Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
http://classichomesofpensacola.com//perfect/index.php
|
URL
|
initial url
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\index[2].htm
|
HTML document, UTF-8 Unicode text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{44CA2AF4-B344-11EB-90EB-ECF4BBEA1588}.dat
|
Microsoft Word Document
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{44CA2AF6-B344-11EB-90EB-ECF4BBEA1588}.dat
|
Microsoft Word Document
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{44CA2AF7-B344-11EB-90EB-ECF4BBEA1588}.dat
|
Microsoft Word Document
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\gee00pr\imagestore.dat
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\index[1].htm
|
HTML document, ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\master[1].css
|
ASCII text
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\master[1].js
|
ASCII text
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\css[1].css
|
ASCII text
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\css[2].css
|
ASCII text
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\favicon[1].ico
|
MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\notif[1].png
|
PNG image data, 40 x 2000, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\b64.min[1].js
|
ASCII text, with very long lines
|
downloaded
|
||
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\logo[1].svg
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
C:\Users\user\AppData\Local\Temp\~DF2E3BD50B36985F65.TMP
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DF33D489DE5A268363.TMP
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\~DF6E7407FC22AF9C37.TMP
|
data
|
dropped
|
There are 8 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\internet explorer\iexplore.exe
|
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
|
||
C:\Program Files (x86)\Internet Explorer\iexplore.exe
|
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:6396 CREDAT:17410 /prefetch:2
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://classichomesofpensacola.com//perfect/index.php
|
107.180.38.104
|
||
http://classichomesofpensacola.com//perfect/index.phpRoot
|
unknown
|
||
http://classichomesofpensacola.com//perfect/index.phpensacola.com//perfect/index.php?country.x=US&lo
|
unknown
|
||
http://classichomesofpensacola.com//perfect/assets/js/b64.min.js
|
107.180.38.104
|
||
http://classichomesofpensacola.com//perfect/assets/css/master.css
|
107.180.38.104
|
||
http://classichomesofpensacola.com//perfect/assets/img/logo.svg
|
107.180.38.104
|
||
http://classichomesofpensacola.com//perfect/assets/js/master.js
|
107.180.38.104
|
||
http://classichomesofpensacola.com//perfect/assets/img/favicon.ico
|
107.180.38.104
|
||
http://classichomesofpensacola.com//perfect/assets/img/favicon.ico~
|
unknown
|
||
http://classichomesofpensacola.com//perfect/assets/img/notif.png
|
107.180.38.104
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
classichomesofpensacola.com
|
107.180.38.104
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
107.180.38.104
|
classichomesofpensacola.com
|
United States
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\internet explorer\iexplore.exe
|
{44CA2AF4-B344-11EB-90EB-ECF4BBEA1588}
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Blocked
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Blocked
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
||
C:\Program Files\internet explorer\iexplore.exe
|
LoadTimeArray
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Count
|
||
C:\Program Files\internet explorer\iexplore.exe
|
Time
|
||
C:\Program Files (x86)\Internet Explorer\iexplore.exe
|
@C:\Windows\System32\ieframe.dll,-912
|
||
C:\Program Files (x86)\Internet Explorer\iexplore.exe
|
@C:\Windows\System32\ieframe.dll,-903
|
There are 11 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7FF579896000
|
unkown
|
page readonly
|
||
29077860000
|
unkown
|
page readonly
|
||
29077C00000
|
unkown
|
page readonly
|
||
1400D9C0000
|
unkown
|
page readonly
|
||
7FF57A295000
|
unkown
|
page readonly
|
||
7FF520B21000
|
unkown
|
page readonly
|
||
1400BF02000
|
unkown
|
page read and write
|
||
7FF57A63E000
|
unkown
|
page readonly
|
||
7FF5213B1000
|
unkown
|
page readonly
|
||
1EAFC46E000
|
unkown
|
page read and write
|
||
7FF521314000
|
unkown
|
page readonly
|
||
7FF54BFB4000
|
unkown
|
page readonly
|
||
7FF579911000
|
unkown
|
page readonly
|
||
7FF521262000
|
unkown
|
page readonly
|
||
7FF5213B2000
|
unkown
|
page readonly
|
||
1EAFC46D000
|
unkown
|
page read and write
|
||
1400BE68000
|
unkown
|
page read and write
|
||
7FF5212BE000
|
unkown
|
page readonly
|
||
7FF57A64D000
|
unkown
|
page readonly
|
||
7FF57976D000
|
unkown
|
page readonly
|
||
7FF57A6C1000
|
unkown
|
page readonly
|
||
1641AFE000
|
unkown
|
page read and write
|
||
7FF54BFD1000
|
unkown
|
page readonly
|
||
7FF54BF98000
|
unkown
|
page readonly
|
||
7FF54BD81000
|
unkown
|
page readonly
|
||
7FF57986A000
|
unkown
|
page readonly
|
||
7FF54BF60000
|
unkown
|
page readonly
|
||
7FF54BF5A000
|
unkown
|
page readonly
|
||
7FF54BF8C000
|
unkown
|
page readonly
|
||
29077190000
|
unkown
|
page readonly
|
||
1EAFC467000
|
unkown
|
page read and write
|
||
7FF54BF23000
|
unkown
|
page readonly
|
||
7FF54BFA4000
|
unkown
|
page readonly
|
||
1400C120000
|
unkown
|
page readonly
|
||
7FF579597000
|
unkown
|
page readonly
|
||
7FF520F8F000
|
unkown
|
page readonly
|
||
7FF57989D000
|
unkown
|
page readonly
|
||
7FF54BE41000
|
unkown
|
page readonly
|
||
7FF579820000
|
unkown
|
page readonly
|
||
1EAFC46C000
|
unkown
|
page read and write
|
||
29077280000
|
unkown
|
page read and write
|
||
1EAFC469000
|
unkown
|
page read and write
|
||
7FF57987F000
|
unkown
|
page readonly
|
||
1EAFC46C000
|
unkown
|
page read and write
|
||
290771A0000
|
unkown
|
page readonly
|
||
7FF57A6B4000
|
unkown
|
page readonly
|
||
1400BE29000
|
unkown
|
page read and write
|
||
7FF579837000
|
unkown
|
page readonly
|
||
7FF5212C5000
|
unkown
|
page readonly
|
||
2907728C000
|
unkown
|
page read and write
|
||
29077302000
|
unkown
|
page read and write
|
||
7FF520F7C000
|
unkown
|
page readonly
|
||
BF6D8FE000
|
unkown
|
page read and write
|
||
7FF5793E0000
|
unkown
|
page readonly
|
||
786B87F000
|
unkown
|
page read and write
|
||
1641A7F000
|
unkown
|
page read and write
|
||
1400BE13000
|
unkown
|
page read and write
|
||
1EAFC456000
|
unkown
|
page read and write
|
||
7FF54BFC8000
|
unkown
|
page readonly
|
||
7FF5796C3000
|
unkown
|
page readonly
|
||
7FF54BF6B000
|
unkown
|
page readonly
|
||
1400D8C0000
|
unkown
|
page read and write
|
||
1E97C0A0000
|
unkown
|
page readonly
|
||
7FF57978C000
|
unkown
|
page readonly
|
||
7FF57A5FC000
|
unkown
|
page readonly
|
||
7FF57A5DB000
|
unkown
|
page readonly
|
||
1641CFF000
|
unkown
|
page read and write
|
||
7FF520F8A000
|
unkown
|
page readonly
|
||
1400BE6A000
|
unkown
|
page read and write
|
||
7FF579784000
|
unkown
|
page readonly
|
||
7FF5211BB000
|
unkown
|
page readonly
|
||
7FF5795A0000
|
unkown
|
page readonly
|
||
BF6DAFF000
|
unkown
|
page read and write
|
||
7FF521328000
|
unkown
|
page readonly
|
||
7FF57A649000
|
unkown
|
page readonly
|
||
1E97BE90000
|
unkown
|
page read and write
|
||
7FF5213A4000
|
unkown
|
page readonly
|
||
7FF52131E000
|
unkown
|
page readonly
|
||
512AAFE000
|
unkown
|
page read and write
|
||
7FF521331000
|
unkown
|
page readonly
|
||
7FF520B1D000
|
unkown
|
page readonly
|
||
BF6D9F7000
|
unkown
|
page read and write
|
||
1400BDB0000
|
heap default
|
page read and write
|
||
29077202000
|
unkown
|
page read and write
|
||
1400BE02000
|
unkown
|
page read and write
|
||
7FF5793F5000
|
unkown
|
page readonly
|
||
1E97BFA0000
|
heap default
|
page read and write
|
||
7FF521304000
|
unkown
|
page readonly
|
||
7FF52132E000
|
unkown
|
page readonly
|
||
1EAFC370000
|
unkown
|
page readonly
|
||
7FF57971B000
|
unkown
|
page readonly
|
||
7FF5212CB000
|
unkown
|
page readonly
|
||
7FF57984F000
|
unkown
|
page readonly
|
||
7FF5212F8000
|
unkown
|
page readonly
|
||
1EAFC467000
|
unkown
|
page read and write
|
||
7FF5211C3000
|
unkown
|
page readonly
|
||
290774D0000
|
unkown
|
page readonly
|
||
7FF521336000
|
unkown
|
page readonly
|
||
1E97C430000
|
unkown
|
page readonly
|
||
7FF579671000
|
unkown
|
page readonly
|
||
29077400000
|
unkown
|
page readonly
|
||
7FF54BDB9000
|
unkown
|
page readonly
|
||
7FF5210E5000
|
unkown
|
page readonly
|
||
7FF579864000
|
unkown
|
page readonly
|
||
1E97BEF0000
|
unkown
|
page readonly
|
||
7FF57A614000
|
unkown
|
page readonly
|
||
1EAFC46E000
|
unkown
|
page read and write
|
||
7FF54BD1B000
|
unkown
|
page readonly
|
||
1400BDC0000
|
unkown
|
page readonly
|
||
1641BF9000
|
unkown
|
page read and write
|
||
7FF521339000
|
unkown
|
page readonly
|
||
7FF5212D7000
|
unkown
|
page readonly
|
||
1400BD50000
|
heap private
|
page read and write
|
||
7FF54C052000
|
unkown
|
page readonly
|
||
7FF54BD26000
|
unkown
|
page readonly
|
||
7FF54BC2A000
|
unkown
|
page readonly
|
||
29077180000
|
heap default
|
page read and write
|
||
1400BE57000
|
unkown
|
page read and write
|
||
7FF57A62F000
|
unkown
|
page readonly
|
||
1EAFC467000
|
unkown
|
page read and write
|
||
7FF57A5D0000
|
unkown
|
page readonly
|
||
BF6D3BE000
|
unkown
|
page read and write
|
||
1641D7F000
|
unkown
|
page read and write
|
||
786B7FF000
|
unkown
|
page read and write
|
||
512AB7A000
|
unkown
|
page read and write
|
||
7FF54BFD9000
|
unkown
|
page readonly
|
||
7FF54BD85000
|
unkown
|
page readonly
|
||
1EAFC240000
|
heap default
|
page read and write
|
||
1EAFDDA0000
|
unkown
|
page read and write
|
||
7FF52133D000
|
unkown
|
page readonly
|
||
7FF54BF77000
|
unkown
|
page readonly
|
||
1EAFC43F000
|
unkown
|
page read and write
|
||
1EAFDEA0000
|
unkown
|
page readonly
|
||
7FF54B7C1000
|
unkown
|
page readonly
|
||
7FF54BE5B000
|
unkown
|
page readonly
|
||
7FF54BF65000
|
unkown
|
page readonly
|
||
29077290000
|
unkown
|
page read and write
|
||
29077200000
|
unkown
|
page read and write
|
||
1E97BED0000
|
unkown
|
page read and write
|
||
1EAFC429000
|
unkown
|
page read and write
|
||
1E97BFDF000
|
heap default
|
page read and write
|
||
7FF54BF00000
|
unkown
|
page readonly
|
||
512AA7E000
|
unkown
|
page read and write
|
||
1400BF00000
|
unkown
|
page read and write
|
||
7FF579857000
|
unkown
|
page readonly
|
||
786B77E000
|
unkown
|
page read and write
|
||
BF6D87B000
|
unkown
|
page read and write
|
||
29077120000
|
heap private
|
page read and write
|
||
7FF521119000
|
unkown
|
page readonly
|
||
1400BE6A000
|
unkown
|
page read and write
|
||
1400BE68000
|
unkown
|
page read and write
|
||
BF6D33B000
|
unkown
|
page read and write
|
||
7FF579904000
|
unkown
|
page readonly
|
||
1400BE4B000
|
unkown
|
page read and write
|
||
29077270000
|
unkown
|
page read and write
|
||
7FF54BC2F000
|
unkown
|
page readonly
|
||
1641B7E000
|
unkown
|
page read and write
|
||
7FF57A5D5000
|
unkown
|
page readonly
|
||
29077313000
|
unkown
|
page read and write
|
||
7FF579912000
|
unkown
|
page readonly
|
||
7FF54BF8F000
|
unkown
|
page readonly
|
||
1400BE68000
|
unkown
|
page read and write
|
||
1400BF13000
|
unkown
|
page read and write
|
||
BF6D67E000
|
unkown
|
page read and write
|
||
7FF57A61A000
|
unkown
|
page readonly
|
||
1E97BEC0000
|
heap private
|
page read and write
|
||
7FF57981E000
|
unkown
|
page readonly
|
||
7FF54B7BD000
|
unkown
|
page readonly
|
||
7FF5212EC000
|
unkown
|
page readonly
|
||
7FF579029000
|
unkown
|
page readonly
|
||
1EAFC502000
|
unkown
|
page read and write
|
||
7FF579701000
|
unkown
|
page readonly
|
||
1641C79000
|
unkown
|
page read and write
|
||
7FF54BFAA000
|
unkown
|
page readonly
|
||
1400BE68000
|
unkown
|
page read and write
|
||
7FF5212C0000
|
unkown
|
page readonly
|
||
2907723C000
|
unkown
|
page read and write
|
||
7FF54BFCE000
|
unkown
|
page readonly
|
||
1E97BDC0000
|
unkown
|
page readonly
|
||
7FF54BC37000
|
unkown
|
page readonly
|
||
BF6DBFF000
|
unkown
|
page read and write
|
||
786B3CB000
|
unkown
|
page read and write
|
||
7FF521260000
|
unkown
|
page readonly
|
||
290771B0000
|
unkown
|
page read and write
|
||
7FF57A638000
|
unkown
|
page readonly
|
||
16417BB000
|
unkown
|
page read and write
|
||
29077A02000
|
unkown
|
page read and write
|
||
7FF57980C000
|
unkown
|
page readonly
|
||
1EAFC500000
|
unkown
|
page read and write
|
||
786B6FF000
|
unkown
|
page read and write
|
||
2907722A000
|
unkown
|
page read and write
|
||
7FF579899000
|
unkown
|
page readonly
|
||
7FF579825000
|
unkown
|
page readonly
|
||
1EAFC250000
|
unkown
|
page readonly
|
||
7FF57A6BA000
|
unkown
|
page readonly
|
||
7FF57A608000
|
unkown
|
page readonly
|
||
7FF54BE63000
|
unkown
|
page readonly
|
||
1400BE68000
|
unkown
|
page read and write
|
||
BF6D77D000
|
unkown
|
page read and write
|
||
7FF54BF02000
|
unkown
|
page readonly
|
||
1400BE6E000
|
unkown
|
page read and write
|
||
7FF520F97000
|
unkown
|
page readonly
|
||
7FF521283000
|
unkown
|
page readonly
|
||
7FF57A551000
|
unkown
|
page readonly
|
||
7FF57988E000
|
unkown
|
page readonly
|
||
7FF54C044000
|
unkown
|
page readonly
|
||
7FF54C051000
|
unkown
|
page readonly
|
||
7FF5793E6000
|
unkown
|
page readonly
|
||
7FF521086000
|
unkown
|
page readonly
|
||
7FF54BC1C000
|
unkown
|
page readonly
|
||
7FF5211A1000
|
unkown
|
page readonly
|
||
1EAFC1E0000
|
heap private
|
page read and write
|
||
7FF5212BA000
|
unkown
|
page readonly
|
||
1400C000000
|
unkown
|
page readonly
|
||
1EAFC46C000
|
unkown
|
page read and write
|
||
7FF57990A000
|
unkown
|
page readonly
|
||
7FF52130A000
|
unkown
|
page readonly
|
||
7FF57A6C2000
|
unkown
|
page readonly
|
||
7FF579773000
|
unkown
|
page readonly
|
||
512ABF9000
|
unkown
|
page read and write
|
||
1EAFC46D000
|
unkown
|
page read and write
|
||
1EAFC46E000
|
unkown
|
page read and write
|
||
7FF57981A000
|
unkown
|
page readonly
|
||
7FF5210E1000
|
unkown
|
page readonly
|
||
7FF52107B000
|
unkown
|
page readonly
|
||
7FF54C04A000
|
unkown
|
page readonly
|
||
7FF5211C8000
|
unkown
|
page readonly
|
||
7FF57982B000
|
unkown
|
page readonly
|
||
7FF57980A000
|
unkown
|
page readonly
|
||
1EAFC46C000
|
unkown
|
page read and write
|
||
1E97BFA7000
|
heap default
|
page read and write
|
||
1400BE3F000
|
unkown
|
page read and write
|
||
1EAFC513000
|
unkown
|
page read and write
|
||
7FF54BFDD000
|
unkown
|
page readonly
|
||
7FF54BFD6000
|
unkown
|
page readonly
|
||
1400BE6A000
|
unkown
|
page read and write
|
||
1EAFC600000
|
unkown
|
page readonly
|
||
1EAFC402000
|
unkown
|
page read and write
|
||
1400BE00000
|
unkown
|
page read and write
|
||
1E97BEC5000
|
heap private
|
page read and write
|
||
7FF5212EF000
|
unkown
|
page readonly
|
||
1EAFC46C000
|
unkown
|
page read and write
|
||
7FF57984C000
|
unkown
|
page readonly
|
||
1E97BFD4000
|
heap default
|
page read and write
|
||
7FF54BE68000
|
unkown
|
page readonly
|
||
512A7DB000
|
unkown
|
page read and write
|
||
7FF54BF5E000
|
unkown
|
page readonly
|
||
7FF57A5D2000
|
unkown
|
page readonly
|
||
7FF57A624000
|
unkown
|
page readonly
|
||
1EAFC320000
|
unkown
|
page write copy
|
||
7FF579888000
|
unkown
|
page readonly
|
||
786B67E000
|
unkown
|
page read and write
|
||
7FF5213AA000
|
unkown
|
page readonly
|
||
1400C0D0000
|
unkown
|
page write copy
|
||
1EAFC413000
|
unkown
|
page read and write
|
||
512AC7F000
|
unkown
|
page read and write
|
||
7FF54BFBE000
|
unkown
|
page readonly
|
||
7FF579874000
|
unkown
|
page readonly
|
||
1EAFC400000
|
unkown
|
page read and write
|
||
29077213000
|
unkown
|
page read and write
|
||
7FF579023000
|
unkown
|
page readonly
|
There are 251 hidden memdumps, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
http://classichomesofpensacola.com//perfect/index.php?country.x=US&locale.x=en_US>&client=e04bf1c0993800b8e4b6d7a615864141
|