Loading ...

Play interactive tourEdit tour

Analysis Report presentation.jar

Overview

General Information

Sample Name:presentation.jar
Analysis ID:406076
MD5:6c5e7908c3a06aafd6dcebc8a2dcb674
SHA1:d094aef9d24e13ab70f2ef767242be554ed855ae
SHA256:cb8b20c28a0ac697b6f5bd430bd86762f6b9ef635428fe3fe77e174b172ac6f4
Infos:

Most interesting Screenshot:

Detection

Ursnif
Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Ursnif
Exploit detected, runtime environment dropped PE file
Exploit detected, runtime environment starts unknown processes
Found stalling execution ending in API Sleep call
Abnormal high CPU Usage
Contains capabilities to detect virtual machines
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Found dropped PE file which has not been started or loaded
Found evasive API chain (may stop execution after checking a module file name)
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Registers a DLL
Sample execution stops while process was sleeping (likely an evasion)
Tries to load missing DLLs
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)

Classification

Startup

  • System is w10x64
  • cmd.exe (PID: 6552 cmdline: C:\Windows\system32\cmd.exe /c 7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar' MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
    • 7za.exe (PID: 6584 cmdline: 7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar' MD5: 77E556CDFDC5C592F5C46DB4127C6F4C)
  • cmd.exe (PID: 6624 cmdline: 'C:\Windows\System32\cmd.exe' /c java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer >> C:\cmdlinestart.log 2>&1 MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
    • conhost.exe (PID: 6632 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • java.exe (PID: 6684 cmdline: java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer MD5: 28733BA8C383E865338638DF5196E6FE)
      • icacls.exe (PID: 6740 cmdline: C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M MD5: FF0D1D4317A44C951240FAE75075D501)
        • conhost.exe (PID: 6760 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • iexplore.exe (PID: 6828 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' https://www.java.com/ MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596)
        • iexplore.exe (PID: 6884 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6828 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A)
      • regsvr32.exe (PID: 7152 cmdline: regsvr32.exe /s C:\Users\user\AppData\Local\broker.dll MD5: 426E7499F6A7346F0410DEAD0805586B)
  • cleanup

Malware Configuration

Threatname: Ursnif

{"lang_id": "RU, CN", "RSA Public Key": "C6HtybW6gOadm/yj7zZMo6G6KXFQ4dEp7zHfMW5IRELO0uvqi07MPT6/x9S6litknH+BvSY8WUJSCe++K06Znqzju0G9p4s7vFCRkOmz8D6jF964Fzsv95HaHsXi47+U2GiQ2Gikw0inkLSb2F3I2SWzZYUSFyC2M/2JSO9/RfzN4fQovVmdO23GnRaRT7RQ80xdzZmG/1KSXrPdpz6L0pheEWvnVtXAtJsxn0oJ2Av+YPARe6ceA0vZDing87oj0OaTGGHfCE60e2J7m50kPk40R/wZ5kCD/nJn2jktSyio6o+GuLZKR/fZyVreMHafB6O7UghEGnsrn77tN0EAJaA+F5jMamer1uRrqfAyszw=", "c2_domain": ["app.buboleinov.com", "chat.veminiare.com", "chat.billionady.com", "app3.maintorna.com"], "botnet": "2500", "server": "580", "serpent_key": "ZihFTxUSedu9uCzM", "sleep_time": "10", "SetWaitableTimer_value": "10"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
0000000A.00000003.535228068.0000000003410000.00000040.00000001.sdmpJoeSecurity_Ursnif_1Yara detected UrsnifJoe Security

    Unpacked PEs

    SourceRuleDescriptionAuthorStrings
    10.2.regsvr32.exe.4cf0000.1.unpackJoeSecurity_Ursnif_1Yara detected UrsnifJoe Security
      10.3.regsvr32.exe.3418d23.0.raw.unpackJoeSecurity_Ursnif_1Yara detected UrsnifJoe Security

        Sigma Overview

        No Sigma rule has matched

        Signature Overview

        Click to jump to signature section

        Show All Signature Results

        AV Detection:

        barindex
        Found malware configurationShow sources
        Source: 10.3.regsvr32.exe.3418d23.0.raw.unpackMalware Configuration Extractor: Ursnif {"lang_id": "RU, CN", "RSA Public Key": "C6HtybW6gOadm/yj7zZMo6G6KXFQ4dEp7zHfMW5IRELO0uvqi07MPT6/x9S6litknH+BvSY8WUJSCe++K06Znqzju0G9p4s7vFCRkOmz8D6jF964Fzsv95HaHsXi47+U2GiQ2Gikw0inkLSb2F3I2SWzZYUSFyC2M/2JSO9/RfzN4fQovVmdO23GnRaRT7RQ80xdzZmG/1KSXrPdpz6L0pheEWvnVtXAtJsxn0oJ2Av+YPARe6ceA0vZDing87oj0OaTGGHfCE60e2J7m50kPk40R/wZ5kCD/nJn2jktSyio6o+GuLZKR/fZyVreMHafB6O7UghEGnsrn77tN0EAJaA+F5jMamer1uRrqfAyszw=", "c2_domain": ["app.buboleinov.com", "chat.veminiare.com", "chat.billionady.com", "app3.maintorna.com"], "botnet": "2500", "server": "580", "serpent_key": "ZihFTxUSedu9uCzM", "sleep_time": "10", "SetWaitableTimer_value": "10"}
        Multi AV Scanner detection for dropped fileShow sources
        Source: C:\Users\user\AppData\Local\broker.dllReversingLabs: Detection: 27%
        Multi AV Scanner detection for submitted fileShow sources
        Source: presentation.jarVirustotal: Detection: 19%Perma Link
        Source: presentation.jarReversingLabs: Detection: 41%
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll
        Source: unknownHTTPS traffic detected: 99.86.2.60:443 -> 192.168.2.6:49726 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 99.86.2.60:443 -> 192.168.2.6:49727 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 50.87.249.219:443 -> 192.168.2.6:49721 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 13.32.21.15:443 -> 192.168.2.6:49733 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 13.32.21.15:443 -> 192.168.2.6:49732 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 65.9.66.38:443 -> 192.168.2.6:49734 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 65.9.66.38:443 -> 192.168.2.6:49735 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.6:49737 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.6:49736 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 3.212.50.245:443 -> 192.168.2.6:49739 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 3.212.50.245:443 -> 192.168.2.6:49738 version: TLS 1.2
        Source: Binary string: c:\119\Minute\Force_Lead\Apple\oil.pdb source: regsvr32.exe, 0000000A.00000002.601653478.0000000004D24000.00000002.00020000.sdmp, broker.dll.5.dr

        Software Vulnerabilities:

        barindex
        Exploit detected, runtime environment starts unknown processesShow sources
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Program Files\internet explorer\iexplore.exe
        Source: Joe Sandbox ViewIP Address: 35.181.18.61 35.181.18.61
        Source: Joe Sandbox ViewJA3 fingerprint: 9e10692f1b7f78228b2d4e424db3a98c
        Source: Joe Sandbox ViewJA3 fingerprint: d2935c58fe676744fecc8614ee5356c7
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: <FavoriteIcon>http://www.facebook.com/favicon.ico</FavoriteIcon> equals www.facebook.com (Facebook)
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: <FavoriteIcon>http://www.myspace.com/favicon.ico</FavoriteIcon> equals www.myspace.com (Myspace)
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: <FavoriteIcon>http://www.rambler.ru/favicon.ico</FavoriteIcon> equals www.rambler.ru (Rambler)
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: <URL>http://www.facebook.com/</URL> equals www.facebook.com (Facebook)
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: <URL>http://www.rambler.ru/</URL> equals www.rambler.ru (Rambler)
        Source: msapplication.xml0.8.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0xac86d482,0x01d742dd</date><accdate>0xac86d482,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
        Source: msapplication.xml0.8.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0xac86d482,0x01d742dd</date><accdate>0xac86d482,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig> equals www.facebook.com (Facebook)
        Source: msapplication.xml5.8.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0xac8b98f7,0x01d742dd</date><accdate>0xac8b98f7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
        Source: msapplication.xml5.8.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0xac8b98f7,0x01d742dd</date><accdate>0xac8b98f7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig> equals www.twitter.com (Twitter)
        Source: msapplication.xml7.8.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0xac8dfb49,0x01d742dd</date><accdate>0xac8dfb49,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
        Source: msapplication.xml7.8.drString found in binary or memory: <browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0xac8dfb49,0x01d742dd</date><accdate>0xac8dfb49,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig> equals www.youtube.com (Youtube)
        Source: unknownDNS traffic detected: queries for: www.java.com
        Source: java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: HTTP://WWW.CHAMBERSIGN.ORG
        Source: java.exe, 00000005.00000002.373821358.0000000016640000.00000002.00000001.sdmpString found in binary or memory: http://%s.com
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://amazon.fr/
        Source: java.exe, 00000005.00000002.358273563.000000000487B000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://apps.identrust.com/roots/dstrootcax3.p7c
        Source: java.exe, 00000005.00000002.358264330.0000000004873000.00000004.00000001.sdmpString found in binary or memory: http://apps.identrust.com/roots/dstrootcax3.p7c0
        Source: java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://apps.identrust.com/roots/dstrootcax3.p7cK#
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://ariadna.elmundo.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://ariadna.elmundo.es/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://arianna.libero.it/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://arianna.libero.it/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://asp.usatoday.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://asp.usatoday.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://auone.jp/favicon.ico
        Source: java.exe, 00000005.00000002.373821358.0000000016640000.00000002.00000001.sdmpString found in binary or memory: http://auto.search.msn.com/response.asp?MT=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://br.search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://browse.guardian.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://browse.guardian.co.uk/favicon.ico
        Source: java.exe, 00000005.00000002.358510729.00000000099A1000.00000004.00000001.sdmpString found in binary or memory: http://bugreport.sun.com/bugreport/
        Source: 0D070042D9C67A68E1A4BF804E6E0E06.cache[1].htm.9.drString found in binary or memory: http://bugs.webkit.org/show_bug.cgi?id=3810
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.buscape.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.buscape.com.br/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.estadao.com.br/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.igbusca.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.igbusca.com.br//app/static/images/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.orange.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.uol.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busca.uol.com.br/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://buscador.lycos.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://buscador.terra.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://buscador.terra.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://buscador.terra.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://buscador.terra.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://buscar.ozu.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://buscar.ya.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://busqueda.aol.com.mx/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://cerca.lycos.it/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://cgi.search.biglobe.ne.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://cgi.search.biglobe.ne.jp/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://clients5.google.com/complete/search?hl=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://cnet.search.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://cnweb.search.live.com/results.aspx?q=
        Source: notice[2].js.9.drString found in binary or memory: http://consent-pref.trustarc.com/?type=oracle6
        Source: notice[2].js.9.drString found in binary or memory: http://consent.trustarc.com/
        Source: notice[2].js.9.drString found in binary or memory: http://consent.trustarc.com/bannermsg?
        Source: notice[2].js.9.drString found in binary or memory: http://consent.trustarc.com/noticemsg?
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://corp.naukri.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://corp.naukri.com/favicon.ico
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://cps.chambersign.org/cps/chambersroot.html
        Source: java.exe, 00000005.00000002.358700508.0000000009ACC000.00000004.00000001.sdmpString found in binary or memory: http://cps.chambersign.org/cps/chambersroot.html0
        Source: java.exe, 00000005.00000002.358273563.000000000487B000.00000004.00000001.sdmpString found in binary or memory: http://cps.letsencrypt.org
        Source: java.exe, 00000005.00000002.358264330.0000000004873000.00000004.00000001.sdmpString found in binary or memory: http://cps.letsencrypt.org0
        Source: java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://cps.letsencrypt.orgc
        Source: java.exe, 00000005.00000002.358273563.000000000487B000.00000004.00000001.sdmpString found in binary or memory: http://cps.root-x1.letsencrypt.org
        Source: java.exe, 00000005.00000002.358264330.0000000004873000.00000004.00000001.sdmpString found in binary or memory: http://cps.root-x1.letsencrypt.org0
        Source: java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://cps.root-x1.letsencrypt.orgk
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: http://crl.chambersign.org/chambersroot.crl
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://crl.chambersign.org/chambersroot.crl0
        Source: java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl
        Source: 7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.372213730.0000000015970000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
        Source: 7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.372213730.0000000015970000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
        Source: java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://crl.identrust.com/DSTROOTCAX3CRL.crl
        Source: java.exe, 00000005.00000002.358264330.0000000004873000.00000004.00000001.sdmpString found in binary or memory: http://crl.identrust.com/DSTROOTCAX3CRL.crl0
        Source: java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoRSACodeSigningCA.crl
        Source: 7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358444370.0000000009957000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drString found in binary or memory: http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl0
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
        Source: java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoRSACodeSigningCA.crt
        Source: 7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358444370.0000000009957000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drString found in binary or memory: http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://de.search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://es.ask.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://es.search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://esearch.rakuten.co.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://espanol.search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://espn.go.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://find.joins.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://fr.search.yahoo.com/
        Source: renderer[1].js.9.drString found in binary or memory: http://github.com/requirejs/text/LICENSE
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://google.pchome.com.tw/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://home.altervista.org/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://home.altervista.org/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://ie.search.yahoo.com/os?command=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://ie8.ebay.com/open-search/output-xml.php?q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://image.excite.co.jp/jp/favicon/lep.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://images.joins.com/ui_c/fvc_joins.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://images.monster.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://img.atlas.cz/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://img.shopzilla.com/shopzilla/shopzilla.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://in.search.yahoo.com/
        Source: get[1].js.9.drString found in binary or memory: http://inforoom.truste.com
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://it.search.dada.net/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://it.search.dada.net/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://it.search.yahoo.com/
        Source: java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpString found in binary or memory: http://java.oracle.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://jobsearch.monster.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://kr.search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://list.taobao.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://list.taobao.com/browse/search_visual.htm?n=15&amp;q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://mail.live.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://mail.live.com/?rru=compose%3Fsubject%3D
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://msk.afisha.ru/
        Source: java.exe, java.exe, 00000005.00000002.358700508.0000000009ACC000.00000004.00000001.sdmpString found in binary or memory: http://null.oracle.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://ocnsearch.goo.ne.jp/
        Source: java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.comodoca.com
        Source: 7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.372213730.0000000015970000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drString found in binary or memory: http://ocsp.comodoca.com0
        Source: java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpString found in binary or memory: http://ocsp.sectigo.com
        Source: 7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358444370.0000000009957000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drString found in binary or memory: http://ocsp.sectigo.com0
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://openimage.interpark.com/interpark.ico
        Source: render[1].js0.9.drString found in binary or memory: http://oss.oracle.com/licenses/upl.
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://p.zhongsou.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://p.zhongsou.com/favicon.ico
        Source: 1.cache[1].js.9.drString found in binary or memory: http://ph-truste-stage.truste-svc.net/js/cookie_iframe.html
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://policy.camerfirma.com
        Source: java.exe, 00000005.00000002.358700508.0000000009ACC000.00000004.00000001.sdmpString found in binary or memory: http://policy.camerfirma.com0
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://price.ru/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://price.ru/favicon.ico
        Source: java.exe, 00000005.00000002.358273563.000000000487B000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://r3.i.lencr.org/
        Source: java.exe, 00000005.00000002.358264330.0000000004873000.00000004.00000001.sdmpString found in binary or memory: http://r3.i.lencr.org/0
        Source: java.exe, 00000005.00000002.358273563.000000000487B000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://r3.o.lencr.org
        Source: java.exe, 00000005.00000002.358264330.0000000004873000.00000004.00000001.sdmpString found in binary or memory: http://r3.o.lencr.org0
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://recherche.linternaute.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://recherche.tf1.fr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://recherche.tf1.fr/favicon.ico
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://repository.swisssign.com/
        Source: java.exe, 00000005.00000002.358700508.0000000009ACC000.00000004.00000001.sdmpString found in binary or memory: http://repository.swisssign.com/0
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://rover.ebay.com
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://ru.search.yahoo.com
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://sads.myspace.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search-dyn.tiscali.it/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.about.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.alice.it/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.alice.it/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.aol.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.aol.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.aol.in/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.atlas.cz/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.auction.co.kr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.auone.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.books.com.tw/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.books.com.tw/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.centrum.cz/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.centrum.cz/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.chol.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.chol.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.cn.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.daum.net/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.daum.net/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.dreamwiz.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.dreamwiz.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.fr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.in/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ebay.it/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.empas.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.empas.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.espn.go.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.gamer.com.tw/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.gamer.com.tw/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.gismeteo.ru/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.goo.ne.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.goo.ne.jp/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.hanafos.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.hanafos.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.interpark.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ipop.co.kr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.ipop.co.kr/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.live.com/results.aspx?FORM=IEFM1&amp;q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.live.com/results.aspx?FORM=SO2TDF&amp;q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.live.com/results.aspx?FORM=SOLTDF&amp;q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.live.com/results.aspx?q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.livedoor.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.livedoor.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.lycos.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.lycos.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.lycos.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.msn.co.jp/results.aspx?q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.msn.co.uk/results.aspx?q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.msn.com.cn/results.aspx?q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.msn.com/results.aspx?q=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.nate.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.naver.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.naver.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.nifty.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.orange.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.orange.co.uk/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.rediff.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.rediff.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.seznam.cz/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.seznam.cz/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.sify.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.yahoo.co.jp
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.yahoo.co.jp/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.yahoo.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.yahooapis.jp/AssistSearchService/V2/webassistSearch?output=iejson&amp;p=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search.yam.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search1.taobao.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://search2.estadao.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://searchresults.news.com.au/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://service2.bfast.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://sitesearch.timesonline.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://so-net.search.goo.ne.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://suche.aol.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://suche.freenet.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://suche.freenet.de/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://suche.lycos.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://suche.t-online.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://suche.web.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://suche.web.de/favicon.ico
        Source: java.exe, 00000005.00000002.373821358.0000000016640000.00000002.00000001.sdmpString found in binary or memory: http://treyresearch.net
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: http://trustcenter-crl.certificat2.com/Keynectis/KEYNECTIS_ROOT_CA.crl
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://trustcenter-crl.certificat2.com/Keynectis/KEYNECTIS_ROOT_CA.crl0
        Source: 1.cache[1].js.9.drString found in binary or memory: http://truste.com/go.htm?dcme
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://tw.search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://udn.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://udn.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://uk.ask.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://uk.ask.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://uk.search.yahoo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://vachercher.lycos.fr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://video.globo.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://video.globo.com/favicon.ico
        Source: get[1].js.9.drString found in binary or memory: http://watchdog.truste.com/pvr.php?page=complaint
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://web.ask.com/
        Source: java.exe, 00000005.00000002.373821358.0000000016640000.00000002.00000001.sdmpString found in binary or memory: http://www.%s.com
        Source: get[1].js.9.drString found in binary or memory: http://www.aboutads.info/consumers
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.abril.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.abril.com.br/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.afisha.ru/App_Themes/Default/images/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.alarabiya.net/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.alarabiya.net/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.amazon.co.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.amazon.co.uk/
        Source: msapplication.xml.8.drString found in binary or memory: http://www.amazon.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.amazon.com/exec/obidos/external-search/104-2981279-3455918?index=blended&amp;keyword=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.amazon.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.amazon.com/gp/search?ie=UTF8&amp;tag=ie8search-20&amp;index=blended&amp;linkCode=qs&amp;c
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.amazon.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.aol.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.arrakis.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.arrakis.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.asharqalawsat.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.asharqalawsat.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ask.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.auction.co.kr/auction.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.baidu.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.baidu.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.cdiscount.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.cdiscount.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ceneo.pl/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ceneo.pl/favicon.ico
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://www.certplus.com/CRL/class2.crl
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://www.certplus.com/CRL/class2.crl0
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://www.certplus.com/CRL/class3P.crl
        Source: java.exe, 00000005.00000002.358700508.0000000009ACC000.00000004.00000001.sdmpString found in binary or memory: http://www.certplus.com/CRL/class3P.crl0
        Source: java.exe, 00000005.00000002.358253032.0000000004863000.00000004.00000001.sdmpString found in binary or memory: http://www.chambersign.org
        Source: java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpString found in binary or memory: http://www.chambersign.org#j
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://www.chambersign.org1
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.chennaionline.com/ncommon/images/collogo.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.cjmall.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.cjmall.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.clarin.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.cnet.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.cnet.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.dailymail.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.dailymail.co.uk/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.docUrl.com/bar.htm
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.etmall.com.tw/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.etmall.com.tw/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.excite.co.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.expedia.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.expedia.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.gismeteo.ru/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.gmarket.co.kr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.gmarket.co.kr/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.co.in/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.co.jp/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.co.uk/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.com.sa/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.com.tw/
        Source: msapplication.xml1.8.drString found in binary or memory: http://www.google.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.cz/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.fr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.it/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.pl/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.ru/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.google.si/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.iask.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.iask.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.kkbox.com.tw/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.kkbox.com.tw/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.linternaute.com/favicon.ico
        Source: msapplication.xml2.8.drString found in binary or memory: http://www.live.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.maktoob.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.mercadolibre.com.mx/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.mercadolibre.com.mx/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.mercadolivre.com.br/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.mercadolivre.com.br/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.merlin.com.pl/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.merlin.com.pl/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.microsofttranslator.com/?ref=IE8Activity
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.microsofttranslator.com/BV.aspx?ref=IE8Activity&amp;a=
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.microsofttranslator.com/BVPrev.aspx?ref=IE8Activity
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.microsofttranslator.com/Default.aspx?ref=IE8Activity
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.microsofttranslator.com/DefaultPrev.aspx?ref=IE8Activity
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.mtv.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.mtv.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.myspace.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.najdi.si/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.najdi.si/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.nate.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.neckermann.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.neckermann.de/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.news.com.au/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.nifty.com/favicon.ico
        Source: msapplication.xml3.8.drString found in binary or memory: http://www.nytimes.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ocn.ne.jp/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.orange.fr/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.otto.de/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ozon.ru/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ozon.ru/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ozu.es/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.paginasamarillas.es/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.paginasamarillas.es/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.pchome.com.tw/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.priceminister.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.priceminister.com/favicon.ico
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: http://www.quovadis.bm
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://www.quovadis.bm0
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps0
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.rakuten.co.jp/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.rambler.ru/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.rambler.ru/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.recherche.aol.fr/
        Source: msapplication.xml4.8.drString found in binary or memory: http://www.reddit.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.rtl.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.rtl.de/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.servicios.clarin.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.shopzilla.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.sify.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.so-net.ne.jp/share/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.sogou.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.sogou.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.soso.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.soso.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.t-online.de/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.taobao.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.taobao.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.target.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.target.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.tchibo.de/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.tchibo.de/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.tesco.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.tesco.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.timesonline.co.uk/img/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.tiscali.it/favicon.ico
        Source: msapplication.xml5.8.drString found in binary or memory: http://www.twitter.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.univision.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.univision.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.walmart.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.walmart.com/favicon.ico
        Source: msapplication.xml6.8.drString found in binary or memory: http://www.wikipedia.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.ya.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www.yam.com/favicon.ico
        Source: msapplication.xml7.8.drString found in binary or memory: http://www.youtube.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www3.fnac.com/
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://www3.fnac.com/favicon.ico
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://xml-us.amznxslt.com/onca/xml?Service=AWSECommerceService&amp;Version=2008-06-26&amp;Operation
        Source: java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpString found in binary or memory: http://z.about.com/m/a08.ico
        Source: notice[2].js.9.drString found in binary or memory: https://api-js-log.trustarc.com/error
        Source: 0D070042D9C67A68E1A4BF804E6E0E06.cache[1].htm.9.drString found in binary or memory: https://bugzilla.mozilla.org/show_bug.cgi?id=238559
        Source: ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://consent-pref.trustarc.com/?type=oracle6&site=oracle.com&action=notice&country=ch&locale=en&b
        Source: ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://consent-pref.trustarc.com/cookie_inneriframe.html
        Source: ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://consent-pref.trustarc.com/defaultpreferencemanager/0D070042D9C67A68E1A4BF804E6E0E06.cache.ht
        Source: notice[2].js.9.drString found in binary or memory: https://consent.trustarc.com/
        Source: ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://consent.trustarc.com/get?name=crossdomain.html&domain=oracle.com
        Source: notice[2].js.9.drString found in binary or memory: https://consent.trustarc.com/log
        Source: java.exe, 00000005.00000002.358354828.00000000048CF000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: https://docs.cyberservices.biz/presentation.dll
        Source: require[1].js.9.drString found in binary or memory: https://github.com/requirejs/requirejs/blob/master/LICENSE
        Source: java.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpString found in binary or memory: https://ocsp.quovadisoffshore.com
        Source: java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpString found in binary or memory: https://ocsp.quovadisoffshore.com0
        Source: ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://prefmgr-cookie.truste-svc.net/cookie_js/cookie_iframe.html?parent=https://consent-pref.trust
        Source: en[1].htm.9.dr, ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://s.go-mpulse.net/boomerang/
        Source: en[1].htm.9.dr, ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://s2.go-mpulse.net/boomerang/
        Source: java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpString found in binary or memory: https://sectigo.com/CPS
        Source: 7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358444370.0000000009957000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drString found in binary or memory: https://sectigo.com/CPS0
        Source: en[1].htm.9.drString found in binary or memory: https://static.oracle.com/cdn/cec/v21.2.1.30
        Source: en[1].htm.9.drString found in binary or memory: https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/controller.js
        Source: ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/renderer.js
        Source: ~DF317A7A5B5B92E024.TMP.8.drString found in binary or memory: https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/require.js
        Source: notice[2].js.9.drString found in binary or memory: https://trustarc.mgr.consensu.org/
        Source: template[1].htm.9.drString found in binary or memory: https://www.oracle.com/search/results
        Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
        Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
        Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
        Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
        Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
        Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
        Source: unknownHTTPS traffic detected: 99.86.2.60:443 -> 192.168.2.6:49726 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 99.86.2.60:443 -> 192.168.2.6:49727 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 50.87.249.219:443 -> 192.168.2.6:49721 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 13.32.21.15:443 -> 192.168.2.6:49733 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 13.32.21.15:443 -> 192.168.2.6:49732 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 65.9.66.38:443 -> 192.168.2.6:49734 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 65.9.66.38:443 -> 192.168.2.6:49735 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.6:49737 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.6:49736 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 3.212.50.245:443 -> 192.168.2.6:49739 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 3.212.50.245:443 -> 192.168.2.6:49738 version: TLS 1.2

        Key, Mouse, Clipboard, Microphone and Screen Capturing:

        barindex
        Yara detected UrsnifShow sources
        Source: Yara matchFile source: 0000000A.00000003.535228068.0000000003410000.00000040.00000001.sdmp, type: MEMORY
        Source: Yara matchFile source: 10.2.regsvr32.exe.4cf0000.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 10.3.regsvr32.exe.3418d23.0.raw.unpack, type: UNPACKEDPE

        E-Banking Fraud:

        barindex
        Yara detected UrsnifShow sources
        Source: Yara matchFile source: 0000000A.00000003.535228068.0000000003410000.00000040.00000001.sdmp, type: MEMORY
        Source: Yara matchFile source: 10.2.regsvr32.exe.4cf0000.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 10.3.regsvr32.exe.3418d23.0.raw.unpack, type: UNPACKEDPE
        Source: C:\Windows\SysWOW64\regsvr32.exeProcess Stats: CPU usage > 98%
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF2485 NtQueryVirtualMemory,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF2264
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D00C80
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D05C73
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1246B
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D11C3F
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1DD4C
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1204B
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1784A
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1186B
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D089D3
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D17960
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D07131
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D11398
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CFFB80
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1A357
        Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\broker.dll 59767B2AC03EB8320A661F410D53A025C8975B12DE796E80B1C84306200F6A75
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: String function: 04D082D2 appears 34 times
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: String function: 04D05BF0 appears 60 times
        Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
        Source: classification engineClassification label: mal84.troj.expl.evad.winJAR@16/87@19/7
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\CryptoJump to behavior
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6760:120:WilError_01
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6632:120:WilError_01
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile created: C:\Users\user\AppData\Local\Temp\hsperfdata_userJump to behavior
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeSection loaded: C:\Program Files (x86)\Java\jre1.8.0_211\bin\client\jvm.dll
        Source: C:\Program Files\internet explorer\iexplore.exeFile read: C:\Users\desktop.iniJump to behavior
        Source: C:\Windows\System32\7za.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
        Source: presentation.jarVirustotal: Detection: 19%
        Source: presentation.jarReversingLabs: Detection: 41%
        Source: unknownProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c 7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar'
        Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\7za.exe 7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar'
        Source: unknownProcess created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer >> C:\cmdlinestart.log 2>&1
        Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exe java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M
        Source: C:\Windows\SysWOW64\icacls.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' https://www.java.com/
        Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6828 CREDAT:17410 /prefetch:2
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32.exe /s C:\Users\user\AppData\Local\broker.dll
        Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\7za.exe 7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar'
        Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exe java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' https://www.java.com/
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32.exe /s C:\Users\user\AppData\Local\broker.dll
        Source: C:\Program Files\internet explorer\iexplore.exeProcess created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6828 CREDAT:17410 /prefetch:2
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{95E15D0A-66E6-93D9-C53C-76E6219D3341}\InProcServer32
        Source: Window RecorderWindow detected: More than 3 window changes detected
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll
        Source: Binary string: c:\119\Minute\Force_Lead\Apple\oil.pdb source: regsvr32.exe, 0000000A.00000002.601653478.0000000004D24000.00000002.00020000.sdmp, broker.dll.5.dr
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF1F31 LoadLibraryA,GetProcAddress,
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32.exe /s C:\Users\user\AppData\Local\broker.dll
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeCode function: 5_3_1597C292 pushad ; ret
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeCode function: 5_3_1598618D push ebx; ret
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeCode function: 5_3_1597CF00 push eax; iretd
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF2253 push ecx; ret
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF2200 push ecx; ret
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D05C35 push ecx; ret
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1B8E7 push esi; ret
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1BA1D push esi; ret
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D0439D push ecx; ret

        Persistence and Installation Behavior:

        barindex
        Exploit detected, runtime environment dropped PE fileShow sources
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile created: broker.dll.5.drJump to dropped file
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile created: C:\Users\user\AppData\Local\broker.dllJump to dropped file

        Hooking and other Techniques for Hiding and Protection:

        barindex
        Yara detected UrsnifShow sources
        Source: Yara matchFile source: 0000000A.00000003.535228068.0000000003410000.00000040.00000001.sdmp, type: MEMORY
        Source: Yara matchFile source: 10.2.regsvr32.exe.4cf0000.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 10.3.regsvr32.exe.3418d23.0.raw.unpack, type: UNPACKEDPE
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M
        Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX

        Malware Analysis System Evasion:

        barindex
        Found stalling execution ending in API Sleep callShow sources
        Source: C:\Windows\SysWOW64\regsvr32.exeStalling execution: Execution stalls by calling Sleep
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeFile opened / queried: SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\broker.dllJump to dropped file
        Source: C:\Windows\SysWOW64\regsvr32.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
        Source: C:\Windows\System32\conhost.exe TID: 6672Thread sleep count: 37 > 30
        Source: C:\Windows\SysWOW64\regsvr32.exe TID: 7156Thread sleep count: 179 > 30
        Source: C:\Windows\SysWOW64\regsvr32.exe TID: 5816Thread sleep count: 67 > 30
        Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
        Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
        Source: java.exe, 00000005.00000002.369951501.0000000014FF0000.00000002.00000001.sdmpBinary or memory string: A Virtual Machine could not be started because Hyper-V is not installed.
        Source: java.exe, 00000005.00000002.360823874.00000000144F0000.00000002.00000001.sdmpBinary or memory string: ,java/lang/VirtualMachineError
        Source: java.exe, 00000005.00000002.369951501.0000000014FF0000.00000002.00000001.sdmpBinary or memory string: A communication protocol error has occurred between the Hyper-V Host and Guest Compute Service.
        Source: java.exe, 00000005.00000002.369951501.0000000014FF0000.00000002.00000001.sdmpBinary or memory string: The communication protocol version between the Hyper-V Host and Guest Compute Services is not supported.
        Source: java.exe, 00000005.00000002.356743211.00000000021E0000.00000004.00000001.sdmpBinary or memory string: 2[Ljava/lang/VirtualMachineError;
        Source: java.exe, 00000005.00000002.369951501.0000000014FF0000.00000002.00000001.sdmpBinary or memory string: An unknown internal message was received by the Hyper-V Compute Service.
        Source: C:\Windows\SysWOW64\regsvr32.exeAPI call chain: ExitProcess graph end node
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D039FC IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF1F31 LoadLibraryA,GetProcAddress,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D62668 mov eax, dword ptr fs:[00000030h]
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D6259E mov eax, dword ptr fs:[00000030h]
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D621A5 push dword ptr fs:[00000030h]
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D0CC83 __decode_pointer,SetUnhandledExceptionFilter,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D0CC61 SetUnhandledExceptionFilter,__encode_pointer,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D05618 __NMSG_WRITE,_raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D039FC IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D05973 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeMemory protected: page read and write | page guard
        Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\7za.exe 7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar'
        Source: C:\Windows\System32\cmd.exeProcess created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exe java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\icacls.exe C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' https://www.java.com/
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe regsvr32.exe /s C:\Users\user\AppData\Local\broker.dll
        Source: regsvr32.exe, 0000000A.00000002.601321595.00000000038E0000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
        Source: regsvr32.exe, 0000000A.00000002.601321595.00000000038E0000.00000002.00000001.sdmpBinary or memory string: Progman
        Source: regsvr32.exe, 0000000A.00000002.601321595.00000000038E0000.00000002.00000001.sdmpBinary or memory string: &Program Manager
        Source: regsvr32.exe, 0000000A.00000002.601321595.00000000038E0000.00000002.00000001.sdmpBinary or memory string: Progmanlock
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D20ADD cpuid
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: GetLocaleInfoA,GetSystemDefaultUILanguage,VerLanguageNameA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: ___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: _TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,_ProcessCodePage,IsValidCodePage,IsValidLocale,_strcpy_s,__invoke_watson,__itoa_s,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: _strlen,_GetPrimaryLen,EnumSystemLocalesA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: GetLocaleInfoA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,__calloc_crt,___crtGetLocaleInfoA,__calloc_crt,__invoke_watson,___crtGetLocaleInfoA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: _LcidFromHexString,GetLocaleInfoA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: _LocaleUpdate::_LocaleUpdate,__crtGetLocaleInfoW_stat,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: GetLocaleInfoA,_LcidFromHexString,_GetPrimaryLen,_strlen,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: ___getlocaleinfo,__malloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,__calloc_crt,GetCPInfo,___crtGetStringTypeA,___crtLCMapStringA,___crtLCMapStringA,InterlockedDecrement,InterlockedDecrement,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: _LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: GetLocaleInfoA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: EnumSystemLocalesA,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: __calloc_crt,__malloc_crt,__malloc_crt,___getlocaleinfo,___getlocaleinfo,___getlocaleinfo,___free_lconv_num,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF17A7 SetThreadPriority,GetSystemTime,SwitchToThread,Sleep,GetLongPathNameW,GetLongPathNameW,GetLongPathNameW,WaitForSingleObject,GetExitCodeThread,CloseHandle,GetLastError,GetLastError,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04D1CD0B __lock,__invoke_watson,__invoke_watson,__invoke_watson,_strlen,__malloc_crt,_strlen,_strcpy_s,__invoke_watson,GetTimeZoneInformation,__invoke_watson,__invoke_watson,
        Source: C:\Windows\SysWOW64\regsvr32.exeCode function: 10_2_04CF146C CreateEventA,GetVersion,GetCurrentProcessId,OpenProcess,GetLastError,
        Source: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

        Stealing of Sensitive Information:

        barindex
        Yara detected UrsnifShow sources
        Source: Yara matchFile source: 0000000A.00000003.535228068.0000000003410000.00000040.00000001.sdmp, type: MEMORY
        Source: Yara matchFile source: 10.2.regsvr32.exe.4cf0000.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 10.3.regsvr32.exe.3418d23.0.raw.unpack, type: UNPACKEDPE

        Remote Access Functionality:

        barindex
        Yara detected UrsnifShow sources
        Source: Yara matchFile source: 0000000A.00000003.535228068.0000000003410000.00000040.00000001.sdmp, type: MEMORY
        Source: Yara matchFile source: 10.2.regsvr32.exe.4cf0000.1.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: 10.3.regsvr32.exe.3418d23.0.raw.unpack, type: UNPACKEDPE

        Mitre Att&ck Matrix

        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid AccountsNative API2Services File Permissions Weakness1Process Injection12Masquerading1OS Credential DumpingSystem Time Discovery2Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel12Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsExploitation for Client Execution2DLL Side-Loading1Services File Permissions Weakness1Virtualization/Sandbox Evasion2LSASS MemorySecurity Software Discovery121Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)DLL Side-Loading1Disable or Modify Tools1Security Account ManagerVirtualization/Sandbox Evasion2SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Process Injection12NTDSProcess Discovery1Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
        Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptDeobfuscate/Decode Files or Information1LSA SecretsRemote System Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
        Replication Through Removable MediaLaunchdRc.commonRc.commonObfuscated Files or Information2Cached Domain CredentialsFile and Directory Discovery1VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
        External Remote ServicesScheduled TaskStartup ItemsStartup ItemsRegsvr321DCSyncSystem Information Discovery24Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
        Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobServices File Permissions Weakness1Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
        Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)DLL Side-Loading1/etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction

        Behavior Graph

        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet
        behaviorgraph top1 signatures2 2 Behavior Graph ID: 406076 Sample: presentation.jar Startdate: 06/05/2021 Architecture: WINDOWS Score: 84 47 Found malware configuration 2->47 49 Multi AV Scanner detection for dropped file 2->49 51 Multi AV Scanner detection for submitted file 2->51 53 3 other signatures 2->53 8 cmd.exe 2 2->8         started        10 cmd.exe 1 2->10         started        process3 process4 12 java.exe 2 35 8->12         started        16 conhost.exe 8->16         started        18 7za.exe 7 10->18         started        dnsIp5 37 docs.cyberservices.biz 50.87.249.219, 443, 49721 UNIFIEDLAYER-AS-1US United States 12->37 39 192.168.2.1 unknown unknown 12->39 33 C:\Users\user\AppData\Local\broker.dll, PE32 12->33 dropped 20 regsvr32.exe 12->20         started        23 iexplore.exe 2 77 12->23         started        26 icacls.exe 1 12->26         started        file6 process7 dnsIp8 55 Found stalling execution ending in API Sleep call 20->55 35 www.java.com 23->35 28 iexplore.exe 8 102 23->28         started        31 conhost.exe 26->31         started        signatures9 process10 dnsIp11 41 consent-pref.trustarc.com 13.32.21.15, 443, 49732, 49733 ATT-INTERNET4US United States 28->41 43 prefmgr-cookie.truste-svc.net 3.212.50.245, 443, 49738, 49739 AMAZON-AESUS United States 28->43 45 18 other IPs or domains 28->45

        Screenshots

        Thumbnails

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.

        windows-stand

        Antivirus, Machine Learning and Genetic Malware Detection

        Initial Sample

        SourceDetectionScannerLabelLink
        presentation.jar20%VirustotalBrowse
        presentation.jar9%MetadefenderBrowse
        presentation.jar41%ReversingLabsByteCode-JAVA.Trojan.Tnega

        Dropped Files

        SourceDetectionScannerLabelLink
        C:\Users\user\AppData\Local\broker.dll9%MetadefenderBrowse
        C:\Users\user\AppData\Local\broker.dll28%ReversingLabsWin32.Trojan.Johnnie

        Unpacked PE Files

        No Antivirus matches

        Domains

        SourceDetectionScannerLabelLink
        docs.cyberservices.biz0%VirustotalBrowse
        s.go-mpulse.net0%VirustotalBrowse
        c.oracleinfinity.io0%VirustotalBrowse
        6852bd12.akstat.io0%VirustotalBrowse

        URLs

        SourceDetectionScannerLabelLink
        http://www.mercadolivre.com.br/0%URL Reputationsafe
        http://www.mercadolivre.com.br/0%URL Reputationsafe
        http://www.mercadolivre.com.br/0%URL Reputationsafe
        http://www.merlin.com.pl/favicon.ico0%URL Reputationsafe
        http://www.merlin.com.pl/favicon.ico0%URL Reputationsafe
        http://www.merlin.com.pl/favicon.ico0%URL Reputationsafe
        http://www.dailymail.co.uk/0%URL Reputationsafe
        http://www.dailymail.co.uk/0%URL Reputationsafe
        http://www.dailymail.co.uk/0%URL Reputationsafe
        https://s2.go-mpulse.net/boomerang/0%URL Reputationsafe
        https://s2.go-mpulse.net/boomerang/0%URL Reputationsafe
        https://s2.go-mpulse.net/boomerang/0%URL Reputationsafe
        http://www.chambersign.org10%URL Reputationsafe
        http://www.chambersign.org10%URL Reputationsafe
        http://www.chambersign.org10%URL Reputationsafe
        HTTP://WWW.CHAMBERSIGN.ORG0%Avira URL Cloudsafe
        http://image.excite.co.jp/jp/favicon/lep.ico0%URL Reputationsafe
        http://image.excite.co.jp/jp/favicon/lep.ico0%URL Reputationsafe
        http://image.excite.co.jp/jp/favicon/lep.ico0%URL Reputationsafe
        http://%s.com0%URL Reputationsafe
        http://%s.com0%URL Reputationsafe
        http://%s.com0%URL Reputationsafe
        http://busca.igbusca.com.br//app/static/images/favicon.ico0%URL Reputationsafe
        http://busca.igbusca.com.br//app/static/images/favicon.ico0%URL Reputationsafe
        http://busca.igbusca.com.br//app/static/images/favicon.ico0%URL Reputationsafe
        http://policy.camerfirma.com00%URL Reputationsafe
        http://policy.camerfirma.com00%URL Reputationsafe
        http://policy.camerfirma.com00%URL Reputationsafe
        http://www.etmall.com.tw/favicon.ico0%URL Reputationsafe
        http://www.etmall.com.tw/favicon.ico0%URL Reputationsafe
        http://www.etmall.com.tw/favicon.ico0%URL Reputationsafe
        http://it.search.dada.net/favicon.ico0%URL Reputationsafe
        http://it.search.dada.net/favicon.ico0%URL Reputationsafe
        http://it.search.dada.net/favicon.ico0%URL Reputationsafe
        http://cps.letsencrypt.org00%URL Reputationsafe
        http://cps.letsencrypt.org00%URL Reputationsafe
        http://cps.letsencrypt.org00%URL Reputationsafe
        http://search.hanafos.com/favicon.ico0%URL Reputationsafe
        http://search.hanafos.com/favicon.ico0%URL Reputationsafe
        http://search.hanafos.com/favicon.ico0%URL Reputationsafe
        http://cgi.search.biglobe.ne.jp/favicon.ico0%Avira URL Cloudsafe
        http://www.certplus.com/CRL/class2.crl0%URL Reputationsafe
        http://www.certplus.com/CRL/class2.crl0%URL Reputationsafe
        http://www.certplus.com/CRL/class2.crl0%URL Reputationsafe
        http://bugreport.sun.com/bugreport/0%Avira URL Cloudsafe
        http://www.abril.com.br/favicon.ico0%URL Reputationsafe
        http://www.abril.com.br/favicon.ico0%URL Reputationsafe
        http://www.abril.com.br/favicon.ico0%URL Reputationsafe
        http://search.msn.co.jp/results.aspx?q=0%URL Reputationsafe
        http://search.msn.co.jp/results.aspx?q=0%URL Reputationsafe
        http://search.msn.co.jp/results.aspx?q=0%URL Reputationsafe
        http://buscar.ozu.es/0%Avira URL Cloudsafe
        http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s0%URL Reputationsafe
        http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s0%URL Reputationsafe
        http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s0%URL Reputationsafe
        http://ocsp.sectigo.com0%URL Reputationsafe
        http://ocsp.sectigo.com0%URL Reputationsafe
        http://ocsp.sectigo.com0%URL Reputationsafe
        http://busca.igbusca.com.br/0%URL Reputationsafe
        http://busca.igbusca.com.br/0%URL Reputationsafe
        http://busca.igbusca.com.br/0%URL Reputationsafe
        http://cps.chambersign.org/cps/chambersroot.html0%URL Reputationsafe
        http://cps.chambersign.org/cps/chambersroot.html0%URL Reputationsafe
        http://cps.chambersign.org/cps/chambersroot.html0%URL Reputationsafe
        http://www.certplus.com/CRL/class3P.crl0%URL Reputationsafe
        http://www.certplus.com/CRL/class3P.crl0%URL Reputationsafe
        http://www.certplus.com/CRL/class3P.crl0%URL Reputationsafe
        http://search.auction.co.kr/0%URL Reputationsafe
        http://search.auction.co.kr/0%URL Reputationsafe
        http://search.auction.co.kr/0%URL Reputationsafe
        http://crl.securetrust.com/STCA.crl0%URL Reputationsafe
        http://crl.securetrust.com/STCA.crl0%URL Reputationsafe
        http://crl.securetrust.com/STCA.crl0%URL Reputationsafe
        http://busca.buscape.com.br/favicon.ico0%URL Reputationsafe
        http://busca.buscape.com.br/favicon.ico0%URL Reputationsafe
        http://busca.buscape.com.br/favicon.ico0%URL Reputationsafe
        http://cps.letsencrypt.orgc0%Avira URL Cloudsafe
        http://www.pchome.com.tw/favicon.ico0%URL Reputationsafe
        http://www.pchome.com.tw/favicon.ico0%URL Reputationsafe
        http://www.pchome.com.tw/favicon.ico0%URL Reputationsafe
        http://browse.guardian.co.uk/favicon.ico0%URL Reputationsafe
        http://browse.guardian.co.uk/favicon.ico0%URL Reputationsafe
        http://browse.guardian.co.uk/favicon.ico0%URL Reputationsafe
        http://google.pchome.com.tw/0%URL Reputationsafe
        http://google.pchome.com.tw/0%URL Reputationsafe
        http://google.pchome.com.tw/0%URL Reputationsafe
        http://r3.o.lencr.org0%Avira URL Cloudsafe
        http://www.ozu.es/favicon.ico0%Avira URL Cloudsafe
        http://search.yahoo.co.jp/favicon.ico0%URL Reputationsafe
        http://search.yahoo.co.jp/favicon.ico0%URL Reputationsafe
        http://search.yahoo.co.jp/favicon.ico0%URL Reputationsafe
        http://www.gmarket.co.kr/0%URL Reputationsafe
        http://www.gmarket.co.kr/0%URL Reputationsafe
        http://www.gmarket.co.kr/0%URL Reputationsafe
        http://ocsp.sectigo.com00%URL Reputationsafe
        http://ocsp.sectigo.com00%URL Reputationsafe
        http://ocsp.sectigo.com00%URL Reputationsafe
        http://searchresults.news.com.au/0%URL Reputationsafe
        http://searchresults.news.com.au/0%URL Reputationsafe
        http://searchresults.news.com.au/0%URL Reputationsafe

        Domains and IPs

        Contacted Domains

        NameIPActiveMaliciousAntivirus DetectionReputation
        consent-pref.trustarc.com
        13.32.21.15
        truefalse
          high
          consent-st.trustarc.com
          65.9.66.38
          truefalse
            high
            oracle.112.2o7.net
            35.181.18.61
            truefalse
              high
              docs.cyberservices.biz
              50.87.249.219
              truefalseunknown
              prefmgr-cookie.truste-svc.net
              3.212.50.245
              truefalse
                high
                consent.trustarc.com
                99.86.2.60
                truefalse
                  high
                  static.oracle.com
                  unknown
                  unknownfalse
                    high
                    www.oracle.com
                    unknown
                    unknownfalse
                      high
                      s.go-mpulse.net
                      unknown
                      unknownfalseunknown
                      trial-eum-clienttons-s.akamaihd.net
                      unknown
                      unknownfalse
                        high
                        c.oracleinfinity.io
                        unknown
                        unknownfalseunknown
                        6852bd12.akstat.io
                        unknown
                        unknownfalseunknown
                        trial-eum-clientnsv4-s.akamaihd.net
                        unknown
                        unknownfalse
                          high
                          www.java.com
                          unknown
                          unknownfalse
                            high
                            84-17-52-78_s-23-32-238-131_ts-1620317361-clienttons-s.akamaihd.net
                            unknown
                            unknownfalse
                              high
                              kqitits7mulnqyeucsyq-pe4433-4b66e3cf2-clientnsv4-s.akamaihd.net
                              unknown
                              unknownfalse
                                high
                                c.go-mpulse.net
                                unknown
                                unknownfalse
                                  unknown
                                  dc.oracleinfinity.io
                                  unknown
                                  unknownfalse
                                    unknown

                                    URLs from Memory and Binaries

                                    NameSourceMaliciousAntivirus DetectionReputation
                                    http://search.chol.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                      high
                                      http://www.mercadolivre.com.br/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                      • URL Reputation: safe
                                      • URL Reputation: safe
                                      • URL Reputation: safe
                                      unknown
                                      http://www.merlin.com.pl/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                      • URL Reputation: safe
                                      • URL Reputation: safe
                                      • URL Reputation: safe
                                      unknown
                                      http://search.ebay.de/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                        high
                                        http://www.mtv.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                          high
                                          http://www.rambler.ru/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                            high
                                            http://www.nifty.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                              high
                                              http://www.dailymail.co.uk/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              • URL Reputation: safe
                                              unknown
                                              http://www3.fnac.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                high
                                                https://s2.go-mpulse.net/boomerang/en[1].htm.9.dr, ~DF317A7A5B5B92E024.TMP.8.drfalse
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                • URL Reputation: safe
                                                unknown
                                                http://buscar.ya.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                  high
                                                  http://search.yahoo.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                    high
                                                    http://www.chambersign.org1java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpfalse
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    • URL Reputation: safe
                                                    unknown
                                                    http://repository.swisssign.com/0java.exe, 00000005.00000002.358700508.0000000009ACC000.00000004.00000001.sdmpfalse
                                                      high
                                                      http://www.sogou.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                        high
                                                        HTTP://WWW.CHAMBERSIGN.ORGjava.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://asp.usatoday.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                          high
                                                          http://consent.trustarc.com/bannermsg?notice[2].js.9.drfalse
                                                            high
                                                            http://fr.search.yahoo.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                              high
                                                              http://rover.ebay.comjava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                high
                                                                http://www.aboutads.info/consumersget[1].js.9.drfalse
                                                                  high
                                                                  http://in.search.yahoo.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                    high
                                                                    http://img.shopzilla.com/shopzilla/shopzilla.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                      high
                                                                      http://search.ebay.in/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                        high
                                                                        http://image.excite.co.jp/jp/favicon/lep.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        unknown
                                                                        http://%s.comjava.exe, 00000005.00000002.373821358.0000000016640000.00000002.00000001.sdmpfalse
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        • URL Reputation: safe
                                                                        low
                                                                        http://msk.afisha.ru/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                          high
                                                                          https://prefmgr-cookie.truste-svc.net/cookie_js/cookie_iframe.html?parent=https://consent-pref.trust~DF317A7A5B5B92E024.TMP.8.drfalse
                                                                            high
                                                                            http://www.reddit.com/msapplication.xml4.8.drfalse
                                                                              high
                                                                              http://busca.igbusca.com.br//app/static/images/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              http://watchdog.truste.com/pvr.php?page=complaintget[1].js.9.drfalse
                                                                                high
                                                                                http://policy.camerfirma.com0java.exe, 00000005.00000002.358700508.0000000009ACC000.00000004.00000001.sdmpfalse
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                • URL Reputation: safe
                                                                                unknown
                                                                                http://search.rediff.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                  high
                                                                                  https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/renderer.js~DF317A7A5B5B92E024.TMP.8.drfalse
                                                                                    high
                                                                                    http://www.ya.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                      high
                                                                                      http://bugs.webkit.org/show_bug.cgi?id=38100D070042D9C67A68E1A4BF804E6E0E06.cache[1].htm.9.drfalse
                                                                                        high
                                                                                        http://www.etmall.com.tw/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        unknown
                                                                                        http://it.search.dada.net/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        • URL Reputation: safe
                                                                                        unknown
                                                                                        http://search.naver.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                          high
                                                                                          http://www.google.ru/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                            high
                                                                                            http://cps.letsencrypt.org0java.exe, 00000005.00000002.358264330.0000000004873000.00000004.00000001.sdmpfalse
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            unknown
                                                                                            http://search.hanafos.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            unknown
                                                                                            http://cgi.search.biglobe.ne.jp/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            http://www.certplus.com/CRL/class2.crljava.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpfalse
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            unknown
                                                                                            http://bugreport.sun.com/bugreport/java.exe, 00000005.00000002.358510729.00000000099A1000.00000004.00000001.sdmpfalse
                                                                                            • Avira URL Cloud: safe
                                                                                            unknown
                                                                                            http://www.abril.com.br/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            • URL Reputation: safe
                                                                                            unknown
                                                                                            http://search.daum.net/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                              high
                                                                                              http://java.oracle.com/java.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpfalse
                                                                                                high
                                                                                                http://search.naver.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                  high
                                                                                                  http://search.msn.co.jp/results.aspx?q=java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                  • URL Reputation: safe
                                                                                                  • URL Reputation: safe
                                                                                                  • URL Reputation: safe
                                                                                                  unknown
                                                                                                  http://www.clarin.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                    high
                                                                                                    http://buscar.ozu.es/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    unknown
                                                                                                    http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s7za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358444370.0000000009957000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drfalse
                                                                                                    • URL Reputation: safe
                                                                                                    • URL Reputation: safe
                                                                                                    • URL Reputation: safe
                                                                                                    unknown
                                                                                                    http://kr.search.yahoo.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                      high
                                                                                                      http://search.about.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                        high
                                                                                                        http://ocsp.sectigo.comjava.exe, 00000005.00000002.358523949.00000000099A7000.00000004.00000001.sdmpfalse
                                                                                                        • URL Reputation: safe
                                                                                                        • URL Reputation: safe
                                                                                                        • URL Reputation: safe
                                                                                                        unknown
                                                                                                        http://busca.igbusca.com.br/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                        • URL Reputation: safe
                                                                                                        • URL Reputation: safe
                                                                                                        • URL Reputation: safe
                                                                                                        unknown
                                                                                                        http://www.microsofttranslator.com/BVPrev.aspx?ref=IE8Activityjava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                          high
                                                                                                          http://www.ask.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                            high
                                                                                                            http://www.priceminister.com/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                              high
                                                                                                              http://cps.chambersign.org/cps/chambersroot.htmljava.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpfalse
                                                                                                              • URL Reputation: safe
                                                                                                              • URL Reputation: safe
                                                                                                              • URL Reputation: safe
                                                                                                              unknown
                                                                                                              http://www.cjmall.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                high
                                                                                                                http://search.centrum.cz/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                  high
                                                                                                                  http://www.certplus.com/CRL/class3P.crljava.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358789480.0000000009B25000.00000004.00000001.sdmpfalse
                                                                                                                  • URL Reputation: safe
                                                                                                                  • URL Reputation: safe
                                                                                                                  • URL Reputation: safe
                                                                                                                  unknown
                                                                                                                  http://suche.t-online.de/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                    high
                                                                                                                    http://www.google.it/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                      high
                                                                                                                      http://search.auction.co.kr/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                      • URL Reputation: safe
                                                                                                                      • URL Reputation: safe
                                                                                                                      • URL Reputation: safe
                                                                                                                      unknown
                                                                                                                      http://www.ceneo.pl/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                        high
                                                                                                                        http://www.amazon.de/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                          high
                                                                                                                          http://crl.securetrust.com/STCA.crljava.exe, 00000005.00000002.358573143.00000000099F2000.00000004.00000001.sdmpfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          http://sads.myspace.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                            high
                                                                                                                            https://consent.trustarc.com/get?name=crossdomain.html&domain=oracle.com~DF317A7A5B5B92E024.TMP.8.drfalse
                                                                                                                              high
                                                                                                                              http://busca.buscape.com.br/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              http://cps.letsencrypt.orgcjava.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpfalse
                                                                                                                              • Avira URL Cloud: safe
                                                                                                                              unknown
                                                                                                                              http://www.pchome.com.tw/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              http://browse.guardian.co.uk/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              http://google.pchome.com.tw/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              http://list.taobao.com/browse/search_visual.htm?n=15&amp;q=java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                high
                                                                                                                                http://www.rambler.ru/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://consent.trustarc.com/lognotice[2].js.9.drfalse
                                                                                                                                    high
                                                                                                                                    http://uk.search.yahoo.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                      high
                                                                                                                                      http://espanol.search.yahoo.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                        high
                                                                                                                                        http://r3.o.lencr.orgjava.exe, 00000005.00000002.358273563.000000000487B000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358127351.000000000476D000.00000004.00000001.sdmpfalse
                                                                                                                                        • Avira URL Cloud: safe
                                                                                                                                        unknown
                                                                                                                                        http://www.ozu.es/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                        • Avira URL Cloud: safe
                                                                                                                                        unknown
                                                                                                                                        http://search.sify.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                          high
                                                                                                                                          http://openimage.interpark.com/interpark.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                            high
                                                                                                                                            http://search.yahoo.co.jp/favicon.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            • URL Reputation: safe
                                                                                                                                            unknown
                                                                                                                                            http://search.ebay.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                              high
                                                                                                                                              http://www.gmarket.co.kr/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              http://ocsp.sectigo.com07za.exe, 00000002.00000003.332933197.00000000026D0000.00000004.00000001.sdmp, java.exe, 00000005.00000002.358444370.0000000009957000.00000004.00000001.sdmp, SECURE_VIEWER.RSA.2.drfalse
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              • URL Reputation: safe
                                                                                                                                              unknown
                                                                                                                                              http://search.nifty.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                high
                                                                                                                                                http://searchresults.news.com.au/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                • URL Reputation: safe
                                                                                                                                                unknown
                                                                                                                                                http://www.google.si/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                  high
                                                                                                                                                  http://www.google.cz/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                    high
                                                                                                                                                    http://www.soso.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                      high
                                                                                                                                                      http://www.univision.com/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                        high
                                                                                                                                                        http://search.ebay.it/java.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                          high
                                                                                                                                                          http://www.amazon.com/msapplication.xml.8.drfalse
                                                                                                                                                            high
                                                                                                                                                            http://images.joins.com/ui_c/fvc_joins.icojava.exe, 00000005.00000002.374547560.0000000016733000.00000002.00000001.sdmpfalse
                                                                                                                                                              high
                                                                                                                                                              https://github.com/requirejs/requirejs/blob/master/LICENSErequire[1].js.9.drfalse
                                                                                                                                                                high

                                                                                                                                                                Contacted IPs

                                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                                • 75% < No. of IPs

                                                                                                                                                                Public

                                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                3.212.50.245
                                                                                                                                                                prefmgr-cookie.truste-svc.netUnited States
                                                                                                                                                                14618AMAZON-AESUSfalse
                                                                                                                                                                50.87.249.219
                                                                                                                                                                docs.cyberservices.bizUnited States
                                                                                                                                                                46606UNIFIEDLAYER-AS-1USfalse
                                                                                                                                                                13.32.21.15
                                                                                                                                                                consent-pref.trustarc.comUnited States
                                                                                                                                                                7018ATT-INTERNET4USfalse
                                                                                                                                                                35.181.18.61
                                                                                                                                                                oracle.112.2o7.netUnited States
                                                                                                                                                                16509AMAZON-02USfalse
                                                                                                                                                                99.86.2.60
                                                                                                                                                                consent.trustarc.comUnited States
                                                                                                                                                                16509AMAZON-02USfalse
                                                                                                                                                                65.9.66.38
                                                                                                                                                                consent-st.trustarc.comUnited States
                                                                                                                                                                16509AMAZON-02USfalse

                                                                                                                                                                Private

                                                                                                                                                                IP
                                                                                                                                                                192.168.2.1

                                                                                                                                                                General Information

                                                                                                                                                                Joe Sandbox Version:32.0.0 Black Diamond
                                                                                                                                                                Analysis ID:406076
                                                                                                                                                                Start date:06.05.2021
                                                                                                                                                                Start time:18:08:18
                                                                                                                                                                Joe Sandbox Product:CloudBasic
                                                                                                                                                                Overall analysis duration:0h 9m 16s
                                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                                Report type:light
                                                                                                                                                                Sample file name:presentation.jar
                                                                                                                                                                Cookbook file name:defaultwindowsfilecookbook.jbs
                                                                                                                                                                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                                                                                                                Run name:Without Tracing
                                                                                                                                                                Number of analysed new started processes analysed:28
                                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                                Technologies:
                                                                                                                                                                • HCA enabled
                                                                                                                                                                • EGA enabled
                                                                                                                                                                • HDC enabled
                                                                                                                                                                • AMSI enabled
                                                                                                                                                                Analysis Mode:default
                                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                                Detection:MAL
                                                                                                                                                                Classification:mal84.troj.expl.evad.winJAR@16/87@19/7
                                                                                                                                                                EGA Information:
                                                                                                                                                                • Successful, ratio: 50%
                                                                                                                                                                HDC Information:
                                                                                                                                                                • Successful, ratio: 4.5% (good quality ratio 4.3%)
                                                                                                                                                                • Quality average: 79.2%
                                                                                                                                                                • Quality standard deviation: 29.1%
                                                                                                                                                                HCA Information:Failed
                                                                                                                                                                Cookbook Comments:
                                                                                                                                                                • Adjust boot time
                                                                                                                                                                • Enable AMSI
                                                                                                                                                                • Found application associated with file extension: .jar
                                                                                                                                                                Warnings:
                                                                                                                                                                Show All
                                                                                                                                                                • Excluded IPs from analysis (whitelisted): 40.88.32.150, 92.122.145.220, 104.42.151.234, 88.221.62.148, 104.83.83.17, 104.83.125.175, 92.122.246.223, 92.122.144.36, 88.221.62.65, 104.83.83.83, 130.61.67.95, 13.64.90.137, 95.101.22.216, 95.101.22.194, 23.32.238.131, 23.32.238.155, 20.50.102.62, 152.199.19.161, 2.20.142.210, 2.20.142.209, 92.122.213.194, 92.122.213.247, 52.155.217.156, 20.54.26.129, 23.57.80.111, 20.82.210.154
                                                                                                                                                                • TCP Packets have been reduced to 100
                                                                                                                                                                • Excluded domains from analysis (whitelisted): a1024.dscg.akamai.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, e11290.dspg.akamaiedge.net, skypedataprdcoleus15.cloudapp.net, a248.b.akamai.net, audownload.windowsupdate.nsatc.net, watson.telemetry.microsoft.com, ds-www.java.com.edgekey.net, au-bg-shim.trafficmanager.net, ip46.go-mpulse.net.edgekey.net, fs.microsoft.com, e11123.g.akamaiedge.net, e2581.dscx.akamaiedge.net, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, ris-prod.trafficmanager.net, wildcard46.akstat.io.edgekey.net, ris.api.iris.microsoft.com, ds-oracle-microsites.edgekey.net, store-images.s-microsoft.com, wildcard46.go-mpulse.net.edgekey.net, blobcollector.events.data.trafficmanager.net, dc.oracleinfinity.io.akadns.net, c.oracleinfinity.io.edgekey.net, cs9.wpc.v0cdn.net, au.download.windowsupdate.com.edgesuite.net, store-images.s-microsoft.com-c.edgekey.net, a1449.dscg2.akamai.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, arc.msn.com, consumerrp-displaycatalog-aks2eap-europe.md.mp.microsoft.com.akadns.net, iecvlist.microsoft.com, db5eap.displaycatalog.md.mp.microsoft.com.akadns.net, e12564.dspb.akamaiedge.net, go.microsoft.com, arc.trafficmanager.net, e406.dscx.akamaiedge.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, e4518.dscx.akamaiedge.net, displaycatalog-europeeap.md.mp.microsoft.com.akadns.net, skypedataprdcolwus17.cloudapp.net, ie9comview.vo.msecnd.net, e870.dscx.akamaiedge.net, ctldl.windowsupdate.com, e1723.g.akamaiedge.net, a767.dscg3.akamai.net, ds-www.oracle.com.edgekey.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, e4518.dscapi7.akamaiedge.net, go.microsoft.com.edgekey.net, skypedataprdcolwus16.cloudapp.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                                                                                                                                                                • Execution Graph export aborted for target java.exe, PID 6684 because there are no executed function
                                                                                                                                                                • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                                                                                                                                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                                                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.

                                                                                                                                                                Simulations

                                                                                                                                                                Behavior and APIs

                                                                                                                                                                No simulations

                                                                                                                                                                Joe Sandbox View / Context

                                                                                                                                                                IPs

                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                35.181.18.61http://23.129.64.206Get hashmaliciousBrowse
                                                                                                                                                                • metrics.washingtonpost.com/b/ss/wpniwashpostcom/1/H.10-Pdvu-2/s35121958062326?[AQB]&ndh=1&t=2/11/2020%2021%3A42%3A33%203%20480&ns=wpni&pageName=wp%20-%20blog%20-%20/securityfix/2008/08/web_fraud_20_distributing_your.html&g=http%3A//voices.washingtonpost.com/securityfix/2008/08/web_fraud_20_distributing_your.html&cc=USD&ch=wp%20-%20technology&server=washingtonpost.com&events=event1&v1=wp%20-%20blog%20-%20/securityfix/2008/08/web_fraud_20_distributing_your.html&h1=technology%7Cblogs%7Csecurityfix&c2=wp%20-%20technology&v2=wp%20-%20technology&h2=washingtonpost.com%7Ctechnology%7Cblogs%7Csecurityfix&c3=blog&c4=washingtonpost.com&c5=brian%20krebs&v6=wp%20-%20blog%20-%20/securityfix/2008/08/web_fraud_20_tools.html&c8=Thursday&c9=12%3A30AM&c10=Weekday&v11=securityfix&v14=New&v15=First%20page%20view%20or%20cookies%20not%20supported&v16=1&c17=First%20page%20view%20or%20cookies%20not%20supported&c18=New&c23=technology%7Cblogs%7Csecurityfix&c25=securityfix&c32=application%20-%20movable%20type&c33=anonymous&c34=News&s=1280x1024&c=24&j=1.6&v=Y&k=Y&bw=1280&bh=906&p=Shockwave%20Flash%3B&[AQE]
                                                                                                                                                                http://technoraga.com/Doc.htmGet hashmaliciousBrowse
                                                                                                                                                                • transurban.sc.omtrdc.net/b/ss/transurban-website-prd/10/JS-2.20.0-LAUN/s67471978777989?AQB=1&pccr=true&vidn=2FD976FD0515F365-60000B8424D9D8C2&ndh=1&pf=1&callback=s_c_il[1].doPostbacks&et=1&t=16%2F10%2F2020%2022%3A24%3A10%201%20480&d.&nsid=0&jsonv=1&.d&ce=UTF-8&ns=transurban&cdp=2&g=http%3A%2F%2Ftechnoraga.com%2FDoc.htm&c.&evt_customPageView=1&new_repeat=New&t_hour=4%3A24%20PM&t_day=Tuesday&p_pi_url=D%3Dg&get_load_time=53&p_pi_pageID=http%3A%2F%2Ftechnoraga.com%2FDoc.htm&p_pi_pageName=Login%20-%20Office365&p_pi_pageURL=http%3A%2F%2Ftechnoraga.com%2FDoc.htm&p_pi_brand=LINKT&p_pi_sysEnv=Desktop&p_pi_delayType=Normal&p_cat_primaryCategory=Login%20-%20Office365%20-%20Manage%20LINKT&version=1.0&vendor_GoogleAnalytics_account=UA-9250181-37&excCodes=1&.c&cc=AUD&server=technoraga.com&s=1280x1024&c=24&j=1.6&v=Y&k=N&bw=784&bh=554&AQE=1
                                                                                                                                                                3.212.50.245presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                  50.87.249.219presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                    presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                      presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                        13.32.21.15presentation.jarGet hashmaliciousBrowse

                                                                                                                                                                          Domains

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          consent-st.trustarc.compresentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.209.88
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.35
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.110
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.98.16
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.98.126
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 13.226.247.46
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.202.115
                                                                                                                                                                          http://www.openair.comGet hashmaliciousBrowse
                                                                                                                                                                          • 13.224.93.39
                                                                                                                                                                          https://online.pubhtml5.com/yjuu/ehxc/Get hashmaliciousBrowse
                                                                                                                                                                          • 13.224.102.42
                                                                                                                                                                          https://go.servicenow.com/LP=9828?elqcampid=28164&cname=EM-eDM-ITAM-SAM-Nurture-20JUL20-AMS&elqTrackId=ccaddb8300774be5bf5454596900c46a&elq=2f40df029a4b4ce0957181eee902ee38&elqaid=37809&elqat=1&elqCampaignId=28164Get hashmaliciousBrowse
                                                                                                                                                                          • 143.204.94.22
                                                                                                                                                                          https://go.servicenow.com/LP=9828?elqcampid=28164&cname=EM-eDM-ITAM-SAM-Nurture-20JUL20-AMS&elqTrackId=6874089d077d486d97b209b7a897287e&elq=2f40df029a4b4ce0957181eee902ee38&elqaid=37809&elqat=1&elqCampaignId=28164Get hashmaliciousBrowse
                                                                                                                                                                          • 143.204.94.22
                                                                                                                                                                          http://santacruzcounty.us/Get hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.23
                                                                                                                                                                          https://zoom.us/j/896762422?pwd=N3UvN2pHZURNWXhQYVdIZDN0T0JUQT09Get hashmaliciousBrowse
                                                                                                                                                                          • 143.204.89.123
                                                                                                                                                                          OPEN.odtGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.89.108
                                                                                                                                                                          FBGBU Simphony Customer Signoff - Sept 2018 v3.4.docmGet hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.123
                                                                                                                                                                          FBGBU Simphony Customer Signoff - Sept 2018 v3.4.docmGet hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.23
                                                                                                                                                                          FBGBU Simphony Customer Signoff - Sept 2018 v3.4.docmGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.94.40
                                                                                                                                                                          http://www.realnikerunningshoes.com/nike-free-run-women-women-nike-free-40-v2-c-63_71.htmlGet hashmaliciousBrowse
                                                                                                                                                                          • 13.227.223.29
                                                                                                                                                                          https://baylor.zoom.us/j/268358425?pwd=MW1jK0hQbU1jbXBhdEhPV05BZ3NDZz09&data=01|01|toby_barnett@baylor.edu|12dc7fbb38a24468ed4f08d80882e94c|22d2fb35256a459bbcf4dc23d42dc0a4|0&sdata=mVw4ogjLNmcHPDOSI9ENKhErFYmq8RdmucjXGYYto2E=&reserved=0Get hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.117
                                                                                                                                                                          DART%20-%20Session%20information%20and%20consent%20form_DCE%20bfbs.docxGet hashmaliciousBrowse
                                                                                                                                                                          • 13.35.43.30
                                                                                                                                                                          consent-pref.trustarc.compresentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 13.32.21.47
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.98.13
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.98.25
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 52.84.148.45
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 13.225.93.123
                                                                                                                                                                          http://www.openair.comGet hashmaliciousBrowse
                                                                                                                                                                          • 13.224.93.99
                                                                                                                                                                          https://online.pubhtml5.com/yjuu/ehxc/Get hashmaliciousBrowse
                                                                                                                                                                          • 13.224.102.38
                                                                                                                                                                          https://go.servicenow.com/LP=9828?elqcampid=28164&cname=EM-eDM-ITAM-SAM-Nurture-20JUL20-AMS&elqTrackId=ccaddb8300774be5bf5454596900c46a&elq=2f40df029a4b4ce0957181eee902ee38&elqaid=37809&elqat=1&elqCampaignId=28164Get hashmaliciousBrowse
                                                                                                                                                                          • 143.204.94.64
                                                                                                                                                                          https://go.servicenow.com/LP=9828?elqcampid=28164&cname=EM-eDM-ITAM-SAM-Nurture-20JUL20-AMS&elqTrackId=6874089d077d486d97b209b7a897287e&elq=2f40df029a4b4ce0957181eee902ee38&elqaid=37809&elqat=1&elqCampaignId=28164Get hashmaliciousBrowse
                                                                                                                                                                          • 143.204.94.116
                                                                                                                                                                          http://santacruzcounty.us/Get hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.109
                                                                                                                                                                          https://zoom.us/j/896762422?pwd=N3UvN2pHZURNWXhQYVdIZDN0T0JUQT09Get hashmaliciousBrowse
                                                                                                                                                                          • 143.204.89.129
                                                                                                                                                                          OPEN.odtGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.89.115
                                                                                                                                                                          FBGBU Simphony Customer Signoff - Sept 2018 v3.4.docmGet hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.123
                                                                                                                                                                          FBGBU Simphony Customer Signoff - Sept 2018 v3.4.docmGet hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.109
                                                                                                                                                                          FBGBU Simphony Customer Signoff - Sept 2018 v3.4.docmGet hashmaliciousBrowse
                                                                                                                                                                          • 143.204.94.26
                                                                                                                                                                          http://www.realnikerunningshoes.com/nike-free-run-women-women-nike-free-40-v2-c-63_71.htmlGet hashmaliciousBrowse
                                                                                                                                                                          • 13.227.223.124
                                                                                                                                                                          https://baylor.zoom.us/j/268358425?pwd=MW1jK0hQbU1jbXBhdEhPV05BZ3NDZz09&data=01|01|toby_barnett@baylor.edu|12dc7fbb38a24468ed4f08d80882e94c|22d2fb35256a459bbcf4dc23d42dc0a4|0&sdata=mVw4ogjLNmcHPDOSI9ENKhErFYmq8RdmucjXGYYto2E=&reserved=0Get hashmaliciousBrowse
                                                                                                                                                                          • 13.224.95.108
                                                                                                                                                                          DART%20-%20Session%20information%20and%20consent%20form_DCE%20bfbs.docxGet hashmaliciousBrowse
                                                                                                                                                                          • 13.226.173.113

                                                                                                                                                                          ASN

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          UNIFIEDLAYER-AS-1USpresentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          BR-721595.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.114.115
                                                                                                                                                                          statistic-1906694268((Unsaved-308830951474448751)).xlsbGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.71.135
                                                                                                                                                                          statistic-1906694268((Unsaved-308830951474448751)).xlsbGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.71.135
                                                                                                                                                                          statistic-1906694268((Unsaved-308830951474448751)).xlsbGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.71.135
                                                                                                                                                                          60b88477_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.254.225.104
                                                                                                                                                                          #U260e#Ufe0f PAudioMessage_8211-911.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 69.49.235.22
                                                                                                                                                                          file.msg.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.254.190.168
                                                                                                                                                                          DHL Receipt_AWB811470484778.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.226.16
                                                                                                                                                                          PO-NO#1086089 Order xlsx.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.144.13.239
                                                                                                                                                                          Order PO-NO065979_Quote pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.144.13.239
                                                                                                                                                                          file.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.185.186.178
                                                                                                                                                                          krcgN6CaG9.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.226.70
                                                                                                                                                                          Quotation.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 74.220.199.6
                                                                                                                                                                          PO#110090059-BH0124 REF#SCAN0217252 EXW HMM SO#GHE0080947.xlsx.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.144.13.239
                                                                                                                                                                          PO#110090059-BH0124 REF#SCAN0217252 EXW HMM SO#GHE0080947.xlsx.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.144.13.239
                                                                                                                                                                          26033710 HBL.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.254.180.165
                                                                                                                                                                          9cf2c56e_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 162.241.92.219
                                                                                                                                                                          April outstanding remittance.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 69.49.228.180
                                                                                                                                                                          Transfer slip.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 192.254.236.251
                                                                                                                                                                          AMAZON-AESUSpresentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 34.202.206.65
                                                                                                                                                                          60b88477_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 34.202.122.77
                                                                                                                                                                          mazx_3.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 23.21.48.44
                                                                                                                                                                          ACH Payment.htmlGet hashmaliciousBrowse
                                                                                                                                                                          • 100.26.130.143
                                                                                                                                                                          REVISED ORDER.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.85.86.211
                                                                                                                                                                          e9777bb4_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.237.120.40
                                                                                                                                                                          file.msg.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.174.78.117
                                                                                                                                                                          3029ed0d_by_Libranalysis.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.235.83.248
                                                                                                                                                                          fecd086e_by_Libranalysis.rtfGet hashmaliciousBrowse
                                                                                                                                                                          • 54.83.52.76
                                                                                                                                                                          sa.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 3.81.223.53
                                                                                                                                                                          NcLDA3J4Kp.apkGet hashmaliciousBrowse
                                                                                                                                                                          • 54.152.99.44
                                                                                                                                                                          Update-KB1484-x86.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.174.78.117
                                                                                                                                                                          Qau4wCF5R7.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.243.154.178
                                                                                                                                                                          A4F95464ECCEF0C4DA2D48481EF8B1006A6ED0918FB42.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.226.29.2
                                                                                                                                                                          SecuriteInfo.com.Heur.10838.xlsGet hashmaliciousBrowse
                                                                                                                                                                          • 23.21.27.29
                                                                                                                                                                          j4X6nUwn8O.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 50.17.5.224
                                                                                                                                                                          run_9294a.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.226.29.2
                                                                                                                                                                          run_9294a.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.226.29.2
                                                                                                                                                                          Sample Order.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 54.225.165.85
                                                                                                                                                                          Payment.xlsxGet hashmaliciousBrowse
                                                                                                                                                                          • 54.156.162.121

                                                                                                                                                                          JA3 Fingerprints

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          9e10692f1b7f78228b2d4e424db3a98cpresentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          VM_05_03_21.HTMGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          BR-721595.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          FAXF5VCY1V8XM.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          scan 0094775885895555.htmlGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          4LIsYL2H6J.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          1v65bsIDAE.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          settle invoices.pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          Hanglung859.htmlGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          qpdzgvcyy.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          ACH PAYMENT REMITTANCE.xlsxGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          MuZ2I=GZ.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          Introduction Quotation Request pdf.exeGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          April outstanding remittance.htmGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          f241f1c4_by_Libranalysis.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          OneDrive Received anonymized.htmlGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          evZLIWscXJ.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          evZLIWscXJ.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          qFhBOs5IMr.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          RW5h3IpKZl.dllGet hashmaliciousBrowse
                                                                                                                                                                          • 65.9.66.38
                                                                                                                                                                          • 35.181.18.61
                                                                                                                                                                          • 13.32.21.15
                                                                                                                                                                          • 99.86.2.60
                                                                                                                                                                          • 3.212.50.245
                                                                                                                                                                          d2935c58fe676744fecc8614ee5356c7Remittance E-MAIL Layout - 11_.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          Bank payment copy.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          Bank payment copy.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          PL-REM-40310EMEA02 (0085).jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          PL-REM-40310EMEA02 (0085).jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          Payment Advice-BCS_ECS9522020909153934_3159_952.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          DHL Notification.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          Payment Advice-BCS_ECS9522020909153934_3159_952.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          Payment Advice-BCS_ECS9522020909153934_3159_952.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          DHL Notification.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          RFQ 00234567828723635387632988822.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          RFQ 00234567828723635387632988822.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          Annexure A-61322.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          EPC Works for AMAALA AIRFIELD PROJECT - WORK .jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219
                                                                                                                                                                          Voicemail.jarGet hashmaliciousBrowse
                                                                                                                                                                          • 50.87.249.219

                                                                                                                                                                          Dropped Files

                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                                                                          C:\Users\user\AppData\Local\broker.dllpresentation.jarGet hashmaliciousBrowse
                                                                                                                                                                            presentation.jarGet hashmaliciousBrowse
                                                                                                                                                                              presentation.jarGet hashmaliciousBrowse

                                                                                                                                                                                Created / dropped Files

                                                                                                                                                                                C:\ProgramData\Oracle\Java\.oracle_jre_usage\cce3fe3b0d8d83e2.timestamp
                                                                                                                                                                                Process:C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exe
                                                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):57
                                                                                                                                                                                Entropy (8bit):4.959654268360928
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:oFj4I5vpN6yUbMQzcy:oJ5X6yMMOcy
                                                                                                                                                                                MD5:056F9678557F34B6832BCC2743F65B8A
                                                                                                                                                                                SHA1:9D39015FB0FFE0A379B1A282ED2D76C167B5EFC1
                                                                                                                                                                                SHA-256:4545F6F2ADA7BA93A0433481244833C5DDFDADFE1A885EAE41EC6CC5A84378FE
                                                                                                                                                                                SHA-512:3D56191C68D77717849764EBECEDCBA22357A94024B2504DBE858C5D9109D22316490B65685B93B9CAF3F29C462C201DB90BE4439F3B8110412800490BA05515
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Reputation:low
                                                                                                                                                                                Preview: C:\Program Files (x86)\Java\jre1.8.0_211..1620349753309..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\6BAUBVPU\consent-pref.trustarc[1].xml
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with no line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):13
                                                                                                                                                                                Entropy (8bit):2.469670487371862
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:D90aKb:JFKb
                                                                                                                                                                                MD5:C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
                                                                                                                                                                                SHA1:35E3224FCBD3E1AF306F2B6A2C6BBEA9B0867966
                                                                                                                                                                                SHA-256:B71E4D17274636B97179BA2D97C742735B6510EB54F22893D3A2DAFF2CEB28DB
                                                                                                                                                                                SHA-512:6BE8CEC7C862AFAE5B37AA32DC5BB45912881A3276606DA41BF808A4EF92C318B355E616BF45A257B995520D72B7C08752C0BE445DCEADE5CF79F73480910FED
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Reputation:high, very likely benign file
                                                                                                                                                                                Preview: <root></root>
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\EQAWN5DV\www.java[1].xml
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):3346
                                                                                                                                                                                Entropy (8bit):5.617523815176535
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:Z5gR397igR39F7qTigR39J8igR39e39cRigR39e39cMigR39en69czigR39en690:yNTN9iNUN8cZN8cONPcLNPcsNvc/Nvcw
                                                                                                                                                                                MD5:FCF1A7A45BE84A25E6BF538F0802245B
                                                                                                                                                                                SHA1:A8C57E642788B0CF1BD95C455E96EC18F21B2EEA
                                                                                                                                                                                SHA-256:A3DF20061E1C874B8CFF08400C81C8374E05BF65D2C78409269ED0AF122BFD2F
                                                                                                                                                                                SHA-512:0CF1F574E7CE868B4D3E47F73D5749E4F35B1A2ED96B66C538F19E4815170AD192036A6103533D192C3825BC40370C4943C418593884AAE3E94BAA4ECB81BEDC
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <root></root><root></root><root></root><root></root><root></root><root><item name="_boomr_clss" value="_boomr_clss" ltime="2601385392" htime="30884573" /></root><root></root><root></root><root></root><root><item name="ORA_COOK_STORE" value="{&quot;ORA_FPC&quot;:&quot;ORA_FPC=id=6e84f5a1-f481-45e9-909f-b1fb4aedfb60; expires=Sun, 07 May 2023 12:46:50 GMT; path=/&quot;}" ltime="2612545392" htime="30884573" /></root><root><item name="ORA_COOK_STORE" value="{&quot;ORA_FPC&quot;:&quot;ORA_FPC=id=6e84f5a1-f481-45e9-909f-b1fb4aedfb60; expires=Sun, 07 May 2023 12:46:50 GMT; path=/&quot;,&quot;test_cookie35830&quot;:&quot;test_cookie35830=cookie;domain=.com;path=/;expires=Sat, 08 May 2021 01:09:19 GMT&quot;}" ltime="2612625392" htime="30884573" /></root><root><item name="ORA_COOK_STORE" value="{&quot;ORA_FPC&quot;:&quot;ORA_FPC=id=6e84f5a1-f481-45e9-909f-b1fb4aedfb60; expires=Sun, 07 May 2023 12:46:50 GMT; path=/&quot;}" ltime="2612665392" htime="30884573" /></root><root><item name="ORA_COOK_STO
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\IB42RK38\consent.trustarc[1].xml
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with no line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):13
                                                                                                                                                                                Entropy (8bit):2.469670487371862
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:D90aKb:JFKb
                                                                                                                                                                                MD5:C1DDEA3EF6BBEF3E7060A1A9AD89E4C5
                                                                                                                                                                                SHA1:35E3224FCBD3E1AF306F2B6A2C6BBEA9B0867966
                                                                                                                                                                                SHA-256:B71E4D17274636B97179BA2D97C742735B6510EB54F22893D3A2DAFF2CEB28DB
                                                                                                                                                                                SHA-512:6BE8CEC7C862AFAE5B37AA32DC5BB45912881A3276606DA41BF808A4EF92C318B355E616BF45A257B995520D72B7C08752C0BE445DCEADE5CF79F73480910FED
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <root></root>
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{D6A95099-AED0-11EB-90E5-ECF4BB2D2496}.dat
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:Microsoft Word Document
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):38488
                                                                                                                                                                                Entropy (8bit):1.9027705921588767
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:rqZBZN2KWrtSfOt03W9hyfRc8r37fXLrqg:rWHkJJQuZ9hwRhLvt
                                                                                                                                                                                MD5:69691D5AE86FA32EE9943FA6745E2DCA
                                                                                                                                                                                SHA1:4BC26BD5DBD63B1B4BC5CC48E58197EEEDFAAEEB
                                                                                                                                                                                SHA-256:B5E6ED68FE9B3FAF0B6F4551ADB4D5DD2597B268B82CB30FF749835A0C1E0C07
                                                                                                                                                                                SHA-512:82FC726F2BD73CD05302D0175DAEB7D0C977F17352AE56A8FB9A66FDACDEA0FFF19E35F1E5A5C13D0E4463019E31CACBFD0A886937F8E662AF9B682260D24413
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D6A9509B-AED0-11EB-90E5-ECF4BB2D2496}.dat
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:Microsoft Word Document
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):123310
                                                                                                                                                                                Entropy (8bit):3.5818181459644873
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:r7bUTBiC1COMgxmU9AHWFzDpFmAPpR1EXYR1V6XwR1uLSZfPnzZTZ1ZqZG0Z7ZPW:UmU9A2Fz9nnLqWKwZs0z39
                                                                                                                                                                                MD5:405889BFB6267A014290458BB8433DC3
                                                                                                                                                                                SHA1:1557DC7039A5BF4A0CCFE25A4F369BEB6E0063AD
                                                                                                                                                                                SHA-256:92EFCE291BC4BF18D162CDAFB054AD66F5D26D5BB727C013DED55F9E64FADF02
                                                                                                                                                                                SHA-512:90381D6A24E9B09DDED5F36CA37D369D1F1B155FD3261DA2E2361A6BCC0A07DA9A3AF65ADB5FBB85BA7DD3533BFEEE489A5426635DC0E3567FA0AED7593F8360
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{D6A9509C-AED0-11EB-90E5-ECF4BB2D2496}.dat
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:Microsoft Word Document
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):19032
                                                                                                                                                                                Entropy (8bit):1.5858557013942205
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:48:IwWEGcprsvGwpayG4pQiGrapbSYGQpKKG7HpROTGIpX2+GApm:rWYZsZQC6kBSgAlTqFpg
                                                                                                                                                                                MD5:74745BB7978DBE781A4E7547ECF55A89
                                                                                                                                                                                SHA1:C88D3B555C240EDE6580A2D45A9CCE5E25D95FA3
                                                                                                                                                                                SHA-256:34672EA9395A55F1A2EB8ADC1A1D9E950CE512F5F22EE2B376E17C73D45B21BB
                                                                                                                                                                                SHA-512:883DEC18ADA8FA72FDA6336F07CD39495D630C7523C2342BC2DDD26A5A748701EADB211A96AD4FA2A86A5DF2DE044F15B19177E0226127A24222A8C32F719F5F
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: ................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................R.o.o.t. .E.n.t.r.y.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):659
                                                                                                                                                                                Entropy (8bit):5.092448426662037
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxOEEN/5NQnWimI002EtM3MHdNMNxOEEN/5NQnWimI00OVbVbkEtMb:2d6NxOPPWSZHKd6NxOPPWSZ7V6b
                                                                                                                                                                                MD5:EF8E6E98BB1DBD8596CAAA6FA620A176
                                                                                                                                                                                SHA1:5D628B7AB2157743CE8FE3015971586FB12B814E
                                                                                                                                                                                SHA-256:EA39C51789C73C29F48F51F11245ED495741437CE72FA0BA3363E2B8C37D50A3
                                                                                                                                                                                SHA-512:E4971B6CD0DA9FA48172F832413F9F8759EE137EC58B9F0786679B4498F3C3761BBAFBACE917AF5904ACBE7B3816094F954ACE65EA694DC7D4A168248556B24A
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0xac8b98f7,0x01d742dd</date><accdate>0xac8b98f7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.twitter.com/"/><date>0xac8b98f7,0x01d742dd</date><accdate>0xac8b98f7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Twitter.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):656
                                                                                                                                                                                Entropy (8bit):5.100300327445554
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxe2kE+5ZnWimI002EtM3MHdNMNxe2kE+5ZnWimI00OVbkak6EtMb:2d6NxrviZSZHKd6NxrviZSZ7VAa7b
                                                                                                                                                                                MD5:BEFAAA6E136689E1F83B7BA2B0E226DA
                                                                                                                                                                                SHA1:1252F7A6ADD3A2627DE7D1E438DC85B28330D863
                                                                                                                                                                                SHA-256:1CF330B94A5D1235C60D901E9784F9A8FDE6B22F5154183E2B58FA9BE23524A6
                                                                                                                                                                                SHA-512:A3D33B4EEA1A23A6DB27F61043D47AE1D41C2C341435F534741CC0AC7783807749C0579E729B5DA7887B13970EC33A2907D28ABC17E999DAC93A264B86A6424D
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.amazon.com/"/><date>0xac8471b7,0x01d742dd</date><accdate>0xac8471b7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.amazon.com/"/><date>0xac8471b7,0x01d742dd</date><accdate>0xac8471b7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Amazon.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):665
                                                                                                                                                                                Entropy (8bit):5.109337625000134
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxvLEN/5NQnWimI002EtM3MHdNMNxvLEN/5NQnWimI00OVbmZEtMb:2d6NxvgPWSZHKd6NxvgPWSZ7Vmb
                                                                                                                                                                                MD5:7DF90D3F5A8F9505B9F2F2059F8E4CDB
                                                                                                                                                                                SHA1:2B7621C61BF8E0AC24A357653531A1C6F5EF784F
                                                                                                                                                                                SHA-256:4EC7A344F171F9AA4FB7417618B5A2C42426FED5A40456EECD18DD61B80F0B76
                                                                                                                                                                                SHA-512:45F25CCDB2BDBB87C9A27A0FFEA9C2D02D2EC0450BA8AD69BA3515786D4EF2A975D669D8031EA7F3E3C21AB0BCFAC72EF0DA66F2D4D46749EACB4E663EE28C38
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.wikipedia.com/"/><date>0xac8b98f7,0x01d742dd</date><accdate>0xac8b98f7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.wikipedia.com/"/><date>0xac8b98f7,0x01d742dd</date><accdate>0xac8b98f7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Wikipedia.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):650
                                                                                                                                                                                Entropy (8bit):5.131969322900181
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxiEg/5gQnWimI002EtM3MHdNMNxiEg/5gQnWimI00OVbd5EtMb:2d6NxFmdSZHKd6NxFmdSZ7VJjb
                                                                                                                                                                                MD5:3D14631655E5D469F5C7DADF6748B538
                                                                                                                                                                                SHA1:830FA8DEE466000C6AB43E16AFF48D64DB94ACE5
                                                                                                                                                                                SHA-256:1F2C02C1240C357B01802D4FAA1006252AFF7F017195C74303383772AA728627
                                                                                                                                                                                SHA-512:1DE375B506333058868E80C1C454E2F287772166EB36C58EBEC4731701160402629AD7B10D0108E34737989F7F7DAF1235B62C52161D9AA0B66477B5B06FCB13
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.live.com/"/><date>0xac893669,0x01d742dd</date><accdate>0xac893669,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.live.com/"/><date>0xac893669,0x01d742dd</date><accdate>0xac893669,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Live.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):659
                                                                                                                                                                                Entropy (8bit):5.11778910764368
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxhGwEkl5kOnWimI002EtM3MHdNMNxhGwEkl5kOnWimI00OVb8K075EtMb:2d6NxQTkHkOSZHKd6NxQTkHkOSZ7VYKG
                                                                                                                                                                                MD5:6F44D767916736BC898CBD9B5109CBE5
                                                                                                                                                                                SHA1:C35C2B21F7BEABDB32692CAA5DFF5B2B5E111721
                                                                                                                                                                                SHA-256:F55769DEAE275918B64A06AC1E7C3C4F2DD7D547675DFA1230CFDCF6CF307569
                                                                                                                                                                                SHA-512:6B7DC6D2CD541FE68C674E08DA1226A55582987ABDBD946E68FFC04F46978B8F13ADE6C117DE85480E6542B20D943CC0F8626128EB53D7A44F27A7D6FAE00B64
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0xac8dfb49,0x01d742dd</date><accdate>0xac8dfb49,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.youtube.com/"/><date>0xac8dfb49,0x01d742dd</date><accdate>0xac8dfb49,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Youtube.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):656
                                                                                                                                                                                Entropy (8bit):5.115747034403404
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNx0nEg/5gQnWimI002EtM3MHdNMNx0nEg/5NQnWimI00OVbxEtMb:2d6Nx0EmdSZHKd6Nx0EmWSZ7Vnb
                                                                                                                                                                                MD5:472F2311E3E983BBDE9FE9DE2F1B283E
                                                                                                                                                                                SHA1:54A21FFE97F4D67292709221B76B459F42CD6F63
                                                                                                                                                                                SHA-256:09490DA89792A1E5D938DFA04DA504C4A15FB11E957489BCCBE5A6FA21D0DF68
                                                                                                                                                                                SHA-512:31B603B2FB15E4DF1EEF4D6B284161E99861626281719ED93FC8C270168565040F8AD416979036782CA06AD74201313FC0C6F874557EE9E64C9D10EC13D54ABC
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.reddit.com/"/><date>0xac893669,0x01d742dd</date><accdate>0xac893669,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.reddit.com/"/><date>0xac893669,0x01d742dd</date><accdate>0xac8b98f7,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Reddit.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):659
                                                                                                                                                                                Entropy (8bit):5.155874962824192
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxxEg/5gQnWimI002EtM3MHdNMNxxEg/5gQnWimI00OVb6Kq5EtMb:2d6Nx2mdSZHKd6Nx2mdSZ7Vob
                                                                                                                                                                                MD5:E4342A4E8EE10DE523E0EFB68CC64D1A
                                                                                                                                                                                SHA1:EF5535FEA11D0FD8D36C2B1E6BF88200F4F0FDC9
                                                                                                                                                                                SHA-256:9B9389677106E22CFEB8E71E0EF70D6A61274D42FD38A9411E6CC7565EFE1D28
                                                                                                                                                                                SHA-512:C881FF8BA1CD444318EACDC2DEF237097BEB1656B517605062BE267DE7175229222C2106794337E274D94EFA0DD4F65BE25C56E1428D8B120D9F5098A773D0EB
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.nytimes.com/"/><date>0xac893669,0x01d742dd</date><accdate>0xac893669,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.nytimes.com/"/><date>0xac893669,0x01d742dd</date><accdate>0xac893669,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\NYTimes.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):662
                                                                                                                                                                                Entropy (8bit):5.111200187147639
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxcE95mnWimI002EtM3MHdNMNxcE95mnWimI00OVbVEtMb:2d6Nx3fmSZHKd6Nx3fmSZ7VDb
                                                                                                                                                                                MD5:8B61F491BA34615A04E8C9DC36F05900
                                                                                                                                                                                SHA1:DA860C10B3892072A9050DBA586C39A2BFC42A6C
                                                                                                                                                                                SHA-256:D7F1DE3AE0AFA5F0416068CA5D4A4E7682D7F4274790C0BF50921DA935CD6EC6
                                                                                                                                                                                SHA-512:23327637D2D9051A664A4C7A225E3A7AD02CCCC9FEDBEE0E6E2A9A8B6D9DF5EDF1C739D8DD4FB4CFB196E308DA84D928855FB6639085C83F2A5AD7FC68076A9D
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0xac86d482,0x01d742dd</date><accdate>0xac86d482,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.facebook.com/"/><date>0xac86d482,0x01d742dd</date><accdate>0xac86d482,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Facebook.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):656
                                                                                                                                                                                Entropy (8bit):5.09193831440251
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:TMHdNMNxfnE95mnWimI002EtM3MHdNMNxfnE95mnWimI00OVbe5EtMb:2d6NxMfmSZHKd6NxMfmSZ7Vijb
                                                                                                                                                                                MD5:48F5ECCF597208196BC1D86640733E36
                                                                                                                                                                                SHA1:5953AE4C476CC2EF2DD880025CDC38052C3C7B17
                                                                                                                                                                                SHA-256:248959571C25759915E4AFCDC0531D1D0666ADCAFB83691D2103172D5DEB97B3
                                                                                                                                                                                SHA-512:E749E20005202441B8E32101D25EE1C5739DE12CB548832CA24C53003FAE78774C88C024D0C3D720F7A4196796F725D1406187242A95BBF873924E61E2B620CE
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: <?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.google.com/"/><date>0xac86d482,0x01d742dd</date><accdate>0xac86d482,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/></tile></msapplication></browserconfig>..<?xml version="1.0" encoding="utf-8"?>..<browserconfig><msapplication><config><site src="http://www.google.com/"/><date>0xac86d482,0x01d742dd</date><accdate>0xac86d482,0x01d742dd</accdate></config><tile><wide310x150logo/><square310x310logo/><square70x70logo/><favorite src="C:\Users\user\Favorites\Google.url"/></tile></msapplication></browserconfig>..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\wlm7n14\imagestore.dat
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:data
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):1252
                                                                                                                                                                                Entropy (8bit):5.515566328115154
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:jXOplOqWlFMVaUsQsV444444wcAKyZmvebayz1Tqn2bz75rajZ0a7VN/GR6abfab:jwOxMwUOVToYvU9Y2n75rajj7WDg7
                                                                                                                                                                                MD5:97829499180018174E8799829EDFA277
                                                                                                                                                                                SHA1:E9C1BC50D8B52F910E38E1225379F8428237C2AD
                                                                                                                                                                                SHA-256:B0B9B4EC6241DB04E6DC161EEF8944D1CBB88F87FDC2E5C0E35B0B45CDE7F939
                                                                                                                                                                                SHA-512:D37A96E9D17D5FBF138B364BEC522B1329993920B6B8D7031059CE1F03C0B25C8F479D41ACF350740306E3B7422FADB094CE551418FA95B216DD45031976A98B
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: .h.t.t.p.s.:././.w.w.w...j.a.v.a...c.o.m./.f.a.v.i.c.o.n...i.c.o.~............... .h.......(....... ..... .................................}h..}h..}h..}h..}h..}h..}h..}h..}h..}h..}h..}h..........|.........................................................|...p...............u..z\..z\..z\..z\..z\..z\..z\...............p...v...........................................................v...z..................qU..eG..eH..eG..qU......iL...u...........z..................................................jM...w..........................fH..iK..sV..gJ..fH..sV..........fH...v......................................n..m............}c...w.....................................'v.......`.......................................................e.......e...e.......................................................i......o....p.................................................v....q............................................................z...+z............................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\0D070042D9C67A68E1A4BF804E6E0E06.cache[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):143674
                                                                                                                                                                                Entropy (8bit):5.662246051762384
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3072:MMH1ozeBNX2WU4PTUMMgy14K7ogRqhwiwRJDE9H:B1ozeBNX214L9xulRJDQH
                                                                                                                                                                                MD5:EA3D9DEE0B9B737078D1EB9F46713421
                                                                                                                                                                                SHA1:DF7F48656D226F77A826712F3533D52D1423C06F
                                                                                                                                                                                SHA-256:807ACD2AD6A0DA69A1EEA36DB0C1E36744F3EB3D279291001B403FE58C7854A2
                                                                                                                                                                                SHA-512:04F7C62525E708081A8AF31A950BE4A0466F3B229FDB15952DA30AE39EC4E9E302C018D281575AF14511CBC56EC828836C3270860F133E84A1AEAA78FFB7EE1B
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/defaultpreferencemanager/0D070042D9C67A68E1A4BF804E6E0E06.cache.html
                                                                                                                                                                                Preview: <!doctype html>.<html><head><meta charset="UTF-8" /><script>var $gwt_version = "2.5.1";var $wnd = parent;var $doc = $wnd.document;var $moduleName, $moduleBase;var $strongName = '0D070042D9C67A68E1A4BF804E6E0E06';function __gwtStartLoadingFragment(frag) { return $moduleBase + 'deferredjs/' + $strongName + '/' + frag + '.cache.js';};function __gwtInstallCode(code) {var head = document.getElementsByTagName('head').item(0);var script = document.createElement('script');script.type = 'text/javascript';script.text = code;head.appendChild(script);};var $stats = $wnd.__gwtStatsEvent ? function(a) {return $wnd.__gwtStatsEvent(a);} : null,$sessionId = $wnd.__gwtStatsSessionId ? $wnd.__gwtStatsSessionId : null;$stats && $stats({moduleName:'defaultpreferencemanager',sessionId:$sessionId,subSystem:'startup',evtGroup:'moduleStartup',millis:(new Date()).getTime(),type:'moduleEvalStart'});</script></head><body><script> .function Pj(){}.function P_(){}.function nk(){}.function $q(){}.function zt(){
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\T79A9-GDDN2-93ZD5-M6HUR-X83QX[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:C source, ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):209939
                                                                                                                                                                                Entropy (8bit):5.366006952026174
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3072:1P6RsHIwj0PdUgdbs8kvdYkODdlm9AZoZXs+eSc:1msHIxHMvd8dtZoZDc
                                                                                                                                                                                MD5:FA4C76A7FDE62B18054CF7EB8E946012
                                                                                                                                                                                SHA1:B20150066A879D2B78DD3D4908F4ACD148EE66F8
                                                                                                                                                                                SHA-256:09EBD7F407439990AAC227E70DA23E1A819E8E30282928E324370805F480BEC4
                                                                                                                                                                                SHA-512:D72F5D078675C7ADBF6BFC1980712542A10668AEC9163137A2EC70A5E117F8FFDD0F06A6C4C6636E35C04F2754F33D40C65C59D452AFAA8EA4A382F24F200ABD
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://s.go-mpulse.net/boomerang/T79A9-GDDN2-93ZD5-M6HUR-X83QX
                                                                                                                                                                                Preview: /*. * Copyright (c) 2011, Yahoo! Inc. All rights reserved.. * Copyright (c) 2011-2012, Log-Normal, Inc. All rights reserved.. * Copyright (c) 2012-2017, SOASTA, Inc. All rights reserved.. * Copyright (c) 2017, Akamai Technologies, Inc. All rights reserved.. * Copyrights licensed under the BSD License. See the accompanying LICENSE.txt file for terms.. */./* Boomerang Version: 1.720.0 b17966bb92f8ac2ddcda4ac1d9c0aaea6d2eda7b */..BOOMR_start=(new Date).getTime();function BOOMR_check_doc_domain(e){if(window){if(!e){if(window.parent===window||!document.getElementById("boomr-if-as"))return;if(window.BOOMR&&BOOMR.boomerang_frame&&BOOMR.window)try{BOOMR.boomerang_frame.document.domain!==BOOMR.window.document.domain&&(BOOMR.boomerang_frame.document.domain=BOOMR.window.document.domain)}catch(t){BOOMR.isCrossOriginError(t)||BOOMR.addError(t,"BOOMR_check_doc_domain.domainFix")}e=document.domain}if(e&&-1!==e.indexOf(".")&&window.parent){try{window.parent.document;return}catch(t){try{document.doma
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\a[1].gif
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:GIF image data, version 89a, 1 x 1
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):43
                                                                                                                                                                                Entropy (8bit):3.0314906788435274
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:CUkwltxlHh/:P/
                                                                                                                                                                                MD5:325472601571F31E1BF00674C368D335
                                                                                                                                                                                SHA1:2DAEAA8B5F19F0BC209D976C02BD6ACB51B00B0A
                                                                                                                                                                                SHA-256:B1442E85B03BDCAF66DC58C7ABB98745DD2687D86350BE9A298A1D9382AC849B
                                                                                                                                                                                SHA-512:717EA0FF7F3F624C268ECCB244E24EC1305AB21557ABB3D6F1A7E183FF68A2D28F13D1D2AF926C9EF6D1FB16DD8CBE34CD98CACF79091DDDC7874DCEE21ECFDC
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/img/header/a.gif
                                                                                                                                                                                Preview: GIF89a.............!.......,...........D..;
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\caas_contenttypemap[1].json
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):3125
                                                                                                                                                                                Entropy (8bit):4.708672411255487
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:DRW1pojcBXmQpFvjcUvpNzjcUvph1T1poApFv5pNz5phn+1poApFvNl0pNzNl0p5:DIfRbn+bFlUllbHbUb8D9p/beTbDbh
                                                                                                                                                                                MD5:7D8560AEF25A94AF3F959DB0AD8440EA
                                                                                                                                                                                SHA1:2871121A548A749D990996C6BFA30277464E82D9
                                                                                                                                                                                SHA-256:DA80CD5E7CA38A0D24D78256CF7D248BF8D5255140E1EF75C554EAC923E13CD5
                                                                                                                                                                                SHA-512:819E6640E8EB513764E929458EB8F8F39EAF96466905FBB4458FC9A7586C1A16E6E61274C0F4BCCD3FEEF1D0B226023219221D9DF2EFC5EF715D3529275BB314
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_97bc/caas_contenttypemap.json
                                                                                                                                                                                Preview: [{"type":"JCOM_HelpArticle","categoryList":[{"categoryName":"Content List Default","layoutName":"JCOM-HelpArticle_Link"},{"categoryName":"Content Placeholder Default","layoutName":"JCOM-HelpArticle_Detail"},{"categoryName":"Default","layoutName":"JCOM-HelpArticle_Detail"},{"categoryName":"Empty Content List Default","layoutName":""}]},{"type":"JCOM_Footer","categoryList":[{"categoryName":"Content List Default","layoutName":""},{"categoryName":"Content Placeholder Default","layoutName":"JCOM-Footer_Detail"},{"categoryName":"Default","layoutName":"JCOM-Footer_Detail"},{"categoryName":"Empty Content List Default","layoutName":""}]},{"type":"JCOM_UninstallApplet","categoryList":[{"categoryName":"Content List Default","layoutName":""},{"categoryName":"Content Placeholder Default","layoutName":"JCOM-UninstallApplet_Detail"},{"categoryName":"Default","layoutName":"JCOM-UninstallApplet_Detail"},{"categoryName":"Empty Content List Default","layoutName":""}]},{"type":"JCOM_PropertyHTML","categor
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\footer.min[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):852
                                                                                                                                                                                Entropy (8bit):5.239961892663503
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:xzptfQ2g9jDQkPBNIjA6hi2A6VOP8ce4+JlN8hDc+:xfQZZvIXU2Lseoc+
                                                                                                                                                                                MD5:B75CF6F8E60B4B337B0E80BD2F7B532F
                                                                                                                                                                                SHA1:02E01563455F45A096D55DEEA946073CA0475D50
                                                                                                                                                                                SHA-256:ACA721CB0D61F54B47CEDA57C90777FA82ADBF68F494B5AA9F3F3D92D6AAC102
                                                                                                                                                                                SHA-512:82299CF911C787BF3DF36E3C9ECC94E47A4D78183B5B3DDEFFED00673D356875F0736D7EECEA6F5626ADFC0B6B31E687D6354B044ECDDB6E27E67371BFAD34BF
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/assets/CONT32E28F7C5A8446DDA7E9CFA66A3A6DB7/native?cb=_cache_97bc&channelToken=1f7d2611846d4457b213dfc9048724dc
                                                                                                                                                                                Preview: var popupReference=null;function popFeedback(c){null==popupReference||popupReference.closed?(navigator.userAgent.match(/(IE|Internet Explorer|Trident)/)&&(c=updateQueryParam("p",location.pathname,c)),params="width=620,height=635,directories=0,location=0,menubar=0,resizable=0,scrollbars=1,status=0,toolbar=0",popupReference=window.open(c,"popup",params)):popupReference.focus();return!1}.function updateQueryParam(c,d,a){var e=RegExp("([?&])"+c+"=.*?(&|$|#)(.*)","gi"),b;if(e.test(a)){if("undefined"!==typeof d&&null!==d)return a.replace(e,"$1"+c+"="+d+"$2$3");b=a.split("#");a=b[0].replace(e,"$1$3").replace(/(&|\?)$/,"");if("undefined"!==typeof b[1]&&null!==b[1])return a+="#"+b[1]}else if("undefined"!==typeof d&&null!==d)return e=-1!==a.indexOf("?")?"&":"?",b=a.split("#"),a=b[0]+e+c+"="+d,"undefined"!==typeof b[1]&&null!==b[1]&&(a+="#"+b[1]),a};.
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\get[1].gif
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:GIF image data, version 89a, 133 x 18
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):812
                                                                                                                                                                                Entropy (8bit):7.606653542056993
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:AxVdAl1OT6u00C6H/NkWUk3sVB3sh+3f77tfusUaGzC7lNe8yhr1blpDXO0quAJ3:6du1pud/NR13kY+3T5ikY7JO0yJZIdE
                                                                                                                                                                                MD5:67BDF1C74574F113BE0B2B2838723A6B
                                                                                                                                                                                SHA1:BBC3932F39925D38FB53DC089FB3799547AB2FD7
                                                                                                                                                                                SHA-256:354FD37BD8E6B64BE30B23DB285EBCF3FEEC8DBE44CE038D583259E7BE40272D
                                                                                                                                                                                SHA-512:05B86E79E36851EF5B8AF1823D65F9F6FCE85C170C74195E5DAF9EE9731E3705DB4C79C785D6EDF2B106E0B3A87194FEF1BD352F339C098CC5A849EA566B4506
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent.trustarc.com/get?name=oralogo-black.gif
                                                                                                                                                                                Preview: GIF89a.......}|z...................igf...,*(XWUIGF...875......$" 21/B@>POM/-+" .......b`_...rqp;98... .....!.......,............'~D.P...,...(>l]O....Q.I.G...).+.9....A*Y....z...$ ....CJ.v..v...3b..Ml.._.q......#f.a.R.`.R...]..".{|S..]."._...........]L...........Q..]....=..].....k.z.#..b..."...d...]...^C|t..D.@...A;2.......^..l.x....D..!.....].$....I.>..@....e..A.....0.....d;2..4..A.6v..!..}....u.@B>..P.A dO..^.....H.|..S.........AB...U....<y...%....3beS....R.fd..........A.18......R...%..Z...U-L......a......Hp..s..=....7.h.. L.......p....._|...P.^.......}..:x&...`.NzHi@...=. ...}...F (.v.t....D....m.P.X..v...f..6...t..F.....D&..DD....f.Y..........PZx.....h.......@..(w...%....f..0.#$vQ..p.^'...Nz.X..8....9.(w....`........h.".E.Ai.4.....0.6.HP.....]|"...ah7..6..#...;
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\javamagazine(2)[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 125x132, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):4226
                                                                                                                                                                                Entropy (8bit):7.880591113615801
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:VBzQCZdNH3huPYdVNsFNCfBuJcNYK9nnp0V2+TITq:NZdNhuPYthTNYKATIW
                                                                                                                                                                                MD5:2EFF9C6E995AD134C885B4BB0132891B
                                                                                                                                                                                SHA1:35C7E3F315107B38E1E2179B432F5D4EBCCC7EB0
                                                                                                                                                                                SHA-256:4C9A37DE6893B18623F4F0F5D8BD03767CD01CCCD23BD5A0F671B888520975D8
                                                                                                                                                                                SHA-512:6E5140429C7C964B2405572044B39BE1154AC5191EFECE2CE9A386B05EA2BB1076A4A2F41C5993BB58C6FFCB6A5025AE5483F9EB24ED1469E14FA2E4F39A6890
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/assets/CONT7D6EB42C70A34F858C8582494B5B021E/native?cb=_cache_97bc&channelToken=1f7d2611846d4457b213dfc9048724dc
                                                                                                                                                                                Preview: ......JFIF.............C..............................................!........."$".$.......C.........................................................................}..!........................................J..........................!..1..AQa.."2RUq...#BS.......Tcr...$34bt.%Ds.................................1........................!.1Q...3Abq..."2a...4..............?..&;..J..K.0.[m.....YY$...It..+.....x..h..Q.L......te......=.U{..BxK....[....S..a..{...ov..;.U{..A.|\..|...\.U.2......:..e...A.r...s.....:..e....\..U.....A.r...s..T..U.2......>..e..........s.....:..e....S.}W..{.....:....[v.....-.....}....Se..P.8.M.......:M;76.*.y.v...K....w..A..50..01.....%..alu....mx.-..[^.,z...A...0...l.D........e.7!.....+..p.k..G.....okh.Sw.}..J.Y.i..J.QU..s.;....X...O..^KO..}.....i_hb...G...6..0rZ..+....-....|.....Z......N,..I....3.......d....e..a.s.a.e..P0nOQ.!....9.<~.o..8FE......rM.7......?.+...#-Z.......r+).Sq.v.mY..fbiUba..C...<IP.I.../0..H.j z.1.`.K.&e.%.y
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\jv0h[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:[TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS4 Macintosh, datetime=2011:01:25 18:25:40], baseline, precision 8, 777x95, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):33382
                                                                                                                                                                                Entropy (8bit):7.450231632805739
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:768:aFZ3oEM+kcnJbKMY24ibgwJOEtW73o79d3SP:eZ3oiJd6wJOj7QbY
                                                                                                                                                                                MD5:3AAFB427F71A50D3D6BDFFA76ABA4380
                                                                                                                                                                                SHA1:E8D483CFB9DAB0446C89666FF12A8B8E1F97CA6D
                                                                                                                                                                                SHA-256:F8E752CEAE01AF6482D110260838F393C84B8D822E53D9E24BE8D3EFCB57651E
                                                                                                                                                                                SHA-512:13DFBE537B2AC5654C2DF5F673BDB4E1CC9E54FBE457C4A05921433C1D50E45FC559C6419DB21F56071FAB9AF41ADB6B9F6B3E272B029919D1A0EFA74DF49A5B
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/img/header/jv0h.jpg
                                                                                                                                                                                Preview: ......JFIF.....H.H......Exif..MM.*.............................b...........j.(...........1.........r.2...........i....................'.......'.Adobe Photoshop CS4 Macintosh.2011:01:25 18:25:40......................................_...........................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d......................................................................................................................................................"................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?..V....ljo.l7.k..............;.......[&..z..u{.{...m....c}...8.5.2....<msK..P..2.;k.c.7......}U. H......2........{..A7.
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\layout[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):69
                                                                                                                                                                                Entropy (8bit):4.2053905817469905
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:uGK4bqf6FGs/:vf
                                                                                                                                                                                MD5:31E65444B9EF22C90B0CB11A27F64863
                                                                                                                                                                                SHA1:D2AFF3063580CD697754584D923972FBDCFABE7A
                                                                                                                                                                                SHA-256:EE8A71FAFB65F44BF73C699B1C21F8C49B9FB176700FC2807D36413E5BF8A13B
                                                                                                                                                                                SHA-512:8FC0836155CD0B01BB7002C512DFD3661605676BC3F06C5837295715EC6343821CB30CF4955B0EAD8944BB140B461DC61623685229726BD2C42AA6B14308BDC3
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_compdelivery/_cache_2094/JCOM-Footer_Detail/assets/layout.html
                                                                                                                                                                                Preview: <div class="jvf0">. {{#fields}}. {{{body}}}. {{/fields}}.</div>.
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\notice[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):8929
                                                                                                                                                                                Entropy (8bit):5.410329350680202
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:57TGITdVKY0GASJ7MF1fpem4T2J1tvFnj1E6mnNUy3cr:BGS97ASJ3T2JFnj6NUy3cr
                                                                                                                                                                                MD5:0FE49EF9F538E6269DB10F9252675236
                                                                                                                                                                                SHA1:477E7C7547BB1B41D8ECA0A5874E513BB1939C1A
                                                                                                                                                                                SHA-256:3BE11544451643FD5750391DE4723874601F17FA3D12E55EC7408AA8064495FD
                                                                                                                                                                                SHA-512:A8EFAE9E134D018C814A81AB92AB5210C798AB26F601812937C1BA4E24AF2F6B90E9DF1F18CA6F4487B95C6D188AFF61DC95D8434B8E0597769377EAFB5337BF
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: function _truste_eumap(){truste=self.truste||{};truste.eu||(truste.eu={});truste.util||(truste.util={});.(new Image(1,1)).src=("https://consent.trustarc.com/log".replace("http:","https:"))+"?domain=oracle.com&country=ch&state=&behavior=expressed&c="+(((1+Math.random())*65536)|0).toString(16).substring(1);.truste.util.error=function(l,h,k){k=k||{};var j=h&&h.toString()||"",e=k.caller||"";if(h&&h.stack){j+="\n"+h.stack.match(/(@|at)[^\n\r\t]*/)[0]+"\n"+h.stack.match(/(@|at)[^\n\r\t]*$/)[0].}truste.util.trace(l,j,k);if(truste.util.debug||!h&&!l){return}var d={apigwlambdaUrl:"https://api-js-log.trustarc.com/error",enableJsLog:false};.if(d.enableJsLog){delete k.caller;delete k.mod;delete k.domain;delete k.authority;k.msg=l;var i=new (self.XMLHttpRequest||self.XDomainRequest||self.ActiveXObject)("MSXML2.XMLHTTP.3.0");.i.open("POST",d.apigwlambdaUrl,true);i.setRequestHeader&&i.setRequestHeader("Content-type","application/json");.i.send(truste.util.getJSON({info:truste.util.getJSON(k)||"",erro
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\notice[2].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):8929
                                                                                                                                                                                Entropy (8bit):5.410329350680202
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:57TGITdVKY0GASJ7MF1fpem4T2J1tvFnj1E6mnNUy3cr:BGS97ASJ3T2JFnj6NUy3cr
                                                                                                                                                                                MD5:0FE49EF9F538E6269DB10F9252675236
                                                                                                                                                                                SHA1:477E7C7547BB1B41D8ECA0A5874E513BB1939C1A
                                                                                                                                                                                SHA-256:3BE11544451643FD5750391DE4723874601F17FA3D12E55EC7408AA8064495FD
                                                                                                                                                                                SHA-512:A8EFAE9E134D018C814A81AB92AB5210C798AB26F601812937C1BA4E24AF2F6B90E9DF1F18CA6F4487B95C6D188AFF61DC95D8434B8E0597769377EAFB5337BF
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent.trustarc.com/notice?domain=oracle.com&c=teconsent&js=bb&noticeType=bb&text=true&gtm=1&language=en
                                                                                                                                                                                Preview: function _truste_eumap(){truste=self.truste||{};truste.eu||(truste.eu={});truste.util||(truste.util={});.(new Image(1,1)).src=("https://consent.trustarc.com/log".replace("http:","https:"))+"?domain=oracle.com&country=ch&state=&behavior=expressed&c="+(((1+Math.random())*65536)|0).toString(16).substring(1);.truste.util.error=function(l,h,k){k=k||{};var j=h&&h.toString()||"",e=k.caller||"";if(h&&h.stack){j+="\n"+h.stack.match(/(@|at)[^\n\r\t]*/)[0]+"\n"+h.stack.match(/(@|at)[^\n\r\t]*$/)[0].}truste.util.trace(l,j,k);if(truste.util.debug||!h&&!l){return}var d={apigwlambdaUrl:"https://api-js-log.trustarc.com/error",enableJsLog:false};.if(d.enableJsLog){delete k.caller;delete k.mod;delete k.domain;delete k.authority;k.msg=l;var i=new (self.XMLHttpRequest||self.XDomainRequest||self.ActiveXObject)("MSXML2.XMLHTTP.3.0");.i.open("POST",d.apigwlambdaUrl,true);i.setRequestHeader&&i.setRequestHeader("Content-type","application/json");.i.send(truste.util.getJSON({info:truste.util.getJSON(k)||"",erro
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\print[1].css
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):804
                                                                                                                                                                                Entropy (8bit):5.112445136333023
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:+qAyjfRR4ZN3A7JCHWX3d+yFrYaOzekBBsuDJ/cOYuOYgIWxnoDmZ2aLAob:FreBYJCm3RZI+YbEZ0aJ
                                                                                                                                                                                MD5:4F4FA7F6D2D8B440E06729E428EF16B1
                                                                                                                                                                                SHA1:B20A0C9A0FF94FA896ABEEEF26033291EAB959A9
                                                                                                                                                                                SHA-256:852B5C251CE5A304159750A6493E562C2E30AEC62C47C9549AD9B7D3D4D2CAE6
                                                                                                                                                                                SHA-512:A645D8DB979033C4E84E7066B5F8BB9791FC90942B8E3D4347928B85E7FFFA4DAD376CC7F2AC2F8CDBD7F6D32F60BF4502A35DCCAEF8ED8F364F70EE3F771E38
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/css/print.css
                                                                                                                                                                                Preview: body{line-height:1.5;font-family:"Helvetica Neue",Helvetica,Arial,sans-serif;color:#000;background:0;font-size:10pt}.container{background:0}hr{background:#ccc;color:#ccc;width:100%;height:2px;margin:2em 0;padding:0;border:0}hr.space{background:#fff;color:#fff}h1,h2,h3,h4,h5,h6{font-family:"Helvetica Neue",Arial,"Lucida Grande",sans-serif}code{font:.9em "Courier New",Monaco,Courier,monospace}img{float:left;margin:1.5em 1.5em 1.5em 0}a img{border:0}p img.top{margin-top:0}blockquote{margin:1.5em;padding:1em;font-style:italic;font-size:.9em}.small{font-size:.9em}.large{font-size:1.1em}.quiet{color:#999}.hide{display:none}a:link,a:visited{background:transparent;font-weight:700;text-decoration:underline}a:link:after,a:visited:after{content:" (" attr(href) ") ";font-size:90%}.jvf0,.jvh0{display:none}
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\render[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:exported SGML document, UTF-8 Unicode text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):3922
                                                                                                                                                                                Entropy (8bit):5.033296563341562
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:vb2Lm3CaOFVyvB4Ex0+m0YyMPt7xAQ5MiQwbGBOb7cDDts6J:TN4c9rEF7xqwbG4b7cftsq
                                                                                                                                                                                MD5:1E621F239F2EF351D86D5E41C75126EF
                                                                                                                                                                                SHA1:FBA636F058780CD43C981DFAB65BCF40499D5C26
                                                                                                                                                                                SHA-256:86AC00A8DCFBEC6B2013EEA74A851C1FBC8FE6BB128F746293744A9DE7162196
                                                                                                                                                                                SHA-512:475432796F0CFE3219E525DEECF5825284E328C492715CE5A322272E99EF5A4090E4FD83E02FE7FD2B01248770C2692E265C58279B0E6611B8FD79328995C543
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_compdelivery/_cache_2094/JCOM-Footer_Detail/assets/render.js
                                                                                                                                                                                Preview: /**. * Copyright (c) 2019 Oracle and/or its affiliates. All rights reserved.. * Licensed under the Universal Permissive License v 1.0 as shown at http://oss.oracle.com/licenses/upl.. */./* globals define,console */.define([.."jquery",.."mustache",.."marked",.."text!./layout.html".], function ($, Mustache, Marked, templateHtml) {.."use strict";...// Content Layout constructor function...function ContentLayout(params) {...this.contentItemData = params.contentItemData || {};...this.scsData = params.scsData;...this.contentClient = params.contentClient;..}...// Helper function to format a date field by locale...function dateToMDY(date) {...if (!date) {....return "";...}....var dateObj = new Date(date);....var options = {....year: "numeric",....month: "long",....day: "numeric",....hour: "2-digit",....minute: "2-digit"...};...var formattedDate = dateObj.toLocaleDateString("en-US", options);....return formattedDate;..}...// Helper function to parse markdown text...function parseMarkdown(mdText
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\require[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):17793
                                                                                                                                                                                Entropy (8bit):5.215395984599636
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:6vCwvGiN5cMU8QatLePlko998VpSAIgujHrEDO11yy1qlMW2IP4VldNJ:0G7MU8qPlko998PhIg0HrEDM1yy1qlR2
                                                                                                                                                                                MD5:E9342BC1D3266232090154892C0637D3
                                                                                                                                                                                SHA1:AF6E361DC1E0EABD7AA52E8C0BBA133C60E5E388
                                                                                                                                                                                SHA-256:8D4B8FCEDCB0B6181A85C79254CDF85F7B97ABFCBA9DD51C93C308C9835FDEA9
                                                                                                                                                                                SHA-512:7B8D96A8A2F82125FBDD162A37E7B4ADAE474931F9BCDDEFAA1911D35147BBAA32CF3350C92363D1194505F7A6DDF72A961A907A6926F7EBAC7F37F9D5304D18
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/require.js
                                                                                                                                                                                Preview: /** vim: et:ts=4:sw=4:sts=4. * @license RequireJS 2.3.6 Copyright jQuery Foundation and other contributors.. * Released under MIT license, https://github.com/requirejs/requirejs/blob/master/LICENSE. */.var requirejs,require,define;(function(global,setTimeout){var req,s,head,baseElement,dataMain,src,interactiveScript,currentlyAddingScript,mainScript,subPath,version="2.3.6",commentRegExp=/\/\*[\s\S]*?\*\/|([^:"'=]|^)\/\/.*$/gm,cjsRequireRegExp=/[^.]\s*require\s*\(\s*["']([^'"\s]+)["']\s*\)/g,jsSuffixRegExp=/\.js$/,currDirRegExp=/^\.\//,op=Object.prototype,ostring=op.toString,hasOwn=op.hasOwnProperty,isBrowser=!("undefined"==typeof window||"undefined"==typeof navigator||!window.document),isWebWorker=!isBrowser&&"undefined"!=typeof importScripts,readyRegExp=isBrowser&&"PLAYSTATION 3"===navigator.platform?/^complete$/:/^(complete|loaded)$/,defContextName="_",isOpera="undefined"!=typeof opera&&"[object Opera]"===opera.toString(),contexts={},cfg={},globalDefQueue=[],useInteractive=!1;function
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\results[1].txt
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):8
                                                                                                                                                                                Entropy (8bit):2.5
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:x:x
                                                                                                                                                                                MD5:402E7A087747CB56C718BDE84651F96A
                                                                                                                                                                                SHA1:7CE01F6381463362CF6AEF2F843A59261E8F5587
                                                                                                                                                                                SHA-256:662EFAF46C617DDBCB8FF4A2A8F64CFFD3D93630F1003F8E66511F369B87730F
                                                                                                                                                                                SHA-512:5080D776D0B123F20E97D44472EF2343BC022105AA67FC802B71668BAEB74A81530355589D50B1142165D17EF995AEAC196B6C15136D518A1EC0ABFA13C91D10
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://kqitits7mulnqyeucsyq-pe4433-4b66e3cf2-clientnsv4-s.akamaihd.net/eum/results.txt
                                                                                                                                                                                Preview: Success!
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\trustarc-logo-small[1].png
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:PNG image data, 198 x 34, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):4197
                                                                                                                                                                                Entropy (8bit):7.949279468766667
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:cf2qaUvpL7qZRfYj76vPQ77VizJQyAcP7/IEPGD83nJ7rW0F1u2:cvtWRy76XQ7HFcPEvDOJ2n2
                                                                                                                                                                                MD5:01E1B7108FA9F6B54F403309A1616588
                                                                                                                                                                                SHA1:E3328418159B7371B64A6CFF199B2812C4D0B9C1
                                                                                                                                                                                SHA-256:91C4A6C4295F8889E8B04339A4A2C2E86D5EEF71BA808164E641D0D8A6435004
                                                                                                                                                                                SHA-512:EC6E3C4220F6675023674AAFEE3BF13C330028E7AB33333B757294575AD4002E890D7E7FDEE35D94E6388C2472413AFF2CB5B0A9B21CD0E19D0577A7B530BBA2
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/images/trustarc-logo-small.png
                                                                                                                                                                                Preview: .PNG........IHDR......."......N......sRGB.........IDATx..\.x.E...........V......!..+..DI....Q..Z%.......uU.]5.b.(B.uQ...*.P.C%.`""..@...z..K^..Q.N..........D^.4.i....O...<.x..4.i.....p...v...,..L")...H.W.h)i.UH.")ZI![..$A...>..U>....W.............1fU......A.!.%..R..S...#.h7.t....'.#4....K.&.,=d{..i..h..cp.G.8.EY.....Ak..^....q.6..\..XFI..n.;\h..4P.4P.1.7^]...}..Z...v.M..Z....@..%O.....9.f..JK.| ...c.#..o..^.E..].!...#GF5h.@N.>..Nt..v...3.".v.,..2.~H.i..#..s..$.1..]GG,&g..A./h.=........B.3<..i`.a....6...o....M..&.8...s.=.!.*F!...U01...*i.v.t.,.e....Q..O..o..<...&..).c......~.....7V..U=....P.1...n<....|].e.d.C..~.\.f...Y.d.(.4.S#....u5.mkN.d.o.....Q.P.$$$\.....~...9sr...rFyy9O.N.4.@...y.y..].v.mM+**...,.....il.......|.o...R7=...........!...V@.../11q.pl.GKeh...l.r...).U..}Q..PG...?I'...e.j......P|.`w.......~..A..0...y...._....Q.p....@..<x..s.f.H.l[...y3.j..gz.|.C..."....$77w.*.-.S..ftt.}...{.....t.5.<y...cV.m\R...<...s.]7.*;9.......p..}..q...T..!
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\1.cache[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):19432
                                                                                                                                                                                Entropy (8bit):5.580344910706707
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:EK6hVeThiUgz4Y5Xhsxt8gCxGe6VtWNBK6Z+JA3jviFlJecNKp139J/ozNJMU:EA97gUz8lxktuKA3DizTyo
                                                                                                                                                                                MD5:55C52117BF9BC174A987D07FCD7297D5
                                                                                                                                                                                SHA1:743E92AD8B74903117073C161A376FEEC4BFE6A2
                                                                                                                                                                                SHA-256:3AC30D3684EF5FAC4D54977D24566AEB45B56D17640DD29BC778A44118B7A822
                                                                                                                                                                                SHA-512:2CB23BC98BBD9C7C9DC73791903E44E87DE5C6C30A4A9FE55B40278E016505AA7CD2A337A89F570B272683BAADE1AA492C687707C9B5BE74454F87FC1126CF54
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/defaultpreferencemanager/deferredjs/0D070042D9C67A68E1A4BF804E6E0E06/1.cache.js
                                                                                                                                                                                Preview: function lp(){}.function asb(){}.function dsb(){}.function gsb(){}.function psb(){}.function aub(){ec()}.function eub(a){this.b=a}.function iub(a){this.b=a}.function Lnb(a){this.b=a}.function Onb(a){this.b=a}.function Snb(a){this.b=a}.function jsb(a){this.b=a}.function vsb(a){this.b=a}.function Ltb(a){this.b=a}.function Otb(a){this.b=a}.function Ttb(a){this.b=a}.function Ytb(a){this.b=a}.function msb(a){ec();this.b=a}.function lub(a){ec();this.b=a}.function _ab(a,b){Dl(a.Qd,b)}.function v7(a,b){Nk(a.Qd,b)}.function x7(a,b){Ok(a.Qd,b)}.function Xtb(a,b){a.b.P=b;Wrb(a.b.s,b)}.function uMb(){uMb=Q5b;YPb(NK.e)}.function Dl(b,a){b.selectedIndex=a}.function ftb(a,b){a.o=b;Ri(4,new Etb(a,b))}.function Zrb(){d8(this,ssb(new tsb(this)))}.function kp(){kp=Q5b;jp=new Ep(xec,new lp)}.function Zab(a,b){Yab(a,b);return a.Qd.options[b].value}.function jtb(a){Rsb();return a!=null&&a.length>0&&!yWb(a,P7b)}.function Yab(a,b){if(b<0||b>=a.Qd.options.length){throw new UTb}}.function atb(a,b){a.O=b;sPb=b;a
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\6.cache[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):6773
                                                                                                                                                                                Entropy (8bit):5.516154253697039
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:vPon1HkyuHEi2ziv3Hg70TnmK/SEAapZ4Ru03jf0cyD/Nu0s5jAQVLuxzbi:XoUEU3EJK/17HENxyDFmWI+i
                                                                                                                                                                                MD5:744C2D6A085D074CF6AB0BD7A9AAF6FC
                                                                                                                                                                                SHA1:6FF8D54DC22F2B7B53015D2FBD28372FAA4E07B1
                                                                                                                                                                                SHA-256:3307962B53E30C3BE5CC8FC3145EE53E703FE69C37E9F289640C99BE2D55272E
                                                                                                                                                                                SHA-512:B3D2716A44DD773E84A899E0B86F9A53C2F5493362F4D831A5EB27766B4E52DFA53160721BACBF68B8195B386BA5BB337F17C07DD8753C9F51EE386666A498FC
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/defaultpreferencemanager/deferredjs/0D070042D9C67A68E1A4BF804E6E0E06/6.cache.js
                                                                                                                                                                                Preview: function Kt(){}.function vrb(){}.function frb(a){this.b=a}.function irb(a){this.b=a}.function mrb(a){this.b=a}.function prb(a){this.b=a}.function srb(a){this.b=a}.function yrb(a){this.b=a}.function Atb(a){this.b=a}.function Gv(a){throw new Tu(a)}.function Ddb(a,b){Cdb();a.Ke(a.Ce()+b)}.function XMb(a,b){YMb(a,Cgc,(yv(),Fv(b)))}.function Cdb(){Cdb=Q5b;yt((xt(),xt(),wt))}.function yt(a){!a.b&&(a.b=new Kt);return a.b}.function oi(b,a){b.setDate(a);return b.getTime()}.function ri(a,b,c,d,e,f,g){return new Date(a,b,c,d,e,f,g)}.function Uu(a){bk(this);this.g=!a?null:Sh(a);this.f=a}.function kt(a){it();var b,c;b=yt((xt(),xt(),wt));c=null;a==b&&(c=gw(ht.pg(Llc),77));if(!c){c=new jt(Llc);a==b&&ht.qg(Llc,c)}return c}.function Fv(b){yv();var c;if(b==null){throw new aWb}if(b.length==0){throw new mVb('empty argument')}try{return Ev(b,true)}catch(a){a=YP(a);if(iw(a,11)){c=a;throw new Uu(c)}else throw a}}.function brb(a,b){spb.call(this,a);this.i=new BLb;d8(this,Qrb(new Rrb(this)));this.q=a;this.e=b;
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\EuPreferenceManager[1].css
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):27745
                                                                                                                                                                                Entropy (8bit):5.042943398466011
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:xDMuxcCdWdamlRHq038IiBVT6lXcyfBWfTbQe97jl7yE:R1xcC3mlwIirT6lMEBKEeFIE
                                                                                                                                                                                MD5:182FC39AFF61D22162DFD04D282791E2
                                                                                                                                                                                SHA1:737ED8C224ED9313F5325AEC984CDE6043974C51
                                                                                                                                                                                SHA-256:1EA22EF5CC12712E650AC15269E8E7B75904F47246CE6EB04BF0FCD42F8BED77
                                                                                                                                                                                SHA-512:C20168EDB22C2B2AA9454150EB7DEBB55373C7999E294482AB540DD550BF4FE443D05EA45A62D2816F59D5C4C4F11EDD4E17C23916B61787670688901828F6F9
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/EuPreferenceManager.css
                                                                                                                                                                                Preview: html, body, div, span, applet, object, iframe,.h1, h2, h3, h4, h5, h6, p, blockquote, pre,.a, abbr, acronym, address, big, cite, code,.del, dfn, em, font, img, ins, kbd, q, s, samp,.small, strike, strong, sub, sup, tt, var,.b, u, i, center,.dl, dt, dd, ol, ul, li,.fieldset, form, label, legend,.table, caption, tbody, tfoot, thead, tr, th, td {. background: transparent;. border: 0;. margin: 0;. padding: 0;. vertical-align: baseline;.}..body { font-size: 12px; font-family: "Helvetica Neue",Helvetica,Arial,sans-serif; line-height: 20px; }.body.main { background: url(images/bg.png) no-repeat center 0; line-height: 20px; }.body.pbg { background: #fff url(images/pbg.jpg) repeat-y 1px 0; }.input, textarea, select { font-size: 12px; font-family: 'Lucida Grande', Arial, Helvetica, sans-serif; }..../***INDEX.HTML***/..mainheader {}..mainHeader h1 { color: #2C2D31; font-size: 18px; display: inline-block; }..accept-decline-buttons { float: right; }.#accept_all_button{ background: no
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\JavaAlice[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 125x132, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):3811
                                                                                                                                                                                Entropy (8bit):7.850192369179497
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:YaKeVfWUtV7GNVz9Bu8Qydxh6zzvupXg8B:LfWUniNV5h6zzvYXg8B
                                                                                                                                                                                MD5:F26405E1D9347863352B5E7CEA270155
                                                                                                                                                                                SHA1:192894C813979D6ADB08BD2BECE0D0A5DEBFE96A
                                                                                                                                                                                SHA-256:70145461B9DD7661B2FDE95B572262B9A4AC4044FF9C4D99450A5B1CEC93A1CA
                                                                                                                                                                                SHA-512:94F753BA1F9E6512700DDAA6CD8559109C31B55C2A4B546A5708F75D5CADC175AF1CB438498FE62E94192EFC45B1F88097F4A27CC74340BCCD3EBF45FA12C6CC
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/assets/CONT9D14685A7F0F4C7782D8B91D06E60E37/native?cb=_cache_97bc&channelToken=1f7d2611846d4457b213dfc9048724dc
                                                                                                                                                                                Preview: ......JFIF.....d.d.....C..............................................!........."$".$.......C.........................................................................}..!........................................E..........................!....1Aq"3QRUVa.....246su...#$r...B.S...................................0.......................1..!A.Qa."q..#.......B.............?..J.:e..x...%.[m...8..NV.r.u.^O;.......o...N.'......i..y.u.c|..Y....y.u.c|.ry.p]}X.&.....w.._V7.'......i.....y.u.c|.ry.p]}X.&.....w.._V7.'......i.....y.u.c|.ry.p]}X.&...1....$w..";.(}-.-.h.....t.'hdU*..'j....?n.o...[.T...........8..Gf..)>.j..zOed.:!.\..r.......;..qLT...........8..v_...f.....VOs....O./?.~....c.D.P.H.R..i..$a..m.+s.x..#......$o..Uu't..Bc...z.....<|.!;.:#<=OySe..e*.R......N.k.h..f..$#.<.........u.A.e.E......\.Q...#.....88.."..........R}........tCb.i!2.JQ.E..O@.....oN^e.Q?.DEl....dxMz~..I.>...\R...s.!.\)K.c.... k...&M...q....N.^pn%j..ki.';..[4.Q........^....n.b[.t\..7
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\Oracleacademy(2)[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 125x132, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):4900
                                                                                                                                                                                Entropy (8bit):7.90049937566647
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:XLElCYEO3u1fQ8i0id8UIu3HOwqi/PxbCvGTGK9Q5Sr0gwFC7ofJK:X4lCYEYu148fyuwr0v8ZGpFSofJK
                                                                                                                                                                                MD5:CFE0F1B70C44984498BCBB32E3913E28
                                                                                                                                                                                SHA1:4C71674AB77C183746263886A86051DD6DC7C3DB
                                                                                                                                                                                SHA-256:3A09A1B1EA0D785CA29174C25AF6F42656831898E9B09FC0B2AFB25A5E82A068
                                                                                                                                                                                SHA-512:58B02CF5537D7776468D010992589A57B64DA47ABEF45FD92F83A3423366E5C94D48903216A10A6401634FD7C0E2047D8DE4A014BD258414250675E6E252C56B
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/assets/CONT862DE06B4B724C38B1F5D3FA3EB08BFB/native?cb=_cache_97bc&channelToken=1f7d2611846d4457b213dfc9048724dc
                                                                                                                                                                                Preview: ......JFIF.............C..............................................!........."$".$.......C.........................................................................}..!.........................................X...........................!1...."AQaq...#25BSUt.....$RTbrs.......%3C......467Dcu.....................................3.........................!.1Q.A..."BSTq.......a..............?..v..<....1.R]e......1.I+a.K.1.*5.......X.S..M,.x.u..:=4.....7....K;.;..c}N.M,.x.u..:........X.S..K;.;..c}N.=4.....7....N....X.S.$....w.%.[:v.k...\d..g..u0\..O.y..."5...k9...Q...Q...p;..q@qj.j.V.s...c............%>^.@w...k.n.b..[..u..1..j.)&.A.%..."V..nO.&+%.1...i.....4.0....Z*Y.*?f.v....4..4.E.Q@.P..WN_5M.N...Ls.m'..Q<... U...cm....:......`....{...(G.....%K..Z..t...)..iI.$...O....\..vk.=.e.s.....8...z..@.i....$..+.,..@........'....B.6.A.6.4.HD.....a.s.A..hQ.e.=..U3`.pfz..2Tw.IASJDD..J....9q..r......7[f..7gK...1...o....%......+a.-9.d'.Z.^g^."T..;[...y..9..N?
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\W3ZUK9WP.htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):5147
                                                                                                                                                                                Entropy (8bit):5.154022406877804
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:r8qy7YxdYhAVYYn3MCysvq15MwxXkqnSqcO/2C1gigij:r8/0xChAaJvGqtx0qnSq9/bj
                                                                                                                                                                                MD5:14C0A5A0AF9411825A689ADE15E42B51
                                                                                                                                                                                SHA1:F94CC78F1D464582CEF3217C183C7C3B012E54A3
                                                                                                                                                                                SHA-256:5D59D71FA30604E26C815B2BCFEA777BEF1564467E2FF9B1B4DC45CA2EE0F6FE
                                                                                                                                                                                SHA-512:E046C5DF4CEA8E473ACAB8BE624BB30946D03F4CEEC81A03E1826EAD692FE704682E4097E9E6D39CCCC4BD469205E241A6FFEE7DF84082945D8C1A5CE6F7C839
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/?type=oracle6&site=oracle.com&action=notice&country=ch&locale=en&behavior=expressed&gtm=1&layout=default_eu&irm=undefined&from=https://consent.trustarc.com/
                                                                                                                                                                                Preview: <!doctype html>.<html>.<head>.<meta http-equiv="content-type" content="text/html; charset=UTF-8">.<meta name="viewport" content="width=device-width, initial-scale=1.0" />.<link href="images/favicon.ico" rel="shortcut icon" type="image/x-icon">.<title>TrustArc Preference Manager</title>..<meta name="keywords"..content="online trust, online privacy, email privacy, email safety, consumer privacy, brand trust, online seals, prevent spyware, privacy alert" />.<meta name="description"..content="TrustArc Cookie Consent Manager helps ensure online privacy compliance." />..<script type="text/javascript">..var baseCDNUrl = "//consent-st.trustarc.com/get?name=";..var QueryString = function() {...// This function is anonymous, is executed immediately and ...// the return value is assigned to QueryString!...var query_string = {};...var query = window.location.search.substring(1);...var vars = query.split("&");...for ( var i = 0; i < vars.length; i++) {....var pair = vars[i].split("=");....// If fi
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\controller[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):29779
                                                                                                                                                                                Entropy (8bit):5.384616840808838
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:2tAXfo1yc8Z4n7hR0RQRRVVZxWJTSF1sR1ECaZq4kzer/JKva3M:Nbc8Z47zacVVZ8i1sReAHt
                                                                                                                                                                                MD5:4E7A74127C680C9953242315466999E9
                                                                                                                                                                                SHA1:E25BC8DA188D9D69A3A3276F4E834F871C8B2F7E
                                                                                                                                                                                SHA-256:E27E66F37F0DE43B16DB3E9D60D0D3E537C09E55C84D19B2E42BA63308795478
                                                                                                                                                                                SHA-512:3AA848EED23083121972B5F864E3402BCA05BA93CC32DC9E0AFC1A8E59B31EB55B122F5493F423EE6043F1991A8D9F4EDC29B5E22EE84157173767F0CD080D26
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/controller.js
                                                                                                                                                                                Preview: "use strict";var SCS=window.SCS||{};SCS.sitePrefix=SCS.sitePrefix||"/",SCS.data={pageId:null,siteInfo:null,structure:null,structurePages:null,basePageModel:null,baseSlotReuseModel:null,pageModel:null,pageLayout:null,mobileLayout:null,navMap:{},navRoot:null,placeholderContent:null,startProgressTimer:null,pageTimeoutTimer:null},SCS.performance={timers:{}},SCS.xmlhttp=new XMLHttpRequest,Array.isArray||(Array.isArray=function(e){return"[object Array]"===Object.prototype.toString.call(e)}),String.prototype.trim||(String.prototype.trim=function(){return this.replace(/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,"")}),String.prototype.startsWith||(String.prototype.startsWith=function(e,t){return t=t||0,this.substr(t,e.length)===e}),SCS.preInitRendering=SCS.preInitRendering||function(){},SCS.initRendering=function(){this.data.startProgressTimer=setTimeout(this.onStartProgress,2500),this.data.pageTimeoutTimer=setTimeout(this.onPageTimeout,3e4),this.setCacheKeys(),this.processSitePrefix(),this.isPrerende
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\get[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):2004
                                                                                                                                                                                Entropy (8bit):5.228582846237988
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:48:Qd+wePCCFJw2Gb7IhVkAvm7CJQZfuPEgOpcGbpCBOxm:QdjeqCF0TAvmOJ/Bos
                                                                                                                                                                                MD5:EB36752D424D4B17D5C0786DA41ACF66
                                                                                                                                                                                SHA1:EBCE41EF9C2581EA61E5C856885008A3E88E55FD
                                                                                                                                                                                SHA-256:BD478D1E075F071CA0F0E7F3E27E4C22D27831B23DF86DD6D0F7A37C38263B0E
                                                                                                                                                                                SHA-512:E071D33A9B303113E821A3626EBF8CA0E45B0241251862C521A42C68E5ED73C75FD0F18144517569940606736733B7BD2F974791DB10167606C610A838F5A231
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent.trustarc.com/get?name=crossdomain.html&domain=oracle.com
                                                                                                                                                                                Preview: <html><head><script>!function(){var e,t,a,r,n,s="truste.consent.",i=function(e){var t,a={},e=a._url=e;if(e=(a._query=e.replace(/^[^;?#]*[;?#]/,"")).replace(/[#;?&]+/g,"&"))for(e=e.split("&"),t=e.length;0<t--;){var r=e[t].split("="),n=r.shift();a[n]||(a[n]=r.length?decodeURIComponent(r.join("=")):"")}return a}(location.href).domain;function o(e,t){var a=JSON.stringify({source:"preference_manager",message:e,data:t});top.postMessage(a,"*"),parent.postMessage(a,"*")}function c(e){var t=null;try{var a=self.localStorage;t=a.getItem?a.getItem(e):a[e]}catch(e){}return t&&JSON.parse(t)||null}function p(e){try{var t=s+e,a=c(t);if(!a)return null;if(new Date(a.expires)<new Date)try{return self.localStorage.removeItem(t),null}catch(e){return null}return a}catch(e){}return null}function l(e,t){var a=c(e);!t.popTime&&a&&a.popTime&&(t.popTime=a.popTime);var r="string"==typeof t||t instanceof String?t:JSON.stringify(t);try{var n=self.localStorage;n.setItem?n.setItem(e,r):n[e]=r}catch(e){}}void 0!==i&&o
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\items[1].json
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):7214
                                                                                                                                                                                Entropy (8bit):5.647875097933699
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:9q0XkZ4JddBzuclksHEqpK5lf35hS5hf5hO5h4Y:g0xJddtFlksHEWK5lf3PSPfPOP4Y
                                                                                                                                                                                MD5:DE149FC4558B3C853E30AABCE0DC7F56
                                                                                                                                                                                SHA1:2F7B55A7D6F62F63CF2760B93FFCA5BE04F373BB
                                                                                                                                                                                SHA-256:8C9344A56407F0903D36DC274EBBD3D33D7014DB50BE118687F5F2D21661A6D7
                                                                                                                                                                                SHA-512:89CA9A98A46A7D19057D43E50E6A2BF4B6D8826C708BF643031D2997822FB63913F257763EBCFA297B12D39A5DDA53947264362E93B17E7EF42524427B17C3B6
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/items?q=((id%20eq%20"COREEACA6644ABED46228A54322C5E14161D"%20or%20id%20eq%20"CORE1CE64AD7F2E944B68F223DEBB0AF616A")%20and%20(language%20eq%20"en"))&channelToken=1f7d2611846d4457b213dfc9048724dc&cb=_cache_97bc
                                                                                                                                                                                Preview: {"hasMore":false,"offset":0,"count":2,"limit":2,"items":[{"translatable":true,"createdDate":{"value":"2020-05-18T21:48:54.443Z","timezone":"UTC"},"name":"Home content","description":"","language":"en","links":[{"href":"https://orasites-prodapp.cec.ocp.oraclecloud.com/content/published/api/v1.1/items/COREEACA6644ABED46228A54322C5E14161D","rel":"self","method":"GET","mediaType":"application/json"}],"id":"COREEACA6644ABED46228A54322C5E14161D","updatedDate":{"value":"2021-04-22T20:08:16.263Z","timezone":"UTC"},"type":"JCOM_SimplePage","fields":{"omniture":null,"keywords":["java","downloads","software","java runtime","jre","java download","download java"],"Webreference":null,"addBodyTags":" Begin SiteCatalyst code version: G.5. --> <script language=\"JavaScript\" type=\"text/javascript\"> var s_channel = \"javac:Home\"; var s_pageName = \"javac:Homepage\"; var s_prop19 = \"en_javac:Homepage\"; var s_prop20 = \"Home_Pages\"; // var s_prop21 = \"180X150-728X90\"; var s_prop21 = \"180X
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\loading[1].gif
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:GIF image data, version 89a, 31 x 31
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):2608
                                                                                                                                                                                Entropy (8bit):7.212558742538955
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:48:opmEwU9deVtdpwUCiesszQwUCivxn3wUCivjvwUCiPF3BZBwUyysnjUTROL:orwmcdpwfBsszQwfSx3wfSjvwf4FRnwj
                                                                                                                                                                                MD5:394BAFC3CC4DFB3A0EE48C1F54669539
                                                                                                                                                                                SHA1:5640EA4D0EBA1C390F587EC69463C9A5196B7FA2
                                                                                                                                                                                SHA-256:EB7CFD3D959B2E09C170F532E29F8B825F9BC770B2279FDE58E595617753E244
                                                                                                                                                                                SHA-512:A2B86BFEBA74FEAE3247C1C53BBC4C4D922936BC099FA8D8487B20AD0B699EC5D279A94F972BA478000CBF4053BA08FFBB2CA5BA82EE01B680F5033B148BBD69
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/images/loading.gif
                                                                                                                                                                                Preview: GIF89a................................................................666&&&PPP...ppp...VVV...hhhFFF......HHH222..........................................................................................!..NETSCAPE2.0.....!..Created with ajaxload.info.!.......,...........@.pH......b.$..tx@$.W@e..8>S...-k.\.'<\0.f4..`...../..yXg{.w.Q.o..X.........h...Dd....a....e.Ty..vky.BVe..vC..p..y..C.yFp..Q.pGpP.C.pHp..pIp....pJ......e......X.......e.....p...X....%.ia6....'_S$.jt...EY.<..M..z..h..*AY. ....I8..q...J6c.....N..8/...f...s......!.......,...........@.pH......P ...tx@$.W...8L......'...p.0g...B.h..ew....f.!.Q.mx[.........[... .Dbd...j..x....B..iti...BV[..tC.......f..C.....c..C...gc..D....c.......c.......[...cL...cM...cN..[O...fPba..lB.-.N.....!..t....."..`Q...$}..`.........b..J,{.q.G.....V.....x.I....:A..!.......,...........@.pH......P ...tx@$.W...8L......'...p.0g...B.h..ew....fusD.mx[.........[e.iCbd...j...X.T..jif^.V[..tC..[...f..C.fFc..Q.[Gc..D.cHc...cIc..B.cJ..
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\render[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):5443
                                                                                                                                                                                Entropy (8bit):4.986757619365243
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:42wPg4jiZqTxEE2jSBOyOLpoVuM9gXlyVTakH:4VPgCiZWR2eBOyepoVuM9SAaW
                                                                                                                                                                                MD5:1AB11CB35BFDFB48448EA5594C3BC5AE
                                                                                                                                                                                SHA1:A6D9DE08907DEA946248751637E7592AF59DA9CF
                                                                                                                                                                                SHA-256:B719089A5754F4FEC74C1A01E8AD645CBC8841C00FF1362FF31EDEC9EE7D4C1A
                                                                                                                                                                                SHA-512:7DA26591CC62F8886F8AB76AB134594ED6899553D8C54FC2713FEB9199716026BE1FE9B75B50843505A6B3677A30852A66874ED456EB60E94A1039C1B629A523
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_2094/_compdelivery/JCOM-Header/assets/render.js
                                                                                                                                                                                Preview: /* globals define */.define(['knockout', 'jquery', 'text!./template.html', 'i18n!nls/header'], function(ko, $, sampleComponentTemplate, head) {.'use strict';.var ComponentViewModel = function (args) {....// Boilerplate to help us store....var self = this,.....SitesSDK = args.SitesSDK;.....// Store the args. Some times we need these for various functions.....// For example the viewMode will tell you whether you are in edit or edit mode....self.mode = args.viewMode;....self.id = args.id;.....// Define the observables that we are binding....self.showLogo = ko.observable(false);....self.showNav = ko.observable(false);....self.showSearch = ko.observable(false);....self.navLinks = ko.observableArray([]);....self.srchDefault = head.Search;.....// Define any computed functions, which are essentially read only observables.....// This computed function returns the url of the image we were passed......self.resetNav = function() {.....self.renderNav();....};.....self.renderNav = function() {.....s
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\results[1].txt
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):8
                                                                                                                                                                                Entropy (8bit):2.5
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:x:x
                                                                                                                                                                                MD5:402E7A087747CB56C718BDE84651F96A
                                                                                                                                                                                SHA1:7CE01F6381463362CF6AEF2F843A59261E8F5587
                                                                                                                                                                                SHA-256:662EFAF46C617DDBCB8FF4A2A8F64CFFD3D93630F1003F8E66511F369B87730F
                                                                                                                                                                                SHA-512:5080D776D0B123F20E97D44472EF2343BC022105AA67FC802B71668BAEB74A81530355589D50B1142165D17EF995AEAC196B6C15136D518A1EC0ABFA13C91D10
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://84-17-52-78_s-23-32-238-131_ts-1620317361-clienttons-s.akamaihd.net/eum/results.txt
                                                                                                                                                                                Preview: Success!
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\screen[1].css
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):20825
                                                                                                                                                                                Entropy (8bit):4.994143793467963
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:UoURDmGjjKJzOh+7V6iKFd7FAtDHFxQFW23:WiGj+zOI7Vq7FAlFSFV3
                                                                                                                                                                                MD5:A74B0D2CD7E657A5CB55B9BC1B6985C3
                                                                                                                                                                                SHA1:5D4CDC3E796E06B2542450F4D0533F02E26D9C09
                                                                                                                                                                                SHA-256:8CF75A638B4DB506BC4B28FB12AB33432AC5DA8DD775EC721B4627F8D50246A4
                                                                                                                                                                                SHA-512:547331AC9047504133D53AED25675BAC90A3FB0FD166E536C23BD0EBD07DDEA75B586428A8E6C4F280A97C66293DE3286A12A8C3FE8AA669C7A8C01202C034ED
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/css/screen.css
                                                                                                                                                                                Preview: html, body, div, span, object, iframe, h1, h2, h3, h4, h5, h6, p, blockquote, pre, a, abbr, acronym, address, code, del, dfn, em, img, q, dl, dt, dd, ol, ul, li, fieldset, form, label, legend, table, caption, tbody, tfoot, thead, tr, th, td {. margin: 0;. padding: 0;. border: 0;. font-weight: inherit;. font-style: inherit;. font-size: 100%;. font-family: inherit;. vertical-align: baseline.}..body {. line-height: 1.5.}..table {. border-collapse: separate;. border-spacing: 0.}..caption, th, td {. text-align: left;. font-weight: normal.}..table, td, th {. vertical-align: middle.}..blockquote:before, blockquote:after, q:before, q:after {. content: "".}..blockquote, q {. quotes: """".}..a img {. border: 0.}..body {. font-size: 75%;. color: #222;. background: #fff;. font-family: "Helvetica Neue", Helvetica, Arial, sans-serif.}..h1, h2, h3, h4, h5, h6 {. font-weight: normal;. color: #111.}..h1 {. font-size: 3em;. line-height: 1;. margin-bottom: .5em.}..h2 {. font-si
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\theme.min[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):86057
                                                                                                                                                                                Entropy (8bit):5.293478370265226
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:1536:X+SiP1GohxDDogabxkHB4SpcEkMj/t7KZ/52uFGEeJul1BgJ2tM5Po+bQuo4kQ4H:iNV7KZMoWISJQMdkuo4kQ47GK/
                                                                                                                                                                                MD5:EB519B683BF8B78B57BBCCB92F2B6FFA
                                                                                                                                                                                SHA1:02906CED3B1DE28743DCB6CB7BF09F9E89E1FDAC
                                                                                                                                                                                SHA-256:7ED7C6A415CE8873EE944D54FBD3B886CC9BB0D62B5B6A84E05EBE963C4005AD
                                                                                                                                                                                SHA-512:29594674F002C9080CD277950EC1C8DB87DA77949C1885AA8A56BF2742FADCB5DD9B240BC3C5DB0F9AF95EDA84CD1044F8CF497B96FE8BD4F75556A263FFECB1
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/js/theme.min.js
                                                                                                                                                                                Preview: !function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(C,e){"use strict";var t=[],E=C.document,r=Object.getPrototypeOf,s=t.slice,g=t.concat,u=t.push,i=t.indexOf,n={},o=n.toString,h=n.hasOwnProperty,a=h.toString,l=a.call(Object),v={};function m(e,t){var n=(t=t||E).createElement("script");n.text=e,t.head.appendChild(n).parentNode.removeChild(n)}function c(e,t){return t.toUpperCase()}var f="3.2.1",k=function(e,t){return new k.fn.init(e,t)},p=/^[\s\uFEFF\xA0]+|[\s\uFEFF\xA0]+$/g,d=/^-ms-/,y=/-([a-z])/g;function x(e){var t=!!e&&"length"in e&&e.length,n=k.type(e);return"function"!==n&&!k.isWindow(e)&&("array"===n||0===t||"number"==typeof t&&0<t&&t-1 in e)}k.fn=k.prototype={jquery:f,constructor:k,length:0,toArray:function(){return s.call(this)},get:function(e){return null==e?s.c
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\v1[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):71813
                                                                                                                                                                                Entropy (8bit):5.312055266421633
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:1536:tmTkVZQm0BKGEJcnJGqo01KvJ/xKIqarUKYkI8obCJwl8KBwrAcE4/I36sn:gi10BKGiL0svJ/xKLarrYkI8HJwywvn
                                                                                                                                                                                MD5:74A54934262638C24F2C3C7FC0078746
                                                                                                                                                                                SHA1:A60AD452C59E734B476B7CA03D95B2D68BE92314
                                                                                                                                                                                SHA-256:8952CCC09C989C9864DC4D80FC2FF261A1AEC5CE7E02AD9BFE4D0C71B51928A0
                                                                                                                                                                                SHA-512:C2D17807CF0F0098AFC21B05BC4E391239C976BD450130D36E14B90C35EAFF8C40D92429F65F37130ABA78C6942F97456CD623DE2571D59F7A020C47BBB8AD7E
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent.trustarc.com/asset/notice.js/v/v1.7-1745
                                                                                                                                                                                Preview: function _truste_eu(){function u(){var h=truste.eu.bindMap;h.feat.isConsentRetrieved=h.feat.crossDomain?h.feat.isConsentRetrieved:!0;if(!u.done&&h.feat.isConsentRetrieved){u.done=!0;truste.eu.ccpa.initialize();truste.eu.dnt();var l=function(){var a=truste.eu.bindMap;if(a.feat.consentResolution){var b=truste.util.readCookie(truste.eu.COOKIE_GDPR_PREF_NAME,!0);if(b&&(b=b.split(":"),!RegExp(a.behavior+"."+a.behaviorManager).test(b[2])&&(/(,us|none)/i.test(b[2])||"eu"==a.behaviorManager&&/implied.eu/i.test(b[2]))))return!0}return!1};.truste.util.fireCustomEvent(h.prefCookie);var a=function(){var a=(new Date).getTime(),b=truste.util.readCookie(truste.eu.COOKIE_REPOP,!0),c=truste.eu.bindMap.popTime;return c&&c!=b&&a>=c}();a&&(h.feat.dropPopCookie=!0);h.feat.isDNTOptoutEvent?h.feat.dntShowUI&&"expressed"==h.behavior&&(truste.eu.clickListener(truste.eu.noticeLP.pn,!0),truste.eu.msg.log("consent",h,h.messageBaseUrl)):null!=truste.util.getIntValue(h.prefCookie)?("expressed"==h.behavior&&(a||l())
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\JavaGreenfoot[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 125x132, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):3629
                                                                                                                                                                                Entropy (8bit):7.847576284308009
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:jAyzHk1IBRBpKMGLWfUOOyDFvKk2j4qm6mV9PUks4tiDY:l7fjKdyfUoDgjqXr04tiE
                                                                                                                                                                                MD5:D28BC5EA9F5E4C6F983F012E071B2A21
                                                                                                                                                                                SHA1:E76684B1DDC5D7BA3AE0BDB53C09893E1D4DA12B
                                                                                                                                                                                SHA-256:73599CAFDE30FB5C1FC726A0D09595C7D5E681F670661990747B3294F8EF5746
                                                                                                                                                                                SHA-512:4B91C49BD298EF4103D1127DA1D17EC3B75661105164D93AB5A5041192B231654BD84D4483AE24CFC82A4EFE586582EB5013A19AE24E7AA607F5882361E553F6
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/assets/CONTE27F21C0DDA34CE985D9F7C9D23FC8B0/native?cb=_cache_97bc&channelToken=1f7d2611846d4457b213dfc9048724dc
                                                                                                                                                                                Preview: ......JFIF.....d.d.....C..............................................!........."$".$.......C.........................................................................}..!........................................G..........................!.1.."QUq.346ARasu........#B..$r.2b.%S.............................................................1.!A..Qq......."2...............?...i=5R.e.....e..K.@..n..I...)....f&.r........-.`.Ot.W..0..6S.?U.%...)....f.7..{....e=.._b[.....Ot.W..0l..~..K}.X..)....f...O.}.o....e=.._b[........-.acp.Y..:....&....}Y.CB.B....$.Z..4.9..QK../N...>]...s.!...E(.N8...J..s...j.&.P...l.hR....Xis.t...#.N.t...{.ai)v_~..}...H.(%I..p..$OF#..\4F..p[....}D....u~....H..;..@...=X..Q....k..k..I.GH.f...Y....H.!.{k.....8..+..2.s.J.Z.HY.M..>Q.(......a4.L.%3.f.%.N8.7.l.`.H .e.$.4....Fys._......NSj\.s..>....;'/>.<./p.R.....}M.-#....Q,...74K<#d...H...KZ;.~..X......Ki..G.:.....OV...,.....t..j...H|..:$.r.@..B...C.,>..d....qx.SV...N.mJ.je..i.eJ.S.5....2.....
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\config[1].json
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):4375
                                                                                                                                                                                Entropy (8bit):5.0285723246081035
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:48:Y18rrpXYGBc7ay+WvnNtiwhbxuToLZdnU/tcst4vEv2rQEv22UUtVtYtqPqrtymn:WpiMcTBcA4vBbLaqyJfVVXTPLW+p
                                                                                                                                                                                MD5:D05A005275A66A0F900D9BC9604ACACC
                                                                                                                                                                                SHA1:4B8EA2F8E6F63DCD3F885416BAD2C0B5CF48CDC3
                                                                                                                                                                                SHA-256:3F7727C3C2DEA3AE209DA3F92EE67C71D8A11405CCDBD69F1C1CBB0B89933626
                                                                                                                                                                                SHA-512:4C9BBC622ABAD98ECEA6F870029FDE924D4F9F53068170C4DA55E54B8780F93019CAF604AD2EC13004D6057FB50D4EC4A4F59CE4DFBA994D68F4C6262D7815D4
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: {"h.key":"T79A9-GDDN2-93ZD5-M6HUR-X83QX","h.d":"java.com","h.t":1620317358868,"h.cr":"7de682beec3597a57fbc8939e78cb7e29aa85aaf","session_id":"ae3e2d6b-71bd-46bd-a521-98c506a66838","site_domain":"java.com","beacon_url":"//6852bd12.akstat.io/","autorun":false,"instrument_xhr":true,"beacon_interval":60,"BW":{"enabled":false},"RT":{"session_exp":1800},"ResourceTiming":{"enabled":true,"splitAtPath":true},"History":{"enabled":true,"auto":true},"Errors":{"enabled":true,"monitorTimeout":true,"monitorEvents":true,"maxErrors":10,"sendInterval":500},"Continuity":{"enabled":true},"PageParams":{"xhr":"subresource","pageGroups":[{"type":"Regexp","parameter1":"\\/[\\w-]{2,5}\\/$","parameter2":"Homepage","on":["navigation"]},{"type":"Regexp","parameter1":"\\/[\\w-]{2,5}\\/download\\/help\\/*","parameter2":"Help Articles","on":["navigation"]},{"type":"Regexp","parameter1":"\\/[\\w-]{2,5}\\/download\\/faq\\/*","parameter2":"FAQ Articles","on":["navigation"]},{"type":"Regexp","parameter1":"\\/[\\w-]{2,5}
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\defaultpreferencemanager.nocache[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):4867
                                                                                                                                                                                Entropy (8bit):5.424053024572997
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:gGvaPp1xs4ZqPFxUkttqK0wUlhfBPA/eV8rpRrKpKsE5:Nk1bZCXLUK9OhfxADroI
                                                                                                                                                                                MD5:93D4EC6A1649B91D22C24C5C75D77924
                                                                                                                                                                                SHA1:30B431BAB07DF5BF78ABD9F1FD7C6CE1B8CE2493
                                                                                                                                                                                SHA-256:6A66602BD79BD624A3AE23C153EAFE52C677725341F38D682ED9DE7B0B702790
                                                                                                                                                                                SHA-512:74EA046922A679284DCF0D04DC6B23A41FA315F1290C563B3155B250BA66CB935B0C76861490C3B28E85DF9B7D73F8067D8C888EE114D205DA8C6BA5927A4ECE
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/defaultpreferencemanager/defaultpreferencemanager.nocache.js
                                                                                                                                                                                Preview: function defaultpreferencemanager(){var O='',wb='" for "gwt:onLoadErrorFn"',ub='" for "gwt:onPropertyErrorFn"',hb='"><\/script>',Y='#',Gb='.cache.html',$='/',kb='//',Eb='0D070042D9C67A68E1A4BF804E6E0E06',Fb=':',ob='::',Ib='<script defer="defer">defaultpreferencemanager.onInjectionDone(\'defaultpreferencemanager\')<\/script>',gb='<script id="',rb='=',Z='?',tb='Bad handler "',Hb='DOMContentLoaded',ib='SCRIPT',fb='__gwt_marker_defaultpreferencemanager',jb='base',bb='baseUrl',S='begin',R='bootstrap',ab='clear.cache.gif',qb='content',P='defaultpreferencemanager',db='defaultpreferencemanager.nocache.js',nb='defaultpreferencemanager::',X='end',T='gwt.codesvr=',U='gwt.hosted=',V='gwt.hybrid',vb='gwt:onLoadErrorFn',sb='gwt:onPropertyErrorFn',pb='gwt:property',Cb='hosted.html?defaultpreferencemanager',xb='iframe',_='img',yb="javascript:''",Bb='loadExternalRefs',lb='meta',Ab='moduleRequested',W='moduleStartup',mb='name',zb='position:absolute;width:0;height:0;border:none',cb='script',Db='selecting
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\favicon[1].ico
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):1150
                                                                                                                                                                                Entropy (8bit):5.4824647268315285
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:12:NWlFMVaUsQsV444444wcAKyZmvebayz1Tqn2bz75rajZ0a7VN/GR6abfaHl/:EMwUOVToYvU9Y2n75rajj7WDg
                                                                                                                                                                                MD5:8E39F067CC4F41898EF342843171D58A
                                                                                                                                                                                SHA1:AB19E81CE8CCB35B81BF2600D85C659E78E5C880
                                                                                                                                                                                SHA-256:872BAD18B566B0833D6B496477DAAB46763CF8BDEC342D34AC310C3AC045CEFD
                                                                                                                                                                                SHA-512:47CD7F4CE8FCF0FC56B6FFE50450C8C5F71E3C379ECFCFD488D904D85ED90B4A8DAFA335D0E9CA92E85B02B7111C9D75205D12073253EED681868E2A46C64890
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/favicon.ico
                                                                                                                                                                                Preview: ............ .h.......(....... ..... .................................}h..}h..}h..}h..}h..}h..}h..}h..}h..}h..}h..}h..........|.........................................................|...p...............u..z\..z\..z\..z\..z\..z\..z\...............p...v...........................................................v...z..................qU..eG..eH..eG..qU......iL...u...........z..................................................jM...w..........................fH..iK..sV..gJ..fH..sV..........fH...v......................................n..m............}c...w.....................................'v.......`.......................................................e.......e...e.......................................................i......o....p.................................................v....q............................................................z...+z................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\get[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):20646
                                                                                                                                                                                Entropy (8bit):5.219540701770321
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:gjxmfkjIB21UlcgyrtayD4yody5yXyRU96y2IPyyka6yAoyyy6nywym4yy2yybyS:q4Bs8cJjBgCRY9ueIVr/xxLlLcNn5WW9
                                                                                                                                                                                MD5:B2C1B4A41E148456B58383C349CA4B29
                                                                                                                                                                                SHA1:8B8ADB9FBBB407C62A8289DAAB1259949E72BE55
                                                                                                                                                                                SHA-256:F1BA71D3BF034AECEECB8895E71A44F4806DBB5BCC44E46FD8FC461A774EB880
                                                                                                                                                                                SHA-512:14246D376ABF21E6EF7BA2670AF08968E24639F60789301D352FDE5CCCE25D27ADF98A7C7BFA751FB1CB3A413899E62B4AE0DC885DABE11BED4EEEFAE3BAB1CC
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-st.trustarc.com/get?name=combined_static_cm_minified.js
                                                                                                                                                                                Preview: function installPlugin(){function xpinstallCallback(url,status){if(status==0)msg="XPInstall Test: PASSED\n";else msg="XPInstall Test: FAILED\n";dump(msg);alert(msg)}xpi={"ADCookie Plugin install!":"/adcookieoptout/adcookie.xpi"};InstallTrigger.install(xpi,xpinstallCallback)}function TRUSTe_checkplugin(){if(!BrowserDetect.browser)BrowserDetect.init();if(BrowserDetect.browser=="Explorer")TRUSTe_checkPluginForIE();else TRUSTe_checkPluginForNonIE()}.function TRUSTe_checkPluginForNonIE(){if(BrowserDetect.browser=="Chrome"){var elem=document.createElement("div");elem.setAttribute("action","CheckAddonAPIVersion");document.body.appendChild(elem);elem.addEventListener("CookieEventAPIResponse",function(event){if(event.target.getAttribute("action")!="CheckAddonAPIVersion")return;TRUSTe_addVersionToDOM(event);elem.parentNode.removeChild(elem);event.stopPropagation()},false,true);var evt=document.createEvent("Event");evt.initEvent("CookieEventAPI",true,.true);elem.dispatchEvent(evt)}}function T
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\i18n.min[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):1190
                                                                                                                                                                                Entropy (8bit):5.22354092284205
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:cnNQ3iRE19tuafAXP5ucA3R0sFZSMz0fec5AQxofPp16sPvV2oonQSj1pf:qUXtFGP5ucAysFZIfLAffBUopSz
                                                                                                                                                                                MD5:CDC1B9E99E06127C245C3E082B62C8DB
                                                                                                                                                                                SHA1:3584F7B136059DF16096E84A14B7093FBB1C464F
                                                                                                                                                                                SHA-256:E2CDEC61D821EA2D31A5232EE702D6BC3AB73CFAEF75211399CFFB48F8139D37
                                                                                                                                                                                SHA-512:4FE8C7FD00698DFA54FA99E509DBFBAF8D722FE06C71673288FD4E96FF85B87A604B8995ABB0E6D7ED3142237C1AB7DA8E23CE222C6DD36D66EF7A8A0A3184D2
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/js/dependencies/i18n.min.js
                                                                                                                                                                                Preview: !function(){"use strict";function d(o,n,e,a,t,r){n[o]&&(e.push(o),!0!==n[o]&&1!==n[o]||a.push(t+o+"/"+r))}function y(o,n,e,a,t){var r=a+n+"/"+t;require._fileExists(o.toUrl(r+".js"))&&e.push(r)}function w(o,n,e){var a;for(a in n)!n.hasOwnProperty(a)||o.hasOwnProperty(a)&&!e?"object"==typeof n[a]&&(!o[a]&&n[a]&&(o[a]={}),w(o[a],n[a],e)):o[a]=n[a]}var j=/(^.*(^|\/)nls(\/|$))([^\/]*)\/?([^\/]*)/;define(["module"],function(o){var h=o.config?o.config():{};return{version:"2.0.6",load:function(o,r,i,n){(n=n||{}).locale&&(h.locale=n.locale);var e,l,a,t=j.exec(o),u=t[1],f=t[4],s=t[5],c=f.split("-"),g=[],v={},p="";if(t[5]?e=(u=t[1])+s:(e=o,s=t[4],f=(f=h.locale)||(h.locale="undefined"==typeof navigator?"root":(navigator.languages&&navigator.languages[0]||navigator.language||navigator.userLanguage||"root").toLowerCase()),c=f.split("-")),n.isBuild){for(g.push(e),y(r,"root",g,u,s),l=0;l<c.length;l++)a=c[l],y(r,p+=(p?"-":"")+a,g,u,s);r(g,function(){i()})}else r([e],function(a){var o,t=[];for(d("root",
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\infinity_common[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):13562
                                                                                                                                                                                Entropy (8bit):5.416978515318094
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:T2y6zJxt9uvRndnHEbsW0x+B8ccB+3qw2ERhfZR:TbJVK16w2UxZR
                                                                                                                                                                                MD5:A9032E68F2D9591E126404046A2BC7AB
                                                                                                                                                                                SHA1:B504627E622CCB9DFA1B6A828EA2BC2B37E80825
                                                                                                                                                                                SHA-256:B93E3D28B7AA290C8DB2BB4E1CA75D9BD1D84E85AA867BCFA598A6B2A3D27562
                                                                                                                                                                                SHA-512:08407843545CB9709CCA1DEEA3D95A68CAF73BC281A5F006F4499C86C7BD742EFD475533F1B9652A2F53B17F07352D5AF437FA2D085E8619CF33C2632E5D4220
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.oracle.com/asset/web/analytics/infinity_common.js
                                                                                                                                                                                Preview: /*!.######################################################..# INFINITY_COMMON.JS..# Version: 1.16.# BUILD DATE: Friday, Feb 19, 2021..# COPYRIGHT ORACLE CORP 2021 [UNLESS STATED OTHERWISE]..######################################################.*/.var OraInfCustPluginGlobals=(function(){var publicScope={};publicScope.getUrlQueryParameter=function(name){name=name.replace(/[\[]/,"\\[").replace(/[\]]/,"\\]");var regex=new RegExp("[\\?&]"+name+"=([^&#]*)");var results=regex.exec(location.search);return results===null?"":decodeURIComponent(results[1].replace(/\+/g," "));};publicScope.getHostName=function(r){if(r){var e=r.match(/\/\/(www[0-9]?\.)?(.[^/:]+)/i);return null!=e&&e.length>2&&"string"==typeof e[2]&&e[2].length>0?e[2]:null;}};publicScope.getHostObject=function(r){if(r){var e=r.match(/^(?:https?:|ftps?:)?(?:\/\/)?([^\/\?]+[.]+[\w]+[:\w]*)/i);return null!=e&&e.length>1&&"string"==typeof e[1]&&e[1].length>0?{origin:e[0],host:e[1]}:null;}};publicScope.getMetaTagValue=function(name){var
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\java_home_photo2[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, progressive, precision 8, 320x303, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):18684
                                                                                                                                                                                Entropy (8bit):7.941482665517741
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:MD9jCVd+P1avntf3LFbzluWnanYPayLhhRgBuTAzZ4:Y9jCPOgvtf3LFbhuVIayLRgITkZ4
                                                                                                                                                                                MD5:F31AE0A9ACBC9D62A93E4A942C762A2D
                                                                                                                                                                                SHA1:1F9AAFA48280BB10EC6E055C95468EC7C7AC1A58
                                                                                                                                                                                SHA-256:61177657E9643FE669E02FE1971011EA7E1159D42ECC80F1C0E36BA505AD1416
                                                                                                                                                                                SHA-512:3710959B8CADAC9B3B4C0B9D08B7663391404C952124D5FE85E4F1F1DF0E36E5641BBD92481D4F4D8F9CBE3EC46C99FE35048413C007A3F627B2AA2BDB8FDEB0
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/img/home/java_home_photo2.jpg
                                                                                                                                                                                Preview: ......JFIF.....d.d......Ducky.......K.....&Adobe.d.......................0...H............................................................................................................................................./.@.......................................................................................... 1..0@!.P"2.A#..`$B3pC%.......................!1AQ..q"0@a.2B.#. ..R..br.3C..$.P...Scs4....................P`!....................!1A.Qa@q. 0..P..........................F.e]3...-6.3.#1p.Js............:.]9.t....s[\....J...zc....4...............p[1...<6.v../+y..M~....b...........j[.e.3.h:gazzF..;c.K.2...21={-;=..:eP........A.K..8.u.n"m&!..&.c..C;.<...n]..............Zo..s....d...lmH.!.........c.f}.l..........W...e.o.>.._;.Jf&..e*=,f..../....\$........[#.SO...t....1..le...X.V.^D.QRi..g}..GL3R...........\;4M.."....s....|r..R.:..f.\Rz.>.............n|.O...jS..q.d3./.>..;.1{.L......>..Io..M...........M>z...v.[u?/..p....4.\.W.+l,oK.^...>.[\.........h|..O .*
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\jv0_oracle[1].gif
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:GIF image data, version 89a, 91 x 22
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):919
                                                                                                                                                                                Entropy (8bit):6.420171258574878
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:DUifmRlw/Uvzy6yDGr+492MDfywVZ2Nje:3fk8Gr+IekZ2Nje
                                                                                                                                                                                MD5:9AD2F2B528AB933E785FD31BA5C642D6
                                                                                                                                                                                SHA1:8F6519118DC9F35642C046A989302AF11EDD708D
                                                                                                                                                                                SHA-256:9DD4760AD78DA6F14A0EDC582C03982A9392AC676244FC762A7B0BA059C24812
                                                                                                                                                                                SHA-512:DB643B0921949F79B95DB9F63659E6FA988BFEFEC4F4536AFF3FF8E00C6FD5D2FAAA586F1E3039734372BCFA74BE1D50BEF7529B47C1E9D0C62FC2296F0DF07E
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/img/footer/jv0_oracle.gif
                                                                                                                                                                                Preview: GIF89a[.............33.......<<.....................................cc..........??....KK.99.{{....~~....--.......00....**....ii.WW....NN.............ZZ.HH....TT...................``.rr.......ff....EE.......$$.ll.oo.66.xx..........QQ.......BB.]]....''.!!................................................................................................................................................!.......,....[..........................<;......9.........@'...-........(...I.5..-...../.....#...............1...=.1.2.A.J$.........1...@...#..!...t2t-..#...`.....3......"!....W..BB...@......!*..I...B.X. ......x9...P.4.(hI...X"J.@..P.6I.#..F..,..".......tl. ....r. ERl...t.F!QH!..tP.......@.D!@.R..$..@..CJ.1.....E6.$@..H....A..B.g. ....)a...........f#a0Lc...8l..)H...,.........L<.f.....!.....!s.)`.....7.........D|.{.....dt.[7.*.O..@.A.@.F..0..3p..",.6......0.<..s. ..8X.T0.\7.(...,...0.(.4.h.8..<......;
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\jv0dl_a[1].png
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:PNG image data, 672 x 128, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):4741
                                                                                                                                                                                Entropy (8bit):7.853820287173857
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:ySDZ/I09Da01l+gmkyTt6Hk8nTKwD1IBxaf/76744xn+LGDDTmIiQceDrr7k:ySDS0tKg9E05TlD1Uwf/76744oyaIvf0
                                                                                                                                                                                MD5:A6BE3E959427A5B5645356CBE0DFCF51
                                                                                                                                                                                SHA1:818B4E71DACA0CA889B0714935A159E91C2F1B25
                                                                                                                                                                                SHA-256:EEC8393557E19987E71F13592A34E39119CA17F5AC554974B937B437AA7DDC58
                                                                                                                                                                                SHA-512:D7C9467FE6DDE7CA9B93F266F10BB0591B23F0E518BD35251A8DB08E33C3F43A9A5BBC0BDE8AD677E657A45352076D24FF789D0272B6001385EB37B158F91554
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/img/home/jv0dl_a.png
                                                                                                                                                                                Preview: .PNG........IHDR.............[mL.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\jv0ht[1].gif
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:GIF image data, version 89a, 351 x 173
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):5672
                                                                                                                                                                                Entropy (8bit):7.931442402707422
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:7V+XRRyaia6m3ZU9jfmZBDvseok66dOxoGElY8DXQBDk8V0SBqOT3QZgJn9o:7CRxia6+U9jfmXYefFcxoGUhQ68V0OwX
                                                                                                                                                                                MD5:59AA1CA709F752690212C4E0039B0E4F
                                                                                                                                                                                SHA1:BEB6644DF8190D7AF1F3DC1DCB4857AB4AEA74C7
                                                                                                                                                                                SHA-256:26070A72AE2C336CE985EA6650D78B61304F75265087DDC7144FB407661637B0
                                                                                                                                                                                SHA-512:89A2BA004CEFBBC56F19FD4FFBB8BA02DDA9E1063146101DC418436BFA1396FD28D5E7D3884E9A0D762CAFD1831690A5A96D77CF0EF52AD9FA53C4FE82F7C01D
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/img/home/jv0ht.gif
                                                                                                                                                                                Preview: GIF89a_......ddd...........nnn...yyy......................!.......,...._...@....I..8...`(.dirD..g...(..s.....@.xn..n....h.I............Hsp.3..Y.n..k..:.ZA..q9rw.u8n.PR...d....lM.@.T.@.]E-p..4gvxe.....H..hs.}.f$Q.......S'._....Z4...j&....K@...W....z..........!..n.4....@$.<..L..@.%.{..ijD..?....+g...e"...S..)Y.. (.......,.@r......\....!...p...0..0.Y.&.`#B..J...H..8.B.o.l.u...TT.D.X'."D..f=...H.sB.Y.. .....xzu.T.t[.r{.@#.gK.-..B2.d....".3{lp.0.f....O......3....+.....^...X.,...M.(..+...TCf.3J.6.D..L.....j..%<sBW..9....M.......p*\.........9.74.n.y...K .ha7.......YID..r.%..1........s".G.f3.XA,.!........!.e..}]T...0..E!...<.c[.&...u..W..,^....Y..y%..".....PF).TVi.Xf.e.3..ep..!....`...\..g0}y.....cxI.c..d..[.i...`H.....A..A....H....\....D.....iY.t..!.=....N...q.ZI..H..W.*..%.j..|...i...........x...&......C.4.RP..... .%..W.......*+.y..`.4..$[..............b.K..`.-...;...r.n.}m..bp0R.QA.`z...b.A.h.i....+....zq#...2.....r.0...DE...T.G.."ln#.n".~.+b2.
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\layout[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):322
                                                                                                                                                                                Entropy (8bit):4.560479140514086
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:6:DxlY1efZT0a6Oi+xDfQMQMEv1UCTDRnhW56eNzSlMv1H:LFTVrZxDBZE93hW56kz59H
                                                                                                                                                                                MD5:A41911032F556116B5525B553DA01655
                                                                                                                                                                                SHA1:FFB2132F6CF6F610E70790651DE88E63CE6FF140
                                                                                                                                                                                SHA-256:3E4AA2CB4D372FCBEBA22C9AA960E8779F44B6C9584A8C555409B2CA5D742897
                                                                                                                                                                                SHA-512:DFA850FAEE04B38F15653FF551773E727BB1933B8431EC825D90597FF12067D1C327A5EE4FC24032BE64BF012ECCB574B16CCAC24E3479A5FCDD44BC8FDFF098
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_compdelivery/_cache_2094/JCOM-SimplePage_Detail/assets/layout.html
                                                                                                                                                                                Preview: {{{variantScr}}}.<div class="row">. {{#fields}}. <div class="{{divClass}}">. <div class="jvc0w2" data-hydrate="{{hydrateData}}">. {{{body}}}. </div>. </div>. {{#navWidgets}}. <div id="leftNavSection" class="jvcs0 clearfix">{{{widgetContent}}}</div>. {{/navWidgets}}. {{/fields}}.</div>.
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\promise-polyfill.min[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):3873
                                                                                                                                                                                Entropy (8bit):4.934703049448279
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:2sGCUBf6HofDX3Z3QL8t5wvDhk98ez8UX9afVBKkfSqiOH:s68l3sayVKzBNaB6q5
                                                                                                                                                                                MD5:7ECB657D16B1441F47B83F777AC75DCF
                                                                                                                                                                                SHA1:EF2F2A0DD519D2D1CE8D15B00352C26E6BB65762
                                                                                                                                                                                SHA-256:E17AE17F90AE983832F3709E67DE0F7902FE1014568410534615235A158D7AF0
                                                                                                                                                                                SHA-512:60AF9B02352E61D8CF92C6C6408208B149F9860605B1CFA75E0C76D56C1BCBD32FFAB25DF16647D8545ED517654E316ED6FC651A26BDFD1AA650C719B57F81AC
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/js/promise-polyfill.min.js
                                                                                                                                                                                Preview: !function(e,t){"object"==typeof exports&&"undefined"!=typeof module?t():"function"==typeof define&&define.amd?define(t):t()}(0,function(){"use strict";function e(e){var t=this.constructor;return this.then(function(n){return t.resolve(e()).then(function(){return n})},function(n){return t.resolve(e()).then(function(){return t.reject(n)})})}function t(e){return new this(function(t,n){function o(e,n){if(n&&("object"==typeof n||"function"==typeof n)){var f=n.then;if("function"==typeof f)return void f.call(n,function(t){o(e,t)},function(n){r[e]={status:"rejected",reason:n},0==--i&&t(r)})}r[e]={status:"fulfilled",value:n},0==--i&&t(r)}if(!e||"undefined"==typeof e.length)return n(new TypeError(typeof e+" "+e+" is not iterable(cannot read property Symbol(Symbol.iterator))"));var r=Array.prototype.slice.call(e);if(0===r.length)return t([]);for(var i=r.length,f=0;r.length>f;f++)o(f,r[f])})}function n(e){return!(!e||"undefined"==typeof e.length)}function o(){}function r(e){if(!(this instanceof r))
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\render[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:exported SGML document, UTF-8 Unicode text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):9798
                                                                                                                                                                                Entropy (8bit):4.822811148672577
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:TN4cGGvCMLnJUp5faTF7TkSbGibbc1F0MUJhE24o5sRXqMzXpsvo9LM9dqIC:TNuC+gJTmB8J4mvE5
                                                                                                                                                                                MD5:CDA175F1776F94D8025CF4B6578D5EDB
                                                                                                                                                                                SHA1:A9E38E986A90632E63007E6F77DB0CD055F64442
                                                                                                                                                                                SHA-256:610CEE97B15F5669A733F0802726988EA641C103C10AFAAA7353D2C6C3878840
                                                                                                                                                                                SHA-512:A9B691A6D6708C83D5A27783F8C8BD6223056DB2149DC25FAA2137B52FE45C075099D33EDA5A18BB0B6AAF80E515CDD156E3929FF8A6A2BF50D4B9072609255E
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_compdelivery/_cache_2094/JCOM-SimplePage_Detail/assets/render.js
                                                                                                                                                                                Preview: /**. * Copyright (c) 2019 Oracle and/or its affiliates. All rights reserved.. * Licensed under the Universal Permissive License v 1.0 as shown at http://oss.oracle.com/licenses/upl.. */./* globals define,console */.define([.."jquery",.."mustache",.."marked",.."text!./layout.html".], function ($, Mustache, Marked, templateHtml) {.."use strict";...// Content Layout constructor function...function ContentLayout(params) {...this.contentItemData = params.contentItemData || {};...this.scsData = params.scsData;...this.contentClient = params.contentClient;..}...// Helper function to format a date field by locale...function dateToMDY(date) {...if (!date) {....return "";...}....var dateObj = new Date(date);....var options = {....year: "numeric",....month: "long",....day: "numeric",....hour: "2-digit",....minute: "2-digit"...};...var formattedDate = dateObj.toLocaleDateString("en-US", options);....return formattedDate;..}...// Helper function to parse markdown text...function parseMarkdown(mdText
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\s_code_remote[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):3135
                                                                                                                                                                                Entropy (8bit):5.343899292674586
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:48:TIx98yes/Y1josQ45kIIJYaygOObTVno4b6GabIufdB:MPTh/Y1E4xISObBrZabddB
                                                                                                                                                                                MD5:013C759D9E735927DE9443BA35B4FDDB
                                                                                                                                                                                SHA1:2D14300D76E34B41EFDD5A8EA57E4A79859571F4
                                                                                                                                                                                SHA-256:BFF04C18BF3D41EA1E9AE7B5C7694782D282907AE8B3BE78B7FED1ACD5D3DB61
                                                                                                                                                                                SHA-512:0613D1DAB0F61A085229982D9DEEDB50B30A6481B072912B8C4868E5BB973391615A2612394AA4E2F5214174CA5078ECD9D940DE508B062855D6B48793B921F7
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/js/s_code_remote.js
                                                                                                                                                                                Preview: /*!.######################################################..# S_CODE_REMOTE.JS..# Version: 1.00..# BUILD DATE: Tue Jul 17 2018 12:05:01 GMT-0400 (Eastern Daylight Time)..# COPYRIGHT ORACLE CORP 2018 [UNLESS STATED OTHERWISE]..######################################################.*/.try{oracle.truste.api.getConsentDecision().consentDecision;oracle.truste.api.getConsentDecision().source}catch(err){var oracle=oracle||{};oracle.truste={};oracle.truste.api={};(function(){var trusteStorageItemName="truste.eu.cookie.notice_preferences";this.getCookieName=function(){return"notice_preferences"};this.getStorageItemName=function(){return trusteStorageItemName}}).apply(oracle.truste);(function(){var trusteCommon=oracle.truste;function getCookie(cookieKey){for(var name=cookieKey+"=",cookieArray=document.cookie.split(";"),i=0;i<cookieArray.length;i++){for(var c=cookieArray[i];" "==c.charAt(0);)c=c.substring(1);if(0==c.indexOf(name))return c.substring(name.length,c.length)}return null}function getLo
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\10.cache[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):248479
                                                                                                                                                                                Entropy (8bit):5.679841116358217
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:6144:T4Kg0YE59pQVZ0QfqOWIyMeTsBXnYZEq+3:T4K3pwqoOUXnYk
                                                                                                                                                                                MD5:C0505C29146931555F03C9B1CA33ADA8
                                                                                                                                                                                SHA1:C9419243DC3B06FE21B54BD41FBC4FC9AEA3A986
                                                                                                                                                                                SHA-256:B36941FAFF55CB4E1DB3A8DA151B535DC1F330D85AF2F6929C939176D534041F
                                                                                                                                                                                SHA-512:B18667E764CD16550782EDE46B80AAFA41632A0DBAC44B1EA7A54F8EB9482541D7D191C2AC9B27F7E1E256A5C0C36764F6C59C8AA72AC18CD9A29062A7826C55
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/defaultpreferencemanager/deferredjs/0D070042D9C67A68E1A4BF804E6E0E06/10.cache.js
                                                                                                                                                                                Preview: function Rb(){}.function Vb(){}.function up(){}.function Kp(){}.function Qp(){}.function Wp(){}.function bq(){}.function zq(){}.function Oq(){}.function er(){}.function lr(){}.function $u(){}.function oU(){}.function sU(){}.function xU(){}.function HU(){}.function oV(){}.function rV(){}.function uV(){}.function xV(){}.function vW(){}.function QW(){}.function rX(){}.function uX(){}.function BX(){}.function EX(){}.function KX(){}.function EY(){}.function HY(){}.function G_(){}.function M7(){}.function P7(){}.function wbb(){}.function lcb(){}.function ocb(){}.function Meb(){}.function efb(){}.function hfb(){}.function kfb(){}.function nfb(){}.function qfb(){}.function ufb(){}.function xfb(){}.function Vjb(){}.function Itb(){}.function zyb(){}.function Jyb(){}.function hzb(){}.function Rzb(){}.function Uzb(){}.function UOb(){}.function MOb(){}.function QOb(){}.function GMb(){}.function XNb(){}.function KPb(){}.function xQb(){}.function RSb(){}.function YSb(){}.function dTb(){}.function kTb
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\GoJava[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 125x132, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):5138
                                                                                                                                                                                Entropy (8bit):7.907565594845598
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:T2A9GXRAkg1UYIpLaZwJALfmJSB2vulzEviYHO6tuo8U5GmON0/52twL9:aA9Gtg1UYuLaZWnACgzBaRGmaE52e
                                                                                                                                                                                MD5:EB9F0779D76A650F83ACA4488C7B303A
                                                                                                                                                                                SHA1:83165410DE505BA628634CC0CCC7CE737248CAA8
                                                                                                                                                                                SHA-256:C004C648BEDEF20A52400C2A0CDBC5301ED8FB982D2731798C3620734F145C61
                                                                                                                                                                                SHA-512:81ABDF6802666D5AED53F5E5F7780877A276585536FC41A878FCBC5E5ABA96DB29A494DF536A7F6F40CFE97C39550D997C8F5A87245BEC3B74DCF8EBB46D5340
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/assets/CONT2A739CE297364EFC962C8074B610F485/native?cb=_cache_97bc&channelToken=1f7d2611846d4457b213dfc9048724dc
                                                                                                                                                                                Preview: ......JFIF.....d.d.....C..............................................!........."$".$.......C.........................................................................}..!........................................K..........................!.1...Aaq..."4QRSUt....u....26B...#$b...'3Ccr..................................9.........................!14q......AQRa."...$3..#25B...............?....:...2R...d.3.BaJ.K.AE.Q..$Z.o..........L...K.C4My&...X....*i..........b.SP>....^1O.....m..,.g.E..E_..C...b.SP>....^1O.....m.r..xtG.K~..9x.>..|.=...b.SP>..........~...Tr.}M@.&{h9x.>..|.=.........*.-..........L..r.}M@.&{h;..3.?.U.[.=Q..).5...........L..w,.g.D~(....z.3b.E...U.S....7...r..n0:U.:.{qc...K...>Q.U.6...Na.kp...R.g...6..'.O..G.#."-.M......mD.-V.... B ...."......+_....3.zO....OZ~.AzF...=......W....H.......:.Y..'..d...~....V.J.):sN.,.S.$..*%?..&.1_...E0...q.2..+.Z...L^-..nH....0_.,.j..O<..2.U..Nc.F.B.YB.R...t...g..c..C9.#....A.......u..`.L:.E.`.L.Sw......#.fb.I..:.#..O../H.?....P.J
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\JavaOne(2)(2)[1].jpg
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 125x132, frames 3
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):4960
                                                                                                                                                                                Entropy (8bit):7.909328562752296
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:HQsYCRWH4SNU2NA03ysP2sGzaXFo9ThquCgNeEKC3OenqzTUDD:HQsaH4SR22nP2sGzaX+Thq/gTKI5qID
                                                                                                                                                                                MD5:B85FC09ACE4EA90361D6D0953777F962
                                                                                                                                                                                SHA1:92313189D76D3F36D3727C81FD22268C14136307
                                                                                                                                                                                SHA-256:6A258C518CC6607283FE30819E15F51680BB08ECE976FEC96D3646B29AA964F7
                                                                                                                                                                                SHA-512:5B761FF706A496BBFA4D5F2AB3FD8FF8EA8977DA8188D001A61FC0B2EDF66B2BB82A61A2068AED0A0881FBE702A0EF89C6E80F114E8F0DEC04052A58504AAB52
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/content/published/api/v1.1/assets/CONTA16A22C5FE954903AC54EDE7D0200709/native?cb=_cache_97bc&channelToken=1f7d2611846d4457b213dfc9048724dc
                                                                                                                                                                                Preview: ......JFIF.............C..............................................!........."$".$.......C.........................................................................}..!........................................N............................!1.A."3QRaq.%2b......#$BDt....5CSr.......Td....................................3........................!13...AQRaq...."2...#b...............?..6...i...K..mr..he.P...*?...Iq].....?..~....C..AK5.g..rSp..06.p.j...o...Y.7O.#}..?....O..'.=O..$......Y..$..5w.j7......e~<...P...q.>.s;.s.r?.i..z5r..E....^f..u..f.s..)?;{.}...OH.Uz.61.".*...?.=.>.q..V....U=z.~.*....:}.vcm*K..OL..k..&Do.........y...J.........x.MS.+......^.x..U.j.n3{:...!VL....Wq..."....7..#..X*......>u..vGoE.Gnw$oO}.....uM+.#.F..Gs..S...M7'....v....{.to...-V5...:O..o...)]'-.(,)Aa_P.';.)......%tL[..v6.T..d..4N.AQ ....Z......Ty&.%...|w.....G~.:..mGQ4.......@.O..}I5...mq`.. .[. ..<......bp..|UT......]t..........A^RoU.#..*.......0.."%^,.$.+....I.....(.~v...Q.._...X.
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\cookie_iframe[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):5014
                                                                                                                                                                                Entropy (8bit):5.070770931797894
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:yGYYYxNFxNmFZiQ/BDZhFIgRxI/wKRpRTWukeWaTESXDAvdD9iPDJi/dDJ3DDJJ2:yGYYgNLNmSQ5FPIgHILWaTESXDAvdD9k
                                                                                                                                                                                MD5:1159F3467D523D0578BC6FAFEDD369EC
                                                                                                                                                                                SHA1:9F08758879C608D2C718071344B96CEC910499B3
                                                                                                                                                                                SHA-256:E5356C4D200584B116D9AC14F89D883B120DBE4D7878914A4FA22358074C74F8
                                                                                                                                                                                SHA-512:22DAD07905FBB2399C7E83E81FE7514C0B2AF69C384B99CB93805884AFF55B82A6A090A57CC1C3B5435760FB1659BFCBD3A4A1EAE0DB0EA3FC8FE379551698CE
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://prefmgr-cookie.truste-svc.net/cookie_js/cookie_iframe.html?parent=https://consent-pref.trustarc.com/?type=oracle6&site=oracle.com&action=notice&country=ch&locale=en&behavior=expressed&gtm=1&layout=default_eu&irm=undefined&from=https://consent.trustarc.com/
                                                                                                                                                                                Preview: <html>.<body>.<script type="text/javascript">.function createCookie(name,value,days) {. if (days) {. var date = new Date();. date.setTime(date.getTime()+(30000));. var expires = "; expires="+date.toGMTString();. }. else var expires = "";. if (shouldSendSameSiteNone(navigator.userAgent)) {. document.cookie = name+"="+value+expires+"; path=/; secure; SameSite=None";. } else {. document.cookie = name+"="+value+expires+"; path=/";. }.}..function readCookie(name) {. var nameEQ = name + "=";. var ca = document.cookie.split(';');. for(var i=0;i < ca.length;i++) {. var c = ca[i];. while (c.charAt(0)==' ') c = c.substring(1,c.length);. if (c.indexOf(nameEQ) == 0) return c.substring(nameEQ.length,c.length);. }. return null;.}..function eraseCookie(name) {. createCookie(name,"",-1);.}..function gup( name ).{. name = name.replace(/[\[]/,"\\\[").replace(/[\]]/,"\\\]");. var regexS = "[\\?&]"+name+"=([^&#]*)";.
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\cookie_inneriframe[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):2008
                                                                                                                                                                                Entropy (8bit):5.157980344637123
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:48:R+AWZDXeNYhGtcO4S63v0SaATPsLXQa+/NT:GbcciSaATkLgV
                                                                                                                                                                                MD5:D09BEB4594BA45F809C9DB7E4429551B
                                                                                                                                                                                SHA1:6E2D0D8C237175DB1509E707B7166042D65C694B
                                                                                                                                                                                SHA-256:A2DE091C86C5A7B6DCC572EB6E5A76C2CD72CE27A2042A8DC2974F15B33566ED
                                                                                                                                                                                SHA-512:2D5373C167742FFB7654D528BE59029BB930221588A49B27FD3AF17EB9457EC6E41D76F1C040BF21E35A8E94B372AE5F87E95B91C4EB5F70CFFF584B314DCFF0
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://consent-pref.trustarc.com/cookie_inneriframe.html
                                                                                                                                                                                Preview: <html>.<body>.<script type="text/javascript">. function getSameSiteValue(){. var isHttps = ((self.location.protocol == "https:") ? " Secure;" : ""); //conditionally adds Secure tag only if parent frame is HTTPS. var sameSiteValue = isHttps ? "None;" : "Lax;";. var cookieAttrb = (" SameSite=" + sameSiteValue) + isHttps;. return cookieAttrb;. }...function sameSiteCompatible(userAgent){...return !hasWebKitSameSiteBug(userAgent);..}...function hasWebKitSameSiteBug(userAgent){...return isIosVersion(12, userAgent) || (checkMacOSVersion(userAgent) && checkIfSafariBrowser(userAgent)) || checkChromeVersion(userAgent);..}...function isIosVersion(major, userAgent){...var retVal = true;....var start = userAgent.indexOf('OS');...if( ( userAgent.indexOf('iPhone') > -1 || userAgent.indexOf('iPad') > -1 ) && start > -1 ){....var iosVersion = window.Number( userAgent.substr( start + 3, 3 ).replace( '_', '.'));.....if(iosVersion > major){.....retVal = false;....}...}els
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\en[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:HTML document, ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):7868
                                                                                                                                                                                Entropy (8bit):5.956373091566649
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:EwvXRwOI5C0n1YxSLZ95Dd+wThMaBumtK/CvVlYV2Bq:EwvXRwXC0n1YcL5h+wThxgoVl0J
                                                                                                                                                                                MD5:FB17EC6F8E4F7444247DB490B947C140
                                                                                                                                                                                SHA1:B7A549889799CBAD28CB8DF7AAE1886E30B68E58
                                                                                                                                                                                SHA-256:4DA0B34A5D69C562BE7F34430A14DF7BAFA784BA6950EF9E535D035E9F676553
                                                                                                                                                                                SHA-512:EF554AFC7D150947444893E32AE9861C359CE955537B52A479738C9D4FABCC7B63B18EB93ACF46B56E01299CEF95D5D80289701BD123030524B30147147FAC60
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/en/
                                                                                                                                                                                Preview: <!DOCTYPE html>.<html>.<head>.<script type="text/javascript">.var SCSCacheKeys = {..product: '_cache_24c8',..site: '_cache_d099',..theme: '_cache_4ba9',..component: '_cache_2094',..caas: '_cache_97bc'.};.</script>.<meta http-equiv="X-UA-Compatible" content="IE=edge">.<meta name="viewport" content="initial-scale=1">.<script type="text/javascript">.var SCS = { sitesCloudCDN: 'https://static.oracle.com/cdn/cec/v21.2.1.30',.sitePrefix: '/site/JCOM/' };.</script>.<script src="https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/controller.js"></script>.. <script>(window.BOOMR_mq=window.BOOMR_mq||[]).push(["addVar",{"rua.upush":"false","rua.cpush":"false","rua.upre":"true","rua.cpre":"false","rua.uprl":"false","rua.cprl":"false","rua.cprf":"false","rua.trans":"SJ-1acddf3f-8db4-4a02-b4dc-17912945ae6d","rua.cook":"true","rua.ims":"false","rua.ufprl":"false","rua.cfprl":"false","rua.isuxp":"","rua.texp":""}]);</script>. <script>!function(e){var n="
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\header[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):117
                                                                                                                                                                                Entropy (8bit):4.339316892918074
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:FnXKP6jJGAJqjwba3fEVRVJTt8VJfB8JHBV:FnXKPmJpa30RN8VJZqv
                                                                                                                                                                                MD5:7C75E3C13ECB36C435F0DBB588121F1E
                                                                                                                                                                                SHA1:786BDF8C01C423B57F3E32FE4EDFA6BAB8E609A5
                                                                                                                                                                                SHA-256:47FC7E24694B95D777E8DD251A1DC715C0E92EA0DE35873C5790F776FE34C7BA
                                                                                                                                                                                SHA-512:2FD948BC233EBEACD28380CDCEBE5BB8AA039931BFEC2F9ACD89AFAE83B9DD76CD69E6FD46B0E52CCD29458900EF26120854168BDB285D4D4093148CCE012B89
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/translations/header.js
                                                                                                                                                                                Preview: define({root:!0,de:!0,es:!0,fr:!0,it:!0,ja:!0,ko:!0,nl:!0,pl:!0,"pt-BR":!0,ru:!0,sv:!0,tr:!0,"zh-CN":!0,"zh-TW":!0});
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\header[2].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):56
                                                                                                                                                                                Entropy (8bit):4.322381431056328
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:FnW0CfpAGjgeJnTH+aHI:FnTCfJEeNTzHI
                                                                                                                                                                                MD5:D49AB4376BCF767AA505976C21CE99FB
                                                                                                                                                                                SHA1:67A54CA68A46E20B1081EAE5B36B6396DAB55D5A
                                                                                                                                                                                SHA-256:EA733AF2869543FF1CD17BC8F77F5CE7BFC0C76EA801EC8B0B92F727B29AC797
                                                                                                                                                                                SHA-512:998FE632B2B73034C622A7AEDE7735E79F3ED7F9E0B6C87046298B8FCD1D6C6F08546999A027ABA6A2E6E01D97775D8C520A67BC281EDAE956B80FEE3C200D7A
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/translations/root/header.js
                                                                                                                                                                                Preview: define({select_lang:"Select Language",Search:"Search"});
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\jv0_search_btn[1].gif
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:GIF image data, version 89a, 19 x 18
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):99
                                                                                                                                                                                Entropy (8bit):5.689180797659173
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:Clp6Wnta/CSxlOnRFSLUA6wZzzjgPQ2/rnle:Up9oaSjIOLUOjgPxrle
                                                                                                                                                                                MD5:6B63F7479D5FDCF11F57F1315339A071
                                                                                                                                                                                SHA1:0552EA5365B2C87B850DB6974645F0D81FBD22F8
                                                                                                                                                                                SHA-256:AC0AFC4A38CF993FF8048D40E16725EC2C5A59737E68A4DC741A8EDD6A7D3384
                                                                                                                                                                                SHA-512:CD875B3E9F87D9BB13784AEFAF9B155603C7A9E32008CEB7DE69DBF78A15D0EC3BE3664ABB1ACF82227D42DFF0BFEF0DBB9FE46E71F1348C164F6D4E5F6A7E8D
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/img/header/jv0_search_btn.gif
                                                                                                                                                                                Preview: GIF89a...................!.......,..........4..h...HX1....=.L...xP.....R&...u+....f.I*...(Af....;
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\metrics_group1[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:C source, ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):33056
                                                                                                                                                                                Entropy (8bit):5.8215192547091705
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:768:tJJCo9TM7eLE+UOS4bHv/fTzcG8+bau9zaxjPTTkDJa3I97:FCo9OeDS4bHv/fN8+PkwDJa497
                                                                                                                                                                                MD5:4F50071052FF768850C4E3E86ED7EDAC
                                                                                                                                                                                SHA1:B8A533324FA59E0D31934A548337AD09D011FBAD
                                                                                                                                                                                SHA-256:B0254F6D58ECC2EB396CC0722104E42AC097C5FDAF4827571035D2C29A774335
                                                                                                                                                                                SHA-512:DEB987E6BDCA55ADD4F55C3493658CE4C8F217B195C6524865243A6D8ACB441C0FD018E9EDDB04469C0CC95D0A03F9082DA9F3BF5162CE33D126DC53A1DA17AF
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/js/metrics_group1.js
                                                                                                                                                                                Preview: var s=s_gi(s_account,1);s.dynamicAccountSelection=sun_dynamicAccountSelection,s.dynamicAccountList=sun_dynamicAccountList,s.trackDownloadLinks=!0,s.trackExternalLinks=!0,s.trackInlineStats=!0,s.linkDownloadFileTypes="exe,zip,wav,mp3,mov,mpg,avi,doc,pdf,xls,bin,tar,Z,gz,txt,bz2,mp4,jar,dmg,sh,msi,jnlp",s.linkInternalFilters="javascript:,sun.com,java.com,opensolaris.org,sun-catalogue.com,java.net,netbeans.org,openmediacommons.org,sunspotworld.com,openoffice.org,opensparc.net,sunsource.net,opensolaris.com,mysql.com,mysql.de,mysql.fr,projectdarkstar.com,sunstudentcourses.com,kenai.com,virtualbox.org,odftoolkit.org,javafx.com,openoffice.bouncer.osuosl.org,opends.org,suntrainingcatalogue.com,cloudoffice.com",s.linkLeaveQueryString=!1,"undefined"==typeof ltv||""==ltv?s.linkTrackVars="None":s.linkTrackVars=ltv,"undefined"==typeof lte||""==lte?s.linkTrackEvents="None":s.linkTrackEvents=lte;var s_prop33="Version06032013",s_server=location.hostname,s_eVar35=location.href;s_eVar35=(s_eVar35=s_eVar
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\oldcss[1].css
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):19531
                                                                                                                                                                                Entropy (8bit):5.148684251674867
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:PdaRCcLuJDRUuOlg/HPYxbMzZq7F2cqNYJvPb/aG5hDupXOgqt+:0HLuJDiuOlg/HPubMzZwSNg/vi
                                                                                                                                                                                MD5:431EA90E739570FDA7F169C183BE4FBE
                                                                                                                                                                                SHA1:2F7A22A112452C0C02C77545DCB38D65FFB66F80
                                                                                                                                                                                SHA-256:90F255EBB8406F78FEC80E412DB772F50AD451F4989352763BAF69728AF37369
                                                                                                                                                                                SHA-512:B35797825EA18F47FD64B70B5DB91D48D625C22380179FC841F5F3E84D0A7D3DFA594FB21776CF147B30ABE704C9AD0A70CBD1E790AFA31586AD5ACD0606536D
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/css/oldcss.css
                                                                                                                                                                                Preview: TD.bodycell{background-color:#fff}.orangelink{color:#333}a.orangelink{text-decoration:underline}a.orangelink:hover{text-decoration:none}.orangebold{color:#3e6b8a;font-weight:bold}a.orangebold{text-decoration:underline}a.orangebold:hover{text-decoration:none}.subtitle{font-family:Verdana,Arial,Helvetica,Sans-serif;color:#1e475b;font-weight:bold}H3.black{color:#000;font-weight:bold;display:inline}html table.helpHeader{border:1px solid #e4e2e2;border-bottom-width:2px}th.helpHeader{padding-top:3px;padding-bottom:3px;padding-left:10px;color:#000;text-transform:uppercase;vertical-align:middle;line-height:23px}html th.helpHeader{background:#f0efef repeat-y !important}html th.helpHeader a:visited,html th.helpHeader a:link{color:black;font-weight:bold;text-decoration:none}ul.newlist li{color:red;padding-left:0}TD.gradientHeader{padding-top:3px;padding-bottom:3px;padding-left:10px;color:#000;text-transform:uppercase;vertical-align:middle;line-height:23px}a.gradientHeader{color:#000;text-decorati
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\renderer[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:UTF-8 Unicode text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):846112
                                                                                                                                                                                Entropy (8bit):5.706281748309152
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24576:inRcPNfZgEmYr1IVohAkk2JdLO+Ma6AkcQ:0RcPNfnr1IVohAkk2JdLO+MaV8
                                                                                                                                                                                MD5:A8B04F8E85FE22765349A2D75742CF9E
                                                                                                                                                                                SHA1:5BF2BCCF3679399A65FFBDBB9775999934306B1B
                                                                                                                                                                                SHA-256:1FE9B2D5C9E775575851158C4338865563B099DD43254FF5E4F1872C78BDCADC
                                                                                                                                                                                SHA-512:F257AB31C8AAEC33B2A5774C0902732CA6C8AE8D8B74719A3C3FD71B0BA0712749569CCFDA2F16C36BFD5ADDFC79EF1E27F00AF7B8310A95E9EC14BEDC275C3B
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://static.oracle.com/cdn/cec/v21.2.1.30/_sitesclouddelivery/renderer/renderer.js
                                                                                                                                                                                Preview: /** vim: et:ts=4:sw=4:sts=4. * @license RequireJS 2.3.6 Copyright jQuery Foundation and other contributors.. * Released under MIT license, https://github.com/requirejs/requirejs/blob/master/LICENSE. */.var requirejs,require,define;(function(global,setTimeout){var req,s,head,baseElement,dataMain,src,interactiveScript,currentlyAddingScript,mainScript,subPath,version="2.3.6",commentRegExp=/\/\*[\s\S]*?\*\/|([^:"'=]|^)\/\/.*$/gm,cjsRequireRegExp=/[^.]\s*require\s*\(\s*["']([^'"\s]+)["']\s*\)/g,jsSuffixRegExp=/\.js$/,currDirRegExp=/^\.\//,op=Object.prototype,ostring=op.toString,hasOwn=op.hasOwnProperty,isBrowser=!("undefined"==typeof window||"undefined"==typeof navigator||!window.document),isWebWorker=!isBrowser&&"undefined"!=typeof importScripts,readyRegExp=isBrowser&&"PLAYSTATION 3"===navigator.platform?/^complete$/:/^(complete|loaded)$/,defContextName="_",isOpera="undefined"!=typeof opera&&"[object Opera]"===opera.toString(),contexts={},cfg={},globalDefQueue=[],useInteractive=!1;function
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\setupLibs[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines, with no line terminators
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):1672
                                                                                                                                                                                Entropy (8bit):5.318338031938511
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:xaJ0n6WpZCBqmIuHN2jIw30UfImd0/yqUmeyFC1cwKYmRNymRIoTV/2k/VT7G1Rb:EJ0n6WpZCj0VkU0/yqUHgC1bARJOd
                                                                                                                                                                                MD5:D0C9B1531E2D775FCFDD46AE7BE117F1
                                                                                                                                                                                SHA1:6A2EF6AE293DAA32312FF20677F03820BE192C84
                                                                                                                                                                                SHA-256:0090AF7B11B5B2C49CFD848E2A6A6C2F3223AB36A5C093630804A132412D4883
                                                                                                                                                                                SHA-512:F7FBEB4E46405194E4675AF16CC0923BBA8A1AFD4E444FB9BBB5A37104E9F0E210E52BB7A07B2D679AE6D6BA7B4038B9E2686E02E02801CB4DF3C19B9C6B9F22
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/js/setupLibs.js
                                                                                                                                                                                Preview: var setupJET=function(){var e=SCSRenderAPI,t=e.getThemeUrlPrefix(),n={paths:{omniture:t+"/assets/js/s_code_remote",i18n:t+"/assets/js/dependencies/i18n.min",nls:t+"/assets/translations",installed:t+"/assets/js/installed.min",uninstall:t+"/assets/js/uninstallapplet.min"},config:{i18n:{locale:e.getPageLanguageCode()?e.getPageLanguageCode():"en"}}};requirejs.config(n);var a=document.createElement("script");a.async="async",a.type="text/javascript",a.crossOrigin="crossOrigin",a.src="//consent.trustarc.com/notice?domain=oracle.com&c=teconsent&js=bb&noticeType=bb&text=true&gtm=1&language="+(e.getPageLanguageCode()?e.getPageLanguageCode():"en"),$("head").append(a),(-1<window.location.host.indexOf("prodapp")||-1<window.location.host.indexOf("localhost"))&&fixRelativeLinksStatic(),$(".spsidebar li a[href='"+SCSRenderAPI.getPageLinkUrl(SCS.navigationCurr)+"']").css("font-weight","bold")},START_RENDERING_EVENT="scsrenderstart";document.addEventListener?document.addEventListener(START_RENDERING_EVE
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\template[1].htm
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:exported SGML document, ASCII text
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):1516
                                                                                                                                                                                Entropy (8bit):5.245655295264454
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:8FY6rvH9x9UTpEScuy3joMLFMhYw4E/wNCyLiY2PpqjmRl8HFUmG/A9QDy:qTrvH9x9uWSUj/FaYNMNBp2Y+HCvAiy
                                                                                                                                                                                MD5:2E87B6012E2CAD607EB9160C0600DA0D
                                                                                                                                                                                SHA1:FD4A83BDC82D9E6C41831C0FE06BE41788E64ABF
                                                                                                                                                                                SHA-256:407C6F59A9ECA35B0AC2E0A2298BF77419CADA621EBE724686D012DB1CB3AD93
                                                                                                                                                                                SHA-512:CD1891F6B202898ED485F86B21FE7CD237EEAB5A7597C5FAA6B0929B3ABB8BF22BD132C064B22E6246D109FE38259D67F6343225CCAB859D73243B5AF9D066B4
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_2094/_compdelivery/JCOM-Header/assets/template.html
                                                                                                                                                                                Preview: <div class="container-fluid headerContainer gradient">..<header id="header" class="header jvh0">. ko if: showLogo -->...<a title="java.com" class="desktopOracleLogo jvl0 hidden-xs" data-bind="attr: { href: SCSRenderAPI.getPageLinkUrl(SCS.navigationRoot).substring(0,SCSRenderAPI.getPageLinkUrl(SCS.navigationRoot).lastIndexOf('/')+1) }"><span class="headerLogo">Oracle</span></a>. /ko -->... ko if: showNav -->...<p>.... ko foreach: navLinks -->....<a data-bind="text: label, attr: { href: url }"></a>.... /ko -->...</p>... /ko -->... ko if: showSearch -->...<form name="searchForm" method="get" action="https://www.oracle.com/search/results" accept-charset="utf-8" class="jvs0 jv0sv0" onsubmit="if((document.searchForm.Ntt.value == document.searchForm.Ntt.defaultValue) || (document.searchForm.Ntt.value == '')){return false;}">....<input type="hidden" name="cat" value="javacom">....<input type="hidden" name="Ntk" value="SI-ALL5">....<input type="hidden" name="
                                                                                                                                                                                C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\theme.deferred.min[1].js
                                                                                                                                                                                Process:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                File Type:ASCII text, with very long lines
                                                                                                                                                                                Category:downloaded
                                                                                                                                                                                Size (bytes):8914
                                                                                                                                                                                Entropy (8bit):5.089447215809406
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:192:FZavoubOycmVUmbDT5bD4DfAxsAl0Qlgso9QIA2DW8WsY/ADDOmIB:FZcSo14zAxsAlYQIA2qvig
                                                                                                                                                                                MD5:B6F0D719BC1F8A0DD143AF681743B4AE
                                                                                                                                                                                SHA1:E18AD9837E2EDE4185E63CB781FAF2D231C2DFEF
                                                                                                                                                                                SHA-256:E189CC46493B57DE1D751B6554AFDA0A641BAEF1F1A43C7DEF19921A0DBA054F
                                                                                                                                                                                SHA-512:14B0B05E65F01C5C6EF8AA491DBBABBF889FFB2B49E3A629A3FC37E34296FC8A00E916C337A4288A9C19FF8F987EFD4C36EEB5084AE13F3ECEF965D078F5D86B
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                IE Cache URL:https://www.java.com/_cache_4ba9/_themesdelivery/JCOM_Base_Theme/assets/js/theme.deferred.min.js
                                                                                                                                                                                Preview: var debugF = 0 <= location.search.indexOf("debug");..function debug(e) {. debugF && console.log(e).}..function openPopup(e, n, i, o, t, a, d, r, s, w, f) {. popup = window.open(e, n, "width=" + i + ",height=" + o + ",resizable=" + t + ",scrollbars=" + a + ",menubar=" + d + ",toolbar=" + r + ",location=" + s + ",directories=" + w + ",status=" + f), popup.focus().}..function getParameterByName(e) {. var n = window.location.search;. e = e.replace(/[\[\]]/g, "\\$&");. var i = new RegExp("[?&]" + e + "(=([^&#]*)|&|#|$)").exec(n);. return i ? i[2] ? decodeURIComponent(i[2].replace(/\+/g, " ")) : "" : null.}..function processRules(e, n) {. var i = ["equals", "contains", "greaterthan", "lessthan"],. o = ["contains", "equals"];. debug("Got envData"), debug(n), debug("Got Rules"), debug(e);. for (var t = 0; t < e.rules.length; t++) {. var a = e.rules[t];. debug("Checking Rule"), debug(a);. var d = !1;. if ("true" === a.default) return a;. for (var r = !0, s = 0; s < a.
                                                                                                                                                                                C:\Users\user\AppData\Local\Temp\~DF317A7A5B5B92E024.TMP
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:data
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):131556
                                                                                                                                                                                Entropy (8bit):2.954419895498588
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:384:kBqoxKEppiRyoinUomMgxmU9AHWFzDpFmAPpR1EXYR1V6XwR1uLSZfPnzZTZ1Zqi:TmU9A2Fz9nnLqWKwZs0z3
                                                                                                                                                                                MD5:2E2F44EC63DD64BB673068C9264DBF23
                                                                                                                                                                                SHA1:188EB65E506256BAB49E8CEC0BEA1D30FAE4BC21
                                                                                                                                                                                SHA-256:5DE324A709EB72EC72B454C602F3A91AA0322017F49F5BB1651187FA253902EC
                                                                                                                                                                                SHA-512:F7F5AA67D27E7BAA46DCFA75D36DEF7E408D10D88A5036EBDB9CEA25AB46E3B2311807EC4B5DE6FF31C785B504D8E392C98FECB3EF5A376E961C21990A3ADA05
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\Temp\~DFA5E950483B2D2C08.TMP
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:data
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):13077
                                                                                                                                                                                Entropy (8bit):0.5006441362222088
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:c9lLh9lLh9lIn9lIn9loFs9loF89lWFLJV+ruV+CZ+JVFHreRZ+RZ++RZV:kBqoIRXYrp7ucn/
                                                                                                                                                                                MD5:90E45B9BD75F75B728745179D324929B
                                                                                                                                                                                SHA1:B972800C2F462A575A4D78CACB2A1797D0F7F891
                                                                                                                                                                                SHA-256:609F39A4FEF851479FB08C820FAA65325D30580B03000D2B7317A3BFB4734673
                                                                                                                                                                                SHA-512:04A3E818E8144C9925E14E5CBEF8A5884E2FF630E74B8C0870915DD390518937A732C7BA8EE5C9446B2EC3E2C0B529B5A77BEC144B8FD9ABB4A6081031EA0321
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\Temp\~DFF8F4FA532DD29734.TMP
                                                                                                                                                                                Process:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                File Type:data
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):29745
                                                                                                                                                                                Entropy (8bit):0.2920107282763179
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:24:c9lLh9lLh9lIn9lIn9lRx/9lRJ9lTb9lTb9lSSU9lSSU9laAa/9laAC9laAC9lrz:kBqoxxJhHWSVSEabeQ2y
                                                                                                                                                                                MD5:CE909A43525B3843C907DCBE55E9D7DD
                                                                                                                                                                                SHA1:8B6E53CCBAAB132FF8100ECB696282F011402047
                                                                                                                                                                                SHA-256:540A8B39EAF1EF9CF341697FC4CDABBEBDED17B16321398C539639FD17EE1602
                                                                                                                                                                                SHA-512:027F1DF5288441E3BFF63ABABD90521E2A72DC20FFAC545E0F180483761229D13254375ADA525D3C5155C1BAC6602117B24617A160C4B9D21C30721B9DF17446
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: .............................*%..H..M..{y..+.0...(................... ...............................................*%..H..M..{y..+.0...(................... ..........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Local\broker.dll
                                                                                                                                                                                Process:C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exe
                                                                                                                                                                                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):499712
                                                                                                                                                                                Entropy (8bit):6.2016592723723285
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:6144:ZtuOlnq3kHzR1XyrOA5/NeQCJkGg5Q8eb2n1J3M5ScnH7dzVxWmuk:3ln/yrPXeXJk55mSn1FM5Syqmu
                                                                                                                                                                                MD5:AABA239E1C2208A6F00BB10034CBA621
                                                                                                                                                                                SHA1:2520815CDA4B4CDF652DE337D4C9285E74D2A585
                                                                                                                                                                                SHA-256:59767B2AC03EB8320A661F410D53A025C8975B12DE796E80B1C84306200F6A75
                                                                                                                                                                                SHA-512:1C80F3FF51F5D9B53232A1D9FB10C02BF22D8FBD686B76B8C6718B11BF6E834CA5B02C19535F70CBC08ADE26360D0B42C5B944D63516853FB84ACC573614AD16
                                                                                                                                                                                Malicious:true
                                                                                                                                                                                Antivirus:
                                                                                                                                                                                • Antivirus: Metadefender, Detection: 9%, Browse
                                                                                                                                                                                • Antivirus: ReversingLabs, Detection: 28%
                                                                                                                                                                                Joe Sandbox View:
                                                                                                                                                                                • Filename: presentation.jar, Detection: malicious, Browse
                                                                                                                                                                                • Filename: presentation.jar, Detection: malicious, Browse
                                                                                                                                                                                • Filename: presentation.jar, Detection: malicious, Browse
                                                                                                                                                                                Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H....................................................Z..........q...................................Rich............................PE..L....ct`...........!.....0...........=.......@......................................................................p...\.......d..............................., ...B..............................`...@............@...............................text....!.......0.................. ..`.rdata.......@.......@..............@..@.data...0.... ...@... ..............@....rsrc................`..............@..@.reloc...-.......0...p..............@..B................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\83aa4cc77f591dfc2374580bbd95f6ba_d06ed635-68f6-4e9a-955c-4899f5f57b9a
                                                                                                                                                                                Process:C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exe
                                                                                                                                                                                File Type:data
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):45
                                                                                                                                                                                Entropy (8bit):0.9111711733157262
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:/lwlt7n:WNn
                                                                                                                                                                                MD5:C8366AE350E7019AEFC9D1E6E6A498C6
                                                                                                                                                                                SHA1:5731D8A3E6568A5F2DFBBC87E3DB9637DF280B61
                                                                                                                                                                                SHA-256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
                                                                                                                                                                                SHA-512:33C980D5A638BFC791DE291EBF4B6D263B384247AB27F261A54025108F2F85374B579A026E545F81395736DD40FA4696F2163CA17640DD47F1C42BC9971B18CD
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: ........................................J2SE.
                                                                                                                                                                                C:\jar\META-INF\MANIFEST.MF
                                                                                                                                                                                Process:C:\Windows\System32\7za.exe
                                                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):154
                                                                                                                                                                                Entropy (8bit):5.06486570309354
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:3:ZLCAWIzBEb2bGQvzM3yotAXIXHVWfJHvzM3yLGZ5hM5jj5apqv:1KItG2bGQY37tAXkqHY3rlOapqv
                                                                                                                                                                                MD5:9D929FBB45D3AFDAD96F524FB602AAF8
                                                                                                                                                                                SHA1:D5CAB8C171FBD894936F2AD56CFF678663CECC8C
                                                                                                                                                                                SHA-256:6DA74DC73114968576C475F82A58B17DF9CE296B0033C769AE1E1540C3F5326C
                                                                                                                                                                                SHA-512:9BE30D1CE71CFBE534253BF932716C2E32DE60D1EA7F6799FAF840725F680503D9012E3212DD421C1F421C10DC8E09E87D1B719ACFE6C09F80B7A3CE3EBC2639
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: Manifest-Version: 1.0..Main-Class: Secure_Viewer..Permissions: all-permissions....Name: Secure_Viewer.class..SHA1-Digest: qWbZU3DJrmFn9VzxaZ2SVK8eLSM=....
                                                                                                                                                                                C:\jar\META-INF\SECURE_VIEWER.RSA
                                                                                                                                                                                Process:C:\Windows\System32\7za.exe
                                                                                                                                                                                File Type:data
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):6238
                                                                                                                                                                                Entropy (8bit):7.467316542465592
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:96:YaY/Guel4P7pg2LqnlYqufZnYi4hFald6A9HY/8yQbIWR254:HcTeK7pg2L8lYqufZnFYAdx9R2i
                                                                                                                                                                                MD5:CFF4B6140B7CD6A807A8C6E261F701E0
                                                                                                                                                                                SHA1:19ECE88FD6F059618B0C470D6D35A09E3C00240D
                                                                                                                                                                                SHA-256:1A1584581420FD5B850AC2BE68465A94F6E771B2207383EB5CAFF456E879122E
                                                                                                                                                                                SHA-512:6E91DB7FAD49D1627CD747752CFEFCF38A5026A826C41C65F1CA4C39700A6E3D500CF01E1F7324CB72D6DCAE6FECCE75DF7CECB363F8A8C73C0729F22B007D69
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: 0...*.H........0....1.0...`.H.e......0...*.H........$.....Signature-Version: 1.0..Created-By: KeyStore Explorer version 5.4.3..SHA1-Digest-Manifest-Main-Attributes: uz9oWXYZs8YUCuXGTDuco+4P5W0=..SHA1-Digest-Manifest: 1cq4wXH72JSTbyrVbP9nhmPOzIw=....Name: Secure_Viewer.class..SHA1-Digest: 7kuOOU1Dg6NbA0EUHLMvASkupHg=............0..)0.............u....x.......0...*.H........0|1.0...U....GB1.0...U....Greater Manchester1.0...U....Salford1.0...U....Sectigo Limited1$0"..U....Sectigo RSA Code Signing CA0...210324000000Z..220324235959Z0t1.0...U....RU1.0...U....Sankt-Peterburg1+0)..U..."ulica Lva Tolstogo, 1-3/a, room 361.0...U....HORUM1.0...U....HORUM0.."0...*.H.............0.........R.7.@......GR.RZ.A.1.....g.......&..MwG#......5.l...qW.W..4.g.X5......,f.3...8......Qe{......'.1fu.....-.../....A4..R.......T:>-...ETV.....^Y..7..*...F...Z.s.1..0... ...... .FT..$|...L....7...m.;W.yLj...t{ ........\.....!.....r...2.U.........0...0...U.#..0.....:.S:1.....g....4.0...U........
                                                                                                                                                                                C:\jar\META-INF\SECURE_VIEWER.SF
                                                                                                                                                                                Process:C:\Windows\System32\7za.exe
                                                                                                                                                                                File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):263
                                                                                                                                                                                Entropy (8bit):5.599738767116369
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:6:+AeM/5l1xOiov/ELKIojL8jxvDzELKtfltk4CkY3rlO5kn:WM/hQiqELToMjxnELM3NYblO5kn
                                                                                                                                                                                MD5:6A5BF08DB0DE0DF733288D3E1CF88430
                                                                                                                                                                                SHA1:992651F2E37D1E8AE8C40378B11BA14B22D84E72
                                                                                                                                                                                SHA-256:8505860836CFDD9C4AEA78C3FA9AB6840E9E44F650D9380DBDD8941590451536
                                                                                                                                                                                SHA-512:A7C0AFF96E37C3559B0DF424CC5167A22126150B9A98577B6E5205BCFFBD94844C1B7CDF35D5AD1594DD28572B1E583C2B6758C7EB6C873D03A54E511F10CDEE
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: Signature-Version: 1.0..Created-By: KeyStore Explorer version 5.4.3..SHA1-Digest-Manifest-Main-Attributes: uz9oWXYZs8YUCuXGTDuco+4P5W0=..SHA1-Digest-Manifest: 1cq4wXH72JSTbyrVbP9nhmPOzIw=....Name: Secure_Viewer.class..SHA1-Digest: 7kuOOU1Dg6NbA0EUHLMvASkupHg=....
                                                                                                                                                                                C:\jar\Secure_Viewer.class
                                                                                                                                                                                Process:C:\Windows\System32\7za.exe
                                                                                                                                                                                File Type:compiled Java class data, version 52.0 (Java 1.8)
                                                                                                                                                                                Category:dropped
                                                                                                                                                                                Size (bytes):2671
                                                                                                                                                                                Entropy (8bit):5.56255935741172
                                                                                                                                                                                Encrypted:false
                                                                                                                                                                                SSDEEP:48:hTOqeVvmIqQlvWTjiasGf/51N5DYFbJt8dgENKu92UkmATmfZTIjrW:IlmjPsGCtt8+ENV9xwTmRP
                                                                                                                                                                                MD5:400E1B5D32693D6D73DA13686D8D3B1D
                                                                                                                                                                                SHA1:A966D95370C9AE6167F55CF1699D9254AF1E2D23
                                                                                                                                                                                SHA-256:C2FEAA42DDF08B99BDD0EDD80667D8569245E2DCD7FCBACD7313EFBCD2A76ECC
                                                                                                                                                                                SHA-512:44F170E47668E21E4916E42B1DDC925D9A87E20A5FA09D6D9397A1364C7992B690F62B95539DEBA53A8FD2647E049A6EB23BB4A3A36D4A4F7C94D2057E6A20AE
                                                                                                                                                                                Malicious:false
                                                                                                                                                                                Preview: .......4....g..h..~....................x..|..............................................E....F....K....O....P....Q....R....S....M....>....A....G....<....B....T....=....=....B....V....H....N....;....D....I....;....=....?....@....U....J....C....=....L..j.[..j.\..j.b..l.b....]....`....c....[....a....^....v....r....W....Z....Y...._....p....X....t....b....v....v....v....v....v....d....Z....e...()Ljava/awt/Desktop;...()Ljava/io/InputStream;...()Ljava/lang/Runtime;...()Ljava/lang/String;...()V...(Ljava/io/InputStream;)V..-(Ljava/lang/Object;)Ljava/lang/StringBuilder;..'(Ljava/lang/String;)Ljava/lang/Process;..&(Ljava/lang/String;)Ljava/lang/String;..-(Ljava/lang/String;)Ljava/lang/StringBuilder;.."(Ljava/lang/String;)Ljava/net/URI;...(Ljava/lang/String;)V...(Ljava/net/URI;)V...([BII)I...([BII)V...([Ljava/lang/String;)V....biz/....dll...<clinit>...<init>...Code...Dd...I...LSecure_Viewer;...LineNumberTable...Ljava/io/BufferedInputStream;...Ljava/io/File;...Ljava/io/FileOutputStream;...Ljava/io

                                                                                                                                                                                Static File Info

                                                                                                                                                                                General

                                                                                                                                                                                File type:Java archive data (JAR)
                                                                                                                                                                                Entropy (8bit):7.8997767742025085
                                                                                                                                                                                TrID:
                                                                                                                                                                                • Java Archive (13504/1) 62.80%
                                                                                                                                                                                • ZIP compressed archive (8000/1) 37.20%
                                                                                                                                                                                File name:presentation.jar
                                                                                                                                                                                File size:6813
                                                                                                                                                                                MD5:6c5e7908c3a06aafd6dcebc8a2dcb674
                                                                                                                                                                                SHA1:d094aef9d24e13ab70f2ef767242be554ed855ae
                                                                                                                                                                                SHA256:cb8b20c28a0ac697b6f5bd430bd86762f6b9ef635428fe3fe77e174b172ac6f4
                                                                                                                                                                                SHA512:ea44242147e5c9589c56741059f7a7d6f64062ded254d697c06f754fa688bed0c9b5b79e9feac75d5569f560043ab01d88e427c4318a39c03768527686d53acb
                                                                                                                                                                                SSDEEP:192:kF+PVnWW4811rRBBTaikn27xcCQgcN0w7tLIdtZU1elD:kF+PV8811TBTaj27KCy0wmseD
                                                                                                                                                                                File Content Preview:PK........]..R................Secure_Viewer.class.....Vi[.W.~..'.#KTT.E.jP U...]p......hq..8.2.dB.Z..{]Z......>.............N.$.m?.=....s.Yn........._|..............._....?.8%....d\.qQ.%..e|,...Wd|*.3....B.U._.A.>...<!.C@..'.t....*.)..V..1..+X.f.-..)(.n.%

                                                                                                                                                                                File Icon

                                                                                                                                                                                Icon Hash:d28c8e8ea2868ad6

                                                                                                                                                                                Network Behavior

                                                                                                                                                                                Network Port Distribution

                                                                                                                                                                                TCP Packets

                                                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                May 6, 2021 18:09:18.030618906 CEST49721443192.168.2.650.87.249.219
                                                                                                                                                                                May 6, 2021 18:09:18.218223095 CEST4434972150.87.249.219192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:18.218528032 CEST49721443192.168.2.650.87.249.219
                                                                                                                                                                                May 6, 2021 18:09:19.376851082 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.377665997 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.417481899 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.418196917 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.418356895 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.418385983 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.427472115 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.427697897 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.467931986 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468107939 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468149900 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468185902 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468216896 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468240976 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.468286991 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.468364000 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468405008 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468446016 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.468456030 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.468480110 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.468502045 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.470177889 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.470212936 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.470256090 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.470272064 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.470293045 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.470329046 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.470390081 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.493310928 CEST49721443192.168.2.650.87.249.219
                                                                                                                                                                                May 6, 2021 18:09:19.528879881 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.529244900 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.530067921 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.530483007 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.530911922 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.530980110 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.569506884 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.569634914 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.569916010 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.569945097 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.569962025 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.569978952 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.570009947 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.570045948 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.570383072 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.570427895 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.570499897 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.570810080 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.570884943 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.570966959 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.570974112 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.571352005 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.571382999 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.571775913 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.571857929 CEST49726443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.574320078 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.574352980 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.574417114 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.574903011 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.574939966 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.575011015 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.575505972 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.575575113 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.577455997 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.577487946 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.577550888 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.577985048 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.578006983 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.578079939 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.611462116 CEST4434972699.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.611498117 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.681370020 CEST4434972150.87.249.219192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.688009024 CEST4434972150.87.249.219192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.688060999 CEST4434972150.87.249.219192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.688087940 CEST4434972150.87.249.219192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.688153028 CEST49721443192.168.2.650.87.249.219
                                                                                                                                                                                May 6, 2021 18:09:19.795480013 CEST49721443192.168.2.650.87.249.219
                                                                                                                                                                                May 6, 2021 18:09:19.867755890 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.868479013 CEST49721443192.168.2.650.87.249.219
                                                                                                                                                                                May 6, 2021 18:09:19.869993925 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.873725891 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.908513069 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.910468102 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.911154032 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.911217928 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.911309958 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.911334991 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.911689043 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.911736965 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.911744118 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.911781073 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.912859917 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.912913084 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.912981033 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.914009094 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.914079905 CEST4434972799.86.2.60192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.914082050 CEST49727443192.168.2.699.86.2.60
                                                                                                                                                                                May 6, 2021 18:09:19.914128065 CEST49727443192.168.2.699.86.2.60

                                                                                                                                                                                UDP Packets

                                                                                                                                                                                TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                May 6, 2021 18:09:03.220361948 CEST5451353192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:03.271882057 CEST53545138.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:03.854561090 CEST6204453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:03.916276932 CEST53620448.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:03.986875057 CEST6379153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:04.038378000 CEST53637918.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:05.434446096 CEST6426753192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:05.494481087 CEST53642678.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:07.688136101 CEST4944853192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:07.737359047 CEST53494488.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:08.855503082 CEST6034253192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:08.905670881 CEST53603428.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:09.731506109 CEST6134653192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:09.780610085 CEST53613468.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:10.926995039 CEST5177453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:10.975791931 CEST53517748.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:12.187297106 CEST5602353192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:12.238985062 CEST53560238.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:13.583226919 CEST5838453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:13.631818056 CEST53583848.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:15.543122053 CEST6026153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:15.565316916 CEST5606153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:15.601613998 CEST53602618.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:15.618786097 CEST53560618.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:16.809379101 CEST5833653192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:16.869489908 CEST53583368.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:17.058248043 CEST5378153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:17.106874943 CEST53537818.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:17.332037926 CEST5406453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:17.400758982 CEST53540648.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:17.693479061 CEST5281153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:17.752043009 CEST53528118.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:17.954039097 CEST5529953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:18.015702963 CEST53552998.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:18.107434034 CEST6374553192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:18.166744947 CEST53637458.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:18.733800888 CEST5005553192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:18.798551083 CEST53500558.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.312356949 CEST6137453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:19.374965906 CEST53613748.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.461990118 CEST5033953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:19.470868111 CEST6330753192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:19.532146931 CEST53633078.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:19.534553051 CEST53503398.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:20.061518908 CEST4969453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:20.123075008 CEST53496948.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:20.388068914 CEST5498253192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:20.451607943 CEST53549828.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:20.880404949 CEST5001053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:20.938842058 CEST53500108.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:21.071501017 CEST6371853192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:21.129270077 CEST6211653192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:21.133167028 CEST53637188.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:21.189191103 CEST53621168.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:21.386830091 CEST6381653192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:21.445974112 CEST53638168.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:21.567563057 CEST5501453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:21.581800938 CEST6220853192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:21.628978968 CEST53550148.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:21.641249895 CEST53622088.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:21.809602976 CEST5757453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:21.847337961 CEST5181853192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:21.914436102 CEST53575748.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:21.933885098 CEST53518188.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:23.279515982 CEST5662853192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:23.328221083 CEST53566288.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:24.565107107 CEST6077853192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:24.615564108 CEST53607788.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:30.473784924 CEST5379953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:30.525399923 CEST53537998.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:31.641411066 CEST5468353192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:31.690027952 CEST53546838.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:33.015264988 CEST5932953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:33.066375017 CEST53593298.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:34.341239929 CEST6402153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:34.392887115 CEST53640218.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:37.033008099 CEST5612953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:37.093127966 CEST53561298.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:40.836272955 CEST5817753192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:40.911509037 CEST53581778.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:45.526552916 CEST5070053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:45.575516939 CEST53507008.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:46.459764957 CEST5406953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:46.508558989 CEST53540698.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:46.535262108 CEST5070053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:46.585947990 CEST53507008.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:47.476183891 CEST5406953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:47.533520937 CEST53540698.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:47.537137985 CEST5070053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:47.588042974 CEST53507008.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:48.474204063 CEST5406953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:48.524506092 CEST53540698.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:49.536612034 CEST5070053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:49.585320950 CEST53507008.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:50.493859053 CEST5406953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:50.542735100 CEST53540698.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:53.541969061 CEST5070053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:53.593271017 CEST53507008.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:54.494371891 CEST5406953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:54.546031952 CEST53540698.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:09:57.854821920 CEST6117853192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:09:57.917279959 CEST53611788.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:03.334332943 CEST5701753192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:03.394951105 CEST53570178.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:26.176960945 CEST5632753192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:26.240812063 CEST53563278.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:37.869673014 CEST5024353192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:38.033804893 CEST53502438.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:38.763875961 CEST6205553192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:38.821377993 CEST53620558.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:39.405009031 CEST6124953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:39.463521957 CEST53612498.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:39.950659990 CEST6525253192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:40.134582996 CEST53652528.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:40.456129074 CEST6436753192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:40.514662027 CEST5506653192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:40.523745060 CEST53643678.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:40.574218988 CEST53550668.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:40.700234890 CEST6021153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:40.845571995 CEST53602118.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:41.444329977 CEST5657053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:41.505940914 CEST53565708.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:42.013689041 CEST5845453192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:42.070698977 CEST53584548.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:42.954932928 CEST5518053192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:43.008703947 CEST53551808.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:43.940526962 CEST5872153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:44.097349882 CEST53587218.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:44.608972073 CEST5769153192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:44.669256926 CEST53576918.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:10:59.648129940 CEST5294353192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:10:59.696768999 CEST53529438.8.8.8192.168.2.6
                                                                                                                                                                                May 6, 2021 18:11:01.264758110 CEST5948953192.168.2.68.8.8.8
                                                                                                                                                                                May 6, 2021 18:11:01.330215931 CEST53594898.8.8.8192.168.2.6

                                                                                                                                                                                DNS Queries

                                                                                                                                                                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                                                                                                                                                                May 6, 2021 18:09:15.565316916 CEST192.168.2.68.8.8.80x8eacStandard query (0)www.java.comA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:16.809379101 CEST192.168.2.68.8.8.80x7b44Standard query (0)www.java.comA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:17.332037926 CEST192.168.2.68.8.8.80x196Standard query (0)static.oracle.comA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:17.693479061 CEST192.168.2.68.8.8.80x2a8eStandard query (0)s.go-mpulse.netA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:17.954039097 CEST192.168.2.68.8.8.80x84aStandard query (0)docs.cyberservices.bizA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:18.107434034 CEST192.168.2.68.8.8.80x1699Standard query (0)c.go-mpulse.netA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:18.733800888 CEST192.168.2.68.8.8.80xa0f7Standard query (0)c.oracleinfinity.ioA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.312356949 CEST192.168.2.68.8.8.80xd4d6Standard query (0)consent.trustarc.comA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.461990118 CEST192.168.2.68.8.8.80xf331Standard query (0)dc.oracleinfinity.ioA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.470868111 CEST192.168.2.68.8.8.80x6a84Standard query (0)www.oracle.comA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.061518908 CEST192.168.2.68.8.8.80x499dStandard query (0)consent-pref.trustarc.comA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.388068914 CEST192.168.2.68.8.8.80xe1a5Standard query (0)consent-st.trustarc.comA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.880404949 CEST192.168.2.68.8.8.80x7bb3Standard query (0)oracle.112.2o7.netA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.071501017 CEST192.168.2.68.8.8.80x78cdStandard query (0)prefmgr-cookie.truste-svc.netA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.386830091 CEST192.168.2.68.8.8.80x1e59Standard query (0)6852bd12.akstat.ioA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.567563057 CEST192.168.2.68.8.8.80x7bcfStandard query (0)trial-eum-clientnsv4-s.akamaihd.netA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.581800938 CEST192.168.2.68.8.8.80xd6e5Standard query (0)trial-eum-clienttons-s.akamaihd.netA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.809602976 CEST192.168.2.68.8.8.80x25aaStandard query (0)84-17-52-78_s-23-32-238-131_ts-1620317361-clienttons-s.akamaihd.netA (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.847337961 CEST192.168.2.68.8.8.80x84a7Standard query (0)kqitits7mulnqyeucsyq-pe4433-4b66e3cf2-clientnsv4-s.akamaihd.netA (IP address)IN (0x0001)

                                                                                                                                                                                DNS Answers

                                                                                                                                                                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                                                                                                                                                                May 6, 2021 18:09:15.618786097 CEST8.8.8.8192.168.2.60x8eacNo error (0)www.java.comds-www.java.com.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:16.869489908 CEST8.8.8.8192.168.2.60x7b44No error (0)www.java.comds-www.java.com.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:17.400758982 CEST8.8.8.8192.168.2.60x196No error (0)static.oracle.comds-oracle-microsites.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:17.752043009 CEST8.8.8.8192.168.2.60x2a8eNo error (0)s.go-mpulse.netip46.go-mpulse.net.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:18.015702963 CEST8.8.8.8192.168.2.60x84aNo error (0)docs.cyberservices.biz50.87.249.219A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:18.166744947 CEST8.8.8.8192.168.2.60x1699No error (0)c.go-mpulse.netwildcard46.go-mpulse.net.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:18.798551083 CEST8.8.8.8192.168.2.60xa0f7No error (0)c.oracleinfinity.ioc.oracleinfinity.io.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.374965906 CEST8.8.8.8192.168.2.60xd4d6No error (0)consent.trustarc.com99.86.2.60A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.374965906 CEST8.8.8.8192.168.2.60xd4d6No error (0)consent.trustarc.com99.86.2.78A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.374965906 CEST8.8.8.8192.168.2.60xd4d6No error (0)consent.trustarc.com99.86.2.32A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.374965906 CEST8.8.8.8192.168.2.60xd4d6No error (0)consent.trustarc.com99.86.2.119A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.532146931 CEST8.8.8.8192.168.2.60x6a84No error (0)www.oracle.comds-www.oracle.com.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:19.534553051 CEST8.8.8.8192.168.2.60xf331No error (0)dc.oracleinfinity.iodc.oracleinfinity.io.akadns.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.123075008 CEST8.8.8.8192.168.2.60x499dNo error (0)consent-pref.trustarc.com13.32.21.15A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.123075008 CEST8.8.8.8192.168.2.60x499dNo error (0)consent-pref.trustarc.com13.32.21.39A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.123075008 CEST8.8.8.8192.168.2.60x499dNo error (0)consent-pref.trustarc.com13.32.21.47A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.123075008 CEST8.8.8.8192.168.2.60x499dNo error (0)consent-pref.trustarc.com13.32.21.78A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.451607943 CEST8.8.8.8192.168.2.60xe1a5No error (0)consent-st.trustarc.com65.9.66.38A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.451607943 CEST8.8.8.8192.168.2.60xe1a5No error (0)consent-st.trustarc.com65.9.66.37A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.451607943 CEST8.8.8.8192.168.2.60xe1a5No error (0)consent-st.trustarc.com65.9.66.110A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.451607943 CEST8.8.8.8192.168.2.60xe1a5No error (0)consent-st.trustarc.com65.9.66.35A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.938842058 CEST8.8.8.8192.168.2.60x7bb3No error (0)oracle.112.2o7.net35.181.18.61A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.938842058 CEST8.8.8.8192.168.2.60x7bb3No error (0)oracle.112.2o7.net15.237.76.117A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:20.938842058 CEST8.8.8.8192.168.2.60x7bb3No error (0)oracle.112.2o7.net15.237.136.106A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.133167028 CEST8.8.8.8192.168.2.60x78cdNo error (0)prefmgr-cookie.truste-svc.net3.212.50.245A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.133167028 CEST8.8.8.8192.168.2.60x78cdNo error (0)prefmgr-cookie.truste-svc.net34.202.206.65A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.133167028 CEST8.8.8.8192.168.2.60x78cdNo error (0)prefmgr-cookie.truste-svc.net3.232.192.25A (IP address)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.445974112 CEST8.8.8.8192.168.2.60x1e59No error (0)6852bd12.akstat.iowildcard46.akstat.io.edgekey.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.628978968 CEST8.8.8.8192.168.2.60x7bcfNo error (0)trial-eum-clientnsv4-s.akamaihd.neta248.b.akamai.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.641249895 CEST8.8.8.8192.168.2.60xd6e5No error (0)trial-eum-clienttons-s.akamaihd.nettrial-eum.cname.clienttons.comCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.641249895 CEST8.8.8.8192.168.2.60xd6e5No error (0)trial-eum.cname.clienttons.coma1024.dscg.akamai.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.914436102 CEST8.8.8.8192.168.2.60x25aaNo error (0)84-17-52-78_s-23-32-238-131_ts-1620317361-clienttons-s.akamaihd.net84.17.52.78_s-23.32.238.131_ts-1620317361.cname.clienttons.comCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.914436102 CEST8.8.8.8192.168.2.60x25aaNo error (0)84.17.52.78_s-23.32.238.131_ts-1620317361.cname.clienttons.coma1024.dscg.akamai.netCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.933885098 CEST8.8.8.8192.168.2.60x84a7No error (0)kqitits7mulnqyeucsyq-pe4433-4b66e3cf2-clientnsv4-s.akamaihd.netkqitits7mulnqyeucsyq-pe4433-4b66e3cf2.ipv4-only.cname.clienttons.comCNAME (Canonical name)IN (0x0001)
                                                                                                                                                                                May 6, 2021 18:09:21.933885098 CEST8.8.8.8192.168.2.60x84a7No error (0)kqitits7mulnqyeucsyq-pe4433-4b66e3cf2.ipv4-only.cname.clienttons.coma248.b.akamai.netCNAME (Canonical name)IN (0x0001)

                                                                                                                                                                                HTTPS Packets

                                                                                                                                                                                TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                                                                                                                                                                                May 6, 2021 18:09:19.470177889 CEST99.86.2.60443192.168.2.649726CN=*.trustarc.com, O=TrustArc Inc, L=San Francisco, ST=California, C=US CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USThu May 21 19:53:46 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Sun Jul 17 21:03:01 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034
                                                                                                                                                                                May 6, 2021 18:09:19.470293045 CEST99.86.2.60443192.168.2.649727CN=*.trustarc.com, O=TrustArc Inc, L=San Francisco, ST=California, C=US CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USThu May 21 19:53:46 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Sun Jul 17 21:03:01 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034
                                                                                                                                                                                May 6, 2021 18:09:19.688087940 CEST50.87.249.219443192.168.2.649721CN=cpcalendars.servicesteam.org CN=R3, O=Let's Encrypt, C=USCN=R3, O=Let's Encrypt, C=US CN=DST Root CA X3, O=Digital Signature Trust Co.Mon Apr 26 07:10:28 CEST 2021 Wed Oct 07 21:21:40 CEST 2020Sun Jul 25 07:10:28 CEST 2021 Wed Sep 29 21:21:40 CEST 2021771,49188-49192-61-49190-49194-107-106-49162-49172-53-49157-49167-57-56-49187-49191-60-49189-49193-103-64-49161-49171-47-49156-49166-51-50-49196-49195-49200-157-49198-49202-159-163-49199-156-49197-49201-158-162-255,10-11-13-23-0,23-24-25-9-10-11-12-13-14-22,0d2935c58fe676744fecc8614ee5356c7
                                                                                                                                                                                CN=R3, O=Let's Encrypt, C=USCN=DST Root CA X3, O=Digital Signature Trust Co.Wed Oct 07 21:21:40 CEST 2020Wed Sep 29 21:21:40 CEST 2021
                                                                                                                                                                                May 6, 2021 18:09:20.219572067 CEST13.32.21.15443192.168.2.649733CN=*.trustarc.com, O=TrustArc Inc, L=San Francisco, ST=California, C=US CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USThu May 21 19:53:46 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Sun Jul 17 21:03:01 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034
                                                                                                                                                                                May 6, 2021 18:09:20.219609022 CEST13.32.21.15443192.168.2.649732CN=*.trustarc.com, O=TrustArc Inc, L=San Francisco, ST=California, C=US CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USThu May 21 19:53:46 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Sun Jul 17 21:03:01 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034
                                                                                                                                                                                May 6, 2021 18:09:20.541434050 CEST65.9.66.38443192.168.2.649734CN=*.trustarc.com, O=TrustArc Inc, L=San Francisco, ST=California, C=US CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USThu May 21 19:53:46 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Sun Jul 17 21:03:01 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034
                                                                                                                                                                                May 6, 2021 18:09:20.543059111 CEST65.9.66.38443192.168.2.649735CN=*.trustarc.com, O=TrustArc Inc, L=San Francisco, ST=California, C=US CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USThu May 21 19:53:46 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Sun Jul 17 21:03:01 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034
                                                                                                                                                                                May 6, 2021 18:09:21.042653084 CEST35.181.18.61443192.168.2.649737CN=*.112.2o7.net, O=Adobe Systems Incorporated, L=San Jose, ST=California, C=US CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USWed Apr 14 02:00:00 CEST 2021 Thu Sep 24 02:00:00 CEST 2020 Fri Nov 10 01:00:00 CET 2006Thu Apr 21 01:59:59 CEST 2022 Tue Sep 24 01:59:59 CEST 2030 Mon Nov 10 01:00:00 CET 2031771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=USCN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USThu Sep 24 02:00:00 CEST 2020Tue Sep 24 01:59:59 CEST 2030
                                                                                                                                                                                CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USFri Nov 10 01:00:00 CET 2006Mon Nov 10 01:00:00 CET 2031
                                                                                                                                                                                May 6, 2021 18:09:21.043514013 CEST35.181.18.61443192.168.2.649736CN=*.112.2o7.net, O=Adobe Systems Incorporated, L=San Jose, ST=California, C=US CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USWed Apr 14 02:00:00 CEST 2021 Thu Sep 24 02:00:00 CEST 2020 Fri Nov 10 01:00:00 CET 2006Thu Apr 21 01:59:59 CEST 2022 Tue Sep 24 01:59:59 CEST 2030 Mon Nov 10 01:00:00 CET 2031771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=USCN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USThu Sep 24 02:00:00 CEST 2020Tue Sep 24 01:59:59 CEST 2030
                                                                                                                                                                                CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USFri Nov 10 01:00:00 CET 2006Mon Nov 10 01:00:00 CET 2031
                                                                                                                                                                                May 6, 2021 18:09:21.416762114 CEST3.212.50.245443192.168.2.649739CN=*.truste-svc.net, OU=Domain Control Validated CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USSat Apr 25 13:19:21 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Thu Jun 23 16:37:27 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034
                                                                                                                                                                                May 6, 2021 18:09:21.428395987 CEST3.212.50.245443192.168.2.649738CN=*.truste-svc.net, OU=Domain Control Validated CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USCN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=US OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USSat Apr 25 13:19:21 CEST 2020 Tue May 03 09:00:00 CEST 2011 Wed Jan 01 08:00:00 CET 2014 Tue Jun 29 19:06:20 CEST 2004Thu Jun 23 16:37:27 CEST 2022 Sat May 03 09:00:00 CEST 2031 Fri May 30 09:00:00 CEST 2031 Thu Jun 29 19:06:20 CEST 2034771,49196-49195-49200-49199-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-10-11-13-35-16-23-24-65281,29-23-24,09e10692f1b7f78228b2d4e424db3a98c
                                                                                                                                                                                CN=Go Daddy Secure Certificate Authority - G2, OU=http://certs.godaddy.com/repository/, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USCN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USTue May 03 09:00:00 CEST 2011Sat May 03 09:00:00 CEST 2031
                                                                                                                                                                                CN=Go Daddy Root Certificate Authority - G2, O="GoDaddy.com, Inc.", L=Scottsdale, ST=Arizona, C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USWed Jan 01 08:00:00 CET 2014Fri May 30 09:00:00 CEST 2031
                                                                                                                                                                                OU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USOU=Go Daddy Class 2 Certification Authority, O="The Go Daddy Group, Inc.", C=USTue Jun 29 19:06:20 CEST 2004Thu Jun 29 19:06:20 CEST 2034

                                                                                                                                                                                Code Manipulations

                                                                                                                                                                                Statistics

                                                                                                                                                                                Behavior

                                                                                                                                                                                Click to jump to process

                                                                                                                                                                                System Behavior

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:10
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                Commandline:C:\Windows\system32\cmd.exe /c 7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar'
                                                                                                                                                                                Imagebase:0x7ff7180e0000
                                                                                                                                                                                File size:273920 bytes
                                                                                                                                                                                MD5 hash:4E2ACF4F8A396486AB4268C94A6A245F
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:10
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Windows\System32\7za.exe
                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                Commandline:7za.exe x -y -oC:\jar 'C:\Users\user\Desktop\presentation.jar'
                                                                                                                                                                                Imagebase:0x180000
                                                                                                                                                                                File size:289792 bytes
                                                                                                                                                                                MD5 hash:77E556CDFDC5C592F5C46DB4127C6F4C
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:11
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                Commandline:'C:\Windows\System32\cmd.exe' /c java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer >> C:\cmdlinestart.log 2>&1
                                                                                                                                                                                Imagebase:0x7ff7180e0000
                                                                                                                                                                                File size:273920 bytes
                                                                                                                                                                                MD5 hash:4E2ACF4F8A396486AB4268C94A6A245F
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:12
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                Imagebase:0x7ff61de10000
                                                                                                                                                                                File size:625664 bytes
                                                                                                                                                                                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:12
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_885250\java.exe
                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                Commandline:java.exe -jar 'C:\Users\user\Desktop\presentation.jar' Secure_Viewer
                                                                                                                                                                                Imagebase:0xa90000
                                                                                                                                                                                File size:192376 bytes
                                                                                                                                                                                MD5 hash:28733BA8C383E865338638DF5196E6FE
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:Java
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:13
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Windows\SysWOW64\icacls.exe
                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                Commandline:C:\Windows\system32\icacls.exe C:\ProgramData\Oracle\Java\.oracle_jre_usage /grant 'everyone':(OI)(CI)M
                                                                                                                                                                                Imagebase:0x1f0000
                                                                                                                                                                                File size:29696 bytes
                                                                                                                                                                                MD5 hash:FF0D1D4317A44C951240FAE75075D501
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:13
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                Imagebase:0x7ff61de10000
                                                                                                                                                                                File size:625664 bytes
                                                                                                                                                                                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:14
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Program Files\internet explorer\iexplore.exe
                                                                                                                                                                                Wow64 process (32bit):false
                                                                                                                                                                                Commandline:'C:\Program Files\Internet Explorer\iexplore.exe' https://www.java.com/
                                                                                                                                                                                Imagebase:0x7ff721e20000
                                                                                                                                                                                File size:823560 bytes
                                                                                                                                                                                MD5 hash:6465CB92B25A7BC1DF8E01D8AC5E7596
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:15
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Program Files (x86)\Internet Explorer\iexplore.exe
                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                Commandline:'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6828 CREDAT:17410 /prefetch:2
                                                                                                                                                                                Imagebase:0x220000
                                                                                                                                                                                File size:822536 bytes
                                                                                                                                                                                MD5 hash:071277CC2E3DF41EEEA8013E2AB58D5A
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                General

                                                                                                                                                                                Start time:18:09:21
                                                                                                                                                                                Start date:06/05/2021
                                                                                                                                                                                Path:C:\Windows\SysWOW64\regsvr32.exe
                                                                                                                                                                                Wow64 process (32bit):true
                                                                                                                                                                                Commandline:regsvr32.exe /s C:\Users\user\AppData\Local\broker.dll
                                                                                                                                                                                Imagebase:0x11f0000
                                                                                                                                                                                File size:20992 bytes
                                                                                                                                                                                MD5 hash:426E7499F6A7346F0410DEAD0805586B
                                                                                                                                                                                Has elevated privileges:true
                                                                                                                                                                                Has administrator privileges:true
                                                                                                                                                                                Programmed in:C, C++ or other language
                                                                                                                                                                                Yara matches:
                                                                                                                                                                                • Rule: JoeSecurity_Ursnif_1, Description: Yara detected Ursnif, Source: 0000000A.00000003.535228068.0000000003410000.00000040.00000001.sdmp, Author: Joe Security
                                                                                                                                                                                Reputation:high

                                                                                                                                                                                Disassembly

                                                                                                                                                                                Code Analysis

                                                                                                                                                                                Reset < >