Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink
|
URL
|
initial url
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\0d5a6a19-9bef-46df-a3f5-68cd76013007.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\3c15b633-f88a-4b73-be51-23868c220e8d.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\32fca649-82ef-4bb7-9d5d-c624b2ed6d19.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5f59b313-14ee-4101-b6f2-2625e8f7f9aa.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old. (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\56e67e1a4a50be0f_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\6e7f394632e47430_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8bf0835732d01051_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8e98f4b7848fbe37_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\99de76cda7e7f6ae_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\a56ee0ddb5db651b_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\dc3751d27b8cbd66_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\temp-index
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-index. (copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
|
SQLite 3.x database, last written using SQLite version 3032001
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons
|
SQLite 3.x database, last written using SQLite version 3032001
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Session0 (copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last TabsOC (copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old. (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State. (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
|
SQLite 3.x database, last written using SQLite version 3032001
|
modified
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL-journal
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferenceswe (copy)
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old. (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\6eabefa4-0769-4c0c-85c5-f1faea145afe.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG.old
(copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent
Stateod (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG.old
(copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG.old.
(copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\2b7b6dad-c7da-4f46-afd4-a7fca5b369ba.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.old
(copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent
Stateod (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.old
(copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG.old.
(copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.olds
(copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a5f5c538-0be9-4615-af46-693daeeade15.tmp
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ad05ab0c-4d15-4ffe-a2ef-8e8a734520a3.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d7e666ce-745c-4ee3-b23d-d599523309b5.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
modified
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old. (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000004
|
MPEG-4 LOAS
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e56da246-8455-4edd-b13a-53955359f1ac.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\f6f164b0-095e-40fd-a079-f867cab90773.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.oldE (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local StateTM (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\e05e02b6-f162-4417-af40-57678a30a893.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\46203416-4e32-432b-87ac-da1978496b71.tmp
|
Google Chrome extension, version 3
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\a571b8d9-86a6-420f-8c75-3f25be68da97.tmp
|
Google Chrome extension, version 3
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\browser-sslkeys.log
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\dfb6c2da-f77b-4736-b83a-16e40beb3d98.tmp
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\fda7d97e-d53c-47af-a430-cfc234668025.tmp
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\am\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ar\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\bg\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\bn\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ca\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\cs\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\da\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\de\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\el\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\en\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\es\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\et\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fa\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fi\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fil\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\fr\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\gu\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\hi\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\hr\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\hu\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\id\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\it\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ja\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\kn\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ko\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\lt\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\lv\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ml\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\mr\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ms\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\nb\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\nl\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\pl\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\pt\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ro\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ru\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sk\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sl\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sr\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sv\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\sw\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\ta\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\te\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\th\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\tr\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\uk\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\vi\messages.json
|
UTF-8 Unicode text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\zh\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\_locales\zh_TW\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\CRX_INSTALL\manifest.json
|
ASCII text, with very long lines, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1020891473\a571b8d9-86a6-420f-8c75-3f25be68da97.tmp
|
Google Chrome extension, version 3
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\46203416-4e32-432b-87ac-da1978496b71.tmp
|
Google Chrome extension, version 3
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\bg\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ca\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\cs\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\da\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\de\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\el\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\en\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\en_GB\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\es\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\es_419\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\et\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\fi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\fil\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\fr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\hi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\hr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\hu\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\id\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\it\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ja\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ko\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\lt\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\lv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\nb\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\nl\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\pl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\pt_BR\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\pt_PT\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ro\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\ru\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\sv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\th\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\tr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\uk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\vi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\zh_CN\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\_locales\zh_TW\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\images\icon_128.png
|
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\images\icon_16.png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir6624_1827314503\CRX_INSTALL\manifest.json
|
ASCII text, with CRLF line terminators
|
dropped
|
There are 191 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink'
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1508,7393693506506586080,11924844796807865969,131072
--lang=en-GB --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1768 /prefetch:8
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://canva.com/
|
unknown
|
||
https://dns.google
|
unknown
|
||
https://ogs.google.com
|
unknown
|
||
https://static.canva.com/static/lib/underscore-1.8.3.min.js
|
unknown
|
||
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_cam
|
unknown
|
||
https://a.nel.cloudflare.com/report/v3?s=vTxJLcywg59S05ew7XVWhh%2B0FrXv2LtLZBFsEpV79t6xVcIzwW7zCEadC
|
unknown
|
||
https://support.google.com/chromecast/troubleshooter/2995236
|
unknown
|
||
https://static.canva.com/static/lib/jquery-1.8.3.min.2.js
|
unknown
|
||
https://canva.com/k
|
unknown
|
||
https://play.google.com
|
unknown
|
||
https://payments.google.com/payments/v4/js/integrator.js
|
unknown
|
||
https://www.google.com;
|
unknown
|
||
https://www.canva.com
|
unknown
|
||
https://hangouts.google.com/
|
unknown
|
||
https://a.nel.cloudflare.com/report/v3?s=3H5wI1utlz8TSvWfEbFvjvXEuXlKRs49agdLRsghAV5GiLvaMBm7Wkh%2B3
|
unknown
|
||
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink
|
|||
https://a.nel.cloudflare.com/report/v3?s=UlHNxrg8IER2ENUk%2BxcX6KLR1Bo%2FXbtmxTJbPJzzxWe28tdyQFKcdpj
|
unknown
|
||
https://static.cloudflareinsights.com/beacon.min.js
|
unknown
|
||
https://sandbox.google.com/payments/v4/js/integrator.js
|
unknown
|
||
https://static.canva.com/static/lib/segment-snippet-4.1.0.min.js
|
unknown
|
||
https://www.google.com
|
unknown
|
||
https://static.canva.com/static/r/20210803-02/js/23BzzNosJDRE06_zR1W5uA.js
|
unknown
|
||
https://static.canva.com/static/lib/cl/cl-0.4.3.min.js
|
unknown
|
||
https://static.canva.com/static/lib/bluebird-2.3.11.min.js
|
unknown
|
||
https://accounts.google.com
|
unknown
|
||
https://support.google.com/chromecast/answer/2998456
|
unknown
|
||
https://clients2.googleusercontent.com
|
unknown
|
||
https://apis.google.com
|
unknown
|
||
https://canva.com/7
|
unknown
|
||
https://static.canva.com/static/images/favicon.ico
|
unknown
|
||
https://www.google.com/
|
unknown
|
||
https://feedback.googleusercontent.com
|
unknown
|
||
https://clients2.google.com
|
unknown
|
||
https://clients2.google.com/service/update2/crx
|
unknown
|
There are 24 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
gstaticadssl.l.google.com
|
216.58.198.3
|
||
a.nel.cloudflare.com
|
35.190.80.1
|
||
static.cloudflareinsights.com
|
104.16.94.65
|
||
accounts.google.com
|
216.58.205.77
|
||
static.canva.com
|
104.17.114.17
|
||
cl.canva.com
|
104.17.115.17
|
||
clients.l.google.com
|
216.58.208.174
|
||
www.canva.com
|
104.17.115.17
|
||
googlehosted.l.googleusercontent.com
|
216.58.208.129
|
||
clients2.googleusercontent.com
|
unknown
|
||
clients2.google.com
|
unknown
|
There are 1 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
216.58.208.174
|
clients.l.google.com
|
United States
|
||
192.168.2.1
|
unknown
|
unknown
|
||
104.17.115.17
|
cl.canva.com
|
United States
|
||
104.17.114.17
|
static.canva.com
|
United States
|
||
216.58.198.3
|
gstaticadssl.l.google.com
|
United States
|
||
216.58.205.77
|
accounts.google.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
216.58.208.129
|
googlehosted.l.googleusercontent.com
|
United States
|
||
35.190.80.1
|
a.nel.cloudflare.com
|
United States
|
||
127.0.0.1
|
unknown
|
unknown
|
||
104.16.94.65
|
static.cloudflareinsights.com
|
United States
|
There are 1 hidden IPs, click here to show them.
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
S-1-5-21-3853321935-2125563209-4053062332-1002
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
ahfgeienlihckogmohjhadlkjgocpleb
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
gdaefkejpgkiemlaofpalmlakkmbjdnl
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
gfdkimpbcpahaombhbimeihdjnejgicl
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
kmendfapggjehodndflmmgagdbamhnfd
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
mfehgcgbbipciphmccgaenjidiccnmng
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
mhjfbmdgcfjbbpaeojofohoefgiehjai
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
neajdppkdcdipfabeoofebfddakdcjhd
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
nkeimhogjdpnpccoofpliimaahmaaome
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
pkedcjkdefgpdelpbcmbmeomcjbeemfm
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
prefs.preference_reset_time
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
gfdkimpbcpahaombhbimeihdjnejgicl
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
state
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
StatusCodes
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
StatusCodes
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
state
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
dr
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
software_reporter.reporting
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
module_blacklist_cache_md5_digest
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
media.storage_id_salt
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
google.services.last_account_id
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
google.services.account_id
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
software_reporter.prompt_seed
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
settings_reset_prompt.last_triggered_for_homepage
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
default_search_provider_data.template_url_data
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
safebrowsing.incidents_sent
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
pinned_tabs
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
search_provider_overrides
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
settings_reset_prompt.last_triggered_for_default_search
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
prefs.preference_reset_time
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
google.services.last_username
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
session.startup_urls
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
session.restore_on_startup
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
software_reporter.prompt_version
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
settings_reset_prompt.last_triggered_for_startup_urls
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
settings_reset_prompt.prompt_wave
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
homepage
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
homepage_is_newtabpage
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
browser.show_home_button
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
user_experience_metrics.stability.exited_cleanly
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
lastrun
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
Blob
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
Blob
|
There are 35 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7FF52D085000
|
unkown
|
page readonly
|
||
17EC0974000
|
unkown
|
page read and write
|
||
17EC0971000
|
unkown
|
page read and write
|
||
1CD525D0000
|
unkown
|
page read and write
|
||
1CD52611000
|
unkown
|
page read and write
|
||
7FF52D373000
|
unkown
|
page readonly
|
||
17EC0964000
|
unkown
|
page read and write
|
||
17EC0975000
|
unkown
|
page read and write
|
||
1D8E5C00000
|
unkown
|
page read and write
|
||
17EC0989000
|
unkown
|
page read and write
|
||
7FF52D46A000
|
unkown
|
page readonly
|
||
422997F000
|
unkown
|
page read and write
|
||
17EC0E02000
|
unkown
|
page read and write
|
||
17EC0E02000
|
unkown
|
page read and write
|
||
7FF56786C000
|
unkown
|
page readonly
|
||
7FF501F0A000
|
unkown
|
page readonly
|
||
1CD525B0000
|
unkown
|
page readonly
|
||
30982FF000
|
unkown
|
page read and write
|
||
1D8E5C58000
|
unkown
|
page read and write
|
||
7FF52D31A000
|
unkown
|
page readonly
|
||
17EC0E00000
|
unkown
|
page read and write
|
||
17EC09BF000
|
unkown
|
page read and write
|
||
1CD5260C000
|
unkown
|
page read and write
|
||
7FF501FA4000
|
unkown
|
page readonly
|
||
309817F000
|
unkown
|
page read and write
|
||
7FF52D45A000
|
unkown
|
page readonly
|
||
42291AC000
|
unkown
|
page read and write
|
||
7FF52D030000
|
unkown
|
page readonly
|
||
17EC09A7000
|
unkown
|
page read and write
|
||
17EBFF40000
|
heap default
|
page read and write
|
||
7FF52D270000
|
unkown
|
page readonly
|
||
17EC0974000
|
unkown
|
page read and write
|
||
17EC0964000
|
unkown
|
page read and write
|
||
17EC0984000
|
unkown
|
page read and write
|
||
7FF52D4B4000
|
unkown
|
page readonly
|
||
1CD5260C000
|
unkown
|
page read and write
|
||
17EC0964000
|
unkown
|
page read and write
|
||
4BCCE7B000
|
unkown
|
page read and write
|
||
17EC00EE000
|
unkown
|
page read and write
|
||
1D8E5C54000
|
unkown
|
page read and write
|
||
17EC0974000
|
unkown
|
page read and write
|
||
7FF567932000
|
unkown
|
page readonly
|
||
17EC0951000
|
unkown
|
page read and write
|
||
1CD52624000
|
unkown
|
page read and write
|
||
4BCD07D000
|
unkown
|
page read and write
|
||
17EBFF70000
|
unkown
|
page read and write
|
||
1D8E6600000
|
unkown
|
page readonly
|
||
17EC0E02000
|
unkown
|
page read and write
|
||
17EC0971000
|
unkown
|
page read and write
|
||
1D8E5C3C000
|
unkown
|
page read and write
|
||
17EC0000000
|
unkown
|
page read and write
|
||
17EC0973000
|
unkown
|
page read and write
|
||
7FF501DBB000
|
unkown
|
page readonly
|
||
1CD52490000
|
unkown
|
page readonly
|
||
17EC0802000
|
unkown
|
page read and write
|
||
17EC093C000
|
unkown
|
page read and write
|
||
1CD52620000
|
unkown
|
page read and write
|
||
7FF501DA1000
|
unkown
|
page readonly
|
||
7FF501E0D000
|
unkown
|
page readonly
|
||
17EC0900000
|
unkown
|
page read and write
|
||
17EC0943000
|
unkown
|
page read and write
|
||
17EC0E9B000
|
unkown
|
page read and write
|
||
7FF501FB1000
|
unkown
|
page readonly
|
||
17EC0913000
|
unkown
|
page read and write
|
||
17EC0962000
|
unkown
|
page read and write
|
||
17EC0108000
|
unkown
|
page read and write
|
||
7FF501C40000
|
unkown
|
page readonly
|
||
17EC0986000
|
unkown
|
page read and write
|
||
1D8E5AB0000
|
heap private
|
page read and write
|
||
1CD525E0000
|
heap default
|
page read and write
|
||
7FF52D4C4000
|
unkown
|
page readonly
|
||
42294FE000
|
unkown
|
page read and write
|
||
17EC0957000
|
unkown
|
page read and write
|
||
17EC099B000
|
unkown
|
page read and write
|
||
17EBFFA0000
|
unkown
|
page readonly
|
||
7FF56786F000
|
unkown
|
page readonly
|
||
17EC004F000
|
unkown
|
page read and write
|
||
4BCC54B000
|
unkown
|
page read and write
|
||
7FF52D1F0000
|
unkown
|
page readonly
|
||
17EC09A5000
|
unkown
|
page read and write
|
||
1D8E5C6E000
|
unkown
|
page read and write
|
||
7FF56789E000
|
unkown
|
page readonly
|
||
17EC097C000
|
unkown
|
page read and write
|
||
17EC00F8000
|
unkown
|
page read and write
|
||
7FF52D36E000
|
unkown
|
page readonly
|
||
7FF501D63000
|
unkown
|
page readonly
|
||
7FF567878000
|
unkown
|
page readonly
|
||
17EC093B000
|
unkown
|
page read and write
|
||
7FF501F28000
|
unkown
|
page readonly
|
||
7FF501F2E000
|
unkown
|
page readonly
|
||
7FF52D3DC000
|
unkown
|
page readonly
|
||
1D8E5C5A000
|
unkown
|
page read and write
|
||
17EBFFD0000
|
unkown
|
page readonly
|
||
17EC0E9B000
|
unkown
|
page read and write
|
||
17EC0056000
|
unkown
|
page read and write
|
||
7FF567840000
|
unkown
|
page readonly
|
||
7FF52CD71000
|
unkown
|
page readonly
|
||
17EC0985000
|
unkown
|
page read and write
|
||
1D8E5C13000
|
unkown
|
page read and write
|
||
7FF5678AE000
|
unkown
|
page readonly
|
||
7FF501E2C000
|
unkown
|
page readonly
|
||
1CD52611000
|
unkown
|
page read and write
|
||
17EC096D000
|
unkown
|
page read and write
|
||
17EBFFE0000
|
unkown
|
page read and write
|
||
7FF501EAC000
|
unkown
|
page readonly
|
||
7FF52D43F000
|
unkown
|
page readonly
|
||
17EC09A5000
|
unkown
|
page read and write
|
||
17EC0960000
|
unkown
|
page read and write
|
||
7FF52D4D8000
|
unkown
|
page readonly
|
||
7FF501D11000
|
unkown
|
page readonly
|
||
7FF501E24000
|
unkown
|
page readonly
|
||
7FF501EC5000
|
unkown
|
page readonly
|
||
4229A7C000
|
unkown
|
page read and write
|
||
7FF52D55A000
|
unkown
|
page readonly
|
||
17EC00B1000
|
unkown
|
page read and write
|
||
17EBFFF0000
|
unkown
|
page read and write
|
||
17EC094E000
|
unkown
|
page read and write
|
||
7FF501F36000
|
unkown
|
page readonly
|
||
30981FA000
|
unkown
|
page read and write
|
||
17EC0978000
|
unkown
|
page read and write
|
||
7FF52CDC3000
|
unkown
|
page readonly
|
||
17EC0985000
|
unkown
|
page read and write
|
||
7FF501EC0000
|
unkown
|
page readonly
|
||
17EC09A1000
|
unkown
|
page read and write
|
||
17EC093C000
|
unkown
|
page read and write
|
||
17EC093B000
|
unkown
|
page read and write
|
||
17EC09BF000
|
unkown
|
page read and write
|
||
4229877000
|
unkown
|
page read and write
|
||
17EC095C000
|
unkown
|
page read and write
|
||
17EC0965000
|
unkown
|
page read and write
|
||
7FF52D43B000
|
unkown
|
page readonly
|
||
1D8E62C0000
|
unkown
|
page readonly
|
||
7FF52D236000
|
unkown
|
page readonly
|
||
17EC097A000
|
unkown
|
page read and write
|
||
1D8E5C92000
|
unkown
|
page read and write
|
||
7FF52D412000
|
unkown
|
page readonly
|
||
17EC096D000
|
unkown
|
page read and write
|
||
7FF567924000
|
unkown
|
page readonly
|
||
7FF501F3D000
|
unkown
|
page readonly
|
||
17EC0958000
|
unkown
|
page read and write
|
||
7FF501FB2000
|
unkown
|
page readonly
|
||
7FF56751A000
|
unkown
|
page readonly
|
||
7FF56788A000
|
unkown
|
page readonly
|
||
4BCCC7E000
|
unkown
|
page read and write
|
||
309807A000
|
unkown
|
page read and write
|
||
1D8E5C5F000
|
unkown
|
page read and write
|
||
17EC0780000
|
unkown
|
page readonly
|
||
17EC0970000
|
unkown
|
page read and write
|
||
4BCC5CE000
|
unkown
|
page read and write
|
||
17EC0113000
|
unkown
|
page read and write
|
||
1CD525F7000
|
heap default
|
page read and write
|
||
1D8E6270000
|
unkown
|
page read and write
|
||
17EC0E02000
|
unkown
|
page read and write
|
||
7FF567931000
|
unkown
|
page readonly
|
||
7FF52D561000
|
unkown
|
page readonly
|
||
7FF52D470000
|
unkown
|
page readonly
|
||
1CD52618000
|
unkown
|
page read and write
|
||
7FF567894000
|
unkown
|
page readonly
|
||
7FF52D378000
|
unkown
|
page readonly
|
||
17EC0E3C000
|
unkown
|
page read and write
|
||
17EC00C0000
|
unkown
|
page read and write
|
||
7FF52D087000
|
unkown
|
page readonly
|
||
7FF52D3C3000
|
unkown
|
page readonly
|
||
7FF5678A8000
|
unkown
|
page readonly
|
||
7FF501EBA000
|
unkown
|
page readonly
|
||
1CD52606000
|
unkown
|
page read and write
|
||
7FF52D475000
|
unkown
|
page readonly
|
||
1D8E5BF0000
|
unkown
|
page readonly
|
||
4BCC975000
|
unkown
|
page read and write
|
||
7FF52CFD2000
|
unkown
|
page readonly
|
||
17EBFFE0000
|
unkown
|
page read and write
|
||
7FF52CFE2000
|
unkown
|
page readonly
|
||
17EC09A5000
|
unkown
|
page read and write
|
||
1CD52560000
|
unkown
|
page read and write
|
||
17EC0029000
|
unkown
|
page read and write
|
||
7FF501E13000
|
unkown
|
page readonly
|
||
7FF5016CA000
|
unkown
|
page readonly
|
||
17EBFFE0000
|
unkown
|
page readonly
|
||
7FF501EEF000
|
unkown
|
page readonly
|
||
17EC095D000
|
unkown
|
page read and write
|
||
17EC00A7000
|
unkown
|
page read and write
|
||
7FF501EEC000
|
unkown
|
page readonly
|
||
7FF52D2A4000
|
unkown
|
page readonly
|
||
17EC0E02000
|
unkown
|
page read and write
|
||
17EC0F02000
|
unkown
|
page read and write
|
||
7FF52D487000
|
unkown
|
page readonly
|
||
7FF501F14000
|
unkown
|
page readonly
|
||
17EC0989000
|
unkown
|
page read and write
|
||
7FF501F39000
|
unkown
|
page readonly
|
||
17EC097A000
|
unkown
|
page read and write
|
||
4BCCA78000
|
unkown
|
page read and write
|
||
17EC09B5000
|
unkown
|
page read and write
|
||
17EC09A3000
|
unkown
|
page read and write
|
||
7FF52D44F000
|
unkown
|
page readonly
|
||
17EC092C000
|
unkown
|
page read and write
|
||
17EC098C000
|
unkown
|
page read and write
|
||
7FF52D4E9000
|
unkown
|
page readonly
|
||
7FF567193000
|
unkown
|
page readonly
|
||
1D8E5E00000
|
unkown
|
page readonly
|
||
17EC0730000
|
unkown
|
page write copy
|
||
7FF501A86000
|
unkown
|
page readonly
|
||
422967E000
|
unkown
|
page read and write
|
||
1CD525EB000
|
heap default
|
page read and write
|
||
17EC0974000
|
unkown
|
page read and write
|
||
7FF501FAA000
|
unkown
|
page readonly
|
||
7FF52CFDE000
|
unkown
|
page readonly
|
||
17EC0E54000
|
unkown
|
page read and write
|
||
17EC0965000
|
unkown
|
page read and write
|
||
1D8E5C62000
|
unkown
|
page read and write
|
||
17EC096B000
|
unkown
|
page read and write
|
||
7FF52CF4E000
|
unkown
|
page readonly
|
||
17EC0976000
|
unkown
|
page read and write
|
||
17EBFFC0000
|
unkown
|
page readonly
|
||
7FF52D045000
|
unkown
|
page readonly
|
||
7FF52D3D4000
|
unkown
|
page readonly
|
||
422947E000
|
unkown
|
page read and write
|
||
7FF52D410000
|
unkown
|
page readonly
|
||
7FF52D2C1000
|
unkown
|
page readonly
|
||
7FF52D14A000
|
unkown
|
page readonly
|
||
7FF52D22B000
|
unkown
|
page readonly
|
||
4BCCEFE000
|
unkown
|
page read and write
|
||
17EBFFE0000
|
unkown
|
page read and write
|
||
309837C000
|
unkown
|
page read and write
|
||
17EC09C9000
|
unkown
|
page read and write
|
||
7FF567845000
|
unkown
|
page readonly
|
||
17EC0960000
|
unkown
|
page read and write
|
||
7FF52D4A7000
|
unkown
|
page readonly
|
||
17EC0200000
|
unkown
|
page readonly
|
||
17EC0966000
|
unkown
|
page read and write
|
||
7FF52D46E000
|
unkown
|
page readonly
|
||
7FF56792A000
|
unkown
|
page readonly
|
||
17EC0964000
|
unkown
|
page read and write
|
||
17EC0081000
|
unkown
|
page read and write
|
||
17EC09A5000
|
unkown
|
page read and write
|
||
1CD525F6000
|
unkown
|
page read and write
|
||
17EC0102000
|
unkown
|
page read and write
|
||
17EC0964000
|
unkown
|
page read and write
|
||
17EC00DA000
|
unkown
|
page read and write
|
||
1CD52618000
|
unkown
|
page read and write
|
||
7FF52D36B000
|
unkown
|
page readonly
|
||
17EC0051000
|
unkown
|
page read and write
|
||
7FF501C37000
|
unkown
|
page readonly
|
||
1D8E5D02000
|
unkown
|
page read and write
|
||
17EC0070000
|
unkown
|
page read and write
|
||
17EC0933000
|
unkown
|
page read and write
|
||
17EC0A00000
|
unkown
|
page readonly
|
||
4BCCB77000
|
unkown
|
page read and write
|
||
17EC0944000
|
unkown
|
page read and write
|
||
7FF52D2A6000
|
unkown
|
page readonly
|
||
17EC0955000
|
unkown
|
page read and write
|
||
1CD525C0000
|
unkown
|
page readonly
|
||
1D8E5C5C000
|
unkown
|
page read and write
|
||
17EC0E02000
|
unkown
|
page read and write
|
||
7FF52D562000
|
unkown
|
page readonly
|
||
7FF52D1E7000
|
unkown
|
page readonly
|
||
1D8E5C64000
|
unkown
|
page read and write
|
||
4BCCF7E000
|
unkown
|
page read and write
|
||
1CD525F2000
|
unkown
|
page read and write
|
||
7FF52D49F000
|
unkown
|
page readonly
|
||
17EC0116000
|
unkown
|
page read and write
|
||
17EC00A7000
|
unkown
|
page read and write
|
||
4BCD179000
|
unkown
|
page read and write
|
||
7FF52D554000
|
unkown
|
page readonly
|
||
17EC094C000
|
unkown
|
page read and write
|
||
30980FF000
|
unkown
|
page read and write
|
||
7FF52D4CF000
|
unkown
|
page readonly
|
||
7FF5678B9000
|
unkown
|
page readonly
|
||
17EC00E2000
|
unkown
|
page read and write
|
||
422977B000
|
unkown
|
page read and write
|
||
7FF52D49C000
|
unkown
|
page readonly
|
||
7FF501F1F000
|
unkown
|
page readonly
|
||
1CD5260C000
|
unkown
|
page read and write
|
||
17EC0984000
|
unkown
|
page read and write
|
||
7FF52D4DE000
|
unkown
|
page readonly
|
||
17EC0970000
|
unkown
|
page read and write
|
||
7FF52CC7A000
|
unkown
|
page readonly
|
||
17EC096A000
|
unkown
|
page read and write
|
||
1D8E5D00000
|
unkown
|
page read and write
|
||
7FF501A95000
|
unkown
|
page readonly
|
||
17EC0960000
|
unkown
|
page read and write
|
||
17EC09A5000
|
unkown
|
page read and write
|
||
7FF567884000
|
unkown
|
page readonly
|
||
1D8E5C5D000
|
unkown
|
page read and write
|
||
7FF52D351000
|
unkown
|
page readonly
|
||
1CD52618000
|
unkown
|
page read and write
|
||
4BCD27A000
|
unkown
|
page read and write
|
||
7FF501ECB000
|
unkown
|
page readonly
|
||
17EBFF60000
|
unkown
|
page readonly
|
||
7FF501A80000
|
unkown
|
page readonly
|
||
17EC0965000
|
unkown
|
page read and write
|
||
1CD52860000
|
heap private
|
page read and write
|
||
7FF52D036000
|
unkown
|
page readonly
|
||
4BCCD77000
|
unkown
|
page read and write
|
||
17EC095A000
|
unkown
|
page read and write
|
||
7FF567197000
|
unkown
|
page readonly
|
||
1D8E5B10000
|
heap default
|
page read and write
|
||
1D8E5C87000
|
unkown
|
page read and write
|
||
17EC00C7000
|
unkown
|
page read and write
|
||
17EBFEE0000
|
heap private
|
page read and write
|
||
17EC1000000
|
unkown
|
page readonly
|
||
17EC099D000
|
unkown
|
page read and write
|
||
1CD52580000
|
unkown
|
page read and write
|
||
17EBFF50000
|
unkown
|
page readonly
|
||
17EC09B4000
|
unkown
|
page read and write
|
||
17EC00ED000
|
unkown
|
page read and write
|
||
7FF52D313000
|
unkown
|
page readonly
|
||
17EC095A000
|
unkown
|
page read and write
|
||
1D8E5C6E000
|
unkown
|
page read and write
|
||
17EC0F00000
|
unkown
|
page read and write
|
||
1CD52870000
|
unkown
|
page readonly
|
||
17EC0E3C000
|
unkown
|
page read and write
|
||
7FF501DBE000
|
unkown
|
page readonly
|
||
7FF52D45C000
|
unkown
|
page readonly
|
||
7FF52D444000
|
unkown
|
page readonly
|
||
7FF501EF7000
|
unkown
|
page readonly
|
||
17EC003C000
|
unkown
|
page read and write
|
||
1D8E5C2A000
|
unkown
|
page read and write
|
||
7FF52CDC7000
|
unkown
|
page readonly
|
||
17EC09C9000
|
unkown
|
page read and write
|
||
17EC0013000
|
unkown
|
page read and write
|
||
17EC095A000
|
unkown
|
page read and write
|
||
17EC094C000
|
unkown
|
page read and write
|
||
1CD52607000
|
unkown
|
page read and write
|
||
17EC004C000
|
unkown
|
page read and write
|
||
4BCC87E000
|
unkown
|
page read and write
|
||
17EC0952000
|
unkown
|
page read and write
|
||
17EC094D000
|
unkown
|
page read and write
|
||
1D8E5C8E000
|
unkown
|
page read and write
|
||
7FF52D2B1000
|
unkown
|
page readonly
|
||
1CD52865000
|
heap private
|
page read and write
|
||
1D8E5D08000
|
unkown
|
page read and write
|
||
7FF52D47B000
|
unkown
|
page readonly
|
||
17EC02D0000
|
unkown
|
page readonly
|
||
42295F5000
|
unkown
|
page read and write
|
||
17EC0985000
|
unkown
|
page read and write
|
||
7FF501F04000
|
unkown
|
page readonly
|
||
7FF52D3BD000
|
unkown
|
page readonly
|
||
7FF5678BD000
|
unkown
|
page readonly
|
||
7FF501ED7000
|
unkown
|
page readonly
|
||
1D8E6260000
|
unkown
|
page readonly
|
||
17EC096C000
|
unkown
|
page read and write
|
||
7FF52D4E6000
|
unkown
|
page readonly
|
||
7FF501EBE000
|
unkown
|
page readonly
|
||
1D8E6402000
|
unkown
|
page read and write
|
||
3098279000
|
unkown
|
page read and write
|
||
17EC0E02000
|
unkown
|
page read and write
|
||
1D8E5D13000
|
unkown
|
page read and write
|
||
17EC095D000
|
unkown
|
page read and write
|
||
17EC0977000
|
unkown
|
page read and write
|
||
1D8E5B20000
|
unkown
|
page readonly
|
||
7FF56784B000
|
unkown
|
page readonly
|
||
7FF501EAA000
|
unkown
|
page readonly
|
||
7FF52D4BA000
|
unkown
|
page readonly
|
||
17EC0973000
|
unkown
|
page read and write
|
There are 344 hidden memdumps, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://www.canva.com/design/DAEl-R1jp6Q/7tYJcxXWl2osP9-56-X6pQ/view?utm_content=DAEl-R1jp6Q&utm_campaign=designshare&utm_medium=link&utm_source=publishsharelink
|