Analysis Report https://forms.office.com/Pages/ResponsePage.aspx?id=cDgNZ_NsCEK0nbknGQ7BS4561NiEZjlNhv9vg7q7u5hUOERRUVExUUtGSUJPUkhDVk82TU5JNFlTQS4u

Overview

General Information

Sample URL: https://forms.office.com/Pages/ResponsePage.aspx?id=cDgNZ_NsCEK0nbknGQ7BS4561NiEZjlNhv9vg7q7u5hUOERRUVExUUtGSUJPUkhDVk82TU5JNFlTQS4u
Analysis ID: 324355

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: unknown DNS traffic detected: queries for: forms.office.com
Source: ccfee25f38f911d4_0.0.dr String found in binary or memory: http://amp.azure.net/libs/amp/
Source: 77EC63BDA74BD0D0E0426DC8F8008506.1.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: df05730d55081a08_0.0.dr String found in binary or memory: https://accdn.lpsnmedia.net/api/account/60270350/configuration/engagement-window/window-confs/164436
Source: 156e023462d48427_0.0.dr String found in binary or memory: https://accdn.lpsnmedia.net/api/account/60270350/configuration/le-campaigns/campaigns/1644274130/eng
Source: 72090e93af2b3d0c_0.0.dr String found in binary or memory: https://accdn.lpsnmedia.net/api/account/60270350/configuration/le-campaigns/zones?fields=id&fields=z
Source: 3b5ddd299823dee6_0.0.dr String found in binary or memory: https://accdn.lpsnmedia.net/api/account/60270350/configuration/setting/accountproperties/?cb=lpCb208
Source: manifest.json0.0.dr, 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://accounts.google.com
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/
Source: c94540d4c86c0448_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.11.1.min.js
Source: 094e2d6bf2abec98_0.0.dr, 5334000c05ed2b53_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.11.2.min.js
Source: 5334000c05ed2b53_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.11.2.min.jsaD
Source: f46ad1d2652b0b43_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.7.2.min.js
Source: b180e6523891105c_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.9.1.min.js
Source: 82e92344281b46a9_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jquery.ui/1.11.1/jquery-ui.min.js
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://aka.ms/
Source: History-journal.0.dr String found in binary or memory: https://aka.ms/PrivacyReport
Source: History-journal.0.dr String found in binary or memory: https://aka.ms/PrivacyReportMicrosoft
Source: 166ee82c52b87e97_0.0.dr String found in binary or memory: https://amp.azure.net/libs/amp/1.8.0/azuremediaplayer.min.js
Source: ccfee25f38f911d4_0.0.dr String found in binary or memory: https://amp.azure.net/libs/amp/1.8.0/azuremediaplayer.min.jsa
Source: ccfee25f38f911d4_0.0.dr String found in binary or memory: https://amp.azure.net/libs/amp/1.8.0/azuremediaplayer.min.jsaD
Source: manifest.json0.0.dr, 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://apis.google.com
Source: b63b43555f5ef307_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC021d0a1582e845158b9974bf66e669f
Source: dc7f1e4e542b651c_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC05ac5f311ffd4e5c9ad450f46819401
Source: 1901d97a494284b6_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC15f3408d92fc4519a3a4fbb6f85a3d5
Source: 5193d3a772576834_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC278c787435b94d148603e89a80d2b33
Source: ef812770fec62f00_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC2fdf0b42e0414a7982f3ba48531bc16
Source: 46c1f20282dfa665_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC3743cb8b1ea14f88b7f7258ff32b6dc
Source: c45f8af2b96a162d_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC54b490a964b8430a93c0a4bea8ec38f
Source: bb03dd199347c739_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC683368007e154c38814065ef2499a0b
Source: 55002aca08adc148_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RC9c46fb6a891f4562b65713ecdcbb737
Source: a245930ddc6025a9_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RCa6da6c2ddf044453bdb4d0b0dafda95
Source: 96db824c331a77d5_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RCa7a16d61c0134716b6c5d59808f9fd2
Source: 9e3e3b309feee242_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RCb36993ed0cd440348a1b4711c13dbc8
Source: e020b8b54f7e541f_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RCb931a36f851d412386794b82eefa667
Source: 99d39807317fa33a_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RCc603b998e8c64e55b78656817f79328
Source: a62abfc932b5eff2_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/4c272e8cc694/0e102e270abf/RCce79330d434c45ca8ea9effba974a13
Source: fab5435452b3b5fd_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC1a3e34bc6d5b4a44bdd14eed6f571ac
Source: 6e646dd4f853f7d8_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC30b69654d14a4895ae64b6e5cf0cf81
Source: 049e61f56bdec1ac_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC5548547466864ee2ab73cca512147d7
Source: e9e0fbfc734770b0_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC557c8c9e1a32442f85198b3cd484649
Source: dcbf9a43deeccc1e_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC5f812135e64f48ad85ea100034bc60a
Source: ea27fa7ad55e1017_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC69b31008c50e44318e064df1bd9de72
Source: 09e38a19b46d6eb3_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC8f2e96b0f42b4791b6a87bd6474f9dc
Source: 7d664ffbb549cf44_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC95d5954deda24aa780e2bd87a6eabf8
Source: 4e602b2b62deec45_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RC9f9b3c9f668a4b9dbf5ccda86744fe3
Source: 71533a71068a629c_0.0.dr String found in binary or memory: https://assets.adobedtm.com/5ef092d1efb5/e6b4ca74378c/2418adba327c/RCf16325d3e41c447fb6b66d7d82fcb43
Source: 112ffe0d2f355de3_0.0.dr String found in binary or memory: https://assets.adobedtm.com/launch-EN7506e353034849faa4a18bc4c20e727c.min.js
Source: 3c4d40e130a6a467_0.0.dr String found in binary or memory: https://assets.adobedtm.com/launch-ENbb9d0de7cc374dc99259df2c4b823cef.min.js
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://assets.onestore.ms/
Source: 9edc3bcc45a63d3b_0.0.dr String found in binary or memory: https://assets.onestore.ms/cdnfiles/external/mwf/long/v1/v1.19.1/scripts/mwf-main.var.js
Source: 38b572a46376d5b4_0.0.dr String found in binary or memory: https://assets.onestore.ms/cdnfiles/external/mwf/long/v1/v1.22.1/scripts/mwf-auto-init-main.var.min.
Source: 7bf2e63aba04327d_0.0.dr String found in binary or memory: https://assets.onestore.ms/cdnfiles/external/mwf/long/v1/v1.23.1/scripts/mwf-auto-init-main.var.min.
Source: 106511ff7d335ae7_0.0.dr String found in binary or memory: https://assets.onestore.ms/cdnfiles/external/mwf/long/v1/v1.23.1/scripts/mwf-video-player-main.var.m
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://az725175.vo.msecnd.net/
Source: a04d28593344b886_0.0.dr String found in binary or memory: https://az725175.vo.msecnd.net/scripts/jsll-4.3.1.js
Source: a427860bca0ae4c4_0.0.dr, 6b848a87f40dd230_0.0.dr String found in binary or memory: https://az725175.vo.msecnd.net/scripts/jsll-4.js
Source: Favicons-journal.0.dr String found in binary or memory: https://cdn.forms.office.net/forms/images/favicon.ico
Source: Favicons-journal.0.dr String found in binary or memory: https://cdn.forms.office.net/forms/images/favicon.icorL
Source: b7908b9c9b3341b0_0.0.dr String found in binary or memory: https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.ext.1c44705.js
Source: 5cf7c6cbf1d6c26c_0.0.dr String found in binary or memory: https://cdn.forms.office.net/forms/scripts/dists/light-response-page.chunk.vendors.6a9a01e.js
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: 5a2848e832bc50f4_0.0.dr String found in binary or memory: https://consentreceiverfd-prod.azurefd.net/v1
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: 3131deb4-2687-4838-b861-23b939b0674b.tmp.1.dr, 4d3628b5-7221-4219-bd75-68b7fd0e3fcd.tmp.1.dr, 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: 000003.log4.0.dr String found in binary or memory: https://forms.office.com
Source: 000003.log0.0.dr String found in binary or memory: https://forms.office.com/
Source: Favicons-journal.0.dr String found in binary or memory: https://forms.office.com/Pages/ResponsePage.aspx?id=cDgNZ_NsCEK0nbknGQ7BS4561NiEZjlNhv9vg7q7u5hUOERR
Source: 000003.log4.0.dr String found in binary or memory: https://forms.office.com7_https://forms.office.com
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: 411135a47a8afbd4_0.0.dr String found in binary or memory: https://live.com/
Source: f7ea591cb5d1c051_0.0.dr String found in binary or memory: https://liveperson.net/
Source: 72090e93af2b3d0c_0.0.dr String found in binary or memory: https://liveperson.net//
Source: 3b5ddd299823dee6_0.0.dr String found in binary or memory: https://liveperson.net/O
Source: 22fb0e1969c285c1_0.0.dr String found in binary or memory: https://liveperson.net/W
Source: c69630b836b04401_0.0.dr String found in binary or memory: https://liveperson.net/h
Source: 50030ae951750ff1_0.0.dr String found in binary or memory: https://liveperson.net/iP
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://login.live.com/
Source: Current Session.0.dr String found in binary or memory: https://login.live.com/Me.srf?wa=wsignin1.0&rpsnv=13&ct=1606657350&rver=7.0.6738.0&wp=MBI_SSL&wreply
Source: History-journal.0.dr String found in binary or memory: https://login.live.com/login.srf?wa=wsignin1.0&rpsnv=13&checkda=1&ct=1606657348&rver=7.0.6738.0&wp=S
Source: Current Session.0.dr String found in binary or memory: https://login.microsoftonline.com
Source: Current Session.0.dr String found in binary or memory: https://login.microsoftonline.com/
Source: Current Session.0.dr String found in binary or memory: https://login.microsoftonline.comh
Source: 411135a47a8afbd4_0.0.dr String found in binary or memory: https://logincdn.msauth.net/16.000/content/js/MeControl_zXOsandYqRnW6Qh35WUOMw2.js
Source: 411135a47a8afbd4_0.0.dr String found in binary or memory: https://logincdn.msauth.net/16.000/content/js/MeControl_zXOsandYqRnW6Qh35WUOMw2.jsaD
Source: 000003.log4.0.dr String found in binary or memory: https://lpcdn.lpsnmedia.net
Source: 000003.log4.0.dr String found in binary or memory: https://lpcdn.lpsnmedia.net(_https://lpcdn.lpsnmedia.net
Source: 000003.log0.0.dr String found in binary or memory: https://lpcdn.lpsnmedia.net/
Source: 50030ae951750ff1_0.0.dr String found in binary or memory: https://lpcdn.lpsnmedia.net/le_re/3.43.0.1-release_5028/jsv2/UISuite.js?_v=3.43.0.1-release_5028
Source: 309184ad59030aa2_0.0.dr String found in binary or memory: https://lpcdn.lpsnmedia.net/le_re/3.43.0.1-release_5028/jsv2/overlay.js?_v=3.43.0.1-release_5028
Source: Current Session.0.dr String found in binary or memory: https://lpcdn.lpsnmedia.net/le_secure_storage/3.11.0.2-release_5036/storage.secure.min.html?loc=http
Source: e080674af345915e_0.0.dr String found in binary or memory: https://lpcdn.lpsnmedia.net/le_secure_storage/3.11.0.2-release_5036/storage.secure.min.js?loc=https%
Source: f7ea591cb5d1c051_0.0.dr String found in binary or memory: https://lptag.liveperson.net/lptag/api/account/60270350/configuration/applications/taglets/.jsonp?v=
Source: 22fb0e1969c285c1_0.0.dr String found in binary or memory: https://lptag.liveperson.net/tag/tag.js?site=60270350
Source: 8a41173cbadc68f7_0.0.dr String found in binary or memory: https://mem.gfx.ms
Source: Network Action Predictor.0.dr String found in binary or memory: https://mem.gfx.ms/
Source: 4ac2f448771ab57b_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=OfficeProducts&market=de-ch&uhf=1
Source: 462d64d34aad30da_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=OfficeProducts&market=en-us&uhf=1
Source: 226692e5ab9c95ba_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=RetailStore2&market=en-us&uhf=1
Source: 8a41173cbadc68f7_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=SMCConvergence&market=en-us&uhf=1
Source: 8a41173cbadc68f7_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=SMCConvergence&market=en-us&uhf=1aD
Source: 300bb9fb98ab63f0_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=amc&market=en-us&uhf=1
Source: 1a82e691e1d458ec_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=surface&market=en-us&uhf=1
Source: a5b18de7662d18f2_0.0.dr String found in binary or memory: https://mem.gfx.ms/meversion?partner=windows&market=en-us&uhf=1
Source: 94a5143d10615cf8_0.0.dr String found in binary or memory: https://mem.gfx.ms/scripts/me/MeControl/10.20300.4/de-DE/meBoot.min.js
Source: 601763cfed8be44f_0.0.dr String found in binary or memory: https://mem.gfx.ms/scripts/me/MeControl/10.20300.4/de-DE/meCore.min.js
Source: c02db6ab60fb1129_0.0.dr String found in binary or memory: https://mem.gfx.ms/scripts/me/MeControl/10.20300.4/en-US/meBoot.min.js
Source: c02db6ab60fb1129_0.0.dr String found in binary or memory: https://mem.gfx.ms/scripts/me/MeControl/10.20300.4/en-US/meBoot.min.jsaD
Source: 16d2f3faad7856af_0.0.dr String found in binary or memory: https://mem.gfx.ms/scripts/me/MeControl/10.20300.4/en-US/meCore.min.js
Source: 16d2f3faad7856af_0.0.dr String found in binary or memory: https://mem.gfx.ms/scripts/me/MeControl/10.20300.4/en-US/meCore.min.jsaD
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://mwf-service.akamaized.net/
Source: 94d12f6ce814ffd5_0.0.dr String found in binary or memory: https://mwf-service.akamaized.net/mwf/js/bundle/1.57.8/mwf-main.umd.min.js
Source: b7908b9c9b3341b0_0.0.dr String found in binary or memory: https://office.com/
Source: 5cf7c6cbf1d6c26c_0.0.dr String found in binary or memory: https://office.com//(
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://play.google.com
Source: 000003.log4.0.dr String found in binary or memory: https://publisher.liveperson.net
Source: 000003.log4.0.dr String found in binary or memory: https://publisher.liveperson.net-_https://publisher.liveperson.net
Source: 000003.log0.0.dr String found in binary or memory: https://publisher.liveperson.net/
Source: Current Session.0.dr String found in binary or memory: https://publisher.liveperson.net/iframe-le-tag/iframe.html?lpsite=60270350&lpsection=store-sales-en-
Source: 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://r3---sn-h0jeln7r.gvt1.com
Source: 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://redirector.gvt1.com
Source: manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: c69630b836b04401_0.0.dr String found in binary or memory: https://static-assets.fs.liveperson.com/microsoft/aibot.js
Source: 3b99dc3d3bc104fb_0.0.dr String found in binary or memory: https://static-assets.fs.liveperson.com/microsoft/lp_ada_enhancements-prod.js
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://statics-marketingsites-eus-ms-com.akamaized.net/
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://statics-marketingsites-neu-ms-com.akamaized.net/
Source: Network Action Predictor-journal.0.dr String found in binary or memory: https://statics-marketingsites-wcus-ms-com.akamaized.net/
Source: Network Action Predictor.0.dr String found in binary or memory: https://statics-storeexp-neu-ms-com.akamaized.net/
Source: c7b12560f839e230_0.0.dr String found in binary or memory: https://statics-storeexp-neu-ms-com.akamaized.net/_h/46c44584/coreui.statics/externalscripts/jquery/
Source: adcefe05f695f7f2_0.0.dr String found in binary or memory: https://statics-storeexp-neu-ms-com.akamaized.net/store/_scrf/js/themes=store-web-default/2f-63ce8f/
Source: 71f52630121e1252_0.0.dr String found in binary or memory: https://statics-storeexp-neu-ms-com.akamaized.net/store/_scrf/js/themes=store-web-default/e2-ed7413/
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: manifest.json0.0.dr, 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://www.google.com
Source: manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 7af3b868-3d93-4fde-9550-fcbc12cf696e.tmp.1.dr, 13aa37f0-eeee-45c8-90b1-d51e2544daae.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49872
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49960
Source: unknown Network traffic detected: HTTP traffic on port 50011 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50087
Source: unknown Network traffic detected: HTTP traffic on port 50092 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49857 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49872 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50011
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50137
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49960 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50081
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50092
Source: unknown Network traffic detected: HTTP traffic on port 50137 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50140
Source: unknown Network traffic detected: HTTP traffic on port 50081 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50140 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49857
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 50087 -> 443
Source: classification engine Classification label: clean0.win@53/303@29/11
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-5FC423B7-1724.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\41eb0a49-5c28-4756-8488-c4eebba75e99.tmp Jump to behavior
Source: QuotaManager.0.dr Binary or memory string: CREATE TABLE HostQuotaTable(host TEXT NOT NULL, type INTEGER NOT NULL, quota INTEGER DEFAULT 0, UNIQUE(host, type));
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized 'https://forms.office.com/Pages/ResponsePage.aspx?id=cDgNZ_NsCEK0nbknGQ7BS4561NiEZjlNhv9vg7q7u5hUOERRUVExUUtGSUJPUkhDVk82TU5JNFlTQS4u'
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1504,15741333574045818394,7388905800530690174,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1916 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1504,15741333574045818394,7388905800530690174,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1916 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 324355 URL: https://forms.office.com/Pa... Startdate: 29/11/2020 Architecture: WINDOWS Score: 0 12 support.content.office.net 2->12 14 mcraa.fs.liveperson.com 2->14 16 cdn.forms.office.net 2->16 6 chrome.exe 14 501 2->6         started        process3 dnsIp4 18 192.168.2.1 unknown unknown 6->18 20 239.255.255.250 unknown Reserved 6->20 9 chrome.exe 200 6->9         started        process5 dnsIp6 22 blob.bl6prdstr14a.store.core.windows.net 52.239.152.74, 443, 49960 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 9->22 24 va.v.liveperson.net 208.89.12.87, 443, 50140 LIVEPERSONUS United States 9->24 26 34 other IPs or domains 9->26
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
13.225.73.51
unknown United States
16509 AMAZON-02US false
15.237.136.106
unknown United States
16509 AMAZON-02US false
216.58.215.225
unknown United States
15169 GOOGLEUS false
239.255.255.250
unknown Reserved
unknown unknown false
192.229.221.185
unknown United States
15133 EDGECASTUS false
104.74.143.169
unknown United States
16625 AKAMAI-ASUS false
52.239.152.74
unknown United States
8075 MICROSOFT-CORP-MSN-AS-BLOCKUS false
208.89.12.87
unknown United States
11054 LIVEPERSONUS false
151.101.1.192
unknown United States
54113 FASTLYUS false

Private

IP
192.168.2.1
127.0.0.1

Contacted Domains

Name IP Active
microsoftwindows.112.2o7.net 15.237.136.106 true
blob.bl6prdstr14a.store.core.windows.net 52.239.152.74 true
dh1y47vf5ttia.cloudfront.net 13.225.73.51 true
va.v.liveperson.net 208.89.12.87 true
cs1227.wpc.alphacdn.net 192.229.221.185 true
mcraa.fs.liveperson.com 3.216.53.130 true
liveperson.map.fastly.net 151.101.1.192 true
aka.ms 104.74.143.169 true
googlehosted.l.googleusercontent.com 216.58.215.225 true
logincdn.msauth.net unknown unknown
lpcdn.lpsnmedia.net unknown unknown
statics-eas.onestore.ms unknown unknown
assets.onestore.ms unknown unknown
ajax.aspnetcdn.com unknown unknown
static-assets.fs.liveperson.com unknown unknown
cdn.forms.office.net unknown unknown
surfaceselfserviceoffertool.azurewebsites.net unknown unknown
clients2.googleusercontent.com unknown unknown
statics-wcus.onestore.ms unknown unknown
publisher.liveperson.net unknown unknown
c.office.com unknown unknown
forms.office.com unknown unknown
accdn.lpsnmedia.net unknown unknown
assets.adobedtm.com unknown unknown
mem.gfx.ms unknown unknown
statics-neu.onestore.ms unknown unknown
statics-eus.onestore.ms unknown unknown
support.content.office.net unknown unknown
amp.azure.net unknown unknown
login.microsoftonline.com unknown unknown
offertooldataprod.blob.core.windows.net unknown unknown
lptag.liveperson.net unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://forms.office.com/Pages/ResponsePage.aspx?id=cDgNZ_NsCEK0nbknGQ7BS4561NiEZjlNhv9vg7q7u5hUOERRUVExUUtGSUJPUkhDVk82TU5JNFlTQS4u false
    high