flash

COVID-19 Advice from the Australian Government.docx

Status: finished
Submission Time: 28.05.2020 04:49:11
Clean

Comments

Tags

Details

  • Analysis ID:
    233674
  • API (Web) ID:
    363500
  • Analysis Started:
    28.05.2020 04:49:12
  • Analysis Finished:
    28.05.2020 05:03:37
  • MD5:
    dc0ac6506cb941bc55222b68a8e78b73
  • SHA1:
    b86dcf81990372bd6a99fde829e96d7543b881a5
  • SHA256:
    3760e4dc9ee824d61933a7c11196a03f931b901d6d11fd05ebaf512dcfbe87b7
  • Technologies:
Full Report Engine Info Verdict Score Reports

System: Windows 7 SP1 (with Office 2010 SP2, IE 11, FF 54, Chrome 60, Acrobat Reader DC 17, Java 8.0.1440.1, Flash 30.0.0.113)

clean
2/100

System: Windows 10 64 bit (version 1803) with Office 2016, Adobe Reader DC 19, Chrome 70, Firefox 63, Java 8.171, Flash 30.0.0.113
Run Condition: Potential for more IOCs and behavior

clean
1/100

IPs

IP Country Detection
173.194.76.155
United States
31.13.92.36
Ireland
185.60.216.19
Ireland

Domains

Name IP Detection
star-mini.c10r.facebook.com
31.13.92.36
scontent.xx.fbcdn.net
185.60.216.19
stats.l.doubleclick.net
173.194.76.155
Click to see the 5 hidden entries
www.facebook.com
0.0.0.0
education.us17.list-manage.com
0.0.0.0
connect.facebook.net
0.0.0.0
www.health.gov.au
0.0.0.0
stats.g.doubleclick.net
0.0.0.0

URLs

Name Detection
https://www.health.gov.au/sites/default/files/js/js_Kqgjpz8gxLopAsE9YGrKt1dQPDTNNfCPrso7y60J1T0.js
https://www.health.gov.au/sites/default/themes/custom/health/favicon-16x16.png
https://www.health.gov.au/sites/default/files/styles/content_max_width_mobile/public/images/news/202
Click to see the 97 hidden entries
https://github.com/jquery/jquery/issues/2432
https://github.com/jquery/jquery/commit/a839af034db2bd934e4d4fa6758a3fed8de74174
https://www.health.gov.au/about-us/the-australian-health-system
https://au.linkedin.com/company/dept-of-health-and-ageing
https://www.health.gov.au/about-us
https://www.health.gov
https://github.com/jquery/jquery/pull/4333
http://jqueryui.com
http://stackoverflow.com/questions/699941/handle-ajax-error-when-a-user-clicks-refresh.
https://stats.g.doubleclick.net/r/collect?t=dc&aip=1&_r=3&
http://www.adequatelygood.com/2010/3/JavaScript-Module-Pattern-In-Depth
https://www.hotdoc.com.au/search?in=canberra-ACT-2600&purpose=respiratory&where=service:resp
https://education.us17.list-manage.com/track/click?u=e11e7c8d748ec85b8de00986c&id=f79985874e&e=2b55c
https://www.health.gov.au/resources/apps-and-tools/covidsafe-app
https://www.youtube.com/user/healthgovau
https://www.health.gov.au/sites/default/files/js/js_rsGiM5M1ffe6EhN-RnhM5f3pDyJ8ZAPFJNKpfjtepLk.js
https://www.health.gov.au/sites/default/files/styles/full__3500x3500__-_b/public/images/publications
https://www.health.gov.au/sites/default/files/styles/square_thumbnail/public/healthdirect-coronaviru
https://drupal.org/node/1446420
https://www.health.gov.au/health-topics/aged-care
https://www.health.gov.au/sites/default/files/js/js_bxNedYwJnSkVUSrBYdo4Cc8cSIc7aruKrjnujdJleCU.js
https://www.health.gov.au/sites/default/files/styles/large/public/9cd6741a-f29f-496e-b4f4-c8966d461c
https://www.health.gov.au/sites/default/files/styles/square_thumbnail/public/images/publications/202
http://www.opensource.org/licenses/mit-license.php
https://www1.health.gov.au/
https://www.health.gov.au/sites/default/files/styles/content_max_width_mobile/public/images/publicat
https://www.health.gov.au/ministers4Health
https://github.com/scottjehl/picturefill/blob/master/Authors.txt;
https://pandora.nla.gov.au/col/c12402
https://www.hotdoc.com.au/search?in=brisbane-QLD-4000&purpose=respiratory&where=service:resp
https://www.health.gov.au/nRoot
https://www.health.gov.au/about-us/contact-us
https://education.us17.list-manage.com/track/click?u=e11e7c8d748ec85b8de00986c&id=2d814b834f&e=2b55c
http://bugs.jquery.com/ticket/9521
https://www.healthdirect.gov.au/
https://github.com/krux/postscribe/blob/master/LICENSE.
https://github.com/js-cookie/js-cookie/tree/latest#readme
http://govcms.gov.au)
https://stats.g.doubleclick.net/j/collect
https://www.health.gov.au/sites/default/files/js/js_y4OK_wTh2vRYH5lQSYUus_QkCcYjiPd7BycNMUsQenI.js
https://github.com/angular/angular.js/blob/v1.4.4/src/ng/urlUtils.js
https://www.health.gov.au/sites/default/files/styles/content__max_width_no_upscale_/public/images/ne
https://www.healthdirect.gov.au/symptom-checker/tool/basic-details
http://www.health.gov.au/sport
https://www.health.gov.au/sites/default/files/js/js_i3kKUS8pGlCjbbDR65Y8kiD_iGWAFxKW8Uy4JYoZSY4.js
http://ogp.me/ns/product#
https://www.health.gov.au/about-ush-alerts/novel-coronavirus-2019-ncov-health-alertstatement-on-earl
https://www.health.gov.au/sites/default/files/styles/square_thumbnail/public/the-hon-mark-coulton-mp
https://www.health.gov.au/sites/default/files/styles/square_thumbnail/public/covidsafe-app_1.png?ito
http://www.agls.gov.au/agls/terms/
https://education.us17.list-manage.com/track/click?u=e11e7c8d748ec85b8de00986c&id=51146fdebd&e=2b55c
https://www.health.gov.au/health-topicstHealth
https://www.health.gov.au/sites/default/themes/custom/health/images/mini-site/ministers/ministers-sh
https://www.health.gov.au/news/health-alerts/novel-coronavirus-2019-ncov-health-alertstatement-on-ea
http://www.mbsonline.gov.au/internet/mbsonline/publishing.nsf/Content/Factsheet-TempBB
https://www.hotdoc.com.au/search?in=sydney-NSW-2000&purpose=respiratory&where=service:respir
https://www.health.gov.au/sites/default/themes/custom/health/site.webmanifest
https://www.health.gov.au/media-centreerts/novel-coronavirus-2019-ncov-health-alertstatement-on-earl
https://www.health.gov.au/TAustralian
https://www.health.gov.au/about-us/contact-usovel-coronavirus-2019-ncov-health-alertstatement-on-ear
https://www.health.gov.au/resources
http://fancyapps.com/fancybox/
https://www.google.%/ads/ga-audiences
https://education.us17.list-manage.com/track/click?u=e11e7c8d748ec85b8de00986c&id=0e162aebcd&e=2b55c
https://headtohealth.gov.au/covid-19-support/covid-19
https://www.health.gov.au/resources/apps-and-tools/healthdirect-find-a-health-service
https://education.us17.list-manage.com/track/click?u=e11e7c8d748ec85b8de00986c&id=66763ea8a1&e=2b55c
https://www.health.gov.au/news/australian-health-protection-principal-committee-ahppc-statement-on-e
https://www.health.gov.au/sites/default/files/js/js_4RJzE_b3R7CGOowHkSV32IEW5teiyQfZ-1bsg-vtXyk.js
https://www.health.gov.au/sites/default/files/styles/square_thumbnail/public/contact-single.png?itok
https://education.us17.list-manage.com/track/click?u=e11e7c8d748ec85b8de00986c&id=dbfadbe568&e=2b55c
http://ogp.me/ns#
https://www.health.gov.au/news/health-alerts/novel-coronavirus-2019-ncov-health-alert/government-res
https://www.health.gov.au/news/health-alerts/novel-coronavirus-2019-ncov-health-alert
http://www.gnu.org/licenses/gpl.html
https://www.health.gov.au/sites/default/files/images/news/2020/05/australian-health-protection-princ
https://www.tga.gov.au/
https://www.health.gov.au/newslttralian-health-protection-principal-committee-ahppc-statemenRoot
http://ogp.me/ns/book#
https://www.health.gov.au/sites/default/files/styles/content__max_width_no_upscale_/public/images/pu
https://www.health.gov.au/sites/default/themes/custom/health/images/Department-of-Health-crest.png
http://departmentofhealthandageing.createsend.com/t/r/u/kkdkdr/
https://www.health.gov.au/newscentreerts/novel-coronavirus-2019-ncov-health-alertstatement-on-early-
https://www.hotdoc.com.au/search?in=adelaide-SA-5000&purpose=respiratory&where=service:respi
https://health.gov.au/news/health-alerts/novel-coronavirus-2019-ncov-health-alert/what-you-need-to-k
https://www.health.gov.au/ws/health-alerts/novel-coronavirus-2019-ncov-health-alertstatement-on-earl
http://drupal.org/update/modules/6/7#javascript_compatibility
https://www.health.gov.au/health-topics/medicare
https://www.health.gov.au/sites/default/files/styles/thumbnail_cropped_16x9/public/default_images/cr
http://plugins.jquery.com/project/once
https://www.health.gov.au/sites/default/files/styles/thumbnail_cropped_16x9/public/images/news/2020/
http://scottjehl.github.io/picturefill
http://www.australia.gov.au
https://mydomain.com/node/1
http://ogp.me/ns/video#
https://www.health.gov.au/sites/default/files/styles/square_thumbnail/public/senator-the-hon-richard
https://education.us17.list-manage.com/track/click?u=e11e7c8d748ec85b8de00986c&id=cc0ee62e57&e=2b55c

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 58383 bytes, 1 file
#
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
#
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
#
Click to see the 97 hidden entries
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E0F5C59F9FA661F6F4C50B87FEF3A15A
data
#
C:\Users\user\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
PNG image data, 16 x 16, 4-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms
data
#
C:\Users\user\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Suggested Sites~.feed-ms
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{292B66F1-A08E-11EA-B813-B2C276BF9C88}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{292B66F3-A08E-11EA-B813-B2C276BF9C88}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{4368BE90-A08E-11EA-B813-B2C276BF9C88}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-2845162440\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\kzbn0r5\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\about-us[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\contact-us[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\coronavirus-covid-19-at-a-glance_24[1].png
PNG image data, 760 x 569, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\favicon-32x32[1].png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\health-topics[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\initiatives-and-programs[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\jquery.fancybox.min[1].js
HTML document, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\js_1UhnDylzrCv-G7FdiZvBm10-ukgGl6kWcxJF2sTaQl0[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\js_Kqgjpz8gxLopAsE9YGrKt1dQPDTNNfCPrso7y60J1T0[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\js_bxNedYwJnSkVUSrBYdo4Cc8cSIc7aruKrjnujdJleCU[1].js
Pascal source, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\js_v9di2yB0uyapaOHjJ3Z7Dki4opUswlt13t79uPpoCHw[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\media-centre[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\ministers[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\news[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\tr[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DK5QQ90E\tr[2].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\1203272169843664[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\DoHCrest[1].png
PNG image data, 858 x 208, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\australian-health-protection-principal-committee-ahppc-statement-on-early-childhood-and-learning-centres_0[1].jpg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 80", baseline, precision 8, 425x245, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\crest_stacked_16_9[1].png
PNG image data, 384 x 216, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\css_yADUQJNC7-mDQLUqnbhQy6NlJWk7pAuQS2Gkz_7M0ck[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\gtm[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\jquery.fancybox.min[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[2].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[3].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[4].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[5].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[6].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[7].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZ201Y8W\tr[8].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\RS18PWE7.htm
HTML document, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\css_7mRumdE-s-o0bApXDfYNgKKtw20VP4Q0ABAoDHSGxEo[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\css_d9OzHCh-CyyP3HN8OKIeLkdJF2DqkytRxecKAU21K7U[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\fbevents[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\js_i3kKUS8pGlCjbbDR65Y8kiD_iGWAFxKW8Uy4JYoZSY4[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\js_y4OK_wTh2vRYH5lQSYUus_QkCcYjiPd7BycNMUsQenI[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\novel-coronavirus-2019-ncov-health-alert[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\senator-the-hon-richard-colbeck[1].jpg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 80", baseline, precision 8, 360x360, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\the-hon-greg-hunt-mp[1].jpg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 80", baseline, precision 8, 360x360, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\the-hon-mark-coulton-mp_1[1].jpg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 80", baseline, precision 8, 360x360, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\tr[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\tr[2].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\tr[3].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\tr[4].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\tr[5].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TLQKCO6L\tr[6].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\9cd6741a-f29f-496e-b4f4-c8966d461c97[1].png
PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\GovCrest[1].png
PNG image data, 201 x 147, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\analytics[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\australian-health-protection-principal-committee-ahppc-statement-on-early-childhood-and-learning-centres[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\contact-single[1].png
PNG image data, 200 x 200, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\continued-support-for-endometriosis-research[1].jpg
gd-jpeg v1.0 (using IJG JPEG v80), quality = 80", baseline, precision 8, 384x216, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\coronavirus-covid-19-health-alert[1].png
PNG image data, 447 x 150, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\coronavirus-covid-19-health-alert[2].png
PNG image data, 480 x 161, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\favicon[1].ico
PNG image data, 16 x 16, 4-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\js_4RJzE_b3R7CGOowHkSV32IEW5teiyQfZ-1bsg-vtXyk[1].js
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\js_GSnYyl2rs0BeuYdp8goiFcWaOBi-AiZT1fytKOWKsk4[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\js_j3d_d2Aft_zoxQniWUC2D1UWBSV_5IOw6MddoRX7w48[1].js
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\js_rsGiM5M1ffe6EhN-RnhM5f3pDyJ8ZAPFJNKpfjtepLk[1].js
C source, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\tr[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X5RL12UQ\tr[2].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{00F6D9E1-B30C-4177-9EBB-E1CCEC45E6F7}.tmp
data
#
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{2EFFAB38-9E93-4C94-8008-9F12312E8216}.tmp
data
#
C:\Users\user\AppData\Local\Temp\Cab74FA.tmp
Microsoft Cabinet archive data, 58383 bytes, 1 file
#
C:\Users\user\AppData\Local\Temp\Cab751A.tmp
Microsoft Cabinet archive data, 58383 bytes, 1 file
#
C:\Users\user\AppData\Local\Temp\Tar74FB.tmp
data
#
C:\Users\user\AppData\Local\Temp\Tar751B.tmp
data
#
C:\Users\user\AppData\Local\Temp\msoCD47.tmp
GIF image data, version 89a, 15 x 15
#
C:\Users\user\AppData\Local\Temp\www85C3.tmp
MS Windows 95 Internet shortcut text (URL=<https://ieonline.microsoft.com/#ieslice>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\www85CE.tmp
MS Windows 95 Internet shortcut text (URL=<https://ieonline.microsoft.com/#ieslice>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\www85D9.tmp
MS Windows 95 Internet shortcut text (URL=<https://ieonline.microsoft.com/#ieslice>), ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Temp\~DF36E98C93F98EC030.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DF5443237B1F529679.TMP
data
#
C:\Users\user\AppData\Local\Temp\~DFFA548E81E0892EB2.TMP
data
#
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Archive, ctime=Mon Aug 7 11:48:48 2017, mtime=Mon Aug 7 11:48:48 2017, atime=Wed May 31 02:32:40 2017, length (…)
#
C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\COVID-19 Advice from the Australian Government.LNK
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Tue Jan 28 13:45:43 2020, mtime=Tue Jan 28 13:45:43 2020, atime=Thu May 28 01:51:14 2020, length=17879, window=hide
#
C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
data
#
C:\Users\user\AppData\Roaming\Microsoft\UProof\ExcludeDictionaryEN0c09.lex
Little-endian UTF-16 Unicode text, with no line terminators
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\02UVUOLQ.txt
ASCII text
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\098H6AUN.txt
ASCII text
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\0OYOV8QL.txt
ASCII text
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\1VEN3Q6N.txt
ASCII text
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\2A2IZ6GW.txt
ASCII text
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\2Z5G9EE3.txt
ASCII text
#
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\3BTLLJA2.txt
ASCII text
#