top title background image
flash

https://covid19guards.com

Status: finished
Submission Time: 2020-06-16 15:58:22 +02:00
Suspicious
Phishing

Comments

Tags

Details

  • Analysis ID:
    238914
  • API (Web) ID:
    373733
  • Analysis Started:
    2020-06-16 15:58:48 +02:00
  • Analysis Finished:
    2020-06-16 16:07:15 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
suspicious
Score: 21
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

IPs

IP Country Detection
192.0.76.3
United States
63.250.43.1
United States
192.0.77.37
United States

Domains

Name IP Detection
stats.wp.com
192.0.76.3
c0.wp.com
192.0.77.37
pixel.wp.com
192.0.76.3
Click to see the 1 hidden entries
covid19guards.com
63.250.43.1

URLs

Name Detection
https://covid19guards.com/wp-content/uploads/2020/05/Remember-to-stay-2-carts-apart-Button-150x150.j
https://covid19guards.com/my-account/lost-password/
https://covid19guards.com/life-after-lockdown/
Click to see the 97 hidden entries
https://covid19guards.com/product/safety-first-physical-distancing-floor-sticker-set-of-10/
http://gmpg.org/xfn/11
https://covid19guards.com/wp-content/uploads/2020/05/Do-your-part-red-Button-150x150.jpg
https://covid19guards.com/wp-content/themes/haat/css/meanmenu.min.css?ver=5.4.1
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-Single-Panel-Image-9-1-300x300.j
http://fontello.comFont
https://covid19guards.com/wp-content/uploads/2020/06/Covid-19-Guard-Stabilizer-Clip-Image-1-120x120.
http://api.jqueryui.com/category/ui-core/
https://twitter.com/home?status=Single
https://covid19guards.com/feed/
http://gambit.ph
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-Hospital-Box-Image-6-1-1-150x150
https://covid19guards.com/?add-to-cart=645el-guard-with-transaction-opening/
https://lh5.ggpht.com/
https://github.com/woocommerce/selectWoo
https://covid19guards.com/wishlist/
https://covid19guards.com/wp-content/plugins/yith-woocommerce-wishlist/assets/css/style.css?ver=3.0.
https://covid19guards.com/wp-content/plugins/kingcomposer/assets/css/icons.css?ver=2.9.3
https://c0.wp.com/c/5.4.1/wp-includes/js/jquery/jquery.js
https://covid19guards.com/wp-content/themes/haat/js/jquery.scrollUp.min.js?ver=3.2
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-3-Panel-Image-6-2-100x100.jpg
https://c0.wp.com/c/5.4.1/wp-includes/js/jquery/ui/widget.min.js
https://covid19guards.com/wp-content/plugins/kingcomposer/assets/css/animate.css?ver=2.9.3
https://covid19guards.com/wp-content/uploads/2020/05/Do-your-part-red-Button-100x100.jpg
https://covid19guards.com/product-category/uncategorized/
https://covid19guards.com/wp-content/uploads/2020/05/Safety-First-Red-Button-120x120.jpg
https://covid19guards.com/wp-content/plugins/yith-woocommerce-wishlist/assets/css/jquery.selectBox.c
https://covid19guards.com/wp-content/uploads/2020/06/Covid-19-Guard-Stabilizer-Clip-Image-1-150x150.
https://covid19guards.com/wp-content/uploads/2020/05/Please-stay-6ft-apart-Blue-Button-100x100.jpg
https://covid19guards.com/product-tag/hospital/
http://markgoodyear.com/labs/scrollup/
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-3-Panel-Image-6-2-150x150.jpg
https://covid19guards.com/product/single-panel-guard-with-transaction-opening/feed/
https://covid19guards.com/?p=645
https://c0.wp.com/p/woocommerce/4.1.0/assets/js/frontend/single-product.min.js
https://www.jwatch.org/fw116520/2020/04/05/covid-19-update-aerosol-box-during-intubation-preventing
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-Triple-Panel-Image-9-4-120x120.j
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-Triple-Panel-with-Transacion-Ope
https://covid19guards.com/?add-to-cart=645XCovid-19
https://github.com/js-cookie/js-cookie
https://covid19guards.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcovid19guards.com%2Fabout-us%2F
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-5-Panel-Image-8-1-120x120.jpg
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://covid19guards.com/wp-content/plugins/yith-woocommerce-wishlist/assets/js/jquery.yith-wcwl.js
http://malsup.com/jquery/block/
https://c0.wp.com/c/5.4.1/wp-includes/js/jquery/ui/slider.min.js
https://c0.wp.com/c/5.4.1/wp-includes/css/dist/block-library/style.min.css
https://covid19guards.com/wp-content/plugins/variation-swatches-for-woocommerce/assets/css/frontend.
https://lh6.ggpht.com/
https://covid19guards.com/wp-content/uploads/2020/05/Please-stay-6ft-apart-Blue-Button-120x120.jpg
https://covid19guards.com/XCovid-19
https://covid19guards.com/product/physical-distancing-in-effect-floor-sticker-set-of-10/
http://api.jqueryui.com/jQuery.widget/
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-Triple-Panel-Image-9-4-150x150.j
https://covid19guards.com/wp-content/uploads/2020/04/Blog-Post-4-Image-Re-opening-Retail-1100x470.jp
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-Single-Panel-with-Transacion-Ope
https://covid19guards.com/wp-content/uploads/2020/05/Checkout-Line-Green-Button-150x150.jpg
https://covid19guards.com/wp-content/uploads/2020/05/Safety-First-Mask-Blue-Button-150x150.jpg
https://c0.wp.com/c/5.4.1/wp-includes/js/jquery/jquery-migrate.min.js
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-Single-Panel-Image-9-1-100x100.j
https://covid19guards.com/product-category/stickers/
http://g.co/dev/maps-no-account
https://covid19guards.com/wp-content/uploads/2020/05/Safety-First-Red-Button-100x100.jpg
https://covid19guards.com/wp-content/uploads/2020/04/Covid-19-Guard-5-Panel-Image-7-1-120x120.jpg
https://covid19guards.com/?p=285
https://covid19guards.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcovid19guards.com%2Fwishlist%2F
https://covid19guards.com/wp-content/plugins/variation-swatches-for-woocommerce/assets/js/frontend.j
https://covid19guards.com/wp-content/plugins/mailchimp-for-wp/assets/js/forms.min.js?ver=4.7.7
https://covid19guards.com/wp-content/plugins/yith-woocommerce-wishlist/assets/css/font-awesome.min.c
https://covid19guards.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcovid19guards.com%2Fcart%2F&#03
https://covid19guards.com/wp-content/themes/haat/js/jquery.meanmenu.min.js?ver=5.4.1
https://covid19guards.com/?p=5
https://covid19guards.com/wp-content/themes/haat/css/slick.css?ver=5.4.1
https://covid19guards.com/wp-content/uploads/2020/06/Covid-19-Guard-Stabilizer-Clip-Image-1-100x100.
https://covid19guards.com/wp-content/themes/haat/css/bootstrap.min.css?ver=5.4.1
http://www.reddit.com/
http://wphash.com/.
https://c0.wp.com/p/woocommerce/4.1.0/assets/css/woocommerce-smallscreen.css
https://stats.wp.com/e-202025.js
https://covid19guards.com/wp-content/plugins/yith-woocommerce-wishlist/assets/images/wpspin_light.gi
https://c0.wp.com/c/5.4.1/wp-includes/css/dist/block-library/theme.min.css
https://covid19guards.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcovid19guards.com%2Fcontact-us%
https://secure.gravatar.com/images/grav-share-sprite.png);background-repeat:no-repeat;width:16px;hei
https://covid19guards.com/wp-content/uploads/202v
http://getbootstrap.com)
https://c0.wp.com/p/woocommerce/4.1.0/assets/js/accounting/accounting.min.js
https://c0.wp.com/p/woocommerce/4.1.0/assets/js/frontend/add-to-cart.min.js
https://covid19guards.com/wp-content/uploads/2020/05/Safety-First-Mask-6ft-Red-Button-150x150.jpg
https://covid19guards.com/wp-content/themes/haat/js/bootstrap.min.js?ver=3.3.6
https://stats.wp.com/s-202025.js
https://covid19guards.com/wp-content/themes/haat/css/magnific-popup.css?ver=5.4.1
https://covid19guards.com/wp-content/uploads/2020/05/Do-your-part-red-Button-300x300.jpg
https://covid19guards.com/wp-content/themes/haat/js/jquery.onepage.nav.js?ver=5.4.1
https://covid19guards.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fcovid19guards.com%2F&forma
http://www.opensource.org/licenses/mit-license.php
https://covid19guards.com/featured-products/
https://covid19guards.com/wp-content/uploads/2017/09/breadcrumbs-1.jpg

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\selectWoo.full.min[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\vt[4].png
PNG image data, 256 x 256, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\vt[3].png
PNG image data, 256 x 256, 8-bit colormap, non-interlaced
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\vt[2].png
PNG image data, 256 x 256, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\vt[1].png
PNG image data, 256 x 256, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\theme-style[1].css
UTF-8 Unicode text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\t[1].gif
GIF image data, version 89a, 1 x 1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\styles__ltr[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\styles[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\style[2].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\style[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\star[1].eot
Embedded OpenType (EOT), icomoon family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\skip-link-focus-fix[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\vt[5].png
PNG image data, 256 x 256, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\scripts[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\responsive[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\onion[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\navigation[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\masonry.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\marker[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\map[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\map-marker[1].png
PNG image data, 28 x 40, 4-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\logo_48[1].png
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\js[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\jquery.yith-wcwl[1].js
HTML document, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-3-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTURjIg1_i6t8kCHKm45_cJD3gnD-A[1].woff
Web Open Font Format, TrueType, length 23256, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTURjIg1_i6t8kCHKm45_bZF3gnD-A[1].woff
Web Open Font Format, TrueType, length 23628, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTURjIg1_i6t8kCHKm45_bZF3gfD-A[1].woff
Web Open Font Format, TrueType, length 36444, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTURjIg1_i6t8kCHKm45_aZA3gnD-A[1].woff
Web Open Font Format, TrueType, length 23276, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTURjIg1_i6t8kCHKm45_ZpC3gnD-A[1].woff
Web Open Font Format, TrueType, length 23576, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTUPjIg1_i6t8kCHKm459WxZYgzz_PZ2[1].woff
Web Open Font Format, TrueType, length 23744, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTUPjIg1_i6t8kCHKm459WxZFgrz_PZ2[1].woff
Web Open Font Format, TrueType, length 24148, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\JTUPjIg1_i6t8kCHKm459WxZBg_z_PZ2[1].woff
Web Open Font Format, TrueType, length 23756, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-7-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-6-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-5-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-4-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\jquery.selectBox[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-2-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Single-Panel-with-Transacion-Opening-Image-8-600x643[1].jpg
[TIFF image data, big-endian, direntries=15, height=3744, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=4486], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Single-Panel-with-Transacion-Opening-Image-4-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Single-Panel-with-Transacion-Opening-Image-3-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Single-Panel-with-Transacion-Opening-Image-2-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\Covid-19-Guard-Single-Panel-with-Transacion-Opening-Image-1-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\KGYEP10B\3rd[1].js
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\wp-emoji-release.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\webworker[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\vt[7].png
PNG image data, 256 x 256, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\vt[6].png
PNG image data, 256 x 256, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTUPjIg1_i6t8kCHKm459WxZSgnz_PZ2[1].woff
Web Open Font Format, TrueType, length 24096, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTUPjIg1_i6t8kCHKm459WxZOg3z_PZ2[1].woff
Web Open Font Format, TrueType, length 24056, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTUOjIg1_i6t8kCHKm459WxZqh7k29U[1].woff
Web Open Font Format, TrueType, length 22888, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-1-copy-600x643[1].jpg
[TIFF image data, big-endian, direntries=12, height=857, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=800], baseline, precision 8, 600x643, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\Covid-19-Guard-Triple-Panel-with-Transacion-Opening-Image-1-1[1].png
PNG image data, 800 x 857, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\Covid-19-Guard-Single-Panel-with-Transacion-Opening-Image-9-300x300[1].jpg
[TIFF image data, big-endian, direntries=12, height=3571, bps=0, PhotometricIntepretation=CMYK, orientation=upper-left, width=3334], baseline, precision 8, 300x300, frames 4
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\Covid-19-Guard-Hospital-Box-Image-6-1-1-300x300[1].jpg
[TIFF image data, big-endian, direntries=12, height=3571, bps=0, PhotometricIntepretation=CMYK, orientation=upper-left, width=3334], baseline, precision 8, 300x300, frames 4
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\Covid-19-Guard-Desk-Divider-Image-6-300x300[1].jpg
[TIFF image data, big-endian, direntries=12, height=3571, bps=0, PhotometricIntepretation=CMYK, orientation=upper-left, width=3334], baseline, precision 8, 300x300, frames 4
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\55KBQAYG.htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, CR, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\r1ckxmj\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTUQjIg1_i6t8kCHKm45_QpRyS7g[1].woff
Web Open Font Format, TrueType, length 22500, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2B7E22F7-B025-11EA-AAE6-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2411AE24-B025-11EA-AAE6-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{2411AE22-B025-11EA-AAE6-44C1B3FB757B}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\ZA21IYDR\covid19guards[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\breadcrumbs-1[1].jpg
[TIFF image data, little-endian, direntries=0], baseline, precision 8, 1920x400, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\jquery.selectBox.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\jquery.meanmenu.min[1].js
HTML document, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\google_gray[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\g[5].gif
GIF image data, version 89a, 6 x 5
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\g[4].gif
GIF image data, version 89a, 6 x 5
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\g[3].gif
GIF image data, version 89a, 6 x 5
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\g[2].gif
GIF image data, version 89a, 6 x 5
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\g[1].gif
GIF image data, version 89a, 6 x 5
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\forms.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\font-awesome.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\default[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\comment-reply.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\2NWC0UP7\www.google[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\blog[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\api[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\anchor[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\KFOmCnqEu92Fr1Mu4mxP[1].ttf
TrueType Font data, 18 tables, 1st "GDEF", 8 names, Microsoft, language 0x409, Copyright 2011 Google Inc. All Rights Reserved.RobotoRegularVersion 2.137; 2017Roboto-Regularht
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\KFOlCnqEu92Fr1MmYUtfBBc9[1].ttf
TrueType Font data, 18 tables, 1st "GDEF", 8 names, Microsoft, language 0x409, Copyright 2011 Google Inc. All Rights Reserved.Roboto BlackRegularVersion 2.137; 2017Roboto-Bla
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\KFOlCnqEu92Fr1MmEU9fBBc9[1].ttf
TrueType Font data, 18 tables, 1st "GDEF", 8 names, Microsoft, language 0x409, Copyright 2011 Google Inc. All Rights Reserved.Roboto MediumRegularVersion 2.137; 2017Roboto-Me
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTUSjIg1_i6t8kCHKm459WdhzQ[1].woff
Web Open Font Format, TrueType, length 36476, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTURjIg1_i6t8kCHKm45_epG3gnD-A[1].woff
Web Open Font Format, TrueType, length 23764, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTURjIg1_i6t8kCHKm45_dJE3gnD-A[1].woff
Web Open Font Format, TrueType, length 23836, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTURjIg1_i6t8kCHKm45_c5H3gnD-A[1].woff
Web Open Font Format, TrueType, length 23872, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\HNHL2TDR\JTURjIg1_i6t8kCHKm45_ZpC3gfD-A[1].woff
Web Open Font Format, TrueType, length 36536, version 1.1
#