Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 8 11:15:16 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 8 11:15:15 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 8 11:15:15 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 8 11:15:16 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed May 8 11:15:15 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 100
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 101
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 102
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 103
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 104
|
ASCII text, with very long lines (3383)
|
downloaded
|
||
Chrome Cache Entry: 105
|
PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 106
|
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
|
dropped
|
||
Chrome Cache Entry: 107
|
PNG image data, 16 x 13, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 108
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 109
|
ASCII text, with very long lines (997)
|
downloaded
|
||
Chrome Cache Entry: 110
|
Web Open Font Format (Version 2), TrueType, length 34184, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 111
|
PNG image data, 16 x 13, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 112
|
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
|
dropped
|
||
Chrome Cache Entry: 113
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 114
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 115
|
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 116
|
ASCII text, with very long lines (2124)
|
downloaded
|
||
Chrome Cache Entry: 117
|
ASCII text, with very long lines (2124)
|
downloaded
|
||
Chrome Cache Entry: 118
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 80
|
PNG image data, 64 x 64, 8-bit/color RGB, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 81
|
ASCII text, with very long lines (597)
|
downloaded
|
||
Chrome Cache Entry: 82
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 83
|
PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 84
|
PNG image data, 64 x 64, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 85
|
HTML document, ASCII text
|
downloaded
|
||
Chrome Cache Entry: 86
|
ASCII text, with very long lines (2294)
|
downloaded
|
||
Chrome Cache Entry: 87
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 88
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 89
|
ASCII text, with very long lines (2054)
|
downloaded
|
||
Chrome Cache Entry: 90
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 91
|
ASCII text, with very long lines (962)
|
downloaded
|
||
Chrome Cache Entry: 92
|
ASCII text, with very long lines (1293)
|
downloaded
|
||
Chrome Cache Entry: 93
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 94
|
ASCII text, with very long lines (1572)
|
downloaded
|
||
Chrome Cache Entry: 95
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 96
|
ASCII text, with very long lines (1841)
|
downloaded
|
||
Chrome Cache Entry: 97
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 98
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 99
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
There are 36 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2124 --field-trial-handle=2096,i,3259511740123321582,4811320085073021387,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view?usp=drivesdk"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view?usp=drivesdk
|
|||
https://apis.google.com/js/googleapis.proxy.js?onload=startup
|
172.217.14.206
|
||
https://signaler-staging.sandbox.google.com
|
unknown
|
||
https://feedback.googleusercontent.com/resources/annotator.css
|
unknown
|
||
http://www.broofa.com
|
unknown
|
||
https://apis.google.com/js/client.js
|
unknown
|
||
https://feedback2-test.corp.googleusercontent.com/tools/feedback/%
|
unknown
|
||
https://support.google.com
|
unknown
|
||
https://apis.google.com/js/googleapis.proxy.js
|
unknown
|
||
http://localhost.proxy.googlers.com/inapp/
|
unknown
|
||
https://stagingqual-feedback-pa-googleapis.sandbox.google.com
|
unknown
|
||
https://dataconnector.corp.google.com/:session_prefix:ui/widgetview?usegapi=1
|
unknown
|
||
https://support.google.com/drive/answer/2423485?hl=%s
|
unknown
|
||
https://help.youtube.com/tools/feedback/
|
unknown
|
||
about:blank
|
|||
https://onepick-autopush.sandbox.google.com/picker/minpick/main
|
unknown
|
||
https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
|
unknown
|
||
https://docs.google.com/document/d/1kganm9BHI3TsF8ogVulX2o4DzzO8XA4gu8aIKneTTNU/preview
|
unknown
|
||
https://policies.google.com/terms
|
unknown
|
||
https://www.youtube.com
|
unknown
|
||
https://asx-frontend-staging.corp.google.com/tools/feedback/
|
unknown
|
||
https://www.google.com
|
unknown
|
||
https://support.google.com/drive/answer/2407404?hl=en
|
unknown
|
||
https://pay.google.com/gp/v/widget/save
|
unknown
|
||
https://workspace.google.com
|
unknown
|
||
https://onepick-staging.sandbox.google.com/picker/minpick/main
|
unknown
|
||
https://support.google.com/legal/answer/3110420
|
unknown
|
||
https://support.google.com/docs/answer/49114
|
unknown
|
||
https://support.google.com/drive/answer/2423694
|
unknown
|
||
https://support.google.com/google-workspace-individual/?p=esignature_signer_terms
|
unknown
|
||
https://drive-thirdparty.googleusercontent.com/
|
unknown
|
||
https://lh3.googleusercontent.com/a-/ALV-UjVb9SFnDTZyqkqHArY-sJwqn-ErkFj9L3KnrN0g71pcwcnP-g=s64
|
142.251.33.97
|
||
https://content-googleapis-test.sandbox.google.com
|
unknown
|
||
https://www.google.com/shopping/customerreviews/optin?usegapi=1
|
unknown
|
||
https://asx-frontend-autopush.corp.google.co.uk/tools/feedback/
|
unknown
|
||
https://onepick-preprod.sandbox.google.com/picker/minpick/main
|
unknown
|
||
https://developers.google.com/
|
unknown
|
||
https://onepick-staging-drivequal.sandbox.google.com/picker/minpick/main
|
unknown
|
||
https://developers.google.com/identity/gsi/web/guides/gis-migration)
|
unknown
|
||
https://www.google.com/tools/feedback
|
unknown
|
||
https://sandbox.google.com/inapp/%
|
unknown
|
||
https://www.google.com/recaptcha/api.js?trustedtypes=true
|
unknown
|
||
https://apis.google.com/js/api.js
|
unknown
|
||
https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png
|
142.251.215.228
|
||
https://www.google.com/tools/feedback/
|
unknown
|
||
https://www.youtube.com/subscribe_embed?usegapi=1
|
unknown
|
||
https://feedback2-test.corp.google.com/tools/feedback/%
|
unknown
|
||
https://punctual-dev.corp.google.com
|
unknown
|
||
https://plus.google.com
|
unknown
|
||
https://support.google.com/google-workspace-individual/?p=esignature_signer_tos
|
unknown
|
||
https://asx-frontend-autopush.corp.google.de/tools/feedback/
|
unknown
|
||
https://play.google.com/log?format=json&hasfast=true
|
142.251.33.110
|
||
https://asx-help-frontend-autopush.corp.youtube.com/tools/feedback/
|
unknown
|
||
https://clients5.google.com/webstore/wall/widget
|
unknown
|
||
https://asx-frontend-autopush.corp.google.com/inapp/
|
unknown
|
||
https://preprod-dynamite-alpha-us-signaler-pa.clients6.google.com
|
unknown
|
||
https://feedback.googleusercontent.com/resources/render_frame2.html
|
unknown
|
||
https://sandbox.google.com/tools/feedback/%
|
unknown
|
||
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.SCWmpDDGjPk.O/m=client/exm=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA/cb=gapi.loaded_1
|
142.251.33.78
|
||
https://content-googleapis-staging.sandbox.google.com
|
unknown
|
||
https://localhost.corp.google.com/inapp/
|
unknown
|
||
https://support.google.com/drive/answer/7650301
|
unknown
|
||
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.SCWmpDDGjPk.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA/cb=gapi.loaded_0
|
142.251.33.78
|
||
https://drive.google.com
|
unknown
|
||
https://play.google.com/work/embedded/search?usegapi=1&usegapi=1
|
unknown
|
||
https://policies.google.com/privacy
|
unknown
|
||
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/docos/p/sync?resourcekey&id=12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv&reqid=0
|
142.250.69.206
|
||
https://drive.google.com/requestreview?id=
|
unknown
|
||
https://asx-frontend-staging.corp.google.com/inapp/
|
unknown
|
||
https://drive.google.com/drive/my-drive
|
unknown
|
||
https://fonts.google.com/license/googlerestricted
|
unknown
|
||
https://drive.google.com/viewer2/prod-01/archive?ck=drive&ds=APznzaZx5nAprH_U-3S3p79NDN5zTZblloNhn_gSJSBxMg9DJiUArmcek9liWF_JNJjgJCQjzuwJqwz8Qa4fO0JUELJuF1IfxlPeYN0XvjwrcgCVROX6dofUomAg0MaI4bw5Rkjjs2NQXBzRqEBHpcNzUtMMaUSkC6pFkQUQBfsNwREzd_x6dAXXxMtFWS8_UnvaIAKhEtSAN1F2n5lKGcutXt5vlY-rp_jmDPdOMFTS_QOXC1M55k_ij8cmxTaO15S7tX98BDWS34Hi1ZR9bLX9_lpXMnVWiNRT-OOBSXM3Zk9pTPtQ1Y3eWdMAoiQR9lwtB6EtD3YhrP91HR78LhZababXRODFCD_A1U1iyaSxj5Xh3tv1ePF2GaQtI6X8SWaIcV0JfDNwtYMaO7WygrawGKsZK88ANQ%3D%3D&authuser=0&page=0
|
142.250.69.206
|
||
https://clients6.google.com
|
unknown
|
||
http://localhost.corp.google.com/inapp/
|
unknown
|
||
https://play.google.com
|
unknown
|
||
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view?usp=drivesdk
|
142.250.69.206
|
||
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view
|
|||
https://clients5.google.com
|
unknown
|
||
https://console.developers.google.com/
|
unknown
|
||
https://signaler-pa.youtube.com
|
unknown
|
||
https://support.google.com/docs/answer/65129?hl=en-GB
|
unknown
|
||
https://support.google.com/inapp/%
|
unknown
|
||
https://asx-help-frontend-autopush.corp.youtube.com/inapp/
|
unknown
|
||
https://drivemetadata.clients6.google.com
|
unknown
|
||
https://support.google.com/docs/answer/148505
|
unknown
|
||
https://support.google.com/
|
unknown
|
||
https://support.google.com/docs/answer/37603
|
unknown
|
||
https://www.google.com/shopping/customerreviews/badge?usegapi=1
|
unknown
|
||
https://support.google.com/contacts/answer/7345608
|
unknown
|
||
https://csp.withgoogle.com/csp/lcreport/
|
unknown
|
||
https://drive.google.com/savetodrivebutton?usegapi=1
|
unknown
|
||
https://scone-pa.clients6.google.com
|
unknown
|
||
https://lh3.googleusercontent.com/a/default-user
|
unknown
|
||
https://support.google.com/inapp/
|
unknown
|
||
https://asx-frontend-autopush.corp.google.co.uk/inapp/
|
unknown
|
||
https://developers.google.com/api-client-library/javascript/reference/referencedocs
|
unknown
|
||
https://apis.google.com
|
unknown
|
||
https://drive.google.com/auth_warmup
|
|||
https://asx-frontend-autopush.corp.google.com/tools/feedback/
|
unknown
|
||
https://asx-frontend-autopush.corp.youtube.com/tools/feedback/
|
unknown
|
||
https://domains.google.com/suggest/flow
|
unknown
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
blobcomments-pa.clients6.google.com
|
142.250.217.106
|
||
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
play.google.com
|
142.251.33.110
|
||
plus.l.google.com
|
142.251.33.78
|
||
drive.google.com
|
142.250.69.206
|
||
www.google.com
|
142.251.215.228
|
||
peoplestackwebexperiments-pa.clients6.google.com
|
142.250.69.202
|
||
googlehosted.l.googleusercontent.com
|
142.251.33.97
|
||
fp2e7a.wpc.phicdn.net
|
192.229.211.108
|
||
lh3.googleusercontent.com
|
unknown
|
||
apis.google.com
|
unknown
|
There are 1 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
172.217.14.206
|
unknown
|
United States
|
||
142.251.33.110
|
play.google.com
|
United States
|
||
142.250.217.78
|
unknown
|
United States
|
||
142.251.33.78
|
plus.l.google.com
|
United States
|
||
192.168.2.5
|
unknown
|
unknown
|
||
142.250.217.100
|
unknown
|
United States
|
||
142.251.215.228
|
www.google.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
142.251.33.97
|
googlehosted.l.googleusercontent.com
|
United States
|
||
142.250.69.206
|
drive.google.com
|
United States
|
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
about:blank
|
||
https://drive.google.com/auth_warmup
|
||
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view
|
||
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view
|
||
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view
|
||
https://drive.google.com/file/d/12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv/view
|
||
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdrive.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv%26foreignService%3Dtexmex%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdrive.google.com&followup=https%3A%2F%2Fdrive.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D12wgdoVCUtzv9UaHMbhtpDEnvd4Ke5bzv%26foreignService%3Dtexmex%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdrive.google.com&ifkv=AaSxoQwno2fSZZK4Hk5vEE5Opmd9YYkUIM1dK7xRA0A4oP58Ue8gNFq_7TZhnGhwTJ946Uq64wlb_w&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S2013655146%3A1715170523562473&theme=mn&ddm=0
|
||
https://content.googleapis.com/static/proxy.html?usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.gapi.en.SCWmpDDGjPk.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA%2Fm%3D__features__#parent=https%3A%2F%2Fdrive.google.com&rpctoken=231107307
|