Windows Analysis Report https://1drv.ms:443/o/s!BH0KAtIoTvDMgQINIwbDDmuQjxkp?e=tej6OVmcREW9hZcUcQddjw&at=9

Overview

General Information

Sample URL: https://1drv.ms:443/o/s!BH0KAtIoTvDMgQINIwbDDmuQjxkp?e=tej6OVmcREW9hZcUcQddjw&at=9
Analysis ID: 519
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 72
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Phishing site detected (based on shot template match)
Yara detected HtmlPhish7
Yara detected HtmlPhish10
Antivirus detection for URL or domain
HTML body contains low number of good links
No HTML title found

Classification

AV Detection:

barindex
Antivirus detection for URL or domain
Source: https://great-efficacious-libra.glitch.me/ue908.html SlashNext: Label: Fake Login Page type: Phishing & Social Engineering

Phishing:

barindex
Phishing site detected (based on shot template match)
Source: https://great-efficacious-libra.glitch.me/ue908.html Matcher: Template: office matched
Yara detected HtmlPhish7
Source: Yara match File source: 69819.3.pages.csv, type: HTML
Yara detected HtmlPhish10
Source: Yara match File source: 69819.3.pages.csv, type: HTML
HTML body contains low number of good links
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: Number of links: 0
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: Number of links: 0
No HTML title found
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: HTML title missing
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: HTML title missing
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: No <meta name="author".. found
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: No <meta name="author".. found
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: No <meta name="copyright".. found
Source: https://great-efficacious-libra.glitch.me/ue908.html HTTP Parser: No <meta name="copyright".. found
Source: unknown DNS traffic detected: queries for: accounts.google.com
Source: unknown Network traffic detected: HTTP traffic on port 49710 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51425
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61070
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 53734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 59460 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57305 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 52716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61591
Source: unknown Network traffic detected: HTTP traffic on port 52716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 51043
Source: unknown Network traffic detected: HTTP traffic on port 51043 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57305
Source: unknown Network traffic detected: HTTP traffic on port 61070 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57692 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 54166 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 54166
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57692
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58060
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62210
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49737
Source: unknown Network traffic detected: HTTP traffic on port 63523 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 55217 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 58060 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 63523
Source: unknown Network traffic detected: HTTP traffic on port 49709 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 57381 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 61161
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55816
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 55217
Source: unknown Network traffic detected: HTTP traffic on port 62210 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 53734
Source: unknown Network traffic detected: HTTP traffic on port 58472 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 58472
Source: unknown Network traffic detected: HTTP traffic on port 55816 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 64523 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 61591 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 59460
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 57381
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 64523
Source: unknown Network traffic detected: HTTP traffic on port 61161 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 51425 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 62202
Source: unknown Network traffic detected: HTTP traffic on port 62202 -> 443
Source: unknown TCP traffic detected without corresponding DNS query: 92.123.195.114
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.102.62
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.102.62
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.102.62
Source: unknown TCP traffic detected without corresponding DNS query: 20.50.102.62
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 92.123.195.114
Source: unknown TCP traffic detected without corresponding DNS query: 92.123.195.114
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.41.209
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.41.209
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.41.209
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.41.209
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.221.240
Source: unknown TCP traffic detected without corresponding DNS query: 67.27.157.126
Source: unknown TCP traffic detected without corresponding DNS query: 67.27.157.126
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=92.0.4515.107&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-92.0.4515.107Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /o/s!BH0KAtIoTvDMgQINIwbDDmuQjxkp?e=tej6OVmcREW9hZcUcQddjw&at=9 HTTP/1.1Host: 1drv.msConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /crx/blobs/Acy1k0asWvVP5wt4i50ZtXmm6vOxVjDtXf5_Qw7lkxpfoCKuSDoNNBzgKJlH33NRLE64ElFJ7tH1Z-k87IEqFgY8CrWkCeKjCA9RVUlD1akfG5oQv3gVAMZSmuXL0E38bjZru1-bydB5IpnTlf_6cw/extension_9221_427_0_1.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /api/proxy?v=3 HTTP/1.1Host: skyapi.onedrive.live.comConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: same-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeReferer: https://onedrive.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: xid=af40a8eb-cf35-44b9-b099-fd2b57bb6167&&RD00155D998D3A&315; wla42=; mkt=en-US; xidseq=3; E=P:Fd+1S+WB2Yg=:8rDhaVn++UGOizgd2TnZlTYO+WNUIxy7NzUwWkIP830=:F
Source: global traffic HTTP traffic detected: GET /mydata/myprofile/expressionprofile/profilephoto:UserTileStatic,UserTileSmall/MeControlMediumUserTile?ck=1&ex=24&fofoff=1&sc=1632800013826 HTTP/1.1Host: storage.live.comConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://onenote.officeapps.live.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: xid=af40a8eb-cf35-44b9-b099-fd2b57bb6167&&RD00155D998D3A&315; wla42=; mkt=en-US; xidseq=3; E=P:Fd+1S+WB2Yg=:8rDhaVn++UGOizgd2TnZlTYO+WNUIxy7NzUwWkIP830=:F; BP=l=SDX.Skydrive&FR=&ST=
Source: global traffic HTTP traffic detected: GET /ue908.html HTTP/1.1Host: great-efficacious-libra.glitch.meConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /css/hover.css HTTP/1.1Host: great-efficacious-libra.glitch.meConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://great-efficacious-libra.glitch.me/ue908.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /bootstrap/4.0.0/css/bootstrap.min.css HTTP/1.1Host: maxcdn.bootstrapcdn.comConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"Origin: https://great-efficacious-libra.glitch.mesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: styleReferer: https://great-efficacious-libra.glitch.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /ajax/libs/popper.js/1.12.9/umd/popper.min.js HTTP/1.1Host: cdnjs.cloudflare.comConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"Origin: https://great-efficacious-libra.glitch.mesec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://great-efficacious-libra.glitch.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /css/hover.css HTTP/1.1Host: great-efficacious-libra.glitch.meConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: text/css,*/*;q=0.1Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://great-efficacious-libra.glitch.me/ue908.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /1Rvzzk8/gmail1.png HTTP/1.1Host: i.ibb.coConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://great-efficacious-libra.glitch.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: great-efficacious-libra.glitch.meConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://great-efficacious-libra.glitch.me/ue908.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /vZXCdtH/outlook.png HTTP/1.1Host: i.ibb.coConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://great-efficacious-libra.glitch.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /6rZqcnD/office365.png HTTP/1.1Host: i.ibb.coConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://great-efficacious-libra.glitch.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /qNj7bsz/other1.png HTTP/1.1Host: i.ibb.coConnection: keep-alivesec-ch-ua: "Chromium";v="92", " Not A;Brand";v="99", "Google Chrome";v="92"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://great-efficacious-libra.glitch.me/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 27 Sep 2021 18:33:40 GMTContent-Length: 3616Connection: closeCache-Control: max-age=0
Source: History-journal.0.dr, Favicons.0.dr String found in binary or memory: https://1drv.ms/o/s
Source: Reporting and NEL.2.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=5U%2FkU%2BjFeOKRc1nOWWsjAOd%2BgExs5Erq0pNBD0rlRsbmWcgrcyjk0
Source: Reporting and NEL.2.dr String found in binary or memory: https://a.nel.cloudflare.com/report/v3?s=gbp5iRzxkFD5bhKdG2wq%2Bc1cH1RkcFxLNQmF1R8TtAsFeFWa3oyJOZItm
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr, manifest.json0.0.dr String found in binary or memory: https://accounts.google.com
Source: 93a3fa42e61c139b_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.7.2.min.js
Source: 7444ea2da1317cfb_0.0.dr String found in binary or memory: https://ajax.aspnetcdn.com/ajax/jQuery/jquery-2.1.3.min.js
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr String found in binary or memory: https://ajax.googleapis.com
Source: Network Action Predictor.0.dr String found in binary or memory: https://ajax.googleapis.com/
Source: 92ac6bcd4238ab45_0.0.dr String found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
Source: ba859982ea35aebb_0.0.dr String found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.jsa
Source: ba859982ea35aebb_0.0.dr String found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.jsaD
Source: f7dd50aa7b62010a_0.0.dr String found in binary or memory: https://amcdn.msftauth.net/me?partner=OneNoteOnline&version=10.21153.1&market=EN-US&wrapperId=suites
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr, manifest.json0.0.dr String found in binary or memory: https://apis.google.com
Source: 02d4aaf953a2f242_0.0.dr String found in binary or memory: https://c1-officeapps-15.cdn.office.net/o/s/161451741026_App_Scripts/Feedback/latest/Intl/en/officeb
Source: 65947caaf1db9298_0.0.dr String found in binary or memory: https://c1-officeapps-15.cdn.office.net/o/s/161451741026_App_Scripts/Feedback/latest/officebrowserfe
Source: 4faa0455d4039afa_0.0.dr String found in binary or memory: https://c1-officeapps-15.cdn.office.net/o/s/161451741026_App_Scripts/wacairspaceanimationlibrary.js
Source: fa1d01002fa990ce_0.0.dr String found in binary or memory: https://c1-officeapps-15.cdn.office.net/o/s/h4DDC354F0F9CEFBE_App_Scripts/MicrosoftAjax.js
Source: 2f093249a8f8bca4_0.0.dr String found in binary or memory: https://c1-officeapps-15.cdn.office.net/o/s/h86134E806FB32D83_App_Scripts/1033/CommonIntl.js
Source: Favicons.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/resources/1033/FavIcon_OneNote.ico
Source: 0e9db8ca960fef70_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/1033/OneNoteSimplified.Wac.TellMeM
Source: 97f512e7491a7456_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/1033/onenote-navpane-strings.min.j
Source: 12609919983ee517_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/1033/onenote-ribbon-intl.min.js
Source: 9bee922fc98a1fe8_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/1033/onenote-ribbon-sprite-lazy.mi
Source: f8454b9b69153474_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/1033/osfruntime_strings.js
Source: 2e60a340af51fb52_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/OfficeExtension.WacRuntime.js
Source: 1bff270e32b0ba8c_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/OneNote.box4.dll2.js
Source: 41925020bae877cf_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/OneNoteSimplified.Wac.TellMeSugges
Source: 941b06fb8478e48f_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/OsfRuntimeOneNoteWAC.js
Source: 6c5096a78a4a9b6d_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/appChrome.min.js
Source: 1fd1d25d46212c70_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/appChromeLazy.min.js
Source: ae91f4d35288cc27_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/appIconsLazy.min.js
Source: f3d7599b2ef11517_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/common.min.js
Source: 9e03917aff818da1_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/common50.min.js
Source: 9b678471d0290a69_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/navigation.min.js
Source: a29dc5bca0d7f772_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/onenoteloadingspinner.min.js
Source: 9ef530ac8e11a4d2_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/oreolazy.min.js
Source: 9ed2fcd8165ac8a3_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/oreonavpane.min.js
Source: b67b6a74d56845ce_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/oreonotebookpane.min.js
Source: d83685a8009852e3_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/oreosearchpane.min.js
Source: 3a0931e6eb23e5a7_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/otelFull.min.js
Source: 7627f51e9323d3c1_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/suiteux-shell/js/suiteux.shell.cor
Source: 9a25d4617c36f111_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/suiteux-shell/js/suiteux.shell.plu
Source: c2a8b1231073fa2a_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/uiFabricLazy.min.js
Source: 4a0fdcbc7d76ecf2_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/161451741026_App_Scripts/uiSlice20.min.js
Source: 7cd4eb7d184ef6b5_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/h06FE78141D1F3A43_App_Scripts/Compat.js
Source: 253ada26cb26b6aa_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/h207E6AA8E669E1DB_App_Scripts/common.min.js
Source: 387591b72ede2a53_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/h29DB8AD8C3F08967_App_Scripts/1033/WoncaIntl.js
Source: 1bc1b686e63f82ff_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/h343F8D452E239C63_App_Scripts/onenoteSync.min.js
Source: 047447b274c22c54_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/h4553A1519A41E5EA_App_Scripts/1033/OneNoteIntl.js
Source: af5c3b38004ce8f5_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/h5277160D6043DE10_App_Scripts/OneNote.js
Source: 8e1634acc9edb463_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/hB4C30F06EFC8E468_App_Scripts/OneNote.box4.dll1.js
Source: 3da036a9ad3ac2b3_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/hCBE3A397F2722612_App_Scripts/wacBoot.min.js
Source: 089da834c75847e1_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/hCF8E38AF39F430EA_App_Scripts/jSanity.js
Source: a4e4f981b679f738_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/hDDF49EC81121027B_App_Scripts/1033/Box4Intl.js
Source: 3cea4a09fd476ccb_0.0.dr String found in binary or memory: https://c1-onenote-15.cdn.office.net/o/s/hF3AC95D9C5F18E11_App_Scripts/onenote-boot.min.js
Source: 9353779ee6ffff87_0.0.dr String found in binary or memory: https://cdn.onenote.net/officeaddins/161452140454_Scripts/BrowserUls.js
Source: 494f0b1321cc8f5a_0.0.dr String found in binary or memory: https://cdn.onenote.net/officeaddins/161452140454_Scripts/CommonDiagnostics.js
Source: 8db287ed550f8594_0.0.dr String found in binary or memory: https://cdn.onenote.net/officeaddins/161452140454_Scripts/ExternalResources/js-cookie.js
Source: faa473b89c4cb6d5_0.0.dr String found in binary or memory: https://cdn.onenote.net/officeaddins/161452140454_Scripts/Instrumentation.js
Source: dc791ca3e3d643d6_0.0.dr String found in binary or memory: https://cdn.onenote.net/officeaddins/161452140454_Scripts/LearningTools/LearningTools.js
Source: cbc4c2abcb8aa92a_0.0.dr String found in binary or memory: https://cdn.onenote.net/officeaddins/161452140454_Scripts/aria-web-telemetry-2.9.0.min.js
Source: 621b14f10032e8ca_0.0.dr String found in binary or memory: https://cdn.onenote.net/officeaddins/161452140454_Scripts/pickadate.min.js
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr String found in binary or memory: https://cdnjs.cloudflare.com
Source: 526dece192072100_0.0.dr String found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: Network Action Predictor.0.dr String found in binary or memory: https://code.jquery.com/
Source: ea8fc1980a2c60c0_0.0.dr String found in binary or memory: https://code.jquery.com/jquery-3.1.1.min.js
Source: c589c410046f7db0_0.0.dr String found in binary or memory: https://code.jquery.com/jquery-3.2.1.slim.min.js
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr String found in binary or memory: https://content-autofill.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: Reporting and NEL.2.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external
Source: Reporting and NEL.2.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/OneGoogleWidgetUi/external
Source: Reporting and NEL.2.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/hosted-libraries-pushers
Source: Reporting and NEL.2.dr String found in binary or memory: https://csp.withgoogle.com/csp/report-to/hosted-libraries-pushersu
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr String found in binary or memory: https://fonts.googleapis.com
Source: Network Action Predictor.0.dr String found in binary or memory: https://fonts.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: Network Action Predictor.0.dr, 526dece192072100_0.0.dr String found in binary or memory: https://great-efficacious-libra.glitch.me/
Source: ea8fc1980a2c60c0_0.0.dr String found in binary or memory: https://great-efficacious-libra.glitch.me/.
Source: 92ac6bcd4238ab45_0.0.dr String found in binary or memory: https://great-efficacious-libra.glitch.me/1P
Source: 4a5863ccb129da6d_0.0.dr String found in binary or memory: https://great-efficacious-libra.glitch.me/F
Source: c589c410046f7db0_0.0.dr String found in binary or memory: https://great-efficacious-libra.glitch.me/G
Source: Session_13277273603590869.0.dr String found in binary or memory: https://great-efficacious-libra.glitch.me/ue908.html
Source: History.0.dr String found in binary or memory: https://great-efficacious-libra.glitch.me/ue908.htmlShare
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr String found in binary or memory: https://ka-f.fontawesome.com
Source: Network Action Predictor.0.dr String found in binary or memory: https://ka-f.fontawesome.com/
Source: Network Action Predictor.0.dr String found in binary or memory: https://kit.fontawesome.com/
Source: 5266d9eec5c58a3c_0.0.dr String found in binary or memory: https://kit.fontawesome.com/585b051251.js
Source: 8a281a193daaab2f_0.0.dr, f3d7599b2ef11517_0.0.dr, a4e4f981b679f738_0.0.dr String found in binary or memory: https://live.com/
Source: 1bff270e32b0ba8c_0.0.dr String found in binary or memory: https://live.com/$
Source: 3cea4a09fd476ccb_0.0.dr String found in binary or memory: https://live.com/6
Source: 6307df8c1ac7f419_0.0.dr String found in binary or memory: https://live.com/?
Source: 4a0fdcbc7d76ecf2_0.0.dr String found in binary or memory: https://live.com/C
Source: ae91f4d35288cc27_0.0.dr String found in binary or memory: https://live.com/E
Source: af47f16bd7610af9_0.0.dr String found in binary or memory: https://live.com/H
Source: 1ab14149c9b37915_0.0.dr String found in binary or memory: https://live.com/M
Source: a63ea7b972ca7cfa_0.0.dr String found in binary or memory: https://live.com/Q
Source: 2e60a340af51fb52_0.0.dr, 6c5096a78a4a9b6d_0.0.dr String found in binary or memory: https://live.com/Z
Source: 4faa0455d4039afa_0.0.dr String found in binary or memory: https://live.com/_C
Source: 93a3fa42e61c139b_0.0.dr String found in binary or memory: https://live.com/a
Source: af5c3b38004ce8f5_0.0.dr String found in binary or memory: https://live.com/b
Source: 9bee922fc98a1fe8_0.0.dr String found in binary or memory: https://live.com/e
Source: 047447b274c22c54_0.0.dr String found in binary or memory: https://live.com/fT
Source: 02d4aaf953a2f242_0.0.dr String found in binary or memory: https://live.com/g
Source: 9ef530ac8e11a4d2_0.0.dr String found in binary or memory: https://live.com/h
Source: 7cd4eb7d184ef6b5_0.0.dr String found in binary or memory: https://live.com/qC
Source: 387591b72ede2a53_0.0.dr String found in binary or memory: https://live.com/s)
Source: 1fd1d25d46212c70_0.0.dr String found in binary or memory: https://live.com/x
Source: f8454b9b69153474_0.0.dr String found in binary or memory: https://live.com/y
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com
Source: Network Action Predictor.0.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/
Source: 4a5863ccb129da6d_0.0.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr String found in binary or memory: https://ogs.google.com
Source: Session_13277273603590869.0.dr String found in binary or memory: https://onedrive.live.com
Source: Session_13277273603590869.0.dr String found in binary or memory: https://onedrive.live.com/
Source: 09f2c706fbeaa761_0.0.dr String found in binary or memory: https://onedrive.live.com/handlers/clientstring.mvc?mkt=en-US&group=GroupFolders&v=19.725.0719.2003&
Source: 1ab14149c9b37915_0.0.dr String found in binary or memory: https://onedrive.live.com/handlers/clientstring.mvc?mkt=en-US&group=Office&v=19.725.0719.2003&useReq
Source: History-journal.0.dr, Favicons.0.dr String found in binary or memory: https://onedrive.live.com/redir?resid=CCF04E28D2020A7D
Source: Session_13277273603590869.0.dr, Favicons.0.dr String found in binary or memory: https://onedrive.live.com/redir?resid=CCF04E28D2020A7D%21130&authkey=%21Ag0jBsMOa5CPGSk&page=View&wd
Source: Favicons.0.dr String found in binary or memory: https://onedrive.live.com/view.aspx?resid=CCF04E28D2020A7D
Source: 54ade329-ab1e-4f2e-bd25-0a92bcce7065.tmp.0.dr String found in binary or memory: https://onedrive.live.com:443
Source: 810e53cf61aed9ba_0.0.dr String found in binary or memory: https://onenote.com/
Source: cbc4c2abcb8aa92a_0.0.dr String found in binary or memory: https://onenote.com/(
Source: 7444ea2da1317cfb_0.0.dr String found in binary or memory: https://onenote.com/-
Source: 9353779ee6ffff87_0.0.dr String found in binary or memory: https://onenote.com/WRe)
Source: 511f06892f5a721b_0.0.dr String found in binary or memory: https://onenote.com/b
Source: Session_13277273603590869.0.dr String found in binary or memory: https://onenote.officeapps.live.com
Source: Session_13277273603590869.0.dr, index.txt.tmp.0.dr String found in binary or memory: https://onenote.officeapps.live.com/
Source: QuotaManager.0.dr String found in binary or memory: https://onenote.officeapps.live.com/default
Source: QuotaManager.0.dr String found in binary or memory: https://onenote.officeapps.live.com/default/
Source: Session_13277273603590869.0.dr String found in binary or memory: https://onenote.officeapps.live.com/o/onenoteframe.aspx?edit=0&ui=en-US&rs=en-US&hid=uaD%2BnJ80T0yXy
Source: a5534787ec2d07e5_0.0.dr String found in binary or memory: https://p.sfx.ms//storage/aria-2.5.0.min.js
Source: manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: Session_13277273603590869.0.dr String found in binary or memory: https://skyapi.onedrive.live.com/api/proxy?v=3
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr String found in binary or memory: https://spoprod-a.akamaihd.net
Source: af47f16bd7610af9_0.0.dr String found in binary or memory: https://spoprod-a.akamaihd.net/files/onedrive-website-release-prod_master_20210729.001/jquery-1.7.2-
Source: 8a281a193daaab2f_0.0.dr String found in binary or memory: https://spoprod-a.akamaihd.net/files/onedrive-website-release-prod_master_20210729.001/wac0-efa56458
Source: a63ea7b972ca7cfa_0.0.dr String found in binary or memory: https://spoprod-a.akamaihd.net/files/onedrive-website-release-prod_master_20210729.001/wac1-cdc297b4
Source: 6307df8c1ac7f419_0.0.dr String found in binary or memory: https://spoprod-a.akamaihd.net/files/onedrive-website-release-prod_master_20210729.001/wac2-bf8b3319
Source: 5bde89341a061de0_0.0.dr String found in binary or memory: https://spoprod-a.akamaihd.net/files/onedrive-website-release-prod_master_20210729.001/wac_s_office-
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json42.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json42.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr String found in binary or memory: https://update.googleapis.com
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr, manifest.json0.0.dr String found in binary or memory: https://www.google.com
Source: manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: fa0b0ad1-dad9-48e1-85fb-f534f2ae204e.tmp.2.dr, ca6123e8-1436-4dcd-9c96-9887485f69c2.tmp.2.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: Session_13277273603590869.0.dr String found in binary or memory: https://www.onenote.com/officeaddins/learningtools/?et=
Source: unknown HTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.107 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: CONSENT=PENDING+620; NID=216=I6CuWiAsd2lH6AC5CO2TTw5MCN3WWkiNu-mYvTNujL88oxXy0UK9yalWvycRtySss8iWRiXfqARAdC7BsJaQ5W2cFT6FG6GyJ7HcSQqS8phAgJWdy36gJyljNdy2GR3YUXNQwNkuHyOssVfrbdvpM5caJcSYKuRYB2ICYiL3C7s
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\d481bb98-b939-478b-aad0-c64fbbf79800.tmp Jump to behavior
Source: classification engine Classification label: mal72.phis.win@33/273@24/17
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation --single-argument https://1drv.ms/o/s!BH0KAtIoTvDMgQINIwbDDmuQjxkp?e=tej6OVmcREW9hZcUcQddjw&at=9
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1692,15970318600001114932,16779282638548115686,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1848 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1692,15970318600001114932,16779282638548115686,131072 --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1848 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-61528D00-1CC4.pma Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs