IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://tendaggisilvana.it/officix/
URL
initial url
malicious
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Microsoft Cabinet archive data, 61020 bytes, 1 file
dropped
clean
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\3aa58be2-2ecb-4993-9ab3-30edba5288d4.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\4a649860-1e37-49b1-b266-cf583d98f954.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\5e19e68d-ded2-4729-bdf9-0dbfdcaa9aaa.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\722de754-c991-41f3-9aea-a58889d3d082.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\73ee8ad8-27a1-41ef-9053-eb8c1ef8c5b9.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\94df18bb-9af4-409c-bfdc-8be5bbbe698c.tmp
SysEx File -
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\9a50a46f-5a29-45df-8020-87dc5478f6c0.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\04fdd6e9-8973-49ff-a896-5daff47a3ff0.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\10b9c84d-2825-4c53-b404-2edaaa435120.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\37ffeead-724a-4b78-a7c5-618267c9cbd3.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3948afb1-3bfa-43d0-8c5f-073146cb0677.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3ddb2680-3b07-46e4-8895-0e3ec4b143ad.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\628b765e-a881-4940-af8b-54f13bf29519.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\7742ad49-1a61-46f6-8b9c-b59f81851de5.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\7b158bec-5506-48f9-820e-b9a0dfcc4f39.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9f71be9f-d700-4c23-ae8c-efeb66848fa7.tmp
ASCII text, with very long lines, with no line terminators
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\5bb5e88508645c3a_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\7003b29a8a2647cb_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\c1cd9e851ac26739_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\c3ce0511532c1330_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\cfa84d9308b472a8_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\temp-index
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-indexgk (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Session.. (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Tabs (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State2 (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State9 (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent StateE (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.oldig (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferencesir (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences. (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.v (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferencesjs (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldes (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG.oldis (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\c5c09054-c43a-4f37-81b7-7ef01ac45307.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\4f3c2fac-32bd-4b2f-a8bf-7f5b299ed2f8.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.oldat (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.old] (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG.old41 (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old.d (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Visited Links
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000004
MPEG-4 LOAS
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ef844c49-ca61-4bd6-8342-9d0c4a72e163.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\fefa3471-0cc2-4eb8-bbde-ba3fbdf12262.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local Statet (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache. (copy)
SysEx File -
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cachet (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\b8ae2e38-fb5a-48a3-8aa1-1f802616d876.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\c8eae5f3-5aff-4891-9237-f2c384a28159.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\231f174e-f067-4e3a-b141-0133451ecc5c.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\5800_2077886747\manifest.fingerprint
ASCII text, with no line terminators
modified
clean
C:\Users\user\AppData\Local\Temp\58e9ccff-d8c3-45b5-8f7d-562532b46063.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\5bf8dedc-e0ce-4efc-9c57-38ffeae77a5a.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\6850b377-d875-404c-b217-eb0f637c469a.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\browser-sslkeys.log
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\58e9ccff-d8c3-45b5-8f7d-562532b46063.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\am\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ar\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\bn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\en\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\fa\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\fil\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\gu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\id\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\kn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ml\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\mr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ms\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\nl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\pt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\sw\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\ta\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\te\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\zh\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1605438180\CRX_INSTALL\manifest.json
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\5bf8dedc-e0ce-4efc-9c57-38ffeae77a5a.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir5800_1893443783\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
clean
There are 214 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://tendaggisilvana.it/officix/'
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1632,162788243972043073,8402254026257192306,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1744 /prefetch:8
clean

URLs

Name
IP
Malicious
https://tendaggisilvana.it/officix/
unknown
malicious
http://54.211.202.147/excel-b/excel/excel/mailred.php
unknown
malicious
https://tendaggisilvana.it/officix/2
unknown
malicious
https://tendaggisilvana.it/officix/Log
unknown
malicious
https://tendaggisilvana.it/officix/images/logo.png
unknown
malicious
https://tendaggisilvana.it/officix/
malicious
https://dns.google
unknown
clean
https://ogs.google.com
unknown
clean
https://support.google.com/chromecast/troubleshooter/2995236
unknown
clean
https://tendaggisilvana.it/
unknown
clean
https://ka-f.fontawesome.com
unknown
clean
https://payments.google.com/payments/v4/js/integrator.js
unknown
clean
https://www.google.com;
unknown
clean
https://hangouts.google.com/
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
unknown
clean
https://sandbox.google.com/payments/v4/js/integrator.js
unknown
clean
https://stackpath.bootstrapcdn.com
unknown
clean
https://www.google.com
unknown
clean
https://kit.fontawesome.com
unknown
clean
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
unknown
clean
https://tendaggisilvana.it
unknown
clean
https://a.nel.cloudflare.com/report/v3?s=cWaxdiEc43i3KuzKmLx49BpEGjyi0Zsea9vGGRhkAXFTa%2BAdiURCkk6fR
unknown
clean
https://tendaggisilvana.it/g
unknown
clean
https://accounts.google.com
unknown
clean
https://maxcdn.bootstrapcdn.com
unknown
clean
https://support.google.com/chromecast/answer/2998456
unknown
clean
https://cdnjs.cloudflare.com
unknown
clean
https://clients2.googleusercontent.com
unknown
clean
https://apis.google.com
unknown
clean
https://csp.withgoogle.com/csp/report-to/IdentityListAccountsHttp/external
unknown
clean
https://kit.fontawesome.com/585b051251.js
unknown
clean
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
unknown
clean
https://www.google.com/
unknown
clean
https://csp.withgoogle.com/csp/report-to/downloads-lorry
unknown
clean
https://feedback.googleusercontent.com
unknown
clean
https://a.nel.cloudflare.com/report/v3?s=%2BzF9HjltUl6y4bXv7qh06pECGNvgpowFXMt%2BHBCaM9aidHcxq%2Fvxl
unknown
clean
https://clients2.google.com
unknown
clean
https://clients2.google.com/service/update2/crx
unknown
clean
There are 28 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gstaticadssl.l.google.com
142.250.185.131
clean
stackpath.bootstrapcdn.com
104.18.11.207
clean
accounts.google.com
216.58.205.77
clean
cdnjs.cloudflare.com
104.16.18.94
clean
maxcdn.bootstrapcdn.com
104.18.10.207
clean
clients.l.google.com
216.58.208.174
clean
tendaggisilvana.it
168.119.64.244
clean
googlehosted.l.googleusercontent.com
216.58.208.161
clean
clients2.googleusercontent.com
unknown
clean
clients2.google.com
unknown
clean
ka-f.fontawesome.com
unknown
clean
code.jquery.com
unknown
clean
kit.fontawesome.com
unknown
clean
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
216.58.208.161
googlehosted.l.googleusercontent.com
United States
clean
192.168.2.1
unknown
unknown
clean
104.18.10.207
maxcdn.bootstrapcdn.com
United States
clean
192.168.2.3
unknown
unknown
clean
104.16.18.94
cdnjs.cloudflare.com
United States
clean
168.119.64.244
tendaggisilvana.it
Germany
clean
216.58.208.174
clients.l.google.com
United States
clean
216.58.205.77
accounts.google.com
United States
clean
104.18.11.207
stackpath.bootstrapcdn.com
United States
clean
239.255.255.250
unknown
Reserved
clean
142.250.185.131
gstaticadssl.l.google.com
United States
clean
127.0.0.1
unknown
unknown
clean
There are 2 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
ahfgeienlihckogmohjhadlkjgocpleb
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gdaefkejpgkiemlaofpalmlakkmbjdnl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gfdkimpbcpahaombhbimeihdjnejgicl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
kmendfapggjehodndflmmgagdbamhnfd
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
mfehgcgbbipciphmccgaenjidiccnmng
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
mhjfbmdgcfjbbpaeojofohoefgiehjai
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
neajdppkdcdipfabeoofebfddakdcjhd
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
nkeimhogjdpnpccoofpliimaahmaaome
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
prefs.preference_reset_time
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
S-1-5-21-3853321935-2125563209-4053062332-1002
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gfdkimpbcpahaombhbimeihdjnejgicl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
nmmhkkegccagdldgiimedpiccmgmieda
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
pkedcjkdefgpdelpbcmbmeomcjbeemfm
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
nmmhkkegccagdldgiimedpiccmgmieda
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
state
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
StatusCodes
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
StatusCodes
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
state
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.reporting
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
module_blacklist_cache_md5_digest
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
media.storage_id_salt
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.last_account_id
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.account_id
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.prompt_seed
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_homepage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
default_search_provider_data.template_url_data
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
safebrowsing.incidents_sent
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
pinned_tabs
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
search_provider_overrides
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_default_search
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
prefs.preference_reset_time
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.last_username
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
session.startup_urls
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
session.restore_on_startup
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.prompt_version
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_startup_urls
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.prompt_wave
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
homepage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
homepage_is_newtabpage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
browser.show_home_button
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
user_experience_metrics.stability.exited_cleanly
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
lastrun
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
There are 36 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1348C9AA000
unkown
page read and write
clean
1349189C000
unkown
page read and write
clean
7FF569205000
unkown
page readonly
clean
13A84300000
unkown
page read and write
clean
7FF5453CB000
unkown
page readonly
clean
7FF560466000
unkown
page readonly
clean
7FF5092D6000
unkown
page readonly
clean
7FF50912A000
unkown
page readonly
clean
1348BF10000
unkown
page readonly
clean
13A84EC0000
unkown
page readonly
clean
1348C102000
unkown
page read and write
clean
134918A6000
unkown
page read and write
clean
7FF50934D000
unkown
page readonly
clean
13491800000
unkown
page read and write
clean
13A84060000
heap default
page read and write
clean
7FF5D070D000
unkown
page readonly
clean
7FF568EA1000
unkown
page readonly
clean
13491580000
unkown
page read and write
clean
1348C9DB000
unkown
page read and write
clean
7FF5693F7000
unkown
page readonly
clean
219FD855000
unkown
page read and write
clean
219FD800000
unkown
page read and write
clean
7FF5D08B7000
unkown
page readonly
clean
43DC17C000
unkown
page read and write
clean
23B27629000
unkown
page read and write
clean
1348C913000
unkown
page read and write
clean
219FDF30000
unkown
page readonly
clean
7FF5D0131000
unkown
page readonly
clean
13491630000
unkown
page read and write
clean
1348D030000
unkown
page readonly
clean
7FF5691B7000
unkown
page readonly
clean
7FF5D0635000
unkown
page readonly
clean
13491670000
unkown
page read and write
clean
6F7C92E000
unkown
page read and write
clean
6F7D17F000
unkown
page read and write
clean
1348C058000
unkown
page read and write
clean
7FF568F8B000
unkown
page readonly
clean
23B27D40000
unkown
page read and write
clean
7FF5D0927000
unkown
page readonly
clean
134918F9000
unkown
page read and write
clean
317487B000
unkown
page read and write
clean
1348C03E000
unkown
page read and write
clean
13A83FD0000
unkown
page read and write
clean
219FD902000
unkown
page read and write
clean
7FF5693CA000
unkown
page readonly
clean
1348C078000
unkown
page read and write
clean
134918AF000
unkown
page read and write
clean
3174D7F000
unkown
page read and write
clean
7FF5D069E000
unkown
page readonly
clean
219FDF40000
unkown
page read and write
clean
7FF56046D000
unkown
page readonly
clean
219FD813000
unkown
page read and write
clean
23B275E0000
heap default
page read and write
clean
7FF569303000
unkown
page readonly
clean
134918DF000
unkown
page read and write
clean
7FF5D0917000
unkown
page readonly
clean
134917B0000
unkown
page readonly
clean
7FF5D0527000
unkown
page readonly
clean
1349156E000
unkown
page read and write
clean
317467E000
unkown
page read and write
clean
13491A50000
unkown
page read and write
clean
23B27682000
unkown
page read and write
clean
7FF5D0628000
unkown
page readonly
clean
7FF5092C2000
unkown
page readonly
clean
13A84067000
heap default
page read and write
clean
7FF5D0967000
unkown
page readonly
clean
13A83FF0000
unkown
page read and write
clean
13491902000
unkown
page read and write
clean
134916C0000
unkown
page read and write
clean
3174EFE000
unkown
page read and write
clean
13A84C90000
unkown
page read and write
clean
1349189C000
unkown
page read and write
clean
7FF568B75000
unkown
page readonly
clean
3174E7A000
unkown
page read and write
clean
7FF5D07D1000
unkown
page readonly
clean
219FD85F000
unkown
page read and write
clean
7FF509383000
unkown
page readonly
clean
134918AF000
unkown
page read and write
clean
7FF508E47000
unkown
page readonly
clean
7FF50936A000
unkown
page readonly
clean
219FD83C000
unkown
page read and write
clean
219FE200000
unkown
page readonly
clean
7FF560477000
unkown
page readonly
clean
7FF5604EB000
unkown
page readonly
clean
7FF508E0A000
unkown
page readonly
clean
7FF5D0844000
unkown
page readonly
clean
3174CFE000
unkown
page read and write
clean
3174A7A000
unkown
page read and write
clean
7FF5692EF000
unkown
page readonly
clean
219FD7E0000
heap default
page read and write
clean
1348C09F000
unkown
page read and write
clean
13A840AF000
unkown
page read and write
clean
1348C959000
unkown
page read and write
clean
1348C770000
unkown
page read and write
clean
7FF56933D000
unkown
page readonly
clean
7FF55FC50000
unkown
page readonly
clean
7FF569238000
unkown
page readonly
clean
13A84390000
unkown
page read and write
clean
7FF5D07A8000
unkown
page readonly
clean
134915A0000
unkown
page read and write
clean
7FF5693BB000
unkown
page readonly
clean
7FF5D0849000
unkown
page readonly
clean
13491568000
unkown
page read and write
clean
134918F9000
unkown
page read and write
clean
219FDA00000
unkown
page readonly
clean
1348C918000
unkown
page read and write
clean
134918C5000
unkown
page read and write
clean
134915A4000
unkown
page read and write
clean
7FF5693B7000
unkown
page readonly
clean
1348D080000
unkown
page readonly
clean
7FF5D0873000
unkown
page readonly
clean
2D3A9FD000
unkown
page read and write
clean
7FF509215000
unkown
page readonly
clean
7FF5D0956000
unkown
page readonly
clean
23B2766C000
unkown
page read and write
clean
134917F4000
unkown
page readonly
clean
13A83F70000
unkown
page read and write
clean
6F7CDFB000
unkown
page read and write
clean
7FF5693E6000
unkown
page readonly
clean
7FF509347000
unkown
page readonly
clean
219FD829000
unkown
page read and write
clean
7FF56931A000
unkown
page readonly
clean
7FF5D0707000
unkown
page readonly
clean
7FF5D070A000
unkown
page readonly
clean
23B275F0000
unkown
page readonly
clean
7FF560527000
unkown
page readonly
clean
7FF5D0914000
unkown
page readonly
clean
134913E0000
unkown
page read and write
clean
13A84F30000
unkown
page read and write
clean
43DBF77000
unkown
page read and write
clean
13A84EE0000
unkown
page read and write
clean
1348BFE0000
unkown
page readonly
clean
7FF5604D4000
unkown
page readonly
clean
134916F0000
unkown
page read and write
clean
43DC07F000
unkown
page read and write
clean
7FF5D087D000
unkown
page readonly
clean
7FF56041F000
unkown
page readonly
clean
1349163C000
unkown
page readonly
clean
134918B1000
unkown
page read and write
clean
13491902000
unkown
page read and write
clean
13491654000
unkown
page readonly
clean
7FF569336000
unkown
page readonly
clean
13491410000
unkown
page readonly
clean
219FD900000
unkown
page read and write
clean
13491657000
unkown
page readonly
clean
23B27E02000
unkown
page read and write
clean
7FF560527000
unkown
page readonly
clean
1348C093000
unkown
page read and write
clean
1348CA01000
unkown
page read and write
clean
23B28000000
unkown
page readonly
clean
317447E000
unkown
page read and write
clean
1348CA81000
unkown
page read and write
clean
134916F0000
unkown
page readonly
clean
134918F9000
unkown
page read and write
clean
7FF5D04DC000
unkown
page readonly
clean
3174B7B000
unkown
page read and write
clean
7FF5693A4000
unkown
page readonly
clean
7FF5604FA000
unkown
page readonly
clean
1348C7D1000
unkown
page read and write
clean
134916B0000
unkown
page read and write
clean
7FF509291000
unkown
page readonly
clean
7FF509397000
unkown
page readonly
clean
13491854000
unkown
page read and write
clean
7FF5693A1000
unkown
page readonly
clean
7FF55FCCC000
unkown
page readonly
clean
1348C7F3000
unkown
page read and write
clean
7FF5693AD000
unkown
page readonly
clean
23B278D0000
unkown
page readonly
clean
134916B0000
unkown
page read and write
clean
7FF5D06C4000
unkown
page readonly
clean
1349181A000
unkown
page read and write
clean
13A84230000
unkown
page readonly
clean
219FD780000
heap private
page read and write
clean
7FF5D0737000
unkown
page readonly
clean
13A840D1000
unkown
page read and write
clean
13491560000
unkown
page read and write
clean
7FF5D070F000
unkown
page readonly
clean
1348C900000
unkown
page read and write
clean
7FF5092AD000
unkown
page readonly
clean
13491584000
unkown
page read and write
clean
1348C013000
unkown
page read and write
clean
1349183D000
unkown
page read and write
clean
13491565000
unkown
page read and write
clean
134918FD000
unkown
page read and write
clean
7FF55FCA4000
unkown
page readonly
clean
134918AD000
unkown
page read and write
clean
1348CE60000
unkown
page read and write
clean
7FF569316000
unkown
page readonly
clean
7FF5692F1000
unkown
page readonly
clean
1348C0A1000
unkown
page read and write
clean
7FF5604D1000
unkown
page readonly
clean
23B27702000
unkown
page read and write
clean
7FF50928F000
unkown
page readonly
clean
7FF509354000
unkown
page readonly
clean
3174BFF000
unkown
page read and write
clean
7FF5D00A8000
unkown
page readonly
clean
7FF5D06A0000
unkown
page readonly
clean
1348C000000
unkown
page read and write
clean
13A84370000
unkown
page read and write
clean
2D3AA79000
unkown
page read and write
clean
7FF5092BA000
unkown
page readonly
clean
1348C800000
unkown
page read and write
clean
7FF568EA7000
unkown
page readonly
clean
7FF5D066A000
unkown
page readonly
clean
31741BB000
unkown
page read and write
clean
7FF5D0840000
unkown
page readonly
clean
2D3ABF9000
unkown
page read and write
clean
13A843A0000
heap private
page read and write
clean
3174F7E000
unkown
page read and write
clean
7FF569347000
unkown
page readonly
clean
7FF5692FF000
unkown
page readonly
clean
1348BEA0000
heap private
page read and write
clean
7FF5693F7000
unkown
page readonly
clean
13A840AF000
unkown
page read and write
clean
7FF50929F000
unkown
page readonly
clean
7FF560516000
unkown
page readonly
clean
7FF560368000
unkown
page readonly
clean
1348C0FC000
unkown
page read and write
clean
1349189C000
unkown
page read and write
clean
6F7C8AB000
unkown
page read and write
clean
317497F000
unkown
page read and write
clean
7FF55FCAB000
unkown
page readonly
clean
134917C8000
unkown
page readonly
clean
7FF5D060D000
unkown
page readonly
clean
13491884000
unkown
page read and write
clean
1348C113000
unkown
page read and write
clean
13A843A5000
heap private
page read and write
clean
23B27602000
unkown
page read and write
clean
23B27655000
unkown
page read and write
clean
13491590000
unkown
page read and write
clean
1348C802000
unkown
page read and write
clean
23B2767A000
unkown
page read and write
clean
13A84950000
unkown
page readonly
clean
7FF508E41000
unkown
page readonly
clean
7FF5D088A000
unkown
page readonly
clean
134918FC000
unkown
page read and write
clean
219FD913000
unkown
page read and write
clean
7FF5D0659000
unkown
page readonly
clean
13A84010000
unkown
page readonly
clean
23B28340000
unkown
page readonly
clean
1348D050000
unkown
page readonly
clean
43DBE7E000
unkown
page read and write
clean
7FF5691E6000
unkown
page readonly
clean
134917E4000
unkown
page write copy
clean
7FF509157000
unkown
page readonly
clean
317507A000
unkown
page read and write
clean
7FF569322000
unkown
page readonly
clean
13491891000
unkown
page read and write
clean
13491581000
unkown
page read and write
clean
13491A10000
unkown
page readonly
clean
1348C08A000
unkown
page read and write
clean
7FF5D0723000
unkown
page readonly
clean
134918A2000
unkown
page read and write
clean
2D3AB7F000
unkown
page read and write
clean
7FF5453CB000
unkown
page readonly
clean
7FF5D0834000
unkown
page readonly
clean
7FF5092E7000
unkown
page readonly
clean
7FF509001000
unkown
page readonly
clean
23B27580000
heap private
page read and write
clean
7FF560361000
unkown
page readonly
clean
6F7CE7F000
unkown
page read and write
clean
13A840D0000
unkown
page read and write
clean
43DB94E000
unkown
page read and write
clean
13491720000
unkown
page readonly
clean
7FF5D063F000
unkown
page readonly
clean
1348CF40000
unkown
page read and write
clean
7FF509341000
unkown
page readonly
clean
7FF568B7B000
unkown
page readonly
clean
1348C074000
unkown
page read and write
clean
7FF5D019B000
unkown
page readonly
clean
23B27713000
unkown
page read and write
clean
6F7CF77000
unkown
page read and write
clean
43DBCF5000
unkown
page read and write
clean
7FF560479000
unkown
page readonly
clean
7FF5091A0000
unkown
page readonly
clean
31744FE000
unkown
page read and write
clean
7FF55FD15000
unkown
page readonly
clean
134918FB000
unkown
page read and write
clean
7FF5D06AB000
unkown
page readonly
clean
23B27700000
unkown
page read and write
clean
13491891000
unkown
page read and write
clean
7FF5D093A000
unkown
page readonly
clean
13A84086000
unkown
page read and write
clean
23B27D30000
unkown
page readonly
clean
7FF5D085F000
unkown
page readonly
clean
1348C590000
unkown
page readonly
clean
23B27708000
unkown
page read and write
clean
7FF5092A3000
unkown
page readonly
clean
7FF5D08AD000
unkown
page readonly
clean
23B27613000
unkown
page read and write
clean
13A84020000
unkown
page readonly
clean
13491A2C000
unkown
page read and write
clean
134918E8000
unkown
page read and write
clean
7FF5091A5000
unkown
page readonly
clean
7FF5D0670000
unkown
page readonly
clean
7FF509344000
unkown
page readonly
clean
13A84160000
unkown
page readonly
clean
7FF5091D8000
unkown
page readonly
clean
7FF5D0924000
unkown
page readonly
clean
7FF5D0492000
unkown
page readonly
clean
31752FF000
unkown
page read and write
clean
7FF5D0886000
unkown
page readonly
clean
7FF5D012C000
unkown
page readonly
clean
219FE540000
unkown
page readonly
clean
7FF55FCA6000
unkown
page readonly
clean
219FD884000
unkown
page read and write
clean
13A840D0000
unkown
page read and write
clean
31745F7000
unkown
page read and write
clean
134917C0000
unkown
page read and write
clean
31753FD000
unkown
page read and write
clean
134916F0000
unkown
page read and write
clean
2D3AAFE000
unkown
page read and write
clean
23B2764F000
unkown
page read and write
clean
2D3A97E000
unkown
page read and write
clean
13491827000
unkown
page read and write
clean
23B27671000
unkown
page read and write
clean
23B2762C000
unkown
page read and write
clean
7FF5091A8000
unkown
page readonly
clean
23B2763C000
unkown
page read and write
clean
7FF5D061A000
unkown
page readonly
clean
7FF560351000
unkown
page readonly
clean
1349184A000
unkown
page read and write
clean
7FF5D04E9000
unkown
page readonly
clean
13491400000
unkown
page read and write
clean
134917A0000
unkown
page readonly
clean
7FF5D0652000
unkown
page readonly
clean
13A840A7000
unkown
page read and write
clean
13A840C3000
unkown
page read and write
clean
7FF5D0837000
unkown
page readonly
clean
134913C0000
unkown
page read and write
clean
7FF5D0664000
unkown
page readonly
clean
6F7D07E000
unkown
page read and write
clean
219FDAD0000
unkown
page readonly
clean
7FF5604E4000
unkown
page readonly
clean
1348D020000
unkown
page readonly
clean
1348C99A000
unkown
page read and write
clean
7FF55FDA1000
unkown
page readonly
clean
134918AF000
unkown
page read and write
clean
7FF5D014A000
unkown
page readonly
clean
1348D060000
unkown
page readonly
clean
7FF5604DD000
unkown
page readonly
clean
13491440000
unkown
page read and write
clean
134918AD000
unkown
page read and write
clean
7FF5604E7000
unkown
page readonly
clean
1348D070000
unkown
page readonly
clean
1348BF00000
heap default
page read and write
clean
23B27600000
unkown
page read and write
clean
7FF5D0962000
unkown
page readonly
clean
7FF5092B6000
unkown
page readonly
clean
134915A0000
unkown
page read and write
clean
7FF50935B000
unkown
page readonly
clean
219FD870000
unkown
page read and write
clean
3174C7E000
unkown
page read and write
clean
7FF5D0911000
unkown
page readonly
clean
1348D040000
unkown
page readonly
clean
134916A0000
unkown
page read and write
clean
13491891000
unkown
page read and write
clean
2D3A8FD000
unkown
page read and write
clean
7FF5D0713000
unkown
page readonly
clean
7FF560338000
unkown
page readonly
clean
6F7CCF5000
unkown
page read and write
clean
1348C029000
unkown
page read and write
clean
7FF5D0861000
unkown
page readonly
clean
7FF569275000
unkown
page readonly
clean
134918FC000
unkown
page read and write
clean
7FF5D086F000
unkown
page readonly
clean
134917E7000
unkown
page write copy
clean
13491560000
unkown
page read and write
clean
1349180F000
unkown
page read and write
clean
1348C99A000
unkown
page read and write
clean
7FF569200000
unkown
page readonly
clean
7FF569208000
unkown
page readonly
clean
13A84ED0000
unkown
page read and write
clean
7FF5D052E000
unkown
page readonly
clean
13491860000
unkown
page read and write
clean
13491648000
unkown
page read and write
clean
13491891000
unkown
page read and write
clean
7FF509392000
unkown
page readonly
clean
7FF5D0815000
unkown
page readonly
clean
7FF5602AC000
unkown
page readonly
clean
1348CD00000
unkown
page read and write
clean
1348C08D000
unkown
page read and write
clean
13A845C0000
unkown
page readonly
clean
7FF5D0953000
unkown
page readonly
clean
3174779000
unkown
page read and write
clean
7FF5693A7000
unkown
page readonly
clean
7FF569061000
unkown
page readonly
clean
13491649000
unkown
page write copy
clean
13491700000
unkown
page readonly
clean
134917F0000
unkown
page read and write
clean
1349189C000
unkown
page read and write
clean
13491710000
unkown
page readonly
clean
13491450000
unkown
page read and write
clean
1348C08F000
unkown
page read and write
clean
7FF560434000
unkown
page readonly
clean
7FF5D0828000
unkown
page readonly
clean
134913D0000
unkown
page read and write
clean
7FF5D08B9000
unkown
page readonly
clean
219FD908000
unkown
page read and write
clean
134918E7000
unkown
page read and write
clean
7FF5693B4000
unkown
page readonly
clean
1349189C000
unkown
page read and write
clean
7FF5693E3000
unkown
page readonly
clean
134918AD000
unkown
page read and write
clean
7FF5D0666000
unkown
page readonly
clean
7FF5D091D000
unkown
page readonly
clean
7FF509386000
unkown
page readonly
clean
7FF5D08BE000
unkown
page readonly
clean
1348C815000
unkown
page read and write
clean
6F7C9AE000
unkown
page read and write
clean
13491893000
unkown
page read and write
clean
13A840C3000
unkown
page read and write
clean
317517C000
unkown
page read and write
clean
7FF5604D7000
unkown
page readonly
clean
43DB9CE000
unkown
page read and write
clean
13A840AF000
unkown
page read and write
clean
7FF5D050D000
unkown
page readonly
clean
1348D3C0000
unkown
page read and write
clean
219FD7F0000
unkown
page readonly
clean
13A84310000
unkown
page read and write
clean
7FF5D04C2000
unkown
page readonly
clean
13491590000
unkown
page read and write
clean
7FF5D07E5000
unkown
page readonly
clean
1348C200000
unkown
page readonly
clean
2D3A87C000
unkown
page read and write
clean
219FE002000
unkown
page read and write
clean
23B27800000
unkown
page readonly
clean
7FF569349000
unkown
page readonly
clean
1348C959000
unkown
page read and write
clean
7FF5092E9000
unkown
page readonly
clean
1348C125000
unkown
page read and write
clean
7FF56930D000
unkown
page readonly
clean
1348C7F0000
unkown
page read and write
clean
7FF5D0613000
unkown
page readonly
clean
134918AD000
unkown
page read and write
clean
7FF5D0854000
unkown
page readonly
clean
13491690000
unkown
page read and write
clean
13A843B0000
unkown
page read and write
clean
1348C918000
unkown
page read and write
clean
7FF560446000
unkown
page readonly
clean
13491680000
unkown
page read and write
clean
7FF509357000
unkown
page readonly
clean
13491561000
unkown
page read and write
clean
134918FC000
unkown
page read and write
clean
7FF5D06FA000
unkown
page readonly
clean
7FF5D07A1000
unkown
page readonly
clean
1348C959000
unkown
page read and write
clean
134917B4000
unkown
page read and write
clean
13A84087000
unkown
page read and write
clean
1348BFF0000
unkown
page readonly
clean
219FD84F000
unkown
page read and write
clean
13491A30000
unkown
page readonly
clean
1348C660000
unkown
page read and write
clean
7FF5D0892000
unkown
page readonly
clean
7FF509186000
unkown
page readonly
clean
7FF5D08A6000
unkown
page readonly
clean
7FF5693F2000
unkown
page readonly
clean
13491460000
unkown
page read and write
clean
7FF5092DD000
unkown
page readonly
clean
7FF509397000
unkown
page readonly
clean
13A840B1000
unkown
page read and write
clean
134916F0000
unkown
page read and write
clean
1348C06F000
unkown
page read and write
clean
43DB8CB000
unkown
page read and write
clean
7FF56918A000
unkown
page readonly
clean
7FF560513000
unkown
page readonly
clean
43DBDFA000
unkown
page read and write
clean
13A843A9000
heap private
page read and write
clean
There are 458 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://tendaggisilvana.it/officix/
malicious