URL:

https://jsjcorporation-my.sharepoint.com/:o:/g/personal/gillesm_jsjcorp_com/El3LMnws4WZAn7a-DWcgo-oBQOivV1QSdopp5DSJ_EMPKQ?e=13FjPv

Full analysis: https://app.any.run/tasks/0ca6aec5-919c-4598-b5bb-3d7699e97d47
Verdict: Malicious activity
Analysis date: May 17, 2025, 06:09:07
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
possible-phishing
sharepoint
arch-doc
Indicators:
MD5:

22A7F6B7F82DB4C6FBA91C37D639CC2D

SHA1:

C52A805E195DD2B766F9F0A625FE6B9F53D3E747

SHA256:

DAC827E4401DAEB8865F53BF41C2B12F50EFC654BF22B506E012D3E6D3DD7EDE

SSDEEP:

3:N8oXS88hiN+ArL5+KVFSCIOtTKI3mREcoKIK0qS4028VVQhf5w:2Kqhu+AfNQOtTKIC3oTlj402EVQh+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Access to SharePoint Content

      • firefox.exe (PID: 2472)
      • firefox.exe (PID: 372)
  • INFO

    • Application launched itself

      • firefox.exe (PID: 372)
      • firefox.exe (PID: 2472)
    • The sample compiled with english language support

      • firefox.exe (PID: 372)
    • Executable content was dropped or overwritten

      • firefox.exe (PID: 372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
19
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs svchost.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.0.366841850\182190046" -parentBuildID 20230710165010 -prefsHandle 1096 -prefMapHandle 1088 -prefsLen 28739 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {00316026-92c8-4424-a80f-7ef4ee534cd2} 372 "\\.\pipe\gecko-crash-server-pipe.372" 1180 d3820d0 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
372"C:\Program Files\Mozilla Firefox\firefox.exe" https://jsjcorporation-my.sharepoint.com/:o:/g/personal/gillesm_jsjcorp_com/El3LMnws4WZAn7a-DWcgo-oBQOivV1QSdopp5DSJ_EMPKQ?e=13FjPvC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
752"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.1.1427210512\290432066" -parentBuildID 20230710165010 -prefsHandle 1320 -prefMapHandle 1316 -prefsLen 28816 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {40987c98-2f3e-4872-b775-b58ad806c7a2} 372 "\\.\pipe\gecko-crash-server-pipe.372" 1332 8045e0 socketC:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
984"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.14.393792905\1100821733" -childID 11 -isForBrowser -prefsHandle 7512 -prefMapHandle 7524 -prefsLen 29609 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {91dbf00f-b81d-40c1-95b5-3bb8e82310c4} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7492 1dc52560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1080C:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1276"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.2.746821663\1494519448" -childID 1 -isForBrowser -prefsHandle 2216 -prefMapHandle 2140 -prefsLen 24527 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {1b3b26d0-0579-43fc-872c-6ded66d05b29} 372 "\\.\pipe\gecko-crash-server-pipe.372" 2176 1394e560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1332"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.8.8600991\1091232264" -childID 7 -isForBrowser -prefsHandle 7940 -prefMapHandle 7948 -prefsLen 29349 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {78d32d1b-15f8-402d-a669-eaf3ab695dc6} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7928 ff93b20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1548"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.12.784552678\1688824317" -parentBuildID 20230710165010 -prefsHandle 3940 -prefMapHandle 3936 -prefsLen 36654 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6b8a3e24-4bd3-41d1-a152-265e57a9fe31} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7524 1d6e8f20 rddC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1596"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.11.1920454876\1622257291" -childID 10 -isForBrowser -prefsHandle 3968 -prefMapHandle 7728 -prefsLen 29609 -prefMapSize 244371 -jsInitHandle 900 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {dc9914f2-2c71-45df-9aab-69d33492a960} 372 "\\.\pipe\gecko-crash-server-pipe.372" 3956 1b964560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1980"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="372.13.1365880231\1358825622" -parentBuildID 20230710165010 -sandboxingKind 1 -prefsHandle 7536 -prefMapHandle 7540 -prefsLen 36654 -prefMapSize 244371 -appDir "C:\Program Files\Mozilla Firefox\browser" - {40f0392a-e734-4984-93c6-0b2d2f2d2336} 372 "\\.\pipe\gecko-crash-server-pipe.372" 7508 12fb8710 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
25 388
Read events
25 338
Write events
45
Delete events
5

Modification events

(PID) Process:(2472) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
9BEBFF5001000000
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
C8AC015101000000
(PID) Process:(1080) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet
Operation:writeName:{4040CF00-1B3E-486A-B407-FA14C56B6FC0}
Value:
D4DA6D39D73C
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Installer\308046B0AF4A39CB
Operation:delete valueName:installer.taskbarpin.win10.enabled
Value:
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Enabled
Value:
1
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableTelemetry
Value:
1
(PID) Process:(372) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Default Browser Agent
Operation:writeName:C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent
Value:
0
Executable files
5
Suspicious files
319
Text files
40
Unknown types
1

Dropped files

PID
Process
Filename
Type
372firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.json.tmpbinary
MD5:B89F821178FDCFB57C4446F1970FB124
SHA256:53A1BCC3D48836F88F6C98576083A0C1F7A719B36A7AC85E213FD2F3BD7A7B4B
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.jsonbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
372firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\activity-stream.discovery_stream.jsonbinary
MD5:B89F821178FDCFB57C4446F1970FB124
SHA256:53A1BCC3D48836F88F6C98576083A0C1F7A719B36A7AC85E213FD2F3BD7A7B4B
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\datareporting\glean\db\data.safe.tmpbinary
MD5:B1C8AA9861B461806C9E738511EDD6AE
SHA256:7CEA48E7ADD3340B36F47BA4EA2DED8D6CB0423FFC2A64B44D7E86E0507D6B70
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite
MD5:
SHA256:
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\sessionCheckpoints.json.tmpbinary
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A
SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.jstext
MD5:10838BA4D091CD29EB56089222ECB443
SHA256:934225516EF688A07796A04C2358410D6F7238FD8056C261780E20B098F1189C
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shmbinary
MD5:B7C14EC6110FA820CA6B65F5AEC85911
SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs-1.jstext
MD5:10838BA4D091CD29EB56089222ECB443
SHA256:934225516EF688A07796A04C2358410D6F7238FD8056C261780E20B098F1189C
372firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\storage.sqlite-journalbinary
MD5:35A9F683D6C49B62E51BF1FD9CAD5E0B
SHA256:E47AC382D0B2EF3FF1571F9C27B4823E6F831F4A00D8C43A7E0EFA2B2EC634EE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
202
DNS requests
315
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
372
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
whitelisted
372
firefox.exe
POST
172.217.16.195:80
http://o.pki.goog/s/wr3/FIY
unknown
whitelisted
372
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
whitelisted
372
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/we2
unknown
whitelisted
372
firefox.exe
POST
184.24.77.62:80
http://r11.o.lencr.org/
unknown
whitelisted
372
firefox.exe
POST
200
184.24.77.62:80
http://r11.o.lencr.org/
unknown
whitelisted
372
firefox.exe
POST
200
184.24.77.48:80
http://r10.o.lencr.org/
unknown
whitelisted
372
firefox.exe
POST
200
184.24.77.48:80
http://r10.o.lencr.org/
unknown
whitelisted
372
firefox.exe
POST
200
172.217.16.195:80
http://o.pki.goog/we2
unknown
whitelisted
372
firefox.exe
POST
200
184.24.77.62:80
http://r11.o.lencr.org/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
372
firefox.exe
13.107.138.10:443
jsjcorporation-my.sharepoint.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
372
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
372
firefox.exe
34.36.137.203:443
spocs.getpocket.com
GOOGLE-CLOUD-PLATFORM
US
whitelisted
372
firefox.exe
142.250.184.234:443
safebrowsing.googleapis.com
whitelisted
372
firefox.exe
172.217.16.195:80
o.pki.goog
GOOGLE
US
whitelisted
372
firefox.exe
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.174
whitelisted
jsjcorporation-my.sharepoint.com
  • 13.107.138.10
  • 13.107.136.10
unknown
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
dual-spo-0005.spo-msedge.net
  • 13.107.138.10
  • 13.107.136.10
  • 2620:1ec:8fa::10
  • 2620:1ec:8f8::10
unknown
example.org
  • 23.215.0.132
  • 96.7.128.192
  • 96.7.128.186
  • 23.215.0.133
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted
spocs.getpocket.com
  • 34.36.137.203
whitelisted
mc.prod.ads.prod.webservices.mozgcp.net
  • 34.36.137.203
whitelisted
contile.services.mozilla.com
  • 34.36.137.203
whitelisted

Threats

PID
Process
Class
Message
372
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to SharePoint public/private file sharing TLS SNI (.sharepoint .com)
372
firefox.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to SharePoint public/private file sharing TLS SNI (.sharepoint .com)
1080
svchost.exe
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Suspected Malicious Domain ( .spo-msedge .net)
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Request to SharePoint public/private file sharing DNS (.sharepoint .com)
1080
svchost.exe
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Suspected Malicious Domain ( .spo-msedge .net)
372
firefox.exe
Possible Social Engineering Attempted
SUSPICIOUS [ANY.RUN] Accessing SharePoint content without a legitimate Microsoft Sign-In
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
1080
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info