IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink
URL
initial url
malicious
C:\Users\user\AppData\Local\Google\Chrome\User Data\0d5a6a19-9bef-46df-a3f5-68cd76013007.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\3c15b633-f88a-4b73-be51-23868c220e8d.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\32fca649-82ef-4bb7-9d5d-c624b2ed6d19.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5f59b313-14ee-4101-b6f2-2625e8f7f9aa.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\56e67e1a4a50be0f_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\6e7f394632e47430_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8bf0835732d01051_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8e98f4b7848fbe37_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\99de76cda7e7f6ae_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\a56ee0ddb5db651b_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\dc3751d27b8cbd66_0
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\temp-index
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-index. (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons
SQLite 3.x database, last written using SQLite version 3032001
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Session0 (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last TabsOC (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State. (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
SQLite 3.x database, last written using SQLite version 3032001
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL-journal
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferenceswe (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\6eabefa4-0769-4c0c-85c5-f1faea145afe.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent Stateod (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\2b7b6dad-c7da-4f46-afd4-a7fca5b369ba.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent Stateod (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.olds (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a5f5c538-0be9-4615-af46-693daeeade15.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ad05ab0c-4d15-4ffe-a2ef-8e8a734520a3.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d7e666ce-745c-4ee3-b23d-d599523309b5.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000004
MPEG-4 LOAS
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e56da246-8455-4edd-b13a-53955359f1ac.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\f6f164b0-095e-40fd-a079-f867cab90773.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.oldE (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local StateTM (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\e05e02b6-f162-4417-af40-57678a30a893.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\46203416-4e32-432b-87ac-da1978496b71.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\a571b8d9-86a6-420f-8c75-3f25be68da97.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\browser-sslkeys.log
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\dfb6c2da-f77b-4736-b83a-16e40beb3d98.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\fda7d97e-d53c-47af-a430-cfc234668025.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\am\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ar\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\bn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\en\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fa\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fil\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\gu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\id\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\kn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ml\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\mr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ms\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\nl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\pt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sw\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ta\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\te\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\zh\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\manifest.json
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\a571b8d9-86a6-420f-8c75-3f25be68da97.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\46203416-4e32-432b-87ac-da1978496b71.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
clean
There are 191 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink'
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1508,7393693506506586080,11924844796807865969,131072 --lang=en-GB --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1768 /prefetch:8
clean

URLs

Name
IP
Malicious
https://canva.com/
unknown
clean
https://dns.google
unknown
clean
https://ogs.google.com
unknown
clean
https://static.canva.com/static/lib/underscore-1.8.3.min.js
unknown
clean
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_cam
unknown
clean
https://a.nel.cloudflare.com/report/v3?s=vTxJLcywg59S05ew7XVWhh%2B0FrXv2LtLZBFsEpV79t6xVcIzwW7zCEadC
unknown
clean
https://support.google.com/chromecast/troubleshooter/2995236
unknown
clean
https://static.canva.com/static/lib/jquery-1.8.3.min.2.js
unknown
clean
https://canva.com/k
unknown
clean
https://play.google.com
unknown
clean
https://payments.google.com/payments/v4/js/integrator.js
unknown
clean
https://www.google.com;
unknown
clean
https://www.canva.com
unknown
clean
https://hangouts.google.com/
unknown
clean
https://a.nel.cloudflare.com/report/v3?s=3H5wI1utlz8TSvWfEbFvjvXEuXlKRs49agdLRsghAV5GiLvaMBm7Wkh%2B3
unknown
clean
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink
clean
https://a.nel.cloudflare.com/report/v3?s=UlHNxrg8IER2ENUk%2BxcX6KLR1Bo%2FXbtmxTJbPJzzxWe28tdyQFKcdpj
unknown
clean
https://static.cloudflareinsights.com/beacon.min.js
unknown
clean
https://sandbox.google.com/payments/v4/js/integrator.js
unknown
clean
https://static.canva.com/static/lib/segment-snippet-4.1.0.min.js
unknown
clean
https://www.google.com
unknown
clean
https://static.canva.com/static/r/20210803-02/js/23BzzNosJDRE06_zR1W5uA.js
unknown
clean
https://static.canva.com/static/lib/cl/cl-0.4.3.min.js
unknown
clean
https://static.canva.com/static/lib/bluebird-2.3.11.min.js
unknown
clean
https://accounts.google.com
unknown
clean
https://support.google.com/chromecast/answer/2998456
unknown
clean
https://clients2.googleusercontent.com
unknown
clean
https://apis.google.com
unknown
clean
https://canva.com/7
unknown
clean
https://static.canva.com/static/images/favicon.ico
unknown
clean
https://www.google.com/
unknown
clean
https://feedback.googleusercontent.com
unknown
clean
https://clients2.google.com
unknown
clean
https://clients2.google.com/service/update2/crx
unknown
clean
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gstaticadssl.l.google.com
216.58.198.3
clean
a.nel.cloudflare.com
35.190.80.1
clean
static.cloudflareinsights.com
104.16.94.65
clean
accounts.google.com
216.58.205.77
clean
static.canva.com
104.17.114.17
clean
cl.canva.com
104.17.115.17
clean
clients.l.google.com
216.58.208.174
clean
www.canva.com
104.17.115.17
clean
googlehosted.l.googleusercontent.com
216.58.208.129
clean
clients2.googleusercontent.com
unknown
clean
clients2.google.com
unknown
clean
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
216.58.208.174
clients.l.google.com
United States
clean
192.168.2.1
unknown
unknown
clean
104.17.115.17
cl.canva.com
United States
clean
104.17.114.17
static.canva.com
United States
clean
216.58.198.3
gstaticadssl.l.google.com
United States
clean
216.58.205.77
accounts.google.com
United States
clean
239.255.255.250
unknown
Reserved
clean
216.58.208.129
googlehosted.l.googleusercontent.com
United States
clean
35.190.80.1
a.nel.cloudflare.com
United States
clean
127.0.0.1
unknown
unknown
clean
104.16.94.65
static.cloudflareinsights.com
United States
clean
There are 1 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
S-1-5-21-3853321935-2125563209-4053062332-1002
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
ahfgeienlihckogmohjhadlkjgocpleb
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gdaefkejpgkiemlaofpalmlakkmbjdnl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gfdkimpbcpahaombhbimeihdjnejgicl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
kmendfapggjehodndflmmgagdbamhnfd
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
mfehgcgbbipciphmccgaenjidiccnmng
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
mhjfbmdgcfjbbpaeojofohoefgiehjai
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
neajdppkdcdipfabeoofebfddakdcjhd
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
nkeimhogjdpnpccoofpliimaahmaaome
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
nmmhkkegccagdldgiimedpiccmgmieda
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
pkedcjkdefgpdelpbcmbmeomcjbeemfm
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
prefs.preference_reset_time
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
gfdkimpbcpahaombhbimeihdjnejgicl
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
nmmhkkegccagdldgiimedpiccmgmieda
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
state
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
StatusCodes
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
StatusCodes
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
state
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
dr
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.reporting
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
module_blacklist_cache_md5_digest
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
media.storage_id_salt
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.last_account_id
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.account_id
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.prompt_seed
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_homepage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
default_search_provider_data.template_url_data
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
safebrowsing.incidents_sent
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
pinned_tabs
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
search_provider_overrides
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_default_search
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
prefs.preference_reset_time
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
google.services.last_username
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
session.startup_urls
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
session.restore_on_startup
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
software_reporter.prompt_version
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.last_triggered_for_startup_urls
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
settings_reset_prompt.prompt_wave
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
homepage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
homepage_is_newtabpage
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
browser.show_home_button
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
user_experience_metrics.stability.exited_cleanly
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
lastrun
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
Blob
clean
There are 35 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF52D085000
unkown
page readonly
clean
17EC0974000
unkown
page read and write
clean
17EC0971000
unkown
page read and write
clean
1CD525D0000
unkown
page read and write
clean
1CD52611000
unkown
page read and write
clean
7FF52D373000
unkown
page readonly
clean
17EC0964000
unkown
page read and write
clean
17EC0975000
unkown
page read and write
clean
1D8E5C00000
unkown
page read and write
clean
17EC0989000
unkown
page read and write
clean
7FF52D46A000
unkown
page readonly
clean
422997F000
unkown
page read and write
clean
17EC0E02000
unkown
page read and write
clean
17EC0E02000
unkown
page read and write
clean
7FF56786C000
unkown
page readonly
clean
7FF501F0A000
unkown
page readonly
clean
1CD525B0000
unkown
page readonly
clean
30982FF000
unkown
page read and write
clean
1D8E5C58000
unkown
page read and write
clean
7FF52D31A000
unkown
page readonly
clean
17EC0E00000
unkown
page read and write
clean
17EC09BF000
unkown
page read and write
clean
1CD5260C000
unkown
page read and write
clean
7FF501FA4000
unkown
page readonly
clean
309817F000
unkown
page read and write
clean
7FF52D45A000
unkown
page readonly
clean
42291AC000
unkown
page read and write
clean
7FF52D030000
unkown
page readonly
clean
17EC09A7000
unkown
page read and write
clean
17EBFF40000
heap default
page read and write
clean
7FF52D270000
unkown
page readonly
clean
17EC0974000
unkown
page read and write
clean
17EC0964000
unkown
page read and write
clean
17EC0984000
unkown
page read and write
clean
7FF52D4B4000
unkown
page readonly
clean
1CD5260C000
unkown
page read and write
clean
17EC0964000
unkown
page read and write
clean
4BCCE7B000
unkown
page read and write
clean
17EC00EE000
unkown
page read and write
clean
1D8E5C54000
unkown
page read and write
clean
17EC0974000
unkown
page read and write
clean
7FF567932000
unkown
page readonly
clean
17EC0951000
unkown
page read and write
clean
1CD52624000
unkown
page read and write
clean
4BCD07D000
unkown
page read and write
clean
17EBFF70000
unkown
page read and write
clean
1D8E6600000
unkown
page readonly
clean
17EC0E02000
unkown
page read and write
clean
17EC0971000
unkown
page read and write
clean
1D8E5C3C000
unkown
page read and write
clean
17EC0000000
unkown
page read and write
clean
17EC0973000
unkown
page read and write
clean
7FF501DBB000
unkown
page readonly
clean
1CD52490000
unkown
page readonly
clean
17EC0802000
unkown
page read and write
clean
17EC093C000
unkown
page read and write
clean
1CD52620000
unkown
page read and write
clean
7FF501DA1000
unkown
page readonly
clean
7FF501E0D000
unkown
page readonly
clean
17EC0900000
unkown
page read and write
clean
17EC0943000
unkown
page read and write
clean
17EC0E9B000
unkown
page read and write
clean
7FF501FB1000
unkown
page readonly
clean
17EC0913000
unkown
page read and write
clean
17EC0962000
unkown
page read and write
clean
17EC0108000
unkown
page read and write
clean
7FF501C40000
unkown
page readonly
clean
17EC0986000
unkown
page read and write
clean
1D8E5AB0000
heap private
page read and write
clean
1CD525E0000
heap default
page read and write
clean
7FF52D4C4000
unkown
page readonly
clean
42294FE000
unkown
page read and write
clean
17EC0957000
unkown
page read and write
clean
17EC099B000
unkown
page read and write
clean
17EBFFA0000
unkown
page readonly
clean
7FF56786F000
unkown
page readonly
clean
17EC004F000
unkown
page read and write
clean
4BCC54B000
unkown
page read and write
clean
7FF52D1F0000
unkown
page readonly
clean
17EC09A5000
unkown
page read and write
clean
1D8E5C6E000
unkown
page read and write
clean
7FF56789E000
unkown
page readonly
clean
17EC097C000
unkown
page read and write
clean
17EC00F8000
unkown
page read and write
clean
7FF52D36E000
unkown
page readonly
clean
7FF501D63000
unkown
page readonly
clean
7FF567878000
unkown
page readonly
clean
17EC093B000
unkown
page read and write
clean
7FF501F28000
unkown
page readonly
clean
7FF501F2E000
unkown
page readonly
clean
7FF52D3DC000
unkown
page readonly
clean
1D8E5C5A000
unkown
page read and write
clean
17EBFFD0000
unkown
page readonly
clean
17EC0E9B000
unkown
page read and write
clean
17EC0056000
unkown
page read and write
clean
7FF567840000
unkown
page readonly
clean
7FF52CD71000
unkown
page readonly
clean
17EC0985000
unkown
page read and write
clean
1D8E5C13000
unkown
page read and write
clean
7FF5678AE000
unkown
page readonly
clean
7FF501E2C000
unkown
page readonly
clean
1CD52611000
unkown
page read and write
clean
17EC096D000
unkown
page read and write
clean
17EBFFE0000
unkown
page read and write
clean
7FF501EAC000
unkown
page readonly
clean
7FF52D43F000
unkown
page readonly
clean
17EC09A5000
unkown
page read and write
clean
17EC0960000
unkown
page read and write
clean
7FF52D4D8000
unkown
page readonly
clean
7FF501D11000
unkown
page readonly
clean
7FF501E24000
unkown
page readonly
clean
7FF501EC5000
unkown
page readonly
clean
4229A7C000
unkown
page read and write
clean
7FF52D55A000
unkown
page readonly
clean
17EC00B1000
unkown
page read and write
clean
17EBFFF0000
unkown
page read and write
clean
17EC094E000
unkown
page read and write
clean
7FF501F36000
unkown
page readonly
clean
30981FA000
unkown
page read and write
clean
17EC0978000
unkown
page read and write
clean
7FF52CDC3000
unkown
page readonly
clean
17EC0985000
unkown
page read and write
clean
7FF501EC0000
unkown
page readonly
clean
17EC09A1000
unkown
page read and write
clean
17EC093C000
unkown
page read and write
clean
17EC093B000
unkown
page read and write
clean
17EC09BF000
unkown
page read and write
clean
4229877000
unkown
page read and write
clean
17EC095C000
unkown
page read and write
clean
17EC0965000
unkown
page read and write
clean
7FF52D43B000
unkown
page readonly
clean
1D8E62C0000
unkown
page readonly
clean
7FF52D236000
unkown
page readonly
clean
17EC097A000
unkown
page read and write
clean
1D8E5C92000
unkown
page read and write
clean
7FF52D412000
unkown
page readonly
clean
17EC096D000
unkown
page read and write
clean
7FF567924000
unkown
page readonly
clean
7FF501F3D000
unkown
page readonly
clean
17EC0958000
unkown
page read and write
clean
7FF501FB2000
unkown
page readonly
clean
7FF56751A000
unkown
page readonly
clean
7FF56788A000
unkown
page readonly
clean
4BCCC7E000
unkown
page read and write
clean
309807A000
unkown
page read and write
clean
1D8E5C5F000
unkown
page read and write
clean
17EC0780000
unkown
page readonly
clean
17EC0970000
unkown
page read and write
clean
4BCC5CE000
unkown
page read and write
clean
17EC0113000
unkown
page read and write
clean
1CD525F7000
heap default
page read and write
clean
1D8E6270000
unkown
page read and write
clean
17EC0E02000
unkown
page read and write
clean
7FF567931000
unkown
page readonly
clean
7FF52D561000
unkown
page readonly
clean
7FF52D470000
unkown
page readonly
clean
1CD52618000
unkown
page read and write
clean
7FF567894000
unkown
page readonly
clean
7FF52D378000
unkown
page readonly
clean
17EC0E3C000
unkown
page read and write
clean
17EC00C0000
unkown
page read and write
clean
7FF52D087000
unkown
page readonly
clean
7FF52D3C3000
unkown
page readonly
clean
7FF5678A8000
unkown
page readonly
clean
7FF501EBA000
unkown
page readonly
clean
1CD52606000
unkown
page read and write
clean
7FF52D475000
unkown
page readonly
clean
1D8E5BF0000
unkown
page readonly
clean
4BCC975000
unkown
page read and write
clean
7FF52CFD2000
unkown
page readonly
clean
17EBFFE0000
unkown
page read and write
clean
7FF52CFE2000
unkown
page readonly
clean
17EC09A5000
unkown
page read and write
clean
1CD52560000
unkown
page read and write
clean
17EC0029000
unkown
page read and write
clean
7FF501E13000
unkown
page readonly
clean
7FF5016CA000
unkown
page readonly
clean
17EBFFE0000
unkown
page readonly
clean
7FF501EEF000
unkown
page readonly
clean
17EC095D000
unkown
page read and write
clean
17EC00A7000
unkown
page read and write
clean
7FF501EEC000
unkown
page readonly
clean
7FF52D2A4000
unkown
page readonly
clean
17EC0E02000
unkown
page read and write
clean
17EC0F02000
unkown
page read and write
clean
7FF52D487000
unkown
page readonly
clean
7FF501F14000
unkown
page readonly
clean
17EC0989000
unkown
page read and write
clean
7FF501F39000
unkown
page readonly
clean
17EC097A000
unkown
page read and write
clean
4BCCA78000
unkown
page read and write
clean
17EC09B5000
unkown
page read and write
clean
17EC09A3000
unkown
page read and write
clean
7FF52D44F000
unkown
page readonly
clean
17EC092C000
unkown
page read and write
clean
17EC098C000
unkown
page read and write
clean
7FF52D4E9000
unkown
page readonly
clean
7FF567193000
unkown
page readonly
clean
1D8E5E00000
unkown
page readonly
clean
17EC0730000
unkown
page write copy
clean
7FF501A86000
unkown
page readonly
clean
422967E000
unkown
page read and write
clean
1CD525EB000
heap default
page read and write
clean
17EC0974000
unkown
page read and write
clean
7FF501FAA000
unkown
page readonly
clean
7FF52CFDE000
unkown
page readonly
clean
17EC0E54000
unkown
page read and write
clean
17EC0965000
unkown
page read and write
clean
1D8E5C62000
unkown
page read and write
clean
17EC096B000
unkown
page read and write
clean
7FF52CF4E000
unkown
page readonly
clean
17EC0976000
unkown
page read and write
clean
17EBFFC0000
unkown
page readonly
clean
7FF52D045000
unkown
page readonly
clean
7FF52D3D4000
unkown
page readonly
clean
422947E000
unkown
page read and write
clean
7FF52D410000
unkown
page readonly
clean
7FF52D2C1000
unkown
page readonly
clean
7FF52D14A000
unkown
page readonly
clean
7FF52D22B000
unkown
page readonly
clean
4BCCEFE000
unkown
page read and write
clean
17EBFFE0000
unkown
page read and write
clean
309837C000
unkown
page read and write
clean
17EC09C9000
unkown
page read and write
clean
7FF567845000
unkown
page readonly
clean
17EC0960000
unkown
page read and write
clean
7FF52D4A7000
unkown
page readonly
clean
17EC0200000
unkown
page readonly
clean
17EC0966000
unkown
page read and write
clean
7FF52D46E000
unkown
page readonly
clean
7FF56792A000
unkown
page readonly
clean
17EC0964000
unkown
page read and write
clean
17EC0081000
unkown
page read and write
clean
17EC09A5000
unkown
page read and write
clean
1CD525F6000
unkown
page read and write
clean
17EC0102000
unkown
page read and write
clean
17EC0964000
unkown
page read and write
clean
17EC00DA000
unkown
page read and write
clean
1CD52618000
unkown
page read and write
clean
7FF52D36B000
unkown
page readonly
clean
17EC0051000
unkown
page read and write
clean
7FF501C37000
unkown
page readonly
clean
1D8E5D02000
unkown
page read and write
clean
17EC0070000
unkown
page read and write
clean
17EC0933000
unkown
page read and write
clean
17EC0A00000
unkown
page readonly
clean
4BCCB77000
unkown
page read and write
clean
17EC0944000
unkown
page read and write
clean
7FF52D2A6000
unkown
page readonly
clean
17EC0955000
unkown
page read and write
clean
1CD525C0000
unkown
page readonly
clean
1D8E5C5C000
unkown
page read and write
clean
17EC0E02000
unkown
page read and write
clean
7FF52D562000
unkown
page readonly
clean
7FF52D1E7000
unkown
page readonly
clean
1D8E5C64000
unkown
page read and write
clean
4BCCF7E000
unkown
page read and write
clean
1CD525F2000
unkown
page read and write
clean
7FF52D49F000
unkown
page readonly
clean
17EC0116000
unkown
page read and write
clean
17EC00A7000
unkown
page read and write
clean
4BCD179000
unkown
page read and write
clean
7FF52D554000
unkown
page readonly
clean
17EC094C000
unkown
page read and write
clean
30980FF000
unkown
page read and write
clean
7FF52D4CF000
unkown
page readonly
clean
7FF5678B9000
unkown
page readonly
clean
17EC00E2000
unkown
page read and write
clean
422977B000
unkown
page read and write
clean
7FF52D49C000
unkown
page readonly
clean
7FF501F1F000
unkown
page readonly
clean
1CD5260C000
unkown
page read and write
clean
17EC0984000
unkown
page read and write
clean
7FF52D4DE000
unkown
page readonly
clean
17EC0970000
unkown
page read and write
clean
7FF52CC7A000
unkown
page readonly
clean
17EC096A000
unkown
page read and write
clean
1D8E5D00000
unkown
page read and write
clean
7FF501A95000
unkown
page readonly
clean
17EC0960000
unkown
page read and write
clean
17EC09A5000
unkown
page read and write
clean
7FF567884000
unkown
page readonly
clean
1D8E5C5D000
unkown
page read and write
clean
7FF52D351000
unkown
page readonly
clean
1CD52618000
unkown
page read and write
clean
4BCD27A000
unkown
page read and write
clean
7FF501ECB000
unkown
page readonly
clean
17EBFF60000
unkown
page readonly
clean
7FF501A80000
unkown
page readonly
clean
17EC0965000
unkown
page read and write
clean
1CD52860000
heap private
page read and write
clean
7FF52D036000
unkown
page readonly
clean
4BCCD77000
unkown
page read and write
clean
17EC095A000
unkown
page read and write
clean
7FF567197000
unkown
page readonly
clean
1D8E5B10000
heap default
page read and write
clean
1D8E5C87000
unkown
page read and write
clean
17EC00C7000
unkown
page read and write
clean
17EBFEE0000
heap private
page read and write
clean
17EC1000000
unkown
page readonly
clean
17EC099D000
unkown
page read and write
clean
1CD52580000
unkown
page read and write
clean
17EBFF50000
unkown
page readonly
clean
17EC09B4000
unkown
page read and write
clean
17EC00ED000
unkown
page read and write
clean
7FF52D313000
unkown
page readonly
clean
17EC095A000
unkown
page read and write
clean
1D8E5C6E000
unkown
page read and write
clean
17EC0F00000
unkown
page read and write
clean
1CD52870000
unkown
page readonly
clean
17EC0E3C000
unkown
page read and write
clean
7FF501DBE000
unkown
page readonly
clean
7FF52D45C000
unkown
page readonly
clean
7FF52D444000
unkown
page readonly
clean
7FF501EF7000
unkown
page readonly
clean
17EC003C000
unkown
page read and write
clean
1D8E5C2A000
unkown
page read and write
clean
7FF52CDC7000
unkown
page readonly
clean
17EC09C9000
unkown
page read and write
clean
17EC0013000
unkown
page read and write
clean
17EC095A000
unkown
page read and write
clean
17EC094C000
unkown
page read and write
clean
1CD52607000
unkown
page read and write
clean
17EC004C000
unkown
page read and write
clean
4BCC87E000
unkown
page read and write
clean
17EC0952000
unkown
page read and write
clean
17EC094D000
unkown
page read and write
clean
1D8E5C8E000
unkown
page read and write
clean
7FF52D2B1000
unkown
page readonly
clean
1CD52865000
heap private
page read and write
clean
1D8E5D08000
unkown
page read and write
clean
7FF52D47B000
unkown
page readonly
clean
17EC02D0000
unkown
page readonly
clean
42295F5000
unkown
page read and write
clean
17EC0985000
unkown
page read and write
clean
7FF501F04000
unkown
page readonly
clean
7FF52D3BD000
unkown
page readonly
clean
7FF5678BD000
unkown
page readonly
clean
7FF501ED7000
unkown
page readonly
clean
1D8E6260000
unkown
page readonly
clean
17EC096C000
unkown
page read and write
clean
7FF52D4E6000
unkown
page readonly
clean
7FF501EBE000
unkown
page readonly
clean
1D8E6402000
unkown
page read and write
clean
3098279000
unkown
page read and write
clean
17EC0E02000
unkown
page read and write
clean
1D8E5D13000
unkown
page read and write
clean
17EC095D000
unkown
page read and write
clean
17EC0977000
unkown
page read and write
clean
1D8E5B20000
unkown
page readonly
clean
7FF56784B000
unkown
page readonly
clean
7FF501EAA000
unkown
page readonly
clean
7FF52D4BA000
unkown
page readonly
clean
17EC0973000
unkown
page read and write
clean
There are 344 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink
clean