top title background image
flash

Invoice#0036473 .xlsx

Status: finished
Submission Time: 2022-07-01 16:20:22 +02:00
Malicious
Phishing
Exploiter
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    655755
  • API (Web) ID:
    1023260
  • Analysis Started:
    2022-07-01 16:20:25 +02:00
  • Analysis Finished:
    2022-07-01 16:37:00 +02:00
  • MD5:
    c93e6dcf32928e1da7346b6ca3a1dc85
  • SHA1:
    b90d66412b4d6669a175fd30e32bbe44428bd245
  • SHA256:
    3ffe69c9e2e2f8a350f7d2ff6e64acf8cffbf390489807b81cf8e4eec87d4047
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 76
System: Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
malicious
Score: 76
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Run Condition: Potential for more IOCs and behavior

Third Party Analysis Engines

malicious
Score: 18/88
malicious
malicious

IPs

IP Country Detection
69.49.244.155
United States
142.250.185.78
United States
104.18.10.207
United States
Click to see the 8 hidden entries
142.251.36.205
United States
142.251.36.227
United States
104.18.11.207
United States
239.255.255.250
Reserved
104.18.29.243
United States
172.64.150.12
United States
172.217.16.161
United States
104.17.25.14
United States

Domains

Name IP Detection
eyecandylashcompany.com
69.49.244.155
gstaticadssl.l.google.com
142.251.36.227
stackpath.bootstrapcdn.com
104.18.11.207
Click to see the 12 hidden entries
accounts.google.com
142.251.36.205
cdnjs.cloudflare.com
104.17.25.14
maxcdn.bootstrapcdn.com
104.18.10.207
clients.l.google.com
142.250.185.78
cdn.iconscout.com
104.18.29.243
cdn.pixabay.com
172.64.150.12
googlehosted.l.googleusercontent.com
172.217.16.161
clients2.google.com
0.0.0.0
ka-f.fontawesome.com
0.0.0.0
code.jquery.com
0.0.0.0
kit.fontawesome.com
0.0.0.0
lh3.googleusercontent.com
0.0.0.0

URLs

Name Detection
https://eyecandylashcompany.com/payment/frontend_paper_lantern/index.html
https://eyecandylashcompany.com/payment/frontend_paper_lantern/images/gmail.png
https://eyecandylashcompany.com/payment/frontend_paper_lantern/images/office3651.png
Click to see the 39 hidden entries
https://eyecandylashcompany.com/payment/frontend_paper_lantern/css/hover.css
https://eyecandylashcompany.com/payment/frontend_paper_lantern/index.html2
https://eyecandylashcompany.com/payment/frontend_paper_lantern/index.html
https://www.google.com
https://clients2.google.com/service/update2/crx
https://www.google.com/images/dot2.gif
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
https://accounts.google.com
https://cdn.iconscout.com/icon/free/png-512/microsoft-sharepoint-3-599372.png
https://clients2.googleusercontent.com
https://apis.google.com
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
https://kit.fontawesome.com/585b051251.js
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
https://www.google.com/
https://www-googleapis-staging.sandbox.google.com
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=84.0.4147.135&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://clients2.google.com
https://consent.google.com
https://payments.google.com/payments/v4/js/integrator.js
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://www.google.com/intl/en-US/chrome/blank.html
https://ogs.google.com
https://cdn.pixabay.com/photo/2018/03/10/12/00/paper-3213924_1280.jpg
https://www.google.com/images/cleardot.gif
https://code.jquery.com/jquery-3.2.1.slim.min.js
http://www.gmail.com
https://code.jquery.com/jquery-3.1.1.min.js
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
https://lh3.googleusercontent.com/proxy/bATQDWurvLlY3z2KTwUlb1gMxwLZoCk7CvqzrLqN1JioLU4nXkElVj-rMrvNZjuUXh3c1WhNOGX5_Cg18Wmltm3vvna-uZDqOkUISXU4XOYsUyt-4962tq2u0WiI358gef4ewWcVp0PA6YiTnICV2Cg7wLzdb0DlXw
https://adservice.google.com
https://lh3.googleusercontent.com
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
https://lh3.googleusercontent.com/proxy/bATQDWurvLlY3z2KTwUlb1gMxwLZoCk7CvqzrLqN1JioLU4nXkElVj-rMrvN
https://sandbox.google.com/payments/v4/js/integrator.js
https://www.google.com/images/x2.gif
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
https://code.jquery.com/jquery-3.3.1.js
https://accounts.google.com/MergeSession

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZAE7RW1P\index[1].htm
HTML document, UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\5b406153-e928-4185-97db-235773365636.tmp
Google Chrome extension, version 3
#
C:\Users\user\AppData\Local\Temp\5b406153-e928-4185-97db-235773365636.tmp
Google Chrome extension, version 3
#
C:\Users\user\AppData\Local\Temp\55b2e026-228a-40a5-8bfd-0bdbd2ce629e.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\24CF.tmp
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8B3464B5.png
PNG image data, 1140 x 1281, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\b4fa85b6-444c-425f-a911-93b415a035a5.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\ab0bf9f2-309c-4bce-bd9c-e4ac34748242.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ef55ff91-ca42-48c2-8615-538469a3af8b.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e0720955-3d9c-4af0-bd4a-8510afe9a7c7.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000008.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d3ab0dfa-11f4-433d-9005-94d12dd095d7.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\scoped_dir1212_480453973\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\1f2324ab-adab-45fc-a3ab-9367bc32878e.tmp
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Code Cache\js\index
ISO-8859 text, with no line terminators, with escape sequences
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\61c8e5c5-f16b-4c38-9921-56f055e52cd4.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\262f10db-b419-4f57-98ae-ce9fa3a50196.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\2277d4eb-77ab-4279-9966-ee1e49db086b.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Code Cache\js\index-dir\temp-index
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0eb7fe35-30bc-48b6-8257-0982ee1a4890.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0a6c3045-da8d-47a3-8153-9afce256711f.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\055edf99-becc-45c4-be14-4dc525a5432e.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\8658dadd-071f-4fed-a194-d19faaa6b86c.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\51b2f774-2252-48f6-923d-fd7fac7b6110.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\51a627a5-22fb-4a4b-9790-73b801998960.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\3a1d6b1f-342a-4802-8123-4b45d21f9eab.tmp
PGP symmetric key encrypted data - Plaintext or unencrypted data salted -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\31067a2a-5ce7-4ec9-98cd-89c86b9b1309.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\26d44847-f29b-44b4-83c5-a4e6cc440bf9.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\24bfe171-efe7-4072-8cd7-5dd0ecaef267.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\MANIFEST-000001
PGP\011Secret Key -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\c30600a5-0365-44d0-9fe1-ffaca26edf6a.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ae88f5b9-6052-479d-9cbb-f68142e85df6.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\dbf751fd-7169-44d5-bc18-7d3260ccc2c2.tmp
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\MANIFEST-000001
PGP\011Secret Key -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000001.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\MANIFEST-000001
PGP\011Secret Key -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\000001.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\0f9da6dd-02d1-4716-bb65-0ecc794f8349.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\000001.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\index
FoxPro FPT, blocks size 512, next free block index 3284796353, field type 0
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_3
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_2
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_0
FoxPro FPT, blocks size 512, next free block index 3284796609, field type 0
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Code Cache\wasm\index-dir\the-real-index (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Code Cache\wasm\index-dir\temp-index
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Code Cache\wasm\index
ISO-8859 text, with no line terminators, with escape sequences
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Code Cache\js\index-dir\the-real-index (copy)
data
#