IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://www.grainger.ca/fr/content/covid-19-recovery
URL
initial url
clean
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 61020 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\4f25f9cd-7214-495e-a570-101c1920fd4b.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3a74a108-5304-48e7-9799-89585014dbf1.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9af6c785-10fb-45c2-8eb5-fd4683da394d.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9d9855b2-212b-4336-9d7e-06f1a8cdb372.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
SQLite 3.x database, last written using SQLite version 3032001
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\0c349248-2579-4279-9c09-1b1ace5f1999.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
ASCII text
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\cd2515be-85df-4552-9f7c-9a30c6d411c1.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d3b4f4d6-622d-4fe4-a5ec-4d3e478e0c25.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000004
MPEG-4 LOAS
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\2750ee0c-a433-4add-a1ee-e1c4fbc1b59c.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\94cd6afc-499f-4d1b-8dc2-c8cfaa757483.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\browser-sslkeys.log
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\eb6f4f72-ac3f-4664-a6f7-9c111c23d08a.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\eb89fec9-2c10-4d28-8437-9db3dbaee116.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1093469420\eb89fec9-2c10-4d28-8437-9db3dbaee116.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\am\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ar\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\bn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\en\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\fa\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\fil\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\gu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\id\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\kn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ml\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\mr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ms\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\nl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\pt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\sw\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\ta\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\te\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\zh\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\CRX_INSTALL\manifest.json
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5428_1184234559\eb6f4f72-ac3f-4664-a6f7-9c111c23d08a.tmp
Google Chrome extension, version 3
dropped
clean
There are 138 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://www.grainger.ca/fr/content/covid-19-recovery'
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1576,8722109470797325843,6740444566604102159,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1712 /prefetch:8
clean

URLs

Name
IP
Malicious
https://dns.google
unknown
clean
https://clients2.googleusercontent.com
unknown
clean
https://www.grainger.ca/fr/content/covid-19-recovery
unknown
clean
https://www.grainger.ca/fr/content/covid-19-recovery8
unknown
clean
https://feedback.googleusercontent.com
unknown
clean

Domains

Name
IP
Malicious
googlehosted.l.googleusercontent.com
172.217.168.33
clean
clients2.googleusercontent.com
unknown
clean
www.grainger.ca
unknown
clean

IPs

IP
Domain
Country
Malicious
192.168.2.1
unknown
unknown
clean
239.255.255.250
unknown
Reserved
clean
172.217.168.33
googlehosted.l.googleusercontent.com
United States
clean
127.0.0.1
unknown
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
ahfgeienlihckogmohjhadlkjgocpleb
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gdaefkejpgkiemlaofpalmlakkmbjdnl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gfdkimpbcpahaombhbimeihdjnejgicl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
kmendfapggjehodndflmmgagdbamhnfd
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
mfehgcgbbipciphmccgaenjidiccnmng
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
mhjfbmdgcfjbbpaeojofohoefgiehjai
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
neajdppkdcdipfabeoofebfddakdcjhd
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
nkeimhogjdpnpccoofpliimaahmaaome
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
prefs.preference_reset_time
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
S-1-5-21-3853321935-2125563209-4053062332-1002
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
state
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
StatusCodes
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
StatusCodes
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
state
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.reporting
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
module_blacklist_cache_md5_digest
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
media.storage_id_salt
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.last_account_id
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.account_id
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.prompt_seed
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_homepage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
default_search_provider_data.template_url_data
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
safebrowsing.incidents_sent
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
pinned_tabs
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
search_provider_overrides
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_default_search
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
prefs.preference_reset_time
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.last_username
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
session.startup_urls
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
session.restore_on_startup
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.prompt_version
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_startup_urls
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.prompt_wave
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
homepage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
homepage_is_newtabpage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
browser.show_home_button
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
user_experience_metrics.stability.exited_cleanly
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
lastrun
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
There are 30 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
2AAF2892000
unkown
page read and write
clean
2AAF288D000
unkown
page read and write
clean
7FF56B754000
unkown
page readonly
clean
2AAF7F44000
unkown
page readonly
clean
7FF56BAB4000
unkown
page readonly
clean
2AAF283F000
unkown
page read and write
clean
7FF56B8D1000
unkown
page readonly
clean
B85CFFB000
unkown
page read and write
clean
7FF56B3B2000
unkown
page readonly
clean
B85CACB000
unkown
page read and write
clean
7FF56BBCE000
unkown
page readonly
clean
7FF56B711000
unkown
page readonly
clean
2AAF3159000
unkown
page read and write
clean
2AAF7F80000
unkown
page read and write
clean
7FF56BAE7000
unkown
page readonly
clean
2AAF2FC1000
unkown
page read and write
clean
7FF56BAEC000
unkown
page readonly
clean
2AAF2800000
unkown
page read and write
clean
2AAF2858000
unkown
page read and write
clean
2AAF7E50000
unkown
page read and write
clean
7FF56B760000
unkown
page readonly
clean
2AAF7F5C000
unkown
page readonly
clean
7FF56B86A000
unkown
page readonly
clean
B85CBCE000
unkown
page read and write
clean
B85D57F000
unkown
page read and write
clean
2AAF3158000
unkown
page read and write
clean
2AAF7FA0000
unkown
page read and write
clean
2AAF80AF000
unkown
page read and write
clean
2AAF8061000
unkown
page read and write
clean
2AAF82A0000
unkown
page read and write
clean
2AAF2AD0000
unkown
page readonly
clean
7FF56B998000
unkown
page readonly
clean
7FF56BB19000
unkown
page readonly
clean
2AAF7E80000
unkown
page read and write
clean
7FF56B8E7000
unkown
page readonly
clean
B85D0FB000
unkown
page read and write
clean
2AAF7D40000
unkown
page read and write
clean
2AAF7F90000
unkown
page read and write
clean
7FF56BBCB000
unkown
page readonly
clean
7FF56BBDF000
unkown
page readonly
clean
7FF56BBAB000
unkown
page readonly
clean
2AAF2889000
unkown
page read and write
clean
2180884B000
unkown
page read and write
clean
B85CB4E000
unkown
page read and write
clean
2AAF809B000
unkown
page read and write
clean
7FF56BAB0000
unkown
page readonly
clean
2AAF7FB0000
unkown
page readonly
clean
2AAF80BB000
unkown
page read and write
clean
2AAF3930000
unkown
page readonly
clean
2AAF7F24000
unkown
page readonly
clean
7FF56B37C000
unkown
page readonly
clean
B85DA7C000
unkown
page read and write
clean
2AAF289D000
unkown
page read and write
clean
7FF56B8D3000
unkown
page readonly
clean
2AAF7E50000
unkown
page read and write
clean
7FF56B901000
unkown
page readonly
clean
2AAF3102000
unkown
page read and write
clean
7FF56B784000
unkown
page readonly
clean
2AAF2FE3000
unkown
page read and write
clean
2AAF3980000
unkown
page readonly
clean
2AAF7D50000
unkown
page read and write
clean
7FF56BAC2000
unkown
page readonly
clean
B85D47F000
unkown
page read and write
clean
2AAF7E90000
unkown
page read and write
clean
7FF56BAD3000
unkown
page readonly
clean
2AAF7E5E000
unkown
page read and write
clean
B85D5FE000
unkown
page read and write
clean
2AAF3960000
unkown
page readonly
clean
2AAF7E74000
unkown
page read and write
clean
7FF56BA90000
unkown
page readonly
clean
2AAF2FF0000
unkown
page read and write
clean
B85D97E000
unkown
page read and write
clean
2AAF8290000
unkown
page readonly
clean
2AAF805F000
unkown
page read and write
clean
2AAF2875000
unkown
page read and write
clean
7FF56B8D8000
unkown
page readonly
clean
7FF56B02C000
unkown
page readonly
clean
2AAF82B0000
unkown
page readonly
clean
7FF56B6E6000
unkown
page readonly
clean
7FF56BA54000
unkown
page readonly
clean
2AAF80B5000
unkown
page read and write
clean
7FF56BACC000
unkown
page readonly
clean
7FF56B993000
unkown
page readonly
clean
7FF56BB9F000
unkown
page readonly
clean
B85D6FF000
unkown
page read and write
clean
2AAF8200000
unkown
page readonly
clean
21808850000
unkown
page read and write
clean
2AAF2790000
heap private
page read and write
clean
2AAF3CC0000
unkown
page read and write
clean
2AAF7F58000
unkown
page write copy
clean
7FF56B767000
unkown
page readonly
clean
2AAF3970000
unkown
page readonly
clean
2AAF2F40000
unkown
page readonly
clean
7FF56BA8D000
unkown
page readonly
clean
7FF56B01A000
unkown
page readonly
clean
2AAF802C000
unkown
page read and write
clean
2AAF3940000
unkown
page readonly
clean
B85D4FF000
unkown
page read and write
clean
7FF56BA2F000
unkown
page readonly
clean
2AAF2829000
unkown
page read and write
clean
2AAF3950000
unkown
page readonly
clean
7FF56BBAE000
unkown
page readonly
clean
7FF56BB45000
unkown
page readonly
clean
2AAF3920000
unkown
page readonly
clean
2AAF3118000
unkown
page read and write
clean
2AAF3000000
unkown
page read and write
clean
7FF56BBDF000
unkown
page readonly
clean
2AAF3760000
unkown
page read and write
clean
7FF56BA97000
unkown
page readonly
clean
7FF56BBA6000
unkown
page readonly
clean
2AAF3100000
unkown
page read and write
clean
2AAF80BB000
unkown
page read and write
clean
2AAF2887000
unkown
page read and write
clean
7FF56B974000
unkown
page readonly
clean
7FF56BAB8000
unkown
page readonly
clean
7FF56BB15000
unkown
page readonly
clean
2AAF286F000
unkown
page read and write
clean
2AAF2F60000
unkown
page read and write
clean
2AAF803E000
unkown
page read and write
clean
7FF56B76F000
unkown
page readonly
clean
2AAF7FB0000
unkown
page read and write
clean
7FF56B899000
unkown
page readonly
clean
2AAF809C000
unkown
page read and write
clean
2AAF804B000
unkown
page read and write
clean
2AAF288B000
unkown
page read and write
clean
2AAF7D00000
unkown
page readonly
clean
B85D1FF000
unkown
page read and write
clean
2AAF2877000
unkown
page read and write
clean
2AAF28F9000
unkown
page read and write
clean
2AAF7CC0000
unkown
page read and write
clean
2AAF2902000
unkown
page read and write
clean
2AAF7E94000
unkown
page read and write
clean
7FF56BAF8000
unkown
page readonly
clean
2AAF3118000
unkown
page read and write
clean
2AAF2813000
unkown
page read and write
clean
B85D87C000
unkown
page read and write
clean
2AAF7E70000
unkown
page read and write
clean
2AAF27F0000
heap default
page read and write
clean
7FF56B89F000
unkown
page readonly
clean
2AAF3015000
unkown
page read and write
clean
7FF56BBDD000
unkown
page readonly
clean
7FF56B68F000
unkown
page readonly
clean
7FF56BAD7000
unkown
page readonly
clean
7FF56B903000
unkown
page readonly
clean
7FF56BBC4000
unkown
page readonly
clean
2AAF3002000
unkown
page read and write
clean
2AAF2A00000
unkown
page readonly
clean
2AAF7F60000
unkown
page read and write
clean
7FF56BB2A000
unkown
page readonly
clean
7FF56BBDB000
unkown
page readonly
clean
2AAF8210000
unkown
page readonly
clean
2AAF2F50000
unkown
page read and write
clean
21808867000
unkown
page read and write
clean
2AAF7FB0000
unkown
page read and write
clean
2AAF7F20000
unkown
page read and write
clean
2AAF3113000
unkown
page read and write
clean
2AAF2CD0000
unkown
page readonly
clean
7FF56BBBD000
unkown
page readonly
clean
2AAF801F000
unkown
page read and write
clean
2AAF8000000
unkown
page read and write
clean
7FF56BB23000
unkown
page readonly
clean
2AAF3840000
unkown
page read and write
clean
2AAF8010000
unkown
page read and write
clean
2AAF7D30000
unkown
page read and write
clean
7FF56BAA0000
unkown
page readonly
clean
7FF56BA17000
unkown
page readonly
clean
7FF56B75A000
unkown
page readonly
clean
2AAF2913000
unkown
page read and write
clean
7FF56B8DD000
unkown
page readonly
clean
2AAF7E71000
unkown
page read and write
clean
2AAF82D0000
unkown
page readonly
clean
B85D77F000
unkown
page read and write
clean
7FF56B930000
unkown
page readonly
clean
7FF56B9AC000
unkown
page readonly
clean
2AAF80B2000
unkown
page read and write
clean
7FF596DBF000
unkown
page readonly
clean
B85CEF7000
unkown
page read and write
clean
2AAF7F20000
unkown
page write copy
clean
7FF56B8CA000
unkown
page readonly
clean
2AAF7FB0000
unkown
page read and write
clean
2AAF2FE0000
unkown
page read and write
clean
2AAF7FB0000
unkown
page read and write
clean
7FF56B97D000
unkown
page readonly
clean
7FF56BB98000
unkown
page readonly
clean
2AAF2E70000
unkown
page readonly
clean
7FF56BB0D000
unkown
page readonly
clean
7FF56B024000
unkown
page readonly
clean
2AAF7E58000
unkown
page read and write
clean
B85D67E000
unkown
page read and write
clean
2AAF7F70000
unkown
page read and write
clean
2AAF7E80000
unkown
page read and write
clean
7FF56B8CC000
unkown
page readonly
clean
2AAF7F47000
unkown
page readonly
clean
2AAF7FF0000
unkown
page readonly
clean
B85D2F9000
unkown
page read and write
clean
B85D3FB000
unkown
page read and write
clean
There are 186 hidden memdumps, click here to show them.