=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

http://titleportals.com

Status: finished
Submission Time: 2022-07-01 02:33:47 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    655387
  • API (Web) ID:
    1022892
  • Analysis Started:
    2022-07-01 02:33:48 +02:00
  • Analysis Finished:
    2022-07-01 02:39:59 +02:00
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
56/100

malicious

IPs

IP Country Detection
52.70.210.174
United States
204.79.197.200
United States
142.251.36.205
United States
Click to see the 17 hidden entries
160.153.136.3
United States
52.179.225.139
United States
206.19.49.24
United States
142.251.37.8
United States
52.54.116.217
United States
142.251.37.2
United States
172.217.16.163
United States
104.198.14.52
United States
142.251.36.238
United States
142.251.36.232
United States
142.251.36.196
United States
185.103.196.211
Turkey
18.205.143.103
United States
239.255.255.250
Reserved
52.29.111.77
United States
34.98.122.12
United States
108.177.15.155
United States

Domains

Name IP Detection
gstaticadssl.l.google.com
142.251.36.227
location.fntg.com
52.179.225.139
ctic.com
52.179.225.139
Click to see the 38 hidden entries
accounts.google.com
142.251.36.205
stats.l.doubleclick.net
108.177.15.155
dual-a-0001.a-msedge.net
204.79.197.200
a4d6c1c8368a911ea98860aeb4e6dc37-182063218.us-east-1.elb.amazonaws.com
52.70.210.174
www-googletagmanager.l.google.com
142.251.37.8
titleportals.com
160.153.136.3
isteam.wsimg.com
52.29.111.77
aksiyonteknik.com.tr
185.103.196.211
app.steezy.co
34.98.122.12
apt-lb.techtarget.com
206.19.49.24
prod-east-stats-tap-alb-627711272.us-east-1.elb.amazonaws.com
18.205.143.103
googleads.g.doubleclick.net
142.251.37.2
ssl-google-analytics.l.google.com
142.251.36.232
www.google.com
142.251.36.196
clients.l.google.com
142.251.36.238
www.google.ch
172.217.16.163
prod-east-pipedream-alb-988701200.us-east-1.elb.amazonaws.com
52.54.116.217
learn.zix.com
104.198.14.52
img1.wsimg.com
0.0.0.0
fast.wistia.com
0.0.0.0
dev.virtualearth.net
0.0.0.0
img6.wsimg.com
0.0.0.0
stats.g.doubleclick.net
0.0.0.0
clients2.google.com
0.0.0.0
code.jquery.com
0.0.0.0
t1.ssl.ak.dynamic.tiles.virtualearth.net
0.0.0.0
t0.ssl.ak.dynamic.tiles.virtualearth.net
0.0.0.0
fg8vvsvnieiv3ej16jby.litix.io
0.0.0.0
distillery.wistia.com
0.0.0.0
location.ctic.com
0.0.0.0
use.typekit.net
0.0.0.0
events.api.secureserver.net
0.0.0.0
embed-ssl.wistia.com
0.0.0.0
p.typekit.net
0.0.0.0
pipedream.wistia.com
0.0.0.0
apt.techtarget.com
0.0.0.0
trk.techtarget.com
0.0.0.0
fast.wistia.net
0.0.0.0

URLs

Name Detection
https://aksiyonteknik.com.tr/js/OFFICE/home/2018.png
https://aksiyonteknik.com.tr/js/OFFICE/center/?sslchannel=true&sessionid=OTOYJovaMRXQj1L2uNuRQfgeC1GOLZz4QA0QhasDAeI9xxxEjfa3EOy4z7B9Y4hBUG3ZXdhzXZ9gsS7O
https://aksiyonteknik.com.tr/js/OFFICE/home/
Click to see the 97 hidden entries
https://location.ctic.com/ScriptResource.axd?d=v_I7_Ww9YDbzP79DTo1lX2_HAoS2zOixeZn2htLcCw3C81xWgdnzK4kgXIT3m821wFCw9TiEGHtdPnFVMrwptnqB0smdYpFykBNvTA5MH-pT8Drz2xdrC199t0dVn3TPApEDcK-aCAyIzS-BxJDeoDD9hnx4ZatjKQgC3ikEyLg1&t=ffffffffefa1ed2f
https://location.ctic.com/images/Logoicons/FNTGIcon.png
https://learn.zix.com/_next/static/chunks/framework-e70c6273bfe3f237.js
https://img1.wsimg.com
https://www.google.com/pagead/1p-user-list/1007604421/?random=1656668116399&cv=9&fst=1656666000000&num=1&bg=ffffff&guid=ON&eid=376635470&u_h=1024&u_w=1280&u_ah=984&u_aw=1280&u_cd=24&u_his=1&u_tz=-420&u_java=false&u_nplug=1&u_nmime=2&gtm=2wg6t0&sendb=1&frm=0&url=https%3A%2F%2Flearn.zix.com%2F&tiba=Learn%20More%20%7C%20Zix&async=1&fmt=3&is_vtc=1&random=2672146430&resp=GooglemKTybQhCsO&rmt_tld=0&ipr=y
https://www.google.com
https://learn.zix.com/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2F4tkc0oryl0w0%2FQr1IOKWvPlTCJkalBnUzb%2Fa84389ad8c6db74618662e7574cf9473%2Fencrypt.png&w=1920&q=75
https://ctic.com/services.aspx#ctl00_menuMain_SkipLink
https://location.ctic.com/images/ServiceIcons/RecordingSpecialProjectsIcon.png
https://isteam.wsimg.com
https://titleportals.com/?__WB_REVISION__=1656632790505
https://location.ctic.com/images/Commercial.png
https://location.ctic.com/images/Logoicons/fnticicon.png
https://learn.zix.com/_next/image?url=%2Fimg%2Fzix_ot_logo.png&w=384&q=75
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
https://location.ctic.com/ScriptResource.axd?d=r5UL-hsNriOxS7UV4wWMiBtmGXBwascwHiSyGwG-7jbgEjOTvs8EXVPukm4d-lG8eKQ5YGhrdEsoLgnt6zwsKsQ_e0mknmbRYu0c2527eJl8AuS9fvq8fnH_MvK2i-WJD5-irjp42UR6PFmgtQEaI9J7ShSnibhIII7l2irW_ao1&t=ffffffffefa1ed2f
https://titleportals.com/favicon.ico
https://location.ctic.com/Content/bootstrap.min.css
https://ctic.com/WebResource.axd?d=IBJQaD7fveb55KcR4-fQDfTsfrgwBmMVeipt17IDyiQmY6SbNyu7xCosHvVir5cU3nSBvMTT6Jha3TPZ2M01cq5q-Zs1&t=637811740157966200
https://img1.wsimg.com/gfonts/s/montserrat/v24/JTUSjIg1_i6t8kCHKm459W1hyzbi.woff2)
https://location.ctic.com/images/placehlder.png
https://dns.google
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://location.ctic.com/
https://learn.zix.com/_ipx/w_3840,q_75/https%3A%2F%2Fimages.ctfassets.net%2F4tkc0oryl0w0%2FQr1IOKWvPlTCJkalBnUzb%2Fa84389ad8c6db74618662e7574cf9473%2Fencrypt.png?url=https%3A%2F%2Fimages.ctfassets.net%2F4tkc0oryl0w0%2FQr1IOKWvPlTCJkalBnUzb%2Fa84389ad8c6db74618662e7574cf9473%2Fencrypt.png&w=3840&q=75
https://img1.wsimg.com/gfonts/s/archivoblack/v17/HTxqL289NzCGg4MzN6KJ7eW6CYyF_g.woff2
https://ctic.com/WebResource.axd?d=QHOpV9n2mmkWhHvrWZpfdgSG4brmNdekVq1V2eiTXljnCT9ZMz_VQ3SJiT_yP_p2C5IjBmFfiS3Hu8ZNCjUwsCWsBRY1&t=637811740157966200
https://location.ctic.com/images/Logoicons/clticicon.png
https://learn.zix.com/_next/static/JUhEJajYhbX_sm8b4qvqE/_buildManifest.js
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://ctic.com/404.aspx?aspxerrorpath=/WebResource.axd
https://payments.google.com/payments/v4/js/integrator.js
https://ctic.com/services.aspx
https://ctic.com/Stylesheets/stylesheet.css
https://ctic.com/Images/header.png
https://ctic.com/images/FNFLogo.png
https://titleportals.com/manifest.webmanifest
https://location.ctic.com/ScriptResource.axd?d=U8OMYmPzb2LbIsKauUCqxkSNWqJn5xVY3b5X4pyEdLSY-7J0Bx8WkVkX2bVFDtnNnOj2ZnuwKjJxY9Qex5nruLENBY1aOVlDzDlemXLGsE1DQZb0kgRrKn1wxNdESRcWdVyQcUaP_ax1uyUDtiJlB93vk1sVAsVKaRxoORUehdU1&t=ffffffffefa1ed2f
https://location.ctic.com/WebResource.axd?d=jATR2aT4MP7vIvfz8UagJKkiwdWFUrwMafXE7LMaJNGoTglPSi0_VyioPRJ_E6rieJtei38XC55ILIgZP84quJoMvucMYd71Gq6xV6YcSH517JXcTQrNAAzIGoOA5NbgJpaynTxgn2P0gq1On2PsOA2&t=637387657600000000
https://titleportals.com/sw.js
https://location.ctic.com/WebResource.axd?d=VdPoLqp1pEU6N0-IfFplZKyznpp8R-oKlM6P0m_n0dRdELswoZPmL5iYOcnZas4LTiTAiwSD5KRary5uUle6KSe9yIGXLK2n2Ah9MpWCJVm7EFRWChA48hFuri4pLW6s6KdwvM6O2irOEXFKC0Nqkg2&t=637387657600000000
https://location.ctic.com/images/Logoicons/TTICicon.png
https://www.google.com/images/x2.gif
https://apt.techtarget.com/activity/activity.gif?activityTypeId=31&cid=22110178&version=2.1.1&ref=https%3A%2F%2Flearn.zix.com%2F&r=1656668116332
https://ctic.com/images/homePageImage.jpg
https://apt.techtarget.com/activity/activity.gif?activityTypeId=31&cid=22110178&version=2.1.1&ref=https%3A%2F%2Flearn.zix.com%2F&r=1656668116333
https://ctic.com/Default.aspx
https://location.ctic.com/ScriptResource.axd?d=fgH2o6PXbcTnUV6W8ibPa1UTg5SpqtP6BID4MUADpeOgOUH0AFf-BUgtmWkycZL20EiuRR1rJ__-cP-0kg08UXQPP0SCZK-CrwD3dy7uuJSkDPJChrz8kmqg5J-7KumM0&t=ffffffffefa1ed2f
https://location.ctic.com/images/ServiceIcons/ClosingEscrowIcon.png
https://location.ctic.com/ScriptResource.axd?d=kLB9_fq97ui9imtAf9uBuF1NpVRG1UQQVuRIV-a3kOc-w2fE7KpvxbpOBSq6c_m8agsMDmWyaPfkDVqDvhNZn7p_IVYKBucXBcn5t3jsnW7QHRj0XcM8oW39SttS3UEOyXSSXDl0qSyYCS0KoUyI8w2&t=ffffffffefa1ed2f
https://location.ctic.com/ScriptResource.axd?d=QZl-WVTSCJn1xAKqTrLix8EyLA5WfLXycD4EDaxR-feekCFUL36YCQ9BG3LeTyocq9jc5LFpobfAqDWUPhTGlrtu43J8bVOjOXmsJ4IAvznRHaNPTCZWB2RcoDVdLfg5V5ojI-RxabX_cOuB0ErE9kmn4tVoRm9fpsfCT9a1h581&t=ffffffffefa1ed2f
https://www.google.com/images/dot2.gif
https://pipedream.wistia.com/mput?topic=metrics
https://ctic.com/default.aspx
https://location.ctic.com/images/NearMeIcon.png
https://location.ctic.com/WebResource.axd?d=f1eAwWpm15Num4LTAbKSBK_zV3-4eqoVprQ24hS1BcPFjzvRA402RTA_sA0Sym8X5vIunZXu1RzvPKFStfoYUxmRN20AtEOuSKT9Lu0TeWlglxvG232gUeVBZWT_4VpkTbHHV2WaLRkJWg5_hRLgdGHpMo5F3gjn6xWAxNvmW2A1&t=637387657600000000
https://ctic.com/services.aspx2
https://learn.zix.com/_next/static/JUhEJajYhbX_sm8b4qvqE/_ssgManifest.js
https://location.ctic.com/images/Logoicons/lticicon.png
https://aksiyonteknik.com.tr/js/OFFICE/home
https://location.ctic.com/scripts/balupton-jquery-scrollto-a1eb8a5/lib/jquery-scrollto.js
https://stats.g.doubleclick.net/j/collect?t=dc&aip=1&_r=3&v=1&_v=j96&tid=UA-91357340-1&cid=1187505010.1656668116&jid=1949436357&gjid=935377435&_gid=1257152793.1656668117&_u=aCDAgEAjQAAAAE~&z=28292997
https://img1.wsimg.com/poly/v3/polyfill.min.js?rum=0&unknown=polyfill&flags=gated&features=Intl.~loc
https://location.ctic.com/ScriptResource.axd?d=pL5wgiwL1GpmyqMwhkDjF4c_RNDd2bVNxvn19KzsTeyUAaLvhqNc_FYdbuGEx47nAp8QjDMTQ-BBmQGadO_K05Ih6O6n_K0a16s5IUG3mH5Signt1J8YewAKEK7mOnb8C4fWWvEML5PdFJu9sQh7Jg2&t=ffffffffefa1ed2f
https://img1.wsimg.com/gfonts/s/archivoblack/v17/HTxqL289NzCGg4MzN6KJ7eW6CYKF_i7y.woff2)
https://learn.zix.com/
https://fg8vvsvnieiv3ej16jby.litix.io/
https://www.google.com/
https://img1.wsimg.com/gfonts/s/montserrat/v24/JTUSjIg1_i6t8kCHKm459Wdhyzbi.woff2)
https://aksiyonteknik.com.tr/js/OFFICE/center/bgblur.png
https://location.ctic.com/ScriptResource.axd?d=dnHi0nMgDDe1Bo6v1KTdpIvDS8CB0DZR5Mt5396HusV8op_xAyYGoNCkXHpY7CA_gQJsuzQAB-t9eW48qt4TibDzZwVNCvHJNc9VJSDYbIAfouilLdFvNVF2m43sDq2kxs-rOZXyaGgCmCxdRzUH5g2&t=ffffffffefa1ed2f
https://aksiyonteknik.com.tr/js/OFFICE/FUNC/o365.png
https://titleportals.com/2
https://ctic.com/images/OfficeButtonCT.png
https://img1.wsimg.com/gfonts/s/montserrat/v24/JTUSjIg1_i6t8kCHKm459Wlhyw.woff2)
https://app.steezy.co/favicon.ico
https://www.google.ch/pagead/1p-user-list/1007604421/?random=1656668116399&cv=9&fst=1656666000000&num=1&bg=ffffff&guid=ON&eid=376635470&u_h=1024&u_w=1280&u_ah=984&u_aw=1280&u_cd=24&u_his=1&u_tz=-420&u_java=false&u_nplug=1&u_nmime=2&gtm=2wg6t0&sendb=1&frm=0&url=https%3A%2F%2Flearn.zix.com%2F&tiba=Learn%20More%20%7C%20Zix&async=1&fmt=3&is_vtc=1&random=2672146430&resp=GooglemKTybQhCsO&rmt_tld=1&ipr=y
https://www.google.com/images/cleardot.gif
https://location.ctic.com/images/CTICLogo.png
https://play.google.com
https://location.ctic.com/images/Residential.png
http://titleportals.com/
https://www.google.ch
https://location.ctic.com/WebResource.axd?d=ki1n1Eahlh7Hg67y-z8gJqJBGNbaGaMMwlnKRV_n3YJ7ndOsyYsROLoAAXZXGZOjUu-YUfxZ6Cv4C3Slc-c6ObBZFvzplc9YRtGN--8JoSUGvkgBOJun1fmZpiNYFcb68Z3aTInS8Ddmwif_HzT-3Q2&t=637387657600000000
https://img1.wsimg.com/gfonts/s/montserrat/v24/JTUSjIg1_i6t8kCHKm459WRhyzbi.woff2)
https://location.ctic.com/ScriptResource.axd?d=uHIkleVeDJf4xS50Krz-yNllrZsOapvNsRC1m7hXLgsBqrfe60OG6eBkCuxfRwBWaGzLwfYPRFWUgM8CWYT0OFaOUBc1XtK32vNXhrc10ZEBRJWqS67AlkZ7w00d1qFLwD5WO0gXuf-U5QT3Mx2PyOBSREBBW48BM6eUxLCEcRE1&t=49337fe8
https://titleportals.com/
https://location.ctic.com/scripts/officelocatorV8b.js
https://stats.g.doubleclick.net
https://location.ctic.com/ScriptResource.axd?d=CJzfp47zwbZkqPEVws6eAG3zvDzIBYIhQrrxQerK8JqsHpw3gxxY5Nv3TJnM-HI3nKx6MEtgsMPJIcTxv-2448uel2-5_KMFl43bVIYS7UYGyJ0uiuUIUWLSEzmpwhDZMKyq4EoJb4E4uPJT572-Ew2&t=ffffffffefa1ed2f
https://ctic.com/services.aspx
https://learn.zix.com/_next/image?url=%2Fimg%2Fzix_ot_logo.png&w=256&q=75
https://location.ctic.com/WebResource.axd?d=fqCPrKvoPJVc1rV7IcjHjTC1Euk1JpPxJtQUTU07H9YduyOTevUSrbVNFSF5A3XbJOUZWzkIXTyXGtN6Q1GmH8wwbyhXMjDg7re6VxyDGsMQzqJstnQWUk39kaIqM5rgudD8WNsRtF_3gjJwRigvbg2&t=637387657600000000
https://titleportals.com/sw.jsaD
https://img1.wsimg.com/gfonts/s/montserrat/v24/JTUSjIg1_i6t8kCHKm459Wlhyw.woff2
https://location.ctic.com/images/ServiceIcons/UCCPlusIcon.png
https://img1.wsimg.com/gfonts/s/montserrat/v24/JTUSjIg1_i6t8kCHKm459WZhyzbi.woff2)

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\0e29182c-003a-4ace-ab5e-4f3ce958f822.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\48b73762-56a3-4cd2-8136-2a8213c5f585.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\6260c43a-ec9d-4c54-8483-01c608068673.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\79a31f17-11e6-4b0b-b4f3-7b4a5b382759.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\993dd78d-87bc-4f03-bd1d-fd088479138a.tmp
SysEx File -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\1010df0a-3bc4-4df1-9aa2-71d78d9e86e0.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\1268924f-714d-4cca-a83b-dabbee905be4.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\2fcc885a-d998-453c-b75f-77a626e0828b.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3366642a-b208-44f4-9666-8a0bc74c8886.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3cd09691-8017-4dd6-ab6b-0ceba7722517.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3dfd17ad-226f-4ce3-9a59-a806c97a13ef.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5fcad953-b64e-4f9e-a365-7f5c02db0e9d.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9e62b013-d25c-4aee-8911-87c356304209.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\f7750fe543b15730b11be8c257b6a20c5057dfeb\38f03569-7f2f-4f21-b256-9c244d98e639\6cedbd8ba1958011_0
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\f7750fe543b15730b11be8c257b6a20c5057dfeb\38f03569-7f2f-4f21-b256-9c244d98e639\index
ISO-8859 text, with no line terminators, with escape sequences
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\f7750fe543b15730b11be8c257b6a20c5057dfeb\38f03569-7f2f-4f21-b256-9c244d98e639\index-dir\temp-index
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\f7750fe543b15730b11be8c257b6a20c5057dfeb\38f03569-7f2f-4f21-b256-9c244d98e639\index-dir\the-real-index (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\f7750fe543b15730b11be8c257b6a20c5057dfeb\index.txt (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\f7750fe543b15730b11be8c257b6a20c5057dfeb\index.txt.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\000001.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\MANIFEST-000001
PGP\011Secret Key -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\2cc80dabc69f58b6_0
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\2cc80dabc69f58b6_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index
ISO-8859 text, with no line terminators, with escape sequences
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\temp-index
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\the-real-index (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\db6b0f7a-620e-47df-adf7-369320b3de00.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\8f6252b1-483e-4433-a007-3c8bb0b23fed.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a17ddf41-6e24-49f0-a8d3-eed64fe28483.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\bf40c10f-c046-4c3b-afa6-c3dca14037b6.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\c800bb10-0f12-4e1c-b44c-e53f68d99c29.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d0aab5b8-33ca-4db0-9a84-b48d69066dc0.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\fc3b3394-aeb0-4a78-9354-4cdd88aebbbc.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\a49f9945-5bbc-4bf3-ad51-c4893b54d231.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\d48bd42f-4b8a-429e-be69-e85284b07e7e.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\ecf891df-bc5b-4731-99ba-8eb9e5fb4567.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\f3bb094e-1491-414e-8b87-cacc8b3a67bf.tmp
data
#
C:\Users\user\AppData\Local\Temp\2d9f91ee-06c2-4623-aaf9-531792f33b0f.tmp
Google Chrome extension, version 3
#
C:\Users\user\AppData\Local\Temp\c69add69-d268-46f6-be66-b764a53639c1.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\2d9f91ee-06c2-4623-aaf9-531792f33b0f.tmp
Google Chrome extension, version 3
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir3808_876821841\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
#