IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://www.ctc.ca.gov/educator-prep/program-accred-sch-act
URL
initial url
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\BACZYXTY\www.youtube[1].xml
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\E5F0NRSV\www.ctc.ca[1].xml
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\URW0GA4Q\www.ca[1].xml
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{38854918-75F4-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3885491A-75F4-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{3F1AE735-75F4-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\6xK3dSBYKcSV-LCoeQqfX1RYOo3qOK7j[1].woff
Web Open Font Format, TrueType, length 20180, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\6xKydSBYKcSV-LCoeQqfX1RYOo3ig4vwlxdo[1].woff
Web Open Font Format, TrueType, length 19896, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\CaGov[1].eot
Embedded OpenType (EOT), icomoon family
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KFOlCnqEu92Fr1MmWUlfBBc-[1].woff
Web Open Font Format, TrueType, length 20356, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\NGH2BVFL.htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\analytics[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\app---oath-2-payment[1].png
PNG image data, 900 x 327, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\app---payment-continue[1].png
PNG image data, 755 x 243, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\app---process-payment[1].png
PNG image data, 461 x 115, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\app---renew-pick-base-zoom[1].png
PNG image data, 231 x 72, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\apply[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ca.gov-portal-logo-bear[1].png
PNG image data, 406 x 143, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\cagov.core[1].css
ASCII text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\cert-clear[1].gif
GIF image data, version 89a, 140 x 140
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\colorscheme-oceanside[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\colorscheme-oceanside[2].css
ASCII text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\complete-recommend[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\covid-19-commission-action-related-to-covid-19[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\ctclogotwo-(1)[1].png
PNG image data, 278 x 67, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\fetch-polyfill[1].js
Pascal source, ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\login-user-id-password[1].png
PNG image data, 400 x 386, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\main[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\program-accred-sch-act[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\recovery[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 800x450, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\renew[1]
HTML document, ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\school-text-sm[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 350x200, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\search-laptop-sm[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 350x200, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\translateelement[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\widgets[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\www-embed-player[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOmCnqEu92Fr1Mu4mxM[1].woff
Web Open Font Format, TrueType, length 20268, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\KFOmCnqEu92Fr1Mu4mxM[2].woff
Web Open Font Format, TrueType, length 19824, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ScriptResource[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\ScriptResource[2].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\app---complete-yes[1].png
PNG image data, 246 x 117, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\app---payment-authorize-and-complete[1].png
PNG image data, 959 x 454, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\app---payment-billing-info[1].png
PNG image data, 754 x 497, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\app---payment-site-cant-be-reached[1].png
PNG image data, 641 x 252, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\app---receipt[1].png
PNG image data, 948 x 487, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\app---recommend-return-zoom[1].png
PNG image data, 1768 x 240, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\app---renewal-section[1].png
PNG image data, 882 x 625, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\apply[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\base-credential-error[1].png
PNG image data, 408 x 122, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\bg-open-data[1].jpg
[TIFF image data, little-endian, direntries=1, copyright=Jezperklauzen], baseline, precision 8, 2000x862, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\cagov.core[1].js
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\cannabis[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 1250x600, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\cert-apply[1].gif
GIF image data, version 89a, 140 x 140
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\cert-explore[1].gif
GIF image data, version 89a, 140 x 140
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\credentials[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\cse_element__en[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\css[1].css
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\dialog_cagov-final[1].css
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\element_main[1].js
HTML document, ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\gov-seal[1].png
PNG image data, 90 x 91, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\herobg[1].jpg
[TIFF image data, little-endian, direntries=0], progressive, precision 8, 1966x339, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\immigrants[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 1250x600, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\jquery-3.4.1.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\jquery-migrate-3.1.0.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\l9Z4R4oM2tU44QRmk9iDyTxeZNIPreXiQsUQR_P65Us[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\siteanalyze_77584[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\6D19FjzPJgc[1].htm
HTML document, ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOkCnqEu92Fr1Mu51xIIzQ[1].woff
Web Open Font Format, TrueType, length 21952, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\KFOlCnqEu92Fr1MmEU9fBBc-[1].woff
Web Open Font Format, TrueType, length 20464, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\ad_status[1].js
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\app---dislosure-pfq-zoom[1].png
PNG image data, 1891 x 405, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\app---renew-pick-base-field-missing-zoom[1].png
PNG image data, 230 x 70, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\app---web-selected-next[1].png
PNG image data, 1080 x 280, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\cagov.core[1].css
ASCII text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\cagovapplets[1].js
ASCII text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\cert-complete[1].gif
GIF image data, version 89a, 140 x 140
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\cert-renew[1].gif
GIF image data, version 89a, 140 x 140
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\clear-credential[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\clear[1].png
PNG image data, 10 x 10, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\css[1].css
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\default+en[1].css
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\default[1].css
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\embed[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\extend[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
modified
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\f[1].txt
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\functions[1].js
ASCII text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\gavin-newsom[1].png
PNG image data, 188 x 48, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\gtm[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\logoone-(1)[1].png
PNG image data, 88 x 64, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\plugins[1].js
UTF-8 Unicode text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\req-credentials[1].htm
HTML document, ASCII text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\translate_24dp[1].png
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\translate_24dp[2].png
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\www-player[1].css
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\DRHAAZ24.htm
HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\able[1].eot
Embedded OpenType (EOT), able family
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\app---recommend-section[1].png
PNG image data, 892 x 568, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\app---renew-base-select[1].png
PNG image data, 756 x 201, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\app---renew-complete[1].png
PNG image data, 968 x 127, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\app---select-yes[1].png
PNG image data, 252 x 124, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\app---web-pick-app[1].png
PNG image data, 497 x 273, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\app---web-section[1].png
PNG image data, 879 x 621, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\apple-touch-icon-192x192[1].png
PNG image data, 192 x 192, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\base[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\ca-seal[1].png
PNG image data, 450 x 450, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\cagov.core[1].js
UTF-8 Unicode text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\cert-extend[1].gif
GIF image data, version 89a, 140 x 140
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\class-students-sm[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 350x200, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\complete-rec-diagram[1].png
PNG image data, 768 x 616, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\ctc-online-written-instructions[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\custom[1].css
assembler source, ASCII text, with very long lines, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\favicon[1].ico
MS Windows icon resource - 1 icon, 16x16, 8 bits/pixel
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\image[1].gif
GIF image data, version 89a, 1 x 1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\js4geo[1].js
UTF-8 Unicode text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\modernizr-2.0.6.min[1].js
HTML document, ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\pxidypY1o9NHyXh3WvSbGSggdOeMaEo[1].woff
Web Open Font Format, TrueType, length 25172, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\pxieypY1o9NHyXh3WvSbGSggdO9TTFlDim0[1].woff
Web Open Font Format, TrueType, length 25972, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\real-id[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 1250x600, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\remote[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\vote[1].png
PNG image data, 160 x 68, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\watermark[1].png
PNG image data, 126 x 126, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\widgets[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DF358A34EB9D432497.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DF372EA54F186BA564.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFC50940B530D7E907.TMP
data
dropped
clean
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PVMXY66IB050AWZRTEG3.temp
data
dropped
clean
There are 127 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4980 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
http://daneden.github.io/animate.css/
unknown
clean
https://www.ctc.ca.gov/credentials/clear-credential
clean
http://jsperf.com/jquery-vs-instanceof-jquery/2
unknown
clean
https://educator.ctc.ca.gov/esales_enu/start.swe?SWECmd=GotoView&SWEView=Login
unknown
clean
https://vimeo.com/groups/:group/videos/:id
unknown
clean
https://www.youtube.com/embed/6D19FjzPJgc
unknown
clean
https://www.ctc.ca.gov/credentials/clear-credentialn-instructions
unknown
clean
http://benalman.com/projects/jquery-misc-plugins/#scrollbarwidth
unknown
clean
https://youtu.be/:id
unknown
clean
https://www.ctc.c/credentialspplyRoot
unknown
clean
http://imakewebthings.com/waypoints/api/context
unknown
clean
http://imakewebthings.com/waypoints/api/next
unknown
clean
http://jsonlint.com/
unknown
clean
https://www.ctc.ca.gov/credentials/extenddentialsn-instructions
unknown
clean
http://www.opensource.org/licenses/mit-license.php
unknown
clean
https://codepen.io/lemagus/pen/RWxEYz
unknown
clean
https://gist.github.com/purtuga/8257269
unknown
clean
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
clean
http://oaa-accessibility.org/examplep/accordian1/
unknown
clean
https://admin.youtube.com
unknown
clean
https://www.ctc.cch-act
unknown
clean
http://imakewebthings.com/waypoints/api/viewport-width
unknown
clean
http://dev.aol.com/dhtml_style_guide/#mediaplayer
unknown
clean
https://gist.github.com/paulirish/5558557
unknown
clean
http://imakewebthings.com/waypoints/api/context-destroy
unknown
clean
http://stackoverflow.com/questions/17328742
unknown
clean
https://stats.g.doubleclick.net/j/collect
unknown
clean
https://www.ctc.ca.gov/credentials/extend(Extensions
unknown
clean
https://css-tricks.com/slightly-careful-sub-elements-clickable-things/
unknown
clean
https://www.ctc.c/educator-prep/program-accred-sch-act#main-anchorcovid-19Root
unknown
clean
https://datatables.net/download
unknown
clean
http://stackoverflow.com/a/20892048/145346
unknown
clean
http://www.reddit.com/
unknown
clean
https://www.ctc.ca.gov/credentials/extend
unknown
clean
https://wwwedit.ctc.ca.gov/images/default-source/cert-images/ctc-online-help/apps-payments/app---sel
unknown
clean
http://commons.wikimedia.org/wiki/File:Blue_a_v.svg#mediaviewer/File:Blue_a_v.svg
unknown
clean
http://imakewebthings.com/waypoints/api/group
unknown
clean
https://www.ctc.ca.gov/credentials/apply0Apply
unknown
clean
https://www.youtube.com/generate_204?cpn=
unknown
clean
https://www.ctc.ca.gov/favicon.ico
unknown
clean
https://www.surveymonkey.com/r/T2V3FMJ?source=ca
unknown
clean
https://github.com/Modernizr/Modernizr/blob/master/feature-detects/css-filters.js
unknown
clean
https://www.ca.gov/ov/educator-prep/program-accred-sch-act#main-anchorcovid-19(
unknown
clean
http://imakewebthings.com/waypoints/api/destroy
unknown
clean
http://www.kellegous.com/j/2013/02/27/innertext-vs-textcontent/
unknown
clean
https://www.ctc.c
unknown
clean
https://www.ctc.c/credentials/ctc-online-written-ls/complete-recommend
unknown
clean
http://www.javascripttoolbox.com/temp/table_cellindex.html
unknown
clean
https://youtu.be/eYF-KJrgj6U
unknown
clean
https://www.youtube.com/watch?v=sS1vsIdDD0Q&feature=youtu.be
unknown
clean
https://github.com/imakewebthings/waypoints/blog/master/licenses.txt
unknown
clean
http://www.ctc.ca.gov/search-results/program-sponsors-search/program-sponsors
unknown
clean
https://wwwedit.ctc.ca.gov/credentials
unknown
clean
https://www.ctc.ca.gov/credentials/complete-recommend8Complete
unknown
clean
https://github.com/douglascrockford/JSON-js
unknown
clean
https://dev.virtualearth.net/REST/v1/Locations
unknown
clean
https://www.ctc.ca.gov/credentials/ctc-online-written-instructionszCTC
unknown
clean
https://www.youtube.com/
unknown
clean
http://www.ctc.ca.gov/credentials/req-credentials.html
unknown
clean
https://www.ctc.c/commission/covid-19-commission-action-related-to-covid-19Root
unknown
clean
https://www.ctc.ca.gov/credentials/req-credentials.Credential
unknown
clean
https://app.vzaar.com/videos/:id
unknown
clean
http://fancyapps.com/fancybox/
unknown
clean
http://imakewebthings.com/waypoints/api/last
unknown
clean
https://www.ctc.ca.gov/credentials/complete-recommend#program
unknown
clean
http://api.jquery.com/event.namespace/
unknown
clean
http://t.co/dKP3o1e
unknown
clean
https://www.ctc.ca.gov/ducator-prep/program-accred-sch-act#main-anchorcovid-19tps://www.ca.gov/%%www
unknown
clean
https://www.youtube.com/watch?v=iqODcICtloE
unknown
clean
http://stackoverflow.com/questions/5312849/jquery-find-self;
unknown
clean
https://www.ctc.ca.gov/credentials/req-credentialsn-instructions
unknown
clean
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
clean
https://github.com/js-cookie/js-cookie
unknown
clean
http://www.ctc.ca.gov/credentials
unknown
clean
http://www.ca.gov/
unknown
clean
http://jsliang.github.com/eqHeight.coffee
unknown
clean
https://github.com/Modernizr/Modernizr/blob/master/feature-detects/svg-filters.js
unknown
clean
http://css-tricks.com/13465-persistent-headers/
unknown
clean
https://www.ctc.ca.gov/credentials/apply
clean
https://github.com/overset/javascript-natural-sort
unknown
clean
https://www.ctc.ca.gov/commission/covid-19-commission-action-related-to-covid-19
unknown
clean
https://www.surveymonkey.com/r/GFDXW5B?source=ca&src=
unknown
clean
http://imakewebthings.com/waypoints/api/first
unknown
clean
http://registertovote.ca.gov/
unknown
clean
http://www.ctc.ca.gov/credentials/submit-online.html
unknown
clean
https://twitter.com/intent/tweet?text=
unknown
clean
https://github.com/FezVrasta/popper.js/pull/715
unknown
clean
https://www.ctc.ca.gov/credentiaRoot
unknown
clean
https://vimeo.com/channels/:channel/:id
unknown
clean
http://imakewebthings.com/waypoints/api/destroy-all
unknown
clean
http://www.amazon.com/
unknown
clean
http://www.twitter.com/
unknown
clean
https://www.surveymonkey.com/r/K8JNQF3?source=ca
unknown
clean
http://youtube.com/streaming/metadata/segment/102015
unknown
clean
https://youtu.be/
unknown
clean
http://www.ctc.ca.gov/search-results/credentials-search/credentials
unknown
clean
http://www.ctc.ca.gov/credentials/ctc-online-written-instructions
unknown
clean
https://www.gov.ca.gov
unknown
clean
http://www.ctc.ca.gov/credentials/complete-recommend
unknown
clean
https://www.ctc.ca.gov//www.ctc.ca.gov/favicon.ico
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ctc.ca.gov
134.186.81.178
clean
siteimproveanalytics.com
172.64.130.35
clean
stats.l.doubleclick.net
74.125.206.155
clean
googleads.g.doubleclick.net
142.250.186.162
clean
ana-cf-col-elb-78-567119012.eu-central-1.elb.amazonaws.com
3.125.230.89
clean
caprod.ogopendata.com
104.19.218.112
clean
platform.twitter.map.fastly.net
151.101.12.157
clean
api.stateentityprofile.ca.gov
unknown
clean
stateentityprofile.ca.gov
unknown
clean
static.doubleclick.net
unknown
clean
www.ca.gov
unknown
clean
stats.g.doubleclick.net
unknown
clean
77584.global.siteimproveanalytics.io
unknown
clean
www.ctc.ca.gov
unknown
clean
code.jquery.com
unknown
clean
platform.twitter.com
unknown
clean
data.ca.gov
unknown
clean
www.youtube.com
unknown
clean
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Active
Malicious
134.186.81.178
unknown
United States
unknown
clean
192.168.2.1
unknown
unknown
unknown
clean
104.19.218.112
unknown
United States
unknown
clean
142.250.186.162
unknown
United States
unknown
clean
3.125.230.89
unknown
United States
unknown
clean
74.125.206.155
unknown
United States
unknown
clean
172.64.130.35
unknown
United States
unknown
clean
151.101.12.157
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{38854918-75F4-11EB-90EB-ECF4BBEA1588}
clean
C:\Program Files\internet explorer\iexplore.exe
MFV
clean
C:\Program Files\internet explorer\iexplore.exe
Type
clean
C:\Program Files\internet explorer\iexplore.exe
Flags
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Type
clean
C:\Program Files\internet explorer\iexplore.exe
Flags
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Type
clean
C:\Program Files\internet explorer\iexplore.exe
Flags
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Type
clean
C:\Program Files\internet explorer\iexplore.exe
Flags
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
CVListPingLastYMD
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
MFV
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NumberOfSubdomains
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-912
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-904
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NumberOfSubdomains
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
VerCache
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
VerCache
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
VerCache
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NumberOfSubdomains
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
There are 74 hidden registries, click here to show them.

DOM / HTML

URL
Malicious
https://www.ca.gov/
clean
https://www.ctc.ca.gov/credentials/clear-credential
clean
https://www.ctc.ca.gov/commission/covid-19-commission-action-related-to-covid-19
clean
https://www.ctc.ca.gov/credentials/req-credentials
clean
https://www.ctc.ca.gov/educator-prep/program-accred-sch-act
clean
https://www.ctc.ca.gov/credentials/complete-recommend
clean
https://www.ctc.ca.gov/credentials/ctc-online-written-instructions
clean
https://www.ctc.ca.gov/educator-prep/program-accred-sch-act#main-anchor
clean
https://www.ctc.ca.gov/
clean
https://www.ctc.ca.gov/credentials/apply
clean
https://www.ctc.ca.gov/credentials
clean
https://www.ctc.ca.gov/credentials/extend
clean
There are 2 hidden doms, click here to show them.