Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 20:25:55 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 20:25:55 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 20:25:55 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 20:25:55 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 20:25:55 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 100
|
Web Open Font Format, TrueType, length 23320, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 101
|
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], progressive, precision 8, 3000x1403, components
3
|
dropped
|
||
Chrome Cache Entry: 102
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 103
|
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 104
|
ASCII text, with very long lines (4757)
|
downloaded
|
||
Chrome Cache Entry: 105
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 106
|
ASCII text, with very long lines (65447)
|
downloaded
|
||
Chrome Cache Entry: 107
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 108
|
ASCII text, with very long lines (65366)
|
downloaded
|
||
Chrome Cache Entry: 109
|
Unicode text, UTF-8 text, with very long lines (50806)
|
downloaded
|
||
Chrome Cache Entry: 110
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 111
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 112
|
MS Windows icon resource - 1 icon, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
|
dropped
|
||
Chrome Cache Entry: 113
|
ASCII text, with very long lines (597)
|
downloaded
|
||
Chrome Cache Entry: 114
|
ASCII text, with very long lines (14965)
|
downloaded
|
||
Chrome Cache Entry: 115
|
ASCII text, with very long lines (13326)
|
downloaded
|
||
Chrome Cache Entry: 116
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 117
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 118
|
Unicode text, UTF-8 (with BOM) text
|
downloaded
|
||
Chrome Cache Entry: 119
|
MS Windows icon resource - 1 icon, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 120
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 121
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 122
|
Web Open Font Format (Version 2), TrueType, length 66624, version 4.262
|
downloaded
|
||
Chrome Cache Entry: 123
|
ASCII text, with very long lines (9373)
|
downloaded
|
||
Chrome Cache Entry: 124
|
ASCII text, with very long lines (1572)
|
downloaded
|
||
Chrome Cache Entry: 125
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 126
|
Unicode text, UTF-8 text, with very long lines (50806)
|
downloaded
|
||
Chrome Cache Entry: 127
|
ASCII text, with very long lines (28941)
|
downloaded
|
||
Chrome Cache Entry: 128
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 129
|
ASCII text, with very long lines (13326)
|
downloaded
|
||
Chrome Cache Entry: 130
|
ASCII text, with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 131
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 132
|
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], progressive, precision 8, 3000x1403, components
3
|
downloaded
|
||
Chrome Cache Entry: 133
|
Unicode text, UTF-8 text, with very long lines (64131)
|
downloaded
|
||
Chrome Cache Entry: 134
|
ASCII text, with very long lines (27303)
|
downloaded
|
||
Chrome Cache Entry: 99
|
ASCII text, with very long lines (65447)
|
downloaded
|
There are 33 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2324,i,16482439069174654375,2879168494582818639,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=2004,i,13570577987484290184,1584069516612223492,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://link.cornellfreespeech.com/campaigns/xd182pswwxb7f/track-url/rt9295q1rf292/ffe1280e2a4f37968a98d9870ae24b3a9e13eb4b%5D_"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://link.cornellfreespeech.com/campaigns/xd182pswwxb7f/track-url/rt9295q1rf292/ffe1280e2a4f37968a98d9870ae24b3a9e13eb4b%5D_
|
|||
https://github.com/lipis/bootstrap-social
|
unknown
|
||
http://fontawesome.io
|
unknown
|
||
https://link.cornellfreespeech.com/articles
|
|||
https://liberationtekcampaign.com/assets/fonts/glyphicons-halflings-regular.woff
|
172.67.190.26
|
||
https://github.com/google/material-design-icons
|
unknown
|
||
https://liberationtekcampaign.com/assets/js/cookie.js?av=206b49bd
|
172.67.190.26
|
||
https://liberationtekcampaign.com/frontend/assets/css/style.css?av=206b49bd
|
172.67.190.26
|
||
https://link.cornellfreespeech.com/frontend/assets/cache/ext-content-builder-innova-studio/contentbuilder/assets/minimalist-blocks/content.css?av=206b49bd
|
97.64.76.25
|
||
https://twitter.com/benjsperry
|
unknown
|
||
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRmgZjcGOO3sLEGIjAfCeYdHWOT-RbG8nwW9YhFLpbUJGtLl65EIYsSKTpXqB8zgCtFpLOPewhZR-BBoUUyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
|
142.250.64.196
|
||
https://github.com/select2/select2/blob/master/LICENSE.md
|
unknown
|
||
https://liberationtekcampaign.com/assets/css/skin-blue.css?av=206b49bd
|
172.67.190.26
|
||
http://www.json.org/json2.js
|
unknown
|
||
https://twitter.com/ionicframework
|
unknown
|
||
https://liberationtekcampaign.com/frontend/assets/js/app.js?av=206b49bd
|
172.67.190.26
|
||
https://liberationtekcampaign.com/assets/js/app.js?av=206b49bd
|
172.67.190.26
|
||
https://link.cornellfreespeech.com/frontend/assets/cache/ext-content-builder-innova-studio/contentbuilder/assets/ionicons/css/ionicons.min.css
|
97.64.76.25
|
||
https://liberationtekcampaign.com/assets/js/select2/js/select2.full.min.js?av=206b49bd
|
172.67.190.26
|
||
https://liberationtekcampaign.com/frontend/assets/cache/f88c644d/jquery.min.js
|
172.67.190.26
|
||
https://liberationtekcampaign.com/assets/css/bootstrap.min.css?av=206b49bd
|
172.67.190.26
|
||
http://getbootstrap.com)
|
unknown
|
||
https://liberationtekcampaign.com/customer/assets/js/app.js?av=206b49bd
|
172.67.190.26
|
||
https://liberationtekcampaign.com/assets/js/knockout.min.js?av=206b49bd
|
172.67.190.26
|
||
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
|
142.250.64.196
|
||
https://link.cornellfreespeech.com/
|
97.64.76.25
|
||
https://liberationtekcampaign.com/customer/assets/css/style.css?av=206b49bd
|
172.67.190.26
|
||
http://creativecommons.org/licenses/by/4.0/
|
unknown
|
||
https://link.cornellfreespeech.com/frontend/assets/files/resized/5000x5000/a0f3e19a-f3b9131o-hero-eagle3.jpg
|
97.64.76.25
|
||
http://almsaeedstudio.com
|
unknown
|
||
https://link.cornellfreespeech.com/frontend/assets/cache/ext-content-builder-innova-studio/static/custom-styles.css?av=206b49bd
|
97.64.76.25
|
||
https://liberationtekcampaign.com/assets/js/bootstrap.min.js?av=206b49bd
|
172.67.190.26
|
||
https://liberationtekcampaign.com/assets/css/ionicons/css/ionicons.min.css?av=206b49bd
|
172.67.190.26
|
||
https://www.mailwizz.com/
|
unknown
|
||
https://www.mailwizz.com/license/
|
unknown
|
||
https://link.cornellfreespeech.com/campaigns/xd182pswwxb7f/track-url/rt9295q1rf292/ffe1280e2a4f37968a98d9870ae24b3a9e13eb4b%5D_
|
|||
https://www.mailwizz.com)
|
unknown
|
||
https://liberationtekcampaign.com/assets/css/adminlte.css?av=206b49bd
|
172.67.190.26
|
||
https://www.google.com/async/newtab_promos
|
142.250.64.196
|
||
http://knockoutjs.com/
|
unknown
|
||
https://liberationtekcampaign.com/assets/css/font-awesome/css/font-awesome.min.css?av=206b49bd
|
172.67.190.26
|
||
http://opensource.org/licenses/MIT
|
unknown
|
||
https://link.cornellfreespeech.com/favicon.ico
|
97.64.76.25
|
||
http://ionicons.com/
|
unknown
|
||
https://liberationtekcampaign.com/frontend/assets/cache/f88c644d/jquery-migrate.min.js
|
172.67.190.26
|
||
https://liberationtekcampaign.com/assets/js/select2/css/select2.min.css?av=206b49bd
|
172.67.190.26
|
||
https://link.cornellfreespeech.com/article/campaign-tag-filters
|
|||
https://liberationtekcampaign.com/customer/assets/cache/f88c644d/jquery.min.js
|
172.67.190.26
|
||
https://github.com/driftyco/ionicons
|
unknown
|
||
http://fontawesome.io/license
|
unknown
|
||
https://link.cornellfreespeech.com/customer/guest/index
|
|||
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
|
142.250.64.196
|
||
http://www.opensource.org/licenses/mit-license.php)
|
unknown
|
||
https://liberationtekcampaign.com/assets/js/notify.js?av=206b49bd
|
172.67.190.26
|
||
https://liberationtekcampaign.com/assets/js/adminlte.js?av=206b49bd
|
172.67.190.26
|
||
https://liberationtekcampaign.com/customer/assets/cache/f88c644d/jquery-migrate.min.js
|
172.67.190.26
|
||
http://www.almsaeedstudio.com
|
unknown
|
||
https://link.cornellfreespeech.com/customer/guest/forgot-password
|
|||
https://liberationtekcampaign.com/assets/css/font-awesome/fonts/fontawesome-webfont.woff2?v=4.5.0
|
172.67.190.26
|
||
https://github.com/twbs/bootstrap/blob/master/LICENSE)
|
unknown
|
||
https://github.com/js-cookie/js-cookie
|
unknown
|
||
https://link.cornellfreespeech.com/customer/
|
97.64.76.25
|
||
https://liberationtekcampaign.com/customer/assets/js/guest.js?av=206b49bd
|
172.67.190.26
|
||
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRmgZjcGOO3sLEGIjAzzAFMYc9EoDL2ndWJazZCJL1bJJesxbvpORk0oldHKw_bWuOiUZlGjEwhTOpGT3MyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
|
142.250.64.196
|
There are 53 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
liberationtekcampaign.com
|
172.67.190.26
|
||
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
www.google.com
|
142.250.64.196
|
||
campaign.liberationtek.com
|
97.64.76.25
|
||
windowsupdatebg.s.llnwi.net
|
208.111.136.128
|
||
link.cornellfreespeech.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
192.168.2.5
|
unknown
|
unknown
|
||
142.250.64.196
|
www.google.com
|
United States
|
||
97.64.76.25
|
campaign.liberationtek.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
172.67.190.26
|
liberationtekcampaign.com
|
United States
|
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://link.cornellfreespeech.com/campaigns/xd182pswwxb7f/track-url/rt9295q1rf292/ffe1280e2a4f37968a98d9870ae24b3a9e13eb4b%5D_
|
||
https://link.cornellfreespeech.com/customer/guest/index
|
||
https://link.cornellfreespeech.com/articles
|
||
https://link.cornellfreespeech.com/customer/guest/forgot-password
|
||
https://link.cornellfreespeech.com/article/campaign-tag-filters
|