F5E36C20E6C800C6B64A3514F71B7D3B5C6E
                                                                                                                                                    SHA-512:013CD6CA8BA9070EA043BA8C4605408CA0DA1E21AEFFC5C118CF586909D05C09AA25DC079FF3580AAAFBB5EA85140C8C9B5E2BD876D83BA266F744347A2B027A
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                    Category:dropped
                                                                                                                                                    Size (bytes):360001
                                                                                                                                                    Entropy (8bit):5.362969264287014
                                                                                                                                                    Encrypted:false
                                                                                                                                                    SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgau/:zTtbmkExhMJCIpEy
                                                                                                                                                    MD5:4862F795922E8E6404E7DD77D07FE8B7
                                                                                                                                                    SHA1:C32780FA8B233FA937E28F00C537CFFF423E559A
                                                                                                                                                    SHA-256:123B93A0F8BA87A494C9E50334C7EA949961B1D982AE63C61D13A16571E4F7D9
                                                                                                                                                    SHA-512:625FCA4CB43A234FD0C864A71CB67C336EBD870DD5B0CDADEB74C597CDC5C8921FE4F0C48E36958833D6E170BEBC5694B60A0941F4DE92DADFC6F83E264470B1
                                                                                                                                                    Malicious:false
                                                                                                                                                    Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                                                                                                                                                    Process:C:\Windows\System32\msiexec.exe
                                                                                                                                                    File Type:Composite Document File V2 Document, Cannot read