you should've told it to analyze it more deeply, analyze it's process builder with a sandbox result, and analyze who owned the domain.
Also no discord webhook, nothing pointing to an info stealer either than what could be the ProcessBuilder at most
I analyzed it in a sandbox, points to a real microsoft owned domain (nexusrules.officeapps.live.com)
Also ProcessBuilder is pretty safe, no files dropped, I won't go in depth but I am 80% sure this is safe
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.