<?xml version='1.0' encoding='UTF-8'?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>d48069520bd8476494358b7fc742be71</id>
  <title>www.filescan.io feed</title>
  <updated>2026-05-11T04:59:43Z</updated>
  <author>
    <name>Filescan.io</name>
    <email>admin@filescan.io</email>
  </author>
  <link href="https://www.filescan.io"/>
  <generator>Filescan.io feed generator</generator>
  <logo>https://www.filescan.io/assets/logo.png</logo>
  <entry>
    <id>5b4ca526b599929a38e97bed3e946a2d6e581bd828be8e64a214f8ee9c1537c5</id>
    <title>Analysis Report for 5b4ca526b599929a38e97bed3e946a2d6e581bd828be8e64a214f8ee9c1537c5</title>
    <updated>2026-05-11T04:56:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0161bd97e8658d088c828b</_id>
        <file_type>application/java-archive</file_type>
        <flow_id>6a0161987d31ad7bba4fe711</flow_id>
        <hash>5b4ca526b599929a38e97bed3e946a2d6e581bd828be8e64a214f8ee9c1537c5</hash>
        <iocs/>
        <name>5b4ca526b599929a38e97bed3e946a2d6e581bd828be8e64a214f8ee9c1537c5.file</name>
        <report_id>61673878-9239-453e-9b93-b0b33c4d7bb1</report_id>
        <tags>
          <value>java</value>
          <value>anti-debug</value>
          <value>obfuscated</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>58c69ff493f724ebe12666ae5dff14b970ea0816931602a806186758db11feb3</id>
    <title>Analysis Report for 58c69ff493f724ebe12666ae5dff14b970ea0816931602a806186758db11feb3</title>
    <updated>2026-05-11T04:56:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0161b8b87f27901eb5f100</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01618f2fcb905ec28c8b51</flow_id>
        <hash>58c69ff493f724ebe12666ae5dff14b970ea0816931602a806186758db11feb3</hash>
        <iocs>
          <urls>
            <value>
              <url>https://www.easeus.com/&amp;x=6&amp;y=5</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://accounts.easeus.com/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://cdn.jsdelivr.net/npm/js-cookie@3.0.5/dist/js.cookie.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://linkedin.com/company/easeus-software-linkedin</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ad-clone/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-product-video-generator/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-ugc-video-generator/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-video-generator/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/avatar-ad/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ecommerce-video-maker/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/effects-ai-video-generator/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/facebook-ad-generator/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/hailuo-02/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/hailuo-2-3/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/home-page/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/image-to-video-generator/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/instagram-ad-maker/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/kling-2-6/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/kling-3-0/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/linkedin-ad-maker/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/marketing-video-maker/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/online-video-downloader/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/snapchat-ad-maker/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/sora-2-pro/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/sora-2/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/text-to-video/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/tiktok-ads-creator/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/url-to-video-generator/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/veo-3-1/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/veo-3/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/vidu-q3/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/wan-2-5/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/wan-2-6/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/youtube-ad-maker/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://recorder.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://recorder.easeus.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://schema.org</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://secure.trust-provider.com/ttb_searcher/trustlogo</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://secure.trust-provider.com/ttb_searcher/trustlogo?v_querytype=W&amp;v_shortname=SECDV&amp;v_search=https://www.easeus.com/&amp;x=6&amp;y=5</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://twitter.com/easeus_software</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/dayjs.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/advancedFormat.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/customParseFormat.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/localeData.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/quarterOfYear.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/weekOfYear.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/weekYear.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/weekday.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://vocalremover.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://vocalremover.easeus.com/ai-stem-splitter/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://vocalremover.easeus.com/lead-backing-vocal-splitter/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/ai-voice/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/online-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-changer-tips/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/call-of-duty-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/darth-vader-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/discord-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/elf-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/fortnite-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/girl-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/grinch-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/obs-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/santa-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/valorant-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/vrchat-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/xbox-voice-changer</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.dmca.com/Protection/Status.aspx?ID=6f87f39c-64f0-4564-88a6-3c1a79e17360</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/campaign/2025-store-new.html?coupon=NEWYEAR2026&amp;off=68</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/company/about-us.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/company/about-us.html#Contact_EaseUS</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/download.htm</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/easeus-complaints-feedback.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/easeus-reviews.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/education.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2016/fav.ico</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/mail/download/?email=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.easeus.com/partner/affiliate.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/partner/oem.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/partner/reseller.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/support-center/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/support-center/livechat-tech.html</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.facebook.com/easeus.global/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.trustpilot.com/review/easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/user/EASEUSsoftware</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://cn.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://tr.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://www.easeus.co.id</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://www.easeus.co.kr</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://www.easeus.cz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://abtest-ali-tokyo-01.saas.sensorsdata.cn/api/v2/abtest/online/results?project-key=3FA6A19C60A42FAFF2DB5911D6491E2C8F6A74AD</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://accounts.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://accounts.easeus.com/login</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://accounts.easeus.com/login?locale=es-ES&amp;host=multimedia.easeus.com&amp;pageurl=https://multimedia.easeus.com/es/online-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://api.ipify.org/?format=json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://b.delivery.consentmanager.net/delivery/cmp.php</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://b.delivery.consentmanager.net/delivery/cmp.php?__cmpcc=1&amp;__cmpfcc=1&amp;id=87305&amp;o=1778475441&amp;h=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;undefined&amp;l=en&amp;odw=0&amp;dlt=1&amp;l=en&amp;lp=EN_ES</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://b.delivery.consentmanager.net/delivery/cmp.php?id=87305&amp;h=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;l=en&amp;ls=EN_EN_EN&amp;lp=EN_ES&amp;o=1778475413971</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://b.delivery.consentmanager.net/delivery/info/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://b.delivery.consentmanager.net/delivery/info/?id=87305&amp;did=1&amp;cfdid=1&amp;t=pv.d_ncs.d_ancs.d_bncs.cv&amp;h=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;o=1778475414625&amp;l=EN&amp;lv=0&amp;d=1&amp;ct=14&amp;e=&amp;e2=&amp;e3=&amp;i=&amp;sv=12&amp;dv=36&amp;</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://bat.bing.com/bat.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://bat.bing.net/action/0</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://bat.bing.net/action/0?ti=343161330&amp;Ver=2&amp;mid=91a55ea1-612e-4061-bad6-1bca14e30f74&amp;bo=2&amp;pi=918639831&amp;lg=en-US&amp;sw=800&amp;sh=600&amp;sc=24&amp;nwd=1&amp;tl=EaseUS%20Online%20Video%20Downloader%20(1,000%20Sites%20Supported)&amp;kw=easeus%20online%20video%20downloader,%20online%20video%20downloader,%20download%20video%20online&amp;p=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;r=&amp;lt=594&amp;evt=pageLoad&amp;sv=2&amp;asc=D&amp;cdb=AQoB&amp;rn=737937</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://bat.bing.net/actionp/0?ti=343161330&amp;Ver=2&amp;mid=91a55ea1-612e-4061-bad6-1bca14e30f74&amp;bo=1&amp;evt=consent&amp;src=update&amp;cdb=AQoB&amp;asc=D</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://br.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/alertdomain/d184NzMwNS5zXzEuZF90cmFmZmljc3luY3Byb19jb20.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/alertdomain/d184NzMwNS5zXzEuZF90cmFmZmljc3luY3Byb19jb20.gif?ref=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/alertdomain/d184NzMwNS5zXzEuZF93ZWJ0cmFmZmljc291cmNlX2NvbQ.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/alertdomain/d184NzMwNS5zXzEuZF93ZWJ0cmFmZmljc291cmNlX2NvbQ.gif?ref=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/autoblocking/766ce23701445.js?_=1778475413182</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/crossdomain.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/customdata/bV8xLndfODczMDUucl9HRFBSLmxfZW4uZF8zNzMyNi54XzM2LnYucC50XzM3MzI2Lnh0XzEy.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/flags/en.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/img/icon1707185674x8794.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.consentmanager.net/delivery/js/cmp_final.min.js?t=2026-5-11</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.jsdelivr.net/npm/js-cookie@3.0.5/dist/js.cookie.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://easeus.recovery-soft.com/sa?project=production&amp;token=999973f358bdc4bc</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://es.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://event.getblue.io/js/blue-tag.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://firebase.googleapis.com/v1alpha/projects/-/apps/1:439846333449:web:6c978fcc3cc20d4dba9cd8/webConfig</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://firebaseinstallations.googleapis.com/v1/projects/easeus-video-downloader-online/installations</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://it.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jp.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://linkedin.com/company/easeus-software-linkedin</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ad-clone/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-avatar-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-product-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-spokesperson-video-creator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-talking-head-video/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-ugc-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ai-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/avatar-ad/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/account-center/config.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/buy_pop_show.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/ga4/es/ga4_data_url.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/globle.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/globle_js/position.js?t=1778475413705</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/jquery.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/marketing/index.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/other.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/js/plug_in.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/typeface/Lexend/Lexend-Light.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/typeface/Lexend/Lexend-Regular.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/typeface/Lexend/Lexend-SemiBold.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/typeface/icon/iconfont.woff</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default/webpack/dist/firebase.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default2/2019/css/all_button.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default2/2022/css/globle_pruduct.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default2/css/base_2021.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/default2/css/iconfont.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/ecommerce-video-maker/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/effects-ai-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/src/assets/fonts/fonts.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/api/getAppInfo</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/api/getCountry</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/Anton-Regular-D-s4rlHi.ttf</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/Lexend-Regular-CTjGI_9W.ttf</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/app-CZAeoZhI.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/app-ChT7hFIB.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/card_bg-ChvcSKLz.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/evf_f1-Bry-tWlb.webm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/evf_f2-CDg89GoM.webm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/evf_feat3-bAIcw8x7.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/feature1-C2R87iUX.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/feature2@2x-Cahl2aaj.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/feature3@2x-DeXwtyX7.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/feature4@2x-DZ92N3q2.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/ico_logo_Instagram-BnpOylsF.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/ico_logo_tiktok-vhp1Tfm_.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/ico_logo_vimeo-CfDx5EmQ.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/ico_logo_x-JR7yIufp.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/ico_logo_youtube-CPOY6-fT.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/icon_download@2x-67sm4aCd.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/img_dbbanner-CGAkCgZ8.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/useImg1-BR2DvLBg.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/useImg2@2x-VgtGDeuU.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/evd/assets/useImg3-C06Ohmho.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/facebook-ad-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/grok-imagine-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/hailuo-02/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/hailuo-2-3/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/home-page/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/image-to-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/product/all_icon/icon0.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/product/all_icon/icon1.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/product/all_icon/icon2.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/product/all_icon/icon3.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/product/all_icon/icon4.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/product/all_icon/icon5.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/product/all_icon/icon6.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/images_2019/videokit/new1/icon-ai01.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/instagram-ad-maker/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/kling-2-6/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/kling-3-0/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/kling-o1/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/linkedin-ad-maker/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/marketing-video-maker/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/proxydirectory/1287310181604/pageInfo</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/proxydirectory/tags/1287310181604/tag.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/seedance-2-0/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/snapchat-ad-maker/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/sora-2-pro/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/sora-2/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/text-to-video/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/tiktok-ads-creator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/url-to-video-generator/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/veo-3-1/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/veo-3/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/vidu-q3/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/wan-2-5/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/wan-2-6/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://multimedia.easeus.com/youtube-ad-maker/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://nl.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://nl.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://pagead2.googlesyndication.com/ccm/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://pagead2.googlesyndication.com/ccm/collect?rcb=12&amp;frm=0&amp;en=page_view&amp;dl=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;scrsrc=www.googletagmanager.com&amp;rnd=1379494676.1778475415&amp;navt=n&amp;npa=1&amp;gdid=dMzk4MW&amp;gtm=45be6562v875306234za200xec&amp;gcs=G100&amp;gcd=13p3p3p2p5l1&amp;dma_cps=-&amp;dma=1&amp;tag_exp=0~115938465~115938468~118463262&amp;apve=1&amp;apvf=f&amp;apvc=0&amp;tids=AW-1064956115&amp;tid=AW-1064956115&amp;tft=1778475415475&amp;tfd=2406</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://pagead2.googlesyndication.com/ccm/collect?rcb=4&amp;frm=0&amp;en=page_view&amp;dl=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;scrsrc=www.googletagmanager.com&amp;rnd=1379494676.1778475415&amp;navt=n&amp;npa=1&amp;gdid=dMzk4MW&amp;gtm=45be6562v9105307171za200xec&amp;gcs=G100&amp;gcd=13p3pPp2p5l1&amp;dma_cps=-&amp;dma=1&amp;tag_exp=0~115938465~115938469~118463261~118864611&amp;apve=1&amp;apvf=f&amp;apvc=1&amp;tids=AW-11113079898&amp;tid=AW-11113079898&amp;tft=1778475415474&amp;tfd=2405</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://pl.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://recorder.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://recorder.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect?v=2&amp;tid=G-Y6YBGF6N1K&amp;gtm=45je6562v873582734za200&amp;_p=1778475413708&amp;gcs=G100&amp;gcd=13p3p3p2p5l1&amp;npa=1&amp;dma_cps=-&amp;dma=1&amp;gdid=dMzk4MW&amp;_eu=AAAAAGAC&amp;are=1&amp;cid=844607858.1778475415&amp;frm=0&amp;pscdl=denied&amp;rcb=19&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;gaf=2&amp;_s=1&amp;tag_exp=0~115938465~115938469~118463262&amp;cu=USD&amp;sid=1778475414&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;dt=EaseUS%20Online%20Video%20Downloader%20(1%2C000%20Sites%20Supported)&amp;en=page_view&amp;_fv=1&amp;_ss=1&amp;_ee=1&amp;ep.page_group1=ES_Product_Page&amp;ep.page_group2=Product_Videodownloader&amp;ep.page_group3=Video%20Downloader_Online&amp;ep.buy_category=web&amp;ep.site_language=es&amp;ep.landing_pageURL=%2Fes%2Fonline-video-downloader%2F&amp;ep.browser_category=chrome&amp;ep.operating_system=windows&amp;tfd=2404</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect?v=2&amp;tid=G-ZCMQPLQNRD&amp;gtm=45je6562v9181691553za200&amp;_p=1778475413708&amp;gcs=G100&amp;gcd=13p3p3p2p5l1&amp;npa=1&amp;dma_cps=-&amp;dma=1&amp;gdid=dMzk4MW&amp;_fid=d8M43UebHKl8Sf02fWoK9r&amp;are=1&amp;cid=844607858.1778475415&amp;frm=0&amp;pscdl=denied&amp;rcb=12&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;_s=1&amp;tag_exp=0~115938465~115938468~118463261&amp;sid=1778475414&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;dt=EaseUS%20Online%20Video%20Downloader%20(1%2C000%20Sites%20Supported)&amp;en=page_view&amp;_fv=1&amp;_nsi=1&amp;_ss=1&amp;_ee=1&amp;ep.origin=firebase&amp;tfd=2369</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://rtg.prdredir.com/sync</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://rtg.prdredir.com/sync?ref=&amp;lp=https%3A%2F%2Fmultimedia.easeus.com%2Fes%2Fonline-video-downloader%2F&amp;sh=600&amp;sw=800&amp;date=1778475414177&amp;fp=uid-8517001543.0384254120</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://scripts.prdredir.com/scripts/auc_easeus.js?_=1778475413181</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://secure.trust-provider.com/ttb_searcher/trustlogo</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://secure.trust-provider.com/ttb_searcher/trustlogo?v_querytype=W&amp;v_shortname=SECDV&amp;v_search=https://www.easeus.com/&amp;x=6&amp;y=5</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://t.contentsquare.net/settings/586000.json?r=1976083</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://t.contentsquare.net/uxa/7db1afeaecaa7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://tw.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://twitter.com/easeus_software</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/dayjs.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/advancedFormat.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/customParseFormat.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/localeData.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/quarterOfYear.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/weekOfYear.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/weekYear.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://unpkg.com/dayjs@1.11.10/plugin/weekday.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://vocalremover.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://vocalremover.easeus.com/ai-stem-splitter/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://vocalremover.easeus.com/lead-backing-vocal-splitter/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/ai-voice/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/online-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-changer-tips/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/call-of-duty-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/darth-vader-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/discord-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/elf-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/fortnite-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/girl-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/grinch-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/obs-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/santa-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/valorant-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/vrchat-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://voicechanger.easeus.com/voice-lab/xbox-voice-changer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://widget.getblue.io/event/?cId=8C02C967-A416-C6E4-55381DC592612AF2&amp;tName=visit&amp;pId=&amp;revenue=&amp;orderId=&amp;p1=&amp;p2=e%3Dvp&amp;p3=e%3Ddis&amp;adce=1&amp;dtycbr=87954&amp;fp=&amp;blueID=955f125a-915d-46a5-9d38-27c5025628d3&amp;ulc=&amp;v=24102025-1118&amp;if=0&amp;nocache=8087372301257.147</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://widget.trustpilot.com/trustboxes/53aa8807dec7e10d38f59f32/index.html?templateId=53aa8807dec7e10d38f59f32&amp;businessunitId=53e320ce0000640005793e9d</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.dmca.com/Protection/Status.aspx?ID=6f87f39c-64f0-4564-88a6-3c1a79e17360</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.ae</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.co.th/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/campaign/2025-store-new.html?coupon=NEWYEAR2026&amp;off=68</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/company/about-us.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/company/about-us.html#Contact_EaseUS</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/default/js/account-center/public.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/default/js/ad_download.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/default/js/cj.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/default/js/sensorsdata.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/default/js/sensorsdata/abtest.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/default/js/sensorsdata/sensors.min.nogif.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/download.htm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/easeus-complaints-feedback.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/easeus-reviews.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/education.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2016/fav.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2019/index/2024/f.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2019/index/header_2022/header_icon.svg?.9900234315</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2019/index/header_2022/icon-h-1.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2019/index/header_2022/icon-s-1.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2019/index/header_2022/logo_black.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2019/index/header_2022/logo_t.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/images_2019/offer_img/tab-discount.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/partner/affiliate.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/partner/oem.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/partner/reseller.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/support-center/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.com/support-center/livechat-tech.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.de/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.fr</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.easeus.ru</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.facebook.com/easeus.global/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=AW-1064956115&amp;cx=c&amp;gtm=4e6562</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=AW-11113079898&amp;cx=c&amp;gtm=4e6562</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-Y6YBGF6N1K&amp;cx=c&amp;gtm=4e6562</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-ZCMQPLQNRD&amp;cx=c&amp;gtm=4e6562</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?l=dataLayer&amp;id=G-ZCMQPLQNRD</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtm.js?id=GTM-PQNTKVRM</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/user/EASEUSsoftware</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>bncs.cv</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;dt=EaseUS</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;l=en&amp;ls=EN_EN_EN&amp;lp=EN_ES&amp;o=1778475413971</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;o=1778475414625&amp;l=EN&amp;lv=0&amp;d=1&amp;ct=14&amp;e=&amp;e2=&amp;e3=&amp;i=&amp;sv=12&amp;dv=36&amp;</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;r=&amp;lt=594&amp;evt=pageLoad&amp;sv=2&amp;asc=D&amp;cdb=AQoB&amp;rn=737937</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;scrsrc=www.googletagmanager.com&amp;rnd=1379494676.1778475415&amp;navt=n&amp;npa=1&amp;gdid=dMzk4MW&amp;gtm=45be6562v875306234za200xec&amp;gcs=G100&amp;gcd=13p3p3p2p5l1&amp;dma_cps=-&amp;dma=1&amp;tag_exp=0~115938465~115938468~118463262&amp;apve=1&amp;apvf=f&amp;apvc=0&amp;tids=AW-1064956115&amp;tid=AW-1064956115&amp;tft=1778475415475&amp;tfd=2406</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;scrsrc=www.googletagmanager.com&amp;rnd=1379494676.1778475415&amp;navt=n&amp;npa=1&amp;gdid=dMzk4MW&amp;gtm=45be6562v9105307171za200xec&amp;gcs=G100&amp;gcd=13p3pPp2p5l1&amp;dma_cps=-&amp;dma=1&amp;tag_exp=0~115938465~115938469~118463261~118864611&amp;apve=1&amp;apvf=f&amp;apvc=1&amp;tids=AW-11113079898&amp;tid=AW-11113079898&amp;tft=1778475415474&amp;tfd=2405</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;sh=600&amp;sw=800&amp;date=1778475414177&amp;fp=uid-8517001543.0384254120</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://multimedia.easeus.com/es/online-video-downloader/&amp;undefined&amp;l=en&amp;odw=0&amp;dlt=1&amp;l=en&amp;lp=EN_ES</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.easeus.com/&amp;x=6&amp;y=5</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>multimedia.easeus.com</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>accounts.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>cdn.jsdelivr.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>linkedin.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>multimedia.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>recorder.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>schema.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>secure.trust-provider.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>twitter.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>unpkg.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>vocalremover.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>voicechanger.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.dmca.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.easeus.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.trustpilot.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>abtest-ali-tokyo-01.saas.sensorsdata.cn</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>accounts.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>api.ipify.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>b.delivery.consentmanager.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>bat.bing.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>bat.bing.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>br.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.consentmanager.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.jsdelivr.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cn.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>easeus.recovery-soft.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>es.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>event.getblue.io</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>firebase.googleapis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>firebaseinstallations.googleapis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>it.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>jp.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>linkedin.com</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>multimedia.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>nl.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>pagead2.googlesyndication.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>pl.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>recorder.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>region1.google-analytics.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>rtg.prdredir.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>scripts.prdredir.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>secure.trust-provider.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>t.contentsquare.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>tr.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>tw.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>twitter.com</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>unpkg.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>vocalremover.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>voicechanger.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>widget.getblue.io</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>widget.trustpilot.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.dmca.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.ae</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.co.id</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.co.kr</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.co.th</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.cz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.de</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.fr</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.easeus.ru</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.youtube.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>dayjs@1.11.10</email>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <email>feature2@2x-Cahl2aaj.webp</email>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <email>feature3@2x-DeXwtyX7.webp</email>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <email>feature4@2x-DZ92N3q2.webp</email>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <email>icon_download@2x-67sm4aCd.webp</email>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <email>useImg2@2x-VgtGDeuU.webp</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>150.171.22.12</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.1.22</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.208.5</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>91.199.212.148</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.222.236.32</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>157.240.253.35</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.28.197</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.226.244.52</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.136</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.31.163</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.0.22</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.2.193</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.31.27</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.6.90</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.250.154.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.95</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.20.154</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>150.171.27.10</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>150.171.28.10</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>151.101.65.229</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.67.74.152</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>18.244.18.112</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>195.181.175.40</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>216.239.32.36</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>47.245.63.221</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>52.222.236.107</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>52.222.236.94</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>54.232.119.193</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>79.127.216.204</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>8.209.201.39</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>94.237.27.56</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.20.139</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.3.193</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.7.90</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.31.163</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.208.5</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.22.12</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.3.193</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.28.197</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.139</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>91.199.212.148</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.1.22</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.226.244.52</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.7.90</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>157.240.253.35</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.222.236.32</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.136</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>220bcb1ca2a00dad8195df3f900f82cab60fa423364e9d9aff31559947bf15ce</SHA-256>
              <SHA-1>8d52cf5d7815d3679d1cd8f326471edfe9fd9f34</SHA-1>
              <MD5>4ddcdb6a2d207dd0277856f0549bcf60</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>11acb9995cd4b3d152e6da03a1b7a42843b2b5158d6c7f09a76a5f040994aca5</SHA-256>
              <SHA-1>40ab95f2d3056bc66ef3016eea297e34fa077590</SHA-1>
              <MD5>fb0f35aaafd997d10659437cdb2c4955</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>f271f08f9c381b3c3ee895b7a8077f9e00afbea4b4b8ea46e6aa5882920c22f2</SHA-256>
              <SHA-1>4bfdde9aa9e8d694284c9c97ec019362fa08274f</SHA-1>
              <MD5>fefa3e3266db310ef54f6d4b1fb59219</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>644031a68bde879af85bcc9cb3e6fa1e9a6b0f61d49307581974b5dbc09d3de8</SHA-256>
              <SHA-1>9176c614fa5aca9af6ceba4996cc9128842803f7</SHA-1>
              <MD5>895d2a337cecd4bf36e6ff9a7e669a63</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>c1457a3ad3aa2c95f448117948abbb8d7e7ffa277938088d4ecee89565bbd205</SHA-256>
              <SHA-1>5e9c6216da797f22a43f6527d89da09e0df6a1f8</SHA-1>
              <MD5>29341916e19c8844098aff8097c03827</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>c1eb83bd2563eefd5d342aea40b2435fb8cc08102f62e8154602acfc3915f62b</SHA-256>
              <SHA-1>c6e199611e2e6b9acc67d0b78dd26d3354e062d1</SHA-1>
              <MD5>edf8237956fecd264a3e3680d4fd4e7c</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>ee41ed19bf9678fba72653b43ce21e7e869cb544352659624c13f01712ee4d05</SHA-256>
              <SHA-1>0924c87b400c5721ef94ec80391ca423ec3c7ced</SHA-1>
              <MD5>8f69d724cdd64a4ca56e103b8d6617f6</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>582b03210d38e14e9b482ccbcf45f11e46ff5258e33273df380298384cc27935</SHA-256>
              <SHA-1>f76af360e4c84ba50a40c6888743e0625c5007de</SHA-1>
              <MD5>ed0ea43271946d63f03ca9c334945784</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>582cc085dd8fea044917d1efde838e77e845262fd025bbfe0339f808607c81f6</SHA-256>
              <SHA-1>d6cd1e79cee878f761715ad811d29ea06637416e</SHA-1>
              <MD5>ae11f74bdaae51ba13385aa097723268</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>6f87f39c-64f0-4564-88a6-3c1a79e17360</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <btc_wallets>
            <value>
              <btc_wallet>x14fa8:$btc: 1jre3yEM1wfQtcrEHdYDEWUAS19UMehP</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://multimedia.easeus.com/es/online-video-downloader/</name>
        <report_id>2c23ef17-7f97-4c63-b031-e35430011744</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>txt</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8f915361682bdb7cc51da3084c9b0368610cc4839697e4d8c2c76f90ec2f5b11</id>
    <title>Analysis Report for 8f915361682bdb7cc51da3084c9b0368610cc4839697e4d8c2c76f90ec2f5b11</title>
    <updated>2026-05-11T04:56:26Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0162060f7e400110050d95</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01617886e92bda70271a18</flow_id>
        <hash>8f915361682bdb7cc51da3084c9b0368610cc4839697e4d8c2c76f90ec2f5b11</hash>
        <iocs>
          <files>
            <value>
              <SHA-256>7d7af8f568f06dc810170b8660df790a648f7d078d56cf2c3e631b957c74b314</SHA-256>
              <SHA-1>7c787e08dc54b9aefa5e16fceed9e84077be0aa3</SHA-1>
              <MD5>aa2cb6b3e0ece86896e01d795e329bbf</MD5>
              <origin>VBA_EMULATION</origin>
              <file_type>application/x-powershell</file_type>
            </value>
            <value>
              <SHA-256>18e11974545f8fb19b715973d4526d41377b10c2a8e26b772a45ee7d03b09f71</SHA-256>
              <SHA-1>f7939bb795bedc469a2bcda57c3f588d66bfaea0</SHA-1>
              <MD5>09bd13cffbea0dd4f0fa16de3d3de513</MD5>
              <origin>POWERSHELL_EMULATION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>e68bb57b61536b3547c64c9f6a5436e93873633e37690b43a04a787976407113</SHA-256>
              <SHA-1>b080eab30ae8a0f147a4f60b0c3dd340cbbc99cd</SHA-1>
              <MD5>dc909bd50c126fd2ee2c027656e8a4e4</MD5>
              <origin>POWERSHELL_EMULATION</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
          </files>
        </iocs>
        <name>OC_Nro. 5700080331.js</name>
        <report_id>572d0b31-b55a-495b-b69f-00a4916077dd</report_id>
        <tags>
          <value>javascript</value>
          <value>powershell</value>
          <value>evasive</value>
          <value>anti-vm</value>
          <value>fingerprint</value>
          <value>obfuscated</value>
          <value>aes</value>
          <value>aspnet_compiler</value>
          <value>crypto</value>
          <value>encrypted</value>
          <value>lolbin</value>
          <value>base64</value>
          <value>reconnaissance</value>
          <value>repaired</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>75cf178df9b823e3af4f26db1f235ea795c9757805fd00ffc9905946b7b8cbcb</id>
    <title>Analysis Report for 75cf178df9b823e3af4f26db1f235ea795c9757805fd00ffc9905946b7b8cbcb</title>
    <updated>2026-05-11T04:56:22Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0161860f7e400110050d7c</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a016173fd9cdd68416ef5cc</flow_id>
        <hash>75cf178df9b823e3af4f26db1f235ea795c9757805fd00ffc9905946b7b8cbcb</hash>
        <iocs>
          <urls>
            <value>
              <url>https://grapier.s3.ap-east-1.amazonaws.com/ADa.tmp</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>grapier.s3.ap-east-1.amazonaws.com</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>3.5.239.149</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>3.5.239.149</ip>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>21bb1f7b01bfa9f72187699c7e3d7af3c1280bea5c4480da747e651462431e38</SHA-256>
              <SHA-1>f4f0bb1d8f75a5cd296b94908851f4c5921c4ce4</SHA-1>
              <MD5>452eb5257a2c80e354b2b9f942b1cc80</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>22e270a86deec4f125f0732fdb2704942c34b500294d52816d02abd79fc246d0</SHA-256>
              <SHA-1>146889be6856f60408d28ff4c81944f883608118</SHA-1>
              <MD5>d38ec1cd4e5612a8abc600d422a76596</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>2b4e0da4754bd2e702feee74f2033735d75c3b84ecc48f223e071dbcc4fbad77</SHA-256>
              <SHA-1>c9c76f1cc7d50f0f8ac44670ad511aa6dd1e13a7</SHA-1>
              <MD5>61343e1c15d7b08109761662de20b0c2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>2c24d7ce8275548f3bfe331ea76cdbe514d0ad4eb51517a731d481fc58b4d652</SHA-256>
              <SHA-1>59acd0824a49d5a16bb729f128fddc8c6dbfba3f</SHA-1>
              <MD5>4c73cbd12f50d1cd6926c6642c8bac06</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>5657326e6f8e5d453f51d63fb46d0f91230b0851c27e356a1a4775632405c3bc</SHA-256>
              <SHA-1>28ed05c1d978cf7a9d22c3f50bb85884daf0dca3</SHA-1>
              <MD5>4cea22a270ee2970b06216e558b416bb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>9661f69a3f81b7141afb79641fa5d94d248f8b12f0a1eb56a1e8fb7add00c69a</SHA-256>
              <SHA-1>2290509f1583158699b1d88bb8f3efa04abf90e7</SHA-1>
              <MD5>30af68194e403e2705b6983b61ebec69</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>9b3ffb006d049c3d9eef2e6f519413388e286f4d0cdfd25e9439b495d425d9d7</SHA-256>
              <SHA-1>cee5bd02803c6582b3aba9b3037d40100fe64808</SHA-1>
              <MD5>cc7d20e83ed3e20001c063167b023640</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>9d534af072774eb18c0a5a4ba661823e780513f8db2b698953ff366de495ba67</SHA-256>
              <SHA-1>685ae9f1ab75ccf5056fe985db5700f55b7977a5</SHA-1>
              <MD5>d189d0f251d1caeb4d57cea2e6a4b7ff</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>a4e13ce7a6d4673450c8011e90c0fa2a52e13bfc21815fb81ee85f2fefca02d8</SHA-256>
              <SHA-1>9f5630ccf3bda1d5f657fac8e7b3121dae8ec594</SHA-1>
              <MD5>e0991c2a0b5fb1d00d0e54dde6cdca54</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>bbd67546e9d57673ddee2a50640c3e2145f637f12778d5134c93daa007328c48</SHA-256>
              <SHA-1>849f89fabb0ad9881512b2b4312638a10690fe1f</SHA-1>
              <MD5>749c772ef5c76e2ce42dcaf103830306</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>61588a4b94cd323890aef2e331d75af5f823de66bf8fa17921a92da021a34951</SHA-256>
              <SHA-1>cfe6ce232b7f7221f91022253511157f2485e75b</SHA-1>
              <MD5>35346d0373e9f3588a2ca10beb7054bc</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/x-sharedlib</file_type>
            </value>
            <value>
              <SHA-256>feb87c8168ae71a87a6f36b92f0d48a792de2473f29cd9c4e729b8db912e73dc</SHA-256>
              <SHA-1>083ca295b8225e337327adf83b2a733a2d3988d5</SHA-1>
              <MD5>b3c274444cd0552f97f9e27291dd6f47</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/zip</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>6F627263-B681-4721-A5B5-CBF38A5118CE</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>护照7人.exe</name>
        <report_id>54b8310d-8da8-497b-83a1-c3b9d40b031f</report_id>
        <tags>
          <value>peexe</value>
          <value>dotnet_pe</value>
          <value>unsafe</value>
          <value>xor-url</value>
          <value>expired-cert</value>
          <value>obfuscated</value>
          <value>invalid-signature</value>
          <value>signed</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>888f1863c06c79828d9657b4acde7b500aeaa552981968120d12246a2e15a266</id>
    <title>Analysis Report for 888f1863c06c79828d9657b4acde7b500aeaa552981968120d12246a2e15a266</title>
    <updated>2026-05-11T04:56:17Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0161880f7e400110050d7d</_id>
        <file_type>application/x-msdownload; format=pe64</file_type>
        <flow_id>6a01616edf14f1cb2acf782d</flow_id>
        <hash>888f1863c06c79828d9657b4acde7b500aeaa552981968120d12246a2e15a266</hash>
        <iocs>
          <files>
            <value>
              <MD5>a525b50b7487a817258e599fc247d555</MD5>
              <SHA-1>75b9f71416d83bf004198c73c2eb63568ed0f161</SHA-1>
              <SHA-256>98671ae962ad31097a5e150fdf191073afba96f745c52e07bb9f7ce208b6ebd9</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
          </files>
          <btc_wallets>
            <value>
              <btc_wallet>37ccba887b7a9edcb45b69c3b8c7acde</btc_wallet>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <btc_wallet>3d86f2dcc8da96b552f85efa6e259379</btc_wallet>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>888f1863c06c79828d9657b4acde7b500aeaa552981968120d12246a2e15a266.dll</name>
        <report_id>a4905732-81b3-45a3-93bf-1c19c78457b9</report_id>
        <tags>
          <value>peexe</value>
          <value>pedll</value>
          <value>golang</value>
          <value>mingw</value>
          <value>signed</value>
          <value>adaptive-context</value>
          <value>anti-debug</value>
          <value>anti-vm</value>
          <value>packed</value>
          <value>overlay</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>21486a8aed09c22a6e392db3f419f723825b592a4b68eb83c877ff207b61dd92</id>
    <title>Analysis Report for 21486a8aed09c22a6e392db3f419f723825b592a4b68eb83c877ff207b61dd92</title>
    <updated>2026-05-11T04:56:13Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a016181b87f27901eb5f0f6</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01616c86e92bda70271a07</flow_id>
        <hash>21486a8aed09c22a6e392db3f419f723825b592a4b68eb83c877ff207b61dd92</hash>
        <iocs>
          <urls>
            <value>
              <url>http://protobuf.dev/programming-guides/enum/#cpp</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>protobuf.dev</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>185.199.110.153</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.199.110.153</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>16abff47107bb7d97576549002a16fb11ca6b10ee77963583c303e7f0f2816e9</SHA-256>
              <SHA-1>2cec5658a2db091ccefafada7b4801658122e9b3</SHA-1>
              <MD5>4426eee555e7ed0ac7aef2cedf0fb7fe</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>6e1ff44173b9685a7b4fe78cbe192f6a9723dc799c3b5140fd8ae23a550ac48e</SHA-256>
              <SHA-1>60d3610fde8ed990b25b32b0cffe02f52ae5d52b</SHA-1>
              <MD5>32765b2e2263b9e36505ef8f421c7a3d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>a7d5158736bff0c90b8ef2128e4da6146718d19857802c5e1def087d9029cfd4</SHA-256>
              <SHA-1>f894fdd4c583849889f1cd97e7c5752a0c2af4ee</SHA-1>
              <MD5>ab32cd9c94d6d4a728431ddde8f162e7</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>88e5e6ed94c62071286cff20182ceb46646ed73e8394620fcc316e35dcf4c95c</SHA-256>
              <SHA-1>9019d5f89c15a27d3f597848df3635d4f9c481d5</SHA-1>
              <MD5>67a948aa8f426a20660a3f13b67b17af</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <registry>
            <value>
              <registry>HKCU\Software\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>21486a8aed09c22a6e392db3f419f723825b592a4b68eb83c877ff207b61dd92.exe</name>
        <report_id>6e743a3d-cdcf-4320-9d96-1002c4a20caa</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>mikey</value>
          <value>packed</value>
          <value>stealer</value>
          <value>adaptive-context</value>
          <value>anti-debug</value>
          <value>anti-vm</value>
          <value>cmd</value>
          <value>overlay</value>
          <value>crypto</value>
          <value>fingerprint</value>
          <value>lolbin</value>
          <value>reconnaissance</value>
          <value>schtasks</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>fc252b5fe95d4a632cfd765684c332e86f987f3cc56fde2d2439d8e344bcf17f</id>
    <title>Analysis Report for fc252b5fe95d4a632cfd765684c332e86f987f3cc56fde2d2439d8e344bcf17f</title>
    <updated>2026-05-11T04:55:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a016167b87f27901eb5f0ef</_id>
        <file_type>message/rfc822</file_type>
        <flow_id>6a0161532fcb905ec28c8af6</flow_id>
        <hash>fc252b5fe95d4a632cfd765684c332e86f987f3cc56fde2d2439d8e344bcf17f</hash>
        <iocs>
          <urls>
            <value>
              <url>https://apps.apple.com/account/purchases</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://apps.apple.com/account/subscriptions</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://buy.itunes.apple.com/WebObjects/MZFinance.woa/wa/accountSummary?mt=8</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://icloud-jp.github.io/app2</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://is1-ssl.mzstatic.com/image/thumb/Purple126/v4/74/89/8c/74898c5f-5649-2d24-c3cd-dd33a89dccd0/AppIcon-1x_U007emarketing-0-7-0-85-220.png/120x0w.jpg</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://reportaproblem.apple.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/images_shared/apple_pay_logo_dark_large_2x.png</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/images_shared/wallet_icon_large_2x.png</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/modern/logo/apple-134-70x84.png</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.apple.com/ja-jp/108772?cid=apy-jpn-sub-amp</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.apple.com/ja-jp/billing</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.apple.com/jp/legal</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.apple.com/jp/legal/internet-services/itunes/jp/terms.html</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.apple.com/jp/privacy</url>
              <origin>EMAIL_BODY</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>file:///tmp/tmp3klgfc51.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://apps.apple.com/account/purchases</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://apps.apple.com/account/subscriptions</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://buy.itunes.apple.com/WebObjects/MZFinanc</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://icloud-jp.github.io/app2</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://reportaproblem.apple.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/images_shared</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/images_shared/appl</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/modern/logo/apple</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.apple.com/ja-jp/108772?cid=3Dapy</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.apple.com/ja-jp/billing</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://apps.apple.com/account/purchases</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://apps.apple.com/account/subscriptions</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://buy.itunes.apple.com/WebObjects/MZFinance.woa/wa/accountSummary?mt=8</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://icloud-jp.github.io/app2</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://is1-ssl.mzstatic.com/image/thumb/Purple126/v4/74/89/8c/74898c5f-5649-2d24-c3cd-dd33a89dccd0/AppIcon-1x_U007emarketing-0-7-0-85-220.png/120x0w.jpg</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://reportaproblem.apple.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/images_shared/apple_pay_logo_dark_large_2x.png</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/images_shared/wallet_icon_large_2x.png</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://s.mzstatic.com/email/modern/logo/apple-134-70x84.png</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.apple.com/ja-jp/108772?cid=apy-jpn-sub-amp</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.apple.com/ja-jp/billing</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.apple.com/jp/legal</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.apple.com/jp/legal/internet-services/itunes/jp/terms.html</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.apple.com/jp/privacy</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>apple.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>apps.apple.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>buy.itunes.apple.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>icloud-jp.github.io</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>is1-ssl.mzstatic.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>reportaproblem.apple.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>s.mzstatic.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>support.apple.com</url>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>apple.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>apps.apple.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>buy.itunes.apple.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>icloud-jp.github.io</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>is1-ssl.mzstatic.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>reportaproblem.apple.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>s.mzstatic.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>support.apple.com</url>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>apps.apple.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>buy.itunes.apple.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>icloud-jp.github.io</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>reportaproblem.apple.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>s.mzstatic.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>support.apple.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>193.239.154.22</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.45.239.67</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>17.56.138.10</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>17.8.136.39</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.199.108.153</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.52.180.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>17.253.144.10</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.52.180.26</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>146.75.123.6</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>17.253.144.10</ip>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.52.180.26</ip>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>17.8.136.39</ip>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.199.108.153</ip>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>146.75.123.6</ip>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>17.56.138.10</ip>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.45.239.67</ip>
              <origin>EMAIL_BODY</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.52.180.240</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>0b1793cbe2d8f24c67a80df93caefe448669e81a15818738b1b17c4c0a1a49de</SHA-256>
              <SHA-1>ccf37bba2b8c26cf8fda0e9054aade6d50438312</SHA-1>
              <MD5>3fc407713dafd00ca8af1f1a367ded99</MD5>
              <origin>EMAIL_BODY</origin>
              <file_type>text/html</file_type>
            </value>
            <value>
              <SHA-256>5840991cc8159956ef8124fe93fb9c8086b870fc1b8fb60f0bcb82874424bf07</SHA-256>
              <SHA-1>f3d5deaa6ad7421ef582fd62c8ec45783eea4f48</SHA-1>
              <MD5>74bb6ffc6891a7953ceaa7334da055b3</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/jpeg</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>493a1b38a75be833065acb903f284f3c384b5900473ff82eb0588a96b76a12e5</SHA-256>
              <SHA-1>2dd89f4b2c769f58dae8ba60f422972271024d52</SHA-1>
              <MD5>ebe45f5afd805fd8bf42514cd5bf5d31</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>4c630018c435a2f04f2de244efb8bacbbf61df100bd75b5f3edc2ae13dc30613</SHA-256>
              <SHA-1>762ce8b07a2498d86883a954a26abd5992d0e448</SHA-1>
              <MD5>7232a483bbe90ef925466db0e9b0660c</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>76efbdd97d6f2696e21e4dfaaea9b2536b366ac7c09dfc0744060bbdaa7b5d08</SHA-256>
              <SHA-1>8d2966546722aca82fbfa83b18d552d0ed3fffba</SHA-1>
              <MD5>fb51ef153f92a2f9de1565fc12a41e0c</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>bb83b718455048aaf094737ef686a3d93302db269feb7f75940983dc06516f7a</SHA-256>
              <SHA-1>5bec9df62c6f57ac38fdf8fe1363fbff2b167b90</SHA-1>
              <MD5>77b23d18459646c8acf9f99f4b48a05a</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>ba542a0c39f1e18f9bcf498713f23ff5fa08ee2b43c601b1554c2fe1f7dfac4b</SHA-256>
              <SHA-1>6424a012976287c71b77ef09079465e1908605fb</SHA-1>
              <MD5>ead8f71f80bb1f3b1eadf24a1b00f1d5</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>13b8890697210022f5ad4c5df40121128132bd5d10447fd391369c2a5cd28452</SHA-256>
              <SHA-1>2749e15681ead91a4d8bc72c9977f84910b58f29</SHA-1>
              <MD5>4a57f2589fb62bd0b8803cdee76dfb65</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/x-plist</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>68982df27492c272722f197674d644080e1ed54d7da09b80e261f6dea28ad05d</SHA-256>
              <SHA-1>d919d0af961208080c2c107d6f4453568ef7a247</SHA-1>
              <MD5>8ec000da2082098df21831a077d5f97a</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>94e28647a6cd81ab2310c4b4953fefbfd7005194b788f4128f147a1c0f0ae617</SHA-256>
              <SHA-1>f1cfd36c9de0eb854d6fdd152cb94cb5e495305d</SHA-1>
              <MD5>fe42fb8267b6c0bdb5ff8dd212d85cf1</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>584c88c7880d7c934271a48cb65cb1d513eb271d70ca5d88187e1323dff1fbc3</SHA-256>
              <SHA-1>403fa04cbcbdc6b6ea9d4c630b90c3d9f73ca45f</SHA-1>
              <MD5>ebd7c0334d4834328b638e397ff7ba2a</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>74898c5f-5649-2d24-c3cd-dd33a89dccd0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>74898c5f-5649-2d24-c3cd-dd33a89dccd0</uuid>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <uuid>74898c5f-5649-2d24-c3cd-dd33a89dccd0</uuid>
              <origin>EMAIL_BODY</origin>
            </value>
          </uuids>
        </iocs>
        <name>submission.eml</name>
        <report_id>5564cc26-36ff-48be-b650-0a9d44e75236</report_id>
        <tags>
          <value>eml</value>
          <value>rfc822</value>
          <value>html</value>
          <value>jpg</value>
          <value>png</value>
          <value>obfuscated</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1ce7da6f2813c2ad1d2e496be6714e08cd618e6d9fe2df26c2bd4d894c9a6ec1</id>
    <title>Analysis Report for 1ce7da6f2813c2ad1d2e496be6714e08cd618e6d9fe2df26c2bd4d894c9a6ec1</title>
    <updated>2026-05-11T04:55:10Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01614497e8658d088c8273</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01612d86e92bda702719e4</flow_id>
        <hash>1ce7da6f2813c2ad1d2e496be6714e08cd618e6d9fe2df26c2bd4d894c9a6ec1</hash>
        <iocs>
          <urls>
            <value>
              <url>http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crls.ssl.com/ssl.com-rsa-RootCA.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://sectigo.com/CPS0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.ssl.com/repository0</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>cert.ssl.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crl.sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crl.usertrust.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crls.ssl.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crt.sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crt.usertrust.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>ssl.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>91.199.212.90</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>35.171.101.7</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.64.149.23</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.38.233</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.216.37.85</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>65.9.175.88</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.216.37.85</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.38.233</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.64.149.23</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>65.9.175.88</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>91.199.212.90</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>35.171.101.7</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>329d8d3a5169b72f453957fdde7144d250cab34fd5cdef1ddcbb7cfdabbf1d5c</SHA-256>
              <SHA-1>b626b4f5de8670bbc61b11391678784df3705cfe</SHA-1>
              <MD5>4a9f1c75eeebc741e4930c85b471109e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>351cf2901c06b010a309819777bcec1650b3a006cbac97e27574188b75e6e920</SHA-256>
              <SHA-1>c796cbff89953c249bff5eddb6fdc67b37f88745</SHA-1>
              <MD5>47f8fe6e6319f839e61484752e5abc2e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>376bdef5a5c972c1b56d4b188a71045e4779a950f716053d1d29dfa7b3f78291</SHA-256>
              <SHA-1>4380a303198ea380fd5b8116d7a164fd75d735f3</SHA-1>
              <MD5>f990b7e9d9c7251575acdcf3f1879a3b</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>5e9b9eaad612df3d4152bbff0f456e0c2c0891f48931be188c743dd25a28678d</SHA-256>
              <SHA-1>e82ae5a14a68a148724d4c2b8a644645f6c55eee</SHA-1>
              <MD5>a6891f38e1825973a0cafcf547064ea6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>9277c15fe539fb978f86dcf41b5aeb98344ff5fa566df1f25230ec4923ce62e0</SHA-256>
              <SHA-1>9f162910e8ceae30aeb602879e6e75eb5cd219ca</SHA-1>
              <MD5>5a6d7a640d663576caee72bd21d75da0</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>9306910d4bb273465765832df77fb1fd78bd6e0bcbf9908636e323c34c92b613</SHA-256>
              <SHA-1>201f2f699e6917e953821d64105b226fdd8b5528</SHA-1>
              <MD5>5beaeebda5346956e395fad21661f382</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>9c28a70ca0c93e2c40b5dac0c122f5e35740e9faee5c257018831abc879a5745</SHA-256>
              <SHA-1>19314e7af6d670eba871449eb72f5be21deb773b</SHA-1>
              <MD5>c2832526dfb7e3ea52a2bea3d0520c44</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>a6d264edfc90626460914241780b6635050855ca34aeef19f6c580bafb95e398</SHA-256>
              <SHA-1>123da8ce5bda7de733d8e8f71f5eaf2ffa117b6a</SHA-1>
              <MD5>f429ccf0798f2757370dcd098efeb7c9</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>ae1748a31db9f5cbcb798cf2e731b59b8fdc8724d297852c999078dc796c49dd</SHA-256>
              <SHA-1>b20092d0c441f2e64d01b5789ff742a49f547ddf</SHA-1>
              <MD5>42a4b9f01356d333a84d484af77beea0</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>aeeccfb984de238a780b19f10447df9bc89a9d4876227bd089cfb79a299df7ad</SHA-256>
              <SHA-1>eab23bde0b24a561109568da1b1626ec3d4ed3e4</SHA-1>
              <MD5>a71bc2df86803876831c8f327fa13ee0</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>c2acf6afa5e5d036552a53fe6217b2522b0ac9e43dc657bc8229e6a139a9904e</SHA-256>
              <SHA-1>268583fc4d8a27c2ccd28219828b2d461666347a</SHA-1>
              <MD5>6e506bd18d95e4188cc2c6dcf4b36556</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>dd16ec3ccde25604528555d3ee74c054cf99c092f95f76db25556a861054bb30</SHA-256>
              <SHA-1>06d36ada025c682261a006616f5923ef37be4280</SHA-1>
              <MD5>70ebe454a143461c67c0153f554c42c3</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4d95f8d7fef14ba3b399ac5f08fdb2083b63076f263fbca389a39ad4d92a13c8</SHA-256>
              <SHA-1>00c8aa98aa528234b6ac63bf5518bb6c61c5f839</SHA-1>
              <MD5>f5f95ed5671c296b97a9475cec3d2987</MD5>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
            <value>
              <SHA-256>2acab1228e8935d5dfdd1756b8a19698b6c8b786c90f87993ce9799a67a96e4e</SHA-256>
              <SHA-1>80c9820ff2efe8aa3d361df7011ae6eee35ec4f0</SHA-1>
              <MD5>4842e206e4cfff2954901467ad54169e</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/octet-stream</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>a824bc7739e226e1b40ea0f8c4e4f4c6f796fc3b4abfa6e9abe3bd119a30d938</SHA-256>
              <SHA-1>0dde8fd9111d807e202b2fb37f8bcc4052fd861e</SHA-1>
              <MD5>b6c792c0f58fa3ec92173c074885221f</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>f0f1e2e6639713702364c73a87bf873f5a82d77da7801b8b7501aded95d8029f</SHA-256>
              <SHA-1>efcbec36e43e9d28ee7d9dc883651da8adb2fcc1</SHA-1>
              <MD5>a43d6fe98edf9cd246790e17e052fa50</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\AutoIt v3\AutoIt</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>AutoClicker.exe</name>
        <report_id>cb3795d3-020c-44f7-a6e2-7be5d9d790d9</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>xml</value>
          <value>data</value>
          <value>xworm</value>
          <value>adaptive-context</value>
          <value>anti-debug</value>
          <value>keylogger</value>
          <value>packed</value>
          <value>compiled-script</value>
          <value>obfuscated</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>autoit</value>
          <value>expired-cert</value>
          <value>microsoft_visual_cc</value>
          <value>signed</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1ce7da6f2813c2ad1d2e496be6714e08cd618e6d9fe2df26c2bd4d894c9a6ec1</id>
    <title>Analysis Report for 1ce7da6f2813c2ad1d2e496be6714e08cd618e6d9fe2df26c2bd4d894c9a6ec1</title>
    <updated>2026-05-11T04:54:37Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01612bd6e5cdb561983747</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01610a2fcb905ec28c8a89</flow_id>
        <hash>1ce7da6f2813c2ad1d2e496be6714e08cd618e6d9fe2df26c2bd4d894c9a6ec1</hash>
        <iocs>
          <urls>
            <value>
              <url>http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://crls.ssl.com/ssl.com-rsa-RootCA.crl0</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://sectigo.com/CPS0</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://www.ssl.com/repository0</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>cert.ssl.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crl.sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crl.usertrust.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crls.ssl.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crt.sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crt.usertrust.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>ssl.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>104.18.38.233</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>91.199.212.90</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>65.9.175.52</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.231.166.37</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>35.171.101.7</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.231.166.37</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.38.233</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>65.9.175.52</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>91.199.212.90</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>35.171.101.7</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>4a9f1c75eeebc741e4930c85b471109e</MD5>
              <SHA-1>b626b4f5de8670bbc61b11391678784df3705cfe</SHA-1>
              <SHA-256>329d8d3a5169b72f453957fdde7144d250cab34fd5cdef1ddcbb7cfdabbf1d5c</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>47f8fe6e6319f839e61484752e5abc2e</MD5>
              <SHA-1>c796cbff89953c249bff5eddb6fdc67b37f88745</SHA-1>
              <SHA-256>351cf2901c06b010a309819777bcec1650b3a006cbac97e27574188b75e6e920</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>f990b7e9d9c7251575acdcf3f1879a3b</MD5>
              <SHA-1>4380a303198ea380fd5b8116d7a164fd75d735f3</SHA-1>
              <SHA-256>376bdef5a5c972c1b56d4b188a71045e4779a950f716053d1d29dfa7b3f78291</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>a6891f38e1825973a0cafcf547064ea6</MD5>
              <SHA-1>e82ae5a14a68a148724d4c2b8a644645f6c55eee</SHA-1>
              <SHA-256>5e9b9eaad612df3d4152bbff0f456e0c2c0891f48931be188c743dd25a28678d</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>5a6d7a640d663576caee72bd21d75da0</MD5>
              <SHA-1>9f162910e8ceae30aeb602879e6e75eb5cd219ca</SHA-1>
              <SHA-256>9277c15fe539fb978f86dcf41b5aeb98344ff5fa566df1f25230ec4923ce62e0</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>5beaeebda5346956e395fad21661f382</MD5>
              <SHA-1>201f2f699e6917e953821d64105b226fdd8b5528</SHA-1>
              <SHA-256>9306910d4bb273465765832df77fb1fd78bd6e0bcbf9908636e323c34c92b613</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>c2832526dfb7e3ea52a2bea3d0520c44</MD5>
              <SHA-1>19314e7af6d670eba871449eb72f5be21deb773b</SHA-1>
              <SHA-256>9c28a70ca0c93e2c40b5dac0c122f5e35740e9faee5c257018831abc879a5745</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>f429ccf0798f2757370dcd098efeb7c9</MD5>
              <SHA-1>123da8ce5bda7de733d8e8f71f5eaf2ffa117b6a</SHA-1>
              <SHA-256>a6d264edfc90626460914241780b6635050855ca34aeef19f6c580bafb95e398</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>42a4b9f01356d333a84d484af77beea0</MD5>
              <SHA-1>b20092d0c441f2e64d01b5789ff742a49f547ddf</SHA-1>
              <SHA-256>ae1748a31db9f5cbcb798cf2e731b59b8fdc8724d297852c999078dc796c49dd</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>a71bc2df86803876831c8f327fa13ee0</MD5>
              <SHA-1>eab23bde0b24a561109568da1b1626ec3d4ed3e4</SHA-1>
              <SHA-256>aeeccfb984de238a780b19f10447df9bc89a9d4876227bd089cfb79a299df7ad</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>6e506bd18d95e4188cc2c6dcf4b36556</MD5>
              <SHA-1>268583fc4d8a27c2ccd28219828b2d461666347a</SHA-1>
              <SHA-256>c2acf6afa5e5d036552a53fe6217b2522b0ac9e43dc657bc8229e6a139a9904e</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>70ebe454a143461c67c0153f554c42c3</MD5>
              <SHA-1>06d36ada025c682261a006616f5923ef37be4280</SHA-1>
              <SHA-256>dd16ec3ccde25604528555d3ee74c054cf99c092f95f76db25556a861054bb30</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>f5f95ed5671c296b97a9475cec3d2987</MD5>
              <SHA-1>00c8aa98aa528234b6ac63bf5518bb6c61c5f839</SHA-1>
              <SHA-256>4d95f8d7fef14ba3b399ac5f08fdb2083b63076f263fbca389a39ad4d92a13c8</SHA-256>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
            <value>
              <MD5>4842e206e4cfff2954901467ad54169e</MD5>
              <SHA-1>80c9820ff2efe8aa3d361df7011ae6eee35ec4f0</SHA-1>
              <SHA-256>2acab1228e8935d5dfdd1756b8a19698b6c8b786c90f87993ce9799a67a96e4e</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/octet-stream</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>b6c792c0f58fa3ec92173c074885221f</MD5>
              <SHA-1>0dde8fd9111d807e202b2fb37f8bcc4052fd861e</SHA-1>
              <SHA-256>a824bc7739e226e1b40ea0f8c4e4f4c6f796fc3b4abfa6e9abe3bd119a30d938</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>84d0db1b2f2cf86cb2bc91e3e390cd25</MD5>
              <SHA-1>61086fd62a58783c5242d1658957b0c5e73822f3</SHA-1>
              <SHA-256>207ce064428ae9e7d7ac8b70e302a978675e09fb7aa78ec03ae4d355e817e4f5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\AutoIt v3\AutoIt</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>AutoClicker.exe</name>
        <report_id>cb3dee07-34bb-4fc7-8bbd-4fcb170279d9</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>xml</value>
          <value>data</value>
          <value>adaptive-context</value>
          <value>anti-debug</value>
          <value>keylogger</value>
          <value>packed</value>
          <value>obfuscated</value>
          <value>compiled-script</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>autoit</value>
          <value>expired-cert</value>
          <value>microsoft_visual_cc</value>
          <value>signed</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>7ef12df41be12d092802d20139c8b82df7f458289c81b02acf22e7280ecc920a</id>
    <title>Analysis Report for 7ef12df41be12d092802d20139c8b82df7f458289c81b02acf22e7280ecc920a</title>
    <updated>2026-05-11T04:54:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01611bb87f27901eb5f0df</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0160ed86e92bda702719af</flow_id>
        <hash>7ef12df41be12d092802d20139c8b82df7f458289c81b02acf22e7280ecc920a</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.mobiledit.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://cacerts.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crt0_</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>http://crl3.digicert.com/DigiCertTrustedG4TimeStampingRSA4096SHA2562025CA1.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>http://crl3.digicert.com/DigiCertTrustedRootG4.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>http://www.digicert.com/CPS0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.mobiledit.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://enigmaprotector.com/taggant/spv.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://enigmaprotector.com/taggant/user.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>cacerts.digicert.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crl3.digicert.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crl4.digicert.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>digicert.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>enigmaprotector.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>mobiledit.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>mobiledit.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>198.185.159.144</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>45.60.131.229</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.11.40.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>205.251.139.155</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>198.185.159.144</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.11.40.157</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>45.60.131.229</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>205.251.139.155</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>014a25473c8790f5cfd7c7d494f99279ec07c4afc9abea64fa6fa5bfff256391</SHA-256>
              <SHA-1>f7e158784926953d42397003b9209d5ad8235f9d</SHA-1>
              <MD5>38c3b27c704e68d11346733097b6811c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>1aef8ee5867f01d638c96f2f3cba889907a6b3b0c8553cfa0c00466ac23dd5e1</SHA-256>
              <SHA-1>33cd0ee5f4b1350d056fee8c22f113c551846218</SHA-1>
              <MD5>86526cf743e4d1e2d899b11eb7b534ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>1c721b7bea702b89282dfb2c3398b757e3db60041eae0d5e4970746552d014e0</SHA-256>
              <SHA-1>b7020f3964f9823c2c1bd482eb0c9e3c2df4dbee</SHA-1>
              <MD5>426e337821b47108843f4676b60c7ef8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>205695fb6c6f70383691cd68178238ba8114c7a74aad0fac8bef35f943fe413d</SHA-256>
              <SHA-1>96edd4cd0293d7cf987704685e78e95442ad6b61</SHA-1>
              <MD5>b9dbb8c2d365486ce99520fa565fd844</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>332e04a40c1e679b568c2c4cd51d0e2c2ddf0b8d8e93001d4e9c18c11cbfbd03</SHA-256>
              <SHA-1>8e07f8d0159193812bd493766b57375a18b9aa33</SHA-1>
              <MD5>bf90a1a61623ac97f0dcd18d8b772505</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>38ade16ce0a0602a0a3be5dfd333baef1f65a852eebc0eb63c60d0e1ce58cc62</SHA-256>
              <SHA-1>e3482b447ab9778170893e29fe3dce1339311e3c</SHA-1>
              <MD5>057e97da98f483317a3039827fb08403</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>451f27e1bbd823fe5a2ca124ff0a5c1b9d6a4d1a0d87b35ff26e40017736d9a4</SHA-256>
              <SHA-1>87099061aa37eb0a6d59a56e6c20f90b57d76fd5</SHA-1>
              <MD5>ff81c5e1959869528a3ba40128e21ecd</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>45c1795e518b3ac386e9478b1f737a1b88ef9ab41c7011579f0a9372492109f1</SHA-256>
              <SHA-1>0d881bb8a7a517992c8e92af2111dfcc56d1fe26</SHA-1>
              <MD5>1c6eee7adbd7088dc07516e32b0eb733</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>468d1f3dc1eeb3019ab8d9718e4eaf3ae058a7a6487197a1b543d8f7cb828000</SHA-256>
              <SHA-1>a253ebf51a3b4115dd6f42e863db630cf8418478</SHA-1>
              <MD5>f0ff4c972db7ceba4625f7260662a70c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4fa27c768265bddea4aaee56ddd4323fa7cb76e975e66b97bdab77b33a5b6441</SHA-256>
              <SHA-1>302c4811fd8095ae15a8dd8b284822c22ba3ca85</SHA-1>
              <MD5>00e344e25efba8290afbf0725fec3fa8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>55e32ebf1ffd60b713d602de8e781b27d770368fe26a7d21a8b387551f792cbf</SHA-256>
              <SHA-1>19bfb8e4971874acc3a1258ecaed2b8ba2cc9625</SHA-1>
              <MD5>49ff8fe0b8b92223ec3b262ccdc1f9ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>5d6a080c14bd9d59c0ae28f29b47a700fca50875e29ded5fb5c9a30aa8fc54f8</SHA-256>
              <SHA-1>0087466acb240c2f477bfac8dbeb344cc84c66b3</SHA-1>
              <MD5>ae959ecf8ec7c79a55703378a82fda7b</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>67f683bbc856e359c6b66f784cee5ecfbcd8a9fa25884c665dd5d7ef5a5a456a</SHA-256>
              <SHA-1>5903ae0a6c49b3b046532ef0566cbc707ac3110d</SHA-1>
              <MD5>77600be16b850868cf2bf5660b39b9f6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>9aed14b5017e8db26d0bf6884e841a76cdd30c81405ede8fd09a6d022fb800e0</SHA-256>
              <SHA-1>1fd7cf4cc150dd8cb452db08dc27e8aab398946f</SHA-1>
              <MD5>e6f67027c2ac559ad1a7d9bb07d754e9</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>bbe79490a27737b44ac084d91326471d8e8d1740690942a363dbe454729e4c2f</SHA-256>
              <SHA-1>eb4302a2088c64ca9cf2f74c405f35edb6dd259a</SHA-1>
              <MD5>4f6359b8d81462696343e442a2814446</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>da03a0d0c6e91f9b6190a74b443c9f76a259a72ab2a07eeadf31dbf6d02b574a</SHA-256>
              <SHA-1>8c65d48ae69983c268414a5937e788b92a27a457</SHA-1>
              <MD5>ee399ff77e02407013db7f5e5e45e2c4</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>f6137ba72a6c25f8889100555fea38bc8be40ba17cdb67d4652e7a3d86f2836c</SHA-256>
              <SHA-1>9861484308c920cdef679d0d1eb2292873177795</SHA-1>
              <MD5>89a9d4430a4c90896b5e8d5ef3ab3f7f</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>fee08e3a05f204b86889b848b7f80ec5e8334f3ac3c8f5306e729e7dab4f5503</SHA-256>
              <SHA-1>8b6c2ea9778e800b591801bcf65f50b5add74fed</SHA-1>
              <MD5>b9dbcf770a69542950970b3f6dce56df</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>ebc3cfbdff6366cc2ede3ebab54b1a9575df262392ad93abf2976759e0ed6f22</SHA-256>
              <SHA-1>64774f040e460bdd682d4fe25d8460c3ff3bb6bb</SHA-1>
              <MD5>daedc25b5a7ba2d22b0692efdef8d099</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
        </iocs>
        <name>MOBILeditForensic.exe</name>
        <report_id>325d746e-5350-444d-a011-0d1d11f469ca</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>enigma</value>
          <value>unsafe</value>
          <value>packed</value>
          <value>overlay</value>
          <value>obfuscated</value>
          <value>microsoft_visual_cc</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c4024fbcb088396fd8665e007b039571af621873143f190eac1b92439864abf2</id>
    <title>Analysis Report for c4024fbcb088396fd8665e007b039571af621873143f190eac1b92439864abf2</title>
    <updated>2026-05-11T04:53:12Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a016123b87f27901eb5f0e1</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0160b7792fe2d217aedca3</flow_id>
        <hash>c4024fbcb088396fd8665e007b039571af621873143f190eac1b92439864abf2</hash>
        <iocs>
          <urls>
            <value>
              <url>https://accounts.google.com/gsi/client</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.jsdelivr.net/gh/devicons/devicon/icons/google/google-original.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.analytics.google.com/g/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.analytics.google.com/g/collect?v=2&amp;tid=G-B6E6ECFR8T&amp;gtm=45je6562v9180653732za200zd9180653732&amp;_p=1778475196835&amp;_gaz=1&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;dma_cps=a&amp;dma=1&amp;_eu=AAAAAGAC&amp;are=1&amp;cid=1583135170.1778475197&amp;frm=0&amp;pscdl=noapi&amp;rcb=9&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;gaf=2&amp;_s=1&amp;tag_exp=0~115938465~115938468~118128922~118463262~118494633&amp;sid=1778475196&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fsavesora.com%2Fes%2Fonline-downloader&amp;dt=SaveSora%20%E2%80%94%20Descargador%20de%20Videos%20Online%20R%C3%A1pido%20y%20Gratuito&amp;en=page_view&amp;_fv=1&amp;_nsi=1&amp;_ss=1&amp;_ee=1&amp;tfd=454</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/api/fetch-product-pricing</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/ar/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/assets/common.js?v=20260228</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/assets/jquery.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/assets/sweetalert2.all.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/assets/sweetalert2.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/bn/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/cs/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/de/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/account</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/ai-tools</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/dmca</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/links</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/my-creations</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/pricing</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/privacy</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/refund-policy</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/reward-center</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/terms</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/fa/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/fr/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/hi/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/id/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/gift.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/global.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/copy.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/email.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/facebook.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/line.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/linkedin.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/messenger.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/more.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/naver.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/reddit.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/share.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/telegram.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/threads.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/whatsapp.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/share/x.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/sora-03.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/icon/vip.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/step01.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/step02.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/images/step03.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/it/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/ja/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/ko/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/nl/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/pl/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/pt-pt/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/ru/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/th/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/tr/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/uk/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/ur/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/uz/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/vi/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/zh-cn/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/zh-tw/online-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stats.g.doubleclick.net/g/collect?v=2&amp;tid=G-B6E6ECFR8T&amp;cid=1583135170.1778475197&amp;gtm=45je6562v9180653732za200zd9180653732&amp;rcb=9&amp;aip=1&amp;dma=1&amp;dma_cps=a&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;frm=0&amp;tag_exp=0~115938465~115938468~118128922~118463262~118494633</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google.com/ccm/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google.com/ccm/collect?rcb=11&amp;frm=0&amp;en=page_view&amp;dl=https%3A%2F%2Fsavesora.com%2Fes%2Fonline-downloader&amp;scrsrc=www.googletagmanager.com&amp;rnd=1839981442.1778475197&amp;dt=SaveSora%20%E2%80%94%20Descargador%20de%20Videos%20Online%20R%C3%A1pido%20y%20Gratuito&amp;auid=296059035.1778475197&amp;navt=n&amp;npa=1&amp;gtm=45be6562v9243821716za200zb9180653732zd9180653732xec&amp;gcd=13l3l3l2l1l1&amp;dma_cps=a&amp;dma=1&amp;tag_exp=0~115938465~115938468~118463261&amp;apve=1&amp;apvf=f&amp;apvc=1&amp;tids=AW-17823741984&amp;tid=AW-17823741984&amp;tft=1778475197122&amp;tfd=582</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google.de/ads/ga-audiences?v=1&amp;t=sr&amp;slf_rd=1&amp;_r=4&amp;tid=G-B6E6ECFR8T&amp;cid=1583135170.1778475197&amp;gtm=45je6562v9180653732za200zd9180653732&amp;rcb=9&amp;aip=1&amp;dma=1&amp;dma_cps=a&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;frm=0&amp;tag_exp=0~115938465~115938468~118128922~118463262~118494633&amp;z=1570819986</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=AW-17823741984&amp;cx=c&amp;gtm=4e6562</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-B6E6ECFR8T</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/embed/VF5MSL7Uqr4?si=N8WsDVXdDn2t4e-z</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>mailto:support@savesora.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/online-downloader&amp;dt=SaveSora</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://savesora.com/es/online-downloader&amp;scrsrc=www.googletagmanager.com&amp;rnd=1839981442.1778475197&amp;dt=SaveSora</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://savesora.com/es/online-downloader</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://www.w3.org/2000/svg</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://accounts.google.com/gsi/client</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://api.whatsapp.com/send?text=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://line.me/R/share?text=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://savesora.com/ar/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/bn/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/cs/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/de/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/ai-tools</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/pricing</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/privacy</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/reward-center</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/es/terms</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/fa/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/fr/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/hi/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/id/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/it/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/ja/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/ko/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/nl/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/pl/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/pt-pt/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/ru/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/th/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/tr/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/uk/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/ur/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/uz/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/vi/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/zh-cn/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://savesora.com/zh-tw/online-downloader</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://schema.org</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://share.naver.com/web/shareView?url=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://t.me/share/url?text=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://twitter.com/intent/tweet?url=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.facebook.com/sharer/sharer.php?u=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.linkedin.com/feed/?shareActive=true&amp;text=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.reddit.com/submit?title=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.threads.com/intent/post?text=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/embed/VF5MSL7Uqr4?si=N8WsDVXdDn2t4e-z</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>accounts.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.jsdelivr.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>region1.analytics.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>savesora.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>stats.g.doubleclick.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.google.de</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.youtube.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>accounts.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>api.whatsapp.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>line.me</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>savesora.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>schema.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>share.naver.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>t.me</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>twitter.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.linkedin.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.reddit.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.threads.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.w3.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <emails>
            <value>
              <email>support@savesora.com</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>57.144.244.1</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.97</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.22.12</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.84</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>175.158.5.166</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>157.240.253.60</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.21.33.202</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>146.75.121.140</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>147.92.243.206</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>149.154.167.99</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.13.190</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.207.5</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.21.33.202</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.154</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.84</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.94</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.150.119</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.20.136</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>192.178.183.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>216.239.32.36</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>163.70.128.63</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.22.19</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.84</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>157.240.253.60</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>147.92.243.206</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.21.33.202</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.101</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>175.158.5.166</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>149.154.167.99</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>57.144.244.1</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.97</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.22.12</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>146.75.121.140</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>163.70.128.63</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.22.19</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.13.190</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>220bcb1ca2a00dad8195df3f900f82cab60fa423364e9d9aff31559947bf15ce</SHA-256>
              <SHA-1>8d52cf5d7815d3679d1cd8f326471edfe9fd9f34</SHA-1>
              <MD5>4ddcdb6a2d207dd0277856f0549bcf60</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>7c5fda4188f3c811d6b0a9438c8b03957a1fc80dcd1d6f4cf8317833282851eb</SHA-256>
              <SHA-1>50206d29d869222723bb4e15ffb0df32ee695948</SHA-1>
              <MD5>cfd24b96019aab5cfdc6bcef4bcf1cfb</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>1fcd9307498908b82871fa6d799a23c6aa8a81ae513c456de3d5778e79b81931</SHA-256>
              <SHA-1>fc246065245eedf53c2fb1d8cfb2c53f2bb30670</SHA-1>
              <MD5>c3ccd61f19b8e8b50faa2acfb58fc1eb</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>2b13d2fe03a2c77fc6c1bf6808886b78c02d274c1feb08be9c1b5e511e794825</SHA-256>
              <SHA-1>0ab552f98ecfbceb0ef14f15f9b1bb6c101204e9</SHA-1>
              <MD5>999fbc742d6ab65aaa7cb40fea9cec56</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>b987e413e8844ed137d5844216c98d61664f44f6ca90a05021de83e3a5518965</SHA-256>
              <SHA-1>2bc586c70ba7ff8e26c01b3d23c351b255623613</SHA-1>
              <MD5>bdd951cdbb6951bb4706119ab14e685f</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>2f0c142050617cba453713611aa9400b71f0d2478ad4c8751b0f00f93043bfad</SHA-256>
              <SHA-1>20e78c82d9672a958b834747bd47b7af1541c872</SHA-1>
              <MD5>8f9ab09ca2b26d0e9169c978fb65e2ba</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>3225d787794e7fac94dc5a0e98d6a1bc0c5de93bf4543ab4ee55515f7c00de94</SHA-256>
              <SHA-1>64271984f522738ae5c1869689a96203d1597196</SHA-1>
              <MD5>f4bf3b02b850989bf0e8f24b48183b40</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>9765b1199a4e68d32fb24b3b37104e793834ec2b679e30f641f4a96abb9c950f</SHA-256>
              <SHA-1>3588be949adb841979a73b1595f2482329cbae62</SHA-1>
              <MD5>df123eab4c1ac5a365434838674d7fc6</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>c8a737c03213274e8cf2ef70854088f5bdf3a88c53c5cb586391fbc4deeff7f4</SHA-256>
              <SHA-1>6323840fcd30adcb83a01ff25df45787f54a3d51</SHA-1>
              <MD5>57d17a6d68c9221b1e1118c475ce94d9</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>be8f423928f1a3f68c3e1a6c1f74a85bae5c33532b078ec2b5bc1ee87d20adbe</SHA-256>
              <SHA-1>859c23619be73224309e49b87db2d5436e6edd66</SHA-1>
              <MD5>f69b31074fbe4bc1644c66d01f1f806a</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>hxxps://savesora.com/es/online-downloader</name>
        <report_id>e0547342-a47d-48bb-81e4-60990d9f74fc</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>base64</value>
          <value>evasive</value>
          <value>obfuscated</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1eba8af7d2b3e54cf72c5ea583ff57c0f90eee130ed52619921aaadd3e950017</id>
    <title>Analysis Report for 1eba8af7d2b3e54cf72c5ea583ff57c0f90eee130ed52619921aaadd3e950017</title>
    <updated>2026-05-11T04:52:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160adb87f27901eb5f0c8</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01608986e92bda70271944</flow_id>
        <hash>1eba8af7d2b3e54cf72c5ea583ff57c0f90eee130ed52619921aaadd3e950017</hash>
        <iocs>
          <urls>
            <value>
              <url>https://jrsoftware.org/ishelp/index.php?topic=setupcmdline</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>jrsoftware.org</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>75.119.223.113</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>7.0.0.1</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>75.119.223.113</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>3ac6937e0010044f0b69d82e16b1f000de878a497fdc8a7b9a166b2132c87be9</SHA-256>
              <SHA-1>4082b959191c985b9419b38c24bae32661663d1c</SHA-1>
              <MD5>039e8a7e7c58c228ce4a147e2102faa9</MD5>
              <origin>PE_EMULATION</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <SHA-256>930f8dbfecdab600c3babd0e10b99018f4db1200bf44af1aa135ee286af2246d</SHA-256>
              <SHA-1>191e18f9659b36eb9957a2fe41d2f8a547ca18d1</SHA-1>
              <MD5>ad0be329bf823c481476b8ed14d25673</MD5>
              <origin>PE_EMULATION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>adb81901042f2654154a003d72e83217aed1403ab25978494cae1df247fec716</SHA-256>
              <SHA-1>be01dc45b5dd45a6ef45a59bd99035b8f5822497</SHA-1>
              <MD5>5decd90cee87bb0ceab8762287b90be0</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <registry>
            <value>
              <registry>Software\Borland\Delphi\Locales</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Borland\Locales</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\CodeGear\Locales</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Embarcadero\Locales</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows NT\CurrentVersion</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Borland\Delphi\Locales</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Borland\Locales</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\CodeGear\Locales</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Embarcadero\Locales</registry>
              <origin>INPUT_FILE</origin>
            </value>
          </registry>
          <btc_wallets>
            <value>
              <btc_wallet>x15d7295:$btc: 11i11i11i11i11i11i11i11i11i1</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>AenamiSetup.exe</name>
        <report_id>92decf97-a645-4b93-814b-cd362c670245</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>wiper</value>
          <value>coinminer</value>
          <value>adaptive-context</value>
          <value>evasive</value>
          <value>packed</value>
          <value>anti-debug</value>
          <value>crypto</value>
          <value>fingerprint</value>
          <value>installer</value>
          <value>reconnaissance</value>
          <value>expand</value>
          <value>lolbin</value>
          <value>inno</value>
          <value>embarcadero_delphi</value>
          <value>installer-heuristic</value>
          <value>zero-day</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6dd22203074be0262ee4c3a9a55b7a67576221d2f967ec849e2f48a53d4b79a4</id>
    <title>Analysis Report for 6dd22203074be0262ee4c3a9a55b7a67576221d2f967ec849e2f48a53d4b79a4</title>
    <updated>2026-05-11T04:52:21Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160aab87f27901eb5f0c7</_id>
        <file_type>application/x-sharedlib</file_type>
        <flow_id>6a0160819b72a1a5304c7781</flow_id>
        <hash>6dd22203074be0262ee4c3a9a55b7a67576221d2f967ec849e2f48a53d4b79a4</hash>
        <iocs>
          <ips>
            <value>
              <ip>142.248.80.139</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
        </iocs>
        <name>agent_mipsle.elf</name>
        <report_id>4eca5fa7-d855-47ae-9899-22ae68ce4a1e</report_id>
        <tags>
          <value>elf</value>
          <value>elf-shared</value>
          <value>mirai</value>
          <value>anti-vm</value>
          <value>bash</value>
          <value>lolbin</value>
          <value>gcc</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>075b79c9cde4ac38a2a427a65b8894ff36ba46090e03b663dbc6ac3a24d4d8e6</id>
    <title>Analysis Report for 075b79c9cde4ac38a2a427a65b8894ff36ba46090e03b663dbc6ac3a24d4d8e6</title>
    <updated>2026-05-11T04:52:08Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160e0b87f27901eb5f0d2</_id>
        <file_type>application/pdf</file_type>
        <flow_id>6a0160757d31ad7bba4fe6bb</flow_id>
        <hash>075b79c9cde4ac38a2a427a65b8894ff36ba46090e03b663dbc6ac3a24d4d8e6</hash>
        <iocs>
          <files>
            <value>
              <SHA-256>7cc4bf6a4f71326d7123124af795fbdc71c16a100984669b27474790fe9606ca</SHA-256>
              <SHA-1>d71a288212a737ce78c169cab3b8bd4b56191b15</SHA-1>
              <MD5>e2b828e52c51733a3165168559c5ab7d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>a2ffce18d222f6bf849a3f9cbb5704795e4184d12bf157269639db451b6b4139</SHA-256>
              <SHA-1>fa7da046c7c6d9a96c58de599f915f7d5412b75c</SHA-1>
              <MD5>da7dd232433d66919c803ee2bfcf5b93</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>03365058-f648-48db-971e-6ae0f9a56b8b</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>1e1f5b28-9e67-42f8-8134-d72e36a98603</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>215daf98-2234-4ac0-a944-591b2ff03056</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>27881f91-1868-4fe3-906f-a2daddd36888</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>2f1598e6-b5da-4fd8-b597-ac0ad34d2599</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>36ac60af-a402-448f-9776-b16f45966e68</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>3f6d4978-e2a9-4010-8fb0-aab22eeed561</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>5114cd55-3208-4a61-a23d-89cc478ec738</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>6251b1ce-74c9-4345-b104-0e90964f305f</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>7f4231df-71d8-45b2-b8ca-bc3fa98394e7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>80d4ed00-d716-4314-ac4c-a796a10a6740</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>84f68c00-46bf-47c4-b8bb-590cbc021272</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>85ff1dde-16f9-42ef-82f0-cdf8498588d5</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8cf422f8-8948-4ab5-9b89-e49d757f059a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>9813a2a9-eeb0-4b2f-ad71-761b4eb7501b</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>b5324e24-fbf8-4c52-b87e-0657bf214682</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>c4db3f3e-e366-409c-97a2-cabdb21b92ee</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>c88756eb-2d78-498e-ba06-78b3c567af1e</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>cae4c3ca-8c5e-4476-802d-ebd3ca53037c</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>d76c4e29-5484-4e9b-aacc-35b7ffa84703</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>d992a69b-8da8-4336-a5ed-f86b97d5c4ec</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e0f14aa7-f4dd-4bca-8d8a-54c6ee4bc67a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e4a6cbf1-6039-442f-9cbd-ae0db59d3a81</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e6793d5b-295a-45b7-bb7e-9434df4a07f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>ec162b63-614c-41fd-a7fc-23df99602ebd</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>f932e9e4-97c0-42b6-ac64-494da4956487</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>f97a49e6-7120-4a03-b2e9-83519a514e50</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>fde10443-bcb8-4666-8e30-adc6b9c83479</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>Vazhename_Parsi_Sereh[ebook.VeyQ.ir].pdf</name>
        <report_id>1c272671-a432-41f8-a253-839efcacf614</report_id>
        <tags>
          <value>pdf</value>
          <value>anti-vm</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>938e8233b3a10f60b1be4b4e67dcd41aaa99e88912755c43331c95c56f04be62</id>
    <title>Analysis Report for 938e8233b3a10f60b1be4b4e67dcd41aaa99e88912755c43331c95c56f04be62</title>
    <updated>2026-05-11T04:52:04Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160820f7e400110050d4d</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0160712fcb905ec28c8986</flow_id>
        <hash>938e8233b3a10f60b1be4b4e67dcd41aaa99e88912755c43331c95c56f04be62</hash>
        <iocs>
          <urls>
            <value>
              <url>https://mediagraph-oce38c6z-yy8emy12tdgsh0xy-801960-76vcr42.hotel-hamburg-koenigshof.de/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://mediagraph-oce38c6z-yy8emy12tdgsh0xy-801960-76vcr42.hotel-hamburg-koenigshof.de/pp</name>
        <report_id>10c777b0-311e-4cea-8b82-2d9e28e789bc</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>9ed3ae5ae6139c07161951548b0807d06e2881904b7505c14ad3155c127d9be5</id>
    <title>Analysis Report for 9ed3ae5ae6139c07161951548b0807d06e2881904b7505c14ad3155c127d9be5</title>
    <updated>2026-05-11T04:51:59Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01609797e8658d088c8255</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01606ddf14f1cb2acf777e</flow_id>
        <hash>9ed3ae5ae6139c07161951548b0807d06e2881904b7505c14ad3155c127d9be5</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.facebook.com/zoomvideocommunications</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.linkedin.com/company/2532259</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>http://www.twitter.com/zoom_us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>http://www.youtube.com/zoommeetings</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://blog.zoom.us/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/scripttemplates/otSDKStub.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://gov-sg.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/en/accessibility</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://sg01st-cf.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://sg01st1.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/css/all.min.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/css/vue/zoom-components.min.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/js/all.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/js/app/conference/platform-detect.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/js/lib/vue/advanced/popup-captcha/popup-captcha.min.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/zoom.ico</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://sg01st3.zoom.us/static/6.3.55949</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://st1.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://st1.zoom.us/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/chunk-vendor.BKOeBV5J.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/index.CxQ_mOac.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/zoom-ui-vue3.hc1eIu_Q.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/app.CwdHnCNX.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/chunk-vendor.CU_0GRWb.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/zoom-ui-vue3.JMjkuW1k.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.zoom.us/hc/en-us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://us01ccistatic.zoom.us/us01cci/web-sdk/chat-client.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://us01st-cf.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/webinar/register/WN_gmMrZxprSrqd-LncYyDcbw#/registration</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://www.facebook.com/zoomvideocommunications</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://www.linkedin.com/company/2532259</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://www.twitter.com/zoom_us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://www.youtube.com/zoommeetings</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://blog.zoom.us/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/consent/b0bfa2ae-4058-4aef-8632-a5281ce4464a/018e6326-8f00-73d6-80d1-f006b8eca35b/en.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/consent/b0bfa2ae-4058-4aef-8632-a5281ce4464a/b0bfa2ae-4058-4aef-8632-a5281ce4464a.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/otCenterRounded.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/otCommonStyles.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/v2/otPcCenter.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/scripttemplates/6.21.0/otBannerSdk.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cookielaw.org/scripttemplates/otSDKStub.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://explore.zoom.us/en/cookie-policy/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://explore.zoom.us/en/privacy/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://explore.zoom.us/privacy</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/assets/zm_bundle.js?async</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/assets/zm_bundle.js?cache</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/assets/zm_bundle.js?seed=AECRTBWeAQAAjFTD0V6gFnjN-Gu-iOGkvVGPYmLI6SzkSYzFGKviTVlG81IS&amp;uQHR71Sqnk--z=q</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/cdn-cgi/challenge-platform/h/g/jsd/oneshot/fe6331af5207/0.7712279383773362:1778473800:FiE_v28k8d-LlCOBWVICzp1YPNuHqdqAw4NuD-hu494/jsdapi-bgx3ev</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/cdn-cgi/challenge-platform/h/g/scripts/jsd/fe6331af5207/api.js?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/cdn-cgi/challenge-platform/h/g/scripts/jsd/fe6331af5207/main.js?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/csrf_js?t_x_zm_rid=1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/en/accessibility</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/rest/webinar/registration/WN_gmMrZxprSrqd-LncYyDcbw</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/webinar/register/WN_gmMrZxprSrqd-LncYyDcbw</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gov-sg.zoom.us/webinar/register/WN_gmMrZxprSrqd-LncYyDcbw#/registration</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/cdn-detect.png?t=1778475129</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/css/all.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/css/vue/zoom-components.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/js/all.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/js/app/conference/platform-detect.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/static/6.3.55949/js/lib/vue/advanced/popup-captcha/popup-captcha.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01st1.zoom.us/zoom.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sg01web.zoom.us/account/branding/p/9404b536-0571-4fda-b668-b89f8dafa372.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/cdn-detect.png?t=1778475129</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/chunk-vendor.BKOeBV5J.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/index.CxQ_mOac.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/register-mixin.C3dsj8gi.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/registration.BxM0I0P2.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/css/zoom-ui-vue3.hc1eIu_Q.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/app.CwdHnCNX.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/chunk-vendor.CU_0GRWb.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/i18n-en-US.C4wdIPPw.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/register-mixin.DlxriS3j.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/registration.CMZUj93B.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/submit-reg-mixin.BgyzfJ4Z.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://st1.zoom.us/fe-static/fe-webinar-register-V3/js/zoom-ui-vue3.JMjkuW1k.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://support.zoom.us/hc/en-us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://support.zoom.us/hc/en-us/articles/360059564372-In-Product-Privacy-Notifications</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://us01campaign.zoom.us/v1/live-sdk-version/fast?apikey=AM_FKF55QOG_vdWum455Vg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://us01ccistatic.zoom.us/us01cci/web-sdk/9401/cross-storage.html?lang=en-US</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://us01ccistatic.zoom.us/us01cci/web-sdk/9401/web-campaign.js?env=us01&amp;apikey=AM_FKF55QOG_vdWum455Vg&amp;lazyLoadCampaignUrl=_blank&amp;v=9401</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://us01ccistatic.zoom.us/us01cci/web-sdk/chat-client.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtm.js?id=GTM-5WKFT9</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.onetrust.com/products/cookie-consent/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://zoom.us/user/anonymous/telemetry</url>
              <origin>URL_RENDER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>blog.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.cookielaw.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>explore.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>geolocation.onetrust.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>gov-sg.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>sg01st1.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>sg01web.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>st1.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>support.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>us01campaign.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>us01ccistatic.zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.linkedin.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.onetrust.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.twitter.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.youtube.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>zoom.us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>blog.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>cdn.cookielaw.org</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>gov-sg.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>sg01st-cf.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>sg01st1.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sg01st3.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>st1.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>support.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>us01ccistatic.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>us01st-cf.zoom.us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.linkedin.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.twitter.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>170.114.52.63</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>170.114.45.1</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.84.151.3</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.91</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>163.70.128.35</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.22.12</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.84.151.31</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.32.137</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.87.42</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>170.114.46.1</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>170.114.52.114</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>170.114.52.17</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>170.114.52.2</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>192.178.183.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.87.42</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>170.114.46.6</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>170.114.52.17</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>170.114.52.63</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.87.42</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>170.114.52.17</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.84.151.3</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>170.114.45.1</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>170.114.46.6</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>52.84.151.31</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>163.70.128.35</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.22.12</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.91</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>4f498a5f4e93fbdff6b01241c9c653c59a884d5724fc4059d7eb3a7d48401efd</SHA-256>
              <SHA-1>95b14a793eec0c0e47f4e12540aaa79b342a2675</SHA-1>
              <MD5>c88d8f7679790072f8b54b42da368a7e</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>43ed5c457b799abe72e15e5ce574960937404f72402c5c15837044c1fc1a3a4a</SHA-256>
              <SHA-1>5854a82bc4373373f08e11b4ba52e373bc3ccdc7</SHA-1>
              <MD5>350f9d68221a0db19024ee40cfc3c7f8</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>a824bc7739e226e1b40ea0f8c4e4f4c6f796fc3b4abfa6e9abe3bd119a30d938</SHA-256>
              <SHA-1>0dde8fd9111d807e202b2fb37f8bcc4052fd861e</SHA-1>
              <MD5>b6c792c0f58fa3ec92173c074885221f</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>04d3f39bd1d9acb3fa419c90273a56d1ce0e9a4e4552886f580b7e79bdc869c4</SHA-256>
              <SHA-1>960cdfbbff6e025e5854dd84db9a3b41615816e8</SHA-1>
              <MD5>1c3edc859b1cd50eee8607cf9058f6b1</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>ded583ca80570c2a28c7e8091356dda49a8d981bb3d6d60969dc8f5a1146b636</SHA-256>
              <SHA-1>cb9c4d77c1240f09ac3630d14c6c19b31384d6ff</SHA-1>
              <MD5>d6ef7cfda3189546aa4543b05fe72670</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>9404b536-0571-4fda-b668-b89f8dafa372</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>b0bfa2ae-4058-4aef-8632-a5281ce4464a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>df6242b3-aef1-4156-bf8e-c5f258d9e602</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>hxxps://gov-sg.zoom.us/webinar/register/WN_gmMrZxprSrqd-LncYyDcbw#/registration</name>
        <report_id>c034af42-1b5c-4642-84e6-4fc3cb8b382c</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
          <value>txt</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>938e8233b3a10f60b1be4b4e67dcd41aaa99e88912755c43331c95c56f04be62</id>
    <title>Analysis Report for 938e8233b3a10f60b1be4b4e67dcd41aaa99e88912755c43331c95c56f04be62</title>
    <updated>2026-05-11T04:51:57Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01607c0f7e400110050d4b</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01606cdf14f1cb2acf777a</flow_id>
        <hash>938e8233b3a10f60b1be4b4e67dcd41aaa99e88912755c43331c95c56f04be62</hash>
        <iocs>
          <urls>
            <value>
              <url>https://mediagraph-oce38c6z-yy8emy12tdgsh0xy-801960-76vcr42.hotel-hamburg-koenigshof.de/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://mediagraph-oce38c6z-yy8emy12tdgsh0xy-801960-76vcr42.hotel-hamburg-koenigshof.de/pp</name>
        <report_id>4e3ff07a-e9e1-4c89-88f2-6587e983914a</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8b3f350c2e1ca4f84bc4fefbb04a0616efdac5612677ed700a1d0b1ccff067df</id>
    <title>Analysis Report for 8b3f350c2e1ca4f84bc4fefbb04a0616efdac5612677ed700a1d0b1ccff067df</title>
    <updated>2026-05-11T04:51:39Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160680f7e400110050d47</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01605b9b72a1a5304c777a</flow_id>
        <hash>8b3f350c2e1ca4f84bc4fefbb04a0616efdac5612677ed700a1d0b1ccff067df</hash>
        <iocs>
          <urls>
            <value>
              <url>https://retevivarch-u62wcpjt-8cu11wobv7spyu5b-991267-90lqs91.reimosta-la-password-verificca-ogetta.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://retevivarch-u62wcpjt-8cu11wobv7spyu5b-991267-90lqs91.reimosta-la-password-verificca-ogetta.com/pp</name>
        <report_id>7dc1d4bc-c169-4fdb-b3b8-899be93e6c70</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8b3f350c2e1ca4f84bc4fefbb04a0616efdac5612677ed700a1d0b1ccff067df</id>
    <title>Analysis Report for 8b3f350c2e1ca4f84bc4fefbb04a0616efdac5612677ed700a1d0b1ccff067df</title>
    <updated>2026-05-11T04:51:35Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a016066d6e5cdb561983723</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01605686e92bda702718fe</flow_id>
        <hash>8b3f350c2e1ca4f84bc4fefbb04a0616efdac5612677ed700a1d0b1ccff067df</hash>
        <iocs>
          <urls>
            <value>
              <url>https://retevivarch-u62wcpjt-8cu11wobv7spyu5b-991267-90lqs91.reimosta-la-password-verificca-ogetta.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://retevivarch-u62wcpjt-8cu11wobv7spyu5b-991267-90lqs91.reimosta-la-password-verificca-ogetta.com/pp</name>
        <report_id>28346de0-d4dd-46bf-8d0e-459dafea4d47</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>282c59ae085d5fc0e70c82a96ae8dc935ed77a4328fc23197e5f90b9fea024e2</id>
    <title>Analysis Report for 282c59ae085d5fc0e70c82a96ae8dc935ed77a4328fc23197e5f90b9fea024e2</title>
    <updated>2026-05-11T04:51:23Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160a8b87f27901eb5f0c5</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01604986e92bda702718f2</flow_id>
        <hash>282c59ae085d5fc0e70c82a96ae8dc935ed77a4328fc23197e5f90b9fea024e2</hash>
        <iocs>
          <urls>
            <value>
              <url>https://ajax.googleapis.com/ajax/libs/jquery/3.5.1/jquery.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://authui-development.us-east.philips-healthsuite.com/css/bootstrap.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://authui-development.us-east.philips-healthsuite.com/images/favicon.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://authui-development.us-east.philips-healthsuite.com/images/philips_shield_transparant.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://authui-development.us-east.philips-healthsuite.com/javascripts/form-validation.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://authui-development.us-east.philips-healthsuite.com/login?redirectUri=changepassword&amp;locale=en</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://authui-development.us-east.philips-healthsuite.com/stylesheets/style.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://kit.fontawesome.com/9963800b57.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://maxcdn.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://ajax.googleapis.com/ajax/libs/jquery/3.5.1/jquery.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://kit.fontawesome.com/9963800b57.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://maxcdn.bootstrapcdn.com/bootstrap/4.4.1/js/bootstrap.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://authui-development.us-east.philips-healthsuite.com/changepassword?locale=en</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>ajax.googleapis.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>cdnjs.cloudflare.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>kit.fontawesome.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>maxcdn.bootstrapcdn.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>ajax.googleapis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>authui-development.us-east.philips-healthsuite.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdnjs.cloudflare.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>kit.fontawesome.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>maxcdn.bootstrapcdn.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>104.17.25.14</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.13.95</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.40.68</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.11.207</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.24.14</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.10.207</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.40.68</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.13.95</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>3.93.104.158</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.13.95</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.25.14</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.40.68</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.11.207</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>799aeb25cc0373fdee0e1b1db7ad6c2f6a0e058dfadaa3379689f583213190bd</SHA-256>
              <SHA-1>512c7d79033e3028a9be61b540cf1a6870c896f8</SHA-1>
              <MD5>269550530cc127b6aa5a35925a7de6ce</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>78342a0905a72ce44da083dcb5d23b8ea0c16992ba2a82eece97e033d76ba3d3</SHA-256>
              <SHA-1>3dab5f6012e3e149b5a939b9cebba4a0b84dc8f5</SHA-1>
              <MD5>722969577a96ca3953e84e3d949dee81</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>a52f7aa54d7bcaafa056ee0a050262dfc5694ae28dee8b4cac3429af37ff0d66</SHA-256>
              <SHA-1>c3b977aa4b8dfb69d651e07015031d385ded964b</SHA-1>
              <MD5>70d3fda195602fe8b75e0097eed74dde</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>5aa53525abc5c5200c70b3f6588388f86076cd699284c23cda64e92c372a1548</SHA-256>
              <SHA-1>b3c116c65e6f053aaab45e5619a78ec00271a50f</SHA-1>
              <MD5>61f338f870fcd0ff46362ef109d28533</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>f7f6a5894f1d19ddad6fa392b2ece2c5e578cbf7da4ea805b6885eb6985b6e3d</SHA-256>
              <SHA-1>c8e1c8b386dc5b7a9184c763c88d19a346eb3342</SHA-1>
              <MD5>dc5e7f18c8d36ac1d3d4753a87c98d0a</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>hxxps://authui-development.us-east.philips-healthsuite.com/changepassword?locale=en</name>
        <report_id>8d2b7996-582f-42b1-9b0d-5f29ac6907d9</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>javascript</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>f1720a814cf1bb4ebbeef1c15458ced0e2f6ff56fe04de14ecef88b6b92b75d3</id>
    <title>Analysis Report for f1720a814cf1bb4ebbeef1c15458ced0e2f6ff56fe04de14ecef88b6b92b75d3</title>
    <updated>2026-05-11T04:50:50Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160380f7e400110050d3e</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0160292fcb905ec28c8930</flow_id>
        <hash>f1720a814cf1bb4ebbeef1c15458ced0e2f6ff56fe04de14ecef88b6b92b75d3</hash>
        <iocs>
          <urls>
            <value>
              <url>https://laaparchitects-kgz14ve9-s54qqry8u4jz91il-636882-89col89.hamburg-astoria.de/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://laaparchitects-kgz14ve9-s54qqry8u4jz91il-636882-89col89.hamburg-astoria.de/pp</name>
        <report_id>d0213bb9-c06c-496f-976c-742f9b56f06a</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>f1720a814cf1bb4ebbeef1c15458ced0e2f6ff56fe04de14ecef88b6b92b75d3</id>
    <title>Analysis Report for f1720a814cf1bb4ebbeef1c15458ced0e2f6ff56fe04de14ecef88b6b92b75d3</title>
    <updated>2026-05-11T04:50:46Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160350f7e400110050d3d</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01602486e92bda702718da</flow_id>
        <hash>f1720a814cf1bb4ebbeef1c15458ced0e2f6ff56fe04de14ecef88b6b92b75d3</hash>
        <iocs>
          <urls>
            <value>
              <url>https://laaparchitects-kgz14ve9-s54qqry8u4jz91il-636882-89col89.hamburg-astoria.de/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://laaparchitects-kgz14ve9-s54qqry8u4jz91il-636882-89col89.hamburg-astoria.de/pp</name>
        <report_id>e15a9050-6e5f-4dd5-aa72-9e730cc513bc</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b27a6c0ec33917fe8a1f75709a88a388eb45ae174a6afb8f9adf9dbaa8bd13df</id>
    <title>Analysis Report for b27a6c0ec33917fe8a1f75709a88a388eb45ae174a6afb8f9adf9dbaa8bd13df</title>
    <updated>2026-05-11T04:50:34Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0160290f7e400110050d39</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0160182fcb905ec28c891b</flow_id>
        <hash>b27a6c0ec33917fe8a1f75709a88a388eb45ae174a6afb8f9adf9dbaa8bd13df</hash>
        <iocs>
          <urls>
            <value>
              <url>https://officinebelletti-vaiblfwl-2gyrgc8o4bc03iey-960861-55yjc57.reimosta-la-password-verificca-ogetta.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://officinebelletti-vaiblfwl-2gyrgc8o4bc03iey-960861-55yjc57.reimosta-la-password-verificca-ogetta.com/pp</name>
        <report_id>f16c41f0-d485-4a83-9168-b06364f08561</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>10bb6af28e0d617ec380873c5ef640b5de9963c60cca5803aa8a96014b76974a</id>
    <title>Analysis Report for 10bb6af28e0d617ec380873c5ef640b5de9963c60cca5803aa8a96014b76974a</title>
    <updated>2026-05-11T04:50:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01608db87f27901eb5f0bf</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0160172fcb905ec28c8917</flow_id>
        <hash>10bb6af28e0d617ec380873c5ef640b5de9963c60cca5803aa8a96014b76974a</hash>
        <iocs>
          <urls>
            <value>
              <url>https://aka.ms/dotnet/app-launch-failed</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://aka.ms/dotnet/download</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://aka.ms/dotnet/info</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://aka.ms/dotnet/sdk-not-found</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>aka.ms</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>72.246.29.230</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.23.19</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>207.46.197.115</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>72.246.29.230</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>207.46.197.115</ip>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.23.19</ip>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>01230ccf8ca92049278289d265efcced36108c12a10ff509519bd695addc98c1</SHA-256>
              <SHA-1>5f2db3ec249ab8ccd8bfb7882180657449bf38e4</SHA-1>
              <MD5>f1fe0044e7a4f099cef120f2247f6822</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>01516d2af83e0f4190f62c4f5cc6fa843bf5663c33ac1a7b2c89a9ec45b68148</SHA-256>
              <SHA-1>8bfd24966d089e0f00f63b145583f233165d967b</SHA-1>
              <MD5>13a1b775158e5fa776c4aa70870b03c1</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>02ec9d0d4ac4854ec485dd3a21db94de4d40cfcb5ae13d6f8bff9cbcdb1d5470</SHA-256>
              <SHA-1>a0c44626be0a5e26e24ec4e3d26b70040d19e89f</SHA-1>
              <MD5>3c184c816e04d17de566e081893c5bc2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>03b53763822319b8b37ee2dc3969c921523823249828931ce53e3a293d8b9604</SHA-256>
              <SHA-1>b22369587f98070cf4c8aa697e895a1ce6b306a9</SHA-1>
              <MD5>5f833d9714bf9539b4e80901b4a9b577</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>07568821fe2cec4f7148886c7b15659800684aa1ac0c7a27ad88919084a1ba19</SHA-256>
              <SHA-1>b62c42ae57f6a7b6b210f8c3e2052025fb493c3f</SHA-1>
              <MD5>34c1e0c31385c817e2a59c7339dd3a94</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>09d8f7db5ba1ae118438287a5c1aa47ac0a4b7c1d8d488527441bbdaf6db272f</SHA-256>
              <SHA-1>85bb54dc681d7d6235924dd6c76d68bf82b5bd57</SHA-1>
              <MD5>6a0ab96ab71bb4f810225cb123ceeed3</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>0a5de43e8df8f669290756d5f95e8a6c01e3e32aa88dc67223ae7ba2e1c3ba34</SHA-256>
              <SHA-1>12931cc1f4348c16bd73ae83b62599cb619b8505</SHA-1>
              <MD5>f488f1eb7f5e35d96c08e5f4bcb54ac4</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>0f5a8b781210205ad4d31e58ffa01339273a811aa67ba385edd61c64964c92e5</SHA-256>
              <SHA-1>d59624f259384dcd87af86be2feed41df821b6c7</SHA-1>
              <MD5>e882d9489fb3244b1405240048e186c2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>130d2e0f2fb64805024912525518c93bd1ff21d02b3a2f8afff311de0ec4a4c6</SHA-256>
              <SHA-1>4c737a87ff2e0be4a3e94f3a62627ee8d3860714</SHA-1>
              <MD5>37770a229bef9badc34edbcc345d5cc8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>1319ec27d52a224b1eb79746995e14467b0188380faa98e7aca75225c2554c27</SHA-256>
              <SHA-1>39dde12fc5f7ba4ded2eee1474cb6e052156e949</SHA-1>
              <MD5>ae7293057292b5531ecffe80ef33a165</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <SHA-256>14670b9dc6e6c95806a3699b7aa70c7b6b4d8db8678b6bdff72ffb54c82f616d</SHA-256>
              <SHA-1>a6069da8b5a0041d473f62cc7837d9f9b6b06245</SHA-1>
              <MD5>d338618365c2152adbca2f12b61729de</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>1683baa453498913a82409df530f0f0499dae57118c36f52be767d7e412c1a94</SHA-256>
              <SHA-1>82f40426825defb8f40c19b4d97bc81c30decbc7</SHA-1>
              <MD5>81dd445200d9b4bf6a7a16839d27e243</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>170090611b3151973b03123f6e14cdcc9410eef396a622f9ced49ddfe52d8f35</SHA-256>
              <SHA-1>97cbd7004733334864df85a3731df35e9557bc52</SHA-1>
              <MD5>186c7a0e12b38306ff6225bbc5091d5b</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>1f92f0d0c1e9b2dc634ad2f7995ac19354ef4ab704b0a73557ba41a642997434</SHA-256>
              <SHA-1>a7aa935d79ed8eb46f1754d587ffc65ce613a47d</SHA-1>
              <MD5>66de8b942890e4add360ca771de8d620</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>206c5f4e91225686e8d4be3db31c6712cc5d2b02471fb186ceebc742c79a2ee2</SHA-256>
              <SHA-1>b0c108fbdc3731a4b7fecc57eb983518553531b4</SHA-1>
              <MD5>054b8faad1824d5b094bf2a8a0f98c56</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>27ad4ba49db37f0b6de2ae845006eed535098b4f5628c457e64bd7e33e76418b</SHA-256>
              <SHA-1>0a231a42343132e705b5a080483734f78d28f1f3</SHA-1>
              <MD5>1d3661fa53dfd7b74957a5e613c7f5fc</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>2830af340bc579a4f1a3a0de715b17f559852f9993383aa3351686af6c13b6d0</SHA-256>
              <SHA-1>6a0ef4b1b57262e86898aaee10436fb9843bb2f6</SHA-1>
              <MD5>373d56661213dce19c5292e880546827</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>2ab44457464ce3c1cfd8f986df87d6113d474b20836cbab5567b98caac040218</SHA-256>
              <SHA-1>2d3ccb5df26790ccbb1e3792f41e82474277b3cf</SHA-1>
              <MD5>990a9f8e5fe0acca5519858ed15acfb8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>31f852e24f583c543bf5287eef5a89e0b8d502fe6b11d679a856dd5fda67b651</SHA-256>
              <SHA-1>145053903664a718e85118ba5478689c4e030960</SHA-1>
              <MD5>1fe402f090b0200d26b74e695a01f2dd</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>32ed2648aad1cddcc40425c783f785f4c72c30e76255bb31afaf96f0b48e92f7</SHA-256>
              <SHA-1>5b6c41945b861815c406c232e75f851113532c67</SHA-1>
              <MD5>3ebe75f3b123253f55f580cee0466333</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>335abfb73c1a8d9bd88897c412fa9d736e7adaf6b72b70782e4f9d7c42558a4f</SHA-256>
              <SHA-1>52d80c504ce8deb0698d449f8c1332000b7f26a2</SHA-1>
              <MD5>92aa3d59c466c8213481766c0aadd8d0</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>36ce44d71fe03b6e35f3cadb1e683882931fbbd551763d02f9b034ed5b12930e</SHA-256>
              <SHA-1>4bcbc3f7f40dcc670ba795a4ade8c47be59d0898</SHA-1>
              <MD5>237120843daa97f1ae84023c15c00203</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>3a3cf1fead3238df9c7e9c2b251946a29cd6505dbc808542e1c39ce7334ab4d6</SHA-256>
              <SHA-1>1329b83933cefd1564ef0e4f4e4a2e7eccfcfb55</SHA-1>
              <MD5>fcc7d1db59864f76f3ca97ccf198a4da</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>3ef2623a73e50b830b79de01707465758990453b72763414f86ab651e6cd82fb</SHA-256>
              <SHA-1>1d9938e134786ae28a6c34e17dbe3d79b168bc91</SHA-1>
              <MD5>71c2a78520d847fd4a0d7faad4b102e1</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>46ebeb2511c275a425d4cf2ec4960e7b0ccd5eb16e231e0cd8a030472ed2820f</SHA-256>
              <SHA-1>a9e635dbbb3e3fa8c13ffdc03e1d20e23646b22a</SHA-1>
              <MD5>f8120e0233801ab37ac9c9acdb44644b</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>482df0dcd11abafc4db524c62196ab5f04c9504320e4980b688bda84b780fadd</SHA-256>
              <SHA-1>fe90206f773140cf84982ae4519873e56045734b</SHA-1>
              <MD5>5b5c20b504b532819b84d73f45c17686</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>494e7ffc04e8153d3239ec128c26f2265ce50d776a8eb4aa12e5ee22d0430a26</SHA-256>
              <SHA-1>2fb2975f387680d7ecbdb32b50eb9d6afa36e41f</SHA-1>
              <MD5>f952f7f92e51af97dbeb3a532238b432</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>495966e820de81590754c01dc5b76668755cc79935326783ebcf47e6af4ab7ff</SHA-256>
              <SHA-1>7094a95a61f85d4e40af7ed6d86980bc9490132b</SHA-1>
              <MD5>ccb4d2f5122766f26e5c6295314d7f8c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>495c2e508909ddbb96b486e9367fff88bbec02872f9aad9bf8a6a59eed06717d</SHA-256>
              <SHA-1>c79de2dbcd145fe88e8c5974fccf564cc5509c7d</SHA-1>
              <MD5>7edc492e85e3cc94d5569f2c22b798c8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>4dae2c7b4f7332de4803a9a04c9465ebc7b3f4c9e822c12d29282424af7296ca</SHA-256>
              <SHA-1>50db8f00e6908cdb6e7857c4dd41e7d231f130ad</SHA-1>
              <MD5>bb20ac724d8511b6af05b7a62535c5e9</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>4f84f4bafbeb27faf72326d5566cac715f650d9996159e5f015945a9f00ac72b</SHA-256>
              <SHA-1>f963b260ed8f9a534de4fdbe1f2dde532ed31fb4</SHA-1>
              <MD5>fdfcc3e0ec1bfe970f9cfc9bad319553</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>5156359327e98205d060aa62aec5245d5d7c5bad74bc38e0ebea4da4fc09f50a</SHA-256>
              <SHA-1>3663f31a2875c1c4e7d4334777b668f4013532ab</SHA-1>
              <MD5>6c975be35df6bc0300db68ca02e2590a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>56cb8d8b06a4bf44a36af51a944722116de86f203c3ea4e16b86b9a1293eabcc</SHA-256>
              <SHA-1>551058bc7970ca37d7b57456bfd5c67e3a054cf4</SHA-1>
              <MD5>ffd5f6904f05fa3eb7a681ca6eff5e14</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>5789e4e4b0cc081329effaa6fbb8e84ebd3c5344edccec7b02768cef4bb02db7</SHA-256>
              <SHA-1>d1923b97d661ec5e654bea564d879a98a134dad0</SHA-1>
              <MD5>d6959e7fd927ddf38f7419d034d7a25d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>5c430e7e90d0fae1ba627bcc4607eb922dcc68e51c10bc4ce69617d0e6eeb50b</SHA-256>
              <SHA-1>4f34c3e204a0467ebcc14f79a30bd9eb8f473c76</SHA-1>
              <MD5>1c5065260133bb7349fcf2d65132170a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>5d774338c22186bf594118ebf66fbbf7af346bd4495daf3de70942744fa263a0</SHA-256>
              <SHA-1>9385eab9a0cf1de3d286c64467ed65c9d0ff5d4a</SHA-1>
              <MD5>23438345fa8880b3cc8ad7cef3d3db75</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>69f284361bd638b6a24ddfc847b880d2c5eb275767ed66cffd2450fc74a47aba</SHA-256>
              <SHA-1>7b224dbddcdf20ae96c5a15f6a43e12c6bf5a8f3</SHA-1>
              <MD5>6cb9546d04fe8c0dd2dddbd5e3780ecc</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>6a464a7af1c4b806ad78f462a691be249b6201dada249559416e9b38aae39a25</SHA-256>
              <SHA-1>1b36dbaa394913c36cbfeb95e7cc7cc8946b96d2</SHA-1>
              <MD5>885fcca262567448e902dfd9f9701bfc</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>6bc98d4289c177562d88bf2274b986ea22426ecf1b009c47cf3600784091bbad</SHA-256>
              <SHA-1>cb6d0e9c25d14f77d3264ff2ee578664f22fd0dd</SHA-1>
              <MD5>f21b9a12a10f6449fe5195f8be592cee</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>6bdf046b22e9b12c64c49c4e1793c15bc1929ccd602a20f534b221d61542cefe</SHA-256>
              <SHA-1>5f9d54a4aeda0212d4b88d5dc1d4f5f15aa97f6e</SHA-1>
              <MD5>0185c816dbc03605dda5a83c03fab975</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>73f67531aaf5412fd3bafad557a08bd058c268c82ec8983df6b9722cefeec760</SHA-256>
              <SHA-1>e3b344054cfb2b85ccc612fb7c83ee3c1a09ce5a</SHA-1>
              <MD5>2351ae44ed65eb217eb60d6e5c6a7259</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>7471466d617fe68ab3b4f17e9ea65e524b3ecb1b970f138f6a81a53f2e8d100d</SHA-256>
              <SHA-1>353f0357074d642410594def083c68b85b487bf8</SHA-1>
              <MD5>0e3faeb33c57eddcdc4a4133953a45b6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>74f7c52ede7187fd66f63df08d96416a532999074684b52bcacd99d87aa17e9b</SHA-256>
              <SHA-1>5129a91935ce7603698c45eee605d2d5e72f0c00</SHA-1>
              <MD5>d257c4c839a4529dae7f4dfba5178ebb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>78c6060a10e8f82c7e105e1c39e3a3b37fb5158b4949a9dbacfc0ab1257d4172</SHA-256>
              <SHA-1>fd6951474b134ec38389deda8529961541e6fad4</SHA-1>
              <MD5>651f247046ab0873df4693aa8aac66dd</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>78fd8c02206a8c2a79a0e7b16872b54ddc799e52f71874566c7aa4cc12bdd1b7</SHA-256>
              <SHA-1>9f5170a3f52f84299151f3d0196d3eb3cad3577c</SHA-1>
              <MD5>401556566c03480e2302be8e713f3c23</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>7a66dffce2ff45ff71f09d698a26955efe24fad8e164cadc1b33c267ef11dbe0</SHA-256>
              <SHA-1>1d6e6a677c5b64900eb71c419d3e0342cdde2caa</SHA-1>
              <MD5>c55ce0202de4c047f76dfa089d6ba23c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>7de82f1f803002b5c86c93884ee1dd59ca5f43e6bf7d48d4be1c93adeb34ca22</SHA-256>
              <SHA-1>5d9de14764dd0454f5ed033b160d3e2a40793027</SHA-1>
              <MD5>ddbdb7ee2924b9cc69b04d991d52420d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>7ea179b4f0ebbad42181956e1fc51860e44f4a0172e0b2a00cbc00f90684db97</SHA-256>
              <SHA-1>8e16d97ae9552be2621c56185b50b673f968cb2c</SHA-1>
              <MD5>cdd08dafd2ce3f008e1ab0c524bfdaf6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>8a09f3d7ac16d689ae32ad2f428a0afcd558251047445cb937d7f51cf657e15e</SHA-256>
              <SHA-1>bffedea3c198e21af07a79b3d502873bd8f52ced</SHA-1>
              <MD5>d60b9593a25b017cc06cb6376718bbf3</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>8a5d607d104459e00636bf15b1d1946e86e2fe36d012445f138fde4a6c39da5f</SHA-256>
              <SHA-1>daebc65027b799a211f183b15ea8c1f827d659d7</SHA-1>
              <MD5>7dde648db356def462154549ab6a1548</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>8a9b410b4a6ede62522ffde0c2f15478cafc3ffcd8fa23d5d89f9d7aa45ce534</SHA-256>
              <SHA-1>08da2c1a19f6f338f8a317cd1465a57fa1d91687</SHA-1>
              <MD5>d915dc5a210f11b9914fac9c377ab422</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>8b671d767a49366e34f8b4c13653b6b0b1a6073e2f7a4bfdfc3240a513e19a5a</SHA-256>
              <SHA-1>75f237c3e753189250a875dd070c5c145fd2de3b</SHA-1>
              <MD5>f48ee08f77a992d22029006680bab224</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>8d963c178c5d7fa41f0eb8b4f3d9637f139f28868e653ed9157eae1d7429f31c</SHA-256>
              <SHA-1>465f6dfea4e5f47302370bda9f2d38748cc0f142</SHA-1>
              <MD5>93c345fd0e98193a1448dc72b5c40d03</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>8da5a8a6a39b54f500d4a22033d235ceb408e4bc2180ba7b1d5ef1d92df6430e</SHA-256>
              <SHA-1>87ed0da2cfca948088963d2af9630a707a1c1824</SHA-1>
              <MD5>f73fa0b41eb70a65a3c0c49fc8865ecb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>8f3af421bb5aeafd5d90730dd62db66684e031fc6fd73456bdef84f3eeece6dc</SHA-256>
              <SHA-1>a1f36d1a157e920beccf216b05dc69b54b97b382</SHA-1>
              <MD5>77ae9047cbfa4c32401095eb4070e7c7</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>90264b70bd365921ee9d1c85e024c7bf3f108c9817e2a09319c8a99ab34c4316</SHA-256>
              <SHA-1>f0b8e724a2348609ac2d8de6e4d07b39889b51d6</SHA-1>
              <MD5>c297985f957151ef7b1c6c6edf46d0e8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>93dcd4ab2bd0bf10a572fc46d6ce4d2589db601bbf416a2086e520f317c3c9a1</SHA-256>
              <SHA-1>048f8a63a85f4ebcedec1d120b933a675f9892ec</SHA-1>
              <MD5>d1ce29436f11f12f2f5f33a1893ea86c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>956a6a59588597ea57b6316492351093e2eff8f27456527b17cdc7a75dd769d3</SHA-256>
              <SHA-1>fe47f817dfc83d0b93101cea28fb41663cea1192</SHA-1>
              <MD5>44ade1197b3fbe4c2a52291b4968c006</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>96baa02c744dac687c65e37519e146b28e05f1c2d5a09b9d059044c0b67aa49b</SHA-256>
              <SHA-1>42a229b5946b1d59d8db74f8d094c7064f6fc1a0</SHA-1>
              <MD5>178bb65b8c56d7888f6bcb6f5207eb90</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>9858ed1cdf44e2b2689541cf9360b86d221ab6299f5abd118a6c60ffce6b8f21</SHA-256>
              <SHA-1>ebb5198853cac001e7a0d09035c2937b24c3ee13</SHA-1>
              <MD5>bca8bd8525dd0c06bae7b2ffe5025402</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>9a50931cd565912a3feaebe2ad5d3dd07bd48466fe855ec0af72b016ed184387</SHA-256>
              <SHA-1>c42687664f7c42751d7b097c0dff40e4b974a8f6</SHA-1>
              <MD5>23d266c3a36c316c0757c1ddda478835</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>9aedb1b62d25b0da0784fd2d7a510db13f638090492864b675cfaa2f13f211df</SHA-256>
              <SHA-1>a486a9080089dde5d810178986b835a4842f7839</SHA-1>
              <MD5>620fc51f2a7c8b7e7af6bbc9daf8a06c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>a2704e23601adb3e513697c4744698ff0e00aa44e898c465bcb9f1790ba67952</SHA-256>
              <SHA-1>60086dfee15e2aa8c3262b735b71ad0fedd1eaa6</SHA-1>
              <MD5>476068db285960b7e48200aad5e0782f</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>a83dce99bde30a12d20000d69a2c5721fbae07a932c8914ebc9aef80acbd8ce6</SHA-256>
              <SHA-1>ae42c70e7dcedbff48124d30db7d59e398b2477c</SHA-1>
              <MD5>1c0ec791ed6f6f2812d96f53ef94d531</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>a8f9948bfd5cbc2088f01bec21fac0db1aad84b4fe9a017212a860a5dcf49583</SHA-256>
              <SHA-1>806a6a71bfd68e91f9d86fbbc14a4db264d482c0</SHA-1>
              <MD5>2dee4fa69586e1f14725ff68628318dd</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>af0afc5d4fb77dbfb396cf8ca56118b04d506db03cba15a9b3304127d71261ca</SHA-256>
              <SHA-1>18bd6b02876cb1f99f48e5962c1fdc5ec48e6186</SHA-1>
              <MD5>60a32281b8e9579e8cec3b73757f5639</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>afa1d9c709eba4f5e7fb86f4afe859831bab4522d9658f9395a379313b267cd9</SHA-256>
              <SHA-1>cc1262d5099f68df103a3bcbedc76e956317c4bd</SHA-1>
              <MD5>dd58004febfab32ac86b276cd1fac03f</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>b068bd26c7427287161846dcb2e87609ab185962114f75def725499976ba6ca9</SHA-256>
              <SHA-1>99ad2648ca14dba10c97b4b7b657ad77aa8f5f81</SHA-1>
              <MD5>56639cecc56ea658fd84a719d0837876</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>b09399245643597f228b58b186273370df06ed3b08d0e84998e13e6c4f28a5ca</SHA-256>
              <SHA-1>20bf86198a5f6304ca0561983b16295c520503ea</SHA-1>
              <MD5>aa87707b6763f8461b09f3dd94961a8f</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>b0ea4a4a561ad5084a1c32b5ed60c7756db9bed4fecc8d113899d3ba0b4b2ff2</SHA-256>
              <SHA-1>1c7a2bc37b18560df9c1ccf603183e2a9cb9b190</SHA-1>
              <MD5>6eb24b0f68ebbb91abba7c6a48f8de79</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>b43a994f00edc7ef325446f8f545cecb00b4f24ecf05e78867aefda0405fc3eb</SHA-256>
              <SHA-1>138678dd6ce88c26ad65b588931b12fcb185e070</SHA-1>
              <MD5>f6928bd7fe7390cc0920b4232d4964b6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>b81aa9348496254f4252120fb332349398b066a4b98464eb012c1735592e580b</SHA-256>
              <SHA-1>fd1f2689c02b8634f20d37411647ecc1f088fe77</SHA-1>
              <MD5>6b6aa60b68fcdda485fd4502de848832</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <SHA-256>b87bb77bbe3e2a417e2456202d9b0a3f1c6a50750d7fbd1bdd498e2bd6e48206</SHA-256>
              <SHA-1>e293f594a89e10d7adab9d876b09c2eea796d9be</SHA-1>
              <MD5>2eab58b42f697cba3710d6430eabc6ea</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>bb3d5247cd89b3c0b9a77043257f217f68aee31d5923e75c3594b7dc702f5062</SHA-256>
              <SHA-1>8c284a773c66e4fd5e68294b5560e1a9da25221e</SHA-1>
              <MD5>355e80ea10278de2169e6d50e5133433</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>bbda4f4e7698b4b84a966a3d703a686f2fefcf017f286d0e092331bc9c2736d8</SHA-256>
              <SHA-1>f2143015939fc0bb2ed97c9d41e9d6f765094c6f</SHA-1>
              <MD5>27906b46d9eee8d3980997a1c6b2570b</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>be5704d8cc1d961c6ca057846d5fa629709e608d0779bab16674b9dd78c5daa0</SHA-256>
              <SHA-1>5afcc01c4c6b104b42cab80b7fe7820fa611c66f</SHA-1>
              <MD5>64524c60e7083405363dcb6950a3aaf1</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>bfe6045cd067a1a02b9dcffeff001c7ee7e3368682c254ffdba613f21dc7dbfe</SHA-256>
              <SHA-1>8142c8d1376832517d6b9c928476275d7e150306</SHA-1>
              <MD5>a4fa7846e4da44f1abae4de6a0a90d73</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>c43e7a29ecadd0c40b92abc3f8b51557c38062768ba432833a45918d1ee01152</SHA-256>
              <SHA-1>042aa6b345f348cc62dbef9b4ab3e76af9f5f8b3</SHA-1>
              <MD5>c49538244cf669126ce830faa3ec5645</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>c48b0d507f7196a0c862cbecd11f56ece5b17a9a28d86a83b6f42a97dd9cbd61</SHA-256>
              <SHA-1>fcacf642bea1f45ad19b7bc0f37fafe11286776e</SHA-1>
              <MD5>a6291c113061f6cae722fcb2423b23e4</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>c6d9f9923e15ecb144dfc239cd11ab981bd1368fb73482d45736a93d98693f39</SHA-256>
              <SHA-1>440c67dfe0b569ecd8d3ebbe9451f169a2543fc0</SHA-1>
              <MD5>ee7214c82707df5cb416338346094506</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>c76903cde8580d1c809ac5352aab33af5a310ad05126294d66e06db880c463ed</SHA-256>
              <SHA-1>79366e0c7d2cffd92706b3a3dec0f8bc44f04667</SHA-1>
              <MD5>8a77e487095b9fc40c2ed1dfbb422892</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>c809e5d27a143e9e595c186c35305478e7a236f7404f75486a83b6e7e1feb4a3</SHA-256>
              <SHA-1>55b645051746e7097c06d643c84389fdc58a7f8d</SHA-1>
              <MD5>919e134369935f8a7c32033714d5483a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>ccdafebe47f3cba56a8e05bb009c20a7eaafa6e8a15464dc25f065e8effb05c0</SHA-256>
              <SHA-1>e5b3eb8d194d6e8e287856bfbeabe83b82ade06f</SHA-1>
              <MD5>1a9f7f75f5b45a87cbce74c10deb35e2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>ce365cee5827a6e3a6d46dacf6f1090b60a46a92b7e321b88190ad99a362be51</SHA-256>
              <SHA-1>ca44253ca5dff3adcb4cec72d245b8d11e977f1f</SHA-1>
              <MD5>3a21133aa9c6037425ce9a9cba77408a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>ce5f5f121c08bf33313459e8fcd9fcc3115bbc87fb5a5bda3d747f2cebe20d1f</SHA-256>
              <SHA-1>30bec398bce74eaf6835145a6643fda28bf330e7</SHA-1>
              <MD5>8955eb375d0e239fd1dfb0bd8e542a19</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>d2b2788e09b304fc5ed786dfc1f49a6bff3f77b67509c51a22bfeed36d7bfdfe</SHA-256>
              <SHA-1>82deb81516f9fcc9f94dafe1557428e44bc53247</SHA-1>
              <MD5>3d6781d14fcc98cbc341f0849d9b79c1</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>d2fe03fe0bd520eba279943785b8407170554db28dd1913ee2d8c406693fc360</SHA-256>
              <SHA-1>5e473b5fde599b126c131ca3fe9bdce2963fde7a</SHA-1>
              <MD5>8a8cbbd1c1492c2fd8459e8445d8e522</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>d3b756dc66f5daac47cf3f6bdba4b21ea74f252e52dc2e22fa562878d3d698c8</SHA-256>
              <SHA-1>ce25d978b251c87a140413bea5334f745a317ddd</SHA-1>
              <MD5>4e14cea98cd1c9285472100fcf255ed5</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>d4431c9df702a27bbf779cc4046b838515e360942f8395387d93b55df53fb076</SHA-256>
              <SHA-1>bff5b8a4612f387352f1bc457363b60e51fc427a</SHA-1>
              <MD5>de1fb0ba27dd2ee3d67f53e1a92ad669</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>d94742dd12ae00da332846f2023a09e253a875a6eb0c8de8e7d2da9e9a144ffa</SHA-256>
              <SHA-1>032593b31adf97a5f80cbbba985774790b97a96e</SHA-1>
              <MD5>a56b21ca8b71a510d0a00def028e538b</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>dcd24266f9a61d0a85b33e451f250ca5ed083d22082dc8fd9c0f874449cf848b</SHA-256>
              <SHA-1>6dc54c39c2bb7e9c92aad2e43e004ecff6ad496c</SHA-1>
              <MD5>4f3d6c52e371fe55c37afa7552faab7c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>dd60f2aa080c2638ae14e9db2c093132ac102a478ba1afad81ea9700c8af10c5</SHA-256>
              <SHA-1>b50c423f57e01bed081ea2a96fb2632c7e915de9</SHA-1>
              <MD5>78318c0e48cb76f9b392a6e38bfd6fe8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>ddcb463fcf8b6517faeac232038b210d5ddc123aa8a7106c8fbef43c7dca1fd9</SHA-256>
              <SHA-1>5ba6b3e6848dd6ff865a279a2e56105b3d28ff04</SHA-1>
              <MD5>9abd280e6ed054d52e3dbfdc7ca313a6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>de73345c51ae20b3136107915b4152c790ad09c8846c1b95903a35cb5c54ff8e</SHA-256>
              <SHA-1>d265b1386d1b8d5e15f5a0cd44e6049f218b026f</SHA-1>
              <MD5>38fcf8a94f567b9779e9f8fb30c1b1ba</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>de816246bb04ba3dc53fcc411063bc737e545acf654d5a9f6c8c5af2b3b8bdf5</SHA-256>
              <SHA-1>46190381c25e75e0562abb563adc0285d9eb1840</SHA-1>
              <MD5>5278110a1172acf1cd70cf99a0c13eb8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>e21f4b75478af2ab586b9a9e82e99d894c5a5e903f92120f153b47d14fb2e711</SHA-256>
              <SHA-1>e77f8e09e512e360cc5c485d9b4e994cf3a35dfa</SHA-1>
              <MD5>f061babf2cb43dc7b3c2db4fde72699e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e6463abdf4b187230e2aee1ed172d470b771466dd2c379227d42e254c924b0d1</SHA-256>
              <SHA-1>4333f6d9567cfe06b6f68700e48837f6c62d1b73</SHA-1>
              <MD5>e8d684d147cfc9e14b9b06430e4006b0</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e65529c9b6a29355c9999cfbc774f6ea32ac67bda1f06ab6e6660d2cf111cddd</SHA-256>
              <SHA-1>8da0db0c571b1dfb62c3d775ef6ce318e1784a88</SHA-1>
              <MD5>16d66ddeb7b950010ec08657b63e5dba</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>ede1093a1f3bf4dd3815bd9a9c59001b73bc40c310bac7a6a78f3a0d4fe80a4c</SHA-256>
              <SHA-1>afb3830ced336a9876b9528d0282c9404f1d32f9</SHA-1>
              <MD5>89ecbe1ef064b0098e974e2c4f414786</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>f0261f55aa32683f28f14f15a1a8ffba0221cbdebdc5d0214b425b32753ae3d9</SHA-256>
              <SHA-1>41025e97e3a03f6f7126df7112141db150fd91c5</SHA-1>
              <MD5>b615770d32476a72061400f45fef1654</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>f659c47ffff3f8eeae21d64b1f87a2a4627839c98763493d2c5d5ba23030d391</SHA-256>
              <SHA-1>b9fc642e752d4b04211fb62888deab2eb90a2248</SHA-1>
              <MD5>2e88b030995f2a186cb598130db1457a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>f70e1b845349b22590d18b5c65e6b516c2dc1c46cd1017aa3a131aba6ebad33a</SHA-256>
              <SHA-1>1560d26c3560f0d5ed94687e01182196badb4da4</SHA-1>
              <MD5>04aa7d538eea32a24de12cdb70ce0d34</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>f72a153ef18c6e9acd323089d29f580e6989744443cecc46e021551f4f35488c</SHA-256>
              <SHA-1>e9598959aa4b08f945939c95d1341fe8a048c3f8</SHA-1>
              <MD5>0d65a6d5d00f11319dfeeeef432ad5da</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>faaf30b0b81efa5734163797ebb7cd6bdc8790ae7bb119fdf62bd0ea0621501c</SHA-256>
              <SHA-1>68ba49b0500ca06b55a8967eb9ff403a126b2e95</SHA-1>
              <MD5>172e251479043bdc371c0471d36811ac</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>fda3d5ff7574ae6fc1165259f8946730239b12462e12f76ab29e5abe939a70f2</SHA-256>
              <SHA-1>84690a593daf833c2b1cb048a6a6562df19b87d9</SHA-1>
              <MD5>ef43a983d6c356d965c1775667873543</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>f73605dc5831a57028066e47c3dd7fd8d8efec9ffb8b97aa9bdc4f88ee986c6d</SHA-256>
              <SHA-1>26a02aafe62b890380f22e87efb97b57bbaca6e6</SHA-1>
              <MD5>fa0280061b0c853c8eb0d38cc400bb32</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>0a878ddda468ac917756f1cf47c9fe1189e7f4d228a2b7220ca2e1a5cead95fb</SHA-256>
              <SHA-1>6008bbe3fbbb3e01cc1bf1b9cf780075020120cc</SHA-1>
              <MD5>4c833ae93b32f1e1eb1bb4055cd27dbf</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>390785d5726624ed4b22dd7cbb0b087fb690f48b404a4b4d4275e1bf60efb481</SHA-256>
              <SHA-1>18ed8ccd2900f8ef2014083dded6bacb62dc18c5</SHA-1>
              <MD5>24dcf8a02633d33c58c36351c25beb03</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>6bffb0d878e85a512aabd25355d8dea0d5028dcdcb87219eba75bcac7c74cbfa</SHA-256>
              <SHA-1>20dda195cc1f05a428e01153a6914076c93b9924</SHA-1>
              <MD5>0203f7ea026456d79b3a927d1a1ac32b</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>21992a2e3e7825a9d6dedd65d74a2ff7c2e3eb537c82e3e32342189428413637</SHA-256>
              <SHA-1>d35580399a6664205387bfce1c69286b3d983991</SHA-1>
              <MD5>e1059f0307358c02766193e5e24c107b</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>1dc18830097a96a4b30f370e06598335fee0b24bcde1fb26049d99da1d134b43</SHA-256>
              <SHA-1>9764b4d3f560854c1f7d7c9e53600380f1e6e67f</SHA-1>
              <MD5>c7b99acecbda1bebab35340c9e84e7ce</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
          <btc_wallets>
            <value>
              <btc_wallet>x219fd69:$btc: 15V11H13V15H11V9H15V7H11M</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21a49b4:$btc: 15V7H9V15H11V8H13V15H15V7H17V15A</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21a4ac0:$btc: 15V7H15V15H13V8H11V15H9V7H7V15A</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21a4bbf:$btc: 15V7H9V15H11V8H13V15H15V7H17V15A</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21a4d03:$btc: 15V7H15V15H13V8H11V15H9V7H7V15A</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21a4df8:$btc: 15V7H9V15H11V8H13V15H15V7H17V15A</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21b9aa8:$btc: 18H11V15H2V13H22V15H13V18H16L1</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21b9b6f:$btc: 16V13H15V22H13V2H15V11H18V8L2</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x21b9b9e:$btc: 16V13H9V22H11V2H9V11H6V8L</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x2209706:$btc: 14V17H4V14H2V22H4V19H9V22L1</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>Ryujinx.exe</name>
        <report_id>34b726c6-3762-4659-82c5-30cbbfab9a65</report_id>
        <tags>
          <value>peexe</value>
          <value>xml</value>
          <value>html</value>
          <value>anti-vm</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>dotnet</value>
          <value>fingerprint</value>
          <value>lolbin</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
          <value>net</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b27a6c0ec33917fe8a1f75709a88a388eb45ae174a6afb8f9adf9dbaa8bd13df</id>
    <title>Analysis Report for b27a6c0ec33917fe8a1f75709a88a388eb45ae174a6afb8f9adf9dbaa8bd13df</title>
    <updated>2026-05-11T04:50:29Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a016023d6e5cdb561983716</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0160132fcb905ec28c8910</flow_id>
        <hash>b27a6c0ec33917fe8a1f75709a88a388eb45ae174a6afb8f9adf9dbaa8bd13df</hash>
        <iocs>
          <urls>
            <value>
              <url>https://officinebelletti-vaiblfwl-2gyrgc8o4bc03iey-960861-55yjc57.reimosta-la-password-verificca-ogetta.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://officinebelletti-vaiblfwl-2gyrgc8o4bc03iey-960861-55yjc57.reimosta-la-password-verificca-ogetta.com/pp</name>
        <report_id>40d5b647-644a-46fa-a4a3-b62d531e654b</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>577d343361543c69ae2fc4ace3c9526f8d639eadc548b92260b2b5269c4f0258</id>
    <title>Analysis Report for 577d343361543c69ae2fc4ace3c9526f8d639eadc548b92260b2b5269c4f0258</title>
    <updated>2026-05-11T04:49:48Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015ffa0f7e400110050d30</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015feadf14f1cb2acf7725</flow_id>
        <hash>577d343361543c69ae2fc4ace3c9526f8d639eadc548b92260b2b5269c4f0258</hash>
        <iocs>
          <urls>
            <value>
              <url>https://invio-certificato-hp0a987l-mv9ejptyvvsfpk8e-075229-31qdo40.ogetto-verifica-richiesta-password.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://invio-certificato-hp0a987l-mv9ejptyvvsfpk8e-075229-31qdo40.ogetto-verifica-richiesta-password.com/pp</name>
        <report_id>de42e405-ecca-4e76-a3a8-4c7e69dc2f99</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>577d343361543c69ae2fc4ace3c9526f8d639eadc548b92260b2b5269c4f0258</id>
    <title>Analysis Report for 577d343361543c69ae2fc4ace3c9526f8d639eadc548b92260b2b5269c4f0258</title>
    <updated>2026-05-11T04:49:41Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015ff40f7e400110050d2e</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015fe586e92bda7027189b</flow_id>
        <hash>577d343361543c69ae2fc4ace3c9526f8d639eadc548b92260b2b5269c4f0258</hash>
        <iocs>
          <urls>
            <value>
              <url>https://invio-certificato-hp0a987l-mv9ejptyvvsfpk8e-075229-31qdo40.ogetto-verifica-richiesta-password.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://invio-certificato-hp0a987l-mv9ejptyvvsfpk8e-075229-31qdo40.ogetto-verifica-richiesta-password.com/pp</name>
        <report_id>797d4c0d-5dee-4794-88e6-2b63b500e5fc</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>20558f18c55b6b5aa4bae7bc0c8b228704f5242f6e92ecf1e8d4d34bde3512cf</id>
    <title>Analysis Report for 20558f18c55b6b5aa4bae7bc0c8b228704f5242f6e92ecf1e8d4d34bde3512cf</title>
    <updated>2026-05-11T04:49:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015fea0f7e400110050d2b</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015fd9df14f1cb2acf7718</flow_id>
        <hash>20558f18c55b6b5aa4bae7bc0c8b228704f5242f6e92ecf1e8d4d34bde3512cf</hash>
        <iocs>
          <urls>
            <value>
              <url>https://responsabile-zrj3fnsz-6b8quax875kxglcw-369399-25fea13.ogetto-verifica-richiesta-password.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://responsabile-zrj3fnsz-6b8quax875kxglcw-369399-25fea13.ogetto-verifica-richiesta-password.com/pp</name>
        <report_id>1e3a0bd7-a256-45e4-9acb-0f38d5a3657e</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>20558f18c55b6b5aa4bae7bc0c8b228704f5242f6e92ecf1e8d4d34bde3512cf</id>
    <title>Analysis Report for 20558f18c55b6b5aa4bae7bc0c8b228704f5242f6e92ecf1e8d4d34bde3512cf</title>
    <updated>2026-05-11T04:49:26Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015fe30f7e400110050d29</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015fd486e92bda70271891</flow_id>
        <hash>20558f18c55b6b5aa4bae7bc0c8b228704f5242f6e92ecf1e8d4d34bde3512cf</hash>
        <iocs>
          <urls>
            <value>
              <url>https://responsabile-zrj3fnsz-6b8quax875kxglcw-369399-25fea13.ogetto-verifica-richiesta-password.com/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://responsabile-zrj3fnsz-6b8quax875kxglcw-369399-25fea13.ogetto-verifica-richiesta-password.com/pp</name>
        <report_id>f45d95fd-bf8c-43af-abcb-b470f0275997</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>dd436d0566ea3790576cb013b63f05457ff09521c84fe5597f5802981fb64a8e</id>
    <title>Analysis Report for dd436d0566ea3790576cb013b63f05457ff09521c84fe5597f5802981fb64a8e</title>
    <updated>2026-05-11T04:49:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015fd00f7e400110050d24</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015fc37d31ad7bba4fe696</flow_id>
        <hash>dd436d0566ea3790576cb013b63f05457ff09521c84fe5597f5802981fb64a8e</hash>
        <iocs>
          <urls>
            <value>
              <url>https://jtd-gwe7m8ks-je8pb9bie9erofeb-519487-56avv13.hotel-hamburg-koenigshof.de/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://jtd-gwe7m8ks-je8pb9bie9erofeb-519487-56avv13.hotel-hamburg-koenigshof.de/pp</name>
        <report_id>220e447d-84b2-424c-bce3-763db2779f3c</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>9740278c9d2fd279c45b85473b01483e54ba4f592a329a54d5b80a747bb5038d</id>
    <title>Analysis Report for 9740278c9d2fd279c45b85473b01483e54ba4f592a329a54d5b80a747bb5038d</title>
    <updated>2026-05-11T04:49:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015fe5b87f27901eb5f0a0</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015fc12fcb905ec28c88b5</flow_id>
        <hash>9740278c9d2fd279c45b85473b01483e54ba4f592a329a54d5b80a747bb5038d</hash>
        <iocs>
          <urls>
            <value>
              <url>https://snapany.com/es/ok-ru</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://api.snapany.com/customer/contact</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://api.snapany.com/desktop/info</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://chromewebstore.google.com/detail/gcoecfgebkokdbahlhodbkmbmdkdcibj</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.gg/dbKP6FKfvx</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://files.feeprint.com/snapany/desktop/SnapAny-1.1.5-installer.exe</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://microsoftedge.microsoft.com/addons/detail/ekofkmacnfchhjplbkdehdkecjoplckc</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect?v=2&amp;tid=G-8BFPWBG3X1&amp;gtm=45je6570h2v9180264425za200zd9180264425&amp;_p=1778474952755&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;dma_cps=a&amp;dma=1&amp;are=1&amp;cid=441801759.1778474953&amp;frm=0&amp;pscdl=noapi&amp;rcb=9&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;_s=1&amp;tag_exp=0~115616985~115938466~115938468~118463262&amp;sid=1778474952&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fsnapany.com%2Fes%2Fok-ru&amp;dt=Descargador%20de%20videos%20de%20OK.ru%20%E2%80%93%20Guardar%20videos%20sociales%20de%20Odnoklassniki&amp;en=page_view&amp;_fv=1&amp;_nsi=1&amp;_ss=1&amp;_ee=1&amp;tfd=398</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/image?url=%2Fimages%2Fextension-use.png&amp;w=640&amp;q=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/image?url=%2Fimages%2Fsnapany-desktop-v1.png&amp;w=640&amp;q=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/1482-2337f89790e46107.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/1576-28b37254ebf5ac06.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/222-9204abf272a1bba9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/25caf76a-23c4b79d0a92c804.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/2922-e830ee10136b2e88.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/464-d1df7e375c43b0bf.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/47859e56-ac5cd355eca09c15.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/4831-3819ee1fd0b42b20.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/5629-37aa020ebfea5c8d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/5725-6b0539fc2abc1bea.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/5763-8ff2adf646482326.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/5bce41f4-3c5127f6ebad4f9c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/604ae3ac-c6ff5f376ddc6aa8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/6088-7df5c9a98db9c1be.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/6632-60f05ea7edd3cd82.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/687-571a478b00549294.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/6893-dfae68c704355de2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/69543acc-8cebb0c59f44401b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/7273-4f1040495fe012ae.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/7327-1bb16983feb65392.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/7564-5da1fa982f851440.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/8228-c573efd13cbe147f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/8605-773ef0207fb300f9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/8744-98c1053124141869.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/899-690a068844df71f7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/8d80975d-2c2b1fdac9b33b4b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/9632-4b206160ceef291f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/981-1497137f0f5bb838.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/app/%5Blocale%5D/(main)/%5Bsite%5D/page-24e686f36fd842fa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/app/%5Blocale%5D/(main)/error-b41c19ce73c0e3f2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/app/%5Blocale%5D/(main)/layout-17d2d2c6015ecd47.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/app/%5Blocale%5D/layout-11ea57a57fe03d43.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/app/global-error-67979ff7a6138fad.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/app/layout-3c05900b2c17372a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/b59c0c5a-a63a39198a336ac2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/b9fcb08a-86af0e2c75ba3caa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/bd84db0a-3768b3e44b72bd4e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/fa0d9156-8b440bbd86606627.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/main-app-3a1d833cdd876ec1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/chunks/webpack-1df91f25721d5caa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/_next/static/css/e4102b793af90582.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/es/ok-ru</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://snapany.com/images/hero-pattern.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://sssora.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://t.me/snapany_app</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-8BFPWBG3X1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>mailto:support@snapany.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>OK.ru</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://snapany.com/es/ok-ru&amp;dt=Descargador</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://chromewebstore.google.com/detail/gcoecfgebkokdbahlhodbkmbmdkdcibj</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discord.gg/dbKP6FKfvx</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://microsoftedge.microsoft.com/addons/detail/ekofkmacnfchhjplbkdehdkecjoplckc</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://snapany.com/de/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/es/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/fr/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/it/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/ja/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/ko/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/pt/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/ru/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/zh-Hant/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://snapany.com/zh/ok-ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://sssora.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://t.me/snapany_app</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-8BFPWBG3X1</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>chromewebstore.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>discord.gg</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>microsoftedge.microsoft.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>snapany.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>sssora.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>t.me</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>api.snapany.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>chromewebstore.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>discord.gg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>files.feeprint.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>microsoftedge.microsoft.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>region1.google-analytics.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>snapany.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>sssora.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>t.me</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>support@snapany.com</email>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <email>upport@snapany.com</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>104.21.87.28</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>99.84.152.44</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.107.6.203</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>216.239.34.36</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>99.84.152.79</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>162.159.136.234</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.97</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.139</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>149.154.167.99</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.139</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.136.234</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.107.6.203</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>99.84.152.44</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.21.87.28</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>149.154.167.99</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.97</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>8b02ae4cef2fe908568ecd09bc987b4184e4ca4e397c0f21b7f097076e44b2fd</SHA-256>
              <SHA-1>9ae563773862510ef8ec2fb7ff10ed8ed7566099</SHA-1>
              <MD5>961fbe01d53c49e6559aef85d099df51</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xhtml+xml</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>e11b73cd580f81533fdd8818f98c06379b5a6e2bb316ad1f7d99e8b977e01bb3</SHA-256>
              <SHA-1>07ec094666025e08765fa41903243a3549bbb449</SHA-1>
              <MD5>f98da09bc5c2371b2978aeb100022cfa</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>d441f77bb769835bd30569b671b13af800fd1b1ca738afeb44b33fa4cbf12095</SHA-256>
              <SHA-1>c90c7a6fe8aa5966f0f69fc0110557c13a5da5b5</SHA-1>
              <MD5>a54d634b29c74beca3fb0e356500a7c9</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>95c9f56df83e44d663b71a7e4bc5497db4cf8f5835177885bfc248a1ef364818</SHA-256>
              <SHA-1>a9b44182e31624290c18c7372d57fddddd84837e</SHA-1>
              <MD5>ca5f76b3d76941a9d2a347a86cbf0473</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>a9a5a111eeee05afbcdc1cec606b9405d30b981539ecfd43d1c9926b8fddb484</SHA-256>
              <SHA-1>437b1fc14477691521c5906ad09dd879c51fa69f</SHA-1>
              <MD5>b26ee6c806a4bcefff0a66d9666168f3</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>6ce8f057d13d049702a6eb067f7f038b7e42781d9b205418da49c87b90932f60</SHA-256>
              <SHA-1>96b0161b722d34e18ba1cc26b331386a1ca23a0c</SHA-1>
              <MD5>a144a7890fadd41a3b678aa23269a1e0</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>85c228aae203469e488b3162523f2e215fef046f4b87c7660eac76b1ad4d8da0</SHA-256>
              <SHA-1>20a9b8628cee67aedf87e1e2c4e4de79071851d6</SHA-1>
              <MD5>978dd81eb99273b0020afad239b34ea8</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>623e73caa13b96e16e7669ff43f9640f9529d399b0f4e740b3877b0a29c7abec</SHA-256>
              <SHA-1>351267d04143048435c1c9bfde8deb5c00956915</SHA-1>
              <MD5>3daf3750744275386aaf20a0d116f8d1</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>4cce3551d90bcbe8d1b28dc1632faf48d0d44a659d3aed04a949c129a8885681</SHA-256>
              <SHA-1>7ee4c3eafbc984f95f603c8fa765373f2e5eae53</SHA-1>
              <MD5>5ab099826c71b5e7731e766c812833db</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <SHA-256>994832d862d663aa315e5429cc640583e120929dd30511faa45be9a493dbd5fa</SHA-256>
              <SHA-1>d3c7c6ae66123af42230b010bb39bf5250567d82</SHA-1>
              <MD5>9e25571140cb94243b8dc53a122451f9</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>hxxps://snapany.com/es/ok-ru</name>
        <report_id>c6035124-204a-42e7-a971-815fc56afa36</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>dd436d0566ea3790576cb013b63f05457ff09521c84fe5597f5802981fb64a8e</id>
    <title>Analysis Report for dd436d0566ea3790576cb013b63f05457ff09521c84fe5597f5802981fb64a8e</title>
    <updated>2026-05-11T04:49:04Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015fced6e5cdb561983706</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015fbe2fcb905ec28c88b0</flow_id>
        <hash>dd436d0566ea3790576cb013b63f05457ff09521c84fe5597f5802981fb64a8e</hash>
        <iocs>
          <urls>
            <value>
              <url>https://jtd-gwe7m8ks-je8pb9bie9erofeb-519487-56avv13.hotel-hamburg-koenigshof.de/pp</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <btc_wallets>
            <value>
              <btc_wallet>x6332:$btc: 34hM3Nwz17921ByUQt1a1UCDsUq</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x8d10:$btc: 1SodL43XmP6w66xpZM2N63zQtevNv</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>hxxps://jtd-gwe7m8ks-je8pb9bie9erofeb-519487-56avv13.hotel-hamburg-koenigshof.de/pp</name>
        <report_id>dd98e5cc-2751-4758-a880-3faf78eb8e25</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>f7290000ea62b9c588cb0163bf93ce951ee558afdf2f038f2a4d67c2522f74e7</id>
    <title>Analysis Report for f7290000ea62b9c588cb0163bf93ce951ee558afdf2f038f2a4d67c2522f74e7</title>
    <updated>2026-05-11T04:46:21Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015f2bb87f27901eb5f07e</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a015f1a2fcb905ec28c8787</flow_id>
        <hash>f7290000ea62b9c588cb0163bf93ce951ee558afdf2f038f2a4d67c2522f74e7</hash>
        <iocs>
          <ips>
            <value>
              <ip>127.0.0.1</ip>
              <origin>INPUT_FILE</origin>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df</SHA-256>
              <SHA-1>4260284ce14278c397aaf6f389c1609b0ab0ce51</SHA-1>
              <MD5>1e4a89b11eae0fcf8bb5fdd5ec3b6f61</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
          </files>
        </iocs>
        <name>client.exe</name>
        <report_id>0cbd2345-211e-42b6-8bb3-e682427105b7</report_id>
        <tags>
          <value>peexe</value>
          <value>adaptive-context</value>
          <value>anti-debug</value>
          <value>cmd</value>
          <value>lolbin</value>
          <value>crypto</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>865b53a17ff436fda09bce606a144648123f818a8865b81e187729de59a055aa</id>
    <title>Analysis Report for 865b53a17ff436fda09bce606a144648123f818a8865b81e187729de59a055aa</title>
    <updated>2026-05-11T04:43:25Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015e8097e8658d088c81f6</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a015e6a2fcb905ec28c86cc</flow_id>
        <hash>865b53a17ff436fda09bce606a144648123f818a8865b81e187729de59a055aa</hash>
        <iocs>
          <urls>
            <value>
              <url>http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://schemas.microsoft.com/SMI/2016/WindowsSettings</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.microsoft.com/pkiops/Docs/Repository.htm0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.microsoft.com/pkiops/certs/Microsoft%20Time-Stamp%20PCA%202010(1).crt0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%200a</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl0l</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://www.microsoft.com/windows0</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>crl.microsoft.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>microsoft.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>schemas.microsoft.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>23.55.110.193</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.55.110.193</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>10f86daa4593b7da6a08cde629aff7aaa3f89730a83823c72156faf30c467e51</SHA-256>
              <SHA-1>3842ca3e23411cf2e41d087032da34b08aedd92e</SHA-1>
              <MD5>c44630e19fb8909907254abb18f25349</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>141abd920876e2566f0b9e0d99ba3edc6b96af591a1a89cbe31ddff8133f65dc</SHA-256>
              <SHA-1>3fa63d6d93626682df7e35bc796cda26fe8ddd9b</SHA-1>
              <MD5>b66cf9b71ffb4447da9de2473f7dbaed</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>40016d17f02bb7187a7ad838405a7b37881a1290846befbc441c390b817aaffe</SHA-256>
              <SHA-1>74e23592a4844ed47d994cd3ddb3aeeb2304e804</SHA-1>
              <MD5>edbc83f341080e7ff894afd116ffa9f3</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>8d5c3dc4a02696f38d9208220773b5f99a32910fb305cf52c7e11b29c29e85ed</SHA-256>
              <SHA-1>62f326261e379b77fd5c2bdc0cf3fa00587abc3f</SHA-1>
              <MD5>db5e3ca3adc68bc1a7d062f26ba69c28</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>8e70c313e081d79c7594e16d9f4a29b1fe3a3d045fe56e278079a841b0b3fa6a</SHA-256>
              <SHA-1>a7691c7946378789cc0ba0702208dc46e6e1d3b6</SHA-1>
              <MD5>a9b0147fb3e4abf8eea35debc7e09079</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>abf8f2022f12f350789d961aceaf9ccfd53e7ec58d8c9934cfce77779b4eac11</SHA-256>
              <SHA-1>5f8991f3e065fd95614859a293f88b9c70e4bb23</SHA-1>
              <MD5>84da8dee6b319ea0b10b6de5489c6aae</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>b1e54dc9d12ba9b747801d6c7f1633b45bd08d607e2043bf0ba980e357808a8a</SHA-256>
              <SHA-1>860f45a989c416c34f694e825e2a710ca0c0d89b</SHA-1>
              <MD5>71f76bfdad3db146df9353003ffe2008</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>ba55cc36b2c2de8f4f45c4acae13d1e4d42a83ca129540001d5fa42ca06400f7</SHA-256>
              <SHA-1>4e82c2fc11bdbbb57325623b868ffbd26ceb03f4</SHA-1>
              <MD5>6205d660602f51e7370e80318ea703ab</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>c4035ae01242b11bcac219d46d950d98f65383288406abca8ca41e6d48340b24</SHA-256>
              <SHA-1>e56ee475fa77690c470a6241ec6f8603cf309be7</SHA-1>
              <MD5>293176297dbc13f015d68813e4b6dcea</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/zlib</file_type>
            </value>
            <value>
              <SHA-256>d370f5ba1537e4a6f13f72bb5b241c53941181ab62f9fc0bad0f67abfec2f3df</SHA-256>
              <SHA-1>7c5d9c4876bf55d327e2886ea29aa91ac10354c5</SHA-1>
              <MD5>f64cc10d13c591d99ee73baf9d9df518</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>x865b53a17ff436fda09bce606a144648123f818a8865b81e187729de59a055aa.exe</name>
        <report_id>e01b718e-74e7-41dc-83c5-431615963e91</report_id>
        <tags>
          <value>peexe</value>
          <value>blank</value>
          <value>crypt</value>
          <value>python</value>
          <value>packed</value>
          <value>stealer</value>
          <value>anti-debug</value>
          <value>overlay</value>
          <value>expand</value>
          <value>lolbin</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
          <value>pyinstaller</value>
          <value>invalid-signature</value>
          <value>signed</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>342259dd783e503fcdae41bad7f77bd80b59f4a3a4593c782a18bf705337c4f2</id>
    <title>Analysis Report for 342259dd783e503fcdae41bad7f77bd80b59f4a3a4593c782a18bf705337c4f2</title>
    <updated>2026-05-11T04:42:35Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015e5ed6e5cdb5619836c6</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a015e3786e92bda70271724</flow_id>
        <hash>342259dd783e503fcdae41bad7f77bd80b59f4a3a4593c782a18bf705337c4f2</hash>
        <iocs>
          <urls>
            <value>
              <url>https://clients2.google.com/cr/report</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://crashpad.chromium.org/</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://crashpad.chromium.org/bug/new</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://support.google.com/chrome/contact/chromeuninstall3?hl</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>clients2.google.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crashpad.chromium.org</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>support.google.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <emails>
            <value>
              <email>appro@openssl.org</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>142.251.127.138</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.102</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.121</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.138</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.121</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.102</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>498745d88d7d011477735cf2c59d584d</MD5>
              <SHA-1>2725c61b5bcbb07270522c5c76337fd13ce7d1ec</SHA-1>
              <SHA-256>0af5f402d0b26ab544614614985a913bd0a36096daf85af7e29d4acc143ad7b2</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>14308ade6022420146a99efe500380a8</MD5>
              <SHA-1>49f31589ac3e57325bd324ac2fb8ef76dba86993</SHA-1>
              <SHA-256>1ddf570b8ddbdbfc95a41c2b5c5eb322cc5aa5ccde49550e5b8d00a33fa9d876</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <MD5>039076f7fd5f5fdc8ba1364ce9a1fd64</MD5>
              <SHA-1>1d6ef2cc50a77585f2f9c2b7014b3ca67dccd88e</SHA-1>
              <SHA-256>35c764272e688195eefd421b169776f1e87f3f924c1a66c7e2b2682f22835c2f</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <MD5>3ecf6a0cb6b6734b55a5d50a5ec9526d</MD5>
              <SHA-1>3318c5cac272603074afea437f074fd6cefcef6a</SHA-1>
              <SHA-256>3f921d65d0ba465f97f4d44efb8a13ebb76f8df0dde7d69b42f78a9e8318b239</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <MD5>e276ba3b77eaefdb4bed5e73d6dc87b8</MD5>
              <SHA-1>9965d1cad47e857fb5b8331b5ff57d0790cef7fa</SHA-1>
              <SHA-256>4578c6b999cf2e0610bd5d13787d8f28826f938dea2ad75f39a4d0b7c4765a34</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.zbrush.pcx</file_type>
            </value>
            <value>
              <MD5>4352d88a78aa39750bf70cd6f27bcaa5</MD5>
              <SHA-1>3c585604e87f855973731fea83e21fab9392d2fc</SHA-1>
              <SHA-256>67abdd721024f0ff4e0b3f4c2fc13bc5bad42d0b7851d456d88d203d15aaa450</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>9ce8c70178061cc4cf4a6bb1e291df93</MD5>
              <SHA-1>dc9804dd3aa348fb0c05f53c53c698518af514a0</SHA-1>
              <SHA-256>6f88bc7cb02ccb2dbc26b5f4ce53e355b331e31bb920b2ba8cbbcd1b5d4cd5a0</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <MD5>4c727abf06a152475ddc1d4407f29727</MD5>
              <SHA-1>fdd1a480d8269817ae06b9376beb0eb3fc099922</SHA-1>
              <SHA-256>9ff8978f223fc4fd0c1fef0e8c5d99701a3657f9488f2a9b50f0d2042bf235e7</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.zbrush.pcx</file_type>
            </value>
            <value>
              <MD5>42cf62b780813706e75fb9f2b2e8c258</MD5>
              <SHA-1>a022d5c1cfdd8aace0089f3e72f2eedd41bda464</SHA-1>
              <SHA-256>a0c9d012e2bf6b2fe05c2d97cb5594d97cf2f539e97935c12abd7a3562f4d9bf</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>a1dcc316112f3b467b45c428abf53fe2</MD5>
              <SHA-1>b1eed383c49c890be9e044c4b3d74199382fe949</SHA-1>
              <SHA-256>a9004a1e0b51225aa03e55134f647f2f2f2914fa641403e77dd860a8186103dd</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.zbrush.pcx</file_type>
            </value>
            <value>
              <MD5>0d62df6f0138e145185b2c1c45bf72bc</MD5>
              <SHA-1>f51d2ad16dc79373001160a2b5e7a2f861f60d5c</SHA-1>
              <SHA-256>b5fae454eae83931e8508b3c158b122f7100b65d70065e8af2aaeddb639a5c40</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>a19a2658ba69030c6ac9d11fd7d7e3c1</MD5>
              <SHA-1>879dcf690e5bf1941b27cf13c8bcf72f8356c650</SHA-1>
              <SHA-256>c0085eb467d2fc9c9f395047e057183b3cd1503a4087d0db565161c13527a76f</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <MD5>10b6640d3859662b3f80b6e5eb5e77ce</MD5>
              <SHA-1>e6ce190126cea61a5dadb831cf89de3d4ec4325a</SHA-1>
              <SHA-256>d7a3ba5860f27c3cb90ae8fc5c370365f0b14d4d87fa3559e6dfc80082509930</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>d450a3232b97b58fd3dc4c929c90f2ec</MD5>
              <SHA-1>2bc1b57bc39a8ccb5ca11419b414c811d8aa9e73</SHA-1>
              <SHA-256>da72701b28dc8f9a809b003c5261d9afa26fcf7e8603cd273008b6a55a33a211</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <MD5>f1d3ff8443297732862df21dc4e57262</MD5>
              <SHA-1>9069ca78e7450a285173431b3e52c5c25299e473</SHA-1>
              <SHA-256>df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>b1feab05237beb3558dc3da814a3af98</MD5>
              <SHA-1>21cf68edd62bd20434948dc1afe8edad0e90f737</SHA-1>
              <SHA-256>eaf94684ccce3349c11cbc32ba6e31aac91727b454d72d17611d3c1f8ceda3c0</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>64cda109f203d67fed159c425a9cdc8c</MD5>
              <SHA-1>11f9fa70fab6223fd97f4e5faf215a9d561755f3</SHA-1>
              <SHA-256>fbc9282cf1ec72444cc08d2467a4ebf8bbd28019905e913702f7320c9c35654a</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.zbrush.pcx</file_type>
            </value>
            <value>
              <MD5>e285e9c67731dd9f6d31a4e9976df89b</MD5>
              <SHA-1>d9f5264c14464959006229106a667d5f6f2c2371</SHA-1>
              <SHA-256>c3caeb0e9ba26ee54dc7e2361cc59227a8ced8b4eb8d42bda6a2e2f0c9441e0b</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>41dfd20f3f6d0960662a51619fdba650</MD5>
              <SHA-1>1b0206c620beebe890c00449754995396bebbc8f</SHA-1>
              <SHA-256>f15a197d40b42e46ebcd55b03afbbd0dec258c75676b1dbc21697c955c6a29d1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>447c6d957aaab0149026eee3e8c42796</MD5>
              <SHA-1>625e831f5d63fc8cd50d9a5eee14acb3de8b1eaa</SHA-1>
              <SHA-256>e06d396ee5ecce2b763b835bd4a901e61658112acad3e43fc2d10fcc8f32ed62</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>347cb07c2af3264c9e544f076a235698</MD5>
              <SHA-1>738d49300ab281beda8c5691f0d8b2debb65fe79</SHA-1>
              <SHA-256>3ac888cfeea1c9e776488b7bb804243e129ea4e605af96f6d068ad08f09e9fd7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1BEAC3E3-B852-44F4-B468-8906C062422E</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>3fe8fa79-5dce-4503-ab23-464ea24babff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>401C381F-E0DE-4B85-8BD8-3F3F14FBDA57</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4DC8B4CA-1BDA-483e-B5FA-D3C12E15B62D</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4ea16ac7-fd5a-47c3-875b-dbf4a2008c20</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>5C65F4B0-3651-4514-B207-D10CB699B14B</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8237E44A-0054-442C-B6B6-EA0509993955</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8A69D345-D564-463c-AFF1-A69D9E530F96</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8BA986DA-5100-405E-AA35-86F34A02ACBF</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>A946A6A9-917E-4949-B9BC-6BADA8C7FD63</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>FDA71E6F-AC4C-4a00-8B70-9958A68906BF</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Macromedia\FlashPlayerPepper</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows NT\CurrentVersion</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\%ls\Products\%ls\InstallProperties</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{%ls}</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>SOFTWARE\Policies\Google\Chrome</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Policies\Google\Update</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Session Manager</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Services\EventLog\Application\</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>Software\Classes\AppID\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Classes\CLSID\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Classes\Interface\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Classes\TypeLib\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Clients\StartMenuInternet</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Common</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Common\Rlz</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Update</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Update\ClientState</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Update\ClientStateMedium\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Update\ClientState\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Update\Clients\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Active Setup\Installed Components\</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\MediaPlayer\ShimInclusionList</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\App Paths</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Uninstall\</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome Frame</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
          <eth_wallets>
            <value>
              <eth_wallet>0x23e4bc:$eth: f\x00c\x00e\x00a\x007\x003\x002\x002\x008\x006\x003\x002\x009\x007\x005\x00e\x000\x005\x002\x00e\x00b\x009\x000\x00f\x00c\x00f\x006\x00c\x00d\x001\x007\x005\x002\x00d\x003\x00b\x004\x002\x00b\x004\x00</eth_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </eth_wallets>
        </iocs>
        <name>x342259dd783e503fcdae41bad7f77bd80b59f4a3a4593c782a18bf705337c4f2.exe</name>
        <report_id>c8777202-4787-4dca-a7fe-5b340342a41f</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>txt</value>
          <value>xworm</value>
          <value>expiro</value>
          <value>virus</value>
          <value>anti-vm</value>
          <value>obfuscated</value>
          <value>keylogger</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>fingerprint</value>
          <value>lolbin</value>
          <value>rundll32</value>
          <value>base64</value>
          <value>reconnaissance</value>
          <value>crypto</value>
          <value>explorer</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>2e2de07e4cacea10fe0a0b211cf02a0cd597cb8b601111dde37e943e96cc2719</id>
    <title>Analysis Report for 2e2de07e4cacea10fe0a0b211cf02a0cd597cb8b601111dde37e943e96cc2719</title>
    <updated>2026-05-11T04:42:05Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015e5eb87f27901eb5f05a</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a015e1b2fcb905ec28c8679</flow_id>
        <hash>2e2de07e4cacea10fe0a0b211cf02a0cd597cb8b601111dde37e943e96cc2719</hash>
        <iocs>
          <urls>
            <value>
              <url>http://schemas.microsoft.com/SMI/2</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://component-warehouse.co.uk:6606</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://malware.component-warehouse.co.uk:8808</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.component-warehouse.co.uk:7707</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>schemas.microsoft.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>component-warehouse.co.uk</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>malware.component-warehouse.co.uk</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.component-warehouse.co.uk</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>150.171.109.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>23202710be8c5fc9672495b0b62bebcf29a087cc7e07236f6bb155efb6e499ad</SHA-256>
              <SHA-1>a60ebbbcae868abd27fc96e22701fae48940e53c</SHA-1>
              <MD5>16ec11406456535d1de48d96513667e8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>3b904ab04cb29f4f2cf083c2b133a494ad05e6ef5c6a0243c31b51fc25e6941f</SHA-256>
              <SHA-1>0767eeafe33c83161aec47ea2c28a30ba954fdc9</SHA-1>
              <MD5>fd29301b5d8935606626f78b52b99694</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/xml</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>Software\</registry>
              <origin>DOTNET_DECOMPILATION</origin>
            </value>
          </registry>
        </iocs>
        <name>winlogon250.exe</name>
        <report_id>891cc14e-8252-4276-b0bb-4511f9ca3ef4</report_id>
        <tags>
          <value>peexe</value>
          <value>dotnet_pe</value>
          <value>asyncrat</value>
          <value>config-extracted</value>
          <value>reg</value>
          <value>fareit</value>
          <value>razy</value>
          <value>samas</value>
          <value>anti-vm</value>
          <value>fingerprint</value>
          <value>base64</value>
          <value>reconnaissance</value>
          <value>lolbin</value>
          <value>schtasks</value>
          <value>obfuscated</value>
          <value>vbnet</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>cdf074c997b73bb1226198d651a7572a39db503ccd0bcc1caa1c4c448b8fa286</id>
    <title>Analysis Report for cdf074c997b73bb1226198d651a7572a39db503ccd0bcc1caa1c4c448b8fa286</title>
    <updated>2026-05-11T04:39:04Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015d7bb87f27901eb5f030</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a015d67792fe2d217aedb68</flow_id>
        <hash>cdf074c997b73bb1226198d651a7572a39db503ccd0bcc1caa1c4c448b8fa286</hash>
        <iocs>
          <urls>
            <value>
              <url>http://crl.comodoca.com/AAACertificateServices.crl04</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crl.sectigo.com/SectigoPublicCodeSigningCAEVR36.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crt.sectigo.com/SectigoPublicCodeSigningCAEVR36.crt0#</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://s.symcb.com/universal-root.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://schemas.microsoft.com/SMI/2016/WindowsSettings</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://d.symcb.com/cps0</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://d.symcb.com/rpa0.</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://d.symcb.com/rpa0@</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://sectigo.com/CPS0</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>crl.comodoca.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crl.sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>crt.sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>d.symcb.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>s.symcb.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>schemas.microsoft.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sectigo.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>ts-aia.ws.symantec.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>ts-crl.ws.symantec.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>23.11.40.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.56.82.130</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.38.233</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>91.199.212.90</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.38.233</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.56.82.130</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>23.11.40.157</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.100</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>91.199.212.90</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>10f86daa4593b7da6a08cde629aff7aaa3f89730a83823c72156faf30c467e51</SHA-256>
              <SHA-1>3842ca3e23411cf2e41d087032da34b08aedd92e</SHA-1>
              <MD5>c44630e19fb8909907254abb18f25349</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>15b108b888972a3f6eb892c219fc998658230e65ee60a8e49f27585507c18008</SHA-256>
              <SHA-1>7c2c72b3111edddf03e046dcc84ed639ae108171</SHA-1>
              <MD5>c974dc7b439fdb0acd86ace5ccae5b4d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>40016d17f02bb7187a7ad838405a7b37881a1290846befbc441c390b817aaffe</SHA-256>
              <SHA-1>74e23592a4844ed47d994cd3ddb3aeeb2304e804</SHA-1>
              <MD5>edbc83f341080e7ff894afd116ffa9f3</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>819075a040dc9026fd1d834310a6961db554757db37293fc9c52fa3c2e4eade2</SHA-256>
              <SHA-1>bd38984ec20d4efe6d0f72d1cc53ef56bc4e59cc</SHA-1>
              <MD5>83ec4810b6d9f519768bc032e3b9755d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/zlib</file_type>
            </value>
            <value>
              <SHA-256>8d5c3dc4a02696f38d9208220773b5f99a32910fb305cf52c7e11b29c29e85ed</SHA-256>
              <SHA-1>62f326261e379b77fd5c2bdc0cf3fa00587abc3f</SHA-1>
              <MD5>db5e3ca3adc68bc1a7d062f26ba69c28</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>8e70c313e081d79c7594e16d9f4a29b1fe3a3d045fe56e278079a841b0b3fa6a</SHA-256>
              <SHA-1>a7691c7946378789cc0ba0702208dc46e6e1d3b6</SHA-1>
              <MD5>a9b0147fb3e4abf8eea35debc7e09079</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>abf8f2022f12f350789d961aceaf9ccfd53e7ec58d8c9934cfce77779b4eac11</SHA-256>
              <SHA-1>5f8991f3e065fd95614859a293f88b9c70e4bb23</SHA-1>
              <MD5>84da8dee6b319ea0b10b6de5489c6aae</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>b1e54dc9d12ba9b747801d6c7f1633b45bd08d607e2043bf0ba980e357808a8a</SHA-256>
              <SHA-1>860f45a989c416c34f694e825e2a710ca0c0d89b</SHA-1>
              <MD5>71f76bfdad3db146df9353003ffe2008</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>ba55cc36b2c2de8f4f45c4acae13d1e4d42a83ca129540001d5fa42ca06400f7</SHA-256>
              <SHA-1>4e82c2fc11bdbbb57325623b868ffbd26ceb03f4</SHA-1>
              <MD5>6205d660602f51e7370e80318ea703ab</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>d370f5ba1537e4a6f13f72bb5b241c53941181ab62f9fc0bad0f67abfec2f3df</SHA-256>
              <SHA-1>7c5d9c4876bf55d327e2886ea29aa91ac10354c5</SHA-1>
              <MD5>f64cc10d13c591d99ee73baf9d9df518</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>2acab1228e8935d5dfdd1756b8a19698b6c8b786c90f87993ce9799a67a96e4e</SHA-256>
              <SHA-1>80c9820ff2efe8aa3d361df7011ae6eee35ec4f0</SHA-1>
              <MD5>4842e206e4cfff2954901467ad54169e</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/octet-stream</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>45d9eef168647963423b0fe755199bf6aae63f7933f7418b0d9dbf2d5ce0ac02</SHA-256>
              <SHA-1>dbf638919ee51f765b6f3872b5f035d396a0a373</SHA-1>
              <MD5>6e2fd59fe34fcac738d65075571e7bf0</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>xcdf074c997b73bb1226198d651a7572a39db503ccd0bcc1caa1c4c448b8fa286.exe</name>
        <report_id>d4e6b52b-f2ca-4b58-8806-6e98c453a8eb</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>data</value>
          <value>blank</value>
          <value>crypt</value>
          <value>python</value>
          <value>packed</value>
          <value>stealer</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>expand</value>
          <value>expired-cert</value>
          <value>lolbin</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
          <value>pyinstaller</value>
          <value>invalid-signature</value>
          <value>signed</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>2a47a9f9fa760c442b11f07caf55665fc0d47b5caf100c9f2fd98b663ba04611</id>
    <title>Analysis Report for 2a47a9f9fa760c442b11f07caf55665fc0d47b5caf100c9f2fd98b663ba04611</title>
    <updated>2026-05-11T04:38:12Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015d59b87f27901eb5f029</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015d3411d0143726890852</flow_id>
        <hash>2a47a9f9fa760c442b11f07caf55665fc0d47b5caf100c9f2fd98b663ba04611</hash>
        <iocs>
          <urls>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/jquery.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/#/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/9gag-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/about/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/akillitv-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/bandcamp-music-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/bilibili-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/bitchute-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/blogger-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/blutv-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/buzzfeed-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/cdn-cgi/challenge-platform/h/g/jsd/oneshot/fe6331af5207/0.21713051731595623:1778469851:brSW0b8eC9FNS7aZXZmC9k6g3lpZb_ilo1K_dknibvc/9f9e7e450fa1a592</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/fe6331af5207/main.js?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/cdn-cgi/rum?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/contact/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/cookies-policy/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/copyright-dmca-report/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/cuser.php?ddt=1778474297679</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/dailymotion-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/disclaimer/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/douyin-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/espn-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/facebook-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/faq/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/febspot-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/flickr-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/gaana-music-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/how-it-works/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/ifunny-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/imdb-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/imgur-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/instagram-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/izlesene-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/kwai-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/likee-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/linkedin-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/mashable-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/mixcloud-music-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/mxtakatak-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/okru-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/okru-video-downloader/#</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/okru-video-downloader/#pokoapps</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/periscope-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/pinterest-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/privacy-policy/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/puhutv-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/reddit-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/rumble-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/sharechat-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/soundcloud-music-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/streamable-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/ted-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/telegram-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/terms-of-service/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/tiktok-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/tumblr-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/twitch-clip-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/twitter-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/vimeo-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/vk-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.5.3</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.5.3</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/plugins/stackable-ultimate-gutenberg-blocks-premium/dist/frontend_blocks.css?ver=2.17.1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/plugins/stackable-ultimate-gutenberg-blocks-premium/dist/frontend_blocks.js?ver=2.17.1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/plugins/stackable-ultimate-gutenberg-blocks-premium/dist/frontend_blocks__premium_only.css?ver=2.17.1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/plugins/stackable-ultimate-gutenberg-blocks-premium/dist/frontend_blocks__premium_only.js?ver=2.17.1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/themes/aiodl-default/assets/icons/translation.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/themes/aiodl-default/assets/sources/odnoklassniki.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/themes/aiodl-default/js/bootstrap/bootstrap.bundle.min.js?ver=1.3.8</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/themes/aiodl-default/js/main.js?ver=1.3.8</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/themes/aiodl-default/style.css?ver=1.3.8</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/uploads/2021/10/favicon.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/uploads/2021/12/givefastlink.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/uploads/2022/04/Download-OKRU-video-1.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/uploads/2022/04/Download-OKRU-video-2.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-content/uploads/2022/04/Download-OKRU-video-3.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/wp-includes/js/wp-emoji-release.min.js?ver=6.6.5</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://instasaver.io/?utm_source=ads_showroom&amp;utm_medium=banner&amp;utm_campaign=display&amp;utm_content=modern-hero</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://s.w.org/images/core/emoji/15.0.3/svg/1f680.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://static.cloudflareinsights.com/beacon.min.js/v8c78df7c7c0f484497ecbca7046644da1771523124516</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://vidooq.com/converter/?utm_source=gfl&amp;utm_medium=display&amp;utm_campaign=2025_campaign&amp;utm_content=banner</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://vidooq.com/downloader/?utm_source=gfl&amp;utm_medium=display&amp;utm_campaign=2025_campaign&amp;utm_content=banner</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtm.js?id=GTM-K7RG3MSQ</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://givefastlink.com/okru-video-downloader/</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>cdnjs.cloudflare.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>givefastlink.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>instasaver.io</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>s.w.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>static.cloudflareinsights.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>vidooq.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>104.16.80.73</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.17.25.14</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>192.0.77.48</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>192.178.183.97</ip>
              <origin>URL_RENDER</origin>
            </value>
          </ips>
        </iocs>
        <name>hxxps://givefastlink.com/okru-video-downloader/</name>
        <report_id>fc5add5f-b475-4699-a2d8-8765ffe690e1</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bcc555631a31c47c74593bda3042986dff568589faedd927a784574a16d180dc</id>
    <title>Analysis Report for bcc555631a31c47c74593bda3042986dff568589faedd927a784574a16d180dc</title>
    <updated>2026-05-11T04:37:30Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015d47b87f27901eb5f024</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a015d092fcb905ec28c84f2</flow_id>
        <hash>bcc555631a31c47c74593bda3042986dff568589faedd927a784574a16d180dc</hash>
        <iocs>
          <urls>
            <value>
              <url>http://xab.uk.com:6606</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>xab.uk.com</url>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>1.108.2.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.67.168.20</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.67.168.20</ip>
              <origin>MALWARE_CONFIG</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>1e1beee8e560e86f77a35a5e9f710ed7528977edbace8c5a98a859997b92b7e0</SHA-256>
              <SHA-1>fc01cf1fa69929757c361513e920d260ec566621</SHA-1>
              <MD5>868e5abc83f5db027387c03dabca4703</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>277ee767a6900856c4bab3f9abd5b1192dddc0eb7bb647dad4fadfb0dd887662</SHA-256>
              <SHA-1>5834dfcafc5fe3f4db189ad711928b3ad07494a0</SHA-1>
              <MD5>05960e1304d853e440c1dca3266949b5</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>4028f9d9098023914d35c9479d7b8c72f66b9fe4dde883ebc6e869a0ac9c245c</SHA-256>
              <SHA-1>bbe14da62699fb4616c7294d00cd1a0e837c4b84</SHA-1>
              <MD5>34bb8830f58d6717c045dc826d4e8641</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>567e963ca8146bda630a9430302404f0f2d28304c703e3c9d264015877d1f7de</SHA-256>
              <SHA-1>6366aeee53c84a546db431e3b3e8a1dfbf08dde0</SHA-1>
              <MD5>a36c9f07814a30dfee675de79846fe87</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>621078fbcb47efc7ba19d144092aeee00e0f5e7fa5aed3e9756085d6299e827b</SHA-256>
              <SHA-1>9d62d5dac24ce3c3315e613b46f6da85ba9c0432</SHA-1>
              <MD5>597c1970c2b54e003eb582180de2962c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>663f048521b4521179252571dfb72f3e163977226df08641983c5953a5474b96</SHA-256>
              <SHA-1>ecaf9d88c221fec55c16d6803df47dc707904be3</SHA-1>
              <MD5>00b43da985465ceb9d311e66803e263a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>6b935f2db530b69dda81206abe4fa751c739ae5f64e1418bedcba18fce0986ae</SHA-256>
              <SHA-1>6428f09b8be1c7e10422a989d94762683eb83408</SHA-1>
              <MD5>2cd0d02104a69d6e5ca39615a4bd0826</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>8855f357a9932e5a536123cdc132d5847a0623a5d15f1e04645fd200ffe2e91a</SHA-256>
              <SHA-1>83e267f8b183fafc273db09a824732b8fafbdaa5</SHA-1>
              <MD5>cae3d3e15a34b45d637b99159354d5ed</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>9d19b188578d99b41f4c7227fba097e9f87dd3e880009e1f328e067b581cd6a3</SHA-256>
              <SHA-1>235b4f88279f29987cd20582fc47e6b0cf67cbc0</SHA-1>
              <MD5>c92870052c2a63708115b329ccc5cfb6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>a5639c71558fe166f2a7659531e4f79e250a4c09e3f7a28562cb6db12c10a522</SHA-256>
              <SHA-1>be444d477887ca10fdd2c84ed588ce569e2598c6</SHA-1>
              <MD5>02e0156d7f851d8f7008450c9132b28c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>a86ddb3e863eafdba757bc92c6f016db52fa1035fdd142bcf6dabc07e1df2cdb</SHA-256>
              <SHA-1>d87d3ff999fb4e4843ff0df01f3b54914858121e</SHA-1>
              <MD5>47e33532ff75ee005afa6afd41c3c116</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>a9135f01695140d3a19d3dc2a4d42929b04234070b7848b362f654b64e8a0e1f</SHA-256>
              <SHA-1>d5e76b03f4287269df18157fa77e19851454500f</SHA-1>
              <MD5>d093189b9a0f73406323dfe234a0a772</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>c65f1f124ed1517cbafc092dca6df55160a9d9780fb45e78f37536f010c67cbe</SHA-256>
              <SHA-1>98c06d9c886b33e4221448cf3f5cbd22930af5f3</SHA-1>
              <MD5>6a0e9391a488b14e819eb960fd53cdb7</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>caca2d836951b9f64ec6bac17c293781e49c6dd989c1d99dccf35edd4014d4e6</SHA-256>
              <SHA-1>b4a72632f3ff141954f227f6c166cb6974a7e2fc</SHA-1>
              <MD5>ca79d4b2110ae26fd00b4f5b8a0cb3ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>debefb13033f1a3688dd99599a6242c6878724f8e1972e691a85717f55da8950</SHA-256>
              <SHA-1>3940fed337581db39bfbe158ef8d23c9beb96bc6</SHA-1>
              <MD5>a8d1c6b7a4f69466b5cf5851e816c2dd</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>e0ecf8c294dfb04be81cfebb0416ccd7a54b1c343e295cfc480671047e1857d8</SHA-256>
              <SHA-1>fb243821958a0d3c3cb3fcc60300326d805edfe9</SHA-1>
              <MD5>2a047d89475220f968ccb3bc1e1c33c9</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>ed857a84505f9318f7216766f69212f89401e410f9113c5642d030ab992a7cb0</SHA-256>
              <SHA-1>6c14dfafad0083035f8242c439773ce56b693bf9</SHA-1>
              <MD5>e463f8e94ab93238934edfc39542c4f0</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>Software\</registry>
              <origin>DOTNET_DECOMPILATION</origin>
            </value>
          </registry>
        </iocs>
        <name>gameupdate.exe</name>
        <report_id>87fc2794-a2cf-46c1-a041-4341c36b55a6</report_id>
        <tags>
          <value>peexe</value>
          <value>dotnet_pe</value>
          <value>asyncrat</value>
          <value>config-extracted</value>
          <value>reg</value>
          <value>dcrat</value>
          <value>fareit</value>
          <value>razy</value>
          <value>samas</value>
          <value>unsafe</value>
          <value>windows</value>
          <value>anti-vm</value>
          <value>fingerprint</value>
          <value>base64</value>
          <value>reconnaissance</value>
          <value>lolbin</value>
          <value>schtasks</value>
          <value>obfuscated</value>
          <value>vbnet</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c78088bbf25414f4aeeab39f4210d5a274bd8491ba0e43af042292d45d0045b3</id>
    <title>Analysis Report for c78088bbf25414f4aeeab39f4210d5a274bd8491ba0e43af042292d45d0045b3</title>
    <updated>2026-05-11T04:34:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c7497e8658d088c819a</_id>
        <file_type>application/octet-stream</file_type>
        <flow_id>6a015c6986e92bda7027159c</flow_id>
        <hash>c78088bbf25414f4aeeab39f4210d5a274bd8491ba0e43af042292d45d0045b3</hash>
        <iocs>
          <btc_wallets>
            <value>
              <btc_wallet>x3acf9:$btc: 36B8B693421CECF8F7F122889462ED4</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <btc_wallet>x3ffb7:$btc: 36B8B693421CECF8F7F122889462ED4</btc_wallet>
              <origin>INPUT_FILE</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>Widget_DinoScanner.uasset</name>
        <report_id>0cb2bc60-c85c-4d43-aff5-fb6cde931b07</report_id>
        <tags>
          <value>data</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>f05948c53bf9dd62a1021618166ffd1c52839b6c0d09284ce2ac0f223a73df01</id>
    <title>Analysis Report for f05948c53bf9dd62a1021618166ffd1c52839b6c0d09284ce2ac0f223a73df01</title>
    <updated>2026-05-11T04:34:04Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c4497e8658d088c818f</_id>
        <file_type>application/octet-stream</file_type>
        <flow_id>6a015c3a2fcb905ec28c83e2</flow_id>
        <hash>f05948c53bf9dd62a1021618166ffd1c52839b6c0d09284ce2ac0f223a73df01</hash>
        <iocs/>
        <name>Buff_StructuresPlus_OmniTool.uasset</name>
        <report_id>80464c33-f33d-43c0-bc29-18f21774dfee</report_id>
        <tags>
          <value>data</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c7bfe5a4aa86cef01b93640d8f7b5087b7ca1383338e31863d3a7d6d26b0739a</id>
    <title>Analysis Report for c7bfe5a4aa86cef01b93640d8f7b5087b7ca1383338e31863d3a7d6d26b0739a</title>
    <updated>2026-05-11T04:33:25Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c290f7e400110050c82</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015c112fcb905ec28c83a5</flow_id>
        <hash>c7bfe5a4aa86cef01b93640d8f7b5087b7ca1383338e31863d3a7d6d26b0739a</hash>
        <iocs>
          <urls>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>file:///tmp/tmpzhtyaljh.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0</url>
              <origin>URL_RENDER</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>https://pap6d6u.mrkhalednasr.com:8443/gygy</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://pap6d6u.mrkhalednasr.com:8443/gygy?eyEp8494jGodzade2potter=chile@corporate-citizenship.com</url>
              <origin>URL_RENDER</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>corporate-citizenship.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>cdnjs.cloudflare.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>pap6d6u.mrkhalednasr.com:8443</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdnjs.cloudflare.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>cdnjs.cloudflare.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>chile@corporate-citizenship.com</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>104.17.25.14</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.67.206.52</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.17.24.14</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.24.14</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>269550530cc127b6aa5a35925a7de6ce</MD5>
              <SHA-1>512c7d79033e3028a9be61b540cf1a6870c896f8</SHA-1>
              <SHA-256>799aeb25cc0373fdee0e1b1db7ad6c2f6a0e058dfadaa3379689f583213190bd</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>Review_Details_Here_079743-781-0598122080400.62QEC.htm</name>
        <report_id>b0c25fa2-9ffc-44d4-b85d-da623ff1f779</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>aidetect</value>
          <value>phishing</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>69e949bcdd57bb0daf8b039ac940c57e6b750eca4c83775fa9c6bcef1b0e93c6</id>
    <title>Analysis Report for 69e949bcdd57bb0daf8b039ac940c57e6b750eca4c83775fa9c6bcef1b0e93c6</title>
    <updated>2026-05-11T04:33:20Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c1ab87f27901eb5efeb</_id>
        <file_type>application/octet-stream</file_type>
        <flow_id>6a015c0f2fcb905ec28c839e</flow_id>
        <hash>69e949bcdd57bb0daf8b039ac940c57e6b750eca4c83775fa9c6bcef1b0e93c6</hash>
        <iocs/>
        <name>BP_OmniTool.uasset</name>
        <report_id>78a68c04-0aaf-413e-9cea-2fc3f5dfabe4</report_id>
        <tags>
          <value>data</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>9025d5ff9eda4f91c6b7e2b2f2e6dc832ac97c52ee78bf0019027e918b7201e7</id>
    <title>Analysis Report for 9025d5ff9eda4f91c6b7e2b2f2e6dc832ac97c52ee78bf0019027e918b7201e7</title>
    <updated>2026-05-11T04:33:20Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c30b87f27901eb5eff2</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a015c0ddf14f1cb2acf74f6</flow_id>
        <hash>9025d5ff9eda4f91c6b7e2b2f2e6dc832ac97c52ee78bf0019027e918b7201e7</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>3a56a76748785ac74bb24119cb042d076a34707f4ce5ac3b90204edd60f166dc</SHA-256>
              <SHA-1>508bc8465dc41260a58ca4c8a794089c7555c6e9</SHA-1>
              <MD5>a06da1675e08a18e5e3dc860894d67cd</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>3c4ecd16d6cdf2edd24c2ea651ea7dfcad691c532b50e136810573ff4385b1a0</SHA-256>
              <SHA-1>44698d147f7f339edbd6ae46a5a37e81ab2e1f44</SHA-1>
              <MD5>c02069700be997f065ff003c5da4c294</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>x9025d5ff9eda4f91c6b7e2b2f2e6dc832ac97c52ee78bf0019027e918b7201e7.exe</name>
        <report_id>98336532-b9f3-43dd-ac23-7948382d9476</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>keylogger</value>
          <value>packed</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>compiled-script</value>
          <value>crypto</value>
          <value>reconnaissance</value>
          <value>fingerprint</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>0de9ab65031210e43dbbce4f14e4c51d9b9d56ccba2d0ffe3756fc6625702fca</id>
    <title>Analysis Report for 0de9ab65031210e43dbbce4f14e4c51d9b9d56ccba2d0ffe3756fc6625702fca</title>
    <updated>2026-05-11T04:33:08Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c15b87f27901eb5efe9</_id>
        <file_type>message/rfc822</file_type>
        <flow_id>6a015c01df14f1cb2acf74e5</flow_id>
        <hash>0de9ab65031210e43dbbce4f14e4c51d9b9d56ccba2d0ffe3756fc6625702fca</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmppqw6zkkw.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://lighting-torch.com/fbd34e090c55b8aaadb63a7fb74f6f</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://lighting-torch.com/braze/unsubscribe/9825/40506913</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://lighting-torch.com/fbd34e090c55b8aaadb63a7fb74f6f</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>lighting-torch.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>lighting-torch.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>213.186.33.24</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>213.186.33.24</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>68494340673d0ca38ed3bf20b672a4f1b58d22ccd49109b46ad554fa764154a2</SHA-256>
              <SHA-1>0eb1d19c196279830377ffd49741c5a61b4f6817</SHA-1>
              <MD5>728e6aa2480c8fea4923f10750194ebf</MD5>
              <origin>EMAIL_BODY</origin>
              <file_type>text/plain</file_type>
            </value>
          </files>
        </iocs>
        <name>submission.eml</name>
        <report_id>55c69476-35d1-407b-9432-0df70b06097c</report_id>
        <tags>
          <value>eml</value>
          <value>rfc822</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bf8a94e4b22744386743788405ef1abfd93da3f712b1452349a9008713078e78</id>
    <title>Analysis Report for bf8a94e4b22744386743788405ef1abfd93da3f712b1452349a9008713078e78</title>
    <updated>2026-05-11T04:32:26Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c0bd6e5cdb56198365e</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015bd986e92bda702714ea</flow_id>
        <hash>bf8a94e4b22744386743788405ef1abfd93da3f712b1452349a9008713078e78</hash>
        <iocs>
          <urls>
            <value>
              <url>https://steptodown.com/okru-video-downloader/</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://app.premium.tools/signup</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://app.premium.tools/signup/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://bcp.crwdcntrl.net/6/map</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://buttons-config.sharethis.com/js/6360007ef2ceb000139840ae.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://count-server.sharethis.com/v2.0/get_counts</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://count-server.sharethis.com/v2.0/get_counts?cb=window.__sharethis__.cb&amp;url=https%3A%2F%2Fsteptodown.com%2Fokru-video-downloader%2F</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fonts.googleapis.com/css?family=Archivo:400,500</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fonts.gstatic.com/s/opensans/v40/memvYaGs126MiZpBA-UvWbX2vVnXBbObj2OVTS-muw.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fundingchoicesmessages.google.com/el/AGSKWxWs_iddB2EvBrLvpPOcQkgSs3vFtouYl3pGNo8ht-bGI-RoOK9BWU96ui9oyrLjz7EQoJNIbBHFnpHMImL_JPg35SoIP0RDm9_9OjtzilqzjtOSDnU3RM9sEAa6SewuhCrfapfNUw==</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fundingchoicesmessages.google.com/f/AGSKWxXK9WocsH0SQCCRE2FgRyE8ZTD_QOK8lFJugMfa1DaBjR2cJup6FGVMLclixKJ74FcgyqmCsfoEQ9vzbseeonEIO-F_HfO1ofxNcctQDSItFQSFTlNA5QpQ_WGX-CgIthN7LMu-9w==?fccs=W251bGwsbnVsbCxudWxsLG51bGwsbnVsbCxudWxsLFsxNzc4NDczOTUxLDMxMDAwMDAwXSxudWxsLG51bGwsbnVsbCxbbnVsbCxbN11dLCJodHRwczovL3N0ZXB0b2Rvd24uY29tL29rcnUtdmlkZW8tZG93bmxvYWRlci8iLG51bGwsW1s4LCJSaWFxYm5TSTVlYyJdLFs5LCJlbi1VUyJdLFsxOCwiW1tbbnVsbCw0MzRdXV0iXSxbMzUsIjE3Nzg0NzM5NTEiXSxbMTksIjEiXSxbMjQsIiJdLFsyOSwiZmFsc2UiXV1d</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fundingchoicesmessages.google.com/i/ca-pub-4455536975557911</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fundingchoicesmessages.google.com/i/ca-pub-4455536975557911?href=https%3A%2F%2Fsteptodown.com%2Fokru-video-downloader&amp;ers=2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://l.sharethis.com/sc</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://l.sharethis.com/sc?event=pview&amp;hostname=steptodown.com&amp;location=%2Fokru-video-downloader%2F&amp;product=sop&amp;url=https%3A%2F%2Fsteptodown.com%2Fokru-video-downloader%2F&amp;source=sharethis.js&amp;fcmp=false&amp;fcmpv2=false&amp;has_segmentio=false&amp;title=OK.ru%20Video%20Downloader%20-%20Fast%20%26%20Secure%20%7C%20Steptodown&amp;cms=unknown&amp;publisher=6360007ef2ceb000139840ae&amp;sop=true&amp;version=st_sop.js&amp;lang=en&amp;description=Free%20and%20Unlimited%20OK.ru%20video%20downloader%20for%20any%20device.%20No%20registration%20or%20installation%20is%20needed.%20Various%20format%20and%20quality%20options.&amp;ua=%22Google%20Chrome%22%3Bv%3D%22147%22%2C%20%22Not.A%2FBrand%22%3Bv%3D%228%22%2C%20%22Chromium%22%3Bv%3D%22147%22&amp;ua_mobile=false&amp;ua_platform=Linux&amp;ua_full_version_list=&amp;uuid=8f3a314c-ec62-4594-9be4-8ed041152021&amp;samesite=None</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://lh3.googleusercontent.com/jlCY0DOwmuLfkUpfokAsvd4FwQcgQ0_eu-wRyBE4xKrYqB2fPwUxcSJcn8-ku-X0TNMJHoayiN-tceNoTwn0OzyDhgllFkL6IyZPdc2S1hhWDVdHOEZ_=h60</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://pagead2.googlesyndication.com/pagead/js/adsbygoogle.js?client=ca-pub-4455536975557911</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://pagead2.googlesyndication.com/pagead/managed/js/adsense/m202605040101/show_ads_impl_fy2021.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-api.sharethis.com/js/sharethis.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-api.sharethis.com/panorama.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-cdn.sharethis.com/img/facebook-white.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-cdn.sharethis.com/img/messenger-white.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-cdn.sharethis.com/img/pinterest-white.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-cdn.sharethis.com/img/sharethis-white.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-cdn.sharethis.com/img/telegram-white.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-cdn.sharethis.com/img/twitter-white.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://platform-cdn.sharethis.com/img/whatsapp-white.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://premium.tools/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://premium.tools/?utm_campaign=Steptodownhome&amp;utm_source=steptodown.com&amp;utm_medium=pop-up</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.analytics.google.com/g/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.analytics.google.com/g/collect?v=2&amp;tid=G-65MWJ3G65V&amp;gtm=45je6562v877166939za200zd877166939&amp;_p=1778473950646&amp;_gaz=1&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;dma_cps=a&amp;dma=1&amp;_eu=AAAAAGA&amp;are=1&amp;cid=123982325.1778473951&amp;frm=0&amp;pscdl=noapi&amp;rcb=2&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;gaf=2&amp;_s=1&amp;tag_exp=0~115938465~115938468~118463261&amp;sid=1778473950&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fsteptodown.com%2Fokru-video-downloader%2F&amp;dt=OK.ru%20Video%20Downloader%20-%20Fast%20%26%20Secure%20%7C%20Steptodown&amp;en=page_view&amp;_fv=1&amp;_nsi=1&amp;_ss=1&amp;_ee=1&amp;tfd=409</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://s.w.org/images/core/emoji/17.0.2/svg/1f514.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://static.cloudflareinsights.com/beacon.min.js/v8c78df7c7c0f484497ecbca7046644da1771523124516</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stats.g.doubleclick.net/g/collect?v=2&amp;tid=G-65MWJ3G65V&amp;cid=123982325.1778473951&amp;gtm=45je6562v877166939za200zd877166939&amp;rcb=2&amp;aip=1&amp;dma=1&amp;dma_cps=a&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;frm=0&amp;tag_exp=0~115938465~115938468~118463261</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/9gag-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/alamy-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/artgrid-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/artlist-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/bandcamp-music-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/bilibili-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/bitchute-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/blog/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/blogger-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/buzzfeed-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/cdn-cgi/challenge-platform/h/g/jsd/oneshot/fe6331af5207/0.21713051731595623:1778469851:brSW0b8eC9FNS7aZXZmC9k6g3lpZb_ilo1K_dknibvc/9f9e75cec9c85d6f</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/fe6331af5207/main.js?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/cdn-cgi/rum?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/cdn-cgi/speculation</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/contact/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/dailymotion-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/douyin-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/epidemic-sound-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/espn-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/eyeem-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/facebook-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/flickr-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/gaana-music-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/getty-images-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/hotstar-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/ifunny-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/instagram-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/istock-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/likee-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/linkedin-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/moj-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/mx-takatak-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/okru-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/okru-video-downloader/#</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/okru-video-downloader/#FAQs</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/okru-video-downloader/#SupportedSources</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/onlyfans-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/pinterest-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/privacy-policy/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/reddit-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/roposo-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/rumble-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/sharechat-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/shutterstock-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/smule-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/snack-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/soundcloud-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/starmaker-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/storyblocks-downloader</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/telegram-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/terms-of-service/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/tiktok-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/tr/okru-video-indirici/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/truth-social-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/tumblr-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/twitch-clip-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/twitter-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/vimeo-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/vk-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/vlive-video-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wesing-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/icons/translation.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/images/steps/download-now.svg?v=1.2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/images/steps/okru-copy-link.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/images/steps/paste-link.svg?v=1.2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/9gag.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/Alamy.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/Artgrid.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/Artlist.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/bandcamp.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/bilibili.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/bitchute.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/blogger.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/buzzfeed.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/dailymotion.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/douyin.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/envato.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/epidemicsound.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/espn.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/eyeem.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/facebook.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/flickr.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/gaana.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/getty-images.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/hotstar.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/ifunny.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/instagram.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/istock.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/likee.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/linkedin.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/moj.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/mxtakatak.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/odnoklassniki.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/onlyfans.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/pinterest.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/reddit.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/roposo.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/rumble.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/sharechat.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/shutterstock.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/smule.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/snack.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/soundcloud.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/starmaker.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/storyblocks.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/telegram.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/tiktok.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/tumblr.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/twitch.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/twitter.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/vimeo.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/vkontakte.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/vlive.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/wesing.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/assets/sources/youtube.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/js/bootstrap/bootstrap.bundle.min.js?ver=1.2.05</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/js/main.js?ver=1.2.05</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/themes/aiodl-default/style.css?ver=1.2.05</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/uploads/2021/12/cropped-icon-32x32.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-content/uploads/2022/03/truth-social.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/wp-includes/js/wp-emoji-release.min.js?ver=6.9.4</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://steptodown.com/youtube-downloader/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://t.sharethis.com/1/k/t.dhj</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://t.sharethis.com/1/k/t.dhj?cid=c010&amp;cls=B&amp;dmn=steptodown.com&amp;rnd=1778473950891</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://t.sharethis.com/a/t_.htm?ver=1.2051.23422&amp;cid=c010&amp;cls=B</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google.de/ads/ga-audiences?v=1&amp;t=sr&amp;slf_rd=1&amp;_r=4&amp;tid=G-65MWJ3G65V&amp;cid=123982325.1778473951&amp;gtm=45je6562v877166939za200zd877166939&amp;rcb=2&amp;aip=1&amp;dma=1&amp;dma_cps=a&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;frm=0&amp;tag_exp=0~115938465~115938468~118463261&amp;z=867696261</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-65MWJ3G65V</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>OK.ru</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://steptodown.com/okru-video-downloader&amp;ers=2</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://steptodown.com/okru-video-downloader/&amp;dt=OK.ru</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://steptodown.com/okru-video-downloader/&amp;source=sharethis.js&amp;fcmp=false&amp;fcmpv2=false&amp;has_segmentio=false&amp;title=OK.ru</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>steptodown.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>app.premium.tools</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>bcp.crwdcntrl.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>buttons-config.sharethis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>count-server.sharethis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>fonts.googleapis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>fonts.gstatic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>fundingchoicesmessages.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>l.sharethis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>lh3.googleusercontent.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>pagead2.googlesyndication.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>platform-api.sharethis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>platform-cdn.sharethis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>premium.tools</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>region1.analytics.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>s.w.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>static.cloudflareinsights.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>stats.g.doubleclick.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>steptodown.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>t.sharethis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.google.de</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>104.16.79.73</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>13.35.58.112</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.250.154.94</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.250.154.95</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.110.132</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.110.154</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.110.94</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.155</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.14.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.20.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.67.217.253</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>192.0.77.48</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>216.239.32.36</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>3.160.150.115</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>3.171.214.34</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>3.248.127.135</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>3.78.153.37</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>52.222.136.119</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>95.101.111.153</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>95.101.111.156</ip>
              <origin>URL_RENDER</origin>
            </value>
          </ips>
        </iocs>
        <name>hxxps://steptodown.com/okru-video-downloader/</name>
        <report_id>73eb90af-c2c4-449a-940d-44c509fdf1b0</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8888e7e02d981feac559f5f42c30bcb74733a543139f914918fd434d83cbc0ce</id>
    <title>Analysis Report for 8888e7e02d981feac559f5f42c30bcb74733a543139f914918fd434d83cbc0ce</title>
    <updated>2026-05-11T04:31:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015c20b87f27901eb5efee</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015bbbdf14f1cb2acf7499</flow_id>
        <hash>8888e7e02d981feac559f5f42c30bcb74733a543139f914918fd434d83cbc0ce</hash>
        <iocs>
          <urls>
            <value>
              <url>https://www.mediafire.com/file/8i3y5a9p6svmpv9/Image-Line-FLStudioProducerEdition25.2.3Build5171.zip/file</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://blog.mediafire.com/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://prebid.org/dev-docs/publisher-api-reference.html#module_pbjs.setConfig</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://app.asana.com/0/1202116959041480/1204891726118085/f</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://blog.mediafire.com/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://btloader.com/tag?o=5678961798414336&amp;upapi=true</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://cdn.amplitude.com/libs/amplitude-8.5.0-min.gz.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://cdn.econventa.com/Scripts/infinity.js.aspx?guid=5ff0fb62-0643-4ff1-aaee-c737f9ffc0e0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://cmp.gatekeeperconsent.com/min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://docs.prebid.org/dev-docs/publisher-api-reference.html</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://infinity.pub.com/log.aspx?msg=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://mediafire.zendesk.com/hc/en-us</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://plus.google.com/+mediafire</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://prebid.adnxs.com/pbc/v1/cache</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://prebid.adnxs.com/pbs/v1/cookie_sync</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://prebid.adnxs.com/pbs/v1/openrtb2/auction</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://securepubads.g.doubleclick.net/tag/js/gpt.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://static.hotjar.com/c/hotjar-</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://the.gatekeeperconsent.com/cmp.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://twitter.com/mediafire</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.facebook.com/mediafire</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.fast.io/?utm_source=mfftr_file</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.fast.io/alternatives/box?utm_source=mfftr_file</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.fast.io/alternatives/dropbox?utm_source=mfftr_file</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.fast.io/alternatives/google-drive?utm_source=mfftr_file</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.fast.io/alternatives?utm_source=mfftr_file</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=UA-829541-1</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtm.js?id=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.googletagmanager.com/ns.html?id=GTM-53LP4T</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.mediafire.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.mediafire.com/download_repair.php?qkey=8i3y5a9p6svmpv9&amp;dkey=n0beoum48wg&amp;template=55&amp;origin=click_button</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.mediafire.com/download_repair.php?qkey=8i3y5a9p6svmpv9&amp;dkey=n0beoum48wg&amp;template=55&amp;origin=server_error</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.mediafire.com/dynamic/af_link.php?a=11</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.mediafire.com/file/8i3y5a9p6svmpv9/Image-Line-FLStudioProducerEdition25.2.3Build5171.zip/file</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.mediafiredls.com/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://xmlfeedparser.4dsply.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>app.asana.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>blog.mediafire.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>btloader.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>cdn.amplitude.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>cdn.econventa.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>cmp.gatekeeperconsent.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>docs.prebid.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>googletagmanager.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>infinity.pub.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>mediafire.zendesk.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>plus.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>prebid.adnxs.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>prebid.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>securepubads.g.doubleclick.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>static.hotjar.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>the.gatekeeperconsent.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>twitter.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.fast.io</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.mediafire.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.mediafiredls.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>xmlfeedparser.4dsply.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>info@adsupply.com</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>104.26.9.66</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.89.208.11</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.67.199.186</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.171.133</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.38.238</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>141.193.213.11</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.66.102.51</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.97</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.172.112.46</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.97</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>216.198.53.6</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.147.83</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>163.70.128.35</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.245.86.111</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.102</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.199.110.153</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.172.112.46</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.147.83</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.171.133</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.245.86.111</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.26.9.66</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.67.199.186</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.199.110.153</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.97</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>216.198.53.6</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.102</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.89.208.11</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>141.193.213.11</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.157</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.66.102.51</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>163.70.128.35</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.38.238</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.97</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>471bcc6c1f08dbb5a5c942c80bfd64b3ecc09e2e055d19b1af2c54337c8250b7</SHA-256>
              <SHA-1>89fb894192235451b8b7fed855f3b47e78d56153</SHA-1>
              <MD5>97d66228a632eb3c9219c98b8dd814aa</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/pdf</file_type>
            </value>
            <value>
              <SHA-256>de8a9639c32d19194cfd0ce4ad21b3e99021b7a55bbdb2c7ae97efcf15baef93</SHA-256>
              <SHA-1>64655a5b087c8c21e52e52ebdc1162618adf4670</SHA-1>
              <MD5>ca0dd3ec948549cad218d50b314a7f08</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>2d16a1cb368665573a51782afbedd09794dad153b3d456aab31ac03dd22ef603</SHA-256>
              <SHA-1>5dd05359e33b5c8faee31120c8093bda3cd8380b</SHA-1>
              <MD5>4efd818c89c13f9415a33be54e45433d</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>ce7ddb78795feec6851a9a4e884276c7236fc07f2a14c144c70aa71b0307f971</SHA-256>
              <SHA-1>7212ada8697d013eedf3728c8cf81082c9bdefd8</SHA-1>
              <MD5>e5a73acd7f1c34ce29f7709d96e04506</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/aspdotnet</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>d42d861518284cc29ac9a39883c28c37dfa46156ba0b271e9f5cb04e04ec4029</SHA-256>
              <SHA-1>58aec5c3cc43f46b31fda132523e43af062d2822</SHA-1>
              <MD5>49c42b42e9f11f43a033e26e8a58134e</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>c40aa69f0b306cea296dd1193c334bc0781587ed51aab579c0433698ba9e0c4b</SHA-256>
              <SHA-1>978c8b03e97680eb62057a7000f6e7fd97fb9658</SHA-1>
              <MD5>34c520d87664032692c4315fff455d18</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>b9dfee2c36f73ae5b4cbbc4ec4f34e348edc6d6af95763c212f6296a9995dbf0</SHA-256>
              <SHA-1>2da9387c433f52f2d4d5023629409a7abe0c8458</SHA-1>
              <MD5>ee0b45632bd776dbb5e7fc0c39aa9388</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <SHA-256>2450e5580136f94bda7ccf95e3167b57e15b05b513a430967943a50036fa47a4</SHA-256>
              <SHA-1>36ad6b0fa2c6bcd116fb642f25789fc2d08a68e6</SHA-1>
              <MD5>c43d9f000a09bd500ed8728606a09de3</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>5ff0fb62-0643-4ff1-aaee-c737f9ffc0e0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>hxxps://www.mediafire.com/file/8i3y5a9p6svmpv9/Image-Line-FLStudioProducerEdition25.2.3Build5171.zip/file</name>
        <report_id>28cb8ac3-cbf8-4c04-948b-66f909bed598</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>javascript</value>
          <value>base64</value>
          <value>obfuscated</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>331ca274fc3117affca8df6ceb6e48baf471da7d9037dc5bf96391b4647d5538</id>
    <title>Analysis Report for 331ca274fc3117affca8df6ceb6e48baf471da7d9037dc5bf96391b4647d5538</title>
    <updated>2026-05-11T04:30:06Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015b71b87f27901eb5efca</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015b4c2fcb905ec28c8244</flow_id>
        <hash>331ca274fc3117affca8df6ceb6e48baf471da7d9037dc5bf96391b4647d5538</hash>
        <iocs>
          <urls>
            <value>
              <url>https://discord.com/ra/r7fLb3JSwbhHsGYyKFSHCpohsqeYOJMoy9BQFmhkxLM</url>
              <origin>IMAGE_QR_CODE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://discord.com/channels/1358618001317822554/1503245664329535608/1503252184987467839</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://cdn.discordapp.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://discord.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discordapp.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://images-ext-1.discordapp.net</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://discord.com/api/v9/apex/experiments?surface=2</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discord.com/api/v9/auth/conditional/start</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discord.com/api/v9/auth/location-metadata</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discord.com/api/v9/experiments?with_guild_experiments=true</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discord.com/api/v9/promotions?locale=en-US&amp;platform=0</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discord.com/api/v9/science</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://discord.com/assets/000992c7034532a2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0062732bd378de9d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/03286dbd684f6207.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/058ce7eeb599987e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/06b0947e5ca6e9de.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/06f031f28e047df7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0700f0845e7c27d0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0769adcf35486d2e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0783e1b9863ef069.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/097ec142fe75c0d4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/09fddae95bcfa2b8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0b2da78b57723921.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0c6380aff3214697.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0cef68abaa36351b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0db4df065ec81211.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0ec4509bd76dcf69.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0ef0fc578c4c37d2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/0f0d3b1f5be9f831.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/10448.bbfa99284ab03bc1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/10448.e64eb7c99d025684.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1086bb58572f42c8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1147.708d8ab127f61417.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1147.c2916c42d5ddc9f9.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/13007.389cd9b86ac723d8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/13007.6cbefcd6949684c4.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/131c318dd45b7aa4.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/13498.b8f1cf2aa08e5307.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/13498.ca916738dd071cf7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1352e18e490ba253.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/14399.9c8322b7f150ccdb.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/14399.c6134f0095382c48.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/15ec9cf07ef46454.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1602280c9a467bfe.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1617757ac457ce19.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/16946.5f81cad48fe3e482.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/16946.cc546e85f696fcde.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/16c0f4d513c4e1b4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/17094.4230418423d81b9b.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/17094.ac70242124bf32d4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/18125.cdf07e16c383d473.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/18125.db88fc3e482e86e0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/182edfaafa64815b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/18934.208dd70fdd13746b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/18934.bbed9aad09951e6c.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/189422196a4f8b53.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/18c6ad72921f51d5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/19248.2c7b5c675fdc1b3c.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/19248.d4bfe5f0c56bbb26.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/19a53edb9f499a5b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/19d886a59a90ac15.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/19e8249def36bbeb.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1bb0433e4b0855c3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1e2805e27c2ba8ec.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/1e3947859c72b22d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/20208bbbe7471e94.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/209a4acf5023c4c3.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/21135.2d09d88a72bada18.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/21135.dba4b0547de54404.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/21a871dc8eb523cd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/21c3bdd31f6e030b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/21e9910cab633a66.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/22513.6f2af8d0aa310c56.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/22513.a68486b1405adb1d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/22604.985437ad93e673cf.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/22604.da4bbd6bb0ae9d14.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/22713.10f737cd14f7f6ba.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/22713.e379c844c10d752e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/22c6170e50abcbf3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/23495.473440073ee69ebf.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/23495.81243490064e18a2.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/25610.9004caa98176277e.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/25610.9a57ce17fccd94df.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/25907.a08c9fe1c38e041a.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/25907.df9442a9b6539e5f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/25e433cb2c9f445d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/26032.574c40a08789fec4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/26032.f49dabfcef1d421b.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2678ddd46e507517.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/27681.6babfc91accec57b.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/27681.a13df9caff466481.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2855d5796e9eca52.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/292fcd6fe5a38723.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/293d11974706df48.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/29c0b212f6aeb37f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2adc722a18faa276.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2c01941f4eb4ec7c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2d0223446f664a29.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2d29fe7ad5230a59.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2df2c3ff74408972.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2e54af6c78a29860.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/2e6c78cd1b88f28e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/30708.9cf8460704deaa3c.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/30708.db47163aece38884.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/31227.e158de00c9b4316a.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/31227.e5334e2db9f8a08a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/31cecb426377ea12.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/32260.a97d836bc6bcdd6c.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/32260.f31b8e07877acda2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/3227658701e4b2fc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/324cf87f02911b42.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/3251b046f3326182.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/327d20973b096df6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/328d2b116379f156.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/3424.086fb29581a56edb.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/3424.c958debdcae8106a.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/34fddbfab81f54b7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/35a3702407cf248e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/35c73e6b14564268.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/35c9329263c2ca32.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/366475408a0ca8c9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/3711af56a38961d5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/379e0b4e17774134.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/3cf8d83374e28340.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/3f7eabfc0bf3bed4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/40153.0c11e3a013e49ab1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/40153.34aa077278e84ef9.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/41444.5ea888d7f819b0cf.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/41444.6b72479df7cadc32.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/42136dfed3fee117.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/42468c47112fa4d3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/43048e168ed41f43.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/43407.a38f4f2cd52ff5b0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/43407.a87be3713ffb59e1.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/437dad2851b730bd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/43851549fb029fff.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/45187.a5c9ca3e05280cbe.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/45187.caf6ca089016de09.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4592.425d3294f67b9038.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4592.f3d769dade141c29.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/45a66c317ead3d12.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4600b4c013fb0a53.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/48433.1eb7c75be61bf40c.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/48433.5d26113bd73ca66d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/48476.504232bdff8bf171.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/48476.c0a0ae7ccf8ea1cb.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/48e06a0106fe8bdc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/49480adde14dfffe.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/49dafa7645015817.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/49e196386720b463.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4a22c590f9802256.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4a5624938a02c4c0.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4ba48b2f4df16124.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4c2dce7094f639e9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4d46ad60532f159c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4e72857fad07a1dd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/4fc6955047412b09.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/50624.7cdf901a2484fb2e.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/50624.91eca4a0fa6edb9d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/510bec8e7140afc9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5119cbca17bd51b2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/516ef675c16202aa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/51e57c5bed57420b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/52196.026c4d8754c85b84.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/52196.aa69c78e0c508648.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/522d5c264c720140.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/52370.32f1451804e10905.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/52370.4474966d84dad64f.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/52706.0eaa18cf2ce282f2.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/52706.6412704e90bcff52.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/537b569f19d0ee92.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/53b106085535acc6.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/54531.16ef5395690e3d09.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/54531.fa0bde9a5fa861e3.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5454864b061f7a6b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/54747.a5b4e0887bc82336.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/54747.af455009324650d4.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/548b990d89588d52.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/54f4729517a57c1d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/55719.3d835740adc8a593.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/55719.3d8c9a33136e83d2.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/56795.8c5dc521d6e8233e.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/56795.e64196df355798b7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/56886.64222f84fb414777.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/57e932bb2a62a5fc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/585cabcc4c371d7f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/58858.33aa316f7f9878fc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/58858.f7ea0a6c4421fa39.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/58ac6f1508804220.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/58d4f7d8b588066c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/594992ad07322185.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/59564.0af2ebc0b1fef6f8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/59564.170d8adc3fcdf9f7.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/59b20bb0b82ab892.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/59d10d35e3ba2bdc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5a1d6391f5a61b0c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5a5299b532ceacc3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5be2e8c0b6aaf63d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5daf17fd50220d44.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5e3c204ba6165e8c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5e848542e6b25b7e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/5e8d03df5e5a43a7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/60060.691e57466fbf0514.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/60060.f2c2a5b8636ecc79.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6026.0a063fbb370c1ebc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6026.69709eb4c44596cc.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/60571.1714458f2a9f69b3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/60571.a10163ec34826a14.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6147653942a0430f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6168f2ace1921e9b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/62320ef8197a8b35.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/62c0e0396e593907.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/63abba734e3dfb93.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64112.4cf75603af800559.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64112.7bf5190f63f06b3b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64227.2def213e23fd172c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64227.9fd9bc3a06261d51.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/643a59464faf9a5d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64441.5376c9fb0ac558a2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64441.8a17d435e31a1188.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/646e481fe4a631de.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64911.9be4b91d6443f5fc.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/64911.d36053e1de517bae.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6498cf6a2c8afe72.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/65182bcbf6f4e323.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/66d715454104d24e.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/66ea017bc4b05593.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6720.97787d3ef3ced317.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6720.d979e28d4a186e94.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/67683.28e71d0d442da916.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/67683.5ca6164c3a44e144.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6772.6e1af36c6e6a8df0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6772.ba703c15f70887c8.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/67aae2c2e5b4c02a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6866.8dcbaa8705a0db81.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6866.a5235bb0f7314dee.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/68953.0ac1d9c6ea845f6e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/68953.abbfa3b829566e12.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/69087db1d0b6db02.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/693313c93d1ad0f0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/696618f89e31d19c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/69a6c34d0549ac47.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/69d3572e6e68e930.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6a1f108a14710b76.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6b1b06a950838910.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6bf75e2fe3b3dd4b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6c90fae397d56275.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6cdd602fc857f5e3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6d5c017c8f28457a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6d867cc1334dbaf8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6e6e667c6e705602.module.wasm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6ea442ae35287c07.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6f420e6714752176.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/6f7713d5b10d7cb3.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7017.5d3dae288bee8bb6.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7017.8a970fe4f13cf544.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7053.abe688beaa0268ea.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7053.e8c6ad375134edb5.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/70530.71feb21d4f7fb4e7.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/70530.8c2319dc2150e552.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/71934.354fbf96249b0fec.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/71934.e2118c277ea05f7a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/72318.6ebd7dac324a8565.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/72318.8409ec4c1b790237.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/72838.559bc1928282456d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/72838.ee3dba0f8e274c8a.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/72d001e9ad58e316.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/72fffb57d3b60e50.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/731c7fbcf7dd300f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/735066f23f51f818.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/74587.a30c6dc3d172ca39.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/74587.b882b96cca202ef3.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/74672.3a0fc23b0fa1e2a6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/74672.87c8912eef7bf10c.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/747973de0e439768.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/74926.01596b55d28e176e.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/74926.ada202dcecf667b5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/75728.5718e2f2f7410b40.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/75728.7e71edf02e645d32.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/758.cf2174ebb4e4391e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/758.ec73366a6c7305c4.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/75916.67ff890cadcde2cc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/75916.6f8f880dd2a840b8.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/75a79e58b35336a1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/76283.7868b2ea31c62fb0.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/76283.979a3fb8558604b6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/76342.68853a1e0b9d94df.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/766b46ae72bafe7c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/76a66fea5b452c0c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/76ec408c233083ec.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/773b4bc3bf84e602.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/77dcbfbad7a14e10.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/78340.1e72c33d89849907.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/78340.cffb763f8088c895.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/79249.21c2185078882620.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/79249.8d1797078a6f7754.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7a0f44df903825f2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7a2ab59e1ed30bdd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7a6a566c2e88a35d.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7ac0e0e975bc8625.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7ac61a2649a3a38a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7b2d1d87df14e6d5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7ba7fcf2c4710bb7.webm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7bae955aa5dc2d39.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7d025eebd308d530.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7d4d21278063ee17.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7e21ba095056385b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/7e6e120329157b06.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/80559.1d0cbad0dc3f828b.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/80559.f6ef5aaf4a8ae4fa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/81280.006e4de58f117843.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/81280.c7657e992c1ca360.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/83004.545a3545006a87f0.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/83004.aafdbb86f28ab738.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/832ad8dc0d14f87c.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/83401666489e38b7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/83928.38d9482202356093.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/83928.8c7ce7a99928c0e4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/84177.564cabb0bf53c85d.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/84177.da37b39a1588beff.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/850a2f2e24c2b251.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8539.316be4cdf7ee32a5.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8539.c11e602c6d0df356.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/85892.08f51a4958cbd9d6.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/85892.589635a80ea8133a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/85fb5c555ddf7561.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/86483.423780a14f47a332.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/86483.580f981a922d8ab5.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/86fc3a053acffc48.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/87157a1fb8094e2a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/88999.284138799e04c11f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/88999.8e8cee89afb2a3a9.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/89203.7fc4a877f32d91d0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/89203.d5502022dd30df08.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/89303650b25da344.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8a6868d968eb9bcf.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8bdfbcfd9352fcd0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8d7536afbef54ced.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8de9caa39a05b297.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8e512236b55d6c6a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8ec4f20367d955d3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/8ef4f550b59149b0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9131.02323730bac853e0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9131.4065537845be0dc4.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/92164.9e76f4ef930f126a.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/92164.bfeaf9501963e3f9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/93c637c21d69ab7e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/94864.78ceb66695b2a280.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/94864.f77cd0c5f3727e01.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/952525b2c0836038.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/95780.a6200b50244ca74e.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/95780.c659918289a33195.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/95e9e50f84171de5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/96251458134bae55.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/96b2b92da831d785.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/96df7595f55ff7a6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/96e81ba43b4186c1.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/97023.6133ff486ea514fb.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/97023.81fdf8252af6bb52.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/984641e698c2acfa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/99045.4dcf9c9ce28d3f2c.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/99045.60c8a36fc7ea5fed.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/99c37d0072d3b000.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9a45fc0a99d63b6c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9a58303519afc229.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9b20d695409ce553.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9bb87b60d9d2607c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9cdba5ade01b5ea8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9d566d091137a4c3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9eb6a8cb4c4689be.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/9f233384a6dac191.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a194f6672e46fdf5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a3a94af053188e46.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a5803b9ddff51ca1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a5cea92172aabb48.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a5fc682aadda4ae2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a6139dc2d77c2b06.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a80d37708d4c0fdf.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/a87356b402ffea30.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/aa7380ffd2ec57fd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/aab928e3054aa35f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ab64a951bef579a9.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ab730ede8dfa52e6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/acc0cb5aab119bba.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ad97b094c77a282e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/aecd361443281edd.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/af31ae89143cdfd5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b03eb3ae7d63aaed.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b11b89aefaea79ba.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b24cf70b3208663e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b272b33815319bae.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b318dc5cb154ca10.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b3948670c37590df.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b754fa70fb1cb5c2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b82d4d939a7a633d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b853f460c0803b8a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b85f8233217614c5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b8d32217cb701d6b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b92266010d2e7ce4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b937a73be69fbbd8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b99b28d5f95d0fe8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/b9caff3c2ced1820.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/bb9057a555f3b50f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/bba16bbcae5d8e54.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/bc020ef8f49692be.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/bc263a87db910c72.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/beb1549b19fe8545.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/bf25c7ff8bf90aef.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c042096506e48b57.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c06ffe2d5c51e773.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c0b057fb88a7e9f4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c6119bd77e336341.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c6b4f2297bec6f8d.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c7eb8c82726fe770.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c8df8e0c2cad2f5b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c995cc1ad6451e28.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c9b5b1fbcc8b8b13.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c9c0c81a09973943.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/c9de30d59c40100f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/cb2006dbced0e246.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/cb2569f2d3e0a064.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/cbc54213617f7354.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/cdfc86e15747fa25.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ce3b8055f5114434.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/cf506b7ca383f67b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/cf55c177de51f002.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/d12d941c62c38193.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/d31453f53b7b1c11.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/d480bdb9c558e1dd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/d5eff8077de8af4e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/d84d8e5bd0493f24.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/d8680b1c1576ecc8.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/da2cc78ad9330179.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/dc603d8683b5bfc4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/dd05fd1ea37e7747.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/dd24010f3cf7def7.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/dd82707589d3cb64.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ddbc0d4e406d192f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ddc007ef367152f1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ddda2e8a1bd66efc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/de5baa48970d18c8.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/df5758ea95cf6a40.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/df59f764952c3a9a.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e042c36ade3058c1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e0bfb5df1991619f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e1497e6938ae2b26.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e24b2f1d194e4476.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e2d32c242db2061a.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e379c32ee76cb786.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e3ada0922f6929c3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e470c65980baec18.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e4b4a8d4376f8550.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e52f0cba712e2fb4.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e58fe1f1cb36f395.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e5e6cab2e7721613.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e7a41e9704558c6a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e958dc3186a7dd7e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/e9e114d0fd3b11e2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ea87c33d025f0d91.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ebab776949c0e926.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ece56679baebfcea.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/ed3b9bd609af7d16.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/edc2c9eaa4875043.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/eea7d52e8fda161f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f1036400daf8b73c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f10666d41e51abf6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f3b4467e04631322.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f405d8ee38d35380.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f41745310a10ee6a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f4a05ed9c1484f42.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f4d735efe9302b0b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f5082ff45959302c.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f7a9924f9285107f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f7f930b9c4ddf3c7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f8a14ad41c14f23a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f8a77d1dbafcefde.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f8e5e8a16390dda5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/f918f8ca701489bf.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/faed0c5d20073511.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/fast-connect.618fafee2f18e501.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/fd53a56eda2fae5e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/fd692e00d82cb26f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/fdfe121d010de677.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/fe127f90e06d92d0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/fe6e71b03e9186e1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/fef4b274d180c28c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/libdiscore-wasm-fetch.143c07e1c96db35d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/sentry.f36cc9d429843670.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/assets/web.c0ce558aa0aa6a32.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/cdn-cgi/challenge-platform/h/g/jsd/oneshot/fe6331af5207/0.21713051731595623:1778469851:brSW0b8eC9FNS7aZXZmC9k6g3lpZb_ilo1K_dknibvc/9f9e72622be12580</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/fe6331af5207/main.js?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/channels/1358618001317822554/1503245664329535608/1503252184987467839</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://discord.com/login?redirect_to=%2Fchannels%2F1358618001317822554%2F1503245664329535608%2F1503252184987467839</url>
              <origin>URL_RENDER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>cdn.discordapp.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>discord.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>discordapp.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>images-ext-1.discordapp.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>discord.com</url>
              <origin>IMAGE_QR_CODE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>discord.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>162.159.134.233</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.128.233</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.128.232</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.129.233</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.136.232</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>162.159.134.233</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.128.233</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.129.233</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.128.232</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>70988db10d46dae7a8f5173e6774de5fd12b51d769b3349d3b5724b8ca98c965</SHA-256>
              <SHA-1>c8c3a679289a7aa5e4d13f3968b9b2d4878e55c4</SHA-1>
              <MD5>53e37f30968d44b9742f328d3ecb8ab0</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>cf42238146976bb75241333be42a9955493bbfd71db8ae90017554c9324adf24</SHA-256>
              <SHA-1>ef31a026ce56b63ae54b89ef122e4a72dbbb82c3</SHA-1>
              <MD5>09de223cbc5ab410c95565bf9a4dae39</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>9cc40a780a8b1933520bc8f45211f95c6d1df262909c538e07c8f20ac4104484</SHA-256>
              <SHA-1>8641561476e9e0cf03f6e4bf914c2d82620e6f65</SHA-1>
              <MD5>7bfca1edbf3fd99ae70e97bed6efac0f</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
        </iocs>
        <name>hxxps://discord.com/channels/1358618001317822554/1503245664329535608/1503252184987467839</name>
        <report_id>c078dad7-9d08-44b0-aa45-f2e374ee462a</report_id>
        <tags>
          <value>html</value>
          <value>obfuscated</value>
          <value>qrcode</value>
          <value>base64</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>19e3136afd62d84d8df2a712cb62fa7a60e0d1233c6649035b4b19e8cd50eed4</id>
    <title>Analysis Report for 19e3136afd62d84d8df2a712cb62fa7a60e0d1233c6649035b4b19e8cd50eed4</title>
    <updated>2026-05-11T04:29:37Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015b3b97e8658d088c815f</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a015b30792fe2d217aeda6f</flow_id>
        <hash>19e3136afd62d84d8df2a712cb62fa7a60e0d1233c6649035b4b19e8cd50eed4</hash>
        <iocs>
          <urls>
            <value>
              <url>http://80.253.249.169:5000/jaspert.exe</url>
              <origin>INPUT_FILE</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <ips>
            <value>
              <ip>80.253.249.169</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>024d0af72ce9d941345fbd89810f8b163f704b1fa8c9d7de690b6ce1b89c64d7</SHA-256>
              <SHA-1>33dd865972d9e859f0c6d269e20e3c1a98aeb361</SHA-1>
              <MD5>7d20b91879fd6a878f1017cb35e07e69</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>40e89281adccec20a52a36dbf66ce5d9065c72f312f3d8c00daba533cd002636</SHA-256>
              <SHA-1>832a2d33c1a0c009a095c71bc635f97e715bf3ab</SHA-1>
              <MD5>d75849a54a130023850a3d64ebb6a8a6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>4bb79dcea0a901f7d9eac5aa05728ae92acb42e0cb22e5dd14134f4421a3d8df</SHA-256>
              <SHA-1>4260284ce14278c397aaf6f389c1609b0ab0ce51</SHA-1>
              <MD5>1e4a89b11eae0fcf8bb5fdd5ec3b6f61</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>6d0e98a255637b9de8b3a8209a3fc1ac2640900afbb50c894dab7f3d4b3e501d</SHA-256>
              <SHA-1>73e8791caed32e996bc9ea75c9157e16f3e4673d</SHA-1>
              <MD5>d5c886064008ff75248e209260bb777e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>783f4e83bd26f0df77fef9d7936743d1cb6a532a9f262c3cf7249732bf647df6</SHA-256>
              <SHA-1>9bbfdcb1a63bf6a5c4e1234ae24cb2630587dbb2</SHA-1>
              <MD5>d0e01a3000e7b9f648d0e200483d4cdc</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>91e3c075ef585e0256e0b3f5943d9f35bf242865d33997b298798eea4cf6c931</SHA-256>
              <SHA-1>570a3bce0bdc74a57609da125b74ec2557ccec13</SHA-1>
              <MD5>5a0d50c3ed8d343f99cc8b9fb4b7dee3</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>9894cf0cd245ce829630d1faee0f982c05d764bf5134a93bcc1db866e59ee6b6</SHA-256>
              <SHA-1>c8453b2184e057a247587189f88d729180594d3b</SHA-1>
              <MD5>ca490e8e5aa73447bfbefd95ad3fc618</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>98a459401ee1230b2649f79bcb053512a7008e56290daeaf3655c74bf7bffea5</SHA-256>
              <SHA-1>d0e26b2119681d50bc0ae7374da33bb9ccb99524</SHA-1>
              <MD5>ca8b3e5736d9027d7937317eace9e7a2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>abad9885204bd3f1e18647ea2fb85b4d6a66ab017bbc8d0a2a6d8583ac340dbb</SHA-256>
              <SHA-1>85c1158d8b09896e02bf20cea6a633326630a7a7</SHA-1>
              <MD5>4e7b47bcffc61b958bbf8ccb2bb94dc6</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>b40a466eb8e9ebcf3ee6879d1e9cf2d223b40e85045c4848d7f4ea08a81e383a</SHA-256>
              <SHA-1>6a8c7bae85ccecaa05209ff66859fd6732a68a09</SHA-1>
              <MD5>f5ac7a8582f877bd0fb994ea46333d29</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>b7d77a75615bffd066f5a9d65c8512b6bce4ba42b0371bbd61a96249ed9fdad1</SHA-256>
              <SHA-1>016f1c8024bc2798195a837c1881c13d23ae8467</SHA-1>
              <MD5>bf137cc76b41544f48e9ff72d1fd7d04</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/png</file_type>
            </value>
            <value>
              <SHA-256>e896110e95973d05c23277edfa0974949654beeed5306136939e34afc5068f87</SHA-256>
              <SHA-1>4fe2e874eb1025eff5c3d05b6be8393957ccacd7</SHA-1>
              <MD5>8e9476d3725ad383edcab5aa03aa4db5</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>e3f7678e9bc3085bfad170c94d9436d2bd4de88bd55f807daa87d1784a13f915</SHA-256>
              <SHA-1>e6308d7231edb6ebb98238543929551f28edc42e</SHA-1>
              <MD5>f004f315667c49abf6ce507d7fd57be9</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
              <verdict>LIKELY_MALICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>x19e3136afd62d84d8df2a712cb62fa7a60e0d1233c6649035b4b19e8cd50eed4.exe</name>
        <report_id>4a9eb46d-4e85-4453-9be5-c63eba0ff50b</report_id>
        <tags>
          <value>peexe</value>
          <value>anti-debug</value>
          <value>anti-vm</value>
          <value>crypto</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>0e30b94418482ce6d0b8cfacb7fc4842571f48bf8732ca700e314af27da46b2d</id>
    <title>Analysis Report for 0e30b94418482ce6d0b8cfacb7fc4842571f48bf8732ca700e314af27da46b2d</title>
    <updated>2026-05-11T04:29:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015b14b87f27901eb5efb9</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a015b0c2fcb905ec28c81ee</flow_id>
        <hash>0e30b94418482ce6d0b8cfacb7fc4842571f48bf8732ca700e314af27da46b2d</hash>
        <iocs/>
        <name>fastflag_injector_gui_enhanced.exe</name>
        <report_id>876ba2e2-bb57-4031-bd25-cbbf50425190</report_id>
        <tags>
          <value>peexe</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
          <value>anti-debug</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bb3653b0d1b215e32abeaf6198b991ef9040997fa083b2cacd0ade7b0933119f</id>
    <title>Analysis Report for bb3653b0d1b215e32abeaf6198b991ef9040997fa083b2cacd0ade7b0933119f</title>
    <updated>2026-05-11T04:26:35Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015a85b87f27901eb5ef9f</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a015a7b7d31ad7bba4fe58f</flow_id>
        <hash>bb3653b0d1b215e32abeaf6198b991ef9040997fa083b2cacd0ade7b0933119f</hash>
        <iocs>
          <urls>
            <value>
              <url>http://schemas.microsoft.com/SMI/2005/WindowsSettings</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>http://schemas.microsoft.com/SMI/2016/WindowsSettings</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>schemas.microsoft.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>150.171.109.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>1.0.7.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>2.6.3.1</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>150.171.109.101</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>1b0aaa5d336b26b7de99a8b43c276058ad196588d7283b6e9def98951151ae26</SHA-256>
              <SHA-1>a55f3386669033d8c4f4447a21a5bcd45724c753</SHA-1>
              <MD5>640af5ac6e1168f90cea6856f777d202</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>6bda71eaee226fbd056f2563bb23023d1ac62a3ab93552e044ea5244e785ba78</SHA-256>
              <SHA-1>8c8a4d7b12aeaa85ec22ff6d594725eef13c8ba5</SHA-1>
              <MD5>d8edc24dd706bd2bbea1e5d943a43d9f</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>29840822-5B84-11D0-BD3B-00A0C911CE86</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>55272A00-42CB-11CE-8135-00AA004BB851</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>62BE5D10-60EB-11d0-BD3B-00A0C911CE86</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>860BB310-5D01-11d0-BD3B-00A0C911CE86</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>codepulse.exe</name>
        <report_id>d755cc31-0dee-47bb-9974-dc071515dd47</report_id>
        <tags>
          <value>peexe</value>
          <value>dotnet_pe</value>
          <value>asyncrat</value>
          <value>razy</value>
          <value>anti-vm</value>
          <value>evasive</value>
          <value>fingerprint</value>
          <value>anti-debug</value>
          <value>base64</value>
          <value>configsecuritypolicy</value>
          <value>hacktool</value>
          <value>lolbin</value>
          <value>mpcmdrun</value>
          <value>msconfig</value>
          <value>reconnaissance</value>
          <value>regedit</value>
          <value>schtasks</value>
          <value>vbnet</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>dbae2d0204aa489e234eb2f903a0127b17c712386428cab12b86c5f68aa75867</id>
    <title>Analysis Report for dbae2d0204aa489e234eb2f903a0127b17c712386428cab12b86c5f68aa75867</title>
    <updated>2026-05-11T04:24:25Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015a4ab87f27901eb5ef93</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0159f8792fe2d217aeda23</flow_id>
        <hash>dbae2d0204aa489e234eb2f903a0127b17c712386428cab12b86c5f68aa75867</hash>
        <iocs>
          <urls>
            <value>
              <url>https://www.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/?cbrd=1</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/howyoutubeworks?utm_source=ythp&amp;utm_medium=LeftNav&amp;utm_campaign=ytgen</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/signin?action_handle_signin=true&amp;app=desktop&amp;hl=en&amp;next=%2Fsignin_passive&amp;feature=passive&amp;hl=en</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/signin?action_handle_signin=true&amp;app=desktop&amp;hl=en&amp;next=https%3A%2F%2Fwww.youtube.com%2F</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/signin?action_handle_signin=true&amp;app=desktop&amp;hl=en&amp;next=https%3A%2F%2Fwww.youtube.com%2F&amp;feature=__FEATURE__</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://accountlinking-pa-clients6.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://accounts.google.com/ServiceLogin</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://accounts.google.com/ServiceLogin?service%5Cu003dyoutube%5Cu0026uilel%5Cu003d3%5Cu0026passive%5Cu003dtrue%5Cu0026continue%5Cu003dhttps%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252F%26feature%3D__FEATURE__%5Cu0026hl%5Cu003den</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://accounts.google.com/ServiceLogin?service=youtube%5Cu0026uilel=3%5Cu0026passive=true%5Cu0026continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252F%5Cu0026hl=en</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://accounts.google.com/ServiceLogin?service=youtube%5Cu0026uilel=3%5Cu0026passive=true%5Cu0026continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252F%5Cu0026hl=en%5Cu0026ec=65620</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://accounts.google.com/ServiceLogin?service=youtube&amp;uilel=3&amp;passive=true&amp;continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3D%252Fsignin_passive%26feature%3Dpassive&amp;hl=en</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://apis.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://client-channel.google.com/client-channel/client</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://clients4.google.com/invalidation/lcs/client</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://consent.youtube.com/d</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://consent.youtube.com/d?continue=https://www.youtube.com/%3Fcbrd%3D1%5Cu0026gl=DE%5Cu0026m=0%5Cu0026pc=yt%5Cu0026cm=2%5Cu0026hl=en%5Cu0026src=2%5Cu0026escs=AZ8E49CTpv6_VjDKtebAQYke9VcFRzEkq72350aFBWQgc9QKcuC12pjEtQ1LgrYrgVa9jl4B6qfnUx8mIKzFAdWJqzHyj8fBRKPs</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://consent.youtube.com/d?continue=https://www.youtube.com/%3Fcbrd%3D1%5Cu0026gl=DE%5Cu0026m=0%5Cu0026pc=yt%5Cu0026oyh=1%5Cu0026cm=6%5Cu0026hl=en%5Cu0026src=4</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://consent.youtube.com/save</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://consent.youtube.com/save?continue=https://www.youtube.com/%5Cu0026gl=DE%5Cu0026m=0%5Cu0026pc=yt%5Cu0026x=5%5Cu0026src=2%5Cu0026hl=en%5Cu0026bl=911651045%5Cu0026cm=2%5Cu0026set_eom=false%5Cu0026set_apyt=true%5Cu0026set_ytc=true%5Cu0026escs=AZ8E49BzbIET-FWw5QjxXhkzYWRxtwEsHOMRF3CkmowJmgvhTQ8TKXevBGlSeh0a5fln3B1FSIxHVQeAUBp7l2uSg2QaffD_HLW-</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://consent.youtube.com/save?continue=https://www.youtube.com/%5Cu0026gl=DE%5Cu0026m=0%5Cu0026pc=yt%5Cu0026x=5%5Cu0026src=2%5Cu0026hl=en%5Cu0026bl=911651045%5Cu0026cm=2%5Cu0026set_eom=true%5Cu0026escs=AZ8E49B8tQF1oIry_vQkaeCVVAXk36y0STWMnK5J2a4Jb0l7JoEi3FsoPl9dGmiqiPnMqYs6PMSazq85N_zkKtVpqcpPp6TkrhG0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://developers.google.com/youtube</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://families.google.com/webcreation?usegapi%5Cu003d1</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://i.ytimg.com/generate_204</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://m.youtube.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://payments.youtube.com/payments/v4/js/integrator.js?ss%5Cu003dmd</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://policies.google.com/privacy?hl=en</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://policies.google.com/technologies/cookies?hl=en</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://policies.google.com/terms?hl=en</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://studio.youtube.com/persist_identity</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.google.com/youtube/?p%5Cu003dcreator_community</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.google.com/youtube/answer/95725</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://support.google.com/youtube/contact/de_cancellation</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.gstatic.com/youtube/img/emojis/emojis-png-15.1.json</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/about/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/about/copyright/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/about/policies/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/about/press/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/ads/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/creators/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/csi_204</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/error_204?t=jserror&amp;level=ERROR</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/howyoutubeworks</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/howyoutubeworks?utm_campaign=ytgen&amp;utm_source=ythp&amp;utm_medium=LeftNav&amp;utm_content=txt&amp;u=https%3A%2F%2Fwww.youtube.com%2Fhowyoutubeworks%3Futm_source%3Dythp%26utm_medium%3DLeftNav%26utm_campaign%3Dytgen</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/opensearch?locale=en_US</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/_/ytmainappweb/_/js/k=ytmainappweb.kevlar_base.en_US.H6w3EUqm5ak.es5.O/am=AAAAAAgAEEg/d=1/rs=AGKMywHzu9tq9NAPW6upNylwI1XtpoEDfw/m=kevlar_base_module</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/_/ytmainappweb/_/js/k=ytmainappweb.kevlar_base.en_US.H6w3EUqm5ak.es5.O/am=AAAAAAgAEEg/d=1/rs=AGKMywHzu9tq9NAPW6upNylwI1XtpoEDfw/m=kevlar_base_module,kevlar_main_module,kevlar_base_sync_mod_chunk</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/_/ytmainappweb/_/ss/k=ytmainappweb.kevlar_base.KgArE42pGE8.L.B1.O/am=AAAAAAggEEw/d=0/rs=AGKMywE4gP0Z_syVQzIwEWBhnbk29kAmqA</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/cssbin/www-main-desktop-home-page-skeleton.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/cssbin/www-main-desktop-watch-page-skeleton.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/cssbin/www-onepick.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/img/favicon.ico</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/img/favicon_144x144.png</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/img/favicon_32x32.png</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/img/favicon_48x48.png</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/img/favicon_96x96.png</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/custom-elements-es5-adapter.vflset/custom-elements-es5-adapter.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/intersection-observer.min.vflset/intersection-observer.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/lottie-light.vflset/lottie-light.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/network.vflset/network.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/scheduler.vflset/scheduler.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/spf.vflset/spf.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/web-animations-next-lite.min.vflset/web-animations-next-lite.min.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/webcomponents-sd.vflset/webcomponents-sd.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/s/desktop/14cba078/jsbin/www-i18n-constants-en_US.vflset/www-i18n-constants.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.youtube.com/t/impressum?hl=de&amp;gl=DE</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://youtubei-att.googleapis.com/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.youtube.com/</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>accountlinking-pa-clients6.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>accounts.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>apis.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>client-channel.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>clients4.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>consent.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>developers.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>families.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>i.ytimg.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>m.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>payments.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>policies.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>studio.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>support.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.gstatic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>youtubei-att.googleapis.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>wght@300..900</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>142.251.14.113</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.102</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.110.94</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.91</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.102</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.92</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.136</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.119</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.139</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.84</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.110.101</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.95</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.110.190</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.139</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.84</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.101</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.102</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.113</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.102</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.119</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.127.92</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.91</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.110.101</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.110.94</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.110.190</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.136</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.95</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>31a293f50831d503cf281ad6458046b2694cc01f84b1cabf164c1eb77a438948</SHA-256>
              <SHA-1>ebe3b48a25a7dd8f59bc916892cd5394b1d2cd65</SHA-1>
              <MD5>837642949e956ea37fa160ff91eeb787</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>992c72c0514bcb286e73769a7a148df06b4f66db8ee67679c203745fd12b06b9</SHA-256>
              <SHA-1>650bfdc3366292564a1b503a543a491e0af6d558</SHA-1>
              <MD5>9a7e26ce2a523d1d776f26fc7de5ba28</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>487bb11042c0d8fa0fdbafd00035a92e055bbaedf7b72a12e7a172b1f35205f8</SHA-256>
              <SHA-1>603c711c0abcf8e3eb6d9aa222a2df96b9f57f9f</SHA-1>
              <MD5>60b4cc1d22ed88ef78b1b65b011ba1e2</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>69c744d3002f76cb205076cc3f79671501b70f17a8564eb02f9705c515ed411e</SHA-256>
              <SHA-1>f536bdd0f98f23d6c859e9b37c26c8e8bc96b661</SHA-1>
              <MD5>8f621b5b8401d33aeffd9dc99a0d872a</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>823614463d57f0fe28ca89a7fb57af71ada12d1c9e6719fc74ab3a39cb8d311a</SHA-256>
              <SHA-1>eecbeec281b82ded13f79fb08add9462cf6bcdd8</SHA-1>
              <MD5>519fc280f1baace437c5f5eed5562c23</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>b41954a580fa3b5c6c27ee46b62660f053ae624b42d39c9e8d57d539b6dbcaf5</SHA-256>
              <SHA-1>1723d97453327e6c1e07ff2f2ef50bd2f6b0391e</SHA-1>
              <MD5>37342d49f5ba1fb20ccbc4fcf82467ed</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>94ba76ed9323807ef830ffd8bf27d9bf15bd1e6e79f3e2e604fb589005b9ec06</SHA-256>
              <SHA-1>8dd3613a20b1d1c2ee2dd32788ff42261804f22a</SHA-1>
              <MD5>a80d166ec1b3b221c6df959a4d85ff3e</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>hxxps://www.youtube.com/</name>
        <report_id>42901c39-167f-4cc8-a3e3-dd4b30fa2f5f</report_id>
        <tags>
          <value>html</value>
          <value>obfuscated</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b3fda80664eaa527564d391151d6a04110fd974d7b6378e280bade6721908cc6</id>
    <title>Analysis Report for b3fda80664eaa527564d391151d6a04110fd974d7b6378e280bade6721908cc6</title>
    <updated>2026-05-11T04:24:20Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015a09b87f27901eb5ef85</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0159f22fcb905ec28c8085</flow_id>
        <hash>b3fda80664eaa527564d391151d6a04110fd974d7b6378e280bade6721908cc6</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>5eefb8b64f9c7b097352c2d5a78a2e24e3a957717e0e0369b9c3a923a6f2b838</SHA-256>
              <SHA-1>b341465c5db053e7f9d7d47af8274c2df416b486</SHA-1>
              <MD5>8d78f5716ca836775484aefa23bbb0b9</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>xb3fda80664eaa527564d391151d6a04110fd974d7b6378e280bade6721908cc6.exe</name>
        <report_id>fa3ca2df-7995-45d1-88e7-1cda16f85fc5</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>windows</value>
          <value>wirenet</value>
          <value>keylogger</value>
          <value>stealer</value>
          <value>compiled-script</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>fdec74d2b2dc90c74224ffc300fd034edb8087b6e3df9d022ffe42c4c63f7bcf</id>
    <title>Analysis Report for fdec74d2b2dc90c74224ffc300fd034edb8087b6e3df9d022ffe42c4c63f7bcf</title>
    <updated>2026-05-11T04:22:31Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01599c97e8658d088c8115</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01598586e92bda702712fe</flow_id>
        <hash>fdec74d2b2dc90c74224ffc300fd034edb8087b6e3df9d022ffe42c4c63f7bcf</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>b299973efa142040b4afaf13c3ed912462a73ad11190f948881ab2e9344dbf7a</SHA-256>
              <SHA-1>137930651184fcdbf53101352047b981188eb76e</SHA-1>
              <MD5>641ebbe9c3a6f10cfff451acde3f976a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>xfdec74d2b2dc90c74224ffc300fd034edb8087b6e3df9d022ffe42c4c63f7bcf.exe</name>
        <report_id>911a99bd-44e5-4370-9be2-de5036b96122</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>windows</value>
          <value>wirenet</value>
          <value>keylogger</value>
          <value>stealer</value>
          <value>compiled-script</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>312154d379d214b525b361e9670bb1b55b23c1fefd989a3e01fa7cf4f0274811</id>
    <title>Analysis Report for 312154d379d214b525b361e9670bb1b55b23c1fefd989a3e01fa7cf4f0274811</title>
    <updated>2026-05-11T04:22:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015993b87f27901eb5ef6f</_id>
        <file_type>application/octet-stream</file_type>
        <flow_id>6a01597f86e92bda702712f4</flow_id>
        <hash>312154d379d214b525b361e9670bb1b55b23c1fefd989a3e01fa7cf4f0274811</hash>
        <iocs/>
        <name>Tomodachi Life Living the Dream [010051F0207B2000][v65536][Up v1.0.1].nsp</name>
        <report_id>7c8a630c-67c1-4eaa-b188-1282c7236821</report_id>
        <tags>
          <value>data</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>227ae8bac300349305137c5bd330ae64a08e93bbdb644f6b76044512bbcaffc2</id>
    <title>Analysis Report for 227ae8bac300349305137c5bd330ae64a08e93bbdb644f6b76044512bbcaffc2</title>
    <updated>2026-05-11T04:21:37Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01595fb87f27901eb5ef65</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01594fdf14f1cb2acf733f</flow_id>
        <hash>227ae8bac300349305137c5bd330ae64a08e93bbdb644f6b76044512bbcaffc2</hash>
        <iocs>
          <urls>
            <value>
              <url>http://127.0.0.1:13556/</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <emails>
            <value>
              <email>A@I9.tGH9</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>127.0.0.1</ip>
              <origin>INPUT_FILE</origin>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>3f921d65d0ba465f97f4d44efb8a13ebb76f8df0dde7d69b42f78a9e8318b239</SHA-256>
              <SHA-1>3318c5cac272603074afea437f074fd6cefcef6a</SHA-1>
              <MD5>3ecf6a0cb6b6734b55a5d50a5ec9526d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>40e00feaf36dd48644183db051e77d2e3e681979dd7d85487106bdfb487448d3</SHA-256>
              <SHA-1>8ff556181b98151f9ff4ed4d6ad74f4a1dba7113</SHA-1>
              <MD5>72216d39b63d543cfac9a9749b7eb743</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <SHA-256>6f88bc7cb02ccb2dbc26b5f4ce53e355b331e31bb920b2ba8cbbcd1b5d4cd5a0</SHA-256>
              <SHA-1>dc9804dd3aa348fb0c05f53c53c698518af514a0</SHA-1>
              <MD5>9ce8c70178061cc4cf4a6bb1e291df93</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>87815d2465272c91fe090908eecc81c131bdf8cab345dddfd6bf2923d15bcd50</SHA-256>
              <SHA-1>0a3c625383f86d445e64991cfc7aece5202404c5</SHA-1>
              <MD5>4e516f61e3b575f4d68d463e105ddbe0</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>c49db3fb9a74c55628b2cf900ca305ede59e01d6332a000d23d0b44be9be06bf</SHA-256>
              <SHA-1>bbe465451083ea2dba8ac4bdf7bcce1e38df3c8c</SHA-1>
              <MD5>ad4e7a7a96e8a94df215a45a172ce7cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>c68a8549e03120f7bf393944a4658e79f8971a8ae8c12d06132372ba0f70c3de</SHA-256>
              <SHA-1>5841a738234eef8c278fa433590204f5b51f854d</SHA-1>
              <MD5>a6b5dce6809b89780a2374cd4f49b2ad</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>22ee32b3-adcb-4ac6-af97-449505754eff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>3b6d6c45-6377-4bf5-9792-dbf8e1881088</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>3fe8fa79-5dce-4503-ab23-464ea24babff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>6ec4ac45-cebc-4f80-aa83-b6b9d3a86ed7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>dd122e0a-fcf8-4dc5-9dbb-6afac5325183</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>Software\AppDataLow\Microsoft\Office</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office Test\AlwaysPersistentOrapiUT</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\Common\Licensing</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Policies\Microsoft</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Policies\Microsoft\Cloud</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Policies\Microsoft\Cloud\Office</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Policies\Microsoft\Office</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Policies\Microsoft\cloud\Office</registry>
              <origin>INPUT_FILE</origin>
            </value>
          </registry>
        </iocs>
        <name>x227ae8bac300349305137c5bd330ae64a08e93bbdb644f6b76044512bbcaffc2.exe</name>
        <report_id>a0c0f9be-e220-4054-8908-97b1fc29b533</report_id>
        <tags>
          <value>peexe</value>
          <value>xworm</value>
          <value>njrat</value>
          <value>unsafe</value>
          <value>anti-vm</value>
          <value>anti-debug</value>
          <value>overlay</value>
          <value>crypto</value>
          <value>expand</value>
          <value>fingerprint</value>
          <value>lolbin</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>71337a2781fc56028d08605c74c43e7ae462423bc0f71bcaafa4607d3b77de24</id>
    <title>Analysis Report for 71337a2781fc56028d08605c74c43e7ae462423bc0f71bcaafa4607d3b77de24</title>
    <updated>2026-05-11T04:20:12Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015916b87f27901eb5ef56</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0158fb2fcb905ec28c7ee1</flow_id>
        <hash>71337a2781fc56028d08605c74c43e7ae462423bc0f71bcaafa4607d3b77de24</hash>
        <iocs>
          <urls>
            <value>
              <url>http://downvideo.net/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://chrome.google.com/webstore/detail/video-downloader-plus/njgehaondchbmjmajphnhlojfnbfokng</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://fbdown.net</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://fbdown.net/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://twdown.net</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://twdown.net/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://use.fontawesome.com/531c15d395.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://yoodownload.com/</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>http://downvideo.net/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://chrome.google.com/webstore/detail/video-downloader-plus/njgehaondchbmjmajphnhlojfnbfokng</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fbdown.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fbdown.net/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fonts.googleapis.com/css?family=Quicksand:400,700</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fonts.gstatic.com/s/quicksand/v37/6xKtdSZaM9iE8KbpRA_hK1QN.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect?v=2&amp;tid=G-P6L7SWCSPS&amp;gtm=45je6562h1v9123080062za20g&amp;_p=1778473217610&amp;gcd=13l3l3l2l2l1&amp;npa=0&amp;dma_cps=a&amp;dma=1&amp;_eu=EBAI&amp;are=1&amp;cid=157813020.1778473218&amp;frm=0&amp;ir=1&amp;pscdl=noapi&amp;rcb=15&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;_s=1&amp;tag_exp=0~115938466~115938469~118012009~118463262~118719172&amp;dl=https%3A%2F%2Fyoodownload.com%2F&amp;dt=Online%20Video%20Downloader%20-%20Youtube%20to%20MP3%20Converter&amp;sid=1778473217&amp;sct=1&amp;seg=0&amp;_tu=wAQ&amp;en=page_view&amp;_fv=1&amp;_ss=1&amp;_ee=1&amp;tfd=586</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://twdown.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://twdown.net/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://use.fontawesome.com/531c15d395.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://use.fontawesome.com/531c15d395.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://use.fontawesome.com/releases/v4.7.0/css/font-awesome-css.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://use.fontawesome.com/releases/v4.7.0/fonts/fontawesome-webfont.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google-analytics.com/analytics.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google-analytics.com/j/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google-analytics.com/j/collect?v=1&amp;_v=j102&amp;a=882396161&amp;t=pageview&amp;_s=1&amp;dl=https%3A%2F%2Fyoodownload.com%2F&amp;ul=en-us&amp;dt=Online%20Video%20Downloader%20-%20Youtube%20to%20MP3%20Converter&amp;sr=800x600&amp;vp=1905x1080&amp;_u=IEBAAEABAAAAACAAI~&amp;jid=836233610&amp;gjid=592243531&amp;cid=157813020.1778473218&amp;tid=UA-73123505-1&amp;_gid=1197542167.1778473218&amp;_r=1&amp;_slc=1&amp;z=874477638</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-P6L7SWCSPS&amp;cx=c&amp;_slc=1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/css/bootstrap.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/favicon.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/all-video-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/facebook-video-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/instagram-video-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/soundcloud-music-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/twitter-video-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/vid.me-video-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/vimeo-video-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/yoodownload-youtube-vimeo-facebook-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/yoodownload.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/youtube-music-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/img/youtube-video-downloader.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/js/bootstrap.bundle.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/js/jquery.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/js/scripts.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://yoodownload.com/&amp;dt=Online</url>
              <origin>URL_RENDER</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://yoodownload.com/&amp;ul=en-us&amp;dt=Online</url>
              <origin>URL_RENDER</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>chrome.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>downvideo.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>fbdown.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>fonts.googleapis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>fonts.gstatic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>region1.google-analytics.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>twdown.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>use.fontawesome.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.google-analytics.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>yoodownload.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>chrome.google.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>downvideo.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>fbdown.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>twdown.net</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>use.fontawesome.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>142.251.13.139</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.94</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.110.138</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.95</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.14.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.67.142.245</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.67.210.194</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>216.239.34.36</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.67.142.245</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.13.139</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.67.142.245</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>78c878e8b4c9d342911ff3b63da283a3625e736c34a95772dbe7b9bccab353de</SHA-256>
              <SHA-1>3264ba7c9c5c381c35b645af991e4a305ee3cf62</SHA-1>
              <MD5>b0fb702a77168b3826489b757a892ed2</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>204b97742c05b3d9fa343264513c1567ccc56038e99f4a4dbef587e432f55bf6</SHA-256>
              <SHA-1>49471ae8b594b083a280aa30eb91b9fb414a41a3</SHA-1>
              <MD5>11be724a8d1720774ed3992575c6ee18</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>85b14b6efac15caeb7136abe489144f59d4d58d7cd4d47ecaee3dfd3a846194b</SHA-256>
              <SHA-1>d877ab5add511c14e5411c167101ceb248ec39be</SHA-1>
              <MD5>9cc6926bbf90c40be319d309090714dc</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>1fe9218f020b2a32c830a6bd3d9d9245217ee20eb2357ce43d55a99adb0d7e75</SHA-256>
              <SHA-1>184f250a08e6ea37dfdfdea1ee62456b8c796f9b</SHA-1>
              <MD5>c0a12e0a715c6c3506cc4231360a107f</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>hxxps://yoodownload.com/</name>
        <report_id>474c614a-0330-48e7-af4e-ff02dfae778b</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>694225b879b40adc44c47acefe6aac67b0f3163d04fdc21af10b92d7e57e85e0</id>
    <title>Analysis Report for 694225b879b40adc44c47acefe6aac67b0f3163d04fdc21af10b92d7e57e85e0</title>
    <updated>2026-05-11T04:19:31Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0158f7d6e5cdb5619835d4</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0158d1fd9cdd68416ef4cc</flow_id>
        <hash>694225b879b40adc44c47acefe6aac67b0f3163d04fdc21af10b92d7e57e85e0</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <MD5>c02069700be997f065ff003c5da4c294</MD5>
              <SHA-1>44698d147f7f339edbd6ae46a5a37e81ab2e1f44</SHA-1>
              <SHA-256>3c4ecd16d6cdf2edd24c2ea651ea7dfcad691c532b50e136810573ff4385b1a0</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>f7a720d1700fae874a7ea7224dd82e78</MD5>
              <SHA-1>5b3448d443f581cc2720d675996aa35cd5087dcc</SHA-1>
              <SHA-256>659e0a29add9e00aa4fd8a0638de65c08f24afb40d7c1d0048e7a28221487e9e</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>x694225b879b40adc44c47acefe6aac67b0f3163d04fdc21af10b92d7e57e85e0.exe</name>
        <report_id>ceca63c3-f0a8-4a29-a19d-c3e152826a14</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>keylogger</value>
          <value>packed</value>
          <value>anti-debug</value>
          <value>overlay</value>
          <value>compiled-script</value>
          <value>crypto</value>
          <value>reconnaissance</value>
          <value>fingerprint</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6398ffd81b9d81c7e836497c1a8500b48ba70b47ed028ebdc8de8a2747e82d80</id>
    <title>Analysis Report for 6398ffd81b9d81c7e836497c1a8500b48ba70b47ed028ebdc8de8a2747e82d80</title>
    <updated>2026-05-11T04:19:09Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0158c797e8658d088c80ee</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0158ba2fcb905ec28c7e97</flow_id>
        <hash>6398ffd81b9d81c7e836497c1a8500b48ba70b47ed028ebdc8de8a2747e82d80</hash>
        <iocs>
          <ips>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>3f921d65d0ba465f97f4d44efb8a13ebb76f8df0dde7d69b42f78a9e8318b239</SHA-256>
              <SHA-1>3318c5cac272603074afea437f074fd6cefcef6a</SHA-1>
              <MD5>3ecf6a0cb6b6734b55a5d50a5ec9526d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>6c62416a7e0dbc669092567cbaed66858792e5433423fdbc655aeaf49363a57d</SHA-256>
              <SHA-1>407f9fbd66d898f94ac01ec8e3998ab4a0c8377a</SHA-1>
              <MD5>cf28ecc49688e85f620909018e8dfa8c</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <SHA-256>6f88bc7cb02ccb2dbc26b5f4ce53e355b331e31bb920b2ba8cbbcd1b5d4cd5a0</SHA-256>
              <SHA-1>dc9804dd3aa348fb0c05f53c53c698518af514a0</SHA-1>
              <MD5>9ce8c70178061cc4cf4a6bb1e291df93</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>3fe8fa79-5dce-4503-ab23-464ea24babff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>x6398ffd81b9d81c7e836497c1a8500b48ba70b47ed028ebdc8de8a2747e82d80.exe</name>
        <report_id>a18901fc-74b0-4726-841f-5d3ec2a9a529</report_id>
        <tags>
          <value>peexe</value>
          <value>xworm</value>
          <value>njrat</value>
          <value>unsafe</value>
          <value>anti-vm</value>
          <value>anti-debug</value>
          <value>overlay</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1642daa9d6adfa645cdbd5d7b7fc5ab267c6de23f760ab8db32a839a7217dd2e</id>
    <title>Analysis Report for 1642daa9d6adfa645cdbd5d7b7fc5ab267c6de23f760ab8db32a839a7217dd2e</title>
    <updated>2026-05-11T04:18:11Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01589797e8658d088c80e4</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0158812fcb905ec28c7e4b</flow_id>
        <hash>1642daa9d6adfa645cdbd5d7b7fc5ab267c6de23f760ab8db32a839a7217dd2e</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>a8089328e971e0cf8916eff6343edf416f2b7cec0e53d03b3779e06f47d21076</SHA-256>
              <SHA-1>20d4e772406f99576c03e51f54d5b056a1bea78a</SHA-1>
              <MD5>532062f7f650d52117caf19208007c34</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>x1642daa9d6adfa645cdbd5d7b7fc5ab267c6de23f760ab8db32a839a7217dd2e.exe</name>
        <report_id>d3729984-d3ef-4e6d-8f9e-5b757bf68cd2</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>windows</value>
          <value>wirenet</value>
          <value>keylogger</value>
          <value>stealer</value>
          <value>anti-debug</value>
          <value>compiled-script</value>
          <value>overlay</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6c58bb5161bd1596edef005d2c774b23cf2383f13ebe964fde00f4f14d8608d8</id>
    <title>Analysis Report for 6c58bb5161bd1596edef005d2c774b23cf2383f13ebe964fde00f4f14d8608d8</title>
    <updated>2026-05-11T04:17:23Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015862b87f27901eb5ef34</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0158502fcb905ec28c7deb</flow_id>
        <hash>6c58bb5161bd1596edef005d2c774b23cf2383f13ebe964fde00f4f14d8608d8</hash>
        <iocs>
          <urls>
            <value>
              <url>https://crashpad.chromium.org/</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://crashpad.chromium.org/bug/new</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>crashpad.chromium.org</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <emails>
            <value>
              <email>appro@openssl.org</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.121</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.20.121</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>3f921d65d0ba465f97f4d44efb8a13ebb76f8df0dde7d69b42f78a9e8318b239</SHA-256>
              <SHA-1>3318c5cac272603074afea437f074fd6cefcef6a</SHA-1>
              <MD5>3ecf6a0cb6b6734b55a5d50a5ec9526d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>47110bca2f8aaf7ecf3c1667f2c9ddb49c814ed611289f8d0df5dc707c24c23b</SHA-256>
              <SHA-1>857e62aeaa7a71fe57620e565d6719a6c2a90a18</SHA-1>
              <MD5>84a26067feca90930eb439f3c1af45c1</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>592f3f1fb6ee234d82e031c097101c94628767cdbb80a6579fe4d3fb5b1204c5</SHA-256>
              <SHA-1>20410adb97361b73277bc3c1c9e57906570ef784</SHA-1>
              <MD5>fd73f9aacf36138310d6de07d5775425</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <SHA-256>6f88bc7cb02ccb2dbc26b5f4ce53e355b331e31bb920b2ba8cbbcd1b5d4cd5a0</SHA-256>
              <SHA-1>dc9804dd3aa348fb0c05f53c53c698518af514a0</SHA-1>
              <MD5>9ce8c70178061cc4cf4a6bb1e291df93</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>a3e0bfa9c0cdd9f77be96f3160ac50b36ac36fa93da23bd877c8c9e3050e1a41</SHA-256>
              <SHA-1>51cedfcb01fc2b27e76db4186bc4f5098966b235</SHA-1>
              <MD5>3f8f0bdc227d5cde0919e7b6f3c3a814</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>c49db3fb9a74c55628b2cf900ca305ede59e01d6332a000d23d0b44be9be06bf</SHA-256>
              <SHA-1>bbe465451083ea2dba8ac4bdf7bcce1e38df3c8c</SHA-1>
              <MD5>ad4e7a7a96e8a94df215a45a172ce7cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>6b76c016c434b495617204d7d661540c9e82b4fe64fba35515aecae9a12d16f4</SHA-256>
              <SHA-1>fdf177e061f2e2c9acf5a210963f4b6e0cb74d76</SHA-1>
              <MD5>a1c673ec20043178772a3c4ddc860c9a</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>45e811c5d8cecc68286e99e910a2eada01da4b57f04842836ace43e40c294e79</SHA-256>
              <SHA-1>8f1ad661262a9071cd20057252c3060573f3e3f9</SHA-1>
              <MD5>bc38cb0322ff88398f71231c4d4a8d29</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>3fe8fa79-5dce-4503-ab23-464ea24babff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Macromedia\FlashPlayerPepper</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows NT\CurrentVersion</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>SOFTWARE\Policies\Google\Chrome</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Google\Update\ClientState\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</registry>
              <origin>INPUT_FILE</origin>
            </value>
          </registry>
        </iocs>
        <name>x6c58bb5161bd1596edef005d2c774b23cf2383f13ebe964fde00f4f14d8608d8.exe</name>
        <report_id>102b413c-5bd8-4c1f-b7b6-1189f88df349</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>xworm</value>
          <value>neshta</value>
          <value>njrat</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>anti-vm</value>
          <value>anti-debug</value>
          <value>lolbin</value>
          <value>rundll32</value>
          <value>crypto</value>
          <value>explorer</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>5eed2b5832483191e67f2ffbdcf349a6256039a8a7f934fb6bb9188873f8a73b</id>
    <title>Analysis Report for 5eed2b5832483191e67f2ffbdcf349a6256039a8a7f934fb6bb9188873f8a73b</title>
    <updated>2026-05-11T04:15:16Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01587eb87f27901eb5ef3b</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a0157d22fcb905ec28c7d26</flow_id>
        <hash>5eed2b5832483191e67f2ffbdcf349a6256039a8a7f934fb6bb9188873f8a73b</hash>
        <iocs>
          <ips>
            <value>
              <ip>207.241.225.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>45.60.101.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>207.241.225.157</ip>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>45.60.101.227</ip>
              <origin>EXTRACTED_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>0d140bc4d51d45eb4afc9975b0c925a048feaccbc1b30f8226a2fc09707ba58e</SHA-256>
              <SHA-1>f695f0d05f5d2c545f414682b2e6b4a6e9fe7823</SHA-1>
              <MD5>1484a7ed8f1626c67df86222ebdb795d</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>28be4c65bdb5368a8a37cc0b6d2ce05db5a6949be37ebd6ac19dd07f1aa57082</SHA-256>
              <SHA-1>c5aa8e40fafb2175ca2466b7ef5aff05a8b054f8</SHA-1>
              <MD5>71b404010843ccaa94857642e508d984</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>380a52770d031344fef77d052f3faf46c37b81c4d1275d6c22cb252d88ade0bd</SHA-256>
              <SHA-1>d770ef64c693ee4a02fd5250481d299c51dfe392</SHA-1>
              <MD5>0dac7b832c241b2bf280f495782562ab</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>380f239cee009fc9f5d75eec64141aec0d3fe81894016a6ccb3cf445b94bf747</SHA-256>
              <SHA-1>545acb9bf3e3acdd916b64f9d42807e0bda8c182</SHA-1>
              <MD5>6aa4953b8f639bc4252b2083d6f95f01</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>41bf4186b756b039749a7b3ff4f1705c5b48f399572492f9e44b6cd37fb2d36a</SHA-256>
              <SHA-1>c85cfcac0acf92ae2249a74c4b11f6d7c9723d0c</SHA-1>
              <MD5>d5f3eac694f567f0f1688ffe927004d2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>4c359b5b3872db77661d148b0f11638e3045854ba702788ac59f5be6d1a8c1c0</SHA-256>
              <SHA-1>96fa64e4054fc0897016ded457bbf6b235e3616d</SHA-1>
              <MD5>8a56f412514743f10b3895e0c3a1cd8a</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>539dc26a14b6277e87348594ab7d6e932d16aabb18612d77f29fe421a9f1d46a</SHA-256>
              <SHA-1>cac699787884fb993ced8d7dc47b7c522c7bc734</SHA-1>
              <MD5>b7db84991f23a680df8e95af8946f9c9</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>5848919ab5bc11a721c097e3ca567b20efc4cc5abe8919cdd532985697138bbf</SHA-256>
              <SHA-1>10fb1cbf4bc78eddf0373d2b2291c08969b6d07b</SHA-1>
              <MD5>d6f7eedb9e4c66a4b19a00f600a6cdba</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>602e53bb8c151a7c1fabb39c68284cc0027fd22796dbf256e182ec3596ce2e74</SHA-256>
              <SHA-1>53b02a9b8b9d0b9c6da3c5f60e2e103e045cdea0</SHA-1>
              <MD5>e08efdd8d8533f45a8417bede4ab5ccc</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>88aa9bcff8823303127c3cb585abfc47aa45d870799e1cc34ee170e3a514b14a</SHA-256>
              <SHA-1>e5d4cfd0c62ffddeceec544b35dcf8fd855465b2</SHA-1>
              <MD5>9da1f7eccf754f155dd5c02394c7f687</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>9d39798c0828c876cd62bdd8d1f602d284ab97a37548a066ee275544f514d471</SHA-256>
              <SHA-1>33ff48f81f9b6dd011c2297c883e3d5720dc6f74</SHA-1>
              <MD5>cdcea22fc902740d48a1ba4f11d20c46</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>a5dc23061d85fae7c25063f976d40f167ed8dc546b49cc139311197f0fe54cae</SHA-256>
              <SHA-1>a2516bf061d8fbc18efdf4a0139490e2d2b487cc</SHA-1>
              <MD5>1bfc9d7149c856cc8d82fe9913f37c1a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>b0f66adc83641586656866813fd9dd0b8ebb63796075661ba45d1aa8089e1d44</SHA-256>
              <SHA-1>7722745105e9e02e8f1aaf17f7b3aac5c56cd805</SHA-1>
              <MD5>7319468847d7b1aee40dbf5dd963c999</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>bbcdbb424d85fcd729d9e9c89a0204a625cd596f8b4023af53009e5203f8a18c</SHA-256>
              <SHA-1>1b2c444db964a9d33af1a959ed3f30f0ea58fe25</SHA-1>
              <MD5>45225636cfcd1bb3e6970a7b5b18ea56</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>be809cba9d14bfb52a969d766992832b10e99e133babcdd99dc6d1bba5597cf7</SHA-256>
              <SHA-1>59f426938522ef9906b0740821e8cc270d1ca897</SHA-1>
              <MD5>841795bb3b61ebd511249778aa26af77</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>cab0d242b139d5280da8d5b48b379b65e8533752e1c57dd42efc7a1a831560d5</SHA-256>
              <SHA-1>025d40865cb33107d47450cff6d26736b305fbf2</SHA-1>
              <MD5>0c4540a7b5847138438ab441d593b341</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>dc6ee4edbbbe1116a200b928f2b62dbc55594a9f79152bbb0076161a58546c11</SHA-256>
              <SHA-1>56dd0b4bbc5ddcc3fab99ea2e8f781d8b7c7c05f</SHA-1>
              <MD5>979b597855746aee2f30ee74f9d7c163</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e4b594d18793e49d8e03caf7050bfd4ebd530e157f89323db9dfc1432db362b3</SHA-256>
              <SHA-1>a528879b87b2bedcc02e00f2313208fea11df3cb</SHA-1>
              <MD5>4afe6c8bed71f801875b250ade4fb06b</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>ed9f02e795f4bbabee61828f32363958aacbbd07900875b22ffc1a57c252357a</SHA-256>
              <SHA-1>fa1b070307df97fcc2cdd0ea582496800616ce9b</SHA-1>
              <MD5>aaf3afb585b569015fbab6fd3cf10afc</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>f48f290eb745c650267e2402d030d3f517771e4717efff690bfdbbd692764c07</SHA-256>
              <SHA-1>844c4c7e48b64b6492e06d2c9d536f6c8b392898</SHA-1>
              <MD5>496e30d458e84735eee5a01166315414</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>fc4b36ccfdf0e1c76396252d8f272c2220814662ce7df50d72d58e72f9b1375c</SHA-256>
              <SHA-1>14481e53943df1dca6b3b9f7b85f33fc1f91a109</SHA-1>
              <MD5>2ba70cc81fa007354b559b1374b32e33</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>2251d8074037580989b076d13b9297d452224b95ce0f78209e924b5b3e7b5b7a</SHA-256>
              <SHA-1>ff733e11a83f248702fd90c17c197df96d5b8014</SHA-1>
              <MD5>e0f41796a5561b386bf4085b241ce0ee</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>6a866ba4daa87a583005fa2d712b12656a541aae86f7c54c1817bb497abdf00c</SHA-256>
              <SHA-1>5afa6327477081200c1d38f97609fda6cf79e01b</SHA-1>
              <MD5>0e1b6fe034649effa13540de31298712</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>70faa0e1498461731f873d3594f20cbf2beaa6f123a06b66f9df59a9cdf862be</SHA-256>
              <SHA-1>97bb45f4076083fca037eee15d001fd284e53e47</SHA-1>
              <MD5>9232120b6ff11d48a90069b25aa30abc</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>84a1c2713642090523f05d9fb015c537fd210d3200cadaf442bb67cf1834b356</SHA-256>
              <SHA-1>946501d358e5e3b10223431e474607e0eb248796</SHA-1>
              <MD5>a4b9662cf3b6ea6626f6081c0d8c13f3</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>8eba94e94bb22256792f7d762ea6a6da96d94943f8525037e35bfdbb086f8bde</SHA-256>
              <SHA-1>ccd54d8040af8d925902896033fc535afd3a9ac2</SHA-1>
              <MD5>deca1e6067fd7c34dac1d5bfaee7ee8e</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/x-font-ttf</file_type>
            </value>
            <value>
              <SHA-256>910e370790c67a0882e352134744fce3d6fd990208a6332a6aef28cb88198491</SHA-256>
              <SHA-1>e879cc25fdd4e11a74e973b33df644e602728650</SHA-1>
              <MD5>16dd12483e8a85de0bbd31b0c7d50660</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>95374cf300097872a546d89306374e7cf2676f7a8b4c70274245d2dccfc79443</SHA-256>
              <SHA-1>6e8f668cba211f1c3303e4947676f2fc9e4a1bcc</SHA-1>
              <MD5>d2774b188ab5dde3e2df5033a676a0b4</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>video/mp4</file_type>
            </value>
            <value>
              <SHA-256>a103e54a29914d8b930cad7fb7cf99061dbdc5b3d47e2a27797071d4fe80b91f</SHA-256>
              <SHA-1>2abd23f8d076cf390b92231e4e9f9eb0a209270f</SHA-1>
              <MD5>7b03c5254971d461a261feb6118347d8</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>b18604254c223c6b3b56b10bcf3caf9b07ac967d6c0626a5ae8472ec44cf8bd4</SHA-256>
              <SHA-1>f155b7685b9e5b63fefab9ca0958772fa81876ce</SHA-1>
              <MD5>b73032c7921e596509a179f1e0780029</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>text/x-msdos-batch</file_type>
            </value>
            <value>
              <SHA-256>ef2fd3a239aa65c7c9cb204e5ae003ddd6a80d439c59f813e76d4e68987a259a</SHA-256>
              <SHA-1>af9309ded2d9ba50e51c83c791ac6aa6ced07fc8</SHA-1>
              <MD5>5e163b1f0c2e5bc318b58d39fd34acce</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>application/rtf</file_type>
            </value>
            <value>
              <SHA-256>f5f56b42be58680d2f666321e3c1d1d16e6b41406250e5226dfa723faef797cd</SHA-256>
              <SHA-1>775254045145cd3a0097fbfc7b069a62beee134d</SHA-1>
              <MD5>b35ffe3dc03de62e10b5dc3f5fa5e77c</MD5>
              <origin>DOTNET_RESOURCES</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>3722f82f9df2efd8da8cae6ec74a255bf20013b7092445a5917373f337c09231</SHA-256>
              <SHA-1>292e4f60b42e1ab8adff3084cdc9cc10f6569a1f</SHA-1>
              <MD5>3bf11f202cfa7da060040abfb45f6541</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>000 (7).exe</name>
        <report_id>fe07d096-a82c-4d5d-84eb-f8633c79206c</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>dotnet_pe</value>
          <value>crypt</value>
          <value>diztakun</value>
          <value>xpack</value>
          <value>locky</value>
          <value>ransomware</value>
          <value>unsafe</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>hacktool</value>
          <value>adaptive-context</value>
          <value>explorer</value>
          <value>lolbin</value>
          <value>net</value>
          <value>persistence</value>
          <value>regedit</value>
          <value>taskkill</value>
          <value>wmic</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>52982608c3b46a7c9628409acf63a026446b5c6d496f60151e87d043b44e482c</id>
    <title>Analysis Report for 52982608c3b46a7c9628409acf63a026446b5c6d496f60151e87d043b44e482c</title>
    <updated>2026-05-11T04:15:10Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157e1b87f27901eb5ef1c</_id>
        <file_type>message/rfc822</file_type>
        <flow_id>6a0157cd86e92bda7027118f</flow_id>
        <hash>52982608c3b46a7c9628409acf63a026446b5c6d496f60151e87d043b44e482c</hash>
        <iocs>
          <urls>
            <value>
              <url>https://lightningwarrior.com/braze/unsubscribe/8954/24436200</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://lightningwarrior.com/d16d02990359cf6088127f6d2b7481</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpgla_gcek.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://lightningwarrior.com/d16d02990359cf6088127f6d2b7481</url>
              <origin>URL_RENDER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>lightningwarrior.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>lightningwarrior.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>76.223.54.146</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>76.223.54.146</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>d6549e1113e7f9298d5dc83cb5c414cb8c61b19dd360d6a61fd36fba1a2e1ae3</SHA-256>
              <SHA-1>64741aa9de30b1d059a2dd4a1af8f1cd1aee0c93</SHA-1>
              <MD5>b99c798072821ac19f54d321f974701a</MD5>
              <origin>EMAIL_BODY</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>6dc9c7fc93bb488bb0520a6c780a8d3c0fb5486a4711aca49b4c53fac7393023</SHA-256>
              <SHA-1>f9d9055e9878723a12063b47d4a1a5f58c3eb1e9</SHA-1>
              <MD5>e89f75f918dbdcee28604d4e09dd71d7</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>submission.eml</name>
        <report_id>849ab59f-77c0-41c4-aac2-e80a4aea4a7f</report_id>
        <tags>
          <value>eml</value>
          <value>rfc822</value>
          <value>html</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>7bcc217ffda3778617a1d2a699001e956ccd0797da522e861d8b563006099d65</id>
    <title>Analysis Report for 7bcc217ffda3778617a1d2a699001e956ccd0797da522e861d8b563006099d65</title>
    <updated>2026-05-11T04:13:43Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015781b87f27901eb5ef08</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0157762fcb905ec28c7cbe</flow_id>
        <hash>7bcc217ffda3778617a1d2a699001e956ccd0797da522e861d8b563006099d65</hash>
        <iocs>
          <ips>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>3f921d65d0ba465f97f4d44efb8a13ebb76f8df0dde7d69b42f78a9e8318b239</SHA-256>
              <SHA-1>3318c5cac272603074afea437f074fd6cefcef6a</SHA-1>
              <MD5>3ecf6a0cb6b6734b55a5d50a5ec9526d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>64388b9d1cabb50c529103662cac51ac8ca87d5bf1db3106fee985142d221971</SHA-256>
              <SHA-1>6ac5d7114c7a7edcdc0a6d3b1714bd5c04529a1a</SHA-1>
              <MD5>71805c5c4cda137c449b4df3dbe310ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>6f88bc7cb02ccb2dbc26b5f4ce53e355b331e31bb920b2ba8cbbcd1b5d4cd5a0</SHA-256>
              <SHA-1>dc9804dd3aa348fb0c05f53c53c698518af514a0</SHA-1>
              <MD5>9ce8c70178061cc4cf4a6bb1e291df93</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>be1a590a5f85d6fa9f134792ff96a95c11ea70376d67fb34fb8c22356ba69309</SHA-256>
              <SHA-1>7914329ce5020a0855ee94b5f6ada2a8166a401f</SHA-1>
              <MD5>8fbb6360dee2146668decfc962dbdf48</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>c49db3fb9a74c55628b2cf900ca305ede59e01d6332a000d23d0b44be9be06bf</SHA-256>
              <SHA-1>bbe465451083ea2dba8ac4bdf7bcce1e38df3c8c</SHA-1>
              <MD5>ad4e7a7a96e8a94df215a45a172ce7cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>3fe8fa79-5dce-4503-ab23-464ea24babff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>x7bcc217ffda3778617a1d2a699001e956ccd0797da522e861d8b563006099d65.exe</name>
        <report_id>e4068ee9-e464-436d-86d6-deb0c828ec78</report_id>
        <tags>
          <value>peexe</value>
          <value>xworm</value>
          <value>njrat</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>anti-vm</value>
          <value>anti-debug</value>
          <value>crypto</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c74ca36fe0d82406f3517083f329b2d00af182d6703e6d8132967ae010aa9451</id>
    <title>Analysis Report for c74ca36fe0d82406f3517083f329b2d00af182d6703e6d8132967ae010aa9451</title>
    <updated>2026-05-11T04:13:40Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015783b87f27901eb5ef09</_id>
        <file_type>application/x-msdownload; format=pe64</file_type>
        <flow_id>6a0157722fcb905ec28c7cb4</flow_id>
        <hash>c74ca36fe0d82406f3517083f329b2d00af182d6703e6d8132967ae010aa9451</hash>
        <iocs>
          <ips>
            <value>
              <ip>120.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>121.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>122.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>123.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>124.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>7ecb74e32b542a4379fd60b3049e06e0a9014d5c9c6367219bd4725b2573448c</SHA-256>
              <SHA-1>d926ceb8548697643cb614ac9a90dd7e1ecb2c90</SHA-1>
              <MD5>ac1da33fb8aa7d042d2f5f42f97f2149</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
          </files>
          <registry>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>agent.dll</name>
        <report_id>de4a9397-5ba0-42a0-ae35-8d6f5f4fa24e</report_id>
        <tags>
          <value>peexe</value>
          <value>pedll</value>
          <value>meterpreter</value>
          <value>magniber</value>
          <value>ransomware</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>dllhost</value>
          <value>explorer</value>
          <value>packed</value>
          <value>crypto</value>
          <value>expand</value>
          <value>lolbin</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>9095add4ea30fd462cb3da684eaf3b7876de7cb0205d89d09b50b3018f015605</id>
    <title>Analysis Report for 9095add4ea30fd462cb3da684eaf3b7876de7cb0205d89d09b50b3018f015605</title>
    <updated>2026-05-11T04:12:39Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01575ab87f27901eb5eeff</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0157352fcb905ec28c7c58</flow_id>
        <hash>9095add4ea30fd462cb3da684eaf3b7876de7cb0205d89d09b50b3018f015605</hash>
        <iocs>
          <urls>
            <value>
              <url>https://backpack.exchange/join/ef026e7d-e056-4ff2-83e7-db101ac032c9</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.google-analytics.com/g/collect?v=2&amp;tid=G-P8BPDKVWT5&amp;gtm=45je6562v883240104za200zd883240104&amp;_p=1778472763326&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;dma_cps=a&amp;dma=1&amp;are=1&amp;cid=1109162364.1778472763&amp;frm=0&amp;pscdl=noapi&amp;rcb=15&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;_s=1&amp;tag_exp=0~115938466~115938469~118463261~118494634&amp;dp=%2Fes%2Fhome%3Furl%3Dhttps%253A%252F%252Fok.ru%252Fvideo%252F12268240439835%2523lst&amp;sid=1778472763&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fwww.savethevideo.com%2Fes%2Fhome%3Furl%3Dhttps%253A%252F%252Fok.ru%252Fvideo%252F12268240439835%2523lst&amp;dt=Descargador%20de%20video%20en%20l%C3%ADnea%20y%20convertidor%20%5BActualizado%202026%5D&amp;en=page_view&amp;_fv=1&amp;_nsi=1&amp;_ss=1&amp;_ee=1&amp;ep.anonymize_ip=true&amp;tfd=257</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.facebook.com/savethevideo</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-P8BPDKVWT5</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/app-79a40aacc6259b0ae0cd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/component---src-pages-converter-js-685b59edf71b090d20f9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/component---src-pages-downloader-js-f9608bfb6d81a9540225.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/component---src-pages-home-js-fbd4b4a7b81e8d448bf0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/component---src-pages-sites-js-247dd8b439a99cb1c2f6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/component---src-pages-terms-js-3dbdd82a7d925a3a1271.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/ea2fca050d18f21b2a4f13c9a2d674143af94247-3452622bab27dc2ed0e1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/es/home</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/es/home?url=https%3A%2F%2Fok.ru%2Fvideo%2F12268240439835%23lst</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/favicon-32x32-2f4c07a604135121803ebab75c8c4f82.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/framework-483c38d17e6be8378a1e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/icons/icon-144x144-2f4c07a604135121803ebab75c8c4f82.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/manifest.webmanifest</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/page-data/app-data.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/page-data/es/converter/page-data.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/page-data/es/downloader/page-data.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/page-data/es/home/page-data.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/page-data/es/sites/page-data.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/page-data/es/terms/page-data.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/page-data/sq/d/1733565625.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/styles.7cff0ead49d9127b40a7.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/webpack-runtime-1ad6313ab0644c21ee84.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/?utm_source=savethevideo.com&amp;utm_medium=referral&amp;utm_campaign=stvideo-home&amp;ttref=stvideo-home</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/feature-ai-super-resolution.htm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/feature-ai-super-resolution.htm?utm_source=savethevideo.com&amp;utm_medium=referral&amp;utm_campaign=stvideo-home-ai&amp;ttref=stvideo-home-ai</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/video-converting-software/feature-video-compressing.htm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/video-converting-software/feature-video-compressing.htm?utm_source=savethevideo.com&amp;utm_medium=referral&amp;utm_campaign=stvideo-home-compress&amp;ttref=stvideo-home-compress</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://x.com/savethevideo</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>2Fok.ru</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://ok.ru/video/12268240439835#lst</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/es/home?url=https%3A%2F%2Fok.ru%2Fvideo%2F12268240439835%23lst&amp;dt=Descargador</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>savethevideo.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>savethevideo.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://backpack.exchange/join/ef026e7d-e056-4ff2-83e7-db101ac032c9</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.facebook.com/savethevideo</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-P8BPDKVWT5</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.savethevideo.com/ar/home</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.savethevideo.com/de/home</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.savethevideo.com/es/home</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://www.savethevideo.com/fr/home</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.savethevideo.com/home</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/it/home</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/nl/home</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/pt/home</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/tr/home</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/?utm_source=savethevideo.com&amp;utm_medium=referral&amp;utm_campaign=stvideo-home&amp;ttref=stvideo-home</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/feature-ai-super-resolution.htm</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/es/video-converting-software/feature-ai-super-resolution.htm?utm_source=savethevideo.com&amp;utm_medium=referral&amp;utm_campaign=stvideo-home-ai&amp;ttref=stvideo-home-ai</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/video-converting-software/feature-video-compressing.htm</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.videoproc.com/video-converting-software/feature-video-compressing.htm?utm_source=savethevideo.com&amp;utm_medium=referral&amp;utm_campaign=stvideo-home-compress&amp;ttref=stvideo-home-compress</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://x.com/savethevideo</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://ok.ru/video/12268240439835#lst</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://www.savethevideo.com/es/home</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://www.savethevideo.com/es/home?url=https%3A%2F%2Fok.ru%2Fvideo%2F12268240439835%23lst</url>
              <origin>INPUT_FILE</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>backpack.exchange</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>region1.google-analytics.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.savethevideo.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.videoproc.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>x.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>backpack.exchange</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>googletagmanager.com</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.savethevideo.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.videoproc.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>x.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>142.251.14.97</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.21.77.134</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.21.77.134</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.20.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>216.239.34.36</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>157.240.253.35</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.67</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>169.46.112.249</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.67</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.97</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>157.240.253.35</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.21.77.134</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>169.46.112.249</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>8a40b56f7cd510c464aa0b1e7fa348551afcc579b0be6f7977bd7fe9f8487d4f</SHA-256>
              <SHA-1>558560a1b859c229da578c95a89a51b5730c2bae</SHA-1>
              <MD5>68b670498b68bae4c624e709c45a01aa</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>b28a6999f348647124fe17b3d3f4e0bef4bb28bae421c3a84c76e92e26ddca2b</SHA-256>
              <SHA-1>274d9f82bc0085a9a30ad1ee03cef50a34fcba6b</SHA-1>
              <MD5>fde579814a7206ca0abf0c78fc22816d</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>bdee938f353a868828c198d083b35083525ff3afa6c87ec626697d6f27e994b3</SHA-256>
              <SHA-1>d349d883a83450207a0e0383dfa4c7c081f318a0</SHA-1>
              <MD5>570230a1a833daf8bc54f4cfb14cf828</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>759ab24c199defd5ce33ec3519aa13e4314ec6f623bae1524bf93c2a8050083e</SHA-256>
              <SHA-1>443cc6c91597f5a62009ecf47e875bd3a2a13089</SHA-1>
              <MD5>7bdd156bf511cfb776f8b977a4875c72</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>bff308e65288d72dc307f9a324b9026b9adc25db435a4d95b6cdfde6e6a4440e</SHA-256>
              <SHA-1>af4bc36a57d774e7c7bd2eeb342c437f6256932a</SHA-1>
              <MD5>48029ece1bdbd07a0ec9541232abe82d</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-ini</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>e55c4e2b26fae2e0f48fd294a3cdbe389a243f690933ce5005331b763e3dcd30</SHA-256>
              <SHA-1>5bcca46abaf2c422f4b0d3923fb8d1e6699bf2e2</SHA-1>
              <MD5>790b4687a43e05c2f4ba8b2bde6b3135</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>0b052e050d4d9476f8621a64b1171a3f70b890d81ba67529a0729b155f8ba37d</SHA-256>
              <SHA-1>bf950c235a4bf478656b5c3d30eb04f143b2e7d9</SHA-1>
              <MD5>f45620748422e554c8986e7bb399febb</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>05fdf97913b2358fe6a2abc2eff0653959cfa3d07c5f19baa91d897924fe48c1</SHA-256>
              <SHA-1>3b81123fab20d237aa43b99b54545db34f6b4cfd</SHA-1>
              <MD5>86f21ad4ceea35b98f7ec1615983d2ea</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>e653534289655f0cbb5fdc9e83bb0c5aa500508a6cd33b822587825afe145e32</SHA-256>
              <SHA-1>122b9c045167cb0bb6093057e852ec694cd1b8e3</SHA-1>
              <MD5>df390f6e97267ffb47ffefabb690b8cd</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>ef026e7d-e056-4ff2-83e7-db101ac032c9</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>hxxps://www.savethevideo.com/es/home?url=https%3A%2F%2Fok.ru%2Fvideo%2F12268240439835%23lst</name>
        <report_id>b74ab7e4-e07b-49b0-9df4-bd5241a7247f</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>ini</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>973d8f133cabb91435901d626d384178c7dddcc9ea00a624b5dcef0c402dd15b</id>
    <title>Analysis Report for 973d8f133cabb91435901d626d384178c7dddcc9ea00a624b5dcef0c402dd15b</title>
    <updated>2026-05-11T04:11:24Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156fab87f27901eb5eeed</_id>
        <file_type>application/x-msdownload; format=pe64</file_type>
        <flow_id>6a0156ea2fcb905ec28c7bc6</flow_id>
        <hash>973d8f133cabb91435901d626d384178c7dddcc9ea00a624b5dcef0c402dd15b</hash>
        <iocs>
          <files>
            <value>
              <SHA-256>49b00c807bcee1e50bdc6752f1041982f609a2d8b270e82a5ad4ce97290898db</SHA-256>
              <SHA-1>f75a6e8eece7735113c5ad1acb5f29fd3402e31f</SHA-1>
              <MD5>f724e5d3fdae46ebfdcf8cb2c730e567</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>a73f26a8d504043f785d7360e8febf2eeb8522ec873a0d4dd5d1d4bfd1e67d3d</SHA-256>
              <SHA-1>6c93b8c5fde8be4b2231dca6b8ec513cdc82c991</SHA-1>
              <MD5>5aa04ce935e78505e230765e85c34355</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <btc_wallets>
            <value>
              <btc_wallet>1742577f9a46d5671a55aa5d4c184d55</btc_wallet>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </btc_wallets>
        </iocs>
        <name>stager.exe</name>
        <report_id>16e2da91-9a30-4b0b-9afa-548cce9fb3a9</report_id>
        <tags>
          <value>peexe</value>
          <value>unsafe</value>
          <value>exploit</value>
          <value>overlay</value>
          <value>anti-debug</value>
          <value>dllhost</value>
          <value>lolbin</value>
          <value>packed</value>
          <value>crypto</value>
          <value>expand</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ced82528b08a52a9a0aaaffdeda31641897e0973685562506f88674a3da1cf98</id>
    <title>Analysis Report for ced82528b08a52a9a0aaaffdeda31641897e0973685562506f88674a3da1cf98</title>
    <updated>2026-05-11T04:10:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156c1b87f27901eb5eee1</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0156b7792fe2d217aed919</flow_id>
        <hash>ced82528b08a52a9a0aaaffdeda31641897e0973685562506f88674a3da1cf98</hash>
        <iocs>
          <urls>
            <value>
              <url>http://nsis.sf.net/NSIS_Error</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>nsis.sf.net</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <emails>
            <value>
              <email>Pseudochromia@Uovervindelighed.Te1</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>104.18.21.237</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.21.237</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>27696bbeca252447cd36391adf04dc2b446b319a4b06b8e5a48668957d00ef05</SHA-256>
              <SHA-1>9430a139e39427ebddbc89f59cd23dcdbd79d322</SHA-1>
              <MD5>1ae8e9847cd22cd7d60a83f7694d7e27</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>31e86baa33fe26cb64a41263b0f24c2a483ad0aff4c8abc2e6095abb8ace9769</SHA-256>
              <SHA-1>67aa3801dfdff0c20aa9348ceb9f9843eff2f71a</SHA-1>
              <MD5>db5aa155f527a0f20bbc59bef3201713</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>439931f0aaa24d3332f84ea45d40f93b56b2948c56be92e78482a1989a491a61</SHA-256>
              <SHA-1>286a35bda40b16a5d53a950a66bb7ba0ccade96e</SHA-1>
              <MD5>2ff34998dea0aab0118e1239e551d446</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>54b90b989ee83351d8e6b8d5639fb2c002bd46170fa740cdae262b955a8f6405</SHA-256>
              <SHA-1>beaae5129019a5454294f1804b829bb0e5bb945c</SHA-1>
              <MD5>bb53605fedbf654872c06a776f4f0fff</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/x-nsis-decompiled</file_type>
            </value>
            <value>
              <SHA-256>5fdca3348172651116726134565e6e46a1e82aadfc9ba57a6fa5333d7329d3b2</SHA-256>
              <SHA-1>6b6a5bf85ec16aa642d412a3af631dfe41ec7559</SHA-1>
              <MD5>f7084a1fb0f96f967b4977b3fc4c6c14</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>6e22059433c4c4beb58c5c237e3cced842e612f959eb9798e16e8e3d1d53ff00</SHA-256>
              <SHA-1>844ac0f5e026d789ee73cefdeb27f5d237dceafa</SHA-1>
              <MD5>38f4dad87089422df42ec16bc4afa76b</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>a08dd0e0312fe1deef7249595439907fd55fb3c40eb20b196e59257a0dc9a93b</SHA-256>
              <SHA-1>9faa761d737c7a877977ec323fda6e3eb358d530</SHA-1>
              <MD5>518bfa899841fff60798bffd3558b9a6</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Chiropterygium146\', '0', 1</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\driverlivs', 'mineas', 0</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\nabolaget\', '0', 1</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\regnebrts\', '0', 0</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
          </registry>
        </iocs>
        <name>_ced82528b08a52a9a0aaaffdeda31641897e0973685562506f88674a3da1cf98.exe</name>
        <report_id>b821da7c-57b7-4fd4-a81c-2a23d32fc00c</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>installer</value>
          <value>reconnaissance</value>
          <value>nsis</value>
          <value>microsoft_visual_cc</value>
          <value>signed</value>
          <value>adaptive-context</value>
          <value>anti-debug</value>
          <value>evasive</value>
          <value>packed</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bfd73c28ecb41ef5a41fd54f8f34123f5f64189032a99b58e36b15da749d751d</id>
    <title>Analysis Report for bfd73c28ecb41ef5a41fd54f8f34123f5f64189032a99b58e36b15da749d751d</title>
    <updated>2026-05-11T04:10:15Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157220f7e400110050b86</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01567c86e92bda7027105b</flow_id>
        <hash>bfd73c28ecb41ef5a41fd54f8f34123f5f64189032a99b58e36b15da749d751d</hash>
        <iocs>
          <urls>
            <value>
              <url>http://nudist-movies.top</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://nudist-movies.top/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/main.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/lazrjlh.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=3808472437&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/tzh.cgi?9&amp;group=ban1</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpv592ywlw.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/analiz.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/ftt2/check.php?t=1778472693&amp;check=97d9f225fd8cc68cc92975adb41d75b9&amp;rand=412377</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/probaee/1.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/probaee/1.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/probaee/5.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/probaee/hots.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/probaee/playh.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://missnudist.eu/probaee/video.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://shhopper.org/uuj6.html</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/lazrjlh.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>missnudist.eu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>nudist-movies.top</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>51.91.57.135</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>51.91.57.135</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>95687545c2fcc6f85c12ba6c2fc30293</MD5>
              <SHA-1>3818bbc46630c1b412eab4c06a8b61a0d6c79bad</SHA-1>
              <SHA-256>5f4e9b53f5c9a8bcee66470f1a678e1e118a5915ed24045c0a52dd553bf4f0b3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>10a4edf661df23548f239ab25e9db1f9</MD5>
              <SHA-1>5772c62475e225be7d8cfb7cdf455ebedeaa344c</SHA-1>
              <SHA-256>6d97e946f69bccb1ce69cc776709c708d53611296d884f5909a941099ca22767</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>a3fb545e01ff1f3d93d69781c0fbfae3</MD5>
              <SHA-1>bad2f83c4475df0cafb74c4e0f1b96f46ead9170</SHA-1>
              <SHA-256>e991e26be5a09b063b234c0480eeeb2456352f288245c92bf1ac115b1fe51d6d</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>835c615164ea25f0c6493b03482cc660</MD5>
              <SHA-1>7062a5f6b4cb3e9c9a7435b754679c7dacbbe2fe</SHA-1>
              <SHA-256>4cd471783a843956a87d36f773558d765ffda72f84eee502792a8e78a5fa8fdb</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>e13c437030d0e87ae123d2279ce05a0b</MD5>
              <SHA-1>c08f38f051edf5e0507e2c36d5d7177b7cedb629</SHA-1>
              <SHA-256>c1c3f7acc736a902dfa2da430cc5a033c0e269f82bdde96de38f694ea13b4283</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>6d006a3eedab11d2da0fdb9d015e9b32</name>
        <report_id>552c8158-17ca-43c0-b367-f8bc6a38bab6</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
          <value>aidetect</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>9fb37b8fcacd904988abaf4a5b5e63fd180717db5a7c8ef3a18c36d0e66eda64</id>
    <title>Analysis Report for 9fb37b8fcacd904988abaf4a5b5e63fd180717db5a7c8ef3a18c36d0e66eda64</title>
    <updated>2026-05-11T04:10:08Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156b1d6e5cdb56198356f</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01569686e92bda7027107d</flow_id>
        <hash>9fb37b8fcacd904988abaf4a5b5e63fd180717db5a7c8ef3a18c36d0e66eda64</hash>
        <iocs/>
        <name>c5fea032376a23d53c23cca8c9cdc358</name>
        <report_id>2af3235b-a2af-4aa2-b21d-375dce958875</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1bcbad3d22788f6ef92d1c3621aaa74f27a82689dce41e4b81b29c491c4c7579</id>
    <title>Analysis Report for 1bcbad3d22788f6ef92d1c3621aaa74f27a82689dce41e4b81b29c491c4c7579</title>
    <updated>2026-05-11T04:10:05Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156add6e5cdb56198356d</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01568f2fcb905ec28c7b29</flow_id>
        <hash>1bcbad3d22788f6ef92d1c3621aaa74f27a82689dce41e4b81b29c491c4c7579</hash>
        <iocs/>
        <name>843a37b8796c700d4bdac8e5803dc024</name>
        <report_id>de7feeaa-bf6f-497d-9005-dc6f1c174ab5</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b097cbc7697351c0f730b05777251bae4ed26fd2681ea5cbf77ea34024b631d1</id>
    <title>Analysis Report for b097cbc7697351c0f730b05777251bae4ed26fd2681ea5cbf77ea34024b631d1</title>
    <updated>2026-05-11T04:09:59Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a7d6e5cdb561983568</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156882fcb905ec28c7b18</flow_id>
        <hash>b097cbc7697351c0f730b05777251bae4ed26fd2681ea5cbf77ea34024b631d1</hash>
        <iocs/>
        <name>b6782c54f732cd4daa1dd96bce4ae557</name>
        <report_id>c5066cb9-7df2-4469-968f-f31878e601ad</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6a7447acdae5f38f18a1208f0255811122e5c08e23a8da453e33532d2f8afd76</id>
    <title>Analysis Report for 6a7447acdae5f38f18a1208f0255811122e5c08e23a8da453e33532d2f8afd76</title>
    <updated>2026-05-11T04:09:59Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a8d6e5cdb561983569</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015689df14f1cb2acf7187</flow_id>
        <hash>6a7447acdae5f38f18a1208f0255811122e5c08e23a8da453e33532d2f8afd76</hash>
        <iocs/>
        <name>fdfe59846865c7754eb1a72f17b99d3d</name>
        <report_id>eacbf175-d548-42c7-9f01-d02e7ba8c710</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8f92a33ff3f133e96091bed7d80381dba44d170a2bb6e135e3b8137e0e03ef5d</id>
    <title>Analysis Report for 8f92a33ff3f133e96091bed7d80381dba44d170a2bb6e135e3b8137e0e03ef5d</title>
    <updated>2026-05-11T04:09:59Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a6d6e5cdb561983567</_id>
        <file_type>application/x-powershell</file_type>
        <flow_id>6a01568a2fcb905ec28c7b1e</flow_id>
        <hash>8f92a33ff3f133e96091bed7d80381dba44d170a2bb6e135e3b8137e0e03ef5d</hash>
        <iocs/>
        <name>98d063c582314d342496836d81623cee</name>
        <report_id>fe08b0da-9388-4a8f-a1a8-936b2b2d5461</report_id>
        <tags>
          <value>powershell</value>
          <value>obfuscated</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>64981eee1638b1be777c0a902cb36e66b39ae8d46bf027074ee9af73c06ccfdd</id>
    <title>Analysis Report for 64981eee1638b1be777c0a902cb36e66b39ae8d46bf027074ee9af73c06ccfdd</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01572e0f7e400110050b8c</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01567f792fe2d217aed8f6</flow_id>
        <hash>64981eee1638b1be777c0a902cb36e66b39ae8d46bf027074ee9af73c06ccfdd</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmpvaymr8_8.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/dencasgj.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/4.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/75.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/77.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/folder.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/main.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/u151.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/u164.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/u440.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/u711-r.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/ftt2/check.php?t=1778472378&amp;check=6708d5e1f8e3af4173748aea69e52ca0&amp;rand=439882</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://shhopper.org/uuj6.html</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/yanqr.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://nudistsmall.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://nudistsmall.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudistsmall.eu/analizpor.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/yanqr.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=1775169411&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>nudistsmall.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>nudist-movies.top</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.57.135</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>81d8623cfa3f7b40bc86282376430272</MD5>
              <SHA-1>72fcde1e63b512bb57ce55a17c514874a0e4cfb5</SHA-1>
              <SHA-256>00a0c890f45e99f511a66d4ff4590f75d95f2d1cff338a6cbc29208762ddecff</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>7935f8918584a3bf49cc40074a1b7587</MD5>
              <SHA-1>84fd00194dad651dc22e28850edfb5ebcc7a1c49</SHA-1>
              <SHA-256>03788ac3952552b1d8f0ea230d361dc098855f87302ac30ece82030ba74eed2a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ae9f3f78ce378e3120ede7b8dcbd5bf3</MD5>
              <SHA-1>d0e27ca24a89586f9c4b396fa494d2a1101724a6</SHA-1>
              <SHA-256>bbd6f344feaf8e96c2c3c449f329e54e911916ada39e69135d3460be4bbac1ee</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>c5dcf02bd1fde49867e9ed992d73cc60</MD5>
              <SHA-1>540b9173f593742aedb6b574c79f9e0c2d966465</SHA-1>
              <SHA-256>bd90a834e7b902c21348bf26107128bc55d03a053fcd52fa8994c9d82e476b40</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>f9adb197c77ac5fd3793c1f4606fe7f3</MD5>
              <SHA-1>f2efa2561f564373e6f148f62a979ecf717b7186</SHA-1>
              <SHA-256>8d4c993089e35c332ee8de01bc17f812cda2380d855bd2bddd416dc7721d73d5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>b4e0f156638b28cba461d1216216b128</name>
        <report_id>3e1286bf-a272-4384-a29c-b415de300df4</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8b84a4bd1108748f15bb6dcd0fff1e81b60e2da55490c1a4d07cc438f5b456fb</id>
    <title>Analysis Report for 8b84a4bd1108748f15bb6dcd0fff1e81b60e2da55490c1a4d07cc438f5b456fb</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157310f7e400110050b92</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01568386e92bda70271067</flow_id>
        <hash>8b84a4bd1108748f15bb6dcd0fff1e81b60e2da55490c1a4d07cc438f5b456fb</hash>
        <iocs>
          <urls>
            <value>
              <url>http://ww1.iclarfied.com/?tr_uuid=20260419-1134-17ae-96cf-97f4a81c9a09&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ww1.iclarfied.com/?tr_uuid=20260419-1134-17ae-96cf-97f4a81c9a09&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ww1.iclarfied.com/?tr_uuid=20260419-1134-17ae-96cf-97f4a81c9a09&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ww1.iclarfied.com/?tr_uuid=20260419-1134-17ae-96cf-97f4a81c9a09&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>ww1.iclarfied.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>ww1.iclarfied.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260419-1134-17ae-96cf-97f4a81c9a09</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260419-1134-17ae-96cf-97f4a81c9a09</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>57102e5bf6d017556c8b81da119b2f13</name>
        <report_id>955a9464-aa4f-407d-84ad-d5cb2923929d</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8fae7081871f0fa97bdb272ec24d8abc9959dbfd772dd3662e05762a30ba6a08</id>
    <title>Analysis Report for 8fae7081871f0fa97bdb272ec24d8abc9959dbfd772dd3662e05762a30ba6a08</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ee0f7e400110050b4c</_id>
        <file_type>application/x-msdownload</file_type>
        <flow_id>6a0156832fcb905ec28c7b0b</flow_id>
        <hash>8fae7081871f0fa97bdb272ec24d8abc9959dbfd772dd3662e05762a30ba6a08</hash>
        <iocs/>
        <name>741a0ac790c4888203e8870e00d4538a</name>
        <report_id>44d3791f-6e0a-4f1c-a390-f86c6a77743c</report_id>
        <tags>
          <value>peexe</value>
          <value>barys</value>
          <value>rogue</value>
          <value>tiny</value>
          <value>masm</value>
          <value>packed</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bfed7c6b7f24ca63d608ba4538234bfb0744a95643b1c686d270ba8ad6ef88ae</id>
    <title>Analysis Report for bfed7c6b7f24ca63d608ba4538234bfb0744a95643b1c686d270ba8ad6ef88ae</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01576d0f7e400110050bab</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01567ddf14f1cb2acf7174</flow_id>
        <hash>bfed7c6b7f24ca63d608ba4538234bfb0744a95643b1c686d270ba8ad6ef88ae</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.01906.loan/?&amp;tr_uuid=20260508-1025-33d7-bf62-2deb65ab1c0c&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.01906.loan/?&amp;tr_uuid=20260508-1025-33d7-bf62-2deb65ab1c0c&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.01906.loan/?&amp;tr_uuid=20260508-1025-33d7-bf62-2deb65ab1c0c&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.01906.loan</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>01906.loan</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.189</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.189</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.189</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1025-33d7-bf62-2deb65ab1c0c</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1025-33d7-bf62-2deb65ab1c0c</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>5723b6759b2960972ab847d79a4f1599</name>
        <report_id>7e6104a7-d878-40fb-a61a-f7984299f027</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b35f2dd09f20d8661a1276c121d916ef09265b4597102a260478bcbe03b1def1</id>
    <title>Analysis Report for b35f2dd09f20d8661a1276c121d916ef09265b4597102a260478bcbe03b1def1</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157350f7e400110050b94</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01567d2fcb905ec28c7b01</flow_id>
        <hash>b35f2dd09f20d8661a1276c121d916ef09265b4597102a260478bcbe03b1def1</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>5b5db30bce182eac144176584b2cc7ba</name>
        <report_id>338141a2-ad0f-4777-bd2d-2d4d50b5708b</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>98aa84be3befe9f384801ffcc4e1a4e626a94230ef55c8a50f7106293b1b265a</id>
    <title>Analysis Report for 98aa84be3befe9f384801ffcc4e1a4e626a94230ef55c8a50f7106293b1b265a</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157770f7e400110050bb1</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015681fd9cdd68416ef488</flow_id>
        <hash>98aa84be3befe9f384801ffcc4e1a4e626a94230ef55c8a50f7106293b1b265a</hash>
        <iocs>
          <urls>
            <value>
              <url>http://tdv.aqwltxhs.club/index.php?amp;cPath=57&amp;amp;products_id=144309&amp;main_page=product_info&amp;&amp;tr_uuid=20260508-1022-328f-a57c-0f24b5c6a479&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>http://tdv.aqwltxhs.club/index.php?amp;cPath=57&amp;products_id=144309&amp;main_page=product_info&amp;&amp;tr_uuid=20260508-1022-328f-a57c-0f24b5c6a479&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>http://tdv.aqwltxhs.club/index.php?amp;cPath=57&amp;amp;products_id=144309&amp;main_page=product_info&amp;&amp;tr_uuid=20260508-1022-328f-a57c-0f24b5c6a479&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>tdv.aqwltxhs.club</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>tdv.aqwltxhs.club</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.189</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.189</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1022-328f-a57c-0f24b5c6a479</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1022-328f-a57c-0f24b5c6a479</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>7e747194c1302503c4f6bd116c6c494a</name>
        <report_id>c0f42f61-e58a-4bae-932a-f626b685d5fa</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c3c53eab61258d48671d61d06547ab1fbfd58dd8fc52fd11f63f59d6dae84134</id>
    <title>Analysis Report for c3c53eab61258d48671d61d06547ab1fbfd58dd8fc52fd11f63f59d6dae84134</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157150f7e400110050b79</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015681df14f1cb2acf717d</flow_id>
        <hash>c3c53eab61258d48671d61d06547ab1fbfd58dd8fc52fd11f63f59d6dae84134</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmp18rbtgr8.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js?pcId=53&amp;domain=my1w0c.pro</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/images/pe262/hero_nc.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parklogic.com/Contact-us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namecheap.com/domains/registration/results/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namecheap.com/domains/registration/results/?domain=my1w0c.pro</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>my1w0c.pro</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>parking3.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.namecheap.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.232.7.47</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>b4b95e968b9065ebc264e484c711c44b</MD5>
              <SHA-1>ed27d43d59b8fc14e66be6e503eccdc4388cb27e</SHA-1>
              <SHA-256>f62032e91ad749bc6f51d0a0f0410ba7034d50e975015c2a6870b3960fab25b5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>4e67cdfe05cf16eecf578682d2c5a39d</name>
        <report_id>ca2114e6-36f4-47aa-a9e5-3f604ad9eb49</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8c1941cb024114541a2812508b39b12fc9a31f47588f5df2472df664a8a5145d</id>
    <title>Analysis Report for 8c1941cb024114541a2812508b39b12fc9a31f47588f5df2472df664a8a5145d</title>
    <updated>2026-05-11T04:09:55Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01573c0f7e400110050b97</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015683df14f1cb2acf7180</flow_id>
        <hash>8c1941cb024114541a2812508b39b12fc9a31f47588f5df2472df664a8a5145d</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.dialogueincludes.com/?&amp;tr_uuid=20260508-1024-05d1-9722-bcea2274a40b&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.dialogueincludes.com/?&amp;tr_uuid=20260508-1024-05d1-9722-bcea2274a40b&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.dialogueincludes.com/?&amp;tr_uuid=20260508-1024-05d1-9722-bcea2274a40b&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.dialogueincludes.com/?&amp;tr_uuid=20260508-1024-05d1-9722-bcea2274a40b&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.dialogueincludes.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>dialogueincludes.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1024-05d1-9722-bcea2274a40b</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1024-05d1-9722-bcea2274a40b</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>e38157786ccf8ca3a4091345088f9781</name>
        <report_id>148edf12-4753-4a2f-abd6-9f186b6daa3b</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6ab8ca06615280e2a6b78c3b829e4092826734c51d62f74d9662a055fcb124ba</id>
    <title>Analysis Report for 6ab8ca06615280e2a6b78c3b829e4092826734c51d62f74d9662a055fcb124ba</title>
    <updated>2026-05-11T04:09:54Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ad0f7e400110050b09</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01568411d01437268907c4</flow_id>
        <hash>6ab8ca06615280e2a6b78c3b829e4092826734c51d62f74d9662a055fcb124ba</hash>
        <iocs/>
        <name>f1dc325ce9b03ebb6e6df84a9d1b3781</name>
        <report_id>7459edf4-f25b-4340-ae31-8c293ff8801e</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>45c9e3c93aebf7c5608130f1f244314c9844e15ba9c896e1a59b05da4fd1ea40</id>
    <title>Analysis Report for 45c9e3c93aebf7c5608130f1f244314c9844e15ba9c896e1a59b05da4fd1ea40</title>
    <updated>2026-05-11T04:09:54Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ae0f7e400110050b0b</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01568186e92bda70271063</flow_id>
        <hash>45c9e3c93aebf7c5608130f1f244314c9844e15ba9c896e1a59b05da4fd1ea40</hash>
        <iocs/>
        <name>41e51c2a3dc283082af63b927dbe575a</name>
        <report_id>b6b495f1-53b3-4649-8b0e-e597064da9bb</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>975e7f74820ee801b0bdafe00621fbd20b4f5a006754d17fea099df7941414a8</id>
    <title>Analysis Report for 975e7f74820ee801b0bdafe00621fbd20b4f5a006754d17fea099df7941414a8</title>
    <updated>2026-05-11T04:09:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01570f0f7e400110050b76</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01566886e92bda70271046</flow_id>
        <hash>975e7f74820ee801b0bdafe00621fbd20b4f5a006754d17fea099df7941414a8</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <MD5>c02069700be997f065ff003c5da4c294</MD5>
              <SHA-1>44698d147f7f339edbd6ae46a5a37e81ab2e1f44</SHA-1>
              <SHA-256>3c4ecd16d6cdf2edd24c2ea651ea7dfcad691c532b50e136810573ff4385b1a0</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <MD5>4746a41001ab31868da9e9c60d9728a0</MD5>
              <SHA-1>e1073522688277d1018fe0ab5b39385dc314da62</SHA-1>
              <SHA-256>cb541e42276d3bf4af6da081d791eac601fb09a27656428fb2b7cb50a2e1400a</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>x975e7f74820ee801b0bdafe00621fbd20b4f5a006754d17fea099df7941414a8.exe</name>
        <report_id>b6202956-da5c-4e87-a7a2-f16d5efc2775</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>keylogger</value>
          <value>packed</value>
          <value>anti-debug</value>
          <value>overlay</value>
          <value>compiled-script</value>
          <value>crypto</value>
          <value>reconnaissance</value>
          <value>fingerprint</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bd28bea6f25bcc2be6146f2178abc801230485e3c01715deb1d7e85cf52d447d</id>
    <title>Analysis Report for bd28bea6f25bcc2be6146f2178abc801230485e3c01715deb1d7e85cf52d447d</title>
    <updated>2026-05-11T04:09:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157680f7e400110050ba7</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01566b2fcb905ec28c7ada</flow_id>
        <hash>bd28bea6f25bcc2be6146f2178abc801230485e3c01715deb1d7e85cf52d447d</hash>
        <iocs>
          <urls>
            <value>
              <url>http://lanajoscafe.placeweb.site/?fp=-5/&amp;tr_uuid=20260508-1005-248b-bf6f-019ce02f41d9&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://lanajoscafe.placeweb.site/?fp=-5/&amp;tr_uuid=20260508-1005-248b-bf6f-019ce02f41d9&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://lanajoscafe.placeweb.site/?fp=-5/&amp;tr_uuid=20260508-1005-248b-bf6f-019ce02f41d9&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>lanajoscafe.placeweb.site</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>lanajoscafe.placeweb.site</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.247</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.247</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1005-248b-bf6f-019ce02f41d9</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1005-248b-bf6f-019ce02f41d9</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>6727455b8058800d0a00f96eac18f007</name>
        <report_id>47fbf64a-9e64-4c1d-b2a4-637be146ce1d</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ece15baa55e298bbd46e4ce88a160d03600e401ed60e90f6d2438e04f51d5452</id>
    <title>Analysis Report for ece15baa55e298bbd46e4ce88a160d03600e401ed60e90f6d2438e04f51d5452</title>
    <updated>2026-05-11T04:09:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01575a0f7e400110050ba3</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015674df14f1cb2acf716c</flow_id>
        <hash>ece15baa55e298bbd46e4ce88a160d03600e401ed60e90f6d2438e04f51d5452</hash>
        <iocs>
          <urls>
            <value>
              <url>http://caldnazza.com/?tr_uuid=20260508-1006-102f-ac92-e68f521fd12a&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpzb60j7m2.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://l.cdn-fileserver.com/bping.php</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://l.cdn-fileserver.com/bping.php?vi=1778472770299344361&amp;hvsid=00001778472770747000554803202651&amp;cc=DE&amp;sc=HE&amp;wsip=170764354&amp;requrl=https%3A%2F%2Fcaldnazza.com&amp;ssld=%7B%22QQNN%22%3A%22r4%22%2C%22QQN75%22%3A%22kL1zUkxL7n1YnY18z%22%2C%22QQ8E%22%3A%22%22%2C%22QQQN%22%3A%22q4%22%2C%22QQl8E%22%3A%22%22%7D&amp;prid=8PR11258V&amp;crid=319610148&amp;lper=100&amp;vgd_rpth=%2Fola&amp;gdpr=1&amp;mspa=0&amp;wshp=0&amp;r=1778472770749&amp;vgd_asn=16509&amp;vgd_tsce=L1226&amp;vgd_cage=18&amp;vgd_cdv=O3125&amp;vgd_l2type=dmola&amp;vgd_setup=c21&amp;ugd=4&amp;lf=6&amp;vgd_oreqf=one&amp;vgd_oresf=one&amp;vgd_wlstp=0&amp;cid=8CUW8U3H3&amp;vgd_len=567&amp;vgd_end=1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://rapidresultsearch.com/sr/754870121/SAFEFRAME.html?ule=913&amp;%21%21=ln&amp;%218yxw=&amp;%21_xw=C-NQ-j-LE&amp;%21qXY%29=k9bLVxX8%21&amp;%21qXYC=NWiQEoS1i&amp;%21wb=iC-%29%28&amp;%21xw=EZe6EeCgC&amp;%2AFxw=&amp;39=&amp;5FXV%21%21Vacy=&amp;5w9y_=&amp;5yRy=&amp;89%21a=d-%29%29Q&amp;9%21=gn&amp;99Rw=%7B%2299%21%21%22%3A%22ln%22%2C%2299%2185%22%3A%223_sXv3M_8+sY+YsxX%22%2C%2299xy%22%3A%22%22%2C%22999%21%22%3A%22gn%22%2C%2299Bxy%22%3A%22%22%7D&amp;9Fw_Sw=&amp;9xBa=--%28LcQEN&amp;Fa=j&amp;Fsa=&amp;Fw_Sw=&amp;Fxw=&amp;Fxwb%29=&amp;M9yaX3=j&amp;Mzw=L&amp;R%2985ya=wYkRs&amp;X8b=&amp;XYa__=-&amp;Y9ys=j&amp;_a2M_R=q88y9%3A%2F%2F%21sRwXsBBs~%21kY&amp;a%21_xw=&amp;bx=-mmELm%29mmj%29NNCLLCQ-&amp;htmlsrc=1&amp;kRs3=kXa&amp;kkdd=Hu%7CH%7C%2AAn9&amp;kxw=m3%28mjs%29-Aa3mNAL%21QCAsa%21sAC%29s%28-F%28NL3EN&amp;q88y9=-&amp;s%218=W4S3c4MX%2FBcz3pcc%2F%2FsB3aCBI2_cL3c_IB_&amp;sF3Ruxw=b%29&amp;sw8%29=&amp;sw8-=&amp;swb=&amp;swkYsxX=&amp;syZM=&amp;tpid=&amp;u9qy=j&amp;uR98y=j&amp;vu_3=&amp;vw=&amp;wY_3=-&amp;wa%21YYY=&amp;x9xw=j&amp;xX8%21R=EKn%2APm%28nT%3AiEdTpm%7CAaEn%3AMxx~MxM~hN~xq&amp;yxw=&amp;zwy_=-&amp;zwy_%21X98=&amp;eobd=&amp;eoac=RvYbkNvbY&amp;ure=1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://ww17.caldnazza.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://ww17.caldnazza.com/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://caldnazza.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://caldnazza.com/?tr_uuid=20260508-1006-102f-ac92-e68f521fd12a&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://caldnazza.com/?tr_uuid=20260508-1006-102f-ac92-e68f521fd12a&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>caldnazza.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>l.cdn-fileserver.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>rapidresultsearch.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>ww17.caldnazza.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>caldnazza.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>188.114.96.3</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>199.191.50.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>103.224.182.251</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.251</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1006-102f-ac92-e68f521fd12a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1006-102f-ac92-e68f521fd12a</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>61fe561429a444bb823bbf5194d927d9</name>
        <report_id>fbf6b769-c54d-4169-af4e-40ae05f74640</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>733a8b4ab3e919a8e086c64e2f8c453908e6852906a2a8e879d2bfd1c83db309</id>
    <title>Analysis Report for 733a8b4ab3e919a8e086c64e2f8c453908e6852906a2a8e879d2bfd1c83db309</title>
    <updated>2026-05-11T04:09:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157270f7e400110050b89</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0156752fcb905ec28c7af6</flow_id>
        <hash>733a8b4ab3e919a8e086c64e2f8c453908e6852906a2a8e879d2bfd1c83db309</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/pbpdy.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=1828816804&amp;ur=1&amp;HTTP_REFERER=&amp;haxvf=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/pbpdy.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0&amp;haxvf=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>263a80491cbb4a8898a2f5a7ef31694a</MD5>
              <SHA-1>f123c24ce1e9cd6bc069491caa85b58bc065e56f</SHA-1>
              <SHA-256>8e1e7c8a37a256e3f08c19e2ee8769e746785688ec0af4da2d1ac2ed695c9bd1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>2829e519f07e4e24f2eede11d4568a58</name>
        <report_id>cd29f095-4a19-4ce5-bc86-2004a54c286e</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>a452059df28813230c039f2ba1880b4b9a13afdb4bbbbb387d20d66255ff2e0d</id>
    <title>Analysis Report for a452059df28813230c039f2ba1880b4b9a13afdb4bbbbb387d20d66255ff2e0d</title>
    <updated>2026-05-11T04:09:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157700f7e400110050bad</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01567b86e92bda70271057</flow_id>
        <hash>a452059df28813230c039f2ba1880b4b9a13afdb4bbbbb387d20d66255ff2e0d</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.ww38.japantraveltip.info/?tr_uuid=20260508-1006-1622-8067-f2b56fb8ae56&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww38.japantraveltip.info/?tr_uuid=20260508-1006-1622-8067-f2b56fb8ae56&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww38.japantraveltip.info/?tr_uuid=20260508-1006-1622-8067-f2b56fb8ae56&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww38.japantraveltip.info/?tr_uuid=20260508-1006-1622-8067-f2b56fb8ae56&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpau4hlxub.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://ww38.ww38.japantraveltip.info/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://ww38.ww38.japantraveltip.info/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.ww38.japantraveltip.info</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>ww38.japantraveltip.info</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>ww38.ww38.japantraveltip.info</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.214</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.53.179.200</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>185.53.179.200</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.53.179.200</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.214</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>ec7e09474832675dbb80a5025397b969</MD5>
              <SHA-1>87dfca734906e1f5d01c0ba052be79a24d532c24</SHA-1>
              <SHA-256>36ba7944653fb4d17f5f1104562813853bf25b7e02a27aae744112c9b5cb4083</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9fe3cb2b7313dc79bb477bc8fde184a7</MD5>
              <SHA-1>4d7b3cb41e90618358d0ee066c45c76227a13747</SHA-1>
              <SHA-256>32f2fa940d4b4fe19aca1e53a24e5aac29c57b7c5ee78588325b87f1b649c864</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>4b074b0b59693fa9f94fb71b175fb187</MD5>
              <SHA-1>0004d4f82b546013424b2e0de084395071eef98b</SHA-1>
              <SHA-256>25fb23868ebf48348f9e438e00cb9b9d9b3a054f32482a781c762cc4f9cc6393</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>20260508-1006-1622-8067-f2b56fb8ae56</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1006-1622-8067-f2b56fb8ae56</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>bc4afcf746cf6f85cf60d59007f3a983</name>
        <report_id>a4db2ff5-cfb7-4b97-8f7f-58db5ad360be</report_id>
        <tags>
          <value>html</value>
          <value>aidetect</value>
          <value>phishing</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>02b9f3818551722739db00ef1c794949fdcc12e331403cff52811d213e9eab0d</id>
    <title>Analysis Report for 02b9f3818551722739db00ef1c794949fdcc12e331403cff52811d213e9eab0d</title>
    <updated>2026-05-11T04:09:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ea0f7e400110050b48</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015668df14f1cb2acf7164</flow_id>
        <hash>02b9f3818551722739db00ef1c794949fdcc12e331403cff52811d213e9eab0d</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/urzak.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/lzufn.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=3325829456&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/tzh.cgi?9&amp;group=ban1</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/urzak.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2714299408&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://videocollection.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://videocollection.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>videocollection.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>137.74.115.151</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>137.74.115.151</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>61cb1589829aa765202e98f367318a5e</MD5>
              <SHA-1>c6135d73b66a20b66ad75827e1d78d403cc7826f</SHA-1>
              <SHA-256>7e462085d47bffcc8f5e6c09962cad8322b2994f090ea663578ba09fdc65bf44</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>8651b03c24887a8534c44f17766fdb51</MD5>
              <SHA-1>172018f9c1f1b7ac182efd0958d456178621209e</SHA-1>
              <SHA-256>6fa307ca41d1250311bd3334ddebcafca4d2a6a9c7662423f11ba2b5b1a8dca2</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>0b6e295bb2aba0253c6af2bee5cfd29c</MD5>
              <SHA-1>349516411a77666493cbb02afd6517eec5039f11</SHA-1>
              <SHA-256>a0f9377b846ff691cc7f9ffa859cf31e24a09ca586cad63c138126bdef855fb9</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>b34691c4a47be7333c20d847c5626723</MD5>
              <SHA-1>77537c1dc9ba3395e823bb0d8646fd208f2935d6</SHA-1>
              <SHA-256>7402aa5d9c7862f64380e38f0fd0d881d6c91edb90ec0443ccd58e71cd27a2ce</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>d07449b3f3cb30361116c6ad76fdfe02</MD5>
              <SHA-1>84164d0b99879e1a5c9377623164058b2db5145d</SHA-1>
              <SHA-256>fc1d980628807732539148cadb70e62bc2ed20e9a3e1f72b4aa9f2c58478717c</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>5fe8f3a64e4162c31d691cfd31606a9a</MD5>
              <SHA-1>5b1883cbc1000e23aa0f4f22284c128a1d2141f8</SHA-1>
              <SHA-256>1e0a42d87dc548af944ee2e6f36a19c793e1ea441a223b6a7d60ffa0855dc4dd</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
        </iocs>
        <name>b204e200fe62ada643e4be93838f0970</name>
        <report_id>d25f5a20-3b82-443f-9554-35619bbd81f4</report_id>
        <tags>
          <value>html</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>9f21fb12e1020e40b5886b2fe091294b5fc3f6994dd5878efa30ac9fd3702f6d</id>
    <title>Analysis Report for 9f21fb12e1020e40b5886b2fe091294b5fc3f6994dd5878efa30ac9fd3702f6d</title>
    <updated>2026-05-11T04:09:51Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a0d6e5cdb561983563</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01567f86e92bda70271060</flow_id>
        <hash>9f21fb12e1020e40b5886b2fe091294b5fc3f6994dd5878efa30ac9fd3702f6d</hash>
        <iocs/>
        <name>cb267870d7b3f7642eb77e1b42c3b51f</name>
        <report_id>b81fa13e-ceb1-4d8c-9a59-a83022602c13</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e809acf6572e5ecc51a28c96bf94a189ad97cf809c050eb71334edceb07bfd42</id>
    <title>Analysis Report for e809acf6572e5ecc51a28c96bf94a189ad97cf809c050eb71334edceb07bfd42</title>
    <updated>2026-05-11T04:09:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156db0f7e400110050b38</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01566b7d31ad7bba4fe4f0</flow_id>
        <hash>e809acf6572e5ecc51a28c96bf94a189ad97cf809c050eb71334edceb07bfd42</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>43d0a189fd2e59762a74cdc714c0765c</name>
        <report_id>fd1c8c10-40ba-48d7-bd20-dcc6c57b5bc0</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>cc06e9294c494df995cff9a047c077be2d48849b13aab2530c757c3b4e2c6de5</id>
    <title>Analysis Report for cc06e9294c494df995cff9a047c077be2d48849b13aab2530c757c3b4e2c6de5</title>
    <updated>2026-05-11T04:09:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157490f7e400110050b9e</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01566bdf14f1cb2acf7166</flow_id>
        <hash>cc06e9294c494df995cff9a047c077be2d48849b13aab2530c757c3b4e2c6de5</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.wwellfargo.com/?tr_uuid=20260508-1005-36f9-adb2-7c5513b0340f&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.wwellfargo.com/?tr_uuid=20260508-1005-36f9-adb2-7c5513b0340f&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.wwellfargo.com/?tr_uuid=20260508-1005-36f9-adb2-7c5513b0340f&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>wwellfargo.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.wwellfargo.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.212.204</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.204</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.204</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1005-36f9-adb2-7c5513b0340f</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1005-36f9-adb2-7c5513b0340f</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>c67b96bbf51cfb2e5b6a6c7870d42590</name>
        <report_id>a148e9db-4e2d-4901-a95b-4bd1f2ce8595</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e681f3a4ad7ca3dd4fa718c1e5793f3e55ce6cdf54fa34889a353ba430fb16a5</id>
    <title>Analysis Report for e681f3a4ad7ca3dd4fa718c1e5793f3e55ce6cdf54fa34889a353ba430fb16a5</title>
    <updated>2026-05-11T04:09:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157040f7e400110050b69</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01566cfd9cdd68416ef485</flow_id>
        <hash>e681f3a4ad7ca3dd4fa718c1e5793f3e55ce6cdf54fa34889a353ba430fb16a5</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmp_rq410f5.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/4325213533/148.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/4325213533/266.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/4325213533/5942.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/4325213533/uVakZF0SbN.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/dasccs/newicoo.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/dasccs/null.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/dencasgj.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/dis/bgfooter.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://oldnudist.eu/ftt2/check.php?t=1778472651&amp;check=da9bdc2bd24050f88b4066a04bc39260&amp;rand=622861</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://shhopper.org/uuj6.html</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/kkisxpeuh.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://maturexxx.icu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://maturexxx.icu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/kkisxpeuh.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2060317510&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/tzh.cgi?9&amp;group=ban1</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>maturexxx.icu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>oldnudist.eu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>51.91.251.47</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>77.83.173.164</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>158392bfb7e2cd8da946a3ab02f671f9</MD5>
              <SHA-1>2f2d78e34e8aa5a365bbe0da6f356954d4b46317</SHA-1>
              <SHA-256>a9499c92956bbdab125cd489b02ffdccbfcdc412a917c214c0db9a42352e6694</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>1e9f1a0287ce5ea558c9d2e04d6dc438</MD5>
              <SHA-1>ab7684595ed1b20068eb24b2e666f31ccf83e3b9</SHA-1>
              <SHA-256>d9d32c3019c7eda0642e73286b6d2f0d9ed77b4cef1456d1cefcafd7a91bbef5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>290e9b1e25336d343607cfa021b61b9b</MD5>
              <SHA-1>88c485b9bef749747824a3647c12847c20bfa482</SHA-1>
              <SHA-256>c82d00eb4605e53d74d289ccbd5e101c632ce413482e4247debb178675a7e351</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>a3b247ebcc6fbf67d0f52487c433abbc</MD5>
              <SHA-1>ea60ae37948704b9238200e6fc587d77a0280509</SHA-1>
              <SHA-256>26009949476466f6e567b78bd42083d4af4f314d92c613d0e03b26f92c11ee6e</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>4219491ec158bc23e48bda100fc0255a</name>
        <report_id>83ef103a-1c8d-4f57-814d-138b263902a9</report_id>
        <tags>
          <value>html</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>2b072e515794ad9e6a800f5e34ae7697af0cbe2d9fd5c021d2b7b850c54100a0</id>
    <title>Analysis Report for 2b072e515794ad9e6a800f5e34ae7697af0cbe2d9fd5c021d2b7b850c54100a0</title>
    <updated>2026-05-11T04:09:47Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01570b0f7e400110050b6f</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01566d2fcb905ec28c7ae1</flow_id>
        <hash>2b072e515794ad9e6a800f5e34ae7697af0cbe2d9fd5c021d2b7b850c54100a0</hash>
        <iocs>
          <urls>
            <value>
              <url>http://rpnews168.store/?tr_uuid=20260508-1006-5673-b8a7-94e1be3ae254&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://rpnews168.store/?tr_uuid=20260508-1006-5673-b8a7-94e1be3ae254&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://rpnews168.store/?tr_uuid=20260508-1006-5673-b8a7-94e1be3ae254&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://rpnews168.store/?tr_uuid=20260508-1006-5673-b8a7-94e1be3ae254&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>rpnews168.store</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>rpnews168.store</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1006-5673-b8a7-94e1be3ae254</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1006-5673-b8a7-94e1be3ae254</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>acfaadbabe86e055db57551f2b05885a</name>
        <report_id>d9e4ec1e-51da-406f-90d9-3ac135b5010e</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8e926e979ffb12fe4854a97f9fab73ba46e85ac2478c56719a9152e18ac43c56</id>
    <title>Analysis Report for 8e926e979ffb12fe4854a97f9fab73ba46e85ac2478c56719a9152e18ac43c56</title>
    <updated>2026-05-11T04:09:47Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157250f7e400110050b88</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0156692fcb905ec28c7ad6</flow_id>
        <hash>8e926e979ffb12fe4854a97f9fab73ba46e85ac2478c56719a9152e18ac43c56</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/utitevcnp.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/utitevcnp.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=1070416544&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>5d5be8be3f197f7aa4d8dafac21a146a</MD5>
              <SHA-1>e0731d2fe2f03d48abb3f69dfe0d238f1c0bd3be</SHA-1>
              <SHA-256>ec724a9e515e7f604df7e23686762776f8301288109f09c06e8e7ef15cd11434</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>84b79bd3bcf6e60532e4fe3c8b0bdfde</name>
        <report_id>f937a49b-f4fb-41b9-814a-01de0bab8a9a</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>cc5507ce641ecfb9f2301f30af00adb77e534fc1a593345154e000fe75792409</id>
    <title>Analysis Report for cc5507ce641ecfb9f2301f30af00adb77e534fc1a593345154e000fe75792409</title>
    <updated>2026-05-11T04:09:47Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01569ad6e5cdb56198355e</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01567d9b72a1a5304c7711</flow_id>
        <hash>cc5507ce641ecfb9f2301f30af00adb77e534fc1a593345154e000fe75792409</hash>
        <iocs/>
        <name>b5ff1866d513b25887ce6cf2d3438534</name>
        <report_id>315a7367-613e-4af6-ad69-691e246f2843</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>a187e38bf135fea5c71acd36aa4709d65ee839d89bb91645b3b97bfcaa654c4d</id>
    <title>Analysis Report for a187e38bf135fea5c71acd36aa4709d65ee839d89bb91645b3b97bfcaa654c4d</title>
    <updated>2026-05-11T04:09:47Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01569cd6e5cdb56198355f</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01567edf14f1cb2acf7177</flow_id>
        <hash>a187e38bf135fea5c71acd36aa4709d65ee839d89bb91645b3b97bfcaa654c4d</hash>
        <iocs/>
        <name>44126e49ba81fe0e9321527f8fdbe0c5</name>
        <report_id>9f03c987-5fc9-48e6-af7a-6a817ba8ad29</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>4f7b268047cb4c2eb58d2ef3bd56460e4ac8b11453f2eff6d76e12591d4e2391</id>
    <title>Analysis Report for 4f7b268047cb4c2eb58d2ef3bd56460e4ac8b11453f2eff6d76e12591d4e2391</title>
    <updated>2026-05-11T04:09:37Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015693d6e5cdb56198355a</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156732fcb905ec28c7af2</flow_id>
        <hash>4f7b268047cb4c2eb58d2ef3bd56460e4ac8b11453f2eff6d76e12591d4e2391</hash>
        <iocs/>
        <name>c293df438ecc11e05a626cc9085c959f</name>
        <report_id>44834511-03e4-4d3f-a078-a92b620858d9</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>a312ac53ded8de9e0e5e244c7325f2c60a1631dec522475afb6822e9901fdf02</id>
    <title>Analysis Report for a312ac53ded8de9e0e5e244c7325f2c60a1631dec522475afb6822e9901fdf02</title>
    <updated>2026-05-11T04:09:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01568fd6e5cdb561983558</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01566e86e92bda7027104c</flow_id>
        <hash>a312ac53ded8de9e0e5e244c7325f2c60a1631dec522475afb6822e9901fdf02</hash>
        <iocs/>
        <name>8a66d6355b39518474b04c4ae52b891a</name>
        <report_id>43a70169-7a16-404e-89c4-8e2c38f2d4ef</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>5e28f84b7cc72e3d4aed760b38092bbd8af9b172011375a1863697b74aaef346</id>
    <title>Analysis Report for 5e28f84b7cc72e3d4aed760b38092bbd8af9b172011375a1863697b74aaef346</title>
    <updated>2026-05-11T04:09:29Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01570d0f7e400110050b75</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01565e2fcb905ec28c7abd</flow_id>
        <hash>5e28f84b7cc72e3d4aed760b38092bbd8af9b172011375a1863697b74aaef346</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/ghsn.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://ebulo.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ebulo.pw/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://ebulo.pw/dencasgj.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ebulo.pw/imeqazoca/stil.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ghsn.cgi</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ghsn.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=30804112&amp;ur=1&amp;HTTP_REFERER=http%3A%2F%2Fshhopper.org%2Fradkvdn.cgi%3F20</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/radkvdn.cgi?20</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>ebulo.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>213.166.71.4</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>213.166.71.4</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>3320ef1b505f5caa7241a5ed62e19052</MD5>
              <SHA-1>48cad1d296c07a4f6013d4c684c0c3f73dc244b7</SHA-1>
              <SHA-256>5f395e2b1adecc6eaef7752a858de63fd3443b9fd63407211bd2c036e2c6c58d</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>278f5fc083d149d8623311ded2da2f99</MD5>
              <SHA-1>7dfa3542acc73102625dffcd80382fae5176b0a5</SHA-1>
              <SHA-256>0488cd68975a31e80ebca6e89a39aa9985a64b18ea0bb268c306b79387a5351b</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>4d7475f81fbb6a609751aea60f8ebe3c</MD5>
              <SHA-1>309e624509fff23bb7de2e4843c6c4ae366b2b54</SHA-1>
              <SHA-256>7a43f7bb9315d27bf2ed7b0220d4587dc9d6b1d688d26b367c13640fce9a73ea</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>d9e9b2eba19d0e9de3a622f169a30ad1</MD5>
              <SHA-1>63586371dc3f951220bae5826f4522dad26c16bc</SHA-1>
              <SHA-256>f80667c80d26a63575c0dd436016e6f43f93a6d1c85222908a50b5b732f16d29</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>e2d647322f48acd68bfb453b5fb9f1ac</MD5>
              <SHA-1>c450dd4e8eb39ac892d2c8f581607a1486444631</SHA-1>
              <SHA-256>10aaf2c9a690456002081d59ef222e9c4eb3415ffbdf12ef317e3f3e4e80dab6</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>7ece4e2f4f95dec5f950d6fe1e1f62f4</MD5>
              <SHA-1>01334b990624765653bb680ba9dd53a08db3445c</SHA-1>
              <SHA-256>c8776dffd0b5c627fef7369a30a7afa20b664948136aec0f1e88d7271afad14a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>db24694f03cf8f2086d3b05001bab5b8</name>
        <report_id>06a80dda-a935-4018-9927-8af75fe07ef7</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ba32029806713c86d0e83bb7dc441ebf6f95d7a21199bdfb3065959b082ffd0d</id>
    <title>Analysis Report for ba32029806713c86d0e83bb7dc441ebf6f95d7a21199bdfb3065959b082ffd0d</title>
    <updated>2026-05-11T04:09:29Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157140f7e400110050b78</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01565e2fcb905ec28c7abb</flow_id>
        <hash>ba32029806713c86d0e83bb7dc441ebf6f95d7a21199bdfb3065959b082ffd0d</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>1e168161c253b22bf80a650ee2fc65b1</name>
        <report_id>8b71dda0-e27f-447b-903e-b239e353711f</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>0639bf843bcec33c5bb38b87547ff31e050accb597b5a1e1351aa7d82abed8e5</id>
    <title>Analysis Report for 0639bf843bcec33c5bb38b87547ff31e050accb597b5a1e1351aa7d82abed8e5</title>
    <updated>2026-05-11T04:09:28Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015688d6e5cdb561983554</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156687d31ad7bba4fe4ee</flow_id>
        <hash>0639bf843bcec33c5bb38b87547ff31e050accb597b5a1e1351aa7d82abed8e5</hash>
        <iocs/>
        <name>5417d9d5c6128de95445a5cf0f18475d</name>
        <report_id>a84515c8-2708-4056-bb5c-78be271bf45f</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6ef128de5fd858e81fd6fd63026edf46814c8473a388e6fe02297c2601acc9a4</id>
    <title>Analysis Report for 6ef128de5fd858e81fd6fd63026edf46814c8473a388e6fe02297c2601acc9a4</title>
    <updated>2026-05-11T04:09:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157090f7e400110050b6d</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015661792fe2d217aed8e5</flow_id>
        <hash>6ef128de5fd858e81fd6fd63026edf46814c8473a388e6fe02297c2601acc9a4</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>eb4f6220047629360dbbf962ff233d16</name>
        <report_id>a405c4cb-e052-4817-ad86-08ad29faa1fa</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c49957d8f96ccb19a9b9b4bb7cc8bbfca1c134232a2760181c9d8f99ac0f9945</id>
    <title>Analysis Report for c49957d8f96ccb19a9b9b4bb7cc8bbfca1c134232a2760181c9d8f99ac0f9945</title>
    <updated>2026-05-11T04:09:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01574b0f7e400110050b9f</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01566686e92bda70271041</flow_id>
        <hash>c49957d8f96ccb19a9b9b4bb7cc8bbfca1c134232a2760181c9d8f99ac0f9945</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmpere6zvsl.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://beachnudist.eu/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://beachnudist.eu/ftt2/check.php?t=1778472671&amp;check=d424d753675c21bf0523c7ce189955da&amp;rand=374817</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://beachnudist.eu/tanolsew.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://cdn.popcash.net/pop.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://tubevideo.eu/6.html</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://dcba.popcash.net/znWaa3gu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://cdn.popcash.net/pop.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://hd-nudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://hd-nudist.eu/</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>http://hd-nudist.eu/tanolsew.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/zrirdbt.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;vlizi=71188007&amp;ur=1&amp;HTTP_REFERER=&amp;pqpkg=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/zrirdbt.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;kpcug=1&amp;vlizi=0&amp;pqpkg=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>tubevideo.eu</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>cdn.popcash.net</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>hd-nudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>beachnudist.eu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.popcash.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>dcba.popcash.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>185.111.111.155</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>178.159.43.126</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>185.111.111.157</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>52.6.69.246</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>178.159.43.126</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.111.111.155</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>178.159.43.126</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>07bf2d04eeb7c8c37a2259517032e5c2</MD5>
              <SHA-1>1e9c50835fd42214605b3f20ffd8314aaa165b1e</SHA-1>
              <SHA-256>dd9f978d2e13a4cfbec9cbdce8b91d09ae090d956955b708cf2937bc493055a0</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>c7df4011555260a99aa6e122d6be2d57</MD5>
              <SHA-1>bdb9d27c0c5fff02293e133a33fc5f72107619e3</SHA-1>
              <SHA-256>c3dff896d37f4ffb1a2eb6f922b2ddb5ec389294ee5228aed3a4d6d9982b04a9</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>e939afbdf8949f0f3c79f94b5619575a</MD5>
              <SHA-1>3b0dd95e8f0a8926bd0d2ed59b001347f38a38a0</SHA-1>
              <SHA-256>cf12837d43c7b502f0fbb2162cdfe3396073e38ae38527d33bdb7c8a2851b003</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>6b188427ec443dd452725b0e5e038deb</name>
        <report_id>72c89bb4-32e2-41f5-af98-db03a091d6ff</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>phishing</value>
          <value>encrypted</value>
          <value>obfuscated</value>
          <value>base64</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>7c24d3448333942b40f003ff079c2e5936ebfd09f45db9db89392c69a9256165</id>
    <title>Analysis Report for 7c24d3448333942b40f003ff079c2e5936ebfd09f45db9db89392c69a9256165</title>
    <updated>2026-05-11T04:09:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156c60f7e400110050b23</_id>
        <file_type>application/x-msdownload</file_type>
        <flow_id>6a015663792fe2d217aed8ea</flow_id>
        <hash>7c24d3448333942b40f003ff079c2e5936ebfd09f45db9db89392c69a9256165</hash>
        <iocs/>
        <name>7065dc07526189c01c3913dcdd1b9688</name>
        <report_id>630e441d-c543-4ed9-9e2a-962f0e14b114</report_id>
        <tags>
          <value>peexe</value>
          <value>pedll</value>
          <value>rogue</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>4c974483e5d12a893664703de91a3106f3f37646608d378b84af6d61d0d25ec3</id>
    <title>Analysis Report for 4c974483e5d12a893664703de91a3106f3f37646608d378b84af6d61d0d25ec3</title>
    <updated>2026-05-11T04:09:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157060f7e400110050b6a</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01565bdf14f1cb2acf7156</flow_id>
        <hash>4c974483e5d12a893664703de91a3106f3f37646608d378b84af6d61d0d25ec3</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmp77u1w6pn.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://ravin-obu.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>86e189d0905b06fc641c69de4311c106</name>
        <report_id>795ac5a0-08ba-4b36-92fd-18a874e7e01d</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
          <value>aidetect</value>
          <value>phishing</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>2cf4670143eccf7c29bd28536cf8060036e3e9d3f49f0f9ace6d1b06fd6c3f16</id>
    <title>Analysis Report for 2cf4670143eccf7c29bd28536cf8060036e3e9d3f49f0f9ace6d1b06fd6c3f16</title>
    <updated>2026-05-11T04:09:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156e10f7e400110050b3d</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015666df14f1cb2acf7160</flow_id>
        <hash>2cf4670143eccf7c29bd28536cf8060036e3e9d3f49f0f9ace6d1b06fd6c3f16</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/plqmvwjou.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2144624156&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ywfd.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=340010124&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://smallnudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://smallnudist.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://smallnudist.eu/logpag.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ywfd.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>smallnudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>3a19177c451849877cd6e19f193e891a</MD5>
              <SHA-1>5cc355ab7ce8d188be8753111503c0f96fee2e11</SHA-1>
              <SHA-256>a890dc5f362e4a0e3ff3b8f31d14ed50cdbbc87294f71f35e93f25f41b5b12b6</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>6bdeb53f7532421e2f038c64a9d95f24</MD5>
              <SHA-1>9ac01f05981fc158693d97d2d86e0bbe2075bbfc</SHA-1>
              <SHA-256>7a79966e5312c0c184ffaa8960430ac3653404fcd8d455a9c07b3ad3c5610cb7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>0b9aeff3a864f4861dbe69b60ade959b</MD5>
              <SHA-1>76d5c47db431db492cc46e1e5742e23aed6314d2</SHA-1>
              <SHA-256>65704b93148fa7706e85c532b2c9ade843f424f8b259f3cf46a2e1ea2b1e6537</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>02e3eac14687a3364b6bffe52db8cdcc</MD5>
              <SHA-1>548eaf97bbaf847233e9a18a02251030cb4900e0</SHA-1>
              <SHA-256>70e8c2d86272e8b8766b9c9ecd59f8e285aa2ed9ef485c432b8d256e55b50d64</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>d9b9c4523346474c4293f6a7e8275193</MD5>
              <SHA-1>34a248dd9c442c72e43ad4a748e85db10ca6a29f</SHA-1>
              <SHA-256>625c3e1af93b2c23bce6cb042e9403be6113355f8dd348913f25e3547e2ecd12</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>d7db2cb1143145a7be873be9a9b6987b</MD5>
              <SHA-1>693551e630c37d9022b53e6b4e5cb317bd3f3cd5</SHA-1>
              <SHA-256>57c8c169328ff15aff7a13ac1c23533fcdf4c2585755a37ea6486e8f0a750b02</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>e2429c57deaf56df5d9c8f88cf936b78</name>
        <report_id>d33845b8-a342-4ee0-94af-4d3f6ff35ee5</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>025f020ab5f9ceddeffc04eeaeea3881336d71c141114a65df8cc1f202ea4372</id>
    <title>Analysis Report for 025f020ab5f9ceddeffc04eeaeea3881336d71c141114a65df8cc1f202ea4372</title>
    <updated>2026-05-11T04:09:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156cf0f7e400110050b2d</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a0156642fcb905ec28c7ace</flow_id>
        <hash>025f020ab5f9ceddeffc04eeaeea3881336d71c141114a65df8cc1f202ea4372</hash>
        <iocs>
          <files>
            <value>
              <MD5>69c1332aef0c23b6c87c10b9d87773f5</MD5>
              <SHA-1>0fac3013e30bff250f0cf8f6a6d0120700f2f4bc</SHA-1>
              <SHA-256>f509c7b2cac1a6b7ebaac56b3c26aed4cbf3d09b0446471d9aa2cb8c69a438de</SHA-256>
              <origin>PE_UNPACKING</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
          </files>
        </iocs>
        <name>ebcf4681eb72921c02597bc8b1182604</name>
        <report_id>5ef6389d-141e-46f5-8e38-ad0a26c33aed</report_id>
        <tags>
          <value>peexe</value>
          <value>crypt</value>
          <value>packed</value>
          <value>upx</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>69c66e89c0bb327a0f3949b63da71991977be942490f41b4e3eb386a9ffa20b3</id>
    <title>Analysis Report for 69c66e89c0bb327a0f3949b63da71991977be942490f41b4e3eb386a9ffa20b3</title>
    <updated>2026-05-11T04:09:27Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157010f7e400110050b67</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015666df14f1cb2acf7162</flow_id>
        <hash>69c66e89c0bb327a0f3949b63da71991977be942490f41b4e3eb386a9ffa20b3</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.ww38.ww25.ww25.crazy-horse.xyz/?tr_uuid=20260508-1006-1428-a979-c6041c2dfa5a&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww38.ww25.ww25.crazy-horse.xyz/?tr_uuid=20260508-1006-1428-a979-c6041c2dfa5a&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww38.ww25.ww25.crazy-horse.xyz/?tr_uuid=20260508-1006-1428-a979-c6041c2dfa5a&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww38.ww25.ww25.crazy-horse.xyz/?tr_uuid=20260508-1006-1428-a979-c6041c2dfa5a&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.ww38.ww25.ww25.crazy-horse.xyz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>ww38.ww25.ww25.crazy-horse.xyz</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1006-1428-a979-c6041c2dfa5a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1006-1428-a979-c6041c2dfa5a</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>5958db038b352c72e15ec1088ec01bb5</name>
        <report_id>264123a7-fad1-4736-873c-7c09af53f968</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1524abfb7f54a8efad657768a95735ecaf02fb3bc74315d835a661141d0542c4</id>
    <title>Analysis Report for 1524abfb7f54a8efad657768a95735ecaf02fb3bc74315d835a661141d0542c4</title>
    <updated>2026-05-11T04:09:26Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157170f7e400110050b7a</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01565e86e92bda70271034</flow_id>
        <hash>1524abfb7f54a8efad657768a95735ecaf02fb3bc74315d835a661141d0542c4</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/btrul.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;moeud=13658572&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://selfservicelps.com/templates/survey/css/style.dotsass</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://xtease.com/templates/survey/css/override/style.dotsass</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/btrul.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>selfservicelps.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>xtease.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>99.84.152.90</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.64.211.69</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>18.64.211.69</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>99.84.152.90</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>6249f8487ceee4c1013132ada8081cc6</MD5>
              <SHA-1>5f536424f75cf1fcc95c23f465a1b71fccb1421f</SHA-1>
              <SHA-256>bb6f9f1314dcbf9a8e468e67851529389f158794cac05ccad815af3aa550fbe7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-php</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>cdfb6aa11ca9af246d1e0c9bc21a5bd7</MD5>
              <SHA-1>74cf44da47aab8e26b8ef81ab240c6e493aaeb90</SHA-1>
              <SHA-256>7bf378b659f14d008abff3233a2173f6ae5bb93a663f2dc5b3f0a4d13fca97a4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>17b744ba6bc943299951ca1ade4117ab</MD5>
              <SHA-1>262c8a93e5c9b160032840ee28b0aecb556817d1</SHA-1>
              <SHA-256>7c2ff5c72ceea213f8b9cd6fa0a0c0d18ed367d918351d1ade60defa25983646</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
        </iocs>
        <name>201aa943e07bead82f332e71c4abd595</name>
        <report_id>f362ab31-07c9-4fb6-a4dd-9dc9e81e7feb</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ea65818e43410dcd85e7bdcbf074e61eea2c0f5636d3d8ef4b8d75d691f3ad1e</id>
    <title>Analysis Report for ea65818e43410dcd85e7bdcbf074e61eea2c0f5636d3d8ef4b8d75d691f3ad1e</title>
    <updated>2026-05-11T04:09:26Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015688b87f27901eb5eed6</_id>
        <file_type>message/rfc822</file_type>
        <flow_id>6a015675df14f1cb2acf716e</flow_id>
        <hash>ea65818e43410dcd85e7bdcbf074e61eea2c0f5636d3d8ef4b8d75d691f3ad1e</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmp6cev8nlq.html</url>
              <origin>URL_RENDER</origin>
            </value>
          </urls>
          <ips>
            <value>
              <ip>109.248.151.251</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>a8e05c42659f103f296c25ec2a4b5564cd6cf7b0f080fcfba95431ddc51f5b16</SHA-256>
              <SHA-1>4dea75d98c46228ca6c5d31ade5cc073a6a87861</SHA-1>
              <MD5>db6c8751e5c050eb89b42c097b27bbfb</MD5>
              <origin>EMAIL_BODY</origin>
              <file_type>text/html</file_type>
            </value>
          </files>
        </iocs>
        <name>submission.eml</name>
        <report_id>4469a535-038e-47d4-9a49-b74e7661fb32</report_id>
        <tags>
          <value>eml</value>
          <value>rfc822</value>
          <value>aidetect</value>
          <value>phishing</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1562c8a8504c4aa26708fc3b39ccbc0300595dd6e161838306c0f7508807d00e</id>
    <title>Analysis Report for 1562c8a8504c4aa26708fc3b39ccbc0300595dd6e161838306c0f7508807d00e</title>
    <updated>2026-05-11T04:09:23Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156fe0f7e400110050b60</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01564bdf14f1cb2acf714b</flow_id>
        <hash>1562c8a8504c4aa26708fc3b39ccbc0300595dd6e161838306c0f7508807d00e</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.api.pusulabet976.com/?tr_uuid=20260508-1007-271f-ba43-62f0e48ecf47&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.api.pusulabet976.com/?tr_uuid=20260508-1007-271f-ba43-62f0e48ecf47&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.api.pusulabet976.com/?tr_uuid=20260508-1007-271f-ba43-62f0e48ecf47&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.api.pusulabet976.com/?tr_uuid=20260508-1007-271f-ba43-62f0e48ecf47&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.api.pusulabet976.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>api.pusulabet976.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1007-271f-ba43-62f0e48ecf47</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1007-271f-ba43-62f0e48ecf47</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>a09e0ccaee01c3bbefaceb49dad14f1f</name>
        <report_id>03468d37-4e37-4a3f-950b-93ed7ab0b48c</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>30926dab23dbb4b7d4cb68ff23db4c6f2012fc1448674f4654e7d963727b2bb0</id>
    <title>Analysis Report for 30926dab23dbb4b7d4cb68ff23db4c6f2012fc1448674f4654e7d963727b2bb0</title>
    <updated>2026-05-11T04:09:23Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156fc0f7e400110050b5d</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01564c7d31ad7bba4fe4d6</flow_id>
        <hash>30926dab23dbb4b7d4cb68ff23db4c6f2012fc1448674f4654e7d963727b2bb0</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>fe6f46a1cc34ea48381c0534f6d2c23e</name>
        <report_id>28aed69d-33e7-486b-9a05-c2200b3c3a66</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bfee5041fb000ea0920979a74af12bb39fca95943a8695202de0592f9ddb58f4</id>
    <title>Analysis Report for bfee5041fb000ea0920979a74af12bb39fca95943a8695202de0592f9ddb58f4</title>
    <updated>2026-05-11T04:09:22Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156f90f7e400110050b5a</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01564e86e92bda70271023</flow_id>
        <hash>bfee5041fb000ea0920979a74af12bb39fca95943a8695202de0592f9ddb58f4</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/uqftiod.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=593330721&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ybyneyr.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=4246180153&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://youngnudism.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://youngnudism.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://youngnudism.eu/analiz.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/uqftiod.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>youngnudism.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>51.91.251.47</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>9f1c4ebce745da79f9e04aa67359c15e</MD5>
              <SHA-1>6fb0c58e953cd2e30e9b73f426f56c9667a927f1</SHA-1>
              <SHA-256>dda27bb136fb3d0b0e539dab7b06c202f175619ec11b7533bc97b5af2cf3f9c5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>10a4edf661df23548f239ab25e9db1f9</MD5>
              <SHA-1>5772c62475e225be7d8cfb7cdf455ebedeaa344c</SHA-1>
              <SHA-256>6d97e946f69bccb1ce69cc776709c708d53611296d884f5909a941099ca22767</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>ed779f44292cddd73a36312685fe3368</MD5>
              <SHA-1>6c02ea14e932d1d4b7d47d35c539595d10ec3330</SHA-1>
              <SHA-256>e19a254b9fc13057fb0293c62fbfb528e252d408c1046906975b3d17fc8beacf</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>fc9131bd8c70e1f420275c8752591ebc</MD5>
              <SHA-1>f5524301918ae38b45fd18a69aa68089b1ea43d8</SHA-1>
              <SHA-256>af4f3071ab9471f1e1e0268250d17a56382686afc1e7a604667123fbbc50fe2c</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>df68f8f70347e53a17356a90ae5a8cb1</MD5>
              <SHA-1>029013f80ed2b4bc41f94a263f6f2f48c0dd3533</SHA-1>
              <SHA-256>8ac717c4ee8f5aeb0659cb6035eeaf45d73b4aed1db66cb31fa0be9134fd0b38</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>f6187c0c0ff32435a55048e0f65cc659</name>
        <report_id>14129db8-3d24-401d-9d84-09eeaa6baa6e</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>05280a7c4df16d1b1ef3d405dbec2d4d823a07e3c88ba9524af9606aad004931</id>
    <title>Analysis Report for 05280a7c4df16d1b1ef3d405dbec2d4d823a07e3c88ba9524af9606aad004931</title>
    <updated>2026-05-11T04:09:22Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015683d6e5cdb561983552</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01566486e92bda7027103f</flow_id>
        <hash>05280a7c4df16d1b1ef3d405dbec2d4d823a07e3c88ba9524af9606aad004931</hash>
        <iocs/>
        <name>05aded34982275c3a147348f24f115f0</name>
        <report_id>2b512b0c-132a-4bda-9251-1fa9b52bc2c6</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>02852cae77abb289f975cb15e470e6e7631d640e010f96b303c01f6079333a1f</id>
    <title>Analysis Report for 02852cae77abb289f975cb15e470e6e7631d640e010f96b303c01f6079333a1f</title>
    <updated>2026-05-11T04:09:20Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01571c0f7e400110050b7c</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01564e86e92bda70271021</flow_id>
        <hash>02852cae77abb289f975cb15e470e6e7631d640e010f96b303c01f6079333a1f</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/ydqhfyw.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;moeud=2166560904&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://api-sr.amplitude.com/sessions/v2/track</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/appicon.png?v=9670c787</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/lightlogo.svg?v=f2f0c2f2</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/metaogimage.jpg?v=4f3e5e4b</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/watermark.svg?v=ec3c3bc9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/translations_en.c387680de7d290.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.strpssts-ana.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com/9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://discord.gg/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://sr-client-cfg.amplitude.com/config</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/blog</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/model</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/studio</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://x.com/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/ydqhfyw.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>api-sr.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.chapturist.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.strpssts-ana.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>discord.gg</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sentry-public.stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sr-client-cfg.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>x.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com</email>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>104.17.10.106</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>34.215.88.67</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.106</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.53.241</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.136.234</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.116</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.117.12</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>34.215.88.67</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.10.106</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.136.234</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.117.12</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.106</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.116</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.53.241</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>f2f0c2f20d8a409950e8043dfdbcabcc</MD5>
              <SHA-1>f6dbfe227f7fe327ddd9bbfbaa2f2c76a297508c</SHA-1>
              <SHA-256>9c2744b63f5011f4013a606e9e82cf2fd7e93d1137377bbb36f985829db80414</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>9670c78727119ad8a4bd51434c76f415</MD5>
              <SHA-1>e2ed790fa0559050f279521407d7d55061bfbce8</SHA-1>
              <SHA-256>0b3f9c85a5564bb1ce247e7171891c838565c9c189c44b0b345dd38877b96513</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>4f3e5e4bb3e151b1a80c2bdcc9c12d71</MD5>
              <SHA-1>8266ea2804b0968beee94faef9f912b4c7a368ad</SHA-1>
              <SHA-256>006019dd903e44adba3b5693faaba5bf06555a8951c8b25ff6a7dd088cbe4c9f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/jpeg</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ec3c3bc9754398d23a777b9ea076cd1e</MD5>
              <SHA-1>779550b440c9cc3e93be366b0ca0bd839f713da8</SHA-1>
              <SHA-256>add0cf2e32d17a36422f9f41edd66e51a6cbf0543257219093647c0c0d4ca5c7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>d0f3602da235fb10a7fe05f0f2f20989</MD5>
              <SHA-1>7896094fc85a761a89aaf2c50e40eb9ef1d81d66</SHA-1>
              <SHA-256>e9b39e33b0d82e2323b6ac5c8a2418858797600c0bc5e27b22b04be345704d73</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>4672a228c481d18b620db79d9874d4b8</MD5>
              <SHA-1>2d704bd91dfaef9a483599c947a7f59857bef8a7</SHA-1>
              <SHA-256>16721391ae35d5ca82c9ad729785e3f7acea4912e9a6584905bd964ff0321984</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>e481c4712106af6d959a8b784d9f1fbb</MD5>
              <SHA-1>725e352e71399d8f0292116db8dc430639053820</SHA-1>
              <SHA-256>b65df47dcdd9381e42034fbc56df666125571dea752ca3a6803fd16f78b7c982</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>bd756308e0e483d2a90e84ffcb8125ff</MD5>
              <SHA-1>08900d65a5b30dd7e74fcf4499967ce671981c53</SHA-1>
              <SHA-256>a30bb5a674290ae82138534fbd681d9cff0f37ea361fab42aa1b7dc05a255f45</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>LIKELY_MALICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>9acfae3b2a44ba2fa63060e67cf91cc9</name>
        <report_id>d80b5abc-fe2b-40a5-941f-b96229588163</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>png</value>
          <value>svg</value>
          <value>jpg</value>
          <value>phishing</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>70635c72f6f4c858a5079513ad384d06dd7137fd4a9fa594b107edc003428f96</id>
    <title>Analysis Report for 70635c72f6f4c858a5079513ad384d06dd7137fd4a9fa594b107edc003428f96</title>
    <updated>2026-05-11T04:09:20Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156f40f7e400110050b56</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01564e7d31ad7bba4fe4d8</flow_id>
        <hash>70635c72f6f4c858a5079513ad384d06dd7137fd4a9fa594b107edc003428f96</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>2d7c1c4da0c2a3e5a8aca1e0cd4f9c9a</name>
        <report_id>3b250985-406c-4ce1-8fb0-22e952dbae3d</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b1a0278e116c148a962c3bd402305fb9f1f8177d1f07ad75959e8e922c3a55ac</id>
    <title>Analysis Report for b1a0278e116c148a962c3bd402305fb9f1f8177d1f07ad75959e8e922c3a55ac</title>
    <updated>2026-05-11T04:09:19Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01567fd6e5cdb56198354f</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156602fcb905ec28c7ac4</flow_id>
        <hash>b1a0278e116c148a962c3bd402305fb9f1f8177d1f07ad75959e8e922c3a55ac</hash>
        <iocs/>
        <name>e414afcda48161fe27ba4e47edc73fe6</name>
        <report_id>e4fb7e9c-55b9-47b1-9c21-1bb8e5e8a232</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>710b531faeedbb36f1193974bfda95f16a9b6d095df5bb20678782e59d76255a</id>
    <title>Analysis Report for 710b531faeedbb36f1193974bfda95f16a9b6d095df5bb20678782e59d76255a</title>
    <updated>2026-05-11T04:09:19Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015680d6e5cdb561983550</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015660792fe2d217aed8e3</flow_id>
        <hash>710b531faeedbb36f1193974bfda95f16a9b6d095df5bb20678782e59d76255a</hash>
        <iocs/>
        <name>e5cf246cd9ca7ae53f777bbce160d933</name>
        <report_id>a73f1991-c256-4ae9-b7ef-31f7f1a436ed</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c31588ec39ab9d4bef8799073a199a6c3cf632ea1f78cd362db83a32f6509d95</id>
    <title>Analysis Report for c31588ec39ab9d4bef8799073a199a6c3cf632ea1f78cd362db83a32f6509d95</title>
    <updated>2026-05-11T04:09:18Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156f60f7e400110050b58</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0156507d31ad7bba4fe4e0</flow_id>
        <hash>c31588ec39ab9d4bef8799073a199a6c3cf632ea1f78cd362db83a32f6509d95</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>df607007be7cdba503a69573d4d7f490</name>
        <report_id>3d105dd0-23ba-4d2c-a59b-f60624f51f7c</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>fb843052aa915ab95df08b0b9485fb34260d814699ded11dc7d2ab2666eecb10</id>
    <title>Analysis Report for fb843052aa915ab95df08b0b9485fb34260d814699ded11dc7d2ab2666eecb10</title>
    <updated>2026-05-11T04:09:18Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01573f0f7e400110050b99</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01565086e92bda70271025</flow_id>
        <hash>fb843052aa915ab95df08b0b9485fb34260d814699ded11dc7d2ab2666eecb10</hash>
        <iocs>
          <urls>
            <value>
              <url>http://johnvieno.com/?&amp;tr_uuid=20260508-1026-5374-8306-8e2dff490ff4&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://johnvieno.com/?&amp;tr_uuid=20260508-1026-5374-8306-8e2dff490ff4&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://johnvieno.com/?&amp;tr_uuid=20260508-1026-5374-8306-8e2dff490ff4&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>johnvieno.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>johnvieno.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.250</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.250</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1026-5374-8306-8e2dff490ff4</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1026-5374-8306-8e2dff490ff4</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>a456af3dde7b0c0a00d32ed64fe6daad</name>
        <report_id>04594d9d-1fd5-4afe-b41c-e39059118347</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>69e38d474070389774cb27375592c420373a7a6af928bdac3c530396ffaaf983</id>
    <title>Analysis Report for 69e38d474070389774cb27375592c420373a7a6af928bdac3c530396ffaaf983</title>
    <updated>2026-05-11T04:09:15Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01567cd6e5cdb56198354d</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01565c2fcb905ec28c7ab9</flow_id>
        <hash>69e38d474070389774cb27375592c420373a7a6af928bdac3c530396ffaaf983</hash>
        <iocs/>
        <name>e6b10faa04ea1e13edd51ecc796399ee</name>
        <report_id>7f4f99ca-d406-4105-9ea2-ea2711074d03</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>7c27cffc513dcf795002cf8b4236de75f3332a99442402b68b5090b9a226531b</id>
    <title>Analysis Report for 7c27cffc513dcf795002cf8b4236de75f3332a99442402b68b5090b9a226531b</title>
    <updated>2026-05-11T04:09:11Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015675d6e5cdb561983546</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01565911d01437268907bd</flow_id>
        <hash>7c27cffc513dcf795002cf8b4236de75f3332a99442402b68b5090b9a226531b</hash>
        <iocs/>
        <name>f3b0f991d2c4a997f604ebce449385f6</name>
        <report_id>47bca25f-0140-4078-a1e4-017c1c6ae32b</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b57685cba7ff0eb1b59c3f76ed4e0aaa6d0dc1d9dda33a8c69cb2439712f3613</id>
    <title>Analysis Report for b57685cba7ff0eb1b59c3f76ed4e0aaa6d0dc1d9dda33a8c69cb2439712f3613</title>
    <updated>2026-05-11T04:09:11Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015677d6e5cdb561983548</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156597d31ad7bba4fe4e6</flow_id>
        <hash>b57685cba7ff0eb1b59c3f76ed4e0aaa6d0dc1d9dda33a8c69cb2439712f3613</hash>
        <iocs/>
        <name>a6527321fb06b11af5f673b54adb88a9</name>
        <report_id>86f62402-b05e-47fd-8136-b2a9adc4e8ab</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>367921a4f19b5d6cfefd89374b85a8f570dbaf96b1f408f75bd6da2e3dd04394</id>
    <title>Analysis Report for 367921a4f19b5d6cfefd89374b85a8f570dbaf96b1f408f75bd6da2e3dd04394</title>
    <updated>2026-05-11T04:09:11Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015676d6e5cdb561983547</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01565a86e92bda7027102f</flow_id>
        <hash>367921a4f19b5d6cfefd89374b85a8f570dbaf96b1f408f75bd6da2e3dd04394</hash>
        <iocs/>
        <name>2fd2edc613fa4fa3a9eb6fd6654f3689</name>
        <report_id>b211bcbd-11a3-4b69-92e5-85f063e29cd4</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>62a5da800588c747d8139c942afaf2b9e1b75ebd6ae2c311229f11c9207c0540</id>
    <title>Analysis Report for 62a5da800588c747d8139c942afaf2b9e1b75ebd6ae2c311229f11c9207c0540</title>
    <updated>2026-05-11T04:08:59Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01567a0f7e400110050ac8</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156507d31ad7bba4fe4de</flow_id>
        <hash>62a5da800588c747d8139c942afaf2b9e1b75ebd6ae2c311229f11c9207c0540</hash>
        <iocs/>
        <name>ca3e788504e3c1204f027b0a6f646b33</name>
        <report_id>cdd61e40-8c70-4a98-a64b-fa1779b50fe9</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1b5a335b4552794b36c16ba1410be353d2b71bdbe1cf33cdf757bfb67ff07fe3</id>
    <title>Analysis Report for 1b5a335b4552794b36c16ba1410be353d2b71bdbe1cf33cdf757bfb67ff07fe3</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156d80f7e400110050b36</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0156132fcb905ec28c7a5b</flow_id>
        <hash>1b5a335b4552794b36c16ba1410be353d2b71bdbe1cf33cdf757bfb67ff07fe3</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>02d192e8d6cdba93e75e9b09b4b74a9e</name>
        <report_id>e0d6b4ce-b375-4436-ba13-08d8f03a02ee</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6ddebace84e65258f8ec902805a51572d8b846507d4b9faeefdbfb046ec89f65</id>
    <title>Analysis Report for 6ddebace84e65258f8ec902805a51572d8b846507d4b9faeefdbfb046ec89f65</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156fa0f7e400110050b5b</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01561a7d31ad7bba4fe4c3</flow_id>
        <hash>6ddebace84e65258f8ec902805a51572d8b846507d4b9faeefdbfb046ec89f65</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>eb97f210c593687dbd1c4d4418339dbb</name>
        <report_id>f3457923-1129-4ae8-ba12-878bbceb52e6</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>cbfed85379e12e2bf26b4f42b6100aff10d356c21ac5062c00fd6cb498ae1e7d</id>
    <title>Analysis Report for cbfed85379e12e2bf26b4f42b6100aff10d356c21ac5062c00fd6cb498ae1e7d</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156da0f7e400110050b37</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01562b2fcb905ec28c7a72</flow_id>
        <hash>cbfed85379e12e2bf26b4f42b6100aff10d356c21ac5062c00fd6cb498ae1e7d</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>7f794071d5ba5dfab4969c971acc2a64</name>
        <report_id>06302aca-170e-4358-87d2-8fc5f4f05e5a</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>11909377b7b4a2cbd51786692981a2e36cc876c92b9220ca6474bf01ec59e762</id>
    <title>Analysis Report for 11909377b7b4a2cbd51786692981a2e36cc876c92b9220ca6474bf01ec59e762</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01572a0f7e400110050b8a</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015619df14f1cb2acf711c</flow_id>
        <hash>11909377b7b4a2cbd51786692981a2e36cc876c92b9220ca6474bf01ec59e762</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/blhd.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0&amp;haxvf=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/blhd.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;moeud=2703229157&amp;ur=1&amp;HTTP_REFERER=&amp;haxvf=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://api-sr.amplitude.com/sessions/v2/track</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/appicon.png?v=9670c787</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/lightlogo.svg?v=f2f0c2f2</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/metaogimage.jpg?v=4f3e5e4b</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/watermark.svg?v=ec3c3bc9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/translations_en.c387680de7d290.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.strpssts-ana.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com/9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://discord.gg/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://sr-client-cfg.amplitude.com/config</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/blog</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/model</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/studio</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://x.com/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>api-sr.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.chapturist.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.strpssts-ana.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>discord.gg</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sentry-public.stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sr-client-cfg.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>x.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com</email>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>184.33.2.216</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.53.241</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.117.12</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.10.106</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.46</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.140.229</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.135.234</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.116</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>184.33.2.216</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.10.106</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.135.234</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.117.12</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.46</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.116</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.53.241</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.140.229</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>9670c78727119ad8a4bd51434c76f415</MD5>
              <SHA-1>e2ed790fa0559050f279521407d7d55061bfbce8</SHA-1>
              <SHA-256>0b3f9c85a5564bb1ce247e7171891c838565c9c189c44b0b345dd38877b96513</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>f2f0c2f20d8a409950e8043dfdbcabcc</MD5>
              <SHA-1>f6dbfe227f7fe327ddd9bbfbaa2f2c76a297508c</SHA-1>
              <SHA-256>9c2744b63f5011f4013a606e9e82cf2fd7e93d1137377bbb36f985829db80414</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>4f3e5e4bb3e151b1a80c2bdcc9c12d71</MD5>
              <SHA-1>8266ea2804b0968beee94faef9f912b4c7a368ad</SHA-1>
              <SHA-256>006019dd903e44adba3b5693faaba5bf06555a8951c8b25ff6a7dd088cbe4c9f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/jpeg</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ec3c3bc9754398d23a777b9ea076cd1e</MD5>
              <SHA-1>779550b440c9cc3e93be366b0ca0bd839f713da8</SHA-1>
              <SHA-256>add0cf2e32d17a36422f9f41edd66e51a6cbf0543257219093647c0c0d4ca5c7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>2e65e602b99e6f34dc20379b0e5cbafd</MD5>
              <SHA-1>cf538d75c55dbc1fc1a41267137705396c26b7a7</SHA-1>
              <SHA-256>7d6198cc43a26d913719b171f4aeaa0e755efe9b9f3c9b4400bad83452f5c20a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>4ff888209f4337caf802f8da4d4e5813</MD5>
              <SHA-1>584606fe5f4fc8861129f3dd004f6eebc33f8dda</SHA-1>
              <SHA-256>9219a84df2b47818c25d32eb39cea6d4206e62f0126f8a552352d3f03376ef97</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ef94b90baea7253ecaabb48e79301201</MD5>
              <SHA-1>53340454126b82c56875b14e5945b8667217d7d0</SHA-1>
              <SHA-256>4b4b583be9d8ae70fb72b2deec3520b49ce3570daba5944a1635f8931fe7f81b</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>bd756308e0e483d2a90e84ffcb8125ff</MD5>
              <SHA-1>08900d65a5b30dd7e74fcf4499967ce671981c53</SHA-1>
              <SHA-256>a30bb5a674290ae82138534fbd681d9cff0f37ea361fab42aa1b7dc05a255f45</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>LIKELY_MALICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>d79fb7ce76f9295f663937cabfe1ab87</name>
        <report_id>2217d597-548f-4126-8e3f-7fc277647ad8</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>svg</value>
          <value>jpg</value>
          <value>png</value>
          <value>phishing</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ed3652ebebf92f57f913c981de54b64f9a5ff0ffb2172423a737a54f9c8a64b2</id>
    <title>Analysis Report for ed3652ebebf92f57f913c981de54b64f9a5ff0ffb2172423a737a54f9c8a64b2</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157070f7e400110050b6c</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015637792fe2d217aed8be</flow_id>
        <hash>ed3652ebebf92f57f913c981de54b64f9a5ff0ffb2172423a737a54f9c8a64b2</hash>
        <iocs>
          <urls>
            <value>
              <url>http://cdn.popcash.net/pop.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/goqrlw.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;vlizi=2857008662&amp;ur=1&amp;HTTP_REFERER=&amp;pqpkg=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://xmature.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://xmature.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://xmature.eu/analiz.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmp8gews7ur.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/analiz.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/dikol/brick054.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/ftt2/check.php?t=1778472622&amp;check=4e74b7801c9d45eaec0ed65298cd7c4c&amp;rand=406091</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/ftt2/cron.php</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/pics/1.jpg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/pics/15.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/pics/aa03.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudisttbeach.eu/pics/hot2.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://tubevideo.eu/6.html</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://panel.tidint.pro/v3/a/ipn/js/137058</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://tubevideo.eu/goqrlw.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;kpcug=1&amp;vlizi=0&amp;pqpkg=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>nudisttbeach.eu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>panel.tidint.pro</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.popcash.net</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>xmature.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>207.154.222.8</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>80.89.234.76</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>185.111.111.156</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.36.162.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.111.111.156</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.36.162.157</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>0587cf99079f2be52c97800b7fb304ea</MD5>
              <SHA-1>216ddb4d774eedc621463adac77b1013edb8559e</SHA-1>
              <SHA-256>d1b50633e35a104611eb4e6589c2d5c72222c1c37d176dee41293bc8a363343b</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xhtml+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>0764379740cf0ed848dc7055fa057614</MD5>
              <SHA-1>c4047719edfcde0b62272fa5a9e0193a60b9cbd9</SHA-1>
              <SHA-256>c0e10b20e7c8bdc3479ac8cb4064ef45f1120b1dabda239f8aadb7c7635dff9a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>7c3f0249739b0daff5752e55da4f7a01</MD5>
              <SHA-1>9762e355efb66a02869e82894dd95eb7cf0735c1</SHA-1>
              <SHA-256>2b7e7662b8d4936aa76a6dd5dc20e82857bddcd205da795d04666c92f4c2aa0f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>b4b1b8e456c6e746728cfb27b79cdcf7</MD5>
              <SHA-1>1683d823e0d8fe74c66088b5962125d07f5e667c</SHA-1>
              <SHA-256>0d8736b216ac571cbc17ab49fe20eb779fee3a324bcd61629635e6169a86ba6f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <MD5>e939afbdf8949f0f3c79f94b5619575a</MD5>
              <SHA-1>3b0dd95e8f0a8926bd0d2ed59b001347f38a38a0</SHA-1>
              <SHA-256>cf12837d43c7b502f0fbb2162cdfe3396073e38ae38527d33bdb7c8a2851b003</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>9497ed71ee1be96fd77b26abd72d4007</name>
        <report_id>fe13fd4a-aec0-4f8c-8832-e66146fb3e3e</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
          <value>javascript</value>
          <value>phishing</value>
          <value>encrypted</value>
          <value>obfuscated</value>
          <value>base64</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ee251d72f5e2f73e2cad24b88dc9ea3459dc757b5421cc29c3c1d030d01aadac</id>
    <title>Analysis Report for ee251d72f5e2f73e2cad24b88dc9ea3459dc757b5421cc29c3c1d030d01aadac</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157340f7e400110050b93</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0156372fcb905ec28c7a81</flow_id>
        <hash>ee251d72f5e2f73e2cad24b88dc9ea3459dc757b5421cc29c3c1d030d01aadac</hash>
        <iocs>
          <urls>
            <value>
              <url>http://cyclotourisme-orleanais-ffct.org/?fp=-5/&amp;tr_uuid=20260508-1004-2741-b72d-d9c3701c56d8&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://cyclotourisme-orleanais-ffct.org/?fp=-5/&amp;tr_uuid=20260508-1004-2741-b72d-d9c3701c56d8&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://cyclotourisme-orleanais-ffct.org/?fp=-5/&amp;tr_uuid=20260508-1004-2741-b72d-d9c3701c56d8&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>cyclotourisme-orleanais-ffct.org</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>cyclotourisme-orleanais-ffct.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.253</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.253</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1004-2741-b72d-d9c3701c56d8</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1004-2741-b72d-d9c3701c56d8</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>577615bb17f733e8e3ddc02c26c1b157</name>
        <report_id>b0901306-4d08-48dd-85f3-c118327c6d28</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>11d7f2f734693209c21ee437924d4e2833b44a4f09c59e30c671511107ee618b</id>
    <title>Analysis Report for 11d7f2f734693209c21ee437924d4e2833b44a4f09c59e30c671511107ee618b</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156b80f7e400110050b11</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a01561a86e92bda70270fd0</flow_id>
        <hash>11d7f2f734693209c21ee437924d4e2833b44a4f09c59e30c671511107ee618b</hash>
        <iocs>
          <files>
            <value>
              <MD5>e653a300c6ecf9e3f26a88da613ed4fd</MD5>
              <SHA-1>e2f06a25ef00e1422d5d02eaf52cb116c917eadd</SHA-1>
              <SHA-256>1297d6a8bcac3f6504c21aac95ea91261f3d679e4caabe46a44a8b935fcee960</SHA-256>
              <origin>PE_UNPACKING</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
          </files>
        </iocs>
        <name>ff1618e301d7f7e523063b559ee8b257</name>
        <report_id>48e7f735-80c8-4c25-8220-698bda854888</report_id>
        <tags>
          <value>peexe</value>
          <value>crypt</value>
          <value>packed</value>
          <value>upx</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>feab1fca5873e18c18c1960349676cb72569abbe1944bd4f5f18a5037955044f</id>
    <title>Analysis Report for feab1fca5873e18c18c1960349676cb72569abbe1944bd4f5f18a5037955044f</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0157230f7e400110050b87</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0156337d31ad7bba4fe4cf</flow_id>
        <hash>feab1fca5873e18c18c1960349676cb72569abbe1944bd4f5f18a5037955044f</hash>
        <iocs>
          <urls>
            <value>
              <url>http://empiricalgames.org/?fp=-5/&amp;tr_uuid=20260508-1007-336b-938e-f13b783afcd9&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://empiricalgames.org/?fp=-5/&amp;tr_uuid=20260508-1007-336b-938e-f13b783afcd9&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://empiricalgames.org/?fp=-5/&amp;tr_uuid=20260508-1007-336b-938e-f13b783afcd9&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>empiricalgames.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>empiricalgames.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.253</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.253</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1007-336b-938e-f13b783afcd9</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1007-336b-938e-f13b783afcd9</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>9dfb09942797906563d7a96d7b3b866b</name>
        <report_id>20845fbb-e790-4776-b72b-e6c323f65e6f</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>cb7a5a750e5c08012cca733a30e13d3df055e1be96541d682ff3c39d1137be0a</id>
    <title>Analysis Report for cb7a5a750e5c08012cca733a30e13d3df055e1be96541d682ff3c39d1137be0a</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01572c0f7e400110050b8b</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01561c86e92bda70270fd7</flow_id>
        <hash>cb7a5a750e5c08012cca733a30e13d3df055e1be96541d682ff3c39d1137be0a</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/jckpoecc.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0&amp;haxvf=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/jckpoecc.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;moeud=3733220899&amp;ur=1&amp;HTTP_REFERER=&amp;haxvf=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://api-sr.amplitude.com/sessions/v2/track</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/appicon.png?v=9670c787</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/lightlogo.svg?v=f2f0c2f2</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/metaogimage.jpg?v=4f3e5e4b</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/watermark.svg?v=ec3c3bc9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/translations_en.c387680de7d290.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.strpssts-ana.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com/9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://discord.gg/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://sr-client-cfg.amplitude.com/config</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/blog</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/model</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/studio</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://x.com/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpchmcihq8.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/11810.2da81b7a3c2f2270.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/13887.4672c3f27c6dc0ae.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/1800.f56c9034fc590d0c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/24538.2de580ca5bc00ddd.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/25447.8ca7f259920879b0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/29219.bd66a57352b59550.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/29302.00a440bc7fdddec2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/29504.e98b74af1f6b285f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/32682.b29a2dd84862cb83.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/34302.046243d5e19907ad.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/39010.e3f54cc7427c41b9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/42015.eb1c2fd175769a62.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/4225.61e317d2fc220a3f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/42636.dbfcb78adb51efb6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/43430.859477f85b4b121b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/46e7d0cd94b684e8.f8369f2541f6dc66.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/46e7d0cd94b684e8_dark.54f7a517ec9e8dc1.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/47520.4f2fd581c1212083.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/51364.78c99be62231b9c6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/52851.74deddecc153b914.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/53295.4ff9b1b2c1c230ab.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/70622.fc9e7788045236ae.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/7089.136fc93fd0384144.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/70999.6bfc35a384b712f9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/71675.32c62d9159ec55f3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/72906.5ad571186e60b751.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/73025.03a9932981249f65.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/73147.61eec67855a19932.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/74555.fc114392be01bd26.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/8064.03fb8ccd1a226ebc.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/85586.58e9df71b813e31c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/85636.2edaeef3f58b4976.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/97257.c6ae37d3d03725e1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/97783.ec6963dfc1a272d1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/98212.7f5f05b992f221c0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/CategoryTagPageEntry.db74eb832431f2be.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/FeedPageEntry.aab2924fba7f3736.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/GalleryPageEntry.e462f2ca64ca7410.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/GroupedTagsModal.09188d2ab17f5f02.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/MediaGalleryViewer.10be8552ea38b2e7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/MediaGalleryViewerModal.8b859d16b8235cd9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/UserFanClubSubscribeModal.11bb18921e466801.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/bootstrap.3726243d4e1ad111.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/bootstrap_dark.abc4945d078be314.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/bootstrap_dark_mobile.abc4945d078be314.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/canvas-performance-test.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CookiesReminder/cookieDark.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/au.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/ca.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/co.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/de.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/ke.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/ua.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/us.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/ve.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/components/ui/CountryFlag/images/za.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/fonts/Inter-Bold.woff2?v=4.1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/fonts/Inter-Medium.woff2?v=4.1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/fonts/Inter-Regular.woff2?v=4.1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/images/static-icons/agreement.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/images/static-icons/asacp.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/images/static-icons/pineapple-support.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/images/static-icons/rta-logo.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/common/images/static-icons/safe-labeling.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/contest-rules.aed27394c3384f20.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/corejs-75349.9e240b24a5ffbb27.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/discovery/components/ModelList/ModelListItem/badges/icons/badge-new-ds.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/discovery/components/ModelList/ModelListItem/badges/icons/badge-vr-ds.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/discovery/components/ModelList/ModelListItem/badges/icons/interactive-toy-ds.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/discovery/components/ModelList/ModelListItem/badges/icons/mobile-phone-ds.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/discovery/components/ModelList/model-loading-dark.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/discovery/components/NonNudeVerifyBanner/resources/de-flag.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/discovery/components/NonNudeVerifyBanner/resources/verified.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/favorites.0096a046196a7647.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/hall-of-fame.2a8493e1890cc747.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/history.03f7aaf5311ab36b.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/favicon-32x32.png?v=9670c787</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/manifest-192x192.png?v=f86ed58a</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/last-24h-winners.787986209f5a1440.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/livetags.e64efe814e3d0a52.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/main.3126b1303eefce93.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/monthly-top-models.f2a3ce8e59c93d86.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/my-collection.7423b137af8a60fb.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/perfect-scrollbar_dark.72abbcdef6a93840.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/profile.7e64eec8787301ae.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/react-74932.10647bbcda6cf480.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/redux-342.c31b3e7947c289b9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/redux-48526.e096bd9b05468601.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/search-all.4af4b43e877bb6de.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/search.2099dacb9f250b49.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/about.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/arrow-down-filled.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/award-hall-of-fame-by-year.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/badge-vr-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/best-models.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/bunny-mask.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/categories-2.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/categories-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/close-2.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/close-3.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/close-arrow.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/cv-search-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/dot.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/favorited.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/filter-slider-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/heart-fill.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/home.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/i18n.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/inquiries.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/interactive-toy-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/lightning.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/locked.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/medal-1.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/medal-3.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/menu-mobile.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/menu.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/mobile.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/next-small.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/photo-2-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/recommended.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/search-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/sort.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/sparks-dark.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/sparks-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/stripchat-logo.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/ticket-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/watch-history.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/svg-icons/x-logo-ds.json?fcd8495b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/translations_en.c387680de7d290.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/vendors-12396.110f6ad74b5cb77e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/vendors-27498.9a122f2d486b11c2.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/vendors-40017.9e28972e9107231a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/vendors-63863.42455e4c9105b361.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/vendors-6440.6c915298c7d894a7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/vendors-66108.607e6a3c16f48ce7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/viewcam.2d1f3fb205b1b109.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.strpssts-ana.com/assets/AmplitudeClientLazy.1dc59775a0815d1f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.strpssts-ana.com/assets/MoengagePort.f6d70c58fe34295a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.strpssts-ana.com/assets/SentryWrapper.e5d7cc25c5c80b2c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdnjs.cloudflare.com/ajax/libs/fingerprintjs2/2.1.2/fingerprint2.min.js</url>
              <origin>URL_RENDER</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>https://creative.eizzih.com/initindex.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://go.eizzih.com/entry</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://go.eizzih.com/entry?url=https%3A%2F%2Fstripchat.com%2Fgirls%3Fsound%3Doff%26affiliateId%3D110526kgf3c7hvz9arvpgy2jvbivwgnc2lnbd1ccehcgrz0j287vzxvaq79m8mqp%26landing%3DgoToTheTag%26realDomain%3Dgo.rmishe.com%26userId%3D31444f1f7c31aecee867955a00dd54a9d5aa89f0f7d7acd01ad95a7504ab23c2&amp;referrer</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://go.eizzih.com/stripchat/widgets</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://go.eizzih.com/stripchat/widgets?promoCampaigns&amp;memberId=0&amp;guestIdUnique=b86db5271c5f04f808de592b40e7c681e2fcecae2676927c85df7e447b9caf2c&amp;url=https%3A%2F%2Fstripchat.com%2Fgirls%3Fsound%3Doff%26affiliateId%3D110526kgf3c7hvz9arvpgy2jvbivwgnc2lnbd1ccehcgrz0j287vzxvaq79m8mqp%26landing%3DgoToTheTag%26realDomain%3Dgo.rmishe.com%26userId%3D31444f1f7c31aecee867955a00dd54a9d5aa89f0f7d7acd01ad95a7504ab23c2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://go.stripchat.com/r</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://go.stripchat.com/r?action=set&amp;favoriteIds&amp;historyIds&amp;isLogged=false&amp;memberId&amp;noc=1&amp;clickTrackId=110526kgf3c7hvz9arvpgy2jvbivwgnc2lnbd1ccehcgrz0j287vzxvaq79m8mqp&amp;guestId&amp;domain=stripchat.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/blurred/1778471820/168543682</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/blurred/1778472150/60246936</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/blurred/1778472300/77085589</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/blurred/1778472600/13844</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/blurred/1778472600/237934994</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/blurred/1778472600/240920936</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/blurred/1778472600/248738784</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/110390233/1778472251</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/119757925/1778472401</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/121247156/1778472369</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/125061376/1778472396</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/131252980/1778472308</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/138539959/1778472187</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/142196021/1778471888</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/162211869/1778471947</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/174927286/1778471799</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/195083246/1778472280</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/197618973/1778472241</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/203647230/1778471841</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/210289946/1778472129</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/218653341/1778471804</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/219171642/1778471863</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/239097528/1778472033</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/239536988/1778472009</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/240965874/1778472092</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/244047467/1778472301</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/244475808/1778472061</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/247647691/1778472340</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/250069009/1778471752</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/250757905/1778472417</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/30597399/1778472220</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/33077830/1778472067</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/51359307/1778471900</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/59045877/1778472213</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/6401/1778471839</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/64366556/1778471769</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/72250054/1778472051</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/72950153/1778472309</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/84739822/1778472253</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/93483446/1778472056</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/9532266/1778471749</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://img.doppiocdn.net/snapshot_blurred/97970164/1778472131</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://mmp.doppiocdn.com/player/mmp/v2.7.1/chunk-2f16997d9906aa8dad9d.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://mmp.doppiocdn.com/player/mmp/v2.7.1/chunk-81c85343ec6878dec551.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://mmp.doppiocdn.com/player/mmp/v2.7.1/chunk-e3b5f7495a197d67e70f.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://mmp.doppiocdn.com/player/mmp/v2.7.1/main.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://pineapplesupport.org/about-pineapple-support/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripcash.com/?utm_source=stripchat&amp;utm_medium=footer&amp;utm_campaign=affiliate</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/api/front/purchase/digest/config?features=abAlternativeCountryB%2CabPIXStarterb%2CabRoundUpSavingsB%2CabUpCheckoutB%2CabXmasNyVisibilityB&amp;alternativeCountry=US&amp;uniq=o1qtvnxyg8fcms6r</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/api/front/v2/logs</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/api/front/v2/models?primaryTag=girls&amp;limit=24&amp;topLimit=61&amp;favoritesLimit=24&amp;removeShows=true&amp;msBlock=true&amp;byw=false&amp;flags=1&amp;srwm=false&amp;rcmGrp=A&amp;rbCnGr=true&amp;iem=true&amp;decMb=true&amp;ctryTop=true&amp;guestHash=b86db5271c5f04f808de592b40e7c681e2fcecae2676927c85df7e447b9caf2c&amp;mlfv=false&amp;rectf=false&amp;nic=true&amp;uniq=ofwxrq3982gtmhv1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/api/front/v2/observability</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/api/front/v2/purchase/guest-promo-config?features=abAlternativeCountryB%2CabPIXStarterb%2CabRoundUpSavingsB%2CabUpCheckoutB%2CabXmasNyVisibilityB&amp;uniq=dkm3nycp1q65fis2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/api/front/v2/purchase/guest-promo-config?features=abAlternativeCountryB%2CabPIXStarterb%2CabRoundUpSavingsB%2CabUpCheckoutB%2CabXmasNyVisibilityB&amp;uniq=oqy72uekwxdc19sl</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/api/front/v3/config/initial-dynamic?requestPath=%2Fgirls</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/blog/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/cdn-cgi/challenge-platform/h/g/jsd/oneshot/fe6331af5207/0.21713051731595623:1778469851:brSW0b8eC9FNS7aZXZmC9k6g3lpZb_ilo1K_dknibvc/9f9e5564194d249b</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/fe6331af5207/main.js?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/girls</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/girls?affiliateId=110526kgf3c7hvz9arvpgy2jvbivwgnc2lnbd1ccehcgrz0j287vzxvaq79m8mqp&amp;landing=goToTheTag&amp;realDomain=go.rmishe.com&amp;sound=off&amp;userId=31444f1f7c31aecee867955a00dd54a9d5aa89f0f7d7acd01ad95a7504ab23c2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/girls?sound=off</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stripchat.com/manifest.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://ststandard.com/adsf</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://support.stripchat.com/hc/en-us/articles/15306146976145-Basic-Tour-for-Users</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://support.stripchat.com/hc/en-us/articles/15413653350417-DMCA-content-takedown-service</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.asacp.org/?content=validate&amp;ql=b9b25de5ba5da974c585d9579f8e9d49</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.rtalabel.org/?content=validate&amp;ql=b9b25de5ba5da974c585d9579f8e9d49&amp;rating=RTA-5042-1996-1400-1577-RTA</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.unseenuk.org/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://x.com/stripchat</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>mailto:press@stripchat.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>go.rmishe.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/girls?sound=off&amp;affiliateId=110526kgf3c7hvz9arvpgy2jvbivwgnc2lnbd1ccehcgrz0j287vzxvaq79m8mqp&amp;landing=goToTheTag&amp;realDomain=go.rmishe.com&amp;userId=31444f1f7c31aecee867955a00dd54a9d5aa89f0f7d7acd01ad95a7504ab23c2</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://stripchat.com/girls?sound=off&amp;affiliateId=110526kgf3c7hvz9arvpgy2jvbivwgnc2lnbd1ccehcgrz0j287vzxvaq79m8mqp&amp;landing=goToTheTag&amp;realDomain=go.rmishe.com&amp;userId=31444f1f7c31aecee867955a00dd54a9d5aa89f0f7d7acd01ad95a7504ab23c2&amp;referrer</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>stripchat.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>api-sr.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.chapturist.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.strpssts-ana.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>discord.gg</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sentry-public.stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sr-client-cfg.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>x.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.chapturist.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>assets.strpssts-ana.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdnjs.cloudflare.com</url>
              <origin>URL_RENDER</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>creative.eizzih.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>go.eizzih.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>go.stripchat.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>img.doppiocdn.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>mmp.doppiocdn.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>pineapplesupport.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>stripcash.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>stripchat.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>ststandard.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>support.stripchat.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.asacp.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.rtalabel.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.unseenuk.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>x.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <emails>
            <value>
              <email>d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com</email>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>104.17.118.12</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.75</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.11.106</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.136.234</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.10.106</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.17.118.12</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.17.223.114</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.17.24.14</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.21.71.4</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.64.147.206</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>65.8.131.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.18.53.241</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.10.106</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.116</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>184.33.2.216</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.140.229</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>184.33.2.216</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.11.106</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.10.106</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.136.234</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.118.12</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.75</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.116</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.53.241</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.140.229</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>9670c78727119ad8a4bd51434c76f415</MD5>
              <SHA-1>e2ed790fa0559050f279521407d7d55061bfbce8</SHA-1>
              <SHA-256>0b3f9c85a5564bb1ce247e7171891c838565c9c189c44b0b345dd38877b96513</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>f2f0c2f20d8a409950e8043dfdbcabcc</MD5>
              <SHA-1>f6dbfe227f7fe327ddd9bbfbaa2f2c76a297508c</SHA-1>
              <SHA-256>9c2744b63f5011f4013a606e9e82cf2fd7e93d1137377bbb36f985829db80414</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>4f3e5e4bb3e151b1a80c2bdcc9c12d71</MD5>
              <SHA-1>8266ea2804b0968beee94faef9f912b4c7a368ad</SHA-1>
              <SHA-256>006019dd903e44adba3b5693faaba5bf06555a8951c8b25ff6a7dd088cbe4c9f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/jpeg</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ec3c3bc9754398d23a777b9ea076cd1e</MD5>
              <SHA-1>779550b440c9cc3e93be366b0ca0bd839f713da8</SHA-1>
              <SHA-256>add0cf2e32d17a36422f9f41edd66e51a6cbf0543257219093647c0c0d4ca5c7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>5edfde793ea8a7d8fe503279494e5434</MD5>
              <SHA-1>0fb91ca98a813bf564d64ee48eb91730c8f090e3</SHA-1>
              <SHA-256>582d184a24ed9073c56543e8e612336f5033617058847593f3cea9edac551e05</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>5fc50b858cf9e2483be10d02d7322aa3</MD5>
              <SHA-1>bde6b7a4b090d67b119548d194fa04b587c91401</SHA-1>
              <SHA-256>e2c2282fb0e5468e1d42c382137fd0e35a7d31b221863444f22c37cc14899033</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>f051cafa24bb2da5fe076b037cfacf5b</MD5>
              <SHA-1>226a9f3f56b44ea44d967476ca72b77495c727b3</SHA-1>
              <SHA-256>54ba43999e77751005b40dd104ed0091f9669464395e308780b0e0b8fe086642</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>bd756308e0e483d2a90e84ffcb8125ff</MD5>
              <SHA-1>08900d65a5b30dd7e74fcf4499967ce671981c53</SHA-1>
              <SHA-256>a30bb5a674290ae82138534fbd681d9cff0f37ea361fab42aa1b7dc05a255f45</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>LIKELY_MALICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>a41e718a3b1fd80ecf87ecec9e81dd4d</name>
        <report_id>b0d09aca-fd60-4cfa-bde1-d3d7f687bbd3</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>jpg</value>
          <value>png</value>
          <value>svg</value>
          <value>phishing</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>5de75bd99bdfb34e37b2dc023119f533da5679dcabe45a1f8a7d8cbeee1363f9</id>
    <title>Analysis Report for 5de75bd99bdfb34e37b2dc023119f533da5679dcabe45a1f8a7d8cbeee1363f9</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156f70f7e400110050b59</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01562b2fcb905ec28c7a74</flow_id>
        <hash>5de75bd99bdfb34e37b2dc023119f533da5679dcabe45a1f8a7d8cbeee1363f9</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>0a431eb73fc86af08c4f92afb27abbdf</name>
        <report_id>e03fd31d-9bcd-43f7-92a3-16011248a6e4</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>717629cf520392147d00df2e9a2ee16d2e90e470781e3ca543254ab3cd89a7f3</id>
    <title>Analysis Report for 717629cf520392147d00df2e9a2ee16d2e90e470781e3ca543254ab3cd89a7f3</title>
    <updated>2026-05-11T04:08:58Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156e20f7e400110050b3e</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01561c792fe2d217aed8a2</flow_id>
        <hash>717629cf520392147d00df2e9a2ee16d2e90e470781e3ca543254ab3cd89a7f3</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>d53e68d4e7b93dcf7239ac8c12049457</name>
        <report_id>7ca620a3-061f-4c54-ba00-027c9cb248a4</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>4b8952e6d7e9f36ad2a17480dd2f73c411ee44d18a47d7fa519d039906f63626</id>
    <title>Analysis Report for 4b8952e6d7e9f36ad2a17480dd2f73c411ee44d18a47d7fa519d039906f63626</title>
    <updated>2026-05-11T04:08:57Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01566bd6e5cdb561983540</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01564d792fe2d217aed8d2</flow_id>
        <hash>4b8952e6d7e9f36ad2a17480dd2f73c411ee44d18a47d7fa519d039906f63626</hash>
        <iocs/>
        <name>5ca4948b13cf8e0c59754f9924e0ae96</name>
        <report_id>e4b0e8cb-a53c-4eef-a7a8-7f536d9a1664</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6648f31275e4ec7b6e654c7c7ca7a5303cbd9062cfdbaabf10715b4eb1334aa5</id>
    <title>Analysis Report for 6648f31275e4ec7b6e654c7c7ca7a5303cbd9062cfdbaabf10715b4eb1334aa5</title>
    <updated>2026-05-11T04:08:56Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01566db87f27901eb5eed0</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0156552fcb905ec28c7aad</flow_id>
        <hash>6648f31275e4ec7b6e654c7c7ca7a5303cbd9062cfdbaabf10715b4eb1334aa5</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>9caa373befa154ad89447adc1a3e217091d08c4bd59f554f04465edf3fa286de</SHA-256>
              <SHA-1>c258706ad88ee6dc0282f7090bec4d5f8e232a1f</SHA-1>
              <MD5>0ffd199cc68e43f9583c904fde0e4ab3</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>x6648f31275e4ec7b6e654c7c7ca7a5303cbd9062cfdbaabf10715b4eb1334aa5.exe</name>
        <report_id>d195c6d5-bf19-4c1f-88f0-23d33c5dbafd</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>windows</value>
          <value>wirenet</value>
          <value>keylogger</value>
          <value>stealer</value>
          <value>compiled-script</value>
          <value>anti-debug</value>
          <value>overlay</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bb3c3a32d19f708df6f2df52172ecfad28560a82d02812e456f290c2b31116f4</id>
    <title>Analysis Report for bb3c3a32d19f708df6f2df52172ecfad28560a82d02812e456f290c2b31116f4</title>
    <updated>2026-05-11T04:08:54Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01566ad6e5cdb56198353f</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156489b72a1a5304c770d</flow_id>
        <hash>bb3c3a32d19f708df6f2df52172ecfad28560a82d02812e456f290c2b31116f4</hash>
        <iocs/>
        <name>5c4dd33b856ec0534c7d8d3fd6ad1419</name>
        <report_id>99a7af58-64ac-42ba-82f1-badbedfa48ab</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>d27ba62770d39632a4c4d58b60c47a18c16346c94a9f468248a25d029ba04bf7</id>
    <title>Analysis Report for d27ba62770d39632a4c4d58b60c47a18c16346c94a9f468248a25d029ba04bf7</title>
    <updated>2026-05-11T04:08:51Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015665d6e5cdb56198353b</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015643df14f1cb2acf7146</flow_id>
        <hash>d27ba62770d39632a4c4d58b60c47a18c16346c94a9f468248a25d029ba04bf7</hash>
        <iocs/>
        <name>eadd52fc0628ac977838acb4a247f07e</name>
        <report_id>65f7a4b6-093f-447f-9454-73a49001c4f5</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e62f955c1be0c9c308c9a1b4a95350627614c0a34e67a789612f155170f728d4</id>
    <title>Analysis Report for e62f955c1be0c9c308c9a1b4a95350627614c0a34e67a789612f155170f728d4</title>
    <updated>2026-05-11T04:08:51Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015664d6e5cdb561983539</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01564486e92bda70271010</flow_id>
        <hash>e62f955c1be0c9c308c9a1b4a95350627614c0a34e67a789612f155170f728d4</hash>
        <iocs/>
        <name>0cee9e0b61f004150d43900b02449902</name>
        <report_id>9339f0a7-86c6-4cc1-ad99-6c1ce071e689</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>deca9ef7a81f2fa8c6329c79d98610fa474e5487754a2260469131a4f9c58e57</id>
    <title>Analysis Report for deca9ef7a81f2fa8c6329c79d98610fa474e5487754a2260469131a4f9c58e57</title>
    <updated>2026-05-11T04:08:51Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015666d6e5cdb56198353d</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156462fcb905ec28c7a96</flow_id>
        <hash>deca9ef7a81f2fa8c6329c79d98610fa474e5487754a2260469131a4f9c58e57</hash>
        <iocs/>
        <name>edfc25c1c8cc65c2b96b1866843b1aea</name>
        <report_id>e6411fb3-2d02-4c0e-b18b-36153e87039c</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e651085e00ddac29234e12265957337e9834fdd5bd1da8bd704c5f6ef08c044a</id>
    <title>Analysis Report for e651085e00ddac29234e12265957337e9834fdd5bd1da8bd704c5f6ef08c044a</title>
    <updated>2026-05-11T04:08:51Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015662d6e5cdb561983538</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015646792fe2d217aed8cb</flow_id>
        <hash>e651085e00ddac29234e12265957337e9834fdd5bd1da8bd704c5f6ef08c044a</hash>
        <iocs/>
        <name>fce6c7d98b3031de64dc13461d522f6b</name>
        <report_id>8bbb7ebd-39c6-45d9-a841-fc415637ea95</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>eb6f90d3a857fe94179558e8ebd347177901f505d5c3c3836d96066bb7dfc015</id>
    <title>Analysis Report for eb6f90d3a857fe94179558e8ebd347177901f505d5c3c3836d96066bb7dfc015</title>
    <updated>2026-05-11T04:08:36Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015652d6e5cdb56198352f</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015635792fe2d217aed8bb</flow_id>
        <hash>eb6f90d3a857fe94179558e8ebd347177901f505d5c3c3836d96066bb7dfc015</hash>
        <iocs/>
        <name>73a5b21eb1daf83f8844390b98e837c2</name>
        <report_id>4b982117-a109-4229-b21c-28d060ba14dd</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>0ee4464e48d594cfc837f3e42bbcccae441fa0de0ff0e0c8333570b70e9791cf</id>
    <title>Analysis Report for 0ee4464e48d594cfc837f3e42bbcccae441fa0de0ff0e0c8333570b70e9791cf</title>
    <updated>2026-05-11T04:08:36Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015656d6e5cdb561983531</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156362fcb905ec28c7a7f</flow_id>
        <hash>0ee4464e48d594cfc837f3e42bbcccae441fa0de0ff0e0c8333570b70e9791cf</hash>
        <iocs/>
        <name>5d50cdb18526e25668b4d35c5f088207</name>
        <report_id>6cadbdd4-a5c4-4096-9185-b53fc637b4ef</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>70e3a2910fa7ccf35d5fb223e40e59918fed5b08ab9d98889c9e7e17e29ea909</id>
    <title>Analysis Report for 70e3a2910fa7ccf35d5fb223e40e59918fed5b08ab9d98889c9e7e17e29ea909</title>
    <updated>2026-05-11T04:08:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01571a0f7e400110050b7b</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01560986e92bda70270fbe</flow_id>
        <hash>70e3a2910fa7ccf35d5fb223e40e59918fed5b08ab9d98889c9e7e17e29ea909</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/ejai.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;moeud=3949086986&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://api-sr.amplitude.com/sessions/v2/track</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/appicon.png?v=9670c787</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/lightlogo.svg?v=f2f0c2f2</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/metaogimage.jpg?v=4f3e5e4b</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/icons/watermark.svg?v=ec3c3bc9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.chapturist.com/assets/translations_en.c387680de7d290.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://assets.strpssts-ana.com/assets</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com/9</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://discord.gg/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://sr-client-cfg.amplitude.com/config</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/blog</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/model</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://stripchat.com/signup/studio</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://x.com/stripchat</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/ejai.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>api-sr.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.chapturist.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>assets.strpssts-ana.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>discord.gg</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sentry-public.stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>sr-client-cfg.amplitude.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripcash.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.app</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>stripchat.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>x.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <emails>
            <value>
              <email>d8629522213649e7a4e0b63d14e1dc5f@sentry-public.stripchat.com</email>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>104.17.10.106</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.48.38</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>184.33.76.13</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.134.234</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.117.12</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.140</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.2</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>184.33.76.13</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.10.106</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.134.234</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.17.117.12</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>13.32.121.2</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.55.140</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.48.38</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.66.0.227</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>9670c78727119ad8a4bd51434c76f415</MD5>
              <SHA-1>e2ed790fa0559050f279521407d7d55061bfbce8</SHA-1>
              <SHA-256>0b3f9c85a5564bb1ce247e7171891c838565c9c189c44b0b345dd38877b96513</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>4f3e5e4bb3e151b1a80c2bdcc9c12d71</MD5>
              <SHA-1>8266ea2804b0968beee94faef9f912b4c7a368ad</SHA-1>
              <SHA-256>006019dd903e44adba3b5693faaba5bf06555a8951c8b25ff6a7dd088cbe4c9f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/jpeg</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>f2f0c2f20d8a409950e8043dfdbcabcc</MD5>
              <SHA-1>f6dbfe227f7fe327ddd9bbfbaa2f2c76a297508c</SHA-1>
              <SHA-256>9c2744b63f5011f4013a606e9e82cf2fd7e93d1137377bbb36f985829db80414</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ec3c3bc9754398d23a777b9ea076cd1e</MD5>
              <SHA-1>779550b440c9cc3e93be366b0ca0bd839f713da8</SHA-1>
              <SHA-256>add0cf2e32d17a36422f9f41edd66e51a6cbf0543257219093647c0c0d4ca5c7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/svg+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>7f8aa88c250e52c3c5920cf65ad6f6ba</MD5>
              <SHA-1>5fa67b947c8a5bdfe5d854955793c426d35e7f8b</SHA-1>
              <SHA-256>689fd88d522594e2e13f55321119bfd7c74c4bb8014f0a3cc53731c32b18dcd5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>d566bd31520de0aacdf7132c71fd4362</MD5>
              <SHA-1>60e724c4aed2b1810f088c6f404bf9e863c4630f</SHA-1>
              <SHA-256>c8c269af09506ddcf7931b6a50e05c55d6d2bf9038f64a323cf1e565d48d8a17</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>67e7da12971d8336af6338cea6074e21</MD5>
              <SHA-1>94acaa32e381071de83e757a9cb96ae98755a34e</SHA-1>
              <SHA-256>129dff7a8ad1182e3d1900a8d9f2b1039d7defcebcdd6ebf479ee9d29a27d062</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>bd756308e0e483d2a90e84ffcb8125ff</MD5>
              <SHA-1>08900d65a5b30dd7e74fcf4499967ce671981c53</SHA-1>
              <SHA-256>a30bb5a674290ae82138534fbd681d9cff0f37ea361fab42aa1b7dc05a255f45</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>LIKELY_MALICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>6704c02cbf00ce0573d129a01aadb85b</name>
        <report_id>05e0fd4d-7edc-45bb-9242-f608938187ad</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>svg</value>
          <value>jpg</value>
          <value>png</value>
          <value>phishing</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>107e97dacbd422a9ef604f239474cc88ce1e02a8d72e0c69fc6ae23071dfb3a6</id>
    <title>Analysis Report for 107e97dacbd422a9ef604f239474cc88ce1e02a8d72e0c69fc6ae23071dfb3a6</title>
    <updated>2026-05-11T04:08:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156d20f7e400110050b2f</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01560e2fcb905ec28c7a55</flow_id>
        <hash>107e97dacbd422a9ef604f239474cc88ce1e02a8d72e0c69fc6ae23071dfb3a6</hash>
        <iocs>
          <urls>
            <value>
              <url>http://milfhd.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://milfhd.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://milfhd.eu/analiz.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/bnnw.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;vlizi=2670775525&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/bnnw.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;kpcug=1&amp;vlizi=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>tubevideo.eu</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>milfhd.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.36.162.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.36.162.157</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>81b1f363a3d3ab7b35063ea8ef0a6521</MD5>
              <SHA-1>ef201dc8912286913abac221477f9c5909e089ae</SHA-1>
              <SHA-256>3153fb9cdf68305b1f84941b4decb770cd5a884793043e959269aec64c18a606</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xhtml+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>d8e2834c8560cbbe22ecb6892637bd0a</MD5>
              <SHA-1>7cd165af17adb4772a3037c9bc311baff88cffb0</SHA-1>
              <SHA-256>4718ab82fc387c814e8cc0a8b3926fa1cc5f2adaf3fb345db0ab6cd0bdbd38c0</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>b4b1b8e456c6e746728cfb27b79cdcf7</MD5>
              <SHA-1>1683d823e0d8fe74c66088b5962125d07f5e667c</SHA-1>
              <SHA-256>0d8736b216ac571cbc17ab49fe20eb779fee3a324bcd61629635e6169a86ba6f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>4ec4d7b93028ad5883bf90af61a780f9</name>
        <report_id>2d32f8b4-5f6a-44da-851d-c35ff95f7a98</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b0386c7a7900cd362107e29c300c3d83f416c5bc3fd3ecc472befe54a83eef20</id>
    <title>Analysis Report for b0386c7a7900cd362107e29c300c3d83f416c5bc3fd3ecc472befe54a83eef20</title>
    <updated>2026-05-11T04:08:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156b50f7e400110050b0e</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01560cdf14f1cb2acf7111</flow_id>
        <hash>b0386c7a7900cd362107e29c300c3d83f416c5bc3fd3ecc472befe54a83eef20</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmp5mys_sav.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://orangeventi.co/?ch=1&amp;js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc1MzM5MjMwMSwiaWF0IjoxNzUzMzg1MTAxLCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMWFrY3RkOWwwZ2NiZzNjbzQyNDZ0czciLCJuYmYiOjE3NTMzODUxMDEsInRzIjoxNzUzMzg1MTAxMTAyMTAxfQ.4r0ehPmkyui-zaHhFCVBqOzNrQXh0XhyTTuGfFyGE_U&amp;sid=e48f7887-68c3-11f0-b7a0-0de634cf22fb</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://orangeventi.co/?ch=1&amp;js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc1MzM5MjMwMSwiaWF0IjoxNzUzMzg1MTAxLCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMWFrY3RkOWwwZ2NiZzNjbzQyNDZ0czciLCJuYmYiOjE3NTMzODUxMDEsInRzIjoxNzUzMzg1MTAxMTAyMTAxfQ.4r0ehPmkyui-zaHhFCVBqOzNrQXh0XhyTTuGfFyGE_U&amp;sid=e48f7887-68c3-11f0-b7a0-0de634cf22fb</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://orangeventi.co/?ch=1&amp;js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc1MzM5MjMwMSwiaWF0IjoxNzUzMzg1MTAxLCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMWFrY3RkOWwwZ2NiZzNjbzQyNDZ0czciLCJuYmYiOjE3NTMzODUxMDEsInRzIjoxNzUzMzg1MTAxMTAyMTAxfQ.4r0ehPmkyui-zaHhFCVBqOzNrQXh0XhyTTuGfFyGE_U&amp;sid=e48f7887-68c3-11f0-b7a0-0de634cf22fb</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>orangeventi.co</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>orangeventi.co</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <files>
            <value>
              <MD5>3ca0670618f38a3af6780fc882a1ff9e</MD5>
              <SHA-1>887164b44f45b61778d1a66f4e2fb0c6249d8c45</SHA-1>
              <SHA-256>a3762398864513ffa79c3bc35c2ad35742b9bd44e26b09c5b5085e0ba44aa451</SHA-256>
              <origin>MSHTA_EMULATION</origin>
              <file_type>application/json</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>e48f7887-68c3-11f0-b7a0-0de634cf22fb</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>e48f7887-68c3-11f0-b7a0-0de634cf22fb</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>f0a68817348c647c7c9bca1724655fdd</name>
        <report_id>1b917879-4426-48f5-b057-39f6ec465fff</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
          <value>obfuscated</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e89c4db07f96e966e0b520cbff803d8e85318b59e2f4a1914103aa475ff40095</id>
    <title>Analysis Report for e89c4db07f96e966e0b520cbff803d8e85318b59e2f4a1914103aa475ff40095</title>
    <updated>2026-05-11T04:08:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156dc0f7e400110050b39</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01560a2fcb905ec28c7a51</flow_id>
        <hash>e89c4db07f96e966e0b520cbff803d8e85318b59e2f4a1914103aa475ff40095</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>3b5153e49bd821e459ec00be25e2cf34</name>
        <report_id>e93e983e-cbfe-451d-b24a-c03f0aef2350</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>d9ec58791724f9c8f8b58b9862f60cf845d888d182a6570b22dd8a169f67a7d3</id>
    <title>Analysis Report for d9ec58791724f9c8f8b58b9862f60cf845d888d182a6570b22dd8a169f67a7d3</title>
    <updated>2026-05-11T04:08:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01569b0f7e400110050af1</_id>
        <file_type>application/x-ms-shortcut</file_type>
        <flow_id>6a015602df14f1cb2acf7109</flow_id>
        <hash>d9ec58791724f9c8f8b58b9862f60cf845d888d182a6570b22dd8a169f67a7d3</hash>
        <iocs>
          <uuids>
            <value>
              <uuid>00021401-0000-0000-C000-000000000046</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>5e9421b9aa61c21ba18b12b6070c32b8</name>
        <report_id>1cd32810-d639-4196-ab2a-e7fe881ba82e</report_id>
        <tags>
          <value>lnk</value>
          <value>dunihi</value>
          <value>jenxcus</value>
          <value>networm</value>
          <value>cmd</value>
          <value>lolbin</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>684360b7d5c368f78ec83758328e5c3e1dadf477f16ef167fd4a5158fa9fac70</id>
    <title>Analysis Report for 684360b7d5c368f78ec83758328e5c3e1dadf477f16ef167fd4a5158fa9fac70</title>
    <updated>2026-05-11T04:08:32Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156d10f7e400110050b2e</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01560886e92bda70270fbb</flow_id>
        <hash>684360b7d5c368f78ec83758328e5c3e1dadf477f16ef167fd4a5158fa9fac70</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/isuhzngmq.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://majus.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://majus.pw/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://majus.pw/diznovua/font-awesome.min.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://majus.pw/diznovua/stylesheet.min.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/isuhzngmq.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=1111674695&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://a.magsrv.com/video-slider.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>a.magsrv.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>majus.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>79.127.211.89</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>77.83.173.164</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>79.127.211.89</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>77.83.173.164</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>dab40cad70d9c8119eeaa952884f2727</MD5>
              <SHA-1>62b439ebf36ec434c725d1449af9631a8b3ee053</SHA-1>
              <SHA-256>cb485facab78d3e3f5c782f9a97507d1bbb2114f6c019f46583b8e82bbf92cb7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>e007f16c378a8ac9aa83063fbb9de816</MD5>
              <SHA-1>d1c87cfc6abcf5a6dec54799681f9399f31dab75</SHA-1>
              <SHA-256>60a4831ee924c4bf5063767ee112040c09a31d460e7a63d7341551f079dd6d96</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>9ed669267a3f7ddb5fd95798d279434c</MD5>
              <SHA-1>56747d2c3f35049523c8e19651ae728cefead5ef</SHA-1>
              <SHA-256>0ca61ab6de8887baeb21e05bcbdd64cdf35bff944873d797efd394519f1b9420</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>f075eeb7082f2a6e38bd066cff47bd29</MD5>
              <SHA-1>212f32e08434455a5fbb90083b17830c4508b46e</SHA-1>
              <SHA-256>f54fa78c59249407458282fd4a6bb591bac87f683e608d6fa83b56d0a522fd09</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>66fe320025f66fcce8aaa498ed5b0743</MD5>
              <SHA-1>e8a4cb7ef5018e77a6ab365ffcbe9e150392d92f</SHA-1>
              <SHA-256>b621667ccda5a07c30dbad7fbaddec3479965b9823e0dae0d7c5cc7306b838b1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>701fc68a9d98614f3d344ea05cc5b6f8</name>
        <report_id>26b78140-2f57-499a-a185-5fdd8e12b8fa</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c74d2059d0dcd254e31866bd78ead711496b72541ced0d38904531f1951cacef</id>
    <title>Analysis Report for c74d2059d0dcd254e31866bd78ead711496b72541ced0d38904531f1951cacef</title>
    <updated>2026-05-11T04:08:29Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01568c0f7e400110050adc</_id>
        <file_type>application/x-msdownload; format=pe</file_type>
        <flow_id>6a0155e3fd9cdd68416ef467</flow_id>
        <hash>c74d2059d0dcd254e31866bd78ead711496b72541ced0d38904531f1951cacef</hash>
        <iocs/>
        <name>0502f07569bf583db0ec99a11c9fa476</name>
        <report_id>26cb6dce-0549-46e4-984c-8fdf0aad2929</report_id>
        <tags>
          <value>peexe</value>
          <value>pedll</value>
          <value>gamarue</value>
          <value>zusy</value>
          <value>packed</value>
          <value>lolbin</value>
          <value>rundll32</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ced82528b08a52a9a0aaaffdeda31641897e0973685562506f88674a3da1cf98</id>
    <title>Analysis Report for ced82528b08a52a9a0aaaffdeda31641897e0973685562506f88674a3da1cf98</title>
    <updated>2026-05-11T04:08:29Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015649b87f27901eb5eec8</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a01563adf14f1cb2acf713b</flow_id>
        <hash>ced82528b08a52a9a0aaaffdeda31641897e0973685562506f88674a3da1cf98</hash>
        <iocs>
          <urls>
            <value>
              <url>http://nsis.sf.net/NSIS_Error</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>nsis.sf.net</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <emails>
            <value>
              <email>Pseudochromia@Uovervindelighed.Te1</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.21.237</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.21.237</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>27696bbeca252447cd36391adf04dc2b446b319a4b06b8e5a48668957d00ef05</SHA-256>
              <SHA-1>9430a139e39427ebddbc89f59cd23dcdbd79d322</SHA-1>
              <MD5>1ae8e9847cd22cd7d60a83f7694d7e27</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>31e86baa33fe26cb64a41263b0f24c2a483ad0aff4c8abc2e6095abb8ace9769</SHA-256>
              <SHA-1>67aa3801dfdff0c20aa9348ceb9f9843eff2f71a</SHA-1>
              <MD5>db5aa155f527a0f20bbc59bef3201713</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>439931f0aaa24d3332f84ea45d40f93b56b2948c56be92e78482a1989a491a61</SHA-256>
              <SHA-1>286a35bda40b16a5d53a950a66bb7ba0ccade96e</SHA-1>
              <MD5>2ff34998dea0aab0118e1239e551d446</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>54b90b989ee83351d8e6b8d5639fb2c002bd46170fa740cdae262b955a8f6405</SHA-256>
              <SHA-1>beaae5129019a5454294f1804b829bb0e5bb945c</SHA-1>
              <MD5>bb53605fedbf654872c06a776f4f0fff</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/x-nsis-decompiled</file_type>
            </value>
            <value>
              <SHA-256>5fdca3348172651116726134565e6e46a1e82aadfc9ba57a6fa5333d7329d3b2</SHA-256>
              <SHA-1>6b6a5bf85ec16aa642d412a3af631dfe41ec7559</SHA-1>
              <MD5>f7084a1fb0f96f967b4977b3fc4c6c14</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>6e22059433c4c4beb58c5c237e3cced842e612f959eb9798e16e8e3d1d53ff00</SHA-256>
              <SHA-1>844ac0f5e026d789ee73cefdeb27f5d237dceafa</SHA-1>
              <MD5>38f4dad87089422df42ec16bc4afa76b</MD5>
              <origin>INSTALLER_EXTRACTION</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>8655f1d8f78cd6d4544b9932f069e85356b840085ebb507ee57a744cf3c2048e</SHA-256>
              <SHA-1>c42651117f619918e8de51970c9c5e3a9ec720d3</SHA-1>
              <MD5>e4558b3e45ea75c6e153f259e44e5e23</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Chiropterygium146\', '0', 1</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\driverlivs', 'mineas', 0</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\nabolaget\', '0', 1</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\regnebrts\', '0', 0</registry>
              <origin>EXTRACTED_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion</registry>
              <origin>INPUT_FILE</origin>
            </value>
          </registry>
        </iocs>
        <name>TransEuropeasia.exe</name>
        <report_id>99121d0f-61fc-420a-ad3e-5553a36053b3</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>installer</value>
          <value>reconnaissance</value>
          <value>nsis</value>
          <value>microsoft_visual_cc</value>
          <value>signed</value>
          <value>adaptive-context</value>
          <value>anti-debug</value>
          <value>evasive</value>
          <value>packed</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6fbdfe0883986b1059a326ea3b1de43da34b5847a819e8960383cf6552d0e659</id>
    <title>Analysis Report for 6fbdfe0883986b1059a326ea3b1de43da34b5847a819e8960383cf6552d0e659</title>
    <updated>2026-05-11T04:08:20Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015646d6e5cdb56198352b</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01562586e92bda70270fec</flow_id>
        <hash>6fbdfe0883986b1059a326ea3b1de43da34b5847a819e8960383cf6552d0e659</hash>
        <iocs/>
        <name>0921d069f649a314e796e8ed683f5f29</name>
        <report_id>30a7bc63-0136-4760-98bd-c98a7163cbdb</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>29ac8bc9370c61b94dbcb62f7292696a7d5345fdd54e3dd0a9d7e35d6d4eb624</id>
    <title>Analysis Report for 29ac8bc9370c61b94dbcb62f7292696a7d5345fdd54e3dd0a9d7e35d6d4eb624</title>
    <updated>2026-05-11T04:08:09Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015638d6e5cdb561983525</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01561b86e92bda70270fd3</flow_id>
        <hash>29ac8bc9370c61b94dbcb62f7292696a7d5345fdd54e3dd0a9d7e35d6d4eb624</hash>
        <iocs/>
        <name>c129c939bce107d494e7ffa3503c1a96</name>
        <report_id>227708e0-0a68-4122-bd3b-7e0f83ceaf51</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>26d57ac3acc436cbe98089b58c7214007f66fe301501b1e88390bbf24ad73e67</id>
    <title>Analysis Report for 26d57ac3acc436cbe98089b58c7214007f66fe301501b1e88390bbf24ad73e67</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156e70f7e400110050b46</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155ecdf14f1cb2acf70f3</flow_id>
        <hash>26d57ac3acc436cbe98089b58c7214007f66fe301501b1e88390bbf24ad73e67</hash>
        <iocs>
          <urls>
            <value>
              <url>http://maturexxx.cyou</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://maturexxx.cyou/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/tzh.cgi?9&amp;group=ban1</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/zojjgsln.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=215195770&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/zojjgsln.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>maturexxx.cyou</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>51.91.251.47</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>9093cbaf89154e3f4b64426bd2424015</MD5>
              <SHA-1>db6cd57f57f7f770251aece75cbc67e11bd10808</SHA-1>
              <SHA-256>7d7b93104c39b99204dbb2a3f2472c97417e055e66c41180ba426b522a09450d</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>6bdeb53f7532421e2f038c64a9d95f24</MD5>
              <SHA-1>9ac01f05981fc158693d97d2d86e0bbe2075bbfc</SHA-1>
              <SHA-256>7a79966e5312c0c184ffaa8960430ac3653404fcd8d455a9c07b3ad3c5610cb7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>29e9970487748a0ca60987424b76e369</MD5>
              <SHA-1>513673d541b64c0f03b26f6ad48659bad903faba</SHA-1>
              <SHA-256>de817d1ddf16fa8f46420586aa5ec93195babf911f13a7d2dbeb31388d356576</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>96e3007becddf3fc49ff1f9275ae980b</MD5>
              <SHA-1>fa8fbca34be79c2396cd6899e49b7fb35b8bc2b9</SHA-1>
              <SHA-256>87e56a806fdae0237568675e28a3974e077275d5cdd35fbbc0279ea69be447bc</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
        </iocs>
        <name>5611159f11050632ec91ea6cf55f8f92</name>
        <report_id>f11ebe49-7545-4c96-b6b3-f1d94414cd10</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e929a074cc889d859ad56644c1552da718db7a7582f4d318735fddca1a62fdf5</id>
    <title>Analysis Report for e929a074cc889d859ad56644c1552da718db7a7582f4d318735fddca1a62fdf5</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156c70f7e400110050b24</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155e62fcb905ec28c79fc</flow_id>
        <hash>e929a074cc889d859ad56644c1552da718db7a7582f4d318735fddca1a62fdf5</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmptuh1skq0.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js?pcId=53&amp;domain=mn04i3.sbs</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/images/pe262/ns_logo_dark.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parklogic.com/Contact-us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout?utm_source=expired&amp;utm_medium=parklogic&amp;dr=mn04i3.sbs</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>mn04i3.sbs</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>parking3.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.232.7.47</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>3a54af737feb13ad0f0c24193c6e9f81</name>
        <report_id>ec0ee0fb-4897-47bf-a5fd-e83c0d7854e9</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>d3e809b4b8442837f92fa5f55165edb1769af1a764cc72f346df98cdee8b0e7a</id>
    <title>Analysis Report for d3e809b4b8442837f92fa5f55165edb1769af1a764cc72f346df98cdee8b0e7a</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156bf0f7e400110050b1a</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155ef792fe2d217aed881</flow_id>
        <hash>d3e809b4b8442837f92fa5f55165edb1769af1a764cc72f346df98cdee8b0e7a</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmp9r4qv8qm.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js?pcId=53&amp;domain=selector8081.buzz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/images/pe262/ns_logo_dark.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parklogic.com/Contact-us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout?utm_source=expired&amp;utm_medium=parklogic&amp;dr=selector8081.buzz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>selector8081.buzz</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>parking3.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.232.7.47</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>80bbccb376c2521f458a632a7f4bcbb8</name>
        <report_id>78b251da-108b-447c-b1d8-4ae776398357</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>5120aacfd41de8fe8f1706fe85b0fd6f5878b98aa23358eb5595f05686bcb25e</id>
    <title>Analysis Report for 5120aacfd41de8fe8f1706fe85b0fd6f5878b98aa23358eb5595f05686bcb25e</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01567b0f7e400110050ac9</_id>
        <file_type>application/hta</file_type>
        <flow_id>6a0155e42fcb905ec28c79f1</flow_id>
        <hash>5120aacfd41de8fe8f1706fe85b0fd6f5878b98aa23358eb5595f05686bcb25e</hash>
        <iocs/>
        <name>13470ee2efc654b6d45614a397e469f6</name>
        <report_id>8b89556e-bd9c-49df-8075-ad13d5e6f92a</report_id>
        <tags>
          <value>hta</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bab49f6c184d70ded731c661c74dc618c43ce65407f2aacd91d2d97d8be596d6</id>
    <title>Analysis Report for bab49f6c184d70ded731c661c74dc618c43ce65407f2aacd91d2d97d8be596d6</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01567e0f7e400110050acc</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155e92fcb905ec28c7a04</flow_id>
        <hash>bab49f6c184d70ded731c661c74dc618c43ce65407f2aacd91d2d97d8be596d6</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/pewlzw.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://oldnudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://oldnudist.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/pewlzw.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2966224867&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>oldnudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>77.83.173.164</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>77.83.173.164</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>adbce5dfa498dd2492dc2e69e8a56b58</MD5>
              <SHA-1>214a7aa503c75be2f3351f1bc95cff7a77d4ed64</SHA-1>
              <SHA-256>2f1522fa15ae5d7e5299ce1d756f0540bc90a174810db03689349005e60e50a8</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9ed669267a3f7ddb5fd95798d279434c</MD5>
              <SHA-1>56747d2c3f35049523c8e19651ae728cefead5ef</SHA-1>
              <SHA-256>0ca61ab6de8887baeb21e05bcbdd64cdf35bff944873d797efd394519f1b9420</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>70134890d00cdec66e766d5bfb2be393</MD5>
              <SHA-1>6f9499dabfb683437b4b4caedb5525dea547c5dc</SHA-1>
              <SHA-256>ed3022b9effa0c3a190e4a1cb08ac355d3914388c9a652dc9480dc0bb13c6b3a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>2dfa36fb87ee17cec4f02f6dd7151279</MD5>
              <SHA-1>ccca1fdb113905cae5e475bb0463dfab7423c69d</SHA-1>
              <SHA-256>bbd7affdd2fa37cb0ecf584a01f8ed92abae649f378d885dcc11e3a1b7efd935</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>f874738a90eff0c2881febd6a4fef992</name>
        <report_id>36c6c423-408e-46da-aa53-9249d577e1d3</report_id>
        <tags>
          <value>html</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>5e7d4482ef32d187614cd181729441a2871f611064e2dc5eb3ea23c564ee8747</id>
    <title>Analysis Report for 5e7d4482ef32d187614cd181729441a2871f611064e2dc5eb3ea23c564ee8747</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156810f7e400110050ace</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155e82fcb905ec28c7a00</flow_id>
        <hash>5e7d4482ef32d187614cd181729441a2871f611064e2dc5eb3ea23c564ee8747</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/tuoyenej.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/tuoyenej.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=2798770403&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>263a80491cbb4a8898a2f5a7ef31694a</MD5>
              <SHA-1>f123c24ce1e9cd6bc069491caa85b58bc065e56f</SHA-1>
              <SHA-256>8e1e7c8a37a256e3f08c19e2ee8769e746785688ec0af4da2d1ac2ed695c9bd1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>1ca3dd077ab13626085cee3faea0deff</name>
        <report_id>745b7f2a-a558-4cc9-aadf-df701f0b941e</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>59df638389e849c0f52940c007e35212632466e238ad0f665d3ae9a800278039</id>
    <title>Analysis Report for 59df638389e849c0f52940c007e35212632466e238ad0f665d3ae9a800278039</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01568e0f7e400110050add</_id>
        <file_type>application/x-python-code</file_type>
        <flow_id>6a0155e6fd9cdd68416ef46b</flow_id>
        <hash>59df638389e849c0f52940c007e35212632466e238ad0f665d3ae9a800278039</hash>
        <iocs>
          <urls>
            <value>
              <url>https://discord.com/api/webhooks/1501482170328285335/t-mGgrCXL-lrAxrmGs4oJqEsADEYmJas8k1wlFQP24ObLfwo7qsMf4ngAOTVD2Zwl5sZc</url>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>discord.com</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>162.159.136.232</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>162.159.136.232</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>4d8bca134b070766dd72264aaaee12b5</MD5>
              <SHA-1>eddc1381da82865472a193adecf8189ea153131c</SHA-1>
              <SHA-256>356fa2d5fe30409a9dd08e329e899da1721a1a185688aafd9de92c0bb75ac8df</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/json</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <registry>
            <value>
              <registry>HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v WinUpdate /t REG_SZ /d "z</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>1d1224dcfc2d4b25fdb990a8ee3eabc9</name>
        <report_id>fd35db1b-f85b-4b30-a1a0-3ed13be1dff6</report_id>
        <tags>
          <value>json</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>7a5fcc828860d6611365ccd05e63623dc47eff49a94c8204e1bc5ac6dd537da1</id>
    <title>Analysis Report for 7a5fcc828860d6611365ccd05e63623dc47eff49a94c8204e1bc5ac6dd537da1</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156c30f7e400110050b21</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155eb2fcb905ec28c7a0c</flow_id>
        <hash>7a5fcc828860d6611365ccd05e63623dc47eff49a94c8204e1bc5ac6dd537da1</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>35981b9d8ee07f9357d7cd3d4c5e129d</name>
        <report_id>6aaa4604-7aba-4db8-870c-bffb50748bd2</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ce0300f892baa5fe2f50c1db33702a7f03dfef510343a60318968efde68afff8</id>
    <title>Analysis Report for ce0300f892baa5fe2f50c1db33702a7f03dfef510343a60318968efde68afff8</title>
    <updated>2026-05-11T04:08:02Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01569f0f7e400110050af3</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155ecdf14f1cb2acf70ee</flow_id>
        <hash>ce0300f892baa5fe2f50c1db33702a7f03dfef510343a60318968efde68afff8</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>312009997248c4f50efab7744491ebba</name>
        <report_id>57dc3d31-45c4-4d2c-acb5-b0d1724a5e9b</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1f5c9f6e41bebe0955eb53043d0b15d67488d3fb240b91d17d4d7bc813f41f1a</id>
    <title>Analysis Report for 1f5c9f6e41bebe0955eb53043d0b15d67488d3fb240b91d17d4d7bc813f41f1a</title>
    <updated>2026-05-11T04:07:59Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01562fd6e5cdb561983522</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015613792fe2d217aed89f</flow_id>
        <hash>1f5c9f6e41bebe0955eb53043d0b15d67488d3fb240b91d17d4d7bc813f41f1a</hash>
        <iocs/>
        <name>0ceec8176415431099b628ba85f70797</name>
        <report_id>c377d467-6a0e-420c-a8a9-fe19a5023970</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>89441793b8024966b2ab76de34ecce0ffdfd4a9667b52e6c048ce2c26e3a3f37</id>
    <title>Analysis Report for 89441793b8024966b2ab76de34ecce0ffdfd4a9667b52e6c048ce2c26e3a3f37</title>
    <updated>2026-05-11T04:07:59Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015630d6e5cdb561983523</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156142fcb905ec28c7a5d</flow_id>
        <hash>89441793b8024966b2ab76de34ecce0ffdfd4a9667b52e6c048ce2c26e3a3f37</hash>
        <iocs/>
        <name>e49202ac14526c22cb51213a83e6b038</name>
        <report_id>d6e4b6cc-0fe7-4d1f-9553-81c2243b4aa8</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>a3e595630d99226a8df52a65ba66021d7355bd26eb86b4d650b7aa29be0fa408</id>
    <title>Analysis Report for a3e595630d99226a8df52a65ba66021d7355bd26eb86b4d650b7aa29be0fa408</title>
    <updated>2026-05-11T04:07:53Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015629d6e5cdb56198351d</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01560c86e92bda70270fc2</flow_id>
        <hash>a3e595630d99226a8df52a65ba66021d7355bd26eb86b4d650b7aa29be0fa408</hash>
        <iocs/>
        <name>c172f3810b3b41da84d24d0e3e005bab</name>
        <report_id>ebe4dbd8-048f-422d-85c1-9e2f47830ae8</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>f90da1391228786a1db1d37afc3ee77a9e885fd9c21c6aff465b967d6f573d59</id>
    <title>Analysis Report for f90da1391228786a1db1d37afc3ee77a9e885fd9c21c6aff465b967d6f573d59</title>
    <updated>2026-05-11T04:07:50Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015626d6e5cdb56198351c</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015607792fe2d217aed895</flow_id>
        <hash>f90da1391228786a1db1d37afc3ee77a9e885fd9c21c6aff465b967d6f573d59</hash>
        <iocs/>
        <name>8849071d176df99b962700f918407ad4</name>
        <report_id>23ab8e89-3380-4259-92d3-db5256e266f9</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>ffcb74840d436ab383f773478a1ef30cea5ed4a9e40dfe802ba452b3fcce5a4e</id>
    <title>Analysis Report for ffcb74840d436ab383f773478a1ef30cea5ed4a9e40dfe802ba452b3fcce5a4e</title>
    <updated>2026-05-11T04:07:50Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156840f7e400110050acf</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155d1df14f1cb2acf70db</flow_id>
        <hash>ffcb74840d436ab383f773478a1ef30cea5ed4a9e40dfe802ba452b3fcce5a4e</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/sfqhlpcyf.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=2278379139&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/sfqhlpcyf.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>263a80491cbb4a8898a2f5a7ef31694a</MD5>
              <SHA-1>f123c24ce1e9cd6bc069491caa85b58bc065e56f</SHA-1>
              <SHA-256>8e1e7c8a37a256e3f08c19e2ee8769e746785688ec0af4da2d1ac2ed695c9bd1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>c05f203b2b41a16851c6c0b697135e9e</name>
        <report_id>a669cd8c-d782-4424-b366-d2681eb5fc7c</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8ecfbe30b8080de9e4fadd0ed03e6081dcd316aea0bf6937d9f75e7baca22171</id>
    <title>Analysis Report for 8ecfbe30b8080de9e4fadd0ed03e6081dcd316aea0bf6937d9f75e7baca22171</title>
    <updated>2026-05-11T04:07:48Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01569e0f7e400110050af2</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155c67d31ad7bba4fe4a1</flow_id>
        <hash>8ecfbe30b8080de9e4fadd0ed03e6081dcd316aea0bf6937d9f75e7baca22171</hash>
        <iocs>
          <urls>
            <value>
              <url>http://nudist-movies.top</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://nudist-movies.top/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudist-movies.top/disainqons/main.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/jfmoc.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=1851783493&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/tzh.cgi?9&amp;group=ban1</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/jfmoc.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>nudist-movies.top</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>51.91.57.135</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.57.135</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>b63cf5a54842e100a025971ba4d24ace</MD5>
              <SHA-1>955c72d2d9a761279bfd7ca3a7618b01c80fed94</SHA-1>
              <SHA-256>f5f49741b34404a0854e4da328abff17822f1811564bf1dc658e95079aa7c30a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>08d062b16a9865f402f50fba929afa28</MD5>
              <SHA-1>2ea2787528e0120626eed938b8c7d96baa7416ea</SHA-1>
              <SHA-256>0eed15ab2b9dc6562339b2f756112a4c9504c1182f7986bc77e395415fedd639</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>278f5fc083d149d8623311ded2da2f99</MD5>
              <SHA-1>7dfa3542acc73102625dffcd80382fae5176b0a5</SHA-1>
              <SHA-256>0488cd68975a31e80ebca6e89a39aa9985a64b18ea0bb268c306b79387a5351b</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>abb57ce5f3e16ebee715e8aa709ae3f4</MD5>
              <SHA-1>47be4927263ba20d15eb47e19eede93529572dc8</SHA-1>
              <SHA-256>e3d3b27f61ffbd655a465631284795e146b7b02347ab4848ce03c61692324c18</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>e13c437030d0e87ae123d2279ce05a0b</MD5>
              <SHA-1>c08f38f051edf5e0507e2c36d5d7177b7cedb629</SHA-1>
              <SHA-256>c1c3f7acc736a902dfa2da430cc5a033c0e269f82bdde96de38f694ea13b4283</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>23c614042610b621a6647f0466b68c87</name>
        <report_id>6c93001d-8a24-48b6-b0fb-133bbad1e6ff</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>0706de0267d70e3bc2ee1dd9386fa34d80629dff1e60b0ee1f9290d0a4c4a01c</id>
    <title>Analysis Report for 0706de0267d70e3bc2ee1dd9386fa34d80629dff1e60b0ee1f9290d0a4c4a01c</title>
    <updated>2026-05-11T04:07:48Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015623d6e5cdb561983519</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a015607792fe2d217aed893</flow_id>
        <hash>0706de0267d70e3bc2ee1dd9386fa34d80629dff1e60b0ee1f9290d0a4c4a01c</hash>
        <iocs/>
        <name>cf5277467db0618df440fcdc914dcfeb</name>
        <report_id>d2f34103-2aae-415d-bae8-f62cf327d2d0</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>9797fd4420f70d3b9f429cd97db6807e2913ca9f65bf5be9c490685154fd042a</id>
    <title>Analysis Report for 9797fd4420f70d3b9f429cd97db6807e2913ca9f65bf5be9c490685154fd042a</title>
    <updated>2026-05-11T04:07:41Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01561dd6e5cdb561983514</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155fe2fcb905ec28c7a42</flow_id>
        <hash>9797fd4420f70d3b9f429cd97db6807e2913ca9f65bf5be9c490685154fd042a</hash>
        <iocs/>
        <name>d5493e644d75dd6939f8177fdf115fe5</name>
        <report_id>7ed98bf7-d87e-40c2-a013-b9c2c99a97b2</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>38abc2761d4d6800de2691cc681b080db8ff51757d8b34374b7f73c99c1fd5b9</id>
    <title>Analysis Report for 38abc2761d4d6800de2691cc681b080db8ff51757d8b34374b7f73c99c1fd5b9</title>
    <updated>2026-05-11T04:07:40Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01561fd6e5cdb561983515</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155ff2fcb905ec28c7a45</flow_id>
        <hash>38abc2761d4d6800de2691cc681b080db8ff51757d8b34374b7f73c99c1fd5b9</hash>
        <iocs/>
        <name>24554ae723aa994753bcda1dfbdc3d15</name>
        <report_id>aa3b3eb3-fbbc-455d-8e60-2723445dfe03</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>d69cde35cfea6bf1a3d5ac03018f43a8550cdd96e2b776a05c46a01632dfa0a4</id>
    <title>Analysis Report for d69cde35cfea6bf1a3d5ac03018f43a8550cdd96e2b776a05c46a01632dfa0a4</title>
    <updated>2026-05-11T04:07:40Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01561cd6e5cdb561983513</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0156017d31ad7bba4fe4bd</flow_id>
        <hash>d69cde35cfea6bf1a3d5ac03018f43a8550cdd96e2b776a05c46a01632dfa0a4</hash>
        <iocs/>
        <name>712eef753552bb926ae41be4fb6f8a4b</name>
        <report_id>c795ab5e-2108-4168-b976-45e67bdc9e6c</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e57438fc64e826bccce229d02f46cf8d56c3ca76067b4e14c532c1ee454dfd1a</id>
    <title>Analysis Report for e57438fc64e826bccce229d02f46cf8d56c3ca76067b4e14c532c1ee454dfd1a</title>
    <updated>2026-05-11T04:07:31Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a015614d6e5cdb56198350e</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155f52fcb905ec28c7a24</flow_id>
        <hash>e57438fc64e826bccce229d02f46cf8d56c3ca76067b4e14c532c1ee454dfd1a</hash>
        <iocs/>
        <name>c674eca36bdcdd190fc7a3cc4f30e1b4</name>
        <report_id>4edbd075-815b-4bb9-becc-2d2871b57edf</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>726ec8444ac3e8ac15021e17e0ec0ab035f1bfd4f0e6f735013acfb1574baef3</id>
    <title>Analysis Report for 726ec8444ac3e8ac15021e17e0ec0ab035f1bfd4f0e6f735013acfb1574baef3</title>
    <updated>2026-05-11T04:07:31Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156bb0f7e400110050b16</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155cd2fcb905ec28c79bc</flow_id>
        <hash>726ec8444ac3e8ac15021e17e0ec0ab035f1bfd4f0e6f735013acfb1574baef3</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>d31ee98ee83f93d328bd9207860df9c3</name>
        <report_id>6fe98eaa-92ab-4fc3-8800-3c063462ea98</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>402860e1cd95adca0c82cb7d5ee3768e143a27000a1a3fa12afd083c34cc37d1</id>
    <title>Analysis Report for 402860e1cd95adca0c82cb7d5ee3768e143a27000a1a3fa12afd083c34cc37d1</title>
    <updated>2026-05-11T04:07:30Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01569a0f7e400110050af0</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155cb2fcb905ec28c79b7</flow_id>
        <hash>402860e1cd95adca0c82cb7d5ee3768e143a27000a1a3fa12afd083c34cc37d1</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmpisktr4z3.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://myindianporn.cc/mvsxxx.php?</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dbipv.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=3206984552&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://trusttraff.com/favicon.ico</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://xnxxbest.pro/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://trusttraff.com/dbipv.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=3206984552&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/dbipv.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>myindianporn.cc</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>xnxxbest.pro</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>109.206.161.72</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>162.251.111.215</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>263a80491cbb4a8898a2f5a7ef31694a</MD5>
              <SHA-1>f123c24ce1e9cd6bc069491caa85b58bc065e56f</SHA-1>
              <SHA-256>8e1e7c8a37a256e3f08c19e2ee8769e746785688ec0af4da2d1ac2ed695c9bd1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>a9a31388d8f8f4db5edd103cea532657</name>
        <report_id>2b253dde-5d08-47d9-bbee-066c67ce1e68</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
          <value>aidetect</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b7130aaeb81d476b91e3726ada4ed8da79fe0b836291d850870320627fbeaef1</id>
    <title>Analysis Report for b7130aaeb81d476b91e3726ada4ed8da79fe0b836291d850870320627fbeaef1</title>
    <updated>2026-05-11T04:07:30Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156be0f7e400110050b19</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155cd792fe2d217aed85b</flow_id>
        <hash>b7130aaeb81d476b91e3726ada4ed8da79fe0b836291d850870320627fbeaef1</hash>
        <iocs>
          <urls>
            <value>
              <url>http://nudistsbeach.eu</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudistsbeach.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudistsbeach.eu/dencasgj.js</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/wxyy.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2960748703&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/wxyy.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>file:///tmp/tmp8igitu4e.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/dencasgj.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/ftt2/check.php?t=1778472572&amp;check=61a7a60b3c3de7883f6275380f9b3e2c&amp;rand=167011</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/imedzjazq/1.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/imedzjazq/2.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/imedzjazq/3.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/imedzjazq/bg-body.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/imedzjazq/style.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://nudistsfamilys.eu/imedzjazq/videoPlayer-anim.gif</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://shhopper.org/uuj6.html</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>nudistsbeach.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>nudistsfamilys.eu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>213.166.71.4</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>213.166.71.4</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>213.166.71.4</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>278f5fc083d149d8623311ded2da2f99</MD5>
              <SHA-1>7dfa3542acc73102625dffcd80382fae5176b0a5</SHA-1>
              <SHA-256>0488cd68975a31e80ebca6e89a39aa9985a64b18ea0bb268c306b79387a5351b</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>4435c8dd33b05560906ac2b56f21998a</MD5>
              <SHA-1>676d3f4268a6ade42f8c24cfefe4d1d0c7169f23</SHA-1>
              <SHA-256>2d868811054bbafca33040c001460c243167a20b726cd9a6adb02a1a22c7e1d4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>f6cedf66277966fd79de7d399231e201</MD5>
              <SHA-1>91a0381c52d6752f2813f20c1c4e683ce996d959</SHA-1>
              <SHA-256>b915a65d17f957fb1c6e0f69d673bf7ef11ac0dcf3174ab621809580f63fb74d</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <MD5>d6974cd6958c7b38b3a2ff63960ea5f1</MD5>
              <SHA-1>683928ae8d62ac95b7c71b5c19c65bcd3421df68</SHA-1>
              <SHA-256>f3f7b78d8cd17391d172edbf853057614f7d6bb7845a5370b458e2e5e2173eca</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/hta</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>e8a5bc880079e35aa2ba8659f7cc8f4e</name>
        <report_id>5166d18a-d78c-4e3f-ae48-5fa01da5c561</report_id>
        <tags>
          <value>html</value>
          <value>hta</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>74eb32688abb96f196be34fb0a7d219418f69a02e5cd1132fec91f55a1da4da6</id>
    <title>Analysis Report for 74eb32688abb96f196be34fb0a7d219418f69a02e5cd1132fec91f55a1da4da6</title>
    <updated>2026-05-11T04:07:29Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a60f7e400110050af9</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155c4df14f1cb2acf70d5</flow_id>
        <hash>74eb32688abb96f196be34fb0a7d219418f69a02e5cd1132fec91f55a1da4da6</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/iqlizhfrx.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=2831278982&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/iqlizhfrx.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>263a80491cbb4a8898a2f5a7ef31694a</MD5>
              <SHA-1>f123c24ce1e9cd6bc069491caa85b58bc065e56f</SHA-1>
              <SHA-256>8e1e7c8a37a256e3f08c19e2ee8769e746785688ec0af4da2d1ac2ed695c9bd1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>72d6f5342960810c6b5393f97f75efb8</name>
        <report_id>96204851-8c00-432a-92f5-d135299bd58b</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>12292510a2c0e4947e6094554ed65402567c64eead1cb6756005027750a3409c</id>
    <title>Analysis Report for 12292510a2c0e4947e6094554ed65402567c64eead1cb6756005027750a3409c</title>
    <updated>2026-05-11T04:07:29Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a50f7e400110050af8</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155c52fcb905ec28c79a9</flow_id>
        <hash>12292510a2c0e4947e6094554ed65402567c64eead1cb6756005027750a3409c</hash>
        <iocs>
          <urls>
            <value>
              <url>http://rans288e.vip/info/faq-faq_withdrawal/?tr_uuid=20260508-1007-23c8-a131-18e0dcb2a7d6&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://rans288e.vip/info/faq-faq_withdrawal/?tr_uuid=20260508-1007-23c8-a131-18e0dcb2a7d6&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://rans288e.vip/info/faq-faq_withdrawal/?tr_uuid=20260508-1007-23c8-a131-18e0dcb2a7d6&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://rans288e.vip/info/faq-faq_withdrawal/?tr_uuid=20260508-1007-23c8-a131-18e0dcb2a7d6&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>rans288e.vip</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>rans288e.vip</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1007-23c8-a131-18e0dcb2a7d6</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1007-23c8-a131-18e0dcb2a7d6</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>bfd2797382361f527e811fd8e2efcf08</name>
        <report_id>01c3d5d3-d240-466c-8045-90955e3003db</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>a1fbb2cf672b315043dc29413fb1e85d8aad2fbe2d0020b222fe37a1ed98d6cc</id>
    <title>Analysis Report for a1fbb2cf672b315043dc29413fb1e85d8aad2fbe2d0020b222fe37a1ed98d6cc</title>
    <updated>2026-05-11T04:07:24Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ff0f7e400110050b66</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155c1792fe2d217aed851</flow_id>
        <hash>a1fbb2cf672b315043dc29413fb1e85d8aad2fbe2d0020b222fe37a1ed98d6cc</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/zfmhgmiwy.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/zfmhgmiwy.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=738172583&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>5d5be8be3f197f7aa4d8dafac21a146a</MD5>
              <SHA-1>e0731d2fe2f03d48abb3f69dfe0d238f1c0bd3be</SHA-1>
              <SHA-256>ec724a9e515e7f604df7e23686762776f8301288109f09c06e8e7ef15cd11434</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>6cc0a2f8a3c236471ee4e78ae25c1c06</name>
        <report_id>68bd8773-62e2-40b5-830b-1e008fd1ea47</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>77ed294a99906d24c2ad45cb02b9aaa5454bb9f31170920d8d692df7aec02b92</id>
    <title>Analysis Report for 77ed294a99906d24c2ad45cb02b9aaa5454bb9f31170920d8d692df7aec02b92</title>
    <updated>2026-05-11T04:07:22Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01560ad6e5cdb56198350a</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155ed86e92bda70270f91</flow_id>
        <hash>77ed294a99906d24c2ad45cb02b9aaa5454bb9f31170920d8d692df7aec02b92</hash>
        <iocs/>
        <name>277e9d36ebe416eaa3c261c4d1403223</name>
        <report_id>9bb0115c-0ad5-4044-941c-8db5ac4ef164</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>dc1c1da3a498e9f4acd9dfde9e544db9186bbf6b63addfbe6bdf127b07cd96e5</id>
    <title>Analysis Report for dc1c1da3a498e9f4acd9dfde9e544db9186bbf6b63addfbe6bdf127b07cd96e5</title>
    <updated>2026-05-11T04:07:18Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156950f7e400110050aed</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155c186e92bda70270f5b</flow_id>
        <hash>dc1c1da3a498e9f4acd9dfde9e544db9186bbf6b63addfbe6bdf127b07cd96e5</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.ww25.ww38.ww25.ww25.ww25.ww25.ww25.r3ndy.cc/?tr_uuid=20260508-1006-301a-9ade-9cd53a96648d&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww25.ww38.ww25.ww25.ww25.ww25.ww25.r3ndy.cc/?tr_uuid=20260508-1006-301a-9ade-9cd53a96648d&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww25.ww38.ww25.ww25.ww25.ww25.ww25.r3ndy.cc/?tr_uuid=20260508-1006-301a-9ade-9cd53a96648d&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.ww25.ww38.ww25.ww25.ww25.ww25.ww25.r3ndy.cc/?tr_uuid=20260508-1006-301a-9ade-9cd53a96648d&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.ww25.ww38.ww25.ww25.ww25.ww25.ww25.r3ndy.cc</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>ww25.ww38.ww25.ww25.ww25.ww25.ww25.r3ndy.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1006-301a-9ade-9cd53a96648d</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1006-301a-9ade-9cd53a96648d</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>73c4f05b53f752da0ebc73b6d818f009</name>
        <report_id>2939d830-500f-4e31-9e0d-0c63f70172bf</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1e4acaec199c6dbf1d72002be384d56eb33770f1664cdeadd9ba0d8202f8437c</id>
    <title>Analysis Report for 1e4acaec199c6dbf1d72002be384d56eb33770f1664cdeadd9ba0d8202f8437c</title>
    <updated>2026-05-11T04:07:18Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a10f7e400110050af5</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155bedf14f1cb2acf70cb</flow_id>
        <hash>1e4acaec199c6dbf1d72002be384d56eb33770f1664cdeadd9ba0d8202f8437c</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>59e58983e7e5bcec5188e521c4d9215e</name>
        <report_id>79b14b58-22f5-4ba0-b4ce-e4401c534d00</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c23f8d74f2e5c0b0ebb45f9b75d8a39e25077dc58717b647d70023f192a951e7</id>
    <title>Analysis Report for c23f8d74f2e5c0b0ebb45f9b75d8a39e25077dc58717b647d70023f192a951e7</title>
    <updated>2026-05-11T04:07:17Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a90f7e400110050b01</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155aedf14f1cb2acf70b4</flow_id>
        <hash>c23f8d74f2e5c0b0ebb45f9b75d8a39e25077dc58717b647d70023f192a951e7</hash>
        <iocs>
          <urls>
            <value>
              <url>http://ikl.zcexp.shop/?tr_uuid=20260508-1008-0047-a67e-1de6d4064146&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ikl.zcexp.shop/?tr_uuid=20260508-1008-0047-a67e-1de6d4064146&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmppz1ci4jc.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://ikl.zcexp.shop/?tr_uuid=20260508-1008-0047-a67e-1de6d4064146&amp;fp=-7</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://ikl.zcexp.shop/?tr_uuid=20260508-1008-0047-a67e-1de6d4064146&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ikl.zcexp.shop/?tr_uuid=20260508-1008-0047-a67e-1de6d4064146&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>ikl.zcexp.shop</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>ikl.zcexp.shop</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1008-0047-a67e-1de6d4064146</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1008-0047-a67e-1de6d4064146</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>a78c6325cf2e89525d87d1b429235333</name>
        <report_id>8ab2fbc3-5eeb-4b0b-a2c9-b3852cf1187d</report_id>
        <tags>
          <value>html</value>
          <value>aidetect</value>
          <value>phishing</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>70192e4f8c2aaab52ee9d1393ca843b9bfcae1023d404986d2e0e68168da2cce</id>
    <title>Analysis Report for 70192e4f8c2aaab52ee9d1393ca843b9bfcae1023d404986d2e0e68168da2cce</title>
    <updated>2026-05-11T04:07:14Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01560597e8658d088c8070</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0155effd9cdd68416ef470</flow_id>
        <hash>70192e4f8c2aaab52ee9d1393ca843b9bfcae1023d404986d2e0e68168da2cce</hash>
        <iocs>
          <urls>
            <value>
              <url>https://crashpad.chromium.org/</url>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://crashpad.chromium.org/bug/new</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>crashpad.chromium.org</url>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <emails>
            <value>
              <email>appro@openssl.org</email>
              <origin>INPUT_FILE</origin>
            </value>
          </emails>
          <ips>
            <value>
              <ip>1.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.121</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>192.178.183.121</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>1b7fa49374c0a59752f90645abb8b0d2235f50a3d3cf89a6e7b2767b2c41324d</SHA-256>
              <SHA-1>da5b7bd5091e769491ec4edab1e1927b0eac6739</SHA-1>
              <MD5>b631610ef69c0a8f07961785204c47e9</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>3cfc17a13158263fc25b7bd692907769e87c8c0a2884dbc9adfb6528d30faddf</SHA-256>
              <SHA-1>5accecfd62c81c7312d93315a5e66a95ccb025e9</SHA-1>
              <MD5>d876902d8a25eeaac8eabc6dbb7c6c50</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload</file_type>
            </value>
            <value>
              <SHA-256>3f921d65d0ba465f97f4d44efb8a13ebb76f8df0dde7d69b42f78a9e8318b239</SHA-256>
              <SHA-1>3318c5cac272603074afea437f074fd6cefcef6a</SHA-1>
              <MD5>3ecf6a0cb6b6734b55a5d50a5ec9526d</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>599377d58acdd8b844757df7049a615059b6b9bb415920fca79d159e8b279327</SHA-256>
              <SHA-1>da77c0d684daae70d4bbeaefc8568d2b45b8526c</SHA-1>
              <MD5>047d257e6d82301a56ff11224c132905</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>6f88bc7cb02ccb2dbc26b5f4ce53e355b331e31bb920b2ba8cbbcd1b5d4cd5a0</SHA-256>
              <SHA-1>dc9804dd3aa348fb0c05f53c53c698518af514a0</SHA-1>
              <MD5>9ce8c70178061cc4cf4a6bb1e291df93</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/xml</file_type>
            </value>
            <value>
              <SHA-256>c49db3fb9a74c55628b2cf900ca305ede59e01d6332a000d23d0b44be9be06bf</SHA-256>
              <SHA-1>bbe465451083ea2dba8ac4bdf7bcce1e38df3c8c</SHA-1>
              <MD5>ad4e7a7a96e8a94df215a45a172ce7cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>daace8f198fd6eaf040af296dbaf9f6059e577db5010205509c63c939ed5847b</SHA-256>
              <SHA-1>9fdfce9b87d62b2eec02f06be5253d1a40384f03</SHA-1>
              <MD5>2a1226674e74901c9cdf9cb6da9f5fb7</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>2998d47ff33cad754af45a002349b21dac347113188836228a4aa8557083496a</SHA-256>
              <SHA-1>fb54ab0f3b94ea86bdcf7da9eb731be8422ad5da</SHA-1>
              <MD5>95a8861331a87f8131f9879052bf6899</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>3fe8fa79-5dce-4503-ab23-464ea24babff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Microsoft\Windows NT\CurrentVersion</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SOFTWARE\Microsoft\Windows\CurrentVersion\Run</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <registry>SOFTWARE\Policies\Google\Chrome</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers</registry>
              <origin>INPUT_FILE</origin>
            </value>
          </registry>
        </iocs>
        <name>x70192e4f8c2aaab52ee9d1393ca843b9bfcae1023d404986d2e0e68168da2cce.exe</name>
        <report_id>92e493b3-b93d-4205-9299-2124d444dd08</report_id>
        <tags>
          <value>peexe</value>
          <value>html</value>
          <value>xworm</value>
          <value>njrat</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>anti-vm</value>
          <value>anti-debug</value>
          <value>crypto</value>
          <value>expand</value>
          <value>explorer</value>
          <value>fingerprint</value>
          <value>lolbin</value>
          <value>reconnaissance</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>7d980d775a45ae359aae76bdd02f146c51be38c6203846262bbb08a880fcc477</id>
    <title>Analysis Report for 7d980d775a45ae359aae76bdd02f146c51be38c6203846262bbb08a880fcc477</title>
    <updated>2026-05-11T04:07:10Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155fed6e5cdb561983506</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155e12fcb905ec28c79e5</flow_id>
        <hash>7d980d775a45ae359aae76bdd02f146c51be38c6203846262bbb08a880fcc477</hash>
        <iocs/>
        <name>8c32cc2db259034023707172d81d7b0e</name>
        <report_id>3e289ee9-d142-4da5-9e45-230021c94a92</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b40f1ec6238d725e49adec4838c44d4b668babf3983120fa5dda4e2247686bad</id>
    <title>Analysis Report for b40f1ec6238d725e49adec4838c44d4b668babf3983120fa5dda4e2247686bad</title>
    <updated>2026-05-11T04:07:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01568a0f7e400110050ada</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155b286e92bda70270f49</flow_id>
        <hash>b40f1ec6238d725e49adec4838c44d4b668babf3983120fa5dda4e2247686bad</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>7df675f7dbf7c5740e6ea7a57b02a65f</name>
        <report_id>5ecc965c-3334-4585-a692-2306a3f26d52</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>dbb9bd9791b9afdd05d2c3917e3e482b589ed5cf44ad32627e3dcda4452570e8</id>
    <title>Analysis Report for dbb9bd9791b9afdd05d2c3917e3e482b589ed5cf44ad32627e3dcda4452570e8</title>
    <updated>2026-05-11T04:07:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156540f7e400110050a9d</_id>
        <file_type>application/pdf</file_type>
        <flow_id>6a0155b2df14f1cb2acf70bc</flow_id>
        <hash>dbb9bd9791b9afdd05d2c3917e3e482b589ed5cf44ad32627e3dcda4452570e8</hash>
        <iocs/>
        <name>031efb0770594fef4394b24d7a24f556</name>
        <report_id>c06bca08-d410-450a-855c-b3b3655a8812</report_id>
        <tags>
          <value>pdf</value>
          <value>encrypted</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>291a1c1c0edcfba648cb0f30a52cc1a02a3d790d3e1e9d00522368547d3e7321</id>
    <title>Analysis Report for 291a1c1c0edcfba648cb0f30a52cc1a02a3d790d3e1e9d00522368547d3e7321</title>
    <updated>2026-05-11T04:07:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156990f7e400110050aef</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155b2792fe2d217aed84a</flow_id>
        <hash>291a1c1c0edcfba648cb0f30a52cc1a02a3d790d3e1e9d00522368547d3e7321</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/rjbxqysrt.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://nudistvoyour.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://nudistvoyour.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudistvoyour.eu/analiz.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/rjbxqysrt.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=3664121851&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>nudistvoyour.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>31.210.173.193</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>31.210.173.193</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>dd1b0ebf935f5340635bcd230a9ed36c</MD5>
              <SHA-1>018a5a40cc61775f43a4f820bad8d934274ea82c</SHA-1>
              <SHA-256>07a3771cb38d87311a5f9da691a3cb0af84943bbd073014238180edc25e4517a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>420a48ee46978e2fbd15311c425ef2f5</MD5>
              <SHA-1>2fb7722cf87c69a39c1495d18f6b1c78475e89f2</SHA-1>
              <SHA-256>e9fa100ab786515a7cba1581435c588abeda4878fc65e52c8ca602978f37b1b2</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>10a4edf661df23548f239ab25e9db1f9</MD5>
              <SHA-1>5772c62475e225be7d8cfb7cdf455ebedeaa344c</SHA-1>
              <SHA-256>6d97e946f69bccb1ce69cc776709c708d53611296d884f5909a941099ca22767</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>f9adb197c77ac5fd3793c1f4606fe7f3</MD5>
              <SHA-1>f2efa2561f564373e6f148f62a979ecf717b7186</SHA-1>
              <SHA-256>8d4c993089e35c332ee8de01bc17f812cda2380d855bd2bddd416dc7721d73d5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>365d833e7d072fed9f231e3200759865</name>
        <report_id>622ab726-1918-4a73-9e61-6bb3dacfaaf9</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>3755635b426808aed2762db7ce53218cd71da25a5cad5d118d2617d15916f93e</id>
    <title>Analysis Report for 3755635b426808aed2762db7ce53218cd71da25a5cad5d118d2617d15916f93e</title>
    <updated>2026-05-11T04:07:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156960f7e400110050aee</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155ba2fcb905ec28c799a</flow_id>
        <hash>3755635b426808aed2762db7ce53218cd71da25a5cad5d118d2617d15916f93e</hash>
        <iocs>
          <urls>
            <value>
              <url>http://poloi.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://poloi.pw/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/oyoge.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2016923159&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/scqved.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=1310685868&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/tzh.cgi?9&amp;group=ban1</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/oyoge.cgi?20&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>poloi.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.57.135</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.57.135</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>5bd91d42f32134f3168014ddce9639ee</MD5>
              <SHA-1>59d7eac3c9634c46a9b1bdeb6e0578ff1ef48d6e</SHA-1>
              <SHA-256>edf56f1b7f2d8d90f44607f909b6577d9061390e336abc8c8d3a4e6358d9b5f9</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xhtml+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>bc50d246170a6760e9e3c150dae8e2a1</MD5>
              <SHA-1>3ddb181fb3e996d17065b608d9ce8c31f81b8fc7</SHA-1>
              <SHA-256>5afd75e8072e73a0946ba81b4c76c9ee86a449d261d6309e1f12ef50d5d8c2a7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>6bdeb53f7532421e2f038c64a9d95f24</MD5>
              <SHA-1>9ac01f05981fc158693d97d2d86e0bbe2075bbfc</SHA-1>
              <SHA-256>7a79966e5312c0c184ffaa8960430ac3653404fcd8d455a9c07b3ad3c5610cb7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>e68a0890a2c349ef8b8358a06ad17027</MD5>
              <SHA-1>1f073f8b1c33db94152c91e7a7c1240ccbd8bbfb</SHA-1>
              <SHA-256>9a33d675ad649e3c5afe55252854ef07af811c7a5d4b32c18be598746ef118d5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>8a6ee978ef6d78d36dc030f116731111</MD5>
              <SHA-1>fce4d3a01343508f26aa6d35edd2ac0b6c5dc17c</SHA-1>
              <SHA-256>c941faf853eaf86f42da87b05cf601dd2f3e2f183a0216291f0d5a8a2ef19e4e</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>e12496492eefd9dd466a1e56762e1546</name>
        <report_id>5dcd0e96-8a2d-4107-a4e8-dbd2f935ed36</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c8e4f0e8eedca706541f9e873d271d778525b7408b1d7b7baa761a9aad3f3570</id>
    <title>Analysis Report for c8e4f0e8eedca706541f9e873d271d778525b7408b1d7b7baa761a9aad3f3570</title>
    <updated>2026-05-11T04:07:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156b70f7e400110050b0f</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155bc2fcb905ec28c799e</flow_id>
        <hash>c8e4f0e8eedca706541f9e873d271d778525b7408b1d7b7baa761a9aad3f3570</hash>
        <iocs>
          <urls>
            <value>
              <url>http://m3u-iptv.online/?ch=1&amp;js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc1NTY4MDUyOSwiaWF0IjoxNzU1NjczMzI5LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMWVtZjVxc3JtdnEybGMydG80cTBkMmMiLCJuYmYiOjE3NTU2NzMzMjksInRzIjoxNzU1NjczMzI5NTQwMDY1fQ.cpH2FSEj3Ct0jO4UsnLfuiqyDHz-J6mMg9ni09cMIi8&amp;sid=96fe2a28-7d93-11f0-bbf4-1b33be7523a8</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>http://m3u-iptv.online/?ch=1&amp;js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc1NTY4MDUyOSwiaWF0IjoxNzU1NjczMzI5LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMWVtZjVxc3JtdnEybGMydG80cTBkMmMiLCJuYmYiOjE3NTU2NzMzMjksInRzIjoxNzU1NjczMzI5NTQwMDY1fQ.cpH2FSEj3Ct0jO4UsnLfuiqyDHz-J6mMg9ni09cMIi8&amp;sid=96fe2a28-7d93-11f0-bbf4-1b33be7523a8</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://m3u-iptv.online/cdn-cgi/styles/main.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>m3u-iptv.online</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>m3u-iptv.online</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>188.114.96.3</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>203f3d7f9372525146f19c2032893527</MD5>
              <SHA-1>3edf198600a49be2cab591cb717fc780e0b650bc</SHA-1>
              <SHA-256>f76b17dcd6337559ec7950806a686684fcf4ec12c5532b279f0b385bc758a454</SHA-256>
              <origin>URL_REDIRECT</origin>
              <file_type>application/json</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ff26f59e28a5fe6ea4ab23586415696b</MD5>
              <SHA-1>4182675484d175e363cd34b43041b7b1af93d0cd</SHA-1>
              <SHA-256>d30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>01883dbaf7c4d8e5b24cc1f0065a374d</MD5>
              <SHA-1>50876f773bc63056277f7e35b0adc845bea37bf0</SHA-1>
              <SHA-256>c28dc73c366357f809c59b308514871fba0124ef4c9277cfe59c6834296a76af</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>96fe2a28-7d93-11f0-bbf4-1b33be7523a8</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>96fe2a28-7d93-11f0-bbf4-1b33be7523a8</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>a0db2ed16f4cc987d51b0236a351451c</name>
        <report_id>f2fb3a8d-3cb9-4d2c-a4c7-65e5e01af6c3</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>json</value>
          <value>base64</value>
          <value>obfuscated</value>
        </tags>
        <verdict>NO_THREAT</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>a31c7f05a63474ce055f65f79ca8601a625e44e2793017974d68145ee4c14614</id>
    <title>Analysis Report for a31c7f05a63474ce055f65f79ca8601a625e44e2793017974d68145ee4c14614</title>
    <updated>2026-05-11T04:07:06Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ed0f7e400110050b4a</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015595df14f1cb2acf709b</flow_id>
        <hash>a31c7f05a63474ce055f65f79ca8601a625e44e2793017974d68145ee4c14614</hash>
        <iocs>
          <urls>
            <value>
              <url>http://maturexxx.icu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://maturexxx.icu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/tzh.cgi?9&amp;group=ban1</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/vyvxehdr.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=1600110515&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/vyvxehdr.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>maturexxx.icu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>81250c0a180847117c6ac33d9fd22732</MD5>
              <SHA-1>7f607c9c706dbc413c3b363349efd8a3f42bc8de</SHA-1>
              <SHA-256>8c66ee6ba4b97e4603ffefde73ee3e3cb27f5ea4aa8a50fa2e9a563405a2ecd1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>8651b03c24887a8534c44f17766fdb51</MD5>
              <SHA-1>172018f9c1f1b7ac182efd0958d456178621209e</SHA-1>
              <SHA-256>6fa307ca41d1250311bd3334ddebcafca4d2a6a9c7662423f11ba2b5b1a8dca2</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>22f211d071683b19d8a4d8bf1856dbbc</MD5>
              <SHA-1>2c4b790a24a8be26a23f42f20c7b149d15a44300</SHA-1>
              <SHA-256>ee8101d7a4e9da4292f28cf2b45bee751c7042756c0f9b6b5ec7262896d25052</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>8f4bfe9222a52bc2b8b572847f914a87</MD5>
              <SHA-1>47f96ea016531986a40eb76df9b482b92171d54d</SHA-1>
              <SHA-256>a15ecadbd6b2c7d5d975bebe9d556f5b39bfa78657fac7abd41140b2c8000f89</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>9093cbaf89154e3f4b64426bd2424015</MD5>
              <SHA-1>db6cd57f57f7f770251aece75cbc67e11bd10808</SHA-1>
              <SHA-256>7d7b93104c39b99204dbb2a3f2472c97417e055e66c41180ba426b522a09450d</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
        </iocs>
        <name>25666cae910146ba23fd3c43c8157a8a</name>
        <report_id>b6867424-50ab-4bb6-b13e-15bc20d58326</report_id>
        <tags>
          <value>html</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>24d37a67c19e9f932bbc63a039ca4fd93b80c2381e54d1b5f3ad85e714123cd7</id>
    <title>Analysis Report for 24d37a67c19e9f932bbc63a039ca4fd93b80c2381e54d1b5f3ad85e714123cd7</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ca0f7e400110050b26</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155962fcb905ec28c795f</flow_id>
        <hash>24d37a67c19e9f932bbc63a039ca4fd93b80c2381e54d1b5f3ad85e714123cd7</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.elitetravelvalue.live/?tr_uuid=20260508-1007-32c3-b2aa-c63e238a19fc&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.elitetravelvalue.live/?tr_uuid=20260508-1007-32c3-b2aa-c63e238a19fc&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.elitetravelvalue.live/?tr_uuid=20260508-1007-32c3-b2aa-c63e238a19fc&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>elitetravelvalue.live</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.elitetravelvalue.live</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.212.118</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.118</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.118</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1007-32c3-b2aa-c63e238a19fc</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1007-32c3-b2aa-c63e238a19fc</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>5ca9f51bf27929ad99d5c540bf3a1ce5</name>
        <report_id>6f7f0d9d-f3d2-4d49-a322-3f3eed47a94f</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>982f467c755c7b19599fda6887068076af35ea39247019a4498f7280196038de</id>
    <title>Analysis Report for 982f467c755c7b19599fda6887068076af35ea39247019a4498f7280196038de</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156410f7e400110050a91</_id>
        <file_type>application/x-msdownload; format=pe</file_type>
        <flow_id>6a015596df14f1cb2acf709d</flow_id>
        <hash>982f467c755c7b19599fda6887068076af35ea39247019a4498f7280196038de</hash>
        <iocs/>
        <name>79fc1c0c681bae9b9f8eb4c64b3e7092</name>
        <report_id>fe322299-5072-49ce-84c0-1a1da166684a</report_id>
        <tags>
          <value>peexe</value>
          <value>pedll</value>
          <value>gamarue</value>
          <value>zusy</value>
          <value>packed</value>
          <value>lolbin</value>
          <value>rundll32</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>2bb3cd04a63cf6ac1f8f9447d2fba5b4ce41cef06e72d0a2d28b5d7dabaae2a7</id>
    <title>Analysis Report for 2bb3cd04a63cf6ac1f8f9447d2fba5b4ce41cef06e72d0a2d28b5d7dabaae2a7</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156cb0f7e400110050b27</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155a486e92bda70270f33</flow_id>
        <hash>2bb3cd04a63cf6ac1f8f9447d2fba5b4ce41cef06e72d0a2d28b5d7dabaae2a7</hash>
        <iocs>
          <urls>
            <value>
              <url>http://best-targeted-traffic.com/install.php?unq=8g526115447eidoxoi&amp;version=1.7&amp;pais=Unknown&amp;tr_uuid=20260509-0740-29b4-80f0-3e4181d74b34&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://best-targeted-traffic.com/install.php?unq=8g526115447eidoxoi&amp;version=1.7&amp;pais=Unknown&amp;tr_uuid=20260509-0740-29b4-80f0-3e4181d74b34&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://best-targeted-traffic.com/install.php?unq=8g526115447eidoxoi&amp;version=1.7&amp;pais=Unknown&amp;tr_uuid=20260509-0740-29b4-80f0-3e4181d74b34&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>best-targeted-traffic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>best-targeted-traffic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.247</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.247</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260509-0740-29b4-80f0-3e4181d74b34</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260509-0740-29b4-80f0-3e4181d74b34</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>076488f31b5aa248853a1cb69989e9b9</name>
        <report_id>0a672232-99af-4ac1-aba0-ecc7c339ad9e</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>876c2eb3e0138eb11ab13a60d288109a5cb14ba0a8ffb7a90e545d396a90cbaf</id>
    <title>Analysis Report for 876c2eb3e0138eb11ab13a60d288109a5cb14ba0a8ffb7a90e545d396a90cbaf</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156900f7e400110050ade</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01559a2fcb905ec28c796b</flow_id>
        <hash>876c2eb3e0138eb11ab13a60d288109a5cb14ba0a8ffb7a90e545d396a90cbaf</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/lxcikfyoz.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/lxcikfyoz.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=751353672&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://a.magsrv.com/ad-provider.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://bhabhixxx.pro/css/style.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://myindianporn.cc/mvs/cgi/out.php?nr=true</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://myindianporn.cc/mvsxxx.php</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>a.magsrv.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>bhabhixxx.pro</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>myindianporn.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.72</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.73.220.202</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>195.181.175.40</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>195.181.175.40</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.73.220.202</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.72</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>164ea27d07539e5db605139b1053d6f3</MD5>
              <SHA-1>415bcf004babe02936c4d1c37e0ebfab1f43e142</SHA-1>
              <SHA-256>eac255f81a2a1183bfb6f7cccbd2594d94cfcda32a5a9377bf3f3e6c624a9678</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>4ee38362e6b14032b90ef0da839206f5</MD5>
              <SHA-1>a5a38bffceb2c1bf93f8a5593721f9dc1ab90bff</SHA-1>
              <SHA-256>75633841991f71b99e41521c5d1c81e954cc29ae5d87e2f1453011f6984ab820</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>394bd5071b58be6a6c0d67dfe2462315</MD5>
              <SHA-1>131b3834efe6eb406f5b8b4928d1a29d8601fadf</SHA-1>
              <SHA-256>83f349be54b4795e4e0621b19e03de4d38e71bc872e94fec7d7e343023ed6764</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>73569ba7c17143b49f7c4e66867b9a62</MD5>
              <SHA-1>06dc02be34f41aa2aa0d3879d473824ed90c0c90</SHA-1>
              <SHA-256>f82350352f0971f953e5daba995827f90dc9d27946301d4d25262fda414e80a5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>7a2f2fd3f186b5c4bf09248469a98a90</name>
        <report_id>b4a2a296-cee1-4734-8e19-e81155b5b686</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>txt</value>
          <value>phishing</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>41346a4349318d8ccb7fd96ca794055a3934b2bd119049bc295d5f48d3124c53</id>
    <title>Analysis Report for 41346a4349318d8ccb7fd96ca794055a3934b2bd119049bc295d5f48d3124c53</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156790f7e400110050ac7</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155a486e92bda70270f35</flow_id>
        <hash>41346a4349318d8ccb7fd96ca794055a3934b2bd119049bc295d5f48d3124c53</hash>
        <iocs>
          <urls>
            <value>
              <url>http://tubevideo.eu/funkqios.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;kpcug=1&amp;vlizi=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://milfhd.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://milfhd.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://milfhd.eu/analiz.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/funkqios.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;vlizi=596959929&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>milfhd.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>54.36.162.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.36.162.157</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>c93de73ff438068f92bf7d8252488805</MD5>
              <SHA-1>e4ce4fb30b47a4bf67c5b071bab50d780efe415c</SHA-1>
              <SHA-256>7e2b182be105f936ca1d72389c522ec98e687f25d020fd15be21347c7d89df0d</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xhtml+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>8698cb4368535e2925204645103c7f5b</MD5>
              <SHA-1>6d7fb3806770c146f21a3df17cafe7689d50a503</SHA-1>
              <SHA-256>beb0c948bb166c965e6a8abbbe9da3b25a503fcc13e22b1d9289a253bcd5a092</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>004731e30667aaadae70ff69f07c3306</MD5>
              <SHA-1>e9646f7621d6a7e61817b09bdef1718a15edeb85</SHA-1>
              <SHA-256>af0129124ef1ffadd204bb2e61b1f66c171300f41c4d590b8f68c0af856fb2d5</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>b4b1b8e456c6e746728cfb27b79cdcf7</MD5>
              <SHA-1>1683d823e0d8fe74c66088b5962125d07f5e667c</SHA-1>
              <SHA-256>0d8736b216ac571cbc17ab49fe20eb779fee3a324bcd61629635e6169a86ba6f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>b1054fc104bf6a182f2d72ba63ab62f4</name>
        <report_id>2bea0db4-d5e0-4233-a8da-e5458821a183</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>3db1892e7464addba8420f67d66054b1b75235d9926f820b482f433cbbde7371</id>
    <title>Analysis Report for 3db1892e7464addba8420f67d66054b1b75235d9926f820b482f433cbbde7371</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156d30f7e400110050b30</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155a286e92bda70270f31</flow_id>
        <hash>3db1892e7464addba8420f67d66054b1b75235d9926f820b482f433cbbde7371</hash>
        <iocs>
          <urls>
            <value>
              <url>http://kattennu.com/?tr_uuid=20260508-1009-11a6-8acd-1eb26e9da590&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://kattennu.com/?tr_uuid=20260508-1009-11a6-8acd-1eb26e9da590&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://kattennu.com/?tr_uuid=20260508-1009-11a6-8acd-1eb26e9da590&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>kattennu.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>kattennu.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.240</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1009-11a6-8acd-1eb26e9da590</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1009-11a6-8acd-1eb26e9da590</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>7f2a8c2a4b59291dd984697c3521967b</name>
        <report_id>f19d785a-383e-4933-9541-57cd717a6608</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>671871c1fb9d633c261f7c50a849381f0c8add891e2c887245bcface9343e68d</id>
    <title>Analysis Report for 671871c1fb9d633c261f7c50a849381f0c8add891e2c887245bcface9343e68d</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156720f7e400110050abb</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155ad792fe2d217aed845</flow_id>
        <hash>671871c1fb9d633c261f7c50a849381f0c8add891e2c887245bcface9343e68d</hash>
        <iocs>
          <urls>
            <value>
              <url>https://weigghtwatchers.com/?ch=1&amp;js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MTA0MDkzNywiaWF0IjoxNzQxMDMzNzM3LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMGttOXRlaDNjaDA1MzhtYTQyczY2NDIiLCJuYmYiOjE3NDEwMzM3MzcsInRzIjoxNzQxMDMzNzM3ODkzMzM5fQ.mwR0sgOOUT7udKVOPx0SbNkVmltpUd0cKYDyrlkXIKc&amp;sid=22651cae-f86e-11ef-a84b-073c6fbeb9b1</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://l.cdn-fileserver.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://searchresultsworld.com/sr/754870121/SAFEFRAME.html?%21%21=ng</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://searchresultsworld.com/sr/754870121/SAFEFRAME.html?--=ua</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://weigghtwatchers.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://weigghtwatchers.com/?ch=1&amp;js=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhdWQiOiJKb2tlbiIsImV4cCI6MTc0MTA0MDkzNywiaWF0IjoxNzQxMDMzNzM3LCJpc3MiOiJKb2tlbiIsImpzIjoxLCJqdGkiOiIzMGttOXRlaDNjaDA1MzhtYTQyczY2NDIiLCJuYmYiOjE3NDEwMzM3MzcsInRzIjoxNzQxMDMzNzM3ODkzMzM5fQ.mwR0sgOOUT7udKVOPx0SbNkVmltpUd0cKYDyrlkXIKc&amp;sid=22651cae-f86e-11ef-a84b-073c6fbeb9b1</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>file:///tmp/tmp2b5yr7dv.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://l.cdn-fileserver.com/bping.php</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://l.cdn-fileserver.com/bping.php?hvsid=00001778472499835000554803203586&amp;sc=HE&amp;wsip=170762850&amp;requrl=https%3A%2F%2Fweigghtwatchers.com&amp;vgd_asn=16509&amp;vgd_rpth=%2Fola&amp;vgd_cage=18&amp;vgd_l2type=dmola&amp;prid=8PR11258V&amp;vi=1778472499571941853&amp;ssld=%7B%22QQNN%22%3A%22r4%22%2C%22QQN75%22%3A%22kL1zUkxL7n1YnY18z%22%2C%22QQ8E%22%3A%22%22%2C%22QQQN%22%3A%22q4%22%2C%22QQl8E%22%3A%22%22%7D&amp;r=1778472499838&amp;vgd_cdv=O3125&amp;vgd_oreqf=one&amp;crid=342704488&amp;ugd=4&amp;cc=DE&amp;gdpr=1&amp;mspa=0&amp;wshp=0&amp;vgd_oresf=one&amp;vgd_wlstp=0&amp;cid=8CU7G8B38&amp;lf=6&amp;lper=100&amp;vgd_tsce=L1226&amp;vgd_setup=c21&amp;vgd_len=573&amp;vgd_end=1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://searchresultsworld.com/sr/754870121/SAFEFRAME.html?ule=888&amp;%219n9=&amp;%21Pe9l=&amp;%21h2LNNLJO9=&amp;%29hdP=&amp;-P9l=T&amp;-P9lN2eX=&amp;25Jll=T&amp;2XB=&amp;5e9v=_&amp;6-P=S&amp;6e9J2D=_&amp;9dP=&amp;Bd=TccsSc%28SiigcTiSTsg7&amp;CeV9=_&amp;CneX9=_&amp;De=&amp;EdP=scshSTcTuPiPvuSvi_uhs_Su%28i%28J%28DT%28c%287U&amp;EnvD=E2J&amp;GClD=&amp;GP=&amp;JNldP=&amp;NN=K%2A&amp;NPB=a7T%28g&amp;NV25%28=EeBSLd2XN&amp;NV257=T.asq7Ica&amp;NX9dP=&amp;NdP=stfcqsZ7s&amp;NldP=7S%28c_SSss&amp;P5lD=T&amp;PJN555=&amp;VXX9e=T&amp;XeNJ=jT%28%28U&amp;d2XNn=so%2A%29Qcg%2Ak%3Aasjk0c%7CuJs%2A%3ADi8wd6w6drw6Yp&amp;dedP=_&amp;eN=Y%2A&amp;edHJ=TTgSOUsi&amp;eenP=%7B%22eeNN%22%3A%22K%2A%22%2C%22eeNX%21%22%3A%22Dlv2GD6lX+v5+5vd2%22%2C%22eed9%22%3A%22%22%2C%22eeeN%22%3A%22Y%2A%22%2C%22eeHd9%22%3A%22%22%7D&amp;ehPlxP=&amp;hJ=_&amp;hPlxP=&amp;hdP=&amp;hdPB%28=&amp;htmlsrc=1&amp;hvJ=&amp;kkdd=n%2A%7Ch%7CnH93uA%2A&amp;lJ46ln=VXX9e%3A%2F%2FCJd--VXCvXNVJlewNE5&amp;n%28X%219J=P5Env&amp;tpid=&amp;v9t6=&amp;vNX=.Zx-0JH006vlvv667DS%2FHZ3Zl7SDZZ76S3v&amp;vPB=&amp;vPE5vd2=&amp;vPX%28=&amp;vPXT=&amp;vhDnCdP=B%28&amp;eobd=&amp;eoac=RvYbkNvbY&amp;ure=1</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://ww1.weigghtwatchers.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://ww1.weigghtwatchers.com/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://weigghtwatchers.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>l.cdn-fileserver.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>searchresultsworld.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>ww1.weigghtwatchers.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>weigghtwatchers.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>l.cdn-fileserver.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>searchresultsworld.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>weigghtwatchers.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>208.91.196.83</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>37.48.72.213</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>208.91.196.145</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>208.91.196.83</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>188.114.96.3</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>208.91.196.83</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>37.48.72.213</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>e6dc070e55b8920ffca568f20f8fcbd5</MD5>
              <SHA-1>715638a84cf9ef1bac54249264f3a3e703345edc</SHA-1>
              <SHA-256>76cb61a70dd070e6799cdb3fbb31678578b47d7e3e41098c2796a251f9447066</SHA-256>
              <origin>MSHTA_EMULATION</origin>
              <file_type>application/json</file_type>
            </value>
            <value>
              <MD5>41dc0c701e0dd49017473f690e969157</MD5>
              <SHA-1>d6df9354ff2678a65a242a52239ba908f94eaa81</SHA-1>
              <SHA-256>2b55f91566835771a07b4eea0d16c24c103260e5c70d013cc3b1aae43e9c39b1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9b090a20631e5a1621776e84af8b6135</MD5>
              <SHA-1>84bacb4a41e459b2599ab63ae1902a965d7f6064</SHA-1>
              <SHA-256>76530f00865bb11ce3adebcdc617a2a1ee1acd55cf594feb9fdd1224faec03a5</SHA-256>
              <origin>EXTERNAL_PARSER</origin>
              <file_type>application/json</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>a4d369fa92576a0d409511a9edd81c1c</MD5>
              <SHA-1>350d7766102588b0269dec756a61278472f37434</SHA-1>
              <SHA-256>855ef03bf604613486d5743bcbd38781df695bceea3538cf21a835f81e150f71</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>22651cae-f86e-11ef-a84b-073c6fbeb9b1</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>22651cae-f86e-11ef-a84b-073c6fbeb9b1</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>40752b4f365cd4e19d6d2b06661fad52</name>
        <report_id>0d07c4d7-8030-4f4a-8d27-9575559b059f</report_id>
        <tags>
          <value>html</value>
          <value>json</value>
          <value>base64</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>67aa06b1daf8cba4b6583f1ff007819c99c76a60030b19ba1e12a0d4f4842351</id>
    <title>Analysis Report for 67aa06b1daf8cba4b6583f1ff007819c99c76a60030b19ba1e12a0d4f4842351</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156c90f7e400110050b25</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155aedf14f1cb2acf70b2</flow_id>
        <hash>67aa06b1daf8cba4b6583f1ff007819c99c76a60030b19ba1e12a0d4f4842351</hash>
        <iocs>
          <urls>
            <value>
              <url>http://ksvg.com/?tr_uuid=20260508-1004-5154-8e8c-8fbe6c0b68c5&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ksvg.com/?tr_uuid=20260508-1004-5154-8e8c-8fbe6c0b68c5&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ksvg.com/?tr_uuid=20260508-1004-5154-8e8c-8fbe6c0b68c5&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>ksvg.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>ksvg.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.247</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.247</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1004-5154-8e8c-8fbe6c0b68c5</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1004-5154-8e8c-8fbe6c0b68c5</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>9f6426ec413b99db80e6e35cb1afec41</name>
        <report_id>3604d36c-27f8-4b01-b4a6-48c6de6b0559</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e9820d021c71cb86cd3469bd3fc21fc658b6efca613b5c7d17eb60ecd668a9d4</id>
    <title>Analysis Report for e9820d021c71cb86cd3469bd3fc21fc658b6efca613b5c7d17eb60ecd668a9d4</title>
    <updated>2026-05-11T04:07:00Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01567c0f7e400110050aca</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155a486e92bda70270f37</flow_id>
        <hash>e9820d021c71cb86cd3469bd3fc21fc658b6efca613b5c7d17eb60ecd668a9d4</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>38a9de24ab0417568cbb7b2acbc77db1</name>
        <report_id>ca1c5f46-a92d-480c-8255-96f5f95fa314</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>40d201ab06a7c791c23ccb6fac184eefd52fbda1fed2b3187939a5fad3d3f4a9</id>
    <title>Analysis Report for 40d201ab06a7c791c23ccb6fac184eefd52fbda1fed2b3187939a5fad3d3f4a9</title>
    <updated>2026-05-11T04:06:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156b40f7e400110050b0d</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015593fd9cdd68416ef454</flow_id>
        <hash>40d201ab06a7c791c23ccb6fac184eefd52fbda1fed2b3187939a5fad3d3f4a9</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.32399.loan/?&amp;tr_uuid=20260508-1024-13fa-a804-6589d558b769&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.32399.loan/?&amp;tr_uuid=20260508-1024-13fa-a804-6589d558b769&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.32399.loan/?&amp;tr_uuid=20260508-1024-13fa-a804-6589d558b769&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>32399.loan</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.32399.loan</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.247</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.247</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.247</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1024-13fa-a804-6589d558b769</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1024-13fa-a804-6589d558b769</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>0cc5ab612c57bd0f2cb51b1eb7e954f5</name>
        <report_id>6c826ba2-9405-41cf-a28b-41b90749da9b</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>59968e30aff7e2535c1fada463dbb9a805ed9cc597f65fef9e12e520bf09be08</id>
    <title>Analysis Report for 59968e30aff7e2535c1fada463dbb9a805ed9cc597f65fef9e12e520bf09be08</title>
    <updated>2026-05-11T04:06:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156690f7e400110050ab5</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015592df14f1cb2acf7094</flow_id>
        <hash>59968e30aff7e2535c1fada463dbb9a805ed9cc597f65fef9e12e520bf09be08</hash>
        <iocs>
          <urls>
            <value>
              <url>file:///tmp/tmp_k2pp2q8.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js?pcId=53&amp;domain=puriy.link</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/images/pe262/hero_nc.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parklogic.com/Contact-us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namecheap.com/domains/registration/results/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namecheap.com/domains/registration/results/?domain=puriy.link</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>puriy.link</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>parking3.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.namecheap.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.232.7.47</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>0639649a685cb03db6f5b197f810d41f</name>
        <report_id>e9b045a6-01e1-4ef7-8ad7-7ee80e69e3ea</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>83c81d540c842e03b0060cc1398ef630e843cb1c85dbabd6a2617693a5043836</id>
    <title>Analysis Report for 83c81d540c842e03b0060cc1398ef630e843cb1c85dbabd6a2617693a5043836</title>
    <updated>2026-05-11T04:06:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156bc0f7e400110050b18</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015594df14f1cb2acf7099</flow_id>
        <hash>83c81d540c842e03b0060cc1398ef630e843cb1c85dbabd6a2617693a5043836</hash>
        <iocs>
          <urls>
            <value>
              <url>https://paramountaxi.com/admin-panel/public/css/firsttime=1&amp;tcs=2217&amp;chn=autopromo&amp;src=LePointfr&amp;cmp=Fil_rouge&amp;med=Bouton_barre_partage&amp;pub=&amp;crtive=&amp;vson=&amp;fmt=&amp;adgrp=&amp;sem_kw=&amp;aff_/MFJvZEhSd2N5VXpRU1V5UmlVeVJu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
            <value>
              <url>https://paramountaxi.com/admin-panel/public/css/firsttime=1&amp;tcs=2217&amp;chn=autopromo&amp;src=LePointfr&amp;cmp=Fil_rouge&amp;med=Bouton_barre_partage&amp;pub=&amp;crtive=&amp;vson=&amp;fmt=&amp;adgrp=&amp;sem_kw=&amp;aff_/MFJvZEhSd2N5VXpRU1V5UmlVeVJu</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>paramountaxi.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>paramountaxi.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>178.16.143.199</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>178.16.143.199</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
        </iocs>
        <name>c1105351c670dbdbff92b7814ce5c0ec</name>
        <report_id>6b724e4c-9774-43f5-ac6b-0962c06e04c1</report_id>
        <tags>
          <value>html</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>0bdcbeb6ca14395641d34d54803924b0cd48a8f18d1674be0c8c27294b8feada</id>
    <title>Analysis Report for 0bdcbeb6ca14395641d34d54803924b0cd48a8f18d1674be0c8c27294b8feada</title>
    <updated>2026-05-11T04:06:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155e9d6e5cdb561983500</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155cd2fcb905ec28c79bf</flow_id>
        <hash>0bdcbeb6ca14395641d34d54803924b0cd48a8f18d1674be0c8c27294b8feada</hash>
        <iocs/>
        <name>3f3255f44af74251f2ac41d43e4aea45</name>
        <report_id>a3157606-a1eb-42d6-aa0d-5ee0ff219149</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>c308b920bc0a5139b97a07c1dbad98f0c85cb30b181bd14109ad4b12020bcd62</id>
    <title>Analysis Report for c308b920bc0a5139b97a07c1dbad98f0c85cb30b181bd14109ad4b12020bcd62</title>
    <updated>2026-05-11T04:06:43Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155e2d6e5cdb5619834fd</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155c62fcb905ec28c79ad</flow_id>
        <hash>c308b920bc0a5139b97a07c1dbad98f0c85cb30b181bd14109ad4b12020bcd62</hash>
        <iocs/>
        <name>6f76bde1519d0c505cea71c3d66d6fdb</name>
        <report_id>8856f70b-8798-4668-afd0-0ed4e47be8f0</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e7d91143b08ab76e91418fb9cd34c24d58cad9cd52aa8715ba41292f74c7ed18</id>
    <title>Analysis Report for e7d91143b08ab76e91418fb9cd34c24d58cad9cd52aa8715ba41292f74c7ed18</title>
    <updated>2026-05-11T04:06:37Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155dfd6e5cdb5619834fa</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155bfdf14f1cb2acf70cd</flow_id>
        <hash>e7d91143b08ab76e91418fb9cd34c24d58cad9cd52aa8715ba41292f74c7ed18</hash>
        <iocs/>
        <name>b46fb2c2a330a42a75b3c794683b7d1e</name>
        <report_id>6086c8b8-2e82-47e9-9d3e-4aec58757cd2</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>668e753c30743ba51f8aefec4239e94a16150939b23bcda86d145c94b3cb9af2</id>
    <title>Analysis Report for 668e753c30743ba51f8aefec4239e94a16150939b23bcda86d145c94b3cb9af2</title>
    <updated>2026-05-11T04:06:37Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155dcd6e5cdb5619834f9</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155bc86e92bda70270f59</flow_id>
        <hash>668e753c30743ba51f8aefec4239e94a16150939b23bcda86d145c94b3cb9af2</hash>
        <iocs/>
        <name>7dc0bc3d69126bfea57044c70561d1ef</name>
        <report_id>27d0dfa3-5594-4f67-83b5-21bb7487dde7</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>bc47ecdaca04eac472546c2023da3554a2d519aed70e28407574de718f729a25</id>
    <title>Analysis Report for bc47ecdaca04eac472546c2023da3554a2d519aed70e28407574de718f729a25</title>
    <updated>2026-05-11T04:06:34Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155e0b87f27901eb5eeb3</_id>
        <file_type>application/x-dosexec</file_type>
        <flow_id>6a0155c82fcb905ec28c79b3</flow_id>
        <hash>bc47ecdaca04eac472546c2023da3554a2d519aed70e28407574de718f729a25</hash>
        <iocs>
          <ips>
            <value>
              <ip>192.0.2.2</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>6.0.0.0</ip>
              <origin>INPUT_FILE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>12598188b44d76a8828aa7a8211c4c1bfa8093f617928f5c8f3da9cd81a42d64</SHA-256>
              <SHA-1>67c460a036df79419b3f280eaef622319e0504b3</SHA-1>
              <MD5>8f86676bbba888f4c3c4c7e3b4fdb4b2</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>1a3c94b10aafd9707c9bf6258e2273c5cab8afbd953fe78c3f5e4317c5185a77</SHA-256>
              <SHA-1>44e97678a53c0c9a55a87c053b1dee4d720acccf</SHA-1>
              <MD5>b8779e11030231fba116bb9ea23daf66</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>245fc49e4e955e1db3975b826dcf27ad2eb32a6831caa4cb6b501a3914bcfaa9</SHA-256>
              <SHA-1>29a1f0faadc42f1b9f9767d8c724fdc58dd165c8</SHA-1>
              <MD5>ad424f5f5d5ff4460343686c61e4f75e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>317bb0b285a5fea8986b4dd1abd9f7d524bd261c83298daacc0f972a8b7958d7</SHA-256>
              <SHA-1>cc4a710ff293b6793d94735b9f7f398d31000119</SHA-1>
              <MD5>6bf932e136993cd49459de108295e09a</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>3a8ffff8485c9ed35dae82574ea1a455ea2ead532251cebea19149d78dfd682c</SHA-256>
              <SHA-1>8bc0f1596c986179b82585c703bacae6d2a00316</SHA-1>
              <MD5>6087bf6af59b9c531f2c9bb421d5e902</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>4fe35e21717d34ceb4717f9e9de8fde1b3de80d76a59bb87405910c2f1d6284b</SHA-256>
              <SHA-1>5b2075b778387182bf97314b593e73f30853435d</SHA-1>
              <MD5>d1f824f98742295a66a25225701dd6d8</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>576f68c52cc25923f3ccb589b5bfde4b51993bd8a06d8351027215c0050b55fd</SHA-256>
              <SHA-1>b25f4eeccbf1fa1d6ca213e292e4a87fe0ab99d3</SHA-1>
              <MD5>013aa7ea4e0383d650ba7a0c90626353</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>903559c5b0ff6dc4123dac19436a5bf563685c157029847b71d2a15de38c36b1</SHA-256>
              <SHA-1>8ea91d98087e7838f1ca4eeca41bd74aab2e69cf</SHA-1>
              <MD5>3f1f069998ad5bf1c5b433fc24838f73</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/dib</file_type>
            </value>
            <value>
              <SHA-256>ae172a9a2fd008910b537c92a95b38bfba0e5bbdaaca719bf686e6415a7a2ba1</SHA-256>
              <SHA-1>42945c3496bc4e1943a1a05926a9b5ee31d3e450</SHA-1>
              <MD5>f64c60b749269fcf6659c450dda98486</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>caf31ff678bb95b2e90f30d9451a78138e42dcb169584bba8ce865fd9795759f</SHA-256>
              <SHA-1>1b8fa630eb87d0ea16c8a9587a09c05529da9589</SHA-1>
              <MD5>dc019e2df3ab9db8bc1b84d56c1c355e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>text/plain</file_type>
            </value>
            <value>
              <SHA-256>da9acfa4567f412e45c461544fcb0fcc2940a06f0980d1a4d75c4f494fb6e72f</SHA-256>
              <SHA-1>6fd981eadf8a89d007924e8101b0b2a49227e927</SHA-1>
              <MD5>2b66b74bec1548d7971bea17f5d9f070</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
            <value>
              <SHA-256>e133e559b524338311212dacf4235440ab833614e4063dc597e46ad17b19048c</SHA-256>
              <SHA-1>7d5f87f0c9f5a41ae8e5315e194bcce62fa65179</SHA-1>
              <MD5>262226f2952a36700daa29c7180fe1cb</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>e1779eff2b7e8ba564fc02a4ff2a6fd81d84718c3fae7d582902e0cf871a7ed6</SHA-256>
              <SHA-1>9ad2e568cd10fa4516268fbeef88095f0c28eb0b</SHA-1>
              <MD5>b6314976e92d826f2c7291168d7ca01e</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>application/octet-stream</file_type>
            </value>
            <value>
              <SHA-256>f83fa955aafb4f7c870927de5cdce598634768c4117d618b95207ce325d90841</SHA-256>
              <SHA-1>aef92f3766093bde1bfac03af9cb63637fc1927d</SHA-1>
              <MD5>c0b2b523c7b4130d99ad56d9ecfce3ec</MD5>
              <origin>INPUT_FILE</origin>
              <file_type>image/vnd.microsoft.icon</file_type>
            </value>
            <value>
              <SHA-256>4c711feef1547ba84b3217c671889b6f166f10eee7415e58428b70d0a1b5465e</SHA-256>
              <SHA-1>fdf906735307486817e4d278a0f7d5e55dde7ce2</SHA-1>
              <MD5>987f0eaa667a5bc9042ca208e6e3f688</MD5>
              <origin>AUTOIT_DECOMPILATION</origin>
              <file_type>text/x-autoit-script</file_type>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>1f676c76-80e1-4239-95bb-83d0f6d0da78</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>35138b9a-5d96-4fbd-8e2d-a2440225f93a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>abe2869f-9b47-4cd9-a358-c22904dba7f7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e2011457-1546-43c5-a5fe-008deee3d3f0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
          <registry>
            <value>
              <registry>SOFTWARE\Classes\</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>SYSTEM\CurrentControlSet\Control\Nls\Language</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Internet Explorer\IntelliForms\Storage2</registry>
              <origin>INPUT_FILE</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <registry>Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Office\16.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676</registry>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <registry>Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders</registry>
              <origin>INPUT_FILE</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </registry>
        </iocs>
        <name>xbc47ecdaca04eac472546c2023da3554a2d519aed70e28407574de718f729a25.exe</name>
        <report_id>3a707948-ab61-4c0a-95bd-4da688c8515e</report_id>
        <tags>
          <value>peexe</value>
          <value>netwire</value>
          <value>unsafe</value>
          <value>virus</value>
          <value>windows</value>
          <value>wirenet</value>
          <value>keylogger</value>
          <value>stealer</value>
          <value>compiled-script</value>
          <value>anti-debug</value>
          <value>overlay</value>
          <value>fingerprint</value>
          <value>reconnaissance</value>
          <value>autoit</value>
          <value>microsoft_visual_cc</value>
          <value>base64</value>
          <value>installer-heuristic</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8b5dc0a715f2777aa0cdb555986731eababc4344d422dda6b54485ad831334d7</id>
    <title>Analysis Report for 8b5dc0a715f2777aa0cdb555986731eababc4344d422dda6b54485ad831334d7</title>
    <updated>2026-05-11T04:06:34Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01562d0f7e400110050a79</_id>
        <file_type>application/x-msdownload</file_type>
        <flow_id>6a01558c86e92bda70270f1d</flow_id>
        <hash>8b5dc0a715f2777aa0cdb555986731eababc4344d422dda6b54485ad831334d7</hash>
        <iocs/>
        <name>0fdb304db13a9425ad7b27e67d5da0bb</name>
        <report_id>07ab15ff-28ae-4a53-912e-b87adfd2bcca</report_id>
        <tags>
          <value>peexe</value>
          <value>pedll</value>
          <value>gamarue</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b8aae3df30e354eff79ec992e040c397e785df9cfedee340425da4a18e544aaa</id>
    <title>Analysis Report for b8aae3df30e354eff79ec992e040c397e785df9cfedee340425da4a18e544aaa</title>
    <updated>2026-05-11T04:06:34Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156ac0f7e400110050b08</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01558c11d0143726890790</flow_id>
        <hash>b8aae3df30e354eff79ec992e040c397e785df9cfedee340425da4a18e544aaa</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.y3-88582539.xyz/?tr_uuid=20260508-1008-2170-aa54-b8fc02854468&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.y3-88582539.xyz/?tr_uuid=20260508-1008-2170-aa54-b8fc02854468&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.y3-88582539.xyz/?tr_uuid=20260508-1008-2170-aa54-b8fc02854468&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>y3-88582539.xyz</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.y3-88582539.xyz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.212.118</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.118</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.118</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1008-2170-aa54-b8fc02854468</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1008-2170-aa54-b8fc02854468</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>772074b06c50607dedd3513415f2a72c</name>
        <report_id>50f9f220-2a7c-4acf-b42e-9d3298dbaa1e</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>4d1460d59a21797710746d24f0701a98935ad37f66a59453aaace35c80724184</id>
    <title>Analysis Report for 4d1460d59a21797710746d24f0701a98935ad37f66a59453aaace35c80724184</title>
    <updated>2026-05-11T04:06:34Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156240f7e400110050a72</_id>
        <file_type>application/x-msdownload; format=pe</file_type>
        <flow_id>6a01558edf14f1cb2acf708d</flow_id>
        <hash>4d1460d59a21797710746d24f0701a98935ad37f66a59453aaace35c80724184</hash>
        <iocs/>
        <name>c20b21a5d19094a2d5124c534f7a0705</name>
        <report_id>443edf55-1cf5-4a33-902e-4f1ba3bbeb41</report_id>
        <tags>
          <value>peexe</value>
          <value>pedll</value>
          <value>gamarue</value>
          <value>zusy</value>
          <value>packed</value>
          <value>lolbin</value>
          <value>rundll32</value>
          <value>microsoft_visual_cc</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b863948fa0d4bf180b54929f67de19986b5567d9acf7851712829738e255e880</id>
    <title>Analysis Report for b863948fa0d4bf180b54929f67de19986b5567d9acf7851712829738e255e880</title>
    <updated>2026-05-11T04:06:30Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01566e0f7e400110050ab8</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01557bdf14f1cb2acf707f</flow_id>
        <hash>b863948fa0d4bf180b54929f67de19986b5567d9acf7851712829738e255e880</hash>
        <iocs>
          <urls>
            <value>
              <url>http://nudevidi.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://nudevidi.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudevidi.eu/ftt2/o.php?=2</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/gpbpnqqk.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2431620004&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://xxxlist.top/2344.56667121.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://xxxlist.top/p.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpvk95ghau.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://maturtube.eu/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://maturtube.eu/annaliz.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://maturtube.eu/dis/bgfooter.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://maturtube.eu/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://maturtube.eu/ftt2/check.php?t=1778472484&amp;check=56cbbc637179644479c1edb7a1d6ade9&amp;rand=728995</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://shhopper.org/wnnbfb.cgi?5</url>
              <origin>URL_RENDER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/gpbpnqqk.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>nudevidi.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>xxxlist.top</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>maturtube.eu</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>185.197.162.55</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>137.74.115.151</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>137.74.115.151</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>137.74.115.151</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.197.162.55</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>f7d67e77464a119e7aebf05be9ed042e</MD5>
              <SHA-1>d5403a30fdee7714e126532a5087b505f1485b71</SHA-1>
              <SHA-256>b9a57eed8bac4445300762268d803d0d338ed063762c869bca88e7ff2b44b478</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>826f1dfd5dfcc65e103f6b857d9f5da7</MD5>
              <SHA-1>ac5d70fad09b1570cd725c896120a88627bf537e</SHA-1>
              <SHA-256>843aa81d682cf8940bd6e376dfd2f6e224e6e4facef72380de090e42a2b9f231</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>4ab8b0e14397c9b93ea60f30e8f6f329</MD5>
              <SHA-1>11275e7b0caf3a0a32eabe535ac400d36583e1e4</SHA-1>
              <SHA-256>02b040ddd6f3a0f6bb174e860d46d938970fdab2c771319e071219bf3a65446a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>5ec54cf8c6f8cc06a8fb7196f3f30b45</MD5>
              <SHA-1>4ed47b15d9c436c899ba1d01a73ecf171258f338</SHA-1>
              <SHA-256>65c40b6c62f79539ab2a48c20936edcd8dcd8c4152f32925439e83a8be897051</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>5b15a94b77a229e75146c45058480e77</MD5>
              <SHA-1>80d3c1273b6cf3953865fc186d25f67bdae9841c</SHA-1>
              <SHA-256>82306f48167715632c1d555f189d943ca3e3971a40a9dfa2728c4dedc2090afe</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>a297af65e088f2078c8a55f6aae18110</name>
        <report_id>57843e55-4d2a-4918-b21b-f0d9680f28be</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>javascript</value>
          <value>phishing</value>
          <value>aidetect</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>3b3d84efa036367d53b781bb7d5e9ccb8a717356e38f42587a2f5abe9e17cc51</id>
    <title>Analysis Report for 3b3d84efa036367d53b781bb7d5e9ccb8a717356e38f42587a2f5abe9e17cc51</title>
    <updated>2026-05-11T04:06:30Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01566b0f7e400110050ab6</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01557a86e92bda70270f0c</flow_id>
        <hash>3b3d84efa036367d53b781bb7d5e9ccb8a717356e38f42587a2f5abe9e17cc51</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>872a4cc8576ad3e9ddbd0e13b9b06640</name>
        <report_id>5c5572d3-c361-4c2b-a697-91c385162571</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e8e5ed222b95d3b5c0cfeb8c2efd2efdf1779e9566f494e30bedf6278e7487da</id>
    <title>Analysis Report for e8e5ed222b95d3b5c0cfeb8c2efd2efdf1779e9566f494e30bedf6278e7487da</title>
    <updated>2026-05-11T04:06:30Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156700f7e400110050ab9</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01557886e92bda70270f06</flow_id>
        <hash>e8e5ed222b95d3b5c0cfeb8c2efd2efdf1779e9566f494e30bedf6278e7487da</hash>
        <iocs>
          <urls>
            <value>
              <url>http://ebulo.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ebulo.pw/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://ebulo.pw/dencasgj.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://ebulo.pw/imeqazoca/stil.css</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/vsakhv.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=1667937449&amp;ur=1&amp;HTTP_REFERER=&amp;sqkzb=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/vsakhv.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0&amp;sqkzb=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>ebulo.pw</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>213.166.71.4</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>213.166.71.4</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>3320ef1b505f5caa7241a5ed62e19052</MD5>
              <SHA-1>48cad1d296c07a4f6013d4c684c0c3f73dc244b7</SHA-1>
              <SHA-256>5f395e2b1adecc6eaef7752a858de63fd3443b9fd63407211bd2c036e2c6c58d</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>0af0a5d33b1ff022a5003b354658fd78</MD5>
              <SHA-1>c379fc021edc0823eadedad031de002e100e5936</SHA-1>
              <SHA-256>891099d7bc542d07ec7225140e97b0fa38042ea834a56f70196f0c7a86e8eca4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>278f5fc083d149d8623311ded2da2f99</MD5>
              <SHA-1>7dfa3542acc73102625dffcd80382fae5176b0a5</SHA-1>
              <SHA-256>0488cd68975a31e80ebca6e89a39aa9985a64b18ea0bb268c306b79387a5351b</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>5a60c0bf98c7ffc6e351859f43902256</MD5>
              <SHA-1>c4cbc9c2129acf95b6aeea3de9d0468015b6fc5d</SHA-1>
              <SHA-256>a3c2b52d842eef9bec04e9560909e6d60cfa3f91b90b674caf550ce17fbff5b4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/plain</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>7ece4e2f4f95dec5f950d6fe1e1f62f4</MD5>
              <SHA-1>01334b990624765653bb680ba9dd53a08db3445c</SHA-1>
              <SHA-256>c8776dffd0b5c627fef7369a30a7afa20b664948136aec0f1e88d7271afad14a</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>a80d3bf75a286c5cd9a283a89a3e5ff3</name>
        <report_id>9a1f6e5e-dc80-4449-8a20-d7b4319c416e</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b335a73d354cf50792b6fb880656d62ae5c6b25edfc0845f44055f52ce4133e0</id>
    <title>Analysis Report for b335a73d354cf50792b6fb880656d62ae5c6b25edfc0845f44055f52ce4133e0</title>
    <updated>2026-05-11T04:06:30Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156750f7e400110050ac0</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01557686e92bda70270f02</flow_id>
        <hash>b335a73d354cf50792b6fb880656d62ae5c6b25edfc0845f44055f52ce4133e0</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.noticedb.xyz/?&amp;tr_uuid=20260508-1023-088c-a6e7-e829c2f87348&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.noticedb.xyz/?&amp;tr_uuid=20260508-1023-088c-a6e7-e829c2f87348&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.noticedb.xyz/?&amp;tr_uuid=20260508-1023-088c-a6e7-e829c2f87348&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.noticedb.xyz/?&amp;tr_uuid=20260508-1023-088c-a6e7-e829c2f87348&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.noticedb.xyz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>noticedb.xyz</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1023-088c-a6e7-e829c2f87348</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1023-088c-a6e7-e829c2f87348</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>31a9b9d68c1aab4ed42ec1f1678ee841</name>
        <report_id>a47e5c63-bd0f-40bc-bad9-94b4390dd7e1</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>68a02489da9c359cec16e3cfa3bbc0e828e2e273ced6bcfd37fcda96c3b3fed4</id>
    <title>Analysis Report for 68a02489da9c359cec16e3cfa3bbc0e828e2e273ced6bcfd37fcda96c3b3fed4</title>
    <updated>2026-05-11T04:06:24Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156670f7e400110050ab3</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01557a86e92bda70270f0a</flow_id>
        <hash>68a02489da9c359cec16e3cfa3bbc0e828e2e273ced6bcfd37fcda96c3b3fed4</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>file:///tmp/tmpk769seq8.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js?pcId=53&amp;domain=ytmaxx.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/images/pe262/ns_logo_dark.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parklogic.com/Contact-us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout?utm_source=expired&amp;utm_medium=parklogic&amp;dr=ytmaxx.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>ytmaxx.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>parking3.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.232.7.47</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>3e2d440068a7d9173f5901d66f908617</name>
        <report_id>ca485701-8c12-4cd8-a5fe-a47c349561fe</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>4a998e6235fc9da5f50870ac3c950e4ac1f15b07b0e59eaae70f2b45ac099aab</id>
    <title>Analysis Report for 4a998e6235fc9da5f50870ac3c950e4ac1f15b07b0e59eaae70f2b45ac099aab</title>
    <updated>2026-05-11T04:06:21Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156b20f7e400110050b0c</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015570792fe2d217aed826</flow_id>
        <hash>4a998e6235fc9da5f50870ac3c950e4ac1f15b07b0e59eaae70f2b45ac099aab</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.gourmetgrowth.food/?tr_uuid=20260508-1004-1844-b54e-30acaecd36ff&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.gourmetgrowth.food/?tr_uuid=20260508-1004-1844-b54e-30acaecd36ff&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.gourmetgrowth.food/?tr_uuid=20260508-1004-1844-b54e-30acaecd36ff&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.gourmetgrowth.food</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>gourmetgrowth.food</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.212.146</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.146</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.146</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1004-1844-b54e-30acaecd36ff</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1004-1844-b54e-30acaecd36ff</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>cda838a443c3eb8d7fb53b13228cb18b</name>
        <report_id>8259fbc3-dd62-4ef8-ac06-dba74e2e280e</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>07b0425385ba1d191f65b0267aa8b7a20e6c07453707df48f97366bf7dc2fccd</id>
    <title>Analysis Report for 07b0425385ba1d191f65b0267aa8b7a20e6c07453707df48f97366bf7dc2fccd</title>
    <updated>2026-05-11T04:06:21Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155cfd6e5cdb5619834f4</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155b0df14f1cb2acf70b8</flow_id>
        <hash>07b0425385ba1d191f65b0267aa8b7a20e6c07453707df48f97366bf7dc2fccd</hash>
        <iocs/>
        <name>b33b0e08b8ea1f249ae7612fce6a2f02</name>
        <report_id>413715da-1734-4f44-8b5a-1daad30f9038</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e9ec626fd91b578d359c3ca59c41dea66c5f5a343f7e060fd41249e3861a867e</id>
    <title>Analysis Report for e9ec626fd91b578d359c3ca59c41dea66c5f5a343f7e060fd41249e3861a867e</title>
    <updated>2026-05-11T04:06:21Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155cdd6e5cdb5619834f3</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155b09b72a1a5304c7704</flow_id>
        <hash>e9ec626fd91b578d359c3ca59c41dea66c5f5a343f7e060fd41249e3861a867e</hash>
        <iocs/>
        <name>066495e8d43c4e5642753d419e22b55f</name>
        <report_id>5b82b1a5-1960-4749-a8e5-5c6be7769870</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8d6ea0bb5752af455266313caa18a19246d9f7eac8c4866d584a33d07bde4526</id>
    <title>Analysis Report for 8d6ea0bb5752af455266313caa18a19246d9f7eac8c4866d584a33d07bde4526</title>
    <updated>2026-05-11T04:06:14Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156620f7e400110050aaf</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01556986e92bda70270eea</flow_id>
        <hash>8d6ea0bb5752af455266313caa18a19246d9f7eac8c4866d584a33d07bde4526</hash>
        <iocs>
          <urls>
            <value>
              <url>http://tubevideo.eu/dwqkvuevn.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;kpcug=1&amp;vlizi=0&amp;pqpkg=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://nudistsport.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://nudistsport.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://nudistsport.eu/analiz.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/dwqkvuevn.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;vlizi=2449609687&amp;ur=1&amp;HTTP_REFERER=&amp;pqpkg=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>tubevideo.eu</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>nudistsport.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>80.89.234.76</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>80.89.234.76</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>e9d5555979ecafc9631dbd2b26a67ee2</MD5>
              <SHA-1>ce398f4db4fc300e929cab4b7f3e89aa1789de5f</SHA-1>
              <SHA-256>fab18b16e6036c472bbe6ad5ddfdb13f86ed4c2cc1c90af9f2c2f5e161db3ac6</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xhtml+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>07bf2d04eeb7c8c37a2259517032e5c2</MD5>
              <SHA-1>1e9c50835fd42214605b3f20ffd8314aaa165b1e</SHA-1>
              <SHA-256>dd9f978d2e13a4cfbec9cbdce8b91d09ae090d956955b708cf2937bc493055a0</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>a899e8356af5b332eda70532e1b4f5b7</MD5>
              <SHA-1>47319b504f9c97fe7f3cf6092c654d7aa1afa769</SHA-1>
              <SHA-256>8b7c9cb4158a6c29d2a8da6fbfa1dd4a5d0e973c316b413c654ba1a47d217fbf</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>b4b1b8e456c6e746728cfb27b79cdcf7</MD5>
              <SHA-1>1683d823e0d8fe74c66088b5962125d07f5e667c</SHA-1>
              <SHA-256>0d8736b216ac571cbc17ab49fe20eb779fee3a324bcd61629635e6169a86ba6f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>1bad3da60a66a9660ed1fa3367d1239d</name>
        <report_id>799cc571-7904-4a5f-9a02-4e03bb6ec6e3</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>2e4192a20ec769fd7ea7090b224d233108049b2041a1244b4a944613216056f0</id>
    <title>Analysis Report for 2e4192a20ec769fd7ea7090b224d233108049b2041a1244b4a944613216056f0</title>
    <updated>2026-05-11T04:06:14Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156650f7e400110050ab1</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01556e86e92bda70270ef5</flow_id>
        <hash>2e4192a20ec769fd7ea7090b224d233108049b2041a1244b4a944613216056f0</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/edadrzghq.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=3075021449&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/edadrzghq.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>263a80491cbb4a8898a2f5a7ef31694a</MD5>
              <SHA-1>f123c24ce1e9cd6bc069491caa85b58bc065e56f</SHA-1>
              <SHA-256>8e1e7c8a37a256e3f08c19e2ee8769e746785688ec0af4da2d1ac2ed695c9bd1</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>fc564a8db55103141f89ee2cf4800116</name>
        <report_id>05bcbd9b-2f2b-46c5-b06e-d27cd9666425</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8d041db70980bc751b7a5a1cff8021fe7357f8148ab5456995c6abc3c279fc2b</id>
    <title>Analysis Report for 8d041db70980bc751b7a5a1cff8021fe7357f8148ab5456995c6abc3c279fc2b</title>
    <updated>2026-05-11T04:06:14Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156680f7e400110050ab4</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01556c86e92bda70270ef1</flow_id>
        <hash>8d041db70980bc751b7a5a1cff8021fe7357f8148ab5456995c6abc3c279fc2b</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>7b03f8713791724f867cdfb194a1ee7b</name>
        <report_id>351c1cc4-8e61-41eb-ac64-a44a07c2faba</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e9c55c849656a2c40a9595a4c90ab95731f78cf570c20098b440f1f4f7780fbe</id>
    <title>Analysis Report for e9c55c849656a2c40a9595a4c90ab95731f78cf570c20098b440f1f4f7780fbe</title>
    <updated>2026-05-11T04:06:12Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155c4d6e5cdb5619834ed</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155a52fcb905ec28c7981</flow_id>
        <hash>e9c55c849656a2c40a9595a4c90ab95731f78cf570c20098b440f1f4f7780fbe</hash>
        <iocs/>
        <name>c363b0ff00e73d75ca4e89332ed48596</name>
        <report_id>14a11cf0-99ed-4b44-8ea5-815dd64d341c</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>13ad979ce36a14026b131658d5392aab6d70e4db19b6b9fe4996d78e8ca0c291</id>
    <title>Analysis Report for 13ad979ce36a14026b131658d5392aab6d70e4db19b6b9fe4996d78e8ca0c291</title>
    <updated>2026-05-11T04:06:10Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156800f7e400110050acd</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01556486e92bda70270edf</flow_id>
        <hash>13ad979ce36a14026b131658d5392aab6d70e4db19b6b9fe4996d78e8ca0c291</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>file:///tmp/tmpvb60k9_c.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/enhance.js?pcId=53&amp;domain=techtwo.pro</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parking3.parklogic.com/page/images/pe262/ns_logo_dark.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://parklogic.com/Contact-us</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.namesilo.com/express-checkout?utm_source=expired&amp;utm_medium=parklogic&amp;dr=techtwo.pro</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>techtwo.pro</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>parking3.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.namesilo.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.232.7.47</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>1d4d305a17ba0f38be764976f55a84e1</name>
        <report_id>eef5a59d-4c5b-4171-937e-f1036df0fdde</report_id>
        <tags>
          <value>html</value>
          <value>aidetect</value>
          <value>phishing</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>130bd88d7f63cf16811e9b95e35b6f0dede0f143c3335b2f822d8aa480b0c217</id>
    <title>Analysis Report for 130bd88d7f63cf16811e9b95e35b6f0dede0f143c3335b2f822d8aa480b0c217</title>
    <updated>2026-05-11T04:06:10Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156f10f7e400110050b54</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015565fd9cdd68416ef444</flow_id>
        <hash>130bd88d7f63cf16811e9b95e35b6f0dede0f143c3335b2f822d8aa480b0c217</hash>
        <iocs>
          <urls>
            <value>
              <url>http://tubevideo.eu/ixgttbvy.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;kpcug=1&amp;vlizi=0&amp;pqpkg=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://hdmilf.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://hdmilf.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://hdmilf.eu/analiz.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://tubevideo.eu/ixgttbvy.cgi?2&amp;pqpkg=0&amp;uunsr=0&amp;vlizi=668566904&amp;ur=1&amp;HTTP_REFERER=&amp;pqpkg=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>tubevideo.eu</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>hdmilf.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>tubevideo.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>54.36.162.157</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>54.36.162.157</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.234.34.240</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>576d3efc7c0e65c43d9a7959775f352a</MD5>
              <SHA-1>505f76655505f4b3a53ccd2e35ad2de9e2f36ff7</SHA-1>
              <SHA-256>96f2254b1da2f80024de6ab850d12254fc62dff83464cfb8630037390e981b49</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>application/xhtml+xml</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>23865609224e96ec01e7883ebb078a7b</MD5>
              <SHA-1>3650fc159a61e6df8ccb5dd51792c5a3b7d6cb96</SHA-1>
              <SHA-256>ad0679a79a3a6d322ae87fc8d2441589ddf86ddf9d2d895cf47ad67421f76334</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>c7df4011555260a99aa6e122d6be2d57</MD5>
              <SHA-1>bdb9d27c0c5fff02293e133a33fc5f72107619e3</SHA-1>
              <SHA-256>c3dff896d37f4ffb1a2eb6f922b2ddb5ec389294ee5228aed3a4d6d9982b04a9</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>b4b1b8e456c6e746728cfb27b79cdcf7</MD5>
              <SHA-1>1683d823e0d8fe74c66088b5962125d07f5e667c</SHA-1>
              <SHA-256>0d8736b216ac571cbc17ab49fe20eb779fee3a324bcd61629635e6169a86ba6f</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>9523233c7e8fcaad33053da618386d72</name>
        <report_id>e7f0b9dc-50ac-4ed1-995e-9379a8d53061</report_id>
        <tags>
          <value>html</value>
          <value>xml</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>23343f4af3b14ce4540eec4528b888efbb8bd68288b3ad31b90f64c72ee655a2</id>
    <title>Analysis Report for 23343f4af3b14ce4540eec4528b888efbb8bd68288b3ad31b90f64c72ee655a2</title>
    <updated>2026-05-11T04:06:10Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156630f7e400110050ab0</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015563792fe2d217aed81c</flow_id>
        <hash>23343f4af3b14ce4540eec4528b888efbb8bd68288b3ad31b90f64c72ee655a2</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/fltkhiqv.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/fltkhiqv.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=4102406397&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>5d5be8be3f197f7aa4d8dafac21a146a</MD5>
              <SHA-1>e0731d2fe2f03d48abb3f69dfe0d238f1c0bd3be</SHA-1>
              <SHA-256>ec724a9e515e7f604df7e23686762776f8301288109f09c06e8e7ef15cd11434</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>6fbacb50b3fc3947927396b3da29e3e2</name>
        <report_id>9be3ff20-1de3-41c1-bf61-3280e9bfa6a2</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>62698f61c2894b992cda5fa298dacc1d4a84faab2c2b9f41272272a907037e22</id>
    <title>Analysis Report for 62698f61c2894b992cda5fa298dacc1d4a84faab2c2b9f41272272a907037e22</title>
    <updated>2026-05-11T04:06:10Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a30f7e400110050af7</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155632fcb905ec28c7907</flow_id>
        <hash>62698f61c2894b992cda5fa298dacc1d4a84faab2c2b9f41272272a907037e22</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.stadscore.com/?tr_uuid=20260508-1008-524a-b842-a631b1abe289&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.stadscore.com/?tr_uuid=20260508-1008-524a-b842-a631b1abe289&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.stadscore.com/?tr_uuid=20260508-1008-524a-b842-a631b1abe289&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>www.stadscore.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>stadscore.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.252</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.252</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.252</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1008-524a-b842-a631b1abe289</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1008-524a-b842-a631b1abe289</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>4bf61839c920c86c846af9e9295a099c</name>
        <report_id>6d3fb290-c786-46dc-8303-f676346307a2</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>7614ddad0d372001bb2f999d570a9409a4737188bc15a85a1cfad2c1655f0322</id>
    <title>Analysis Report for 7614ddad0d372001bb2f999d570a9409a4737188bc15a85a1cfad2c1655f0322</title>
    <updated>2026-05-11T04:06:07Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155c0d6e5cdb5619834eb</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155a2792fe2d217aed842</flow_id>
        <hash>7614ddad0d372001bb2f999d570a9409a4737188bc15a85a1cfad2c1655f0322</hash>
        <iocs/>
        <name>3f24c7db657c600cbb1cad5c01a3351d</name>
        <report_id>fd94cedf-a67f-43ff-8dd0-1082ecaf8178</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6a8ba20cfadc10d66071526e559c8458aa3a7d7c99c516fa158fd0964cf55149</id>
    <title>Analysis Report for 6a8ba20cfadc10d66071526e559c8458aa3a7d7c99c516fa158fd0964cf55149</title>
    <updated>2026-05-11T04:05:57Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155b3d6e5cdb5619834e7</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155987d31ad7bba4fe495</flow_id>
        <hash>6a8ba20cfadc10d66071526e559c8458aa3a7d7c99c516fa158fd0964cf55149</hash>
        <iocs/>
        <name>0718e667934e6e872b218d11c989757c</name>
        <report_id>3b56f5da-1671-4fba-b626-7dcea1a53b60</report_id>
        <tags>
          <value>javascript</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>1a92463ec482ddf5399ae043151a950bc57ca3bf9c43664e3d1623273d768965</id>
    <title>Analysis Report for 1a92463ec482ddf5399ae043151a950bc57ca3bf9c43664e3d1623273d768965</title>
    <updated>2026-05-11T04:05:56Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01562a0f7e400110050a76</_id>
        <file_type>application/x-msdownload; format=pe32</file_type>
        <flow_id>6a0155612fcb905ec28c7902</flow_id>
        <hash>1a92463ec482ddf5399ae043151a950bc57ca3bf9c43664e3d1623273d768965</hash>
        <iocs>
          <files>
            <value>
              <MD5>e2bda64e31575adc98ddd3b1e8f26d1e</MD5>
              <SHA-1>9dc13bf6572d10a5e0ab5394d741cbd8de18fcef</SHA-1>
              <SHA-256>8c1510aeeef67087e89610838c6b10e1a7340e9b30b9d114609fe4a607b54e31</SHA-256>
              <origin>PE_UNPACKING</origin>
              <file_type>application/x-msdownload; format=pe32</file_type>
            </value>
          </files>
        </iocs>
        <name>12a0cb288afd230d54186f02536827a2</name>
        <report_id>c6e45a11-837f-49a9-a5d7-4e644bd191a1</report_id>
        <tags>
          <value>peexe</value>
          <value>crypt</value>
          <value>packed</value>
          <value>upx</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>a99217c5da4eed35ae3d8fe8ab558f3fc0fd844ebe23486110669eb5227794cd</id>
    <title>Analysis Report for a99217c5da4eed35ae3d8fe8ab558f3fc0fd844ebe23486110669eb5227794cd</title>
    <updated>2026-05-11T04:05:52Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155e6b87f27901eb5eeb5</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01559efd9cdd68416ef45a</flow_id>
        <hash>a99217c5da4eed35ae3d8fe8ab558f3fc0fd844ebe23486110669eb5227794cd</hash>
        <iocs>
          <urls>
            <value>
              <url>https://my.gov.uz/ru</url>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <url>https://apps.apple.com/us/app/mygov/id1544175166</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/0xxXx4j6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/3BU_gLR_.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/8iA-tInE.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Alert.CSO7K04_.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/B-McOpgF.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/B0cCjnN9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/B0ku1QvY.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/B2ykx_lj.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/B6YWM5u6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BGI-XLkH.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BIIki-f4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BNiTNjgx.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BQH1BBqB.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BQeYxuos.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BRFbMih9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BSEdIp6O.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BTjuF0hS.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BUuhYUBL.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Bclxk251.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Bd3DuOSj.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BfjbeJRW.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BjR0V9iq.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BqhvDUfA.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BtPRQ44O.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BuOlZa1S.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/C4H8gaq5.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/C4Ti4ws8.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/C7hDE26X.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CBrDW_vk.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CD5pclV7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CGpmdMAx.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CHyVIYpx.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/COlOiR6W.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/COrr8Ogu.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CQVmxQmV.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CRtV-mhp.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CS7CbiWa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CT3wmqjk.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CTs5-Z5V.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CX7xc3Uq.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CXJq3Klm.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CYnG3gX_.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Ca6V7KT_.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CcqhYfnu.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CduGMjTz.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CfOQCzWG.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/ChEHlzn-.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CidH6oXE.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Cnr0-IzI.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Cp6EFGns.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CvQMEdVu.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CxiZclKf.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D-rca1XU.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D-yCh--Y.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D2Su-Ipq.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D2XAR7o7.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D7OsvJ-O.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D90VcTX9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D9ejd6jy.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DDdL2I1e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DDmBF5cB.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DE69QVUb.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DGVp7Jvh.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DLeGDq2B.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DT-3RYyQ.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DVohIWps.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DVrrHx1S.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DWgIlkRo.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D_pUBmBO.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Df3pKa-9.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DjhXrGyC.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DkUMJaPW.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Dmocoduq.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DnckOBl1.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DoSk36fb.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DrJDvg0m.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Dt3lqw0y.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Due7dHU6.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DyXkk0C4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DzKy7h01.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DzUujgLB.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/DzlDPRiq.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/EasySettings.htPylVbQ.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/GBRmmJMy.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Group.CR5zF33J.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/H9FFW_xi.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Image.DLZeltqv.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Info.C2XSEo2P.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Item.CJSmRCa3.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/KQKKi74s.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/LifeSituation.BtsaAK85.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Logo.a31EmOwU.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/LogoIconWhite.BxM2orBD.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/LongText.phhCdaMJ.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Main.G_7kBN76.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/MediaSetting.DIpWOpOp.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/MobileAd.BHKfN5q6.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Montserrat-Bold.BhATX_ML.woff</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Montserrat-Light.DN_ZkAyc.woff</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Montserrat-Regular.BnmNV7Vq.woff</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Montserrat-SemiBold.D1nQcXIZ.woff</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/MoreButton.BoE8mFhe.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/NIYPcSMG.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/NaifUC5n.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Nj6KCyek.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/PGyJV4qV.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Pill.gwiW1aQy.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/R_xzuuCi.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/RwshIj3K.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/SBkzWk60.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/SearchResult.uOxlhiyp.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Service.DnuVl2hC.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Sphere.DYvyVFH1.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/SphereService.DIccnSww.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Stars.CyiYpr81.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/TitleWithLink.tn0RQdqM.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/TopKeywords.CvbZbpsX.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/TopService.Dm4V3V1Z.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/UserPhoto.U-QZeQ74.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/W3rgPjL0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/WEVJ06iH.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/_RJi2gvg.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/base.5i-mbPNQ.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/builds/meta/087229e8-ff4f-44b4-8a96-5f78752520ae.json</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/entry.BxL09sQO.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/g2OibN2E.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/h434if4-.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/index.CKbGNgXC.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/jATnBm8K.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/main.Co16__7W.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/rating.Dtbj8bmg.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/signature_wasm_bg.DmW7dmZj.wasm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/swiper.5kBEcpmi.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/uTxF_Jfa.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/x-USKRLp.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/xugwq-Zt.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/yauCEW-3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/img/alarmBell.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/img/bellDAVRONAKACACHE.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/img/userCard.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/oldStories/2025-05-14/f9e61dc0-cc0e-4a94-aea0-133b0d87ce81-1747225751838.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/oldStories/2026-04-06/12fb365c-c682-4a37-8f88-a269155b1c3c-1775451551613.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/oldStories/2026-04-10/888f0a8d-4d74-4954-9023-d15edeca387a-1775823644439.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/oldStories/2026-04-14/683a1b1e-f9f5-4675-ba07-a35abe767885-1776173337793.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/oldStories/2026-04-14/709e0c46-edcf-4a1e-b43d-d026535ba31d-1776175949072.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/uploads/stories/2023/10/21/0ff8-e424-71f1-338c-31d2.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/uploads/stories/2023/10/21/2699-d0e8-f36f-0850-42b8.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/uploads/stories/2023/10/21/639b-0bf1-6773-416f-0852.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/uploads/stories/2023/10/21/cbaa-7290-9a25-7f6b-6925.jpg?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/uploads/stories/2023/10/23/6622-9162-5d55-57e9-986e.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.my.gov.uz/uploads/stories/2024/02/23/8332-d947-bc3d-fe51-04f7.png?width=140&amp;height=220&amp;format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://eanticor.uz/ru</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://egov.uz/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fingerprint.dev-mygov.uz:8080/fingerprint</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://fonts.googleapis.com/css2?family=Inter:wght@300;400;500;600;700&amp;display=swap</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://fonts.googleapis.com/css2?family=Roboto:wght@300;400;500;700;900&amp;display=swap</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/api/static-content/v1/metadata/last-update/home</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/api/static-content/weather/info?latitude=50.1109221&amp;longitude=8.6821267</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/api/v1/chat/config?application_id=91a9005f-9999-4dc6-a520-e6a53860ae08</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/api/v2/static-content/page-reaction/info?hash=6666cd76f96956469e7be39d750cc7d9</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/assets/2.Dpdfzdaa.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/assets/signature_wasm_bg.DFZ1T6BP.wasm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/assets/signature_wasm_bg_mygov.DmW7dmZj.wasm</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/BgUy-a58.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/BhBVbdHo.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/BzWJs1EE.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/C36Oc2Rh.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/CC78vV99.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/CFKVnMbq.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/Cj_nos9U.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/DbDKyxJo.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/DyzxGAGt.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/Iluuv8F3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/chunks/MP8D2CA0.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/entry/app.b0ygoylV.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/entry/start.CNVMv9ck.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/nodes/0.BtLUSLzD.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/nodes/1.CcoRQkTE.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/_app/immutable/nodes/2.DZDGK-Or.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/widget</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/chat/widget?channelId=833887fd-13da-48f0-835f-b25dbb6801b2&amp;organizationId=170e672d-bf85-4a17-afab-3d0731d227fe&amp;appId=91a9005f-9999-4dc6-a520-e6a53860ae08&amp;apiEndpoint=https%3A%2F%2Fmy.gov.uz%2Fapi&amp;wsEndpoint=https%3A%2F%2Fws.my.gov.uz&amp;operatorType=CLIENT&amp;userName=Website+Visitor&amp;pageUrl=https%3A%2F%2Fmy.gov.uz%2Fru&amp;websiteUrl=my.gov.uz&amp;aiEnabled=false</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/favicon-32x32.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/img/egovru.svg?format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/img/uzinfocomLogoText.png?format=webp&amp;quality=75</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/img/weather/clear.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/ru</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/ru#</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/fonts/flaticons/040-shield.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/08242075-2385-1a37-450a-9dfbef631b96.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/0ab0f3eb-649b-4185-09f7-6959d892ed89.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/0db7983b-bf6c-94f0-8c7b-595d0930cd39.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/0f1fc2f1-0802-af30-0644-388e6559df2b.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/27e4f99b-024b-c356-7287-491e86cded4c.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/32a2461a-32a7-f04b-676c-59a4025af14e.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/338e3220-6489-6003-ca4f-ab1d2f072e3b.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/3cb7c439-ef6e-1bb4-04ca-48502d4ba7af.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/5847fe49-0d3a-d821-10e3-e165e3b8b3c8.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/61414e44-ca9a-ddc0-500b-e857368726a1.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/6495bbf1-202b-7a8a-b965-a255a569ab10.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/650cb872-98c8-5b8f-fbbd-5315c972bb32.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/9a5ff80e-a67c-3996-a618-238c5a31a7de.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/b0423948-1ecb-4f3c-adc9-7f3b40f7bf7f.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/b4140e41-281b-b04e-a5bd-ddd7098dc03a.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/caf183cd-fa0f-f612-4542-226d0f66ce4f.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/d7b3317e-ed16-cbad-99ad-b78819cbd647.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/d921e08e-382e-c48f-cfc4-05420e311675.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/e00ea6ce-6828-a24f-6d92-f3a02e518d5d.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/e45c0372-1ff9-3bae-3ec8-94e0da371f58.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/e8f3b47f-e9f6-18c9-6d98-6baf2440c795.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/ebe33383-0168-e6b0-0237-8c763e70b32f.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://oldmy.gov.uz/uploads/sphere/ff880fd6-893c-58a6-1b39-231c70e9e160.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://play.google.com/store/apps/details?id=uz.uzinfocom.mygov</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://t.me/MyGovUz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://uzinfocom.uz/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.facebook.com/egovernmentuz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.instagram.com/my.gov.uz/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://youtube.com/channel/UC7NMuSYJQUKQSLQnE2L5L2A</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://my.gov.uz/api&amp;wsEndpoint=https://ws.my.gov.uz&amp;operatorType=CLIENT&amp;userName=Website</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://my.gov.uz/ru&amp;websiteUrl=my.gov.uz&amp;aiEnabled=false</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Alert.CSO7K04_.css</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/BTjuF0hS.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/CRtV-mhp.js</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/D_pUBmBO.js</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/EasySettings.htPylVbQ.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Group.CR5zF33J.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Image.DLZeltqv.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Info.C2XSEo2P.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Item.CJSmRCa3.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/LifeSituation.BtsaAK85.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Logo.a31EmOwU.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/LongText.phhCdaMJ.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Main.G_7kBN76.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/MediaSetting.DIpWOpOp.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/MobileAd.BHKfN5q6.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/MoreButton.BoE8mFhe.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Pill.gwiW1aQy.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/SearchResult.uOxlhiyp.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Service.DnuVl2hC.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Sphere.DYvyVFH1.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/SphereService.DIccnSww.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/Stars.CyiYpr81.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/TitleWithLink.tn0RQdqM.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/TopKeywords.CvbZbpsX.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/TopService.Dm4V3V1Z.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/UserPhoto.U-QZeQ74.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/entry.BxL09sQO.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/index.CKbGNgXC.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/rating.Dtbj8bmg.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://assets.my.gov.uz/assets/mygov/_app/a6484adb/swiper.5kBEcpmi.css</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://eanticor.uz/ru</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://egov.uz/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://my.gov.uz</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://my.gov.uz/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://my.gov.uz/logo.png</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://my.gov.uz/search?q=%7Bsearch_term_string%7D</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://my.gov.uz/uz/page/mobile-apps</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://schema.org</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://t.me/MyGovUz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://uzinfocom.uz/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.facebook.com/egovernmentuz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://www.instagram.com/my.gov.uz/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://youtube.com/channel/UC7NMuSYJQUKQSLQnE2L5L2A</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://youtube.com/channel/UC7NMuSYJQUKQSLQnE2L5L2Ahttps://www.facebook.com/egovernmentuzhttps://t.me/MyGovUzhttps://www.instagram.com/my.gov.uz/</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>assets.my.gov.uz</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>eanticor.uz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>egov.uz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>my.gov.uz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>schema.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>t.me</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>uzinfocom.uz</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>www.instagram.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>youtube.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>apps.apple.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>assets.my.gov.uz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.my.gov.uz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>eanticor.uz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>egov.uz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>fonts.googleapis.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>my.gov.uz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>oldmy.gov.uz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>play.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>t.me</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>uzinfocom.uz</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.facebook.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.instagram.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>youtube.com</url>
              <origin>URL_RENDER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>163.70.128.174</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>93.188.84.248</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.95</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>194.93.25.248</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>93.188.84.248</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>93.188.84.54</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>93.188.84.54</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>149.154.167.99</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.136</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>195.158.28.148</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.8.213.58</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>157.240.253.35</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>93.188.84.54</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>185.8.213.58</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>195.158.28.148</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>93.188.84.248</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.250.154.100</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>149.154.167.99</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>157.240.253.35</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>163.70.128.174</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>142.251.14.136</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <SHA-256>62e9a4ea33f2f6715ded7e827b3caef7596925f2cf749b44c43acd2afde42af7</SHA-256>
              <SHA-1>24361c6e0259d7c65918d53005fea8a54b17d5da</SHA-1>
              <MD5>07861dc0f5465e85b829aa237ce74d55</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>image/png</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>220bcb1ca2a00dad8195df3f900f82cab60fa423364e9d9aff31559947bf15ce</SHA-256>
              <SHA-1>8d52cf5d7815d3679d1cd8f326471edfe9fd9f34</SHA-1>
              <MD5>4ddcdb6a2d207dd0277856f0549bcf60</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>b61847b7c11cba291a2db5d4f1a40cfeae93abc82cca146ca556585ac6597da6</SHA-256>
              <SHA-1>598200950f13d3ccb7872b47ba0bf5c7d4a0f3c7</SHA-1>
              <MD5>429bd01aa430513fe647bccdccfc883c</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>1f2fb9ab2a21c5de90044cb1498f2e1848193e7c010bb2c48236cf33a189e9af</SHA-256>
              <SHA-1>215a3af0c3a49dfb869fb12d11a393e1787b1584</SHA-1>
              <MD5>f638477a6ee02703bcc2314cd7f8d63d</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>589b0e05d4f058e5d6392f210effb1d5cc2ae42bda220c9d33a0c1faced55001</SHA-256>
              <SHA-1>280f2b7220a1537c2aeaed3703354c6333d17072</SHA-1>
              <MD5>14021a8d9cd449224b7e661d92cedd59</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <SHA-256>7c0a3a8af531b4779b4a606b87ca943d35d4d7767474af56b425a4fa333c6d13</SHA-256>
              <SHA-1>c91c0c67a3c689b45a49c8ec82b3c1ac64a9017f</SHA-1>
              <MD5>11d6a849836077d2fbaf7d718b18e685</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>c1a6db2e296b5f71c308a88b6a3a5aa129496f4d9315ecf3a52043cdad903737</SHA-256>
              <SHA-1>f8ea220530ee681fa5ccf7c24d49c20915cce5f4</SHA-1>
              <MD5>4463441c32cf1cf2fc2da4a4f7a58c49</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>c50da99e05ab05eafe93eecadf70ee521d7a8bfb23c37eb8ad9b968983b419ea</SHA-256>
              <SHA-1>fe6de49949e4819caf2b737c61d4328db9582ac7</SHA-1>
              <MD5>7a0d59cdad509484fb6b74d83aa2faba</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/css</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>2f6a75e774e2e9e350cca75e021c15af0cd40e4256d7bb2bb34d99fb3b8b1cbd</SHA-256>
              <SHA-1>0c2bceb3433ebdb2fcfc7aca090dff2a1de1b781</SHA-1>
              <MD5>b6e4dc49391b95c0c8cc88ccdb5b3ced</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <SHA-256>aa97e7e7adb8455a7e926477ed09192ae734ee995771c114030b2637e8bd3af2</SHA-256>
              <SHA-1>dd43ff0d5453905b79e76079b8b07f891d46d4fe</SHA-1>
              <MD5>1364aa2ee80d92e5adf8e35f1a142015</MD5>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
          <uuids>
            <value>
              <uuid>01eb672e-cf0a-4950-9de9-3e0819bd2f72</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>08242075-2385-1a37-450a-9dfbef631b96</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>087229e8-ff4f-44b4-8a96-5f78752520ae</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>0ab0f3eb-649b-4185-09f7-6959d892ed89</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>0db7983b-bf6c-94f0-8c7b-595d0930cd39</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>0f1fc2f1-0802-af30-0644-388e6559df2b</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>12fb365c-c682-4a37-8f88-a269155b1c3c</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>27e4f99b-024b-c356-7287-491e86cded4c</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>2bb15260-e751-40b8-a136-dcd947cfb1d6</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>32a2461a-32a7-f04b-676c-59a4025af14e</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>338e3220-6489-6003-ca4f-ab1d2f072e3b</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>3cb7c439-ef6e-1bb4-04ca-48502d4ba7af</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>5847fe49-0d3a-d821-10e3-e165e3b8b3c8</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>61414e44-ca9a-ddc0-500b-e857368726a1</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>6495bbf1-202b-7a8a-b965-a255a569ab10</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>650cb872-98c8-5b8f-fbbd-5315c972bb32</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>683a1b1e-f9f5-4675-ba07-a35abe767885</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>69d0521f-1cce-4442-b2bd-798c2c8b19ec</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>709e0c46-edcf-4a1e-b43d-d026535ba31d</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>7de869ab-0555-4307-917a-a88e481e8a1d</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>888f0a8d-4d74-4954-9023-d15edeca387a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>9a5ff80e-a67c-3996-a618-238c5a31a7de</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>b0423948-1ecb-4f3c-adc9-7f3b40f7bf7f</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>b4140e41-281b-b04e-a5bd-ddd7098dc03a</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>caf183cd-fa0f-f612-4542-226d0f66ce4f</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>d7b3317e-ed16-cbad-99ad-b78819cbd647</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>d921e08e-382e-c48f-cfc4-05420e311675</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e00ea6ce-6828-a24f-6d92-f3a02e518d5d</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e45c0372-1ff9-3bae-3ec8-94e0da371f58</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>e8f3b47f-e9f6-18c9-6d98-6baf2440c795</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>ebe33383-0168-e6b0-0237-8c763e70b32f</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>f9e61dc0-cc0e-4a94-aea0-133b0d87ce81</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>fc053e34-d65d-4466-aaf5-2157c8ea58c7</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>ff880fd6-893c-58a6-1b39-231c70e9e160</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>hxxps://my.gov.uz/ru</name>
        <report_id>2dd09f00-ee0d-481f-9f43-a070f05851d3</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>png</value>
          <value>txt</value>
          <value>obfuscated</value>
          <value>base64</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>f36f92080f213dc34fe5550574e1b7a9afee321cbdb58fc771331c6d58cde30b</id>
    <title>Analysis Report for f36f92080f213dc34fe5550574e1b7a9afee321cbdb58fc771331c6d58cde30b</title>
    <updated>2026-05-11T04:05:51Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155afd6e5cdb5619834e3</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a0155902fcb905ec28c7953</flow_id>
        <hash>f36f92080f213dc34fe5550574e1b7a9afee321cbdb58fc771331c6d58cde30b</hash>
        <iocs/>
        <name>47d2433db510dbba81469ad0b398fe10</name>
        <report_id>d5937454-2e77-4dad-8454-e6da2a9db473</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>4d6a9e40da2c958b85d8529a24822f030e54da82972091913c9de20e2e2f5a10</id>
    <title>Analysis Report for 4d6a9e40da2c958b85d8529a24822f030e54da82972091913c9de20e2e2f5a10</title>
    <updated>2026-05-11T04:05:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156600f7e400110050aae</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555f2fcb905ec28c78fd</flow_id>
        <hash>4d6a9e40da2c958b85d8529a24822f030e54da82972091913c9de20e2e2f5a10</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/rpzjjbe.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=2773526619&amp;ur=1&amp;HTTP_REFERER=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://smallnudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://smallnudist.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://smallnudist.eu/logpag.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/rpzjjbe.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>smallnudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>51.91.251.47</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>65e429f1572121697887733c416f08fa</MD5>
              <SHA-1>26c41b3b6ea59fc228f929c220be5a406a025797</SHA-1>
              <SHA-256>79d2a615f24d946a843a2e41e9648afca5daea39c6a63d9f3102622dfe5a2728</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>009d17688a84ad8a5283d533daec796d</MD5>
              <SHA-1>4cf8c99e818052005c6e07c395f6a24b21077dcb</SHA-1>
              <SHA-256>288c45632c63c425936de6c1530f08d5dc7dd3d5213add0372e361aeee6e6cde</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>d5e980c0d1b1ad677935578dc466f0c5</MD5>
              <SHA-1>e7f6f93704e389c3c85955c61d7cdda7178f70c4</SHA-1>
              <SHA-256>19e3d8a893c44ee9bb805dc0772d7f0030ccfcc9f141a7ee69900aa5d21355c4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>344304fc86d4361010f12450f1fe2196</MD5>
              <SHA-1>efd3ed361c0c668efabe78867814d12be6ae6ba9</SHA-1>
              <SHA-256>a47303cc978ca506246d6129e14ea7af8d515af4a30dcb0c1508a23b0af35149</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>d7db2cb1143145a7be873be9a9b6987b</MD5>
              <SHA-1>693551e630c37d9022b53e6b4e5cb317bd3f3cd5</SHA-1>
              <SHA-256>57c8c169328ff15aff7a13ac1c23533fcdf4c2585755a37ea6486e8f0a750b02</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>202058787fa83caa960ac2c3dfcba2b8</name>
        <report_id>ed0ddce9-2829-4fcb-a95c-3959ddc3adee</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>e20c16c8a137f3fa9b643c23ac1092eba5966db99376f902973eb6219a1e6b21</id>
    <title>Analysis Report for e20c16c8a137f3fa9b643c23ac1092eba5966db99376f902973eb6219a1e6b21</title>
    <updated>2026-05-11T04:05:49Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156aa0f7e400110050b03</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01556286e92bda70270edb</flow_id>
        <hash>e20c16c8a137f3fa9b643c23ac1092eba5966db99376f902973eb6219a1e6b21</hash>
        <iocs>
          <urls>
            <value>
              <url>http://martinezproduccionesperu.com/?&amp;tr_uuid=20260508-1022-53a0-b275-e4409585bab0&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://martinezproduccionesperu.com/?&amp;tr_uuid=20260508-1022-53a0-b275-e4409585bab0&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://martinezproduccionesperu.com/?&amp;tr_uuid=20260508-1022-53a0-b275-e4409585bab0&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://martinezproduccionesperu.com/?&amp;tr_uuid=20260508-1022-53a0-b275-e4409585bab0&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>martinezproduccionesperu.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>martinezproduccionesperu.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1022-53a0-b275-e4409585bab0</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1022-53a0-b275-e4409585bab0</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>e9b6a044eafae57428a29472e292172b</name>
        <report_id>aba5bb4a-9497-44f3-ad88-27c0495520ee</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>4afaac3195701914158bdae659878f531433d4dadcd97ab15f0c7590f137a626</id>
    <title>Analysis Report for 4afaac3195701914158bdae659878f531433d4dadcd97ab15f0c7590f137a626</title>
    <updated>2026-05-11T04:05:47Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0155abd6e5cdb5619834e1</_id>
        <file_type>text/javascript</file_type>
        <flow_id>6a01558cdf14f1cb2acf7089</flow_id>
        <hash>4afaac3195701914158bdae659878f531433d4dadcd97ab15f0c7590f137a626</hash>
        <iocs/>
        <name>1e3b5537e7b936e2918311bfdefee52b</name>
        <report_id>a9764167-b9bd-4493-9b02-beeb2e482726</report_id>
        <tags>
          <value>javascript</value>
          <value>phishing</value>
          <value>evasive</value>
          <value>repaired</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8abd99617d270d088c25392284873008f142b3080390ef21894391b0b03a8ced</id>
    <title>Analysis Report for 8abd99617d270d088c25392284873008f142b3080390ef21894391b0b03a8ced</title>
    <updated>2026-05-11T04:05:40Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01566c0f7e400110050ab7</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555f792fe2d217aed818</flow_id>
        <hash>8abd99617d270d088c25392284873008f142b3080390ef21894391b0b03a8ced</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>b1d4cc9955feaa80cf1940a80e4fdc7c</name>
        <report_id>4a345ca5-3e6d-4b90-a95f-dc0cb6552456</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>5d382238c8521ddde319d129841dda67d25b6581ed55719b4fbe2bcff55ed74a</id>
    <title>Analysis Report for 5d382238c8521ddde319d129841dda67d25b6581ed55719b4fbe2bcff55ed74a</title>
    <updated>2026-05-11T04:05:37Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156870f7e400110050ad7</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555e2fcb905ec28c78f7</flow_id>
        <hash>5d382238c8521ddde319d129841dda67d25b6581ed55719b4fbe2bcff55ed74a</hash>
        <iocs>
          <urls>
            <value>
              <url>http://bigot.life/?&amp;tr_uuid=20260508-1024-2911-b2a9-586b15ed36b2&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://bigot.life/?&amp;tr_uuid=20260508-1024-2911-b2a9-586b15ed36b2&amp;fp=-7</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://bigot.life/?&amp;tr_uuid=20260508-1024-2911-b2a9-586b15ed36b2&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://bigot.life/?&amp;tr_uuid=20260508-1024-2911-b2a9-586b15ed36b2&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpq4tbakxh.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>http://bigot.life/?&amp;tr_uuid=20260508-1024-2911-b2a9-586b15ed36b2&amp;fp=-7</url>
              <origin>URL_RENDER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>bigot.life</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>bigot.life</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <uuids>
            <value>
              <uuid>20260508-1024-2911-b2a9-586b15ed36b2</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1024-2911-b2a9-586b15ed36b2</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>a27e595579f026d1a90dad4684eef4c8</name>
        <report_id>24eb6aee-6a18-45c7-b972-77b05f23d989</report_id>
        <tags>
          <value>html</value>
          <value>aidetect</value>
          <value>phishing</value>
        </tags>
        <verdict>UNKNOWN</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>8c142765ecd8c30c382c7f5190b53a12f424c12581df18e8e7dbdec1708763f0</id>
    <title>Analysis Report for 8c142765ecd8c30c382c7f5190b53a12f424c12581df18e8e7dbdec1708763f0</title>
    <updated>2026-05-11T04:05:34Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156350f7e400110050a7f</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155562fcb905ec28c78e5</flow_id>
        <hash>8c142765ecd8c30c382c7f5190b53a12f424c12581df18e8e7dbdec1708763f0</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>045317e4d971f1d2287855d4e2ab754a</name>
        <report_id>4c394e18-200c-44ee-9a5a-512ae7425f92</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>b06d5f4d0882c6c04c830abe1f80622f4245949212b5df6af3af5dd1168c258c</id>
    <title>Analysis Report for b06d5f4d0882c6c04c830abe1f80622f4245949212b5df6af3af5dd1168c258c</title>
    <updated>2026-05-11T04:05:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156a00f7e400110050af4</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555a792fe2d217aed814</flow_id>
        <hash>b06d5f4d0882c6c04c830abe1f80622f4245949212b5df6af3af5dd1168c258c</hash>
        <iocs>
          <urls>
            <value>
              <url>http://www.servhls.com/?tr_uuid=20260508-1007-131a-844f-89bb6c1c2fce&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.servhls.com/?tr_uuid=20260508-1007-131a-844f-89bb6c1c2fce&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://www.servhls.com/?tr_uuid=20260508-1007-131a-844f-89bb6c1c2fce&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>servhls.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.servhls.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.182.250</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.250</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.182.250</ip>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1007-131a-844f-89bb6c1c2fce</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <uuid>20260508-1007-131a-844f-89bb6c1c2fce</uuid>
              <origin>INPUT_FILE</origin>
            </value>
          </uuids>
        </iocs>
        <name>d35c5ff9b5655e5fe9854f1d887f8994</name>
        <report_id>5e2d33a2-7a19-44fe-8fbf-70563b94db5c</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>SUSPICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>dadca2d28719a35ff37b79a364a7cf482ab285ac28e227cd947c3c3efe52a1e0</id>
    <title>Analysis Report for dadca2d28719a35ff37b79a364a7cf482ab285ac28e227cd947c3c3efe52a1e0</title>
    <updated>2026-05-11T04:05:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156450f7e400110050a93</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155562fcb905ec28c78e7</flow_id>
        <hash>dadca2d28719a35ff37b79a364a7cf482ab285ac28e227cd947c3c3efe52a1e0</hash>
        <iocs>
          <urls>
            <value>
              <url>http://shhopper.org/uypialdpt.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;dxkyv=1&amp;hbzay=0</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://africannudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://africannudist.eu/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>http://africannudist.eu/dencasgj.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://africannudist.eu/j61.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://africannudist.eu/j61_1.js</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://africannudist.eu/j61_1_1.htm</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://africannudist.eu/j61_1_2.htm</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>http://shhopper.org/ajn.cgi?14&amp;group=push</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/uypialdpt.cgi</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/uypialdpt.cgi?2&amp;sqkzb=0&amp;bcpgx=0&amp;hbzay=3349196282&amp;ur=1&amp;HTTP_REFERER=http%3A%2F%2Fshhopper.org%2Flkhtpdbqc.cgi%3F20</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://shhopper.org/lkhtpdbqc.cgi?20</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>africannudist.eu</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>shhopper.org</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>94.103.94.196</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>213.166.71.4</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>213.166.71.4</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>94.103.94.196</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>850f39209f131594d633608eec5ef49f</MD5>
              <SHA-1>91b1065b8bb1ed554181f039552813ab51c334fa</SHA-1>
              <SHA-256>283eba837eff2a2691a3158feaddca0f1e5ee70d99a881a630c0833538aa87c9</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>88727c4d251cd8a92419386f42fd0e04</MD5>
              <SHA-1>b4b53efedcf5fc7c574bf14eb845309f8c8abdc7</SHA-1>
              <SHA-256>14e53edb087b9370823b79e5a97f53cf127a1a0e2e5c394843da5988aea490ee</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>ff57fc4ff0395bd60357211e98fc13c8</MD5>
              <SHA-1>f78b5b1d89daa23e33c8653db3eefc09a1b01785</SHA-1>
              <SHA-256>13560ca2f8e8ce3fb878b95f45aabafbb951daef134dc21926ff1eb780291028</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>10a4edf661df23548f239ab25e9db1f9</MD5>
              <SHA-1>5772c62475e225be7d8cfb7cdf455ebedeaa344c</SHA-1>
              <SHA-256>6d97e946f69bccb1ce69cc776709c708d53611296d884f5909a941099ca22767</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>d9eea68b09a4795893f5fcd90306f950</MD5>
              <SHA-1>22aed5a152bec303e82c64fc1c9ea3c86d4cec02</SHA-1>
              <SHA-256>d6b77e8a15a89c3c3919a561bde2df48ee349d3c45fa4f11c6eab17be57e3f51</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>d4ed08523b82feae8074b9f4a9aac324</MD5>
              <SHA-1>67a052a24268fc4636974732dad1132665866547</SHA-1>
              <SHA-256>63bb32a6653fe25da448683d37cd71f8471ff043e429672ce26dd6735a0f16e0</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <MD5>75cceff3e5f0f90b9fd7761088f03eff</MD5>
              <SHA-1>ef798d74735aab6079b5dd4c8c97449dfeb7b8cf</SHA-1>
              <SHA-256>33d4b114dbeb3b940877ba7ea2c92e2c4d50a765587c110e673fd646e8573ca3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/javascript</file_type>
              <verdict>SUSPICIOUS</verdict>
            </value>
          </files>
        </iocs>
        <name>98ae8c6f13625e2b53156f0736c5db15</name>
        <report_id>113a4967-bdf5-444e-9938-38b645d3f0be</report_id>
        <tags>
          <value>html</value>
          <value>javascript</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>3c87f4cdcaf41623eb7ec2efcd7c7977f84893262003b1a2db559d3932ace213</id>
    <title>Analysis Report for 3c87f4cdcaf41623eb7ec2efcd7c7977f84893262003b1a2db559d3932ace213</title>
    <updated>2026-05-11T04:05:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156510f7e400110050a9c</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555d86e92bda70270ed3</flow_id>
        <hash>3c87f4cdcaf41623eb7ec2efcd7c7977f84893262003b1a2db559d3932ace213</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/enbleema.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;moeud=3120778792&amp;ur=1&amp;HTTP_REFERER=&amp;haxvf=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/enbleema.cgi?19&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0&amp;haxvf=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>file:///tmp/tmpyr086_bh.html</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://0c04f5.binomlink.com/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://0c04f5.binomlink.com/nlp/index.php</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://0c04f5.binomlink.com/nlp/index.php?aff_sub=qe01&amp;aff_sub2=cfd0f2tft1nbgwj5de&amp;aff_sub3=qe01%3Faff_sub5%3DSF_006OG00000HdRY1&amp;url_bnm_redirect=https%3A%2F%2Ft.mbslr2.com%2F324161%2F8865%2F39267</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://0c04f5.binomlink.com/nlp/index.php?aff_sub=qe01&amp;aff_sub2=cfd0f2tft1nbgwj5de&amp;aff_sub3=qe01?aff_sub5=SF_006OG00000HdRY1&amp;duplication=1&amp;url_bnm_redirect=https://t.mbslr2.com/324161/8865/39267</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cvrtjkmt.com/api/v1/project-optional-settings/10047751/10049032</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://cdn.cvrtjkmt.com/v1/js/10047751-10049032.js?environment=production</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://data.jerkmate.com/click_stream</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gateway.jerkmate.com/session-api/ws-session?referer=</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://gateway.jerkmate.com/wswidget/ws-session-widget.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/_ilc/api/v1/registry/template/500</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/_ilc/client.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/assets/event-bus/ws-event-bus.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/assets/observers/cookie-observer.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/assets/observers/modal-queue-observer.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/assets/observers/ws-clickstream-observer.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/assets/observers/ws-ga4-observer.min.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/cams/girl?transaction_id=102e1a5dfe712dc6499def7fff3956:8699&amp;aff_id=324161&amp;source=&amp;xid=jm-hpf-8699-jmlcom&amp;landing_id=33548&amp;display=form2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/au.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/be.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/bg.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/co.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/cr.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/de.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/gb.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/ge.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/jp.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/lt.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/lv.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/ro.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/ua.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/us.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/ve.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/flags/vn.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/fonts/JTUSjIg1_i6t8kCHKm459Wlhyw.woff2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/categories-list/static/js/main.e2385fed.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/chatbot/static/js/main.88fdd922.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/footer/static/js/main.d8fb835a.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/header/static/js/main.BK1y3z48.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/hls-js-1.1.5</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/information-messages/static/js/main.65a7f7e3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/metadata/static/js/main.560cdf14.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/modal-form/static/js/main.d5986e1c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/overlay/static/js/main.a6c37c74.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/performer-filters/static/js/main.509afa52.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/react-17.0.2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/react-dom-17.0.2</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/react-query-3.39.3</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/scroll-limiter/static/js/main.87948bf4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/seo/static/js/main.1894be48.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/session-client/session-client@3.0.4.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/similar-cams/static/js/main.56bdb82c.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/survey-prompt/static/js/main.13afb2c3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/tabs/static/js/main.2e923534.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/tag-chips/static/js/main.52ccca1e.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/mfe/zod-3.21.4</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/ADRIANNA777.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/AdelleGrey.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/AmandaAndrews.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/AnellaSmitt.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Anna_Jenssen.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/AudreyRay.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/AussieCosplay.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/BellaSweet.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Bigtits_168.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Bonbon99.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Bonny_Brok.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/British_EmJess.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Bronze_goddess.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/CathyCavalli.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/ClaraVanessa.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/ClickGirl.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/EVYE.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/EmilyBlack69.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Emily_Xxx69.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/EviilAngel.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/EvonieCarter.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/ExoticGiselle.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/FreshMilf69.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/GemmaMassey.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/HollyJhonson.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Indigoelle.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Isa_Skynny.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/IsabelaJohnson.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Jessiforyou.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/JoiDivision.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/KimLuvv.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/KinkyCorina.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/KountryCutie.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/LadyCoquine.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/LadyJeen.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/LiliithSnoop.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Lily_Flower69.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/LitaJones.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/LyennRae.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/MayaVixxen.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Melissakovalenko.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/MillaBliss.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/MissDesi.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/MissFinley.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/MiticaBrenner.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/OliviaPagani.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Pocahontasfg.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Polluxia.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Rose_Mussica.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/SamanthaaWoods.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/SaraBacker.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/SaschaFit.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Sophiie_Collins.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/StephanyGray.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Sweet_titi.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/Takaramisao.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/VictoriaMorrone.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/imlucyferreira.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/maddieBlummer.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/perf-thumb/s/avatar/xHadesVonDirgex.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/theme.min.css</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/favicon.ico</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/heart-love.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/incognito.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/jerkylogo.webp</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/message-bubble.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/overlay-jerky.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/secure.svg</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/ui-contents/survey-prompt-jerky.png</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.analytics.google.com/g/collect</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.analytics.google.com/g/collect?v=2&amp;tid=G-S6XTBZ5V47&amp;gtm=45je6562v880543691z8811010754za20gzb811010754zd811010754&amp;_p=1778472455422&amp;_gaz=1&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;dma_cps=a&amp;dma=1&amp;_eu=EAAAAGAC&amp;are=1&amp;cid=813081926.1778472457&amp;frm=0&amp;ir=1&amp;pscdl=noapi&amp;rcb=17&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;gaf=2&amp;_s=1&amp;tag_exp=0~115938466~115938469~118463262~118719171&amp;sid=1778472456&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fjerkmate.com%2Fcams%2Fgirl%3Ftransaction_id%3D102e1a5dfe712dc6499def7fff3956%3A8699%26aff_id%3D324161%26source%3D%26xid%3Djm-hpf-8699-jmlcom%26landing_id%3D33548%26display%3Dform2&amp;dt=Live%20Cam%20Girls%3A%20Sex%20Chat%20with%20Nude%20Women%20on%20Webcam%20%7C%20Jerkmate&amp;en=page_view&amp;_fv=1&amp;_nsi=1&amp;_ss=1&amp;ep.content_group=Category%20Grid&amp;up.transaction_id=&amp;up.aff_id=&amp;up.aff_sub=&amp;up.aff_sub2=&amp;up.aff_sub3=&amp;up.aff_sub4=&amp;up.aff_sub5=&amp;up.offer_id=&amp;up.url_id=&amp;tfd=2106</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://region1.analytics.google.com/g/collect?v=2&amp;tid=G-S6XTBZ5V47&amp;gtm=45je6562v880543691za20gzb811010754zd811010754&amp;_p=1778472455422&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;dma_cps=a&amp;dma=1&amp;_eu=EAAAAGQC&amp;are=1&amp;cid=813081926.1778472457&amp;frm=0&amp;ir=1&amp;pscdl=noapi&amp;rcb=17&amp;sr=800x600&amp;uaa=&amp;uab=&amp;uafvl=&amp;uam=&amp;uamb=0&amp;uap=Linux&amp;uapv=&amp;uaw=0&amp;ul=en-us&amp;gaf=2&amp;_s=2&amp;tag_exp=0~115938466~115938469~118463262~118719171&amp;sid=1778472456&amp;sct=1&amp;seg=0&amp;dl=https%3A%2F%2Fjerkmate.com%2Fcams%2Fgirl%3Ftransaction_id%3D102e1a5dfe712dc6499def7fff3956%3A8699%26aff_id%3D324161%26source%3D%26xid%3Djm-hpf-8699-jmlcom%26landing_id%3D33548%26display%3Dform2&amp;dt=Live%20Cam%20Girls%3A%20Sex%20Chat%20with%20Nude%20Women%20on%20Webcam%20%7C%20Jerkmate&amp;en=experience_impression&amp;_ee=1&amp;ep.content_group=Category%20Grid&amp;ep.exp_variant_string=CONV-1004194539-1004457395&amp;_et=73&amp;tfd=2218</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://script.crazyegg.com/pages/data-scripts/0116/2536/sampling/jerkmate.com.json?t=1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://script.crazyegg.com/pages/data-scripts/0116/2536/site/jerkmate.com.json?t=1</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://script.crazyegg.com/pages/scripts/0116/2536.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://script.crazyegg.com/pages/versioned/common-scripts/8d324e852ff7987344b35f9dbd70c7d3.js</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://stats.g.doubleclick.net/g/collect?v=2&amp;tid=G-S6XTBZ5V47&amp;cid=813081926.1778472457&amp;gtm=45je6562v880543691z8811010754za20gzb811010754zd811010754&amp;rcb=17&amp;aip=1&amp;dma=1&amp;dma_cps=a&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;frm=0&amp;tag_exp=0~115938466~115938469~118463262~118719171</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://twitter.com/jerkmatemodels</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.google.com/ccm/collect</url>
              <origin>URL_RENDER</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>https://www.google.com/ccm/collect?rcb=16&amp;frm=0&amp;ae=g&amp;en=page_view&amp;dl=https%3A%2F%2Fjerkmate.com%2Fcams%2Fgirl&amp;scrsrc=www.googletagmanager.com&amp;rnd=766792731.1778472456&amp;dt=Live%20Cam%20Girls%3A%20Sex%20Chat%20with%20Nude%20Women%20on%20Webcam%20%7C%20Jerkmate&amp;auid=313234099.1778472456&amp;navt=n&amp;npa=1&amp;ep.ads_data_redaction=0&amp;gtm=45He6562v811010754za200zd811010754xea&amp;gcd=13l3l3l2l1l1&amp;dma_cps=a&amp;dma=1&amp;tag_exp=0~115938466~115938468~118463262&amp;apve=1&amp;apvf=f&amp;apvc=1&amp;tft=1778472456190&amp;tfd=1487</url>
              <origin>URL_RENDER</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>https://www.google.de/ads/ga-audiences?v=1&amp;t=sr&amp;slf_rd=1&amp;_r=4&amp;tid=G-S6XTBZ5V47&amp;cid=813081926.1778472457&amp;gtm=45je6562v880543691z8811010754za20gzb811010754zd811010754&amp;rcb=17&amp;aip=1&amp;dma=1&amp;dma_cps=a&amp;gcd=13l3l3l2l1l1&amp;npa=1&amp;frm=0&amp;tag_exp=0~115938466~115938469~118463262~118719171&amp;z=1279086873</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtag/js?id=G-S6XTBZ5V47&amp;cx=c&amp;gtm=4e6562</url>
              <origin>URL_RENDER</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>https://www.googletagmanager.com/gtm.js?id=GTM-W8XR2C2</url>
              <origin>URL_RENDER</origin>
              <verdict>whitelisted</verdict>
            </value>
            <value>
              <url>https://www.rtalabel.org/</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>https://jerkmate.com/cams/girl&amp;scrsrc=www.googletagmanager.com&amp;rnd=766792731.1778472456&amp;dt=Live</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://jerkmate.com/cams/girl?transaction_id=102e1a5dfe712dc6499def7fff3956:8699&amp;aff_id=324161&amp;source=&amp;xid=jm-hpf-8699-jmlcom&amp;landing_id=33548&amp;display=form2&amp;dt=Live</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <url>https://t.mbslr2.com/324161/8865/39267</url>
              <origin>URL_RENDER</origin>
              <verdict>NO_THREAT</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>0c04f5.binomlink.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>cdn.cvrtjkmt.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>data.jerkmate.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>gateway.jerkmate.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>jerkmate.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>region1.analytics.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>script.crazyegg.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>stats.g.doubleclick.net</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>twitter.com</url>
              <origin>URL_RENDER</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>www.google.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.google.de</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.googletagmanager.com</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>www.rtalabel.org</url>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>104.18.23.63</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>104.19.147.8</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>13.35.58.40</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.156</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.127.97</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.14.94</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>142.251.152.119</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>18.244.18.25</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>188.114.97.3</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>216.239.32.36</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>3.167.227.58</ip>
              <origin>URL_RENDER</origin>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d295ae6399895df59c4c3dfec19b9e1c</MD5>
              <SHA-1>32ef17705470c20b6a6f604d275a0bc523f42802</SHA-1>
              <SHA-256>e562ca7b60d841f7b14ab8b7fc08c7c0980a5e20eecc0acb28eef179fd505ce0</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>49e6253bd5d43b7121b30414945a3cf5</MD5>
              <SHA-1>71d25fa4b1219611785a8d828d500463509a84a2</SHA-1>
              <SHA-256>1ad13ebdd42b0f6c366d1171af929e55a143221acbd35f0a454726c0139ed1bd</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
          </files>
        </iocs>
        <name>f7776d8df31f526fd221f379b2481d5e</name>
        <report_id>9338d38f-3341-4dcc-8cc8-1c6652b1c4bb</report_id>
        <tags>
          <value>html</value>
          <value>phishing</value>
          <value>obfuscated</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>6f3054775e32e8c377b725615b3620332ccae51102904a5b1b883894702c3f86</id>
    <title>Analysis Report for 6f3054775e32e8c377b725615b3620332ccae51102904a5b1b883894702c3f86</title>
    <updated>2026-05-11T04:05:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01564c0f7e400110050a98</_id>
        <file_type>text/html</file_type>
        <flow_id>6a015558792fe2d217aed811</flow_id>
        <hash>6f3054775e32e8c377b725615b3620332ccae51102904a5b1b883894702c3f86</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>46694f0f719a997c2b91076cc9d4a77d</name>
        <report_id>ad74787d-9464-4735-8545-5edd547342bb</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>12ab9b231f54f0fb9babfff95b84bbf851df83390eb0863b28e621200ca57162</id>
    <title>Analysis Report for 12ab9b231f54f0fb9babfff95b84bbf851df83390eb0863b28e621200ca57162</title>
    <updated>2026-05-11T04:05:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a01561a0f7e400110050a5c</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555a2fcb905ec28c78ec</flow_id>
        <hash>12ab9b231f54f0fb9babfff95b84bbf851df83390eb0863b28e621200ca57162</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>cf265acaabe93dbf062543c81a6dfca1</name>
        <report_id>a0089441-43ab-446a-9337-b3ea335b28d8</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>3da3a014d8616ae64386710997ded2ca086920aab974404872f776e7c5fcc1ff</id>
    <title>Analysis Report for 3da3a014d8616ae64386710997ded2ca086920aab974404872f776e7c5fcc1ff</title>
    <updated>2026-05-11T04:05:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156100f7e400110050a4f</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555b86e92bda70270ecf</flow_id>
        <hash>3da3a014d8616ae64386710997ded2ca086920aab974404872f776e7c5fcc1ff</hash>
        <iocs>
          <urls>
            <value>
              <url>https://router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>https://router.parklogic.com/</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </urls>
          <domains>
            <value>
              <url>router.parklogic.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>router.parklogic.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
          </domains>
          <ips>
            <value>
              <ip>172.234.216.100</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>172.234.216.100</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d0f957cc8f24a490b8b85213216fbd08</MD5>
              <SHA-1>54e81ba0a8ae50829925395235d251f48737741f</SHA-1>
              <SHA-256>25d418f8fc61ae7cd49d6483e21cc5c0ccae3fc9d11c0e6a617b2e6465bd7df4</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>39712574ae85aee0b17c157759769e9e</name>
        <report_id>a02e890e-d080-45bc-a7c3-c4846a1519d0</report_id>
        <tags>
          <value>html</value>
          <value>base64</value>
        </tags>
        <verdict>LIKELY_MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>d8a2182a3438935fa0becdb7b91c367e9174fddb575ef10b796c2ff5081fedeb</id>
    <title>Analysis Report for d8a2182a3438935fa0becdb7b91c367e9174fddb575ef10b796c2ff5081fedeb</title>
    <updated>2026-05-11T04:05:33Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156890f7e400110050ad9</_id>
        <file_type>text/html</file_type>
        <flow_id>6a01555c2fcb905ec28c78f1</flow_id>
        <hash>d8a2182a3438935fa0becdb7b91c367e9174fddb575ef10b796c2ff5081fedeb</hash>
        <iocs>
          <urls>
            <value>
              <url>http://mostmdexpro.info/?tr_uuid=20260508-1006-053a-b7ae-04997ad4b437&amp;</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://mostmdexpro.info/?tr_uuid=20260508-1006-053a-b7ae-04997ad4b437&amp;</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://mostmdexpro.info/?tr_uuid=20260508-1006-053a-b7ae-04997ad4b437&amp;fp=-3</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>mostmdexpro.info</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>mostmdexpro.info</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>103.224.212.146</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>103.224.212.146</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <uuids>
            <value>
              <uuid>20260508-1006-053a-b7ae-04997ad4b437</uuid>
              <origin>INPUT_FILE</origin>
            </value>
            <value>
              <uuid>20260508-1006-053a-b7ae-04997ad4b437</uuid>
              <origin>MSHTA_EMULATION</origin>
            </value>
          </uuids>
        </iocs>
        <name>f51cc2dffab6ec329be7395cc6009309</name>
        <report_id>a5a37fb3-7552-4fbd-9ff1-78785b6879e0</report_id>
        <tags>
          <value>html</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
  <entry>
    <id>36635b2611a2cac5b258668712f9996a321af605d4e5e9a2cf305cf70f8d4539</id>
    <title>Analysis Report for 36635b2611a2cac5b258668712f9996a321af605d4e5e9a2cf305cf70f8d4539</title>
    <updated>2026-05-11T04:05:24Z</updated>
    <content type="application/xml">
      <details>
        <_id>6a0156190f7e400110050a5b</_id>
        <file_type>text/html</file_type>
        <flow_id>6a0155542fcb905ec28c78e0</flow_id>
        <hash>36635b2611a2cac5b258668712f9996a321af605d4e5e9a2cf305cf70f8d4539</hash>
        <iocs>
          <urls>
            <value>
              <url>http://trusttraff.com/pnzquyiwb.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;srnzd=1&amp;moeud=0&amp;haxvf=</url>
              <origin>EXTERNAL_PARSER</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>http://trusttraff.com/pnzquyiwb.cgi?20&amp;haxvf=0&amp;zkzab=0&amp;moeud=2174612323&amp;ur=1&amp;HTTP_REFERER=&amp;haxvf=</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
            <value>
              <url>https://indianpornmvs.cc/</url>
              <origin>MSHTA_EMULATION</origin>
            </value>
            <value>
              <url>https://trusttraff.com/dqjyew.cgi?29&amp;group=indian</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </urls>
          <domains>
            <value>
              <url>trusttraff.com</url>
              <origin>EXTERNAL_PARSER</origin>
            </value>
            <value>
              <url>indianpornmvs.cc</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <url>trusttraff.com</url>
              <origin>MSHTA_EMULATION</origin>
              <verdict>MALICIOUS</verdict>
            </value>
          </domains>
          <ips>
            <value>
              <ip>109.206.161.43</ip>
              <origin>DOMAIN_RESOLVE</origin>
              <verdict>UNKNOWN</verdict>
            </value>
            <value>
              <ip>109.206.161.43</ip>
              <origin>MSHTA_EMULATION</origin>
              <verdict>UNKNOWN</verdict>
            </value>
          </ips>
          <files>
            <value>
              <MD5>d350b840812c669ffbbf16b23ed14e18</MD5>
              <SHA-1>fa99bc9119e0e2df6f2ee9207b9e8157904dd44c</SHA-1>
              <SHA-256>ceec0afaa675304cd15587f2a97a1e3528ad7cc53d3baedd13954ccdadcf97b7</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>9a5810bfec1a9875d5035e1f6978d370</MD5>
              <SHA-1>37ba4a8d97e2fcf80c7f59f067fda8db514938ad</SHA-1>
              <SHA-256>cfb4c213dd3cb45459e0721ee754467909d9e8213b1de4f9fdf07230249e0eb3</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/x-cgi</file_type>
              <verdict>NO_THREAT</verdict>
            </value>
            <value>
              <MD5>5d5be8be3f197f7aa4d8dafac21a146a</MD5>
              <SHA-1>e0731d2fe2f03d48abb3f69dfe0d238f1c0bd3be</SHA-1>
              <SHA-256>ec724a9e515e7f604df7e23686762776f8301288109f09c06e8e7ef15cd11434</SHA-256>
              <origin>DOWNLOADED_FILE</origin>
              <file_type>text/html</file_type>
              <verdict>UNKNOWN</verdict>
            </value>
          </files>
        </iocs>
        <name>8d289d85c0a2f555550b15d9e8810910</name>
        <report_id>f0a89faa-f2b1-4a08-8035-23912f9a991c</report_id>
        <tags>
          <value>html</value>
          <value>txt</value>
          <value>phishing</value>
        </tags>
        <verdict>MALICIOUS</verdict>
      </details>
    </content>
  </entry>
</feed>
