Loading ...

Play interactive tourEdit tour

Windows Analysis Report https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx

Overview

General Information

Sample URL:https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx
Analysis ID:458982
Infos:

Most interesting Screenshot:

Errors
  • URL not reachable

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:60%

Signatures

No high impact signatures.

Classification

Analysis Advice

Joe Sandbox was unable to browse the URL (domain or webserver down or HTTPS issue), try to browse the URL again later
Uses HTTPS for network communication, use the 'Proxy HTTPS (port 443) to read its encrypted data' cookbook for further analysis

Process Tree

  • System is w10x64
  • chrome.exe (PID: 2696 cmdline: 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx' MD5: C139654B5C1438A95B321BB01AD63EF6)
    • chrome.exe (PID: 4424 cmdline: 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,13672721571603381085,4833477021421495498,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1708 /prefetch:8 MD5: C139654B5C1438A95B321BB01AD63EF6)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdicJump to behavior
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: 77EC63BDA74BD0D0E0426DC8F8008506.1.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, manifest.json0.0.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://accounts.google.com
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, manifest.json0.0.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://apis.google.com
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.drString found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.0.drString found in binary or memory: https://content.googleapis.com
Source: Reporting and NEL.1.drString found in binary or memory: https://csp.withgoogle.com/csp/report-to/downloads-lorry
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, 7955c7de-2189-4b50-b1c2-53a20e7e6cda.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://dns.google
Source: Current Session.0.drString found in binary or memory: https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx
Source: manifest.json0.0.drString found in binary or memory: https://feedback.googleusercontent.com
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.drString found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.drString found in binary or memory: https://fonts.googleapis.com;
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.drString found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.0.drString found in binary or memory: https://hangouts.google.com/
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://ogs.google.com
Source: manifest.json.0.drString found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://play.google.com
Source: f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://r3---sn-5hneknee.gvt1.com
Source: f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://redirector.gvt1.com
Source: manifest.json.0.drString found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.drString found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.drString found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, manifest.json0.0.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://www.google.com
Source: manifest.json.0.drString found in binary or memory: https://www.google.com/
Source: manifest.json0.0.drString found in binary or memory: https://www.google.com;
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.drString found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.drString found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drString found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.drString found in binary or memory: https://www.gstatic.com;
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: classification engineClassification label: unknown0.win@27/177@5/7
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-610A3F62-A88.pmaJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Local\Temp\cc0edc97-816f-4b82-8d0c-35136c50e2cb.tmpJump to behavior
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx'
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,13672721571603381085,4833477021421495498,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1708 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,13672721571603381085,4833477021421495498,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1708 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\DictionariesJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeDirectory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdicJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management InstrumentationPath InterceptionProcess Injection1Masquerading3OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx0%Avira URL Cloudsafe

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

SourceDetectionScannerLabelLink
https://dns.google0%URL Reputationsafe
https://www.google.com;0%Avira URL Cloudsafe
https://csp.withgoogle.com/csp/report-to/downloads-lorry0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
dw.myemedapps.com
206.82.195.200
truefalse
    unknown
    accounts.google.com
    216.58.205.77
    truefalse
      high
      clients.l.google.com
      216.58.208.174
      truefalse
        high
        googlehosted.l.googleusercontent.com
        216.58.208.161
        truefalse
          high
          clients2.googleusercontent.com
          unknown
          unknownfalse
            high
            clients2.google.com
            unknown
            unknownfalse
              high

              URLs from Memory and Binaries

              NameSourceMaliciousAntivirus DetectionReputation
              https://www.google.com0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, manifest.json0.0.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                high
                https://dns.google0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, 7955c7de-2189-4b50-b1c2-53a20e7e6cda.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                • URL Reputation: safe
                unknown
                https://ogs.google.com0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                  high
                  https://support.google.com/chromecast/troubleshooter/2995236messages.json41.0.drfalse
                    high
                    https://play.google.com0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                      high
                      https://accounts.google.com0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, manifest.json0.0.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                        high
                        https://payments.google.com/payments/v4/js/integrator.jsmanifest.json.0.drfalse
                          high
                          https://www.google.com;manifest.json0.0.drfalse
                          • Avira URL Cloud: safe
                          low
                          https://support.google.com/chromecast/answer/2998456messages.json41.0.drfalse
                            high
                            https://hangouts.google.com/manifest.json0.0.drfalse
                              high
                              https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspxCurrent Session.0.drfalse
                                unknown
                                https://clients2.googleusercontent.com0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                                  high
                                  https://apis.google.com0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, manifest.json0.0.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                                    high
                                    https://sandbox.google.com/payments/v4/js/integrator.jsmanifest.json.0.drfalse
                                      high
                                      https://www.google.com/manifest.json.0.drfalse
                                        high
                                        https://csp.withgoogle.com/csp/report-to/downloads-lorryReporting and NEL.1.drfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://feedback.googleusercontent.commanifest.json0.0.drfalse
                                          high
                                          https://clients2.google.com0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp.1.dr, f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp.1.drfalse
                                            high
                                            https://clients2.google.com/service/update2/crxmanifest.json0.0.drfalse
                                              high

                                              Contacted IPs

                                              • No. of IPs < 25%
                                              • 25% < No. of IPs < 50%
                                              • 50% < No. of IPs < 75%
                                              • 75% < No. of IPs

                                              Public

                                              IPDomainCountryFlagASNASN NameMalicious
                                              216.58.208.161
                                              googlehosted.l.googleusercontent.comUnited States
                                              15169GOOGLEUSfalse
                                              216.58.208.174
                                              clients.l.google.comUnited States
                                              15169GOOGLEUSfalse
                                              216.58.205.77
                                              accounts.google.comUnited States
                                              15169GOOGLEUSfalse
                                              239.255.255.250
                                              unknownReserved
                                              unknownunknownfalse
                                              206.82.195.200
                                              dw.myemedapps.comUnited States
                                              5693LATISYS-IRVINEUSfalse

                                              Private

                                              IP
                                              192.168.2.1
                                              127.0.0.1

                                              General Information

                                              Joe Sandbox Version:33.0.0 White Diamond
                                              Analysis ID:458982
                                              Start date:04.08.2021
                                              Start time:00:18:13
                                              Joe Sandbox Product:CloudBasic
                                              Overall analysis duration:0h 2m 39s
                                              Hypervisor based Inspection enabled:false
                                              Report type:light
                                              Cookbook file name:browseurl.jbs
                                              Sample URL:https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx
                                              Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                              Number of analysed new started processes analysed:3
                                              Number of new started drivers analysed:0
                                              Number of existing processes analysed:0
                                              Number of existing drivers analysed:0
                                              Number of injected processes analysed:0
                                              Technologies:
                                              • HCA enabled
                                              • EGA enabled
                                              • AMSI enabled
                                              Analysis Mode:default
                                              Analysis stop reason:Timeout
                                              Detection:UNKNOWN
                                              Classification:unknown0.win@27/177@5/7
                                              Cookbook Comments:
                                              • Adjust boot time
                                              • Enable AMSI
                                              • URL browsing timeout or error
                                              Warnings:
                                              Show All
                                              • Exclude process from analysis (whitelisted): taskhostw.exe
                                              • TCP Packets have been reduced to 100
                                              • Created / dropped Files have been reduced to 100
                                              • Excluded IPs from analysis (whitelisted): 168.61.161.212, 40.88.32.150, 142.250.184.110, 74.125.8.72, 173.222.108.210, 173.222.108.226, 209.85.226.8, 142.250.180.163, 142.250.180.106, 142.250.180.138, 142.250.180.170, 216.58.206.42, 216.58.206.74, 216.58.208.138, 216.58.208.170, 216.58.209.42, 142.250.184.42, 142.250.184.74, 142.250.184.106, 216.58.198.42, 216.58.205.74, 172.217.21.74, 142.250.180.74, 20.50.102.62
                                              • Excluded domains from analysis (whitelisted): au.download.windowsupdate.com.edgesuite.net, r3---sn-5hneknee.gvt1.com, skypedataprdcolcus17.cloudapp.net, ctldl.windowsupdate.com, clientservices.googleapis.com, a767.dscg3.akamai.net, www.googleapis.com, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, arc.msn.com, r3.sn-5hnekn76.gvt1.com, skypedataprdcoleus15.cloudapp.net, r3---sn-5hnekn76.gvt1.com, redirector.gvt1.com, blobcollector.events.data.trafficmanager.net, audownload.windowsupdate.nsatc.net, arc.trafficmanager.net, watson.telemetry.microsoft.com, r3.sn-5hneknee.gvt1.com, au-bg-shim.trafficmanager.net
                                              • Not all processes where analyzed, report is missing behavior information
                                              • Report size getting too big, too many NtCreateFile calls found.
                                              • Report size getting too big, too many NtOpenFile calls found.
                                              • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                              • Report size getting too big, too many NtWriteVirtualMemory calls found.
                                              • VT rate limit hit for: https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx
                                              Errors:
                                              • URL not reachable

                                              Simulations

                                              Behavior and APIs

                                              TimeTypeDescription
                                              00:19:02API Interceptor2x Sleep call for process: chrome.exe modified

                                              Joe Sandbox View / Context

                                              IPs

                                              No context

                                              Domains

                                              No context

                                              ASN

                                              No context

                                              JA3 Fingerprints

                                              No context

                                              Dropped Files

                                              No context

                                              Created / dropped Files

                                              C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):451603
                                              Entropy (8bit):5.009711072558331
                                              Encrypted:false
                                              SSDEEP:12288:ZHfRTyGZ6lup8Cfrvq4JBPKh+FBlESBw4p6:NfOCzvRKhGvwJ
                                              MD5:A78AD14E77147E7DE3647E61964C0335
                                              SHA1:CECC3DD41F4CEA0192B24300C71E1911BD4FCE45
                                              SHA-256:0D6803758FF8F87081FAFD62E90F0950DFB2DD7991E9607FE76A8F92D0E893FA
                                              SHA-512:DDE24D5AD50D68FC91E9E325D31E66EF8F624B6BB3A07D14FFED1104D3AB5F4EF1D7969A5CDE0DFBB19CB31C506F7DE97AF67C2F244F7E7E8E10648EA8321101
                                              Malicious:false
                                              Reputation:low
                                              Preview: BDic.... ....6...."..Z..4g....6.2...{/...3...5....AF 1363.AF nm.AF pt.AF n1.AF p.AF tc.AF SM.AF M.AF S.AF MS.AF MNR.AF GDS.AF MNT.AF MH.AF MR.AF SZMR.AF MJ.AF MT.AF MY.AF MRZ.AF MN.AF MG.AF RM.AF N.AF MV.AF XM.AF DSM.AF SD.AF G.AF R.AF MNX.AF MRS.AF MD.AF MNRB.AF B.AF ZSMR.AF PM.AF SMNGJ.AF SMN.AF ZMR.AF SMGB.AF MZR.AF GM.AF SMR.AF SMDG.AF RMZ.AF ZM.AF MDG.AF MDT.AF SMNXT.AF SDY.AF LSDG.AF LGDS.AF GLDS.AF UY.AF U.AF DSGNX.AF GNDSX.AF DSG.AF Y.AF GS.AF IEMS.AF YP.AF ZGDRS.AF XGNVDS.AF UT.AF GNDS.AF GVDS.AF MYPS.AF XGNDS.AF TPRY.AF MDSG.AF ZGSDR.AF DYSG.AF PMYTNS.AF AGDS.AF DRZGS.AF PY.AF GSPMDY.AF EGVDS.AF SL.AF GNXDS.AF DSBG.AF IM.AF I.AF MDGS.AF SMY.AF DSGN.AF DSLG.AF GMDS.AF MDSBG.AF SGD.AF IY.AF P.AF DSMG.AF BLZGDRS.AF TR.AF AGSD.AF ZGBDRSL.AF PTRY.AF ASDGV.AF ASM.AF ICANGSD.AF ICAM.AF IKY.AF AMS.AF PMYTRS.AF BZGVDRS.AF SDRBZG.AF GVMDS.AF PSM.AF DGLS.AF GNVXDS.AF AGDSL.AF DGS.AF XDSGNV.AF BZGDRS.AF AM.AF AS.AF A.AF LDSG.AF AGVDS.AF SDG.AF LDSMG.AF EDSMG.AF EY.AF DRSMZG.AF PRYT.AF LZ
                                              C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:Microsoft Cabinet archive data, 61020 bytes, 1 file
                                              Category:dropped
                                              Size (bytes):122040
                                              Entropy (8bit):7.994886945086499
                                              Encrypted:true
                                              SSDEEP:3072:0tdeYPiuWAVtlLBGbtdeYPiuWAVtlLBGm:0rec7VDBGbrec7VDBGm
                                              MD5:516136E560C1392A28EDFA1A957050D7
                                              SHA1:BBDF208E48EFC052D332255EF84184BFC946BF5F
                                              SHA-256:4F812F7C8163C50FE75F441AC6797E18D02B8B66895BC94D0E1153FE24FADEFE
                                              SHA-512:8F25750E9014F7576E5C81E1A3DE605BB29839A38F0E60D58AB79E034ED1847D9E88A427A834BCA95BF7C4627197AC1194D5A487E0D5E5F88B95E46C4574A425
                                              Malicious:false
                                              Reputation:low
                                              Preview: MSCF....\.......,...................I........l.........R.q .authroot.stl.N....5..CK..8T....c_.d....A.K....=.D.eWI..r."Y...."i..,.=.l.D.....3...3WW.......y...9..w..D.yM10....`.0.e.._.'..a0xN....)F.C..t.z.,.O20.1``L.....m?H..C..X>Oc..q.....%.!^v%<...O...-..@/.......H.J.W...... T...Fp..2.|$....._Y..Y`&..s.1........s.{..,.":o}9.......%._.xW*S.K..4"9......q.G:.........a.H.y.. ..r...q./6.p.;.`=*.Dwj......!......s).B..y.......A.!W.........D!s0..!"X...l.....D0...........Ba...Z.0.o..l.3.v..W1F hSp.S)@.....'Z..QW...G...G.G.y+.x...aa`.3..X&4E..N...._O..<X.......K...xm..+M...O.H...)..........*..o..~4.6.......p.`Bt.(..*V.N.!.p.C>..%.ySXY.>.`..f|.*...'^K`\..e......j/..|..)..&i...wEj.w...o..r<.$.....C.....}.x...L..&..).r..\...>....v........7...^..L!.$..'m...*,*.....7F$..~..S.6$S.-y....|.!.....x...~k...Q/.w.e...h.[...9<x...Q.x.][}*_%Z..K.).3..'....M.6QkJ.N........Y..Q.n.[.(.... ...Bg..33..[...S..[... .Z..<i.-.]...po.k.,...X6......y3^.t[.Dw.]ts. R..L..`..ut_F....
                                              C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):652
                                              Entropy (8bit):3.125297713790607
                                              Encrypted:false
                                              SSDEEP:12:m5kPlE99SNxAhUe0e85kPlE99SNxAhUe0et:m5kPcUQUfe85kPcUQUfet
                                              MD5:E68A32496B24183B7466ECCA05C9BB73
                                              SHA1:FC688DF290CFA1ACEA9B986CF828538B73B39CB7
                                              SHA-256:B73E817145C2921943172B4C6B11754341D52F52CB180613C618E955795AEF46
                                              SHA-512:8C612783A173F54D608F025CC4E143F3FAC374F185F16D20C36F0B43BD8F554121E3C08DFCE1C086DD58482CF71940FFB207E1F4F76A2FBD1810DE4FCF2A2D2E
                                              Malicious:false
                                              Reputation:low
                                              Preview: p...... .........S.....(....................................................... .........T'._......$...........\...h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".0.d.6.5.4.2.7.7.5.f.d.7.1.:.0."...p...... ........^v[.....(....................................................... .........T'._......$...........\...h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".0.d.6.5.4.2.7.7.5.f.d.7.1.:.0."...
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):120
                                              Entropy (8bit):3.254162526001658
                                              Encrypted:false
                                              SSDEEP:3:FkXft0xE1G1mstft0xE1G1mstft0xE1n:+ftIE1G1mkftIE1G1mkftIE1n
                                              MD5:E9224A19341F2979669144B01332DF59
                                              SHA1:F7F760C7104457DF463306A7F7BAE0142EFCEB5B
                                              SHA-256:47DD519C226D23F203ACAE0EC44DF9BB6208828E24F726E1602EA52F63C3E2BE
                                              SHA-512:4184302DEB5009D767FECFC150F580DD57D5CF9CF3BFEB7E52C9F3340E5E6499251B9F0DFF37F0454411FED9046880E0A9204312D021294256372C916B8155AC
                                              Malicious:false
                                              Reputation:low
                                              Preview: sdPC....................s}.....M..2.!..%sdPC....................s}.....M..2.!..%sdPC....................s}.....M..2.!..%
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0f13c3a0-eb16-4ec3-b13e-2877df600fbd.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):4219
                                              Entropy (8bit):4.871684703914691
                                              Encrypted:false
                                              SSDEEP:48:YXsJjMH+5s7YMHBKsvxMHVzspxMHbsIHt/soBDysKqnsllzMHpDCLsWJMHLsNuMg:RG+ZGJG+GTTD7IGpD+G7Gp2GnG4GVhH
                                              MD5:EDC4A4E22003A711AEF67FAED28DB603
                                              SHA1:977E551B9ED5F60D018C030B0B4AA2E33B954556
                                              SHA-256:DD2C9F43F622F801FCC213CDE8E3E90EF1D0D26665AE675449A94CEC7EB1D453
                                              SHA-512:84D3930579FD73C7D86144D5CDC636436955BA79759273C740D2D72BC4847F2F7F165BBCA3EB2E4DFB01777D6A5F141623278C1BF74615C5A491092CE3FD1602
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[],"expiration":"13248543677350473","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543677350474","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31344},"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31656},"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501454993","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501454994","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":39369},"server":"https://www.googleapis.com","supports_spdy":true},
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\197d3279-8b66-435a-9a54-76a165627199.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:very short file (no magic)
                                              Category:dropped
                                              Size (bytes):1
                                              Entropy (8bit):0.0
                                              Encrypted:false
                                              SSDEEP:3:L:L
                                              MD5:5058F1AF8388633F609CADB75A75DC9D
                                              SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                              SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                              SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                              Malicious:false
                                              Reputation:low
                                              Preview: .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3aacc970-7459-4047-8f25-7bfe17f89552.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):1039
                                              Entropy (8bit):5.567309220754564
                                              Encrypted:false
                                              SSDEEP:24:YI6H0UhVsTG1KUerkq/HeUeXby2qUeXvx47wUDZRUenHQ:YI6UUhVseKUewqPeUer2UefxuwULUenw
                                              MD5:92C6064D4F4327C048D3B2B1D2AE8313
                                              SHA1:DA5218F5BE2CCBFFBA27FC783EAB467625D9154E
                                              SHA-256:C6B071CD84EB1F5AB1D9958FC09832D0C3726DED62BB57798CD2E5D7D2015D46
                                              SHA-512:D16C8BB0B7A87715A7F13E5ABF64CE2AAE0C4828AF87A3E6192BFF66388D4AE2FC398D8FC18748856C2B24F66241D74DC8D4898C25029267973D2B5C27894E01
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"expect_ct":[],"sts":[{"expiry":1633014077.350499,"host":"OuKlWsMW1dkkbI1X/oi6o0Y95ZNSWnSoeaIXAEYPlv4=","mode":"force-https","sts_include_subdomains":true,"sts_observed":1601478077.350503},{"expiry":1633014077.22511,"host":"nAuqgR4iEWti7SOdT3UHPl6rmZU/DeaIm38P2O2OkgA=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1601478077.225114},{"expiry":1633014092.4175,"host":"0J7rAWV0ouCFYJ9XrkDiKnAO1SshXJmLJE1SS3V8kDM=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1601478092.417504},{"expiry":1633014091.91938,"host":"5EdUoB7YUY9zZV+2DkgVXgho8WUvp+D+6KpeUOhNQIM=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1601478091.919383},{"expiry":1659597541.909457,"host":"8/RrMmQlCD2Gsp14wUCE1P8r7B2C5+yE0+g79IPyRsc=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1628061541.909462},{"expiry":1633014077.462534,"host":"+ccWXqaoHJ9hfuXbleKV6FQUrBlyXAJ31BdqjNQJpHs=","mode":"force-https","sts_include_subdomains":false,"sts_obs
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3ddd664d-c3cb-48a0-abe1-53054c1f488f.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):22594
                                              Entropy (8bit):5.5357298821370415
                                              Encrypted:false
                                              SSDEEP:384:fuetULl4NXA1kXqKf/pUZNCgVLH2HfDYrUkHGvnThDLQf4L:0LlwA1kXqKf/pUZNCgVLH2HfMrUoGvnn
                                              MD5:C152CF6B63F02F97DD110D4F29D914B0
                                              SHA1:4CD433E2CDE78A159C2FFB8E7C80E65E8317B0EF
                                              SHA-256:23AC2A7CA564916849DC9387B39E765780AB573F750CB37A4829459B5C8568BA
                                              SHA-512:3CD9321E7E4C4E302F1B70F04617C3FA0911C51978AAB4BC889765AC68D1CC6F21A9E5A978891DE09CB3B652B2E3DFF0D4A1391218E2A08D7F9D30128435EA9B
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13272535138831020","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Web Store","pe
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):331
                                              Entropy (8bit):5.123523602926749
                                              Encrypted:false
                                              SSDEEP:6:mMTq2PWXp+N23iKKdK9RXXTZIFUtpzYZmwPz8MFzkwOWXp+N23iKKdK9RXX5LJ:DTva5Kk7XT2FUtpzY/Pz8Ez5f5Kk7XVJ
                                              MD5:CB443B16A8DC783E6EB961C8C3761407
                                              SHA1:17266D21958C58EC06941334870A991A7688392B
                                              SHA-256:FAE0243FBE931AB5E14C44EF35750AD1B7E2A203791781F8347533D9896A019C
                                              SHA-512:B084204C8FCDB96085EC3E08324C08806589D97EBF8BDCC712000BE52A0B3E4D6384BA0953E7F5B3F9D770653F9C863213DD9D2E5F06044A921AC6BEF088C160
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:04.030 a10 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase/MANIFEST-000001.2021/08/04-00:19:04.036 a10 Recovering log #3.2021/08/04-00:19:04.040 a10 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):331
                                              Entropy (8bit):5.123523602926749
                                              Encrypted:false
                                              SSDEEP:6:mMTq2PWXp+N23iKKdK9RXXTZIFUtpzYZmwPz8MFzkwOWXp+N23iKKdK9RXX5LJ:DTva5Kk7XT2FUtpzY/Pz8Ez5f5Kk7XVJ
                                              MD5:CB443B16A8DC783E6EB961C8C3761407
                                              SHA1:17266D21958C58EC06941334870A991A7688392B
                                              SHA-256:FAE0243FBE931AB5E14C44EF35750AD1B7E2A203791781F8347533D9896A019C
                                              SHA-512:B084204C8FCDB96085EC3E08324C08806589D97EBF8BDCC712000BE52A0B3E4D6384BA0953E7F5B3F9D770653F9C863213DD9D2E5F06044A921AC6BEF088C160
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:04.030 a10 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase/MANIFEST-000001.2021/08/04-00:19:04.036 a10 Recovering log #3.2021/08/04-00:19:04.040 a10 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):315
                                              Entropy (8bit):5.164276033519313
                                              Encrypted:false
                                              SSDEEP:6:mcq2PWXp+N23iKKdKyDZIFUtpFXZmwPeE3DkwOWXp+N23iKKdKyJLJ:bva5Kk02FUtpFX/PT3D5f5KkWJ
                                              MD5:AC0539E662FE1C217106523A9ED64FFC
                                              SHA1:98EF326036322DCE9B437ADAA8DD9A7E5C3F0386
                                              SHA-256:5235769DEBD1138EA104B566CA1C19838C273FD76D11D6C1165BD344843EB515
                                              SHA-512:A3A6DBC6FAE717F10E64846A9C898E93DA3CD2B7B4AEE78A0BFFD61CBD9510DDBF3B55B64014A6E71A727BBBD1974E6FCC97B6F27D358C417B813BEA2B9DBF3A
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.976 a10 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase/MANIFEST-000001.2021/08/04-00:19:03.984 a10 Recovering log #3.2021/08/04-00:19:03.988 a10 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):315
                                              Entropy (8bit):5.164276033519313
                                              Encrypted:false
                                              SSDEEP:6:mcq2PWXp+N23iKKdKyDZIFUtpFXZmwPeE3DkwOWXp+N23iKKdKyJLJ:bva5Kk02FUtpFX/PT3D5f5KkWJ
                                              MD5:AC0539E662FE1C217106523A9ED64FFC
                                              SHA1:98EF326036322DCE9B437ADAA8DD9A7E5C3F0386
                                              SHA-256:5235769DEBD1138EA104B566CA1C19838C273FD76D11D6C1165BD344843EB515
                                              SHA-512:A3A6DBC6FAE717F10E64846A9C898E93DA3CD2B7B4AEE78A0BFFD61CBD9510DDBF3B55B64014A6E71A727BBBD1974E6FCC97B6F27D358C417B813BEA2B9DBF3A
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.976 a10 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase/MANIFEST-000001.2021/08/04-00:19:03.984 a10 Recovering log #3.2021/08/04-00:19:03.988 a10 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:SQLite 3.x database, last written using SQLite version 3032001
                                              Category:dropped
                                              Size (bytes):12288
                                              Entropy (8bit):0.6863571317626186
                                              Encrypted:false
                                              SSDEEP:12:TLyen4ufFdbXGwcFOaOndOtJRbGMNmt2SH/+eVpUHFxOUwae6:TLyqJLbXaFpEO5bNmISHn06Uwd
                                              MD5:1C0EAEEE6463CAE33B7A7CD9D9DF4DA5
                                              SHA1:FBC6A28A1501E40154FDC0A9D0C2F34A5F88AA65
                                              SHA-256:ED8AE7C5E6885874A39F4E86258F552670352A18D29BE1FF4D372A2F4CD06C8A
                                              SHA-512:355D19828609971998B09B36E7C7D304B7FB88C7A726670BEBF5CF2E2710F8E71B0F9DEF6FE9712B484C1EB122AEEEFDECF31D13E02C4539C399DFB86EC7619F
                                              Malicious:false
                                              Reputation:low
                                              Preview: SQLite format 3......@ ..........................................................................C....... ..g... .8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies-journal
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):12836
                                              Entropy (8bit):0.9678809581731697
                                              Encrypted:false
                                              SSDEEP:24:ZcLgAZOZD/RB3qLbJLbXaFpEO5bNmISHn06UwQ8:Z8NOZX3q5LLOpEO5J/Kn7U78
                                              MD5:CBA2995A5C939DD8024D3FF1F0B7050D
                                              SHA1:00FBFAF841736F24CC20A64AA1CF21DE8ABC3839
                                              SHA-256:B801343049F01B1DA8E91582F2A4428231361A6DB55563444DC7BD346AEA3A2F
                                              SHA-512:AFBF15EA1010D94278E94B41A418EFA1D54A7B58049549DCA65CF76AE5E4D263B582974BD7D5B31D1EF4547FC827D4E58D01E898060E2326486DFAF269DD9924
                                              Malicious:false
                                              Reputation:low
                                              Preview: ........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):1045
                                              Entropy (8bit):3.4735646719221416
                                              Encrypted:false
                                              SSDEEP:12:3olydJheaCTG7QEPlpxlpN8kIyTLUlowQUJMIBEnvqLClQ1Blptlpl:34SXuxylrlAkUmyh2qm0lLlL
                                              MD5:CAFD2B9D4B350A3E6D175A5DF5A61944
                                              SHA1:CEF3B5E4BDB5B6372CDEB8AD85073C41AC13C80D
                                              SHA-256:0C04C90452B5B631DA35920AF28E272D4C9978E594300CDA771A9D7A8A227180
                                              SHA-512:FCDCB173D705BD6FB5FC3462D4D8E28B9231C044C7F11D42131A895114E01EBA861E49417399493B7D068112B1D8CE26A57A6A1CA643A8354BCB9A3E4016B6A3
                                              Malicious:false
                                              Reputation:low
                                              Preview: SNSS....................................................!.............................................1..,.......$...a86dc9c3_fe73_48ce_a762_e9334e32a73e..........................................................................................................5..0.......&...{524A03AB-861D-4591-9B4E-BDD69F9D425A}............................8...https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx....................................................h.......`...........................................................................0...............................x...8...h.t.t.p.s.:././.d.w...m.y.e.m.e.d.a.p.p.s...c.o.m./.R.D.W.e.b./.P.a.g.e.s./.e.n.-.U.S./.D.e.f.a.u.l.t...a.s.p.x.................................8.......0.......8....................................................................... .......................................................8...https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx.....eq.L'/.............................................................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):8
                                              Entropy (8bit):1.8112781244591325
                                              Encrypted:false
                                              SSDEEP:3:3Dtn:3h
                                              MD5:0686D6159557E1162D04C44240103333
                                              SHA1:053E9DB58E20A67D1E158E407094359BF61D0639
                                              SHA-256:3303D5EED881951B0BB52CF1C6BFA758770034D0120C197F9F7A3520B92A86FB
                                              SHA-512:884C0D3594390E2FC0AEAB05460F0783815170C4B57DB749B8AD9CD10741A5604B7A0F979465C4171AD9C14ED56359A4508B4DE58E794550599AAA261120976C
                                              Malicious:false
                                              Reputation:low
                                              Preview: SNSS....
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):164
                                              Entropy (8bit):4.391736045892206
                                              Encrypted:false
                                              SSDEEP:3:FQxlXayz/t2Hmwg0EOZL7Ao4uhFkEuRLKyC5Ei5+Gg:qT5z/t2qoEwhXeLKB
                                              MD5:0A906A9A542CDF08FF50DAAF1D1E596E
                                              SHA1:B97D6274196F40874A368C265799F5FA78C52893
                                              SHA-256:EB9CABBF5FDA1AD535300B0110EAA4068A083248BA928A631C9278545935426D
                                              SHA-512:8795E905B711ADE6B1C4B402D50AF491B64D157AA738669482DDBFC30E857DF970BFFB774A925F3F4A0802BD27AFAF939CE140894FF09B67FB9C0BB83ED4491A
                                              Malicious:false
                                              Reputation:low
                                              Preview: .f.5................i.Wd...............Sgdaefkejpgkiemlaofpalmlakkmbjdnl.declarative_rules.declarativeContent.onPageChanged.[]..F..................F................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):317
                                              Entropy (8bit):5.204880939784251
                                              Encrypted:false
                                              SSDEEP:6:ml31yq2PWXp+N23iKKdK8aPrqIFUtpKz1ZmwPjRkwOWXp+N23iKKdK8amLJ:G1yva5KkL3FUtp+/PjR5f5KkQJ
                                              MD5:E004691D2E16B28B07D0FFF831886553
                                              SHA1:95E2667EA48A209D37C8C30F8C920038497DDBE5
                                              SHA-256:6B6D3B613564E2144FC2BB7BC266B2EC364808859DE161D589D354A99E361B29
                                              SHA-512:AE7BEE9AB41B2E609FA6227E582B55AEC8B6860AFAB53F5CA12A31198A9A82FC8058FABFC83C9DADFB1E51F1E108FB19C648063E75DDA6D5C077963E8F26F85E
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.189 e34 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules/MANIFEST-000001.2021/08/04-00:18:59.190 e34 Recovering log #3.2021/08/04-00:18:59.191 e34 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):317
                                              Entropy (8bit):5.204880939784251
                                              Encrypted:false
                                              SSDEEP:6:ml31yq2PWXp+N23iKKdK8aPrqIFUtpKz1ZmwPjRkwOWXp+N23iKKdK8amLJ:G1yva5KkL3FUtp+/PjR5f5KkQJ
                                              MD5:E004691D2E16B28B07D0FFF831886553
                                              SHA1:95E2667EA48A209D37C8C30F8C920038497DDBE5
                                              SHA-256:6B6D3B613564E2144FC2BB7BC266B2EC364808859DE161D589D354A99E361B29
                                              SHA-512:AE7BEE9AB41B2E609FA6227E582B55AEC8B6860AFAB53F5CA12A31198A9A82FC8058FABFC83C9DADFB1E51F1E108FB19C648063E75DDA6D5C077963E8F26F85E
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.189 e34 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules/MANIFEST-000001.2021/08/04-00:18:59.190 e34 Recovering log #3.2021/08/04-00:18:59.191 e34 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):570
                                              Entropy (8bit):1.8784775129881184
                                              Encrypted:false
                                              SSDEEP:6:qTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCTCT:qWWWWWWWWWWWWWWWWWWWWWWWWWWWWW
                                              MD5:D4BA0AE0BB0B9FAFF3DA6F35FDBC3C8A
                                              SHA1:FB3E9DEC7F35A9B1D94E54A5659DD0DE484055E7
                                              SHA-256:99DEF1B557F19F04C1AFFC6F247D0451F33FC10EC42E73792223C3215AC98BE6
                                              SHA-512:86FD07C34B9ABD4C52BA19EAE291936F92BC6D38A75C021EDC1DEDBC15617669876180CD99F959C62476D82EC6BB9F5FE4C6CB4D82CB037EFB76D99A4D3D9C51
                                              Malicious:false
                                              Reputation:low
                                              Preview: .f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5................f.5...............
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):320
                                              Entropy (8bit):5.169730259767346
                                              Encrypted:false
                                              SSDEEP:6:mxC+q2PWXp+N23iKKdK8NIFUtpuZmwPZsNVkwOWXp+N23iKKdK8+eLJ:0va5KkpFUtpu/PZo5f5KkqJ
                                              MD5:228D46619B92B0303426FD02EB0B1094
                                              SHA1:91916A9B6A94F6CD119BFA5A47503EF8BC5DD494
                                              SHA-256:067C865144B296A9708683AD4EC3C8BD99542ECEF469254E7FE9F8ED5BF40F24
                                              SHA-512:AA648A8B49E8D4D4CAD6D9A24B6F22B009FFA0AD57AD70E02F6037688DF0A6271E39D7EC6C2667A425D0B8D4F02B3C55FF78C86A0570BFFB7A4A3D3B61041487
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:01.378 1318 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State/MANIFEST-000001.2021/08/04-00:19:01.379 1318 Recovering log #3.2021/08/04-00:19:01.380 1318 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.old. (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):320
                                              Entropy (8bit):5.169730259767346
                                              Encrypted:false
                                              SSDEEP:6:mxC+q2PWXp+N23iKKdK8NIFUtpuZmwPZsNVkwOWXp+N23iKKdK8+eLJ:0va5KkpFUtpu/PZo5f5KkqJ
                                              MD5:228D46619B92B0303426FD02EB0B1094
                                              SHA1:91916A9B6A94F6CD119BFA5A47503EF8BC5DD494
                                              SHA-256:067C865144B296A9708683AD4EC3C8BD99542ECEF469254E7FE9F8ED5BF40F24
                                              SHA-512:AA648A8B49E8D4D4CAD6D9A24B6F22B009FFA0AD57AD70E02F6037688DF0A6271E39D7EC6C2667A425D0B8D4F02B3C55FF78C86A0570BFFB7A4A3D3B61041487
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:01.378 1318 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State/MANIFEST-000001.2021/08/04-00:19:01.379 1318 Recovering log #3.2021/08/04-00:19:01.380 1318 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):11217
                                              Entropy (8bit):6.069602775336632
                                              Encrypted:false
                                              SSDEEP:192:GbylJnlTwGB7V9Hne4qasKxXItmLG48gcLg/PkI:Gb+nldByaFx4toj8VEPT
                                              MD5:90F880064A42B29CCFF51FE5425BF1A3
                                              SHA1:6A3CAE3996E9FFF653A1DDF731CED32B2BE2ACBF
                                              SHA-256:965203D541E442C107DBC6D5B395168123D0397559774BEAE4E5B9ABC44EF268
                                              SHA-512:D9CBFCD865356F19A57954F8FD952CAF3D31B354112766C41892D1EF40BD2533682D4EC3F4DA0E59A5397364F67A484B45091BA94E6C69ED18AB681403DFD3F3
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"file_hashes":[{"block_hashes":["A+1PYW3V6CJbBuQ7aqrgYhyH3bT8PKyBXp3hN2slpI0=","WSOpQRkYTHjPSlG9Zif2a7TNhy43NDcG1Zg5Nv0UbH0=","jDctR8ImG5KZrQKm4kDjUB7FokSJfjo/pmvFowRVlaY=","LPxhhJiuU0lprt0T6flpS7TkaDg7MocrbmzO65xH6RI=","nZ9zLb2By96AkKXALRM+C0Eu11XUjPiMXEKjiCPdtHE=","wifibc1QfMBN2jrtUtLgsCefvuceTpAatmLvul11RJA=","dHjWlSIIdjj7MWqg3T8MG58RuuqRXk32vqi/13JqEgA=","zd3DV7dbvfNvx1hdhU01fW5ily52DLN0CFL/ADaEeTI=","DpjXcO85FFFY9KJFPkGNfFUtdQIOsGwO5jUckiUwY14=","gqid6l1+mk/6yWgUECRofI9lMipXgXh2jEN2+CxmPE0=","prDB91X2Mmfg/M/txVMITWBmEGbOGjqBTP7CMjYqdHs=","yLPAqV4gqoyS/zFkEt3Cn2j0q2v9QOSthVFfWn8EzCM=","EPQ3jzdrLkAHyvf3920B5Y3aAkO1IJdn/UtbnAmq6T0=","+oOc6ca+ChKUpTu+oa2ZRxRE+wG3QJmuYWEvYCs40NI=","3mBGNAiRlTANEQkqzU3TEi+5wJ0ubR5uwtS4/9OOM7w=","1A9NNawxuhu95H5eThvf1rewJ4QQWhhPNxJXO1C/n68=","E3vWLQxzmj+e5QxYbUscllJ5n0ITpw5JBHV1Kph3/KM=","i3I8ghdTF9c1ZXNBZmvsID+DV4gxBVN27rj9wsMtRpg=","R8B8qYabnMSlLPhrtu0hGYrHn3llsMHqBbi70gkIjEE=","rhlzuEvv2KRAFMms896xFwkNgPrw6WvmgPn6xrBSa2Y=","LAMXv6sRb0VZrY34aVXF3Fftxs
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):23474
                                              Entropy (8bit):6.059847580419268
                                              Encrypted:false
                                              SSDEEP:384:7dNc1NC6IcafusK4H1IIGRlhKlkIALQWdynQh2RX4K6M1tVztzr7XSNyzH:7dOscSRKc1nGRSkIhEw6M1tf7SNyb
                                              MD5:6AE2135EA4583C2F06CDEBEA4AE70FA4
                                              SHA1:DCEB26C7F02D53B5F214305F4C75B4A33A79CDC2
                                              SHA-256:03AA1944CB3C4F39E20B6361571BC45DFBEBD3FFDA3D8F148CC6ECB29958F903
                                              SHA-512:B5945E67D9F73DD1982D687E5C6D9B5D6B3886C8050363A259755C76AC0F93651F3425FA7C21AA6A13977AC1C8C9322F998F131648CB8909096058D4F0D23312
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"file_hashes":[{"block_hashes":["DOZdV3jFvk12AM2JNDYKo3KZrIVRprmJ+sVGWkqqE4Q=","rVElW3Hu3T52SzDDUqGT5YiJTBGUv2h3pNuBKFlhZ1U=","X/3fg4KZxgQ1jBr5QGq0F5JnflgE27UErd88mrxTcxs=","VibLbpy0ig+5INMOU71fTYN76iaka2XVpmm1qAKYsX8=","EChCwCbQHbHQ7oDdGT2qNyiRJ0yck2YC2emNGq4whtE="],"block_size":4096,"path":"_locales/iw/messages.json"},{"block_hashes":["xklkoZ7iSU1+7cd6DAtEmUC5lPFd+EgcbnzxkOiFwlk=","3KbsvoxKY/3AwqgF2aAdVQRpMhsNVRkQ3rx2A6Z2Z+Y=","o9+tsohquaCMj+70zeinRG/hBhA2uLoDl/WoC1uokME=","xV/K8xucyWJELVT8Cqn+ugFjobBVmg8pnmACF+2PP4Y=","p/mvJm2wuCl32Rx3it654MljKAsMe3S9IDEabc1A8mE=","j8mPrTb5oOsBTj2Fer78JE6xG6+kR64Cvu2SW8d3j/k=","nqSRpGQ3USU2bZJsZ+AzBmFOyann8omwJrhEWFZDTXc=","eTcQyJUuNuF9yCga/fXGyFCj/pysSceanhBzksdx23s=","Wj7faqnspelXKMvnduxHn1XUBG8TEOqyns7/oUihekM=","VtBwXoadI3EP336rAiL33Gz19KGqtN+RYdKnMKAXoLw=","iDgLXQqXJp8nCZxgLuC9LXM45DGfufvGnXvmHsn18wc=","g+RfdDfrWTUK0Pkcsbot7NJ4SC9wVRV/dVVMuHAtEj8=","2oC4HcCuXu3VjFf6wnKlznt9uqQNaebcuWpm/mWj69U=","aMUIpuFqPMiieSaWhIktCK62v2P3OZQAWupWsYzCnvk=","L
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):19
                                              Entropy (8bit):1.8784775129881184
                                              Encrypted:false
                                              SSDEEP:3:FQxlX:qT
                                              MD5:0407B455F23E3655661BA46A574CFCA4
                                              SHA1:855CB7CC8EAC30458B4207614D046CB09EE3A591
                                              SHA-256:AB5C71347D95F319781DF230012713C7819AC0D69373E8C9A7302CAE3F9A04B7
                                              SHA-512:3020F7C87DC5201589FA43E03B1591ED8BEB64523B37EB3736557F3AB7D654980FB42284115A69D91DE44204CEFAB751B60466C0EF677608467DE43D41BFB939
                                              Malicious:false
                                              Reputation:low
                                              Preview: .f.5...............
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):372
                                              Entropy (8bit):5.235718094246835
                                              Encrypted:false
                                              SSDEEP:6:mFfQ+q2PWXp+N23iKKdK25+Xqx8chI+IFUtpzedWZmwPz9QVkwOWXp+N23iKKdKI:/+va5KkTXfchI3FUtpz0W/Pz2V5f5KkI
                                              MD5:10AB174E90880239C5465991D3E0A144
                                              SHA1:50C64EF6A067EC65E5240554B05CC0ADBE23373C
                                              SHA-256:4D65155F908EB5881DD76649D1A71A8D5861D9618246AC74A756465659FB7AC3
                                              SHA-512:43C6607E47B61FE4F66D0B1CC2BE43415375804E3CF1962BE91EF43F7DA1F9002FDB25E27E1EC7A4EC9CC567706515C28FFC48AC8D46D8EBFBDA238A761B1D05
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.988 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/MANIFEST-000001.2021/08/04-00:19:04.002 17cc Recovering log #3.2021/08/04-00:19:04.005 17cc Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.oldsr (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):372
                                              Entropy (8bit):5.235718094246835
                                              Encrypted:false
                                              SSDEEP:6:mFfQ+q2PWXp+N23iKKdK25+Xqx8chI+IFUtpzedWZmwPz9QVkwOWXp+N23iKKdKI:/+va5KkTXfchI3FUtpz0W/Pz2V5f5KkI
                                              MD5:10AB174E90880239C5465991D3E0A144
                                              SHA1:50C64EF6A067EC65E5240554B05CC0ADBE23373C
                                              SHA-256:4D65155F908EB5881DD76649D1A71A8D5861D9618246AC74A756465659FB7AC3
                                              SHA-512:43C6607E47B61FE4F66D0B1CC2BE43415375804E3CF1962BE91EF43F7DA1F9002FDB25E27E1EC7A4EC9CC567706515C28FFC48AC8D46D8EBFBDA238A761B1D05
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.988 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/MANIFEST-000001.2021/08/04-00:19:04.002 17cc Recovering log #3.2021/08/04-00:19:04.005 17cc Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):358
                                              Entropy (8bit):5.227858931804619
                                              Encrypted:false
                                              SSDEEP:6:m1Q+q2PWXp+N23iKKdK25+XuoIFUtpzpdWZmwPXypQVkwOWXp+N23iKKdK25+Xu6:b+va5KkTXYFUtpzXW/PXyiV5f5KkTXHJ
                                              MD5:591A1EA8FA16FD3EBA8E5C5AD1FF41A4
                                              SHA1:A4B364EB0A0012092E5A90A0B265042F14EE9997
                                              SHA-256:E4F24C630A72B2AD2CE74515913134EC6604405782F55EDFF9F7789806520994
                                              SHA-512:A8593DA71EFBB6A12DE07328EB76D1974194988587B229D097F888B429E84EF361E9737648F715A9FEB815979A6CA4B71B56A35436E099D6F6EF59D5C6F70B52
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.939 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB/MANIFEST-000001.2021/08/04-00:19:03.954 17cc Recovering log #3.2021/08/04-00:19:03.955 17cc Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):358
                                              Entropy (8bit):5.227858931804619
                                              Encrypted:false
                                              SSDEEP:6:m1Q+q2PWXp+N23iKKdK25+XuoIFUtpzpdWZmwPXypQVkwOWXp+N23iKKdK25+Xu6:b+va5KkTXYFUtpzXW/PXyiV5f5KkTXHJ
                                              MD5:591A1EA8FA16FD3EBA8E5C5AD1FF41A4
                                              SHA1:A4B364EB0A0012092E5A90A0B265042F14EE9997
                                              SHA-256:E4F24C630A72B2AD2CE74515913134EC6604405782F55EDFF9F7789806520994
                                              SHA-512:A8593DA71EFBB6A12DE07328EB76D1974194988587B229D097F888B429E84EF361E9737648F715A9FEB815979A6CA4B71B56A35436E099D6F6EF59D5C6F70B52
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.939 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB/MANIFEST-000001.2021/08/04-00:19:03.954 17cc Recovering log #3.2021/08/04-00:19:03.955 17cc Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):330
                                              Entropy (8bit):5.246445263013599
                                              Encrypted:false
                                              SSDEEP:6:miQ+q2PWXp+N23iKKdKWT5g1IdqIFUtpofdWZmwPQKQVkwOWXp+N23iKKdKWT5gZ:i+va5Kkg5gSRFUtpqW/PqV5f5Kkg5gSu
                                              MD5:6522AAC7F42DD7CF229451F34F213D61
                                              SHA1:A39DD2831C5FB8EEDAB80C45DCE26DD4D2D5519A
                                              SHA-256:66025CC968091835C537F5122144737C2EC3DCDEF822E96E4EC80C2CE7B72BE0
                                              SHA-512:C26BFBADF0EA06CA86E15340A44F3236EC8E4991D0A7F160C883BA6C4B8B05F51843F9FC0365DE0C8DD4C487AF66EAADA0167D389D051F0A0593C53E62FB1702
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.738 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption/MANIFEST-000001.2021/08/04-00:19:03.744 17cc Recovering log #3.2021/08/04-00:19:03.745 17cc Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):330
                                              Entropy (8bit):5.246445263013599
                                              Encrypted:false
                                              SSDEEP:6:miQ+q2PWXp+N23iKKdKWT5g1IdqIFUtpofdWZmwPQKQVkwOWXp+N23iKKdKWT5gZ:i+va5Kkg5gSRFUtpqW/PqV5f5Kkg5gSu
                                              MD5:6522AAC7F42DD7CF229451F34F213D61
                                              SHA1:A39DD2831C5FB8EEDAB80C45DCE26DD4D2D5519A
                                              SHA-256:66025CC968091835C537F5122144737C2EC3DCDEF822E96E4EC80C2CE7B72BE0
                                              SHA-512:C26BFBADF0EA06CA86E15340A44F3236EC8E4991D0A7F160C883BA6C4B8B05F51843F9FC0365DE0C8DD4C487AF66EAADA0167D389D051F0A0593C53E62FB1702
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.738 17cc Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption/MANIFEST-000001.2021/08/04-00:19:03.744 17cc Recovering log #3.2021/08/04-00:19:03.745 17cc Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last SessionR. (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):1045
                                              Entropy (8bit):3.4735646719221416
                                              Encrypted:false
                                              SSDEEP:12:3olydJheaCTG7QEPlpxlpN8kIyTLUlowQUJMIBEnvqLClQ1Blptlpl:34SXuxylrlAkUmyh2qm0lLlL
                                              MD5:CAFD2B9D4B350A3E6D175A5DF5A61944
                                              SHA1:CEF3B5E4BDB5B6372CDEB8AD85073C41AC13C80D
                                              SHA-256:0C04C90452B5B631DA35920AF28E272D4C9978E594300CDA771A9D7A8A227180
                                              SHA-512:FCDCB173D705BD6FB5FC3462D4D8E28B9231C044C7F11D42131A895114E01EBA861E49417399493B7D068112B1D8CE26A57A6A1CA643A8354BCB9A3E4016B6A3
                                              Malicious:false
                                              Reputation:low
                                              Preview: SNSS....................................................!.............................................1..,.......$...a86dc9c3_fe73_48ce_a762_e9334e32a73e..........................................................................................................5..0.......&...{524A03AB-861D-4591-9B4E-BDD69F9D425A}............................8...https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx....................................................h.......`...........................................................................0...............................x...8...h.t.t.p.s.:././.d.w...m.y.e.m.e.d.a.p.p.s...c.o.m./.R.D.W.e.b./.P.a.g.e.s./.e.n.-.U.S./.D.e.f.a.u.l.t...a.s.p.x.................................8.......0.......8....................................................................... .......................................................8...https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx.....eq.L'/.............................................................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Tabsfi (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):8
                                              Entropy (8bit):1.8112781244591325
                                              Encrypted:false
                                              SSDEEP:3:3Dtn:3h
                                              MD5:0686D6159557E1162D04C44240103333
                                              SHA1:053E9DB58E20A67D1E158E407094359BF61D0639
                                              SHA-256:3303D5EED881951B0BB52CF1C6BFA758770034D0120C197F9F7A3520B92A86FB
                                              SHA-512:884C0D3594390E2FC0AEAB05460F0783815170C4B57DB749B8AD9CD10741A5604B7A0F979465C4171AD9C14ED56359A4508B4DE58E794550599AAA261120976C
                                              Malicious:false
                                              Reputation:low
                                              Preview: SNSS....
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):332
                                              Entropy (8bit):5.173903421761314
                                              Encrypted:false
                                              SSDEEP:6:m/QtVq2PWXp+N23iKKdK8a2jMGIFUtpa2uYgZmwPa0tIkwOWXp+N23iKKdK8a2jz:KQtVva5Kk8EFUtpaFYg/Pa0tI5f5Kk8N
                                              MD5:243290F55D68E5CA653D9763E48ED1F6
                                              SHA1:5972F756A706F9678344267A8714CB7244930BB8
                                              SHA-256:8F8DBE5903DE204B26916C2E814C6590B7D755687CDBFFDBDFD334CDB04BEF9F
                                              SHA-512:59AD1F1E59E7591E512133272C4309E47E39D6466B916F4C6DA74A94CBC6131E44266EA049D9E6FC56CFE68D63A985BF1C3B97A70E4987665957A201201C4736
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:58.895 12d0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2021/08/04-00:18:58.897 12d0 Recovering log #3.2021/08/04-00:18:58.899 12d0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.oldTM (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):332
                                              Entropy (8bit):5.173903421761314
                                              Encrypted:false
                                              SSDEEP:6:m/QtVq2PWXp+N23iKKdK8a2jMGIFUtpa2uYgZmwPa0tIkwOWXp+N23iKKdK8a2jz:KQtVva5Kk8EFUtpaFYg/Pa0tI5f5Kk8N
                                              MD5:243290F55D68E5CA653D9763E48ED1F6
                                              SHA1:5972F756A706F9678344267A8714CB7244930BB8
                                              SHA-256:8F8DBE5903DE204B26916C2E814C6590B7D755687CDBFFDBDFD334CDB04BEF9F
                                              SHA-512:59AD1F1E59E7591E512133272C4309E47E39D6466B916F4C6DA74A94CBC6131E44266EA049D9E6FC56CFE68D63A985BF1C3B97A70E4987665957A201201C4736
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:58.895 12d0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb/MANIFEST-000001.2021/08/04-00:18:58.897 12d0 Recovering log #3.2021/08/04-00:18:58.899 12d0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):4219
                                              Entropy (8bit):4.871684703914691
                                              Encrypted:false
                                              SSDEEP:48:YXsJjMH+5s7YMHBKsvxMHVzspxMHbsIHt/soBDysKqnsllzMHpDCLsWJMHLsNuMg:RG+ZGJG+GTTD7IGpD+G7Gp2GnG4GVhH
                                              MD5:EDC4A4E22003A711AEF67FAED28DB603
                                              SHA1:977E551B9ED5F60D018C030B0B4AA2E33B954556
                                              SHA-256:DD2C9F43F622F801FCC213CDE8E3E90EF1D0D26665AE675449A94CEC7EB1D453
                                              SHA-512:84D3930579FD73C7D86144D5CDC636436955BA79759273C740D2D72BC4847F2F7F165BBCA3EB2E4DFB01777D6A5F141623278C1BF74615C5A491092CE3FD1602
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[],"expiration":"13248543677350473","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543677350474","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31344},"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501474403","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":31656},"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"alternative_service":[{"advertised_versions":[],"expiration":"13248543501454993","port":443,"protocol_str":"quic"},{"advertised_versions":[],"expiration":"13248543501454994","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":39369},"server":"https://www.googleapis.com","supports_spdy":true},
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State. (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):1932
                                              Entropy (8bit):4.876242082024906
                                              Encrypted:false
                                              SSDEEP:48:YALtdNTntwCXGDH3qyvz5sSRLsOATsk2TSPs0wYhbD:VNTnOCXGDHa+zNKIT8RhH
                                              MD5:CD1FDC82B62B0CB3EA512D4CB8242841
                                              SHA1:8ADCFB25F16A88EBC0CA48CB8286CB89563DFDE6
                                              SHA-256:99AE0456B70101EABE87B95A68999F6B309526F19481DCA766691B5701DEAEE5
                                              SHA-512:866B196425B6D4B38392838CCB24BD1CFF59EF786306AC8BEC8FB784D5EEFEC7EDBFF935C8C3666705A341EDD8BF29E7CC57E575A94FF4ECFEC2A3138C9F9E3D
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"net":{"http_server_properties":{"broken_alternative_services":[{"broken_count":1,"host":"clients2.google.com","isolation":[],"port":443,"protocol_str":"quic"}],"servers":[{"isolation":[],"server":"https://www.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://www.google.com","supports_spdy":true},{"isolation":[],"server":"https://ssl.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://fonts.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://apis.google.com","supports_spdy":true},{"isolation":[],"server":"https://play.google.com","supports_spdy":true},{"isolation":[],"server":"https://ogs.google.com","supports_spdy":true},{"isolation":[],"server":"https://www.googleapis.com","supports_spdy":true},{"isolation":[],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"isolation":[],"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13275127141909391"
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):331
                                              Entropy (8bit):5.24124911669702
                                              Encrypted:false
                                              SSDEEP:6:ma31yq2PWXp+N23iKKdKgXz4rRIFUtpF3j1ZmwPiRkwOWXp+N23iKKdKgXz4q8LJ:9yva5KkgXiuFUtpFZ/PiR5f5KkgX2J
                                              MD5:BA44CD5F077DA7EB144CA27D1E36BBDA
                                              SHA1:6BD3277E0B1AF5CC84910F30A78EF1F827049C8F
                                              SHA-256:1F15781F29F462E375BA8136ACB25177E02A58F4F68294313B9557EB71439634
                                              SHA-512:87C1CBC3D2E322D52522E8555DA9926708838503AC546C3CC7E929C0B7DA91E2887F51F4967821482084ACB75FF7C3C802CEC18491EB34729F37F377FF118026
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.214 e34 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications/MANIFEST-000001.2021/08/04-00:18:59.216 e34 Recovering log #3.2021/08/04-00:18:59.217 e34 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old.7 (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):331
                                              Entropy (8bit):5.24124911669702
                                              Encrypted:false
                                              SSDEEP:6:ma31yq2PWXp+N23iKKdKgXz4rRIFUtpF3j1ZmwPiRkwOWXp+N23iKKdKgXz4q8LJ:9yva5KkgXiuFUtpFZ/PiR5f5KkgX2J
                                              MD5:BA44CD5F077DA7EB144CA27D1E36BBDA
                                              SHA1:6BD3277E0B1AF5CC84910F30A78EF1F827049C8F
                                              SHA-256:1F15781F29F462E375BA8136ACB25177E02A58F4F68294313B9557EB71439634
                                              SHA-512:87C1CBC3D2E322D52522E8555DA9926708838503AC546C3CC7E929C0B7DA91E2887F51F4967821482084ACB75FF7C3C802CEC18491EB34729F37F377FF118026
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.214 e34 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications/MANIFEST-000001.2021/08/04-00:18:59.216 e34 Recovering log #3.2021/08/04-00:18:59.217 e34 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):5446
                                              Entropy (8bit):5.167347058001006
                                              Encrypted:false
                                              SSDEEP:96:ncCIqj9zP/0PWccKI0ok0JCKL8VbOTQVuwn:ncCp9zn0PWcc94K6
                                              MD5:477E05A5387A290561E648CFC7DD204F
                                              SHA1:5598E9669DCA1E34BF78DB09CA83C5DBF076C75B
                                              SHA-256:C9514B1FEF3CF407F47D383C7F298AF08686E249EF1D1061A671BBE77F4147A9
                                              SHA-512:D233399E3148BE8A4064EB9AA42611DB4032FA8145A8C56E174D1CA7B6BE697EAA78CFA3F154B09F865E30E8B82E83A4C363141A9C8970EB93BC955A101F0884
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"account_id_migration_state":2,"account_tracker_service_last_update":"13272535139156421","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13245951485614034","autocomplete":{"retention_policy_last_version":85},"autofill":{"orphan_rows_removed":true},"browser":{"default_browser_infobar_last_declined":"13245951692116406","has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","7355378"],"daily_received_length":["0","0","0","0","0","0","0","
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:SQLite 3.x database, last written using SQLite version 3032001
                                              Category:dropped
                                              Size (bytes):20480
                                              Entropy (8bit):1.002295676650449
                                              Encrypted:false
                                              SSDEEP:48:TUIopK2rJNVr1GJmm8pF82phrJNVrdHX/cjrJN2yJ1n4n1GmhGURTL:wIElwQF8mpcSdf
                                              MD5:16221A9FC7AD2D0138A8F1BE9D8029A9
                                              SHA1:32FC86C2D087495F5974B55A96A3F20EA44E212E
                                              SHA-256:DF0D34B55090C07C70E924EB338DA895F0D6800D97075B857E040FB885976DD4
                                              SHA-512:B6FE3A369111CE069341E403E9FF5D08E33A185735451166654882AD4F49549801F5C0551132C1379806D7111BBE957EBAF99AD389B290D42EAEB81DA405D1F7
                                              Malicious:false
                                              Reputation:low
                                              Preview: SQLite format 3......@ ..........................................................................C..........g...^.........j............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL-journal
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):21044
                                              Entropy (8bit):0.8261068178211103
                                              Encrypted:false
                                              SSDEEP:48:QYqkIopK2rJNVr1GJmm8pF82phrJNVrdHX/cjrJN2yJ1n4n1GmhGUD6:QYhIElwQF8mpcSK
                                              MD5:5AF89EBE2E2F63E159208BEA523629BA
                                              SHA1:56A1C406982F0D262313770B44611A7DA405F8E4
                                              SHA-256:0004DF0C1D8D05474BF5F12BBBD1C2879AD993FE10EA2DC46B01920F416817FA
                                              SHA-512:2F5AF3EF218F65683554FB75D2B3B65B8AFDF4C2B7F3329C240DBCC6B25638EE4E1A6F96A8D9AD53ABD41837186041207A588676B20235529249B55EAD818278
                                              Malicious:false
                                              Reputation:low
                                              Preview: .......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):22594
                                              Entropy (8bit):5.5357298821370415
                                              Encrypted:false
                                              SSDEEP:384:fuetULl4NXA1kXqKf/pUZNCgVLH2HfDYrUkHGvnThDLQf4L:0LlwA1kXqKf/pUZNCgVLH2HfMrUoGvnn
                                              MD5:C152CF6B63F02F97DD110D4F29D914B0
                                              SHA1:4CD433E2CDE78A159C2FFB8E7C80E65E8317B0EF
                                              SHA-256:23AC2A7CA564916849DC9387B39E765780AB573F750CB37A4829459B5C8568BA
                                              SHA-512:3CD9321E7E4C4E302F1B70F04617C3FA0911C51978AAB4BC889765AC68D1CC6F21A9E5A978891DE09CB3B652B2E3DFF0D4A1391218E2A08D7F9D30128435EA9B
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"extensions":{"settings":{"ahfgeienlihckogmohjhadlkjgocpleb":{"active_permissions":{"api":["management","system.display","system.storage","webstorePrivate","system.cpu","system.memory","system.network"],"manifest_permissions":[]},"app_launcher_ordinal":"t","commands":{},"content_settings":[],"creation_flags":1,"events":[],"from_bookmark":false,"from_webstore":false,"incognito_content_settings":[],"incognito_preferences":{},"install_time":"13272535138831020","location":5,"manifest":{"app":{"launch":{"web_url":"https://chrome.google.com/webstore"},"urls":["https://chrome.google.com/webstore"]},"description":"Discover great apps, games, extensions and themes for Google Chrome.","icons":{"128":"webstore_icon_128.png","16":"webstore_icon_16.png"},"key":"MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCtl3tO0osjuzRsf6xtD2SKxPlTfuoy7AWoObysitBPvH5fE1NaAA1/2JkPWkVDhdLBWLaIBPYeXbzlHp3y4Vv/4XG+aN5qFE3z+1RU/NqkzVYHtIpVScf3DjTYtKVL66mzVGijSoAIwbFCC3LpGdaoe6Q1rSRDp76wR6jjFzsYwQIDAQAB","name":"Web Store","pe
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):19
                                              Entropy (8bit):1.9837406708828553
                                              Encrypted:false
                                              SSDEEP:3:5l:5l
                                              MD5:E556F26DF3E95C19DBAECA8F5DF0C341
                                              SHA1:247A89F0557FC3666B5173833DB198B188F3AA2E
                                              SHA-256:B0A7B19404285905663876774A2176939A6ED75EF3904E44283A125824BD0BF3
                                              SHA-512:055BC4AB12FEEDF3245EAAF0A0109036909C44E3B69916F8A01E6C8459785317FE75CA6B28F8B339316FC2310D3E5392CD15DBDB0F84016667F304D377444E2E
                                              Malicious:false
                                              Reputation:low
                                              Preview: ..&f...............
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):317
                                              Entropy (8bit):5.1503860377474115
                                              Encrypted:false
                                              SSDEEP:6:m4m+q2PWXp+N23iKKdKrQMxIFUtpjBIZZmwPCK9VkwOWXp+N23iKKdKrQMFLJ:Znva5KkCFUtp90/PbD5f5KktJ
                                              MD5:38AA68239AADA589C6320EAF2EB2B98D
                                              SHA1:E0BEFE604EEDA9C9A19DFCD34B1E7280326A8943
                                              SHA-256:A99B12422D4272F2E47D08C46C6D06E889E9A3DD7BF93211210939B01769DBBD
                                              SHA-512:7CA6B18809C5AC36378069FB209500B7C9617853C8AC4CC28F677F436E4C04394778B7E1BE2758BBE19786823178F574E2C8FF570C210BB9F0A7EDBF3E499C1F
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.111 de8 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage/MANIFEST-000001.2021/08/04-00:18:59.113 de8 Recovering log #3.2021/08/04-00:18:59.114 de8 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):317
                                              Entropy (8bit):5.1503860377474115
                                              Encrypted:false
                                              SSDEEP:6:m4m+q2PWXp+N23iKKdKrQMxIFUtpjBIZZmwPCK9VkwOWXp+N23iKKdKrQMFLJ:Znva5KkCFUtp90/PbD5f5KktJ
                                              MD5:38AA68239AADA589C6320EAF2EB2B98D
                                              SHA1:E0BEFE604EEDA9C9A19DFCD34B1E7280326A8943
                                              SHA-256:A99B12422D4272F2E47D08C46C6D06E889E9A3DD7BF93211210939B01769DBBD
                                              SHA-512:7CA6B18809C5AC36378069FB209500B7C9617853C8AC4CC28F677F436E4C04394778B7E1BE2758BBE19786823178F574E2C8FF570C210BB9F0A7EDBF3E499C1F
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.111 de8 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage/MANIFEST-000001.2021/08/04-00:18:59.113 de8 Recovering log #3.2021/08/04-00:18:59.114 de8 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):345
                                              Entropy (8bit):5.158068157744009
                                              Encrypted:false
                                              SSDEEP:6:m1Cryq2PWXp+N23iKKdK7Uh2ghZIFUtpQdz1ZmwPQ0V1RkwOWXp+N23iKKdK7Uh9:ova5KkIhHh2FUtpA1/PLd5f5KkIhHLJ
                                              MD5:4BF5CA0DA8E166CA2E3BF255A2DA4532
                                              SHA1:768C7761CC981C6C219F5C0440AB20F2B09E48EC
                                              SHA-256:B05DECAEE4E55652B4A9B1F92D9C195AB87AD53B5059378314390CAA6D090EBA
                                              SHA-512:6F1FB3C47F0E6D410FA88C979A6BC3682352B1585F29D16D325FE2FB0B3054229B3E45EB9721A9B5EB35C7F9A0BAED7CFCD70272373D4678A7E89480E039C461
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:58.833 e94 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database/MANIFEST-000001.2021/08/04-00:18:58.838 e94 Recovering log #3.2021/08/04-00:18:58.839 e94 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):345
                                              Entropy (8bit):5.158068157744009
                                              Encrypted:false
                                              SSDEEP:6:m1Cryq2PWXp+N23iKKdK7Uh2ghZIFUtpQdz1ZmwPQ0V1RkwOWXp+N23iKKdK7Uh9:ova5KkIhHh2FUtpA1/PLd5f5KkIhHLJ
                                              MD5:4BF5CA0DA8E166CA2E3BF255A2DA4532
                                              SHA1:768C7761CC981C6C219F5C0440AB20F2B09E48EC
                                              SHA-256:B05DECAEE4E55652B4A9B1F92D9C195AB87AD53B5059378314390CAA6D090EBA
                                              SHA-512:6F1FB3C47F0E6D410FA88C979A6BC3682352B1585F29D16D325FE2FB0B3054229B3E45EB9721A9B5EB35C7F9A0BAED7CFCD70272373D4678A7E89480E039C461
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:58.833 e94 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database/MANIFEST-000001.2021/08/04-00:18:58.838 e94 Recovering log #3.2021/08/04-00:18:58.839 e94 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\7955c7de-2189-4b50-b1c2-53a20e7e6cda.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):420
                                              Entropy (8bit):4.985305467053914
                                              Encrypted:false
                                              SSDEEP:6:YHpoNXR8+eq7JdV5qQlsDHF4xj70PpqQEsDHF4R8HLJ2AVQBR70S7PMVKJw1K3Ky:YHO8sdBsB6MAsBdLJlyH7E4f3K33y
                                              MD5:C401B619D9D8E0ADABC25A47EE49CFBA
                                              SHA1:C9D3B816DD3FBCD98E9C0A32CEC7B501EFC0BBDA
                                              SHA-256:8F5D75F5EF9876E8D30CE477509F735B50C4D87DBEDB433BE8EDBE6D4B3CB82F
                                              SHA-512:BC12F16CB95CB0AD708C6BBD005EF863A8552613E612F1084086E0F8262752E1B5144D044F0D141CE8462CC33343C36B517A5CC778751680485D8F88FB51B862
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[50],"expiration":"13248543490879170","port":443,"protocol_str":"quic"},{"advertised_versions":[73],"expiration":"13248543490879171","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://dns.google","supports_spdy":true}],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):427
                                              Entropy (8bit):5.232550218202843
                                              Encrypted:false
                                              SSDEEP:6:mIyq2PWXp+N23iKKdKusNpV/2jMGIFUtp9e1ZmwP9IRkwOWXp+N23iKKdKusNpV0:Ova5KkFFUtp9e1/P9Q5f5KkOJ
                                              MD5:BE90210449F0B26345111B5106FB9570
                                              SHA1:4C9E27B1E9E4067DB571D6AB15B95EE1DEF2AA96
                                              SHA-256:D241F602B0F3E40239B3109CD268DE5C23354647D1CF3E4E163E8F944874EBA0
                                              SHA-512:07F2C355C55678C00FC76741045C6F290FC26B1B0959A5E132DA2E844B183E55935DC1D1068366CC70C2E8F1126F89C2B0EE52B8ACCD563746CB8220F25E40AB
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.178 bc0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb/MANIFEST-000001.2021/08/04-00:18:59.180 bc0 Recovering log #3.2021/08/04-00:18:59.180 bc0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):427
                                              Entropy (8bit):5.232550218202843
                                              Encrypted:false
                                              SSDEEP:6:mIyq2PWXp+N23iKKdKusNpV/2jMGIFUtp9e1ZmwP9IRkwOWXp+N23iKKdKusNpV0:Ova5KkFFUtp9e1/P9Q5f5KkOJ
                                              MD5:BE90210449F0B26345111B5106FB9570
                                              SHA1:4C9E27B1E9E4067DB571D6AB15B95EE1DEF2AA96
                                              SHA-256:D241F602B0F3E40239B3109CD268DE5C23354647D1CF3E4E163E8F944874EBA0
                                              SHA-512:07F2C355C55678C00FC76741045C6F290FC26B1B0959A5E132DA2E844B183E55935DC1D1068366CC70C2E8F1126F89C2B0EE52B8ACCD563746CB8220F25E40AB
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.178 bc0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb/MANIFEST-000001.2021/08/04-00:18:59.180 bc0 Recovering log #3.2021/08/04-00:18:59.180 bc0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State. (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):420
                                              Entropy (8bit):4.985305467053914
                                              Encrypted:false
                                              SSDEEP:6:YHpoNXR8+eq7JdV5qQlsDHF4xj70PpqQEsDHF4R8HLJ2AVQBR70S7PMVKJw1K3Ky:YHO8sdBsB6MAsBdLJlyH7E4f3K33y
                                              MD5:C401B619D9D8E0ADABC25A47EE49CFBA
                                              SHA1:C9D3B816DD3FBCD98E9C0A32CEC7B501EFC0BBDA
                                              SHA-256:8F5D75F5EF9876E8D30CE477509F735B50C4D87DBEDB433BE8EDBE6D4B3CB82F
                                              SHA-512:BC12F16CB95CB0AD708C6BBD005EF863A8552613E612F1084086E0F8262752E1B5144D044F0D141CE8462CC33343C36B517A5CC778751680485D8F88FB51B862
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"net":{"http_server_properties":{"servers":[{"alternative_service":[{"advertised_versions":[50],"expiration":"13248543490879170","port":443,"protocol_str":"quic"},{"advertised_versions":[73],"expiration":"13248543490879171","port":443,"protocol_str":"quic"}],"isolation":[],"server":"https://dns.google","supports_spdy":true}],"version":5},"network_qualities":{"CAASABiAgICA+P////8B":"4G","CAESABiAgICA+P////8B":"4G"}}}
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):432
                                              Entropy (8bit):5.276864316543655
                                              Encrypted:false
                                              SSDEEP:6:mOZq2PWXp+N23iKKdKusNpqz4rRIFUtpFkZmwPLkwOWXp+N23iKKdKusNpqz4q8d:Vva5KkmiuFUtpFk/PL5f5Kkm2J
                                              MD5:3D771B52A409F9DCC2E96C58CC7BEAFA
                                              SHA1:6EEF752D6FF44557164771C9EB88B88A6704522E
                                              SHA-256:E4F19130BD9966B93292D0E5B0CC1F62512CB97CFDBF144CB2269EC225D36C90
                                              SHA-512:2992F3C8DB98DC67D889694AB9769A0FC66B160E38B7E1387EC4E308D0CE25F669F2F2CB3522BFAF48038421F9234B2E738F513106DEC42F1E9E90CF5652E9B4
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.210 12b0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications/MANIFEST-000001.2021/08/04-00:18:59.216 12b0 Recovering log #3.2021/08/04-00:18:59.217 12b0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):432
                                              Entropy (8bit):5.276864316543655
                                              Encrypted:false
                                              SSDEEP:6:mOZq2PWXp+N23iKKdKusNpqz4rRIFUtpFkZmwPLkwOWXp+N23iKKdKusNpqz4q8d:Vva5KkmiuFUtpFk/PL5f5Kkm2J
                                              MD5:3D771B52A409F9DCC2E96C58CC7BEAFA
                                              SHA1:6EEF752D6FF44557164771C9EB88B88A6704522E
                                              SHA-256:E4F19130BD9966B93292D0E5B0CC1F62512CB97CFDBF144CB2269EC225D36C90
                                              SHA-512:2992F3C8DB98DC67D889694AB9769A0FC66B160E38B7E1387EC4E308D0CE25F669F2F2CB3522BFAF48038421F9234B2E738F513106DEC42F1E9E90CF5652E9B4
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:59.210 12b0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications/MANIFEST-000001.2021/08/04-00:18:59.216 12b0 Recovering log #3.2021/08/04-00:18:59.217 12b0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):427
                                              Entropy (8bit):5.1772556906158975
                                              Encrypted:false
                                              SSDEEP:12:Gva5KkkGHArBFUtp6J/P15f5KkkGHAryJ:Ea5KkkGgPg01f5KkkGga
                                              MD5:DDFF07AD2AFD53362CC451E9559A90D0
                                              SHA1:968E8B13B2778BBB96A5123FF7043D793F6FE924
                                              SHA-256:DBE05B99EB81544F0148BAF484ECACB5DE8D6A2857B7ACB48009FECF5B7EB89D
                                              SHA-512:D6E829BC35494BB37BD7457AABF0E91A41061FBFCB75080FD67D468F89B6C1263277963C11BBF5D8DEC44FE8CD669B968B1A1016C22E932931044FE220FD6E83
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.851 de8 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb/MANIFEST-000001.2021/08/04-00:19:03.856 de8 Recovering log #3.2021/08/04-00:19:03.859 de8 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):427
                                              Entropy (8bit):5.1772556906158975
                                              Encrypted:false
                                              SSDEEP:12:Gva5KkkGHArBFUtp6J/P15f5KkkGHAryJ:Ea5KkkGgPg01f5KkkGga
                                              MD5:DDFF07AD2AFD53362CC451E9559A90D0
                                              SHA1:968E8B13B2778BBB96A5123FF7043D793F6FE924
                                              SHA-256:DBE05B99EB81544F0148BAF484ECACB5DE8D6A2857B7ACB48009FECF5B7EB89D
                                              SHA-512:D6E829BC35494BB37BD7457AABF0E91A41061FBFCB75080FD67D468F89B6C1263277963C11BBF5D8DEC44FE8CD669B968B1A1016C22E932931044FE220FD6E83
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.851 de8 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb/MANIFEST-000001.2021/08/04-00:19:03.856 de8 Recovering log #3.2021/08/04-00:19:03.859 de8 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):432
                                              Entropy (8bit):5.23740846132248
                                              Encrypted:false
                                              SSDEEP:12:3Ava5KkkGHArqiuFUtpZ1/PDVF5f5KkkGHArq2J:ia5KkkGgCgbVtf5KkkGg7
                                              MD5:8A7E66E1702AE0805FB123F09780F45E
                                              SHA1:B6CBA94F7C83530FE469A57CD96534DDB64BCB2F
                                              SHA-256:A031C7D9C32631F927DE0725057436282B06835D1BB0937B21DC25616E5CFA93
                                              SHA-512:B566FC2D07B78A10F3ADC7F2BBBA3C74E332A6252669736092F5161ECCC37F4708CCDE1777BED31764C9C605E4329EC0C5F1B301C48604E68C15FED98CB90F30
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.863 1234 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications/MANIFEST-000001.2021/08/04-00:19:03.865 1234 Recovering log #3.2021/08/04-00:19:03.867 1234 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):432
                                              Entropy (8bit):5.23740846132248
                                              Encrypted:false
                                              SSDEEP:12:3Ava5KkkGHArqiuFUtpZ1/PDVF5f5KkkGHArq2J:ia5KkkGgCgbVtf5KkkGg7
                                              MD5:8A7E66E1702AE0805FB123F09780F45E
                                              SHA1:B6CBA94F7C83530FE469A57CD96534DDB64BCB2F
                                              SHA-256:A031C7D9C32631F927DE0725057436282B06835D1BB0937B21DC25616E5CFA93
                                              SHA-512:B566FC2D07B78A10F3ADC7F2BBBA3C74E332A6252669736092F5161ECCC37F4708CCDE1777BED31764C9C605E4329EC0C5F1B301C48604E68C15FED98CB90F30
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.863 1234 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications/MANIFEST-000001.2021/08/04-00:19:03.865 1234 Recovering log #3.2021/08/04-00:19:03.867 1234 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):38
                                              Entropy (8bit):1.9837406708828553
                                              Encrypted:false
                                              SSDEEP:3:sgGg:st
                                              MD5:45A8ECA4E5C4A6B1395080C1B728B6C9
                                              SHA1:8A97BB0E599775D9A10C0FC53C4EDB29AA4CEB4E
                                              SHA-256:DB320AB28DFF27CDA0A7F87B82F2F8E61B3178A6DE8503753D76F1172D32E08E
                                              SHA-512:8EE91A3A1E77459273553F6A776C423A8EE95DB9DCFA897771814B7AD13FD84F06BB2B859F22B6DDA384B39EAA91F1819F170BABED6DA16BDBCF5BCB06CF2124
                                              Malicious:false
                                              Reputation:low
                                              Preview: ..F..................F................
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):321
                                              Entropy (8bit):5.18524469506109
                                              Encrypted:false
                                              SSDEEP:6:m1l4q2PWXp+N23iKKdKpIFUtpQ0/ZmwPF6skwOWXp+N23iKKdKa/WLJ:E4va5KkmFUtpL//PIs5f5KkaUJ
                                              MD5:CF4A507724E1D42EDA42B432FD7AC4E9
                                              SHA1:9173F7AD8F51F4FFD6A2734C7EBB2A0B6AA27052
                                              SHA-256:FB07622C1AE5D612CFF304C5D25B552B36F2F4DC74911FC9ACE96DEFAB3BDB7D
                                              SHA-512:E3D0663B67B33F0782BB3A1D166777EA1582A3F7BA03827E564CBD1FEBEBC4B70338FDC85F103CEB97D5EA8B0FB1C63BCF69CF04C451A32E23550E55A88D4AB0
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:58.838 e50 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2021/08/04-00:18:58.839 e50 Recovering log #3.2021/08/04-00:18:58.840 e50 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old.. (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):321
                                              Entropy (8bit):5.18524469506109
                                              Encrypted:false
                                              SSDEEP:6:m1l4q2PWXp+N23iKKdKpIFUtpQ0/ZmwPF6skwOWXp+N23iKKdKa/WLJ:E4va5KkmFUtpL//PIs5f5KkaUJ
                                              MD5:CF4A507724E1D42EDA42B432FD7AC4E9
                                              SHA1:9173F7AD8F51F4FFD6A2734C7EBB2A0B6AA27052
                                              SHA-256:FB07622C1AE5D612CFF304C5D25B552B36F2F4DC74911FC9ACE96DEFAB3BDB7D
                                              SHA-512:E3D0663B67B33F0782BB3A1D166777EA1582A3F7BA03827E564CBD1FEBEBC4B70338FDC85F103CEB97D5EA8B0FB1C63BCF69CF04C451A32E23550E55A88D4AB0
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:18:58.838 e50 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB/MANIFEST-000001.2021/08/04-00:18:58.839 e50 Recovering log #3.2021/08/04-00:18:58.840 e50 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):399
                                              Entropy (8bit):5.324344310134766
                                              Encrypted:false
                                              SSDEEP:12:8Syva5KkkOrsFUtpMM/PMcR5f5KkkOrzJ:PYa5Kk+gxDf5Kkn
                                              MD5:017064D838968A9B45F7147A09DD950A
                                              SHA1:2A28E180F5E2E0A200F442A3A8AA49C2A2868CD9
                                              SHA-256:0A2898432538989F7F0228A704DF1ABDF731397F9B57CBA194B4E70AD9327D0E
                                              SHA-512:DE5F640D8FF2D48E8044815208FBFDB1E36FDE41021B12D78BAE07FEEFEB0D221C6EE881A4DCA425A6C6CAB3CE388CE3F76D66B3861C2BA32DBDCAE388E6CA78
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:05.173 e34 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm/MANIFEST-000001.2021/08/04-00:19:05.175 e34 Recovering log #3.2021/08/04-00:19:05.175 e34 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.olds (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):399
                                              Entropy (8bit):5.324344310134766
                                              Encrypted:false
                                              SSDEEP:12:8Syva5KkkOrsFUtpMM/PMcR5f5KkkOrzJ:PYa5Kk+gxDf5Kkn
                                              MD5:017064D838968A9B45F7147A09DD950A
                                              SHA1:2A28E180F5E2E0A200F442A3A8AA49C2A2868CD9
                                              SHA-256:0A2898432538989F7F0228A704DF1ABDF731397F9B57CBA194B4E70AD9327D0E
                                              SHA-512:DE5F640D8FF2D48E8044815208FBFDB1E36FDE41021B12D78BAE07FEEFEB0D221C6EE881A4DCA425A6C6CAB3CE388CE3F76D66B3861C2BA32DBDCAE388E6CA78
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:05.173 e34 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm/MANIFEST-000001.2021/08/04-00:19:05.175 e34 Recovering log #3.2021/08/04-00:19:05.175 e34 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):1039
                                              Entropy (8bit):5.567309220754564
                                              Encrypted:false
                                              SSDEEP:24:YI6H0UhVsTG1KUerkq/HeUeXby2qUeXvx47wUDZRUenHQ:YI6UUhVseKUewqPeUer2UefxuwULUenw
                                              MD5:92C6064D4F4327C048D3B2B1D2AE8313
                                              SHA1:DA5218F5BE2CCBFFBA27FC783EAB467625D9154E
                                              SHA-256:C6B071CD84EB1F5AB1D9958FC09832D0C3726DED62BB57798CD2E5D7D2015D46
                                              SHA-512:D16C8BB0B7A87715A7F13E5ABF64CE2AAE0C4828AF87A3E6192BFF66388D4AE2FC398D8FC18748856C2B24F66241D74DC8D4898C25029267973D2B5C27894E01
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"expect_ct":[],"sts":[{"expiry":1633014077.350499,"host":"OuKlWsMW1dkkbI1X/oi6o0Y95ZNSWnSoeaIXAEYPlv4=","mode":"force-https","sts_include_subdomains":true,"sts_observed":1601478077.350503},{"expiry":1633014077.22511,"host":"nAuqgR4iEWti7SOdT3UHPl6rmZU/DeaIm38P2O2OkgA=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1601478077.225114},{"expiry":1633014092.4175,"host":"0J7rAWV0ouCFYJ9XrkDiKnAO1SshXJmLJE1SS3V8kDM=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1601478092.417504},{"expiry":1633014091.91938,"host":"5EdUoB7YUY9zZV+2DkgVXgho8WUvp+D+6KpeUOhNQIM=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1601478091.919383},{"expiry":1659597541.909457,"host":"8/RrMmQlCD2Gsp14wUCE1P8r7B2C5+yE0+g79IPyRsc=","mode":"force-https","sts_include_subdomains":false,"sts_observed":1628061541.909462},{"expiry":1633014077.462534,"host":"+ccWXqaoHJ9hfuXbleKV6FQUrBlyXAJ31BdqjNQJpHs=","mode":"force-https","sts_include_subdomains":false,"sts_obs
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):16
                                              Entropy (8bit):3.2743974703476995
                                              Encrypted:false
                                              SSDEEP:3:1sjgWIV//Rv:1qIFJ
                                              MD5:6752A1D65B201C13B62EA44016EB221F
                                              SHA1:58ECF154D01A62233ED7FB494ACE3C3D4FFCE08B
                                              SHA-256:0861415CADA612EA5834D56E2CF1055D3E63979B69EB71D32AE9AE394D8306CD
                                              SHA-512:9CFD838D3FB570B44FC3461623AB2296123404C6C8F576B0DE0AABD9A6020840D4C9125EB679ED384170DBCAAC2FA30DC7FA9EE5B77D6DF7C344A0AA030E0389
                                              Malicious:false
                                              Reputation:low
                                              Preview: MANIFEST-000004.
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENTTM (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):16
                                              Entropy (8bit):3.2743974703476995
                                              Encrypted:false
                                              SSDEEP:3:1sjgWIV//Rv:1qIFJ
                                              MD5:6752A1D65B201C13B62EA44016EB221F
                                              SHA1:58ECF154D01A62233ED7FB494ACE3C3D4FFCE08B
                                              SHA-256:0861415CADA612EA5834D56E2CF1055D3E63979B69EB71D32AE9AE394D8306CD
                                              SHA-512:9CFD838D3FB570B44FC3461623AB2296123404C6C8F576B0DE0AABD9A6020840D4C9125EB679ED384170DBCAAC2FA30DC7FA9EE5B77D6DF7C344A0AA030E0389
                                              Malicious:false
                                              Reputation:low
                                              Preview: MANIFEST-000004.
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):139
                                              Entropy (8bit):4.418498405763055
                                              Encrypted:false
                                              SSDEEP:3:tUK6RuLRNAdWZmwv3IRRUIh7V8sIRgFhh7WGv:mSYdWZmwPiVvTtv
                                              MD5:11C65C2F70993BB8AE312521C955B394
                                              SHA1:A9D5A2F879CB8CCB4529758492F527FBAC16EF0E
                                              SHA-256:F496C356270B8FBDA77A8FCFCCF827205C64DD87E9E0C488F31CF70EDF8EA1B2
                                              SHA-512:4B8B12C98D0462A6074D8AC9942D72EFE3E9C12148F5322B87174ADAB2DECA21C1AA7608352C5E92409246F5F9EE7CFD9D46E6079E76F2137D0A523387057379
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.119 17cc Recovering log #3.2021/08/04-00:19:03.190 17cc Delete type=0 #3.2021/08/04-00:19:03.191 17cc Delete type=3 #2.
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):139
                                              Entropy (8bit):4.418498405763055
                                              Encrypted:false
                                              SSDEEP:3:tUK6RuLRNAdWZmwv3IRRUIh7V8sIRgFhh7WGv:mSYdWZmwPiVvTtv
                                              MD5:11C65C2F70993BB8AE312521C955B394
                                              SHA1:A9D5A2F879CB8CCB4529758492F527FBAC16EF0E
                                              SHA-256:F496C356270B8FBDA77A8FCFCCF827205C64DD87E9E0C488F31CF70EDF8EA1B2
                                              SHA-512:4B8B12C98D0462A6074D8AC9942D72EFE3E9C12148F5322B87174ADAB2DECA21C1AA7608352C5E92409246F5F9EE7CFD9D46E6079E76F2137D0A523387057379
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:03.119 17cc Recovering log #3.2021/08/04-00:19:03.190 17cc Delete type=0 #3.2021/08/04-00:19:03.191 17cc Delete type=3 #2.
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000004
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:MPEG-4 LOAS
                                              Category:dropped
                                              Size (bytes):50
                                              Entropy (8bit):5.028758439731456
                                              Encrypted:false
                                              SSDEEP:3:Ukk/vxQRDKIVmt+8jzn:oO7t8n
                                              MD5:031D6D1E28FE41A9BDCBD8A21DA92DF1
                                              SHA1:38CEE81CB035A60A23D6E045E5D72116F2A58683
                                              SHA-256:B51BC53F3C43A5B800A723623C4E56A836367D6E2787C57D71184DF5D24151DA
                                              SHA-512:E994CD3A8EE3E3CF6304C33DF5B7D6CC8207E0C08D568925AFA9D46D42F6F1A5BDD7261F0FD1FCDF4DF1A173EF4E159EE1DE8125E54EFEE488A1220CE85AF904
                                              Malicious:false
                                              Reputation:low
                                              Preview: V........leveldb.BytewiseComparator...#...........
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e43d18e6-757a-4ed8-93ee-25354f2cd0b8.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:modified
                                              Size (bytes):5446
                                              Entropy (8bit):5.167347058001006
                                              Encrypted:false
                                              SSDEEP:96:ncCIqj9zP/0PWccKI0ok0JCKL8VbOTQVuwn:ncCp9zn0PWcc94K6
                                              MD5:477E05A5387A290561E648CFC7DD204F
                                              SHA1:5598E9669DCA1E34BF78DB09CA83C5DBF076C75B
                                              SHA-256:C9514B1FEF3CF407F47D383C7F298AF08686E249EF1D1061A671BBE77F4147A9
                                              SHA-512:D233399E3148BE8A4064EB9AA42611DB4032FA8145A8C56E174D1CA7B6BE697EAA78CFA3F154B09F865E30E8B82E83A4C363141A9C8970EB93BC955A101F0884
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"account_id_migration_state":2,"account_tracker_service_last_update":"13272535139156421","alternate_error_pages":{"backup":true},"announcement_notification_service_first_run_time":"13245951485614034","autocomplete":{"retention_policy_last_version":85},"autofill":{"orphan_rows_removed":true},"browser":{"default_browser_infobar_last_declined":"13245951692116406","has_seen_welcome_page":true,"navi_onboard_group":"","should_reset_check_default_browser":false,"window_placement":{"bottom":974,"left":10,"maximized":true,"right":1060,"top":10,"work_area_bottom":984,"work_area_left":0,"work_area_right":1280,"work_area_top":0}},"countryid_at_install":21843,"data_reduction":{"daily_original_length":["0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","0","7355378"],"daily_received_length":["0","0","0","0","0","0","0","
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\f9a53b30-4e09-4ec3-b965-9da93bd7e311.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:modified
                                              Size (bytes):1932
                                              Entropy (8bit):4.876242082024906
                                              Encrypted:false
                                              SSDEEP:48:YALtdNTntwCXGDH3qyvz5sSRLsOATsk2TSPs0wYhbD:VNTnOCXGDHa+zNKIT8RhH
                                              MD5:CD1FDC82B62B0CB3EA512D4CB8242841
                                              SHA1:8ADCFB25F16A88EBC0CA48CB8286CB89563DFDE6
                                              SHA-256:99AE0456B70101EABE87B95A68999F6B309526F19481DCA766691B5701DEAEE5
                                              SHA-512:866B196425B6D4B38392838CCB24BD1CFF59EF786306AC8BEC8FB784D5EEFEC7EDBFF935C8C3666705A341EDD8BF29E7CC57E575A94FF4ECFEC2A3138C9F9E3D
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"net":{"http_server_properties":{"broken_alternative_services":[{"broken_count":1,"host":"clients2.google.com","isolation":[],"port":443,"protocol_str":"quic"}],"servers":[{"isolation":[],"server":"https://www.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://www.google.com","supports_spdy":true},{"isolation":[],"server":"https://ssl.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://fonts.gstatic.com","supports_spdy":true},{"isolation":[],"server":"https://apis.google.com","supports_spdy":true},{"isolation":[],"server":"https://play.google.com","supports_spdy":true},{"isolation":[],"server":"https://ogs.google.com","supports_spdy":true},{"isolation":[],"server":"https://www.googleapis.com","supports_spdy":true},{"isolation":[],"server":"https://clients2.googleusercontent.com","supports_spdy":true},{"isolation":[],"server":"https://dns.google","supports_spdy":true},{"alternative_service":[{"advertised_versions":[50],"expiration":"13275127141909391"
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):335
                                              Entropy (8bit):5.167650019483729
                                              Encrypted:false
                                              SSDEEP:6:mMyGlyq2PWXp+N23iKKdKfrzAdIFUtpzD1ZmwPzVRkwOWXp+N23iKKdKfrzILJ:DyGIva5Kk9FUtpzD1/Pzj5f5Kk2J
                                              MD5:93BDAF0CAEE28D0F2BC80B5E4C8E4CDE
                                              SHA1:5F6EC232C2CC422B9CF16E4201015D012CBE8C8C
                                              SHA-256:C9DE3D46759A80D405FC7D6A3BFDD5450D11D8ABCBEE9D2133BE9EE52F2F1FF0
                                              SHA-512:FF1F899D6B1E7D2442C32589DAAE5B5DA01DF0D0FA9F9529F36FD1831EA6F1AD9B25A6222F203777C479FD55F3C4EF52AEC19EE46F818D28087B49007A59E9C3
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:04.113 bc0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2021/08/04-00:19:04.115 bc0 Recovering log #3.2021/08/04-00:19:04.115 bc0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old.. (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):335
                                              Entropy (8bit):5.167650019483729
                                              Encrypted:false
                                              SSDEEP:6:mMyGlyq2PWXp+N23iKKdKfrzAdIFUtpzD1ZmwPzVRkwOWXp+N23iKKdKfrzILJ:DyGIva5Kk9FUtpzD1/Pzj5f5Kk2J
                                              MD5:93BDAF0CAEE28D0F2BC80B5E4C8E4CDE
                                              SHA1:5F6EC232C2CC422B9CF16E4201015D012CBE8C8C
                                              SHA-256:C9DE3D46759A80D405FC7D6A3BFDD5450D11D8ABCBEE9D2133BE9EE52F2F1FF0
                                              SHA-512:FF1F899D6B1E7D2442C32589DAAE5B5DA01DF0D0FA9F9529F36FD1831EA6F1AD9B25A6222F203777C479FD55F3C4EF52AEC19EE46F818D28087B49007A59E9C3
                                              Malicious:false
                                              Reputation:low
                                              Preview: 2021/08/04-00:19:04.113 bc0 Reusing MANIFEST C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata/MANIFEST-000001.2021/08/04-00:19:04.115 bc0 Recovering log #3.2021/08/04-00:19:04.115 bc0 Reusing old log C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata/000003.log .
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):106
                                              Entropy (8bit):3.138546519832722
                                              Encrypted:false
                                              SSDEEP:3:tbloIlrJ5ldQxl7aXVdJiG6R0RlAl:tbdlrnQxZaHIGi0R6l
                                              MD5:DE9EF0C5BCC012A3A1131988DEE272D8
                                              SHA1:FA9CCBDC969AC9E1474FCE773234B28D50951CD8
                                              SHA-256:3615498FBEF408A96BF30E01C318DAC2D5451B054998119080E7FAAC5995F590
                                              SHA-512:CEA946EBEADFE6BE65E33EDFF6C68953A84EC2E2410884E12F406CAC1E6C8A0793180433A7EF7CE097B24EA78A1FDBB4E3B3D9CDF1A827AB6FF5605DA3691724
                                              Malicious:false
                                              Reputation:low
                                              Preview: C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e...e.x.e.
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):13
                                              Entropy (8bit):2.8150724101159437
                                              Encrypted:false
                                              SSDEEP:3:Yx7:4
                                              MD5:C422F72BA41F662A919ED0B70E5C3289
                                              SHA1:AAD27C14B27F56B6E7C744A8EC5B1A7D767D7632
                                              SHA-256:02E71EB4C587FEB7EE00CE8600F97411C2774C2FC34CB95B92D5538E7F30DA59
                                              SHA-512:86010ED2B2EEBDCC5A8A076B37703669C294C6D1BFAAEA963E26A9C94B81B4C53EC765D9425E5B616159C43923F800A891F9B903659575DF02F8845521F8DC46
                                              Malicious:false
                                              Reputation:low
                                              Preview: 85.0.4183.121
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State. (copy)
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):86998
                                              Entropy (8bit):6.10220510280449
                                              Encrypted:false
                                              SSDEEP:1536:SZSGRcZdJiXrXafIyYOetKdapZsyTwL3cDGOLN0nTwY/A3iuR+:SZSFcbXafIB0u1GOJmA3iuR+
                                              MD5:FF58CCB403256DE6019E642CDB6FE4C1
                                              SHA1:10EF63C9F55DF0CF024EFDF846B1A1B3B6170F18
                                              SHA-256:94A763D43CF75F2F8936B0922EBF0B30D3A8B7EF55B1F6DC97B9E6A9F983626C
                                              SHA-512:28E5D607525B79A707F2DAB44F6FB808B50A92D55B422AB84C181687B707A0342A4767BCC5F9E73817543C0886F845AD23FF435B6FF7EF4942E3A92636284312
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"browser":{"last_redirect_origin":"","shortcut_migration_version":"85.0.4183.121"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABL95WKt94zTZq03WydzHLcAAAAAAIAAAAAABBmAAAAAQAAIAAAABAL2tyan+lsWtxhoUVdUYrYiwg8iJkppNr2ZbBFie9UAAAAAA6AAAAAAgAAIAAAABDv4gjLq1dOS7lkRG21YVXojnHhsRhNbP8/D1zs78mXMAAAAB045Od5v4BxiFP4bdRYJjDXn4W2fxYqQj2xfYeAnS1vCL4JXAsdfljw4oXIE4R7l0AAAABlt36FqChftM9b7EtaPw98XRX5Y944rq1WsGWcOPFyXOajfBL3GXBUhMXghJbDGb5WCu+JEdxaxLLxaYPp4zeP"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13245951016607996"},"plugins":{"metadata":{"adobe-flash-player":{"displayurl":true,"group_name_matcher":"*Shockwave Flash*","help_url":"https://support.google.com/chrome/?p=plugin_flash","lang":"en-US","mime_type
                                              C:\Users\user\AppData\Local\Google\Chrome\User Data\a9501a61-c296-44cf-beb0-bbd689447224.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with very long lines, with no line terminators
                                              Category:dropped
                                              Size (bytes):86998
                                              Entropy (8bit):6.10220510280449
                                              Encrypted:false
                                              SSDEEP:1536:SZSGRcZdJiXrXafIyYOetKdapZsyTwL3cDGOLN0nTwY/A3iuR+:SZSFcbXafIB0u1GOJmA3iuR+
                                              MD5:FF58CCB403256DE6019E642CDB6FE4C1
                                              SHA1:10EF63C9F55DF0CF024EFDF846B1A1B3B6170F18
                                              SHA-256:94A763D43CF75F2F8936B0922EBF0B30D3A8B7EF55B1F6DC97B9E6A9F983626C
                                              SHA-512:28E5D607525B79A707F2DAB44F6FB808B50A92D55B422AB84C181687B707A0342A4767BCC5F9E73817543C0886F845AD23FF435B6FF7EF4942E3A92636284312
                                              Malicious:false
                                              Reputation:low
                                              Preview: {"browser":{"last_redirect_origin":"","shortcut_migration_version":"85.0.4183.121"},"data_use_measurement":{"data_used":{"services":{"background":{},"foreground":{}},"user":{"background":{},"foreground":{}}}},"hardware_acceleration_mode_previous":true,"intl":{"app_locale":"en"},"legacy":{"profile":{"name":{"migrated":true}}},"os_crypt":{"encrypted_key":"RFBBUEkBAAAA0Iyd3wEV0RGMegDAT8KX6wEAAABL95WKt94zTZq03WydzHLcAAAAAAIAAAAAABBmAAAAAQAAIAAAABAL2tyan+lsWtxhoUVdUYrYiwg8iJkppNr2ZbBFie9UAAAAAA6AAAAAAgAAIAAAABDv4gjLq1dOS7lkRG21YVXojnHhsRhNbP8/D1zs78mXMAAAAB045Od5v4BxiFP4bdRYJjDXn4W2fxYqQj2xfYeAnS1vCL4JXAsdfljw4oXIE4R7l0AAAABlt36FqChftM9b7EtaPw98XRX5Y944rq1WsGWcOPFyXOajfBL3GXBUhMXghJbDGb5WCu+JEdxaxLLxaYPp4zeP"},"password_manager":{"os_password_blank":true,"os_password_last_changed":"13245951016607996"},"plugins":{"metadata":{"adobe-flash-player":{"displayurl":true,"group_name_matcher":"*Shockwave Flash*","help_url":"https://support.google.com/chrome/?p=plugin_flash","lang":"en-US","mime_type
                                              C:\Users\user\AppData\Local\Temp\23b75392-49fc-4df4-a837-3ce5e46f8130.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:very short file (no magic)
                                              Category:dropped
                                              Size (bytes):1
                                              Entropy (8bit):0.0
                                              Encrypted:false
                                              SSDEEP:3:L:L
                                              MD5:5058F1AF8388633F609CADB75A75DC9D
                                              SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                              SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                              SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                              Malicious:false
                                              Reputation:low
                                              Preview: .
                                              C:\Users\user\AppData\Local\Temp\41642dfc-1e56-4c22-8ef6-95e54307fb8a.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:very short file (no magic)
                                              Category:dropped
                                              Size (bytes):1
                                              Entropy (8bit):0.0
                                              Encrypted:false
                                              SSDEEP:3:L:L
                                              MD5:5058F1AF8388633F609CADB75A75DC9D
                                              SHA1:3A52CE780950D4D969792A2559CD519D7EE8C727
                                              SHA-256:CDB4EE2AEA69CC6A83331BBE96DC2CAA9A299D21329EFB0336FC02A82E1839A8
                                              SHA-512:0B61241D7C17BCBB1BAEE7094D14B7C451EFECC7FFCBD92598A0F13D313CC9EBC2A07E61F007BAF58FBF94FF9A8695BDD5CAE7CE03BBF1E94E93613A00F25F21
                                              Malicious:false
                                              Reputation:low
                                              Preview: .
                                              C:\Users\user\AppData\Local\Temp\browser-sslkeys.log
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):4992
                                              Entropy (8bit):4.648636893047029
                                              Encrypted:false
                                              SSDEEP:96:kz3No3IMMqPXoc3B380cFloaxWpUOAwz0WQT/hu4viM2MRMoDMzC+MTT:kz3NoJjW0cFCaEpybWQrhbvz
                                              MD5:A46A7A5619776A633C02FB78DA96BC69
                                              SHA1:7BCC4EF2461F721EB6ECADBB969D2CDF519B4B71
                                              SHA-256:1435795875E56CE57EA6FB6025AC0CF1CCA6114326C8DCCE7F90DE118FBA5C99
                                              SHA-512:8EE36866DDBD23BA06F293200D604BF8D02597687E9C81B563CD218B852B03D36880CC87A68A113066FE16D1F9BCC911F0C1BBDFC432214E0AF1AAD024FF9E61
                                              Malicious:false
                                              Reputation:low
                                              Preview: CLIENT_HANDSHAKE_TRAFFIC_SECRET 6121ec887ff0b1b70dd056c5c39c16bae6c603fac492fae31ca84e5fafb4bfb5 e69132e295be54547258971edde4c6a86f5989f6b248b02f964716b621ee7a53.SERVER_HANDSHAKE_TRAFFIC_SECRET 6121ec887ff0b1b70dd056c5c39c16bae6c603fac492fae31ca84e5fafb4bfb5 6dc34fe5664c3a904541708ef191cef97c520a0fae96afe44eb6cd7f7c2c45f4.CLIENT_HANDSHAKE_TRAFFIC_SECRET c94e24f23a8f948de0aaae7e38b35bf9a2fc89143c07119e3b36181b7bb6541c afe366a5baee75624576fe9001b6c9b4d023a08ca70adcb2e7d5814b0bdc0108.SERVER_HANDSHAKE_TRAFFIC_SECRET c94e24f23a8f948de0aaae7e38b35bf9a2fc89143c07119e3b36181b7bb6541c b4d7032acf2a6aed00bd8342c9cc967f8685ca8f363d5558c2769ca27690e4f6.CLIENT_HANDSHAKE_TRAFFIC_SECRET 228ae0fe9bd699bcd8df1dddfa57f2b51eab35798acdd90b7ed73b45c7e3ad4c 32491aebe190cddd754fd782180587b63b66963920693e4aecaa4e06f8c183bc.SERVER_HANDSHAKE_TRAFFIC_SECRET 228ae0fe9bd699bcd8df1dddfa57f2b51eab35798acdd90b7ed73b45c7e3ad4c e154480392f2ccc0be2a30acb1fdaa28446a7db0aca16d3e6dab411ec07e945a.CLIENT_TRAFFIC_SECRET_0 c94e
                                              C:\Users\user\AppData\Local\Temp\cc0edc97-816f-4b82-8d0c-35136c50e2cb.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:Google Chrome extension, version 3
                                              Category:dropped
                                              Size (bytes):248531
                                              Entropy (8bit):7.963657412635355
                                              Encrypted:false
                                              SSDEEP:3072:r+nmRykNgoldZ8GjJCiUXZSk+QSVh85PxEalRVHmcld9R6yYfEp4ABUGDcaKklrv:k3oF4Z4h45P99Fld9RBQYBVcaxlnfL
                                              MD5:541F52E24FE1EF9F8E12377A6CCAE0C0
                                              SHA1:189898BB2DCAE7D5A6057BC2D98B8B450AFAEBB6
                                              SHA-256:81E3A4D43A73699E1B7781723F56B8717175C536685C5450122B30789464AD82
                                              SHA-512:D779D78A15C5EFCA51EBD6B96A7CCB6D718741BDF7D9A37F53B2EB4B98AA1A78BC4CFA57D6E763AAB97276C8F9088940AC0476690D4D46023FF4BF52F3326C88
                                              Malicious:false
                                              Reputation:low
                                              Preview: Cr24..............0.."0...*.H.............0...........\7c.<........Fto.8.2'5..qk...%....2...C.F.9.#..e.xQ.......[...L|....3>/....u.:T.7...(.yM...?V.<?........1.a...O?d.....A.H..'.MpB..T.m..Vn Ip..>k.|1..n.<Fb..f..*Q1.....s..2..{*.6....Pp....obM..1.......b1.......(.u^.'z......v.F.W.X4."-*eu...b.........\..F!...b...l5....zJ.q.......L].....w[T0.6....E.....r..%Z.vFm.9..5!,.~g5...;.t...']....+A.....u....k...e..&..l.6r[yU...%..f.......N..V.....<+.....l..}.{...z...)y.n..'..).....,.b....5.08K%..O.g..D.S.F5o..<(....>....\f..X..I..2."l...w....7f|.~.c.4.E.......0..0...*.H............0.......).'..b.*$w\$.q&.]zF_2..;...?.U,...W..L1.2...R..#....W.....c1k.$W..$.J....+M!.Hz.n`U.I)N.|b.l....{.K@]6.LlP/....](.A..................I...).H....IQ.y.;MG.d..ix..#f.Z$|..|.?...0K...t"i..s...Y..%.Ky....0...{.!+.~v.;....J.....Z....).(6..@?v.;~..2..c....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. .0...|!..A..L.+.=...kP.!.1..
                                              C:\Users\user\AppData\Local\Temp\e9d27a10-d674-471b-b450-8e512aa94af1.tmp
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:Google Chrome extension, version 3
                                              Category:dropped
                                              Size (bytes):768843
                                              Entropy (8bit):7.992932603402907
                                              Encrypted:true
                                              SSDEEP:12288:cK2ED9wjXNC1Gse83ru82/u0eKhgxuPFrDXgtbPz54Pm1D0fBmfH1sBrJ9mTiDga:cK2ED9I48seur0/uZKCuPNbgtbz6m1ob
                                              MD5:A11D5CAF6BF849AEB84B0C95B1C3B7CF
                                              SHA1:27F410CCBD75852C01C7464A1FD7EF8C29BE3916
                                              SHA-256:D0E62ACE64AFC334330A7AC3A2CC657914FEB321F1F89AEE11D2A6D0E7D81C31
                                              SHA-512:086C124DE3A01BE467647F3BCB4EA05105F690AB45417A0E3D38935ABA9E2381DF59AF98D0FFF7823CEFD5390B48807352E135AC70977AED7B413A8CC48FB590
                                              Malicious:false
                                              Reputation:low
                                              Preview: Cr24..............0.."0...*.H.............0...........\7c.<........Fto.8.2'5..qk...%....2...C.F.9.#..e.xQ.......[...L|....3>/....u.:T.7...(.yM...?V.<?........1.a...O?d.....A.H..'.MpB..T.m..Vn Ip..>k.|1..n.<Fb..f..*Q1.....s..2..{*.6....Pp....obM..1.......b1.......(.u^.'z......v.F.W.X4."-*eu...b.........6W..>Nuw9..R{c...Nq.H.K..A!....`v.k+..?.5.>v.....;.._~....tp....x.q.V...7.m.O.~.{!.o/q.'..BK..4./?'.....L..fH&.._<..&.p.k^..\s...:1y..F.N.+...X.PO@Mo....X.G1:..Y.@;..j..........=ae...0.......DU....n...n.;.Ipr..Q....:... <.....a.Y....{ei........0..0...*.H............0.......Mbh=.[O}.+..U.KHF(n3.\"...,g.c...6)..(.E...U...#.i.a..:...N.....P...x.O...(mC;|.5.S.{m.aEx...[..fP.i`.y..5..R....v.$......l-m.............m....ni...`..W.....R.p.b.+...+.\k.R$e~.J\.&c%.d...M..j..V.%...+1F....D....X\.1ct.<........E.B.+.i@...8..^...&YR...I.o...,.....[0Y0...*.H.=....*.H.=....B..............r...2..+Y.I...k..bR.j5Sl..8.......H"i.-l..`.Q.{...F0D. D.'.N@.(..GK....m...A.0.."
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\bg\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):796
                                              Entropy (8bit):4.864931792423268
                                              Encrypted:false
                                              SSDEEP:12:1HEJMLkSlwZGGMLkSlwZ+WYpU34f145Gb+dgoxTyO8ZpU34f1L0frhmJ03OyZnLt:1HE7n4gn8WYpYrbhz8ZpotHOGAOf6aD
                                              MD5:6F8E288A9AD5B1ED8633B430E2B4D4CA
                                              SHA1:F671D3D4BEFA431D1946D706F4192D44E29B6F08
                                              SHA-256:A114E2783D0E9B12155017323BA70838F0F82A71C7EE8DC1F115AE36991241F8
                                              SHA-512:0F87F3F0D115B872288949E59ACD3CD41B1FBC64A622D8FDA6D71FAFC5A900D92ADFBB0E7EB926F2A8759BBAA0896D48728FB719BBF5EF54AC21027328F7700C
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "........ . ... ........ .. Chrome".. },.. "app_name": {.. "message": "........ . ... ........ .. Chrome".. },.. "craw_app_unavailable": {.. "message": "........... .... ...... .. .............".. },.. "craw_connect_to_network": {.. "message": "...., ........ .. . ......".. },.. "iap_unavailable": {.. "message": "........... .... ...... .. .......... ....... .. .........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "...., ...... . Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\ca\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):675
                                              Entropy (8bit):4.536753193530313
                                              Encrypted:false
                                              SSDEEP:12:1HEJ0gbbGG0gbb+WYpU34g3YbiLO+dgyGFoO8ZpU34+puiPmb03OyZnLAOfTYABk:1HE5baib6WYpm31Lt0Z8Zp8pxOGAOfKD
                                              MD5:1FDAFC926391BD580B655FBAF46ED260
                                              SHA1:C95743C3F43B2B099FEBEBC5BD850F0C20E820AC
                                              SHA-256:C67898B67F9C9209EAFDA6532B62D5789863CFB855998DD6A70E7775316CEC20
                                              SHA-512:39D95D45C5746DA3BAA7AE6A3344EA17D7A7C3569C2A56959FF119261DA08C747A320FCF701AC72B8DBDBF8BF06FD8B239017A282CDDA444F3826D4EC672CBB4
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Sistema de pagaments de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagaments de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Ara mateix aquesta aplicaci. no est. disponible.".. },.. "craw_connect_to_network": {.. "message": "Connecteu-vos a una xarxa.".. },.. "iap_unavailable": {.. "message": "La funci. Pagaments a l'aplicaci. no est. disponible actualment.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicieu la sessi. a Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\cs\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):641
                                              Entropy (8bit):4.698608127109193
                                              Encrypted:false
                                              SSDEEP:12:1HEJfZGGfZ+WYpU34OBh+dgN/O8ZpU34j05U03OyZnLAOfTYWc:1HEl4G8WYpdt8Zpq5TOGAOfW
                                              MD5:76DEC64ED1556180B452A13C83171883
                                              SHA1:CFB1E56FD587BCDC459C1D9A683B71F9849058F9
                                              SHA-256:32290D69A90E6BAAC428B10382C99221B12773BB9A184F3B93DFB48A4F6D7A40
                                              SHA-512:5230A217968D5DC463E2E92D704544311A721E5CEF65C3125CBD8DEB9C0293D3BFB5C820A6011ABF77095FDEE7DAF67D541DC202B0C9CDB0908CBB85D84885CB
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "app_name": {.. "message": "Platby Internetov.ho obchodu Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikace v sou.asn. dob. nen. dostupn..".. },.. "craw_connect_to_network": {.. "message": "P.ipojte se pros.m k s.ti.".. },.. "iap_unavailable": {.. "message": "Platby v aplikaci aktu.ln. nejsou k dispozici.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "P.ihlaste se do Chromu.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\da\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):624
                                              Entropy (8bit):4.5289746475384565
                                              Encrypted:false
                                              SSDEEP:12:1HEJJMKKFZGGJMKKFZ+WYpU34OHu+dgxlCZO8ZpU34J4Wu03OyZnLAOfTYzD:1HErMKfqMKVWYpM6lL8ZpDNOGAOfiD
                                              MD5:238B97A36E411E42FF37CEFAF2927ED1
                                              SHA1:4E47AC90BA24C8F4724D9293FA40CFD4ADA66FE0
                                              SHA-256:4977D4A053542FF66967FAED6B06585DD70E68E20BFEB533B66FE3287F9655D9
                                              SHA-512:FD0742D47B5F5AB9AAD9B4C3D57F63CB693E060EECE123A72036C6E92156D099495C7E9E9CC6DC83EEBCDDCC4B4C81FB47E4C9559DA3EBA024780FFF10C53E0A
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Betalinger i Chrome Webshop".. },.. "app_name": {.. "message": "Betalinger i Chrome Webshop".. },.. "craw_app_unavailable": {.. "message": "Appen er ikke tilg.ngelig i .jeblikket.".. },.. "craw_connect_to_network": {.. "message": "Opret forbindelse til et netv.rk.".. },.. "iap_unavailable": {.. "message": "Betaling i appen er ikke tilg.ngelig i .jeblikket.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Log ind p. Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\de\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):651
                                              Entropy (8bit):4.583694000020627
                                              Encrypted:false
                                              SSDEEP:12:1HEJQ1ZGGQ1Z+WYpU34pCEMT+dgJMlCTO8ZpU34p6FK603OyZnLAOfTYJ6K:1HEzWWYp3Bewv8Zp7k4OGAOfQj
                                              MD5:6B3E916E8C1991AA0453CBA00FEDCAAA
                                              SHA1:D6366D15912E40CA107FD42BFE9579C3336A51F9
                                              SHA-256:A62FFAB910E31531758EEE48B2CC71A8857BEC3021DEAD50B668CBA3C8667053
                                              SHA-512:87EA4311B61F29543B13F3E17DFA919D0C320B4FE370CC152E0B1514BCA79B0ABB526DDCF08621D6EBFA48923EE8FB4C667EFB120A72BD9583EEBEE7BFB80552
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Chrome Web Store-Zahlungen".. },.. "app_name": {.. "message": "Chrome Web Store-Zahlungen".. },.. "craw_app_unavailable": {.. "message": "Die App ist momentan nicht verf.gbar.".. },.. "craw_connect_to_network": {.. "message": "Bitte stellen Sie eine Verbindung zu einem Netzwerk her.".. },.. "iap_unavailable": {.. "message": "In-App-Zahlungen sind momentan nicht m.glich.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Bitte melden Sie sich in Chrome an.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\el\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):787
                                              Entropy (8bit):4.973349962793468
                                              Encrypted:false
                                              SSDEEP:24:1HEw+aZ+6WYpbWZe80A08ZpCGyDVWlOGAOf+XD:WguYpCZnpEZbGoD
                                              MD5:05C437A322C1148B5F78B2F341339147
                                              SHA1:AB53003A678E44A170E73711FBD9949833BBF3AA
                                              SHA-256:A052C32B4FCAC61152EB0ADB2C260FB6A8256AD104AA0013DB93E9798D41A070
                                              SHA-512:C36CB9202A34356DD06D377E2A088F428D0B8EBE7D2E54F8380485E9D94A0598D7F651C1E7A2FD55BE481D49C02B0812F2BA335E08611EC85EE0BD60784A6B40
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "........ ... Chrome Web Store".. },.. "app_name": {.. "message": "........ ... Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": ". ........ .... .. ..... ... ..... ..........".. },.. "craw_connect_to_network": {.. "message": ".......... .. ... .......".. },.. "iap_unavailable": {.. "message": ".. ........ ..... ......... ... ..... ..... .. ...... ...........".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": ".......... ... Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\en\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):593
                                              Entropy (8bit):4.483686991119526
                                              Encrypted:false
                                              SSDEEP:12:1HEJ6GG6+WYpU34OuFpR+dgGfFZO8ZpU34aEGFpR03OyZnLAOfTYdD:1HEVSWYpVp0JS8Zp5KpaOGAOfuD
                                              MD5:91F5BC87FD478A007EC68C4E8ADF11AC
                                              SHA1:D07DD49E4EF3B36DAD7D038B7E999AE850C5BEF6
                                              SHA-256:92F1246C21DD5FD7266EBFD65798C61E403D01A816CC3CF780DB5C8AA2E3D9C9
                                              SHA-512:FDC2A29B04E67DDBBD8FB6E8D2443E46BADCB2B2FB3A850BBD6198CDCCC32EE0BD8A9769D929FEEFE84D1015145E6664AB5FEA114DF5A864CF963BF98A65FFD9
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Chrome Web Store Payments".. },.. "app_name": {.. "message": "Chrome Web Store Payments".. },.. "craw_app_unavailable": {.. "message": "App currently unavailable.".. },.. "craw_connect_to_network": {.. "message": "Please connect to a network.".. },.. "iap_unavailable": {.. "message": "In-App Payments is currently unavailable.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Please sign into Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\en_GB\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):593
                                              Entropy (8bit):4.483686991119526
                                              Encrypted:false
                                              SSDEEP:12:1HEJ6GG6+WYpU34OuFpR+dgGfFZO8ZpU34aEGFpR03OyZnLAOfTYdD:1HEVSWYpVp0JS8Zp5KpaOGAOfuD
                                              MD5:91F5BC87FD478A007EC68C4E8ADF11AC
                                              SHA1:D07DD49E4EF3B36DAD7D038B7E999AE850C5BEF6
                                              SHA-256:92F1246C21DD5FD7266EBFD65798C61E403D01A816CC3CF780DB5C8AA2E3D9C9
                                              SHA-512:FDC2A29B04E67DDBBD8FB6E8D2443E46BADCB2B2FB3A850BBD6198CDCCC32EE0BD8A9769D929FEEFE84D1015145E6664AB5FEA114DF5A864CF963BF98A65FFD9
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Chrome Web Store Payments".. },.. "app_name": {.. "message": "Chrome Web Store Payments".. },.. "craw_app_unavailable": {.. "message": "App currently unavailable.".. },.. "craw_connect_to_network": {.. "message": "Please connect to a network.".. },.. "iap_unavailable": {.. "message": "In-App Payments is currently unavailable.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Please sign into Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\es\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):661
                                              Entropy (8bit):4.450938335136508
                                              Encrypted:false
                                              SSDEEP:12:1HEJHlbGGHlb+WYpU34ubdDH+dgxbFxTO8ZpU34lPbdlVo03OyZnLAOfTY6xjD:1HEvaC6WYpcDeEFxq8ZpNl5OGAOffD
                                              MD5:82719BD3999AD66193A9B0BB525F97CD
                                              SHA1:41194D511F1ACC16C1CA828AC81C18C8C6B47287
                                              SHA-256:4DB9B2721E625C18B9E05C04B31AF5D9694712F1CAAF6219ABE34BB08E5DB1C7
                                              SHA-512:D4C49B43427799B6292CEED11CACB1D76F7CE43EBF402B43B638A6EB2B414ED0981E386CB8CDF0B51D1BD9552934FE25B2F6392266BB73D8C9A691F65BCE0128
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Esta aplicaci.n no est. disponible en este momento.".. },.. "craw_connect_to_network": {.. "message": "Con.ctate a una red.".. },.. "iap_unavailable": {.. "message": "Los pagos en la aplicaci.n no est.n disponibles en este momento.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Inicia sesi.n en Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\es_419\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):637
                                              Entropy (8bit):4.47253983486615
                                              Encrypted:false
                                              SSDEEP:12:1HEJHlbGGHlb+WYpU34ubdDH+dgxbFxTO8ZpU34GLO03OyZnLAOfTYiJD:1HEvaC6WYpcDeEFxq8Zp4LlOGAOfvD
                                              MD5:6B2583D8D1C147E36A69A88009CBEBC7
                                              SHA1:4D4DEEB4BE6AA0181825F3371A761ABC5B4D5937
                                              SHA-256:6659BC3705311D7641A73995DCFEA80C7734F2F4EBBC3787B3892A240348324F
                                              SHA-512:37F0DBFCC1B5A2B8E4C92C49D2D9DEEF25616421350324F57E0149A45A6CCB437F5E3CBE97412C4B5DBBF2593783C7DF71E9C25A851AEAE6E4764C545723FA53
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "app_name": {.. "message": "Sistema de pagos de Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Esta aplicaci.n no est. disponible en este momento.".. },.. "craw_connect_to_network": {.. "message": "Con.ctate a una red.".. },.. "iap_unavailable": {.. "message": "En este momento, Pagos En-Apps no est. disponible.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Accede a Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\et\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):595
                                              Entropy (8bit):4.467205425399467
                                              Encrypted:false
                                              SSDEEP:12:1HEJfPGGGfPG+WYpU34Ze7z+dgrW9O8ZpU34ZwZz03OyZnLAOfTYgoLIR:1HEdvqlWYpTeObk8ZpT/OGAOfuLIR
                                              MD5:CFF6CB76EC724B17C1BC920726CB35A7
                                              SHA1:14ED068251D65A840F00C05409D705259D329FFC
                                              SHA-256:C85800BF45942FCC7FD6B1DF929C25F9CC2A977A6678966BD03D4B6B69889AFD
                                              SHA-512:53D7D01BB30C0306DE65A79FD9551D2E8C1F71F4F45F71906B009071CB3E0F231E6A50FDD78773E9B4DE94085BC7B97F829842FA21A89A2080D33458B745C46F
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Chrome'i veebipoe maksed".. },.. "app_name": {.. "message": "Chrome'i veebipoe maksed".. },.. "craw_app_unavailable": {.. "message": "Rakendus pole praegu saadaval.".. },.. "craw_connect_to_network": {.. "message": "Looge .hendus v.rguga.".. },.. "iap_unavailable": {.. "message": "Rakendusesisesed maksed ei ole praegu saadaval.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Logige Chrome'i sisse.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\fi\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):647
                                              Entropy (8bit):4.595421267152647
                                              Encrypted:false
                                              SSDEEP:12:1HEJRuzGGRuz+WYpU34ujSBu+dgYO8ZpU34J+Bu03OyZnLAOfTY5HN:1HEFcWYpPNa8ZpD+FOGAOfEHN
                                              MD5:3A01FEE829445C482D1721FF63153D16
                                              SHA1:F3EAAADDC03F943FC88B30B67F534AA13E3336DD
                                              SHA-256:0BDE54B20845124113383B6EB81E43A0F05E4EB0C44BEE3C1DFAC4CC5FEC2836
                                              SHA-512:3B92B6C86D30FD36AA3CEFF8773BA60C3FC5CC19C693540137044C5838A5503895C770C0336A4D0A3DB5E42F3FB36274D8D3F85B9DCA2F3EC0E974FDDB0BEAD8
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Chrome Web Storen maksut".. },.. "app_name": {.. "message": "Chrome Web Storen maksut".. },.. "craw_app_unavailable": {.. "message": "Sovellus ei ole t.ll. hetkell. k.ytett.viss..".. },.. "craw_connect_to_network": {.. "message": "Muodosta verkkoyhteys.".. },.. "iap_unavailable": {.. "message": "Sovelluksen sis.iset maksut eiv.t ole t.ll. hetkell. k.ytett.viss..".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Kirjaudu sis..n Chromeen.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\fil\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):658
                                              Entropy (8bit):4.5231229502550745
                                              Encrypted:false
                                              SSDEEP:12:1HEJADlbGGADlb+WYpU34hTUT+dgHfZAFFZO8ZpU34hTjzeT03OyZnLAOfTYHfvF:1HEYah6WYp7TUSoxOS8Zp7TOsOGAOfqV
                                              MD5:57AF5B654270A945BDA8053A83353A06
                                              SHA1:EEEF7A4F869F97CF471A05D345E74F982D15E167
                                              SHA-256:EC002ED92359F67818B49455DFC579E140368E6A004080AF022FD4F57F6B03F2
                                              SHA-512:5F0AE839FCF3F4EA48FF41A76655AE0F3821564AFD5D42FBB9FBB9A38E8D8F7BB5E9B6F71064588CD441261F644095A44A755C134CE546D506D9A21E488BAF52
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Mga Pagbabayad sa Chrome Web Store".. },.. "app_name": {.. "message": "Mga Pagbabayad sa Chrome Web Store".. },.. "craw_app_unavailable": {.. "message": "Kasalukuyang hindi available ang app.".. },.. "craw_connect_to_network": {.. "message": "Mangyaring kumonekta sa isang network.".. },.. "iap_unavailable": {.. "message": "Kasalukuyang hindi available ang Mga Pagbabayad na In-App.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Mangyaring mag-sign in sa Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\fr\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):677
                                              Entropy (8bit):4.552569602149629
                                              Encrypted:false
                                              SSDEEP:12:1HEJALf/nbGGALf/nb+WYpU34Owdgbyb+dgdQjO8ZpU34ITQpGnbyb03OyZnLAO8:1HE4Hna1Hn6WYpNdgpY8ZpSTQwnBOGAh
                                              MD5:8D11C90F44A6585B57B933AB38D1FFF8
                                              SHA1:3F9D44EA8807069A32AACA2AAAD02FD892E6CC90
                                              SHA-256:599491F8C52B945C16C441ADF45BFD45AFAE046DA07757D97C56AF4DE75ED3B5
                                              SHA-512:D7EF7F5AD7EF1A1595825D79B69E2B1E988AD3CF1F3881496FCCD30F241E4E9C6E457F9F5D0F855DE3536DB7A40C3E1C55946B50D3F556F4A35285066A0CD6F7
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Paiements via le Chrome.Web.Store".. },.. "app_name": {.. "message": "Paiements via le Chrome.Web.Store".. },.. "craw_app_unavailable": {.. "message": "Application indisponible pour le moment.".. },.. "craw_connect_to_network": {.. "message": "Veuillez vous connecter . un r.seau.".. },.. "iap_unavailable": {.. "message": "Les paiements via l'application ne sont pas disponibles pour le moment.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Veuillez vous connecter . Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\hi\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):835
                                              Entropy (8bit):4.791154467711985
                                              Encrypted:false
                                              SSDEEP:24:1HEs07J0JWYp9vnCSVLP8Zp6CsOGAOf8SLm:Wh7qgYp1CMLUph1GiSLm
                                              MD5:E376D757C8FD66AC70A7D2D49760B94E
                                              SHA1:1525C5B1312D409604F097768503298EC440CC4D
                                              SHA-256:8106D98C4F8DA16DB698444409558E29CC96735E188BFA303C333A5D99231C1D
                                              SHA-512:673F3F259AF2946E4F49BBED14A2A70D44BF9FDA9D7A71DC9172BA9B7B3C7F7062B16D29682B638D485B0520ED6F99E7A735F28C7C719B539559005B69FA7555
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Chrome ... ..... ......".. },.. "app_name": {.. "message": "Chrome ... ..... ......".. },.. "craw_app_unavailable": {.. "message": "......... .. ... ...... .... ...".. },.. "craw_connect_to_network": {.. "message": "..... ....... .. ...... .....".. },.. "iap_unavailable": {.. "message": "..-.. ...... ... ...... .... ...".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "..... Chrome ... .... .. .....".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\hr\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):618
                                              Entropy (8bit):4.56999230891419
                                              Encrypted:false
                                              SSDEEP:12:1HEJGiimxmbZGGGiimxmbZ+WYpU34OBOEuhopIO+dgcapZO8ZpU34GiiZrMrQphK:1HE4H4TH8WYpNjTta28ZpQVLP0SOGAOK
                                              MD5:8185D0490C86363602A137F9A261CC50
                                              SHA1:5BD933B874441CEACB9201CCC941FF67BAED6DC0
                                              SHA-256:A2B2EC359A9DD9DCCCE02859CE1E738BD30FAA4A05F1DC522893FFDF722BBC15
                                              SHA-512:D7629978FC031EA5F716F9C1065FB2FEAB48C15F10CD68830DC966FA1002C03DDC7ACDE314C7D075F9F3A0A68552A6ACBCCDEE24CF20B6C3DD1BCE6562D0396E
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Pla.anja u web-trgovini Chrome".. },.. "app_name": {.. "message": "Pla.anja u web-trgovini Chrome".. },.. "craw_app_unavailable": {.. "message": "Aplikacija trenuta.no nije dostupna.".. },.. "craw_connect_to_network": {.. "message": "Pove.ite se s mre.om.".. },.. "iap_unavailable": {.. "message": "Pla.anje u aplikaciji trenuta.no nije dostupno.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Prijavite se na Chrome.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\hu\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:UTF-8 Unicode text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):683
                                              Entropy (8bit):4.675370843321512
                                              Encrypted:false
                                              SSDEEP:12:1HEJVJiGGVJi+WYpU34Hpo9O+dgMmfgijO8ZpU34Huo9O03OyZnLAOfTYBIAYm:1HEVrk5WYpQzTUg/8ZpwoXOGAOfYIAd
                                              MD5:85609CF8623582A8376C206556ED2131
                                              SHA1:1E16EB70DB5E59BB684866FF3E3925C2DEF25A12
                                              SHA-256:32A249749F12ADB6A220BF9ADC272C7E5D9AD5497A38B0086D961E3ABA17FBC6
                                              SHA-512:27883430865D3CFA6EDFE8C6CE1442BD96150B5CE520CCF7D556A330CAA6392C712B47BD86F7350E174876BC681F6DEC94D1312402655B0AF90883A2899EC78B
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Chrome Internetes .ruh.z Fizet.si rendszere".. },.. "app_name": {.. "message": "Chrome Internetes .ruh.z Fizet.si rendszere".. },.. "craw_app_unavailable": {.. "message": "Az alkalmaz.s jelenleg nem .rhet. el.".. },.. "craw_connect_to_network": {.. "message": "K.rj.k, csatlakozzon egy h.l.zathoz.".. },.. "iap_unavailable": {.. "message": "Az alkalmaz.son bel.li fizet.s jelenleg nem .rhet. el.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Jelentkezzen be a Chrome-ba.".. }..}..
                                              C:\Users\user\AppData\Local\Temp\scoped_dir2696_2099816180\CRX_INSTALL\_locales\id\messages.json
                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):604
                                              Entropy (8bit):4.465685261172395
                                              Encrypted:false
                                              SSDEEP:12:1HEJs25bGGs25b+WYpU34ORBHAeSJ+dgkmO8ZpU34s22C/SzFAs03OyZnLAOfTYR:1HEBaA6WYpaHFH8ZptOYOGAOf2D
                                              MD5:EAB2B946D1232AB98137E760954003AA
                                              SHA1:60BDC2937905B311D2C9844DF2D639D7AC9F7F67
                                              SHA-256:C6E8800450602DE0F39FE9F6854472383813FB454B08ABAE7E25A9167CE004C3
                                              SHA-512:970FEC9A9EF0BAF7F693C4C5977F3B47914579C5B5414FCE9DBB5E4574659A5BB9AD2DE0CC886B368F49C019785AF7D2D7FE82F71341F039EADC399ED776CA12
                                              Malicious:false
                                              Reputation:low
                                              Preview: {.. "app_description": {.. "message": "Pembayaran Chrome Webstore".. },.. "app_name": {.. "message": "Pembayaran Chrome Webstore".. },.. "craw_app_unavailable": {.. "message": "Aplikasi tidak tersedia saat ini.".. },.. "craw_connect_to_network": {.. "message": "Sambungkan ke jaringan.".. },.. "iap_unavailable": {.. "message": "Pembayaran Dalam Aplikasi saat ini tidak tersedia.".. },.. "jwt_retrieve_failed": {.. "message": "The transaction could not be completed.".. },.. "please_sign_in": {.. "message": "Harap masuk ke Chrome.".. }..}..

                                              Static File Info

                                              No static file info

                                              Network Behavior

                                              Snort IDS Alerts

                                              TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                              08/04/21-00:19:03.712063ICMP402ICMP Destination Unreachable Port Unreachable192.168.2.3216.58.208.174

                                              Network Port Distribution

                                              TCP Packets

                                              TimestampSource PortDest PortSource IPDest IP
                                              Aug 4, 2021 00:19:02.164963961 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.165227890 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.165767908 CEST49715443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.166465044 CEST49716443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.186045885 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.186211109 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.186398029 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.186520100 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.211596966 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.211826086 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.232736111 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.232768059 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.248735905 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.248785019 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.248840094 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.248874903 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.248898029 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.248915911 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.248955011 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.248960018 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.249028921 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.321209908 CEST44349715206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.321336985 CEST49715443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.321616888 CEST49715443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.321757078 CEST44349716206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.321846008 CEST49716443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.322062969 CEST49716443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.500813007 CEST44349715206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.501017094 CEST44349715206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.501128912 CEST49715443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.501252890 CEST44349715206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.501450062 CEST44349715206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.501519918 CEST49715443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.501737118 CEST44349716206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.502015114 CEST44349716206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.502084970 CEST49716443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.502258062 CEST44349716206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.502487898 CEST44349716206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.502547026 CEST49716443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.648662090 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.650100946 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.650866032 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.651067019 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.651359081 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.651453018 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.651514053 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.656538963 CEST44349715206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.657336950 CEST44349716206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:02.671273947 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.672384977 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.672408104 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.672607899 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.672645092 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.672686100 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.677402020 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.677536964 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.683049917 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.683114052 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.692310095 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.692359924 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.692384958 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.692401886 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.692459106 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.692478895 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.695084095 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.695111036 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.695178032 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.695194960 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.695435047 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.695456028 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.695473909 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.695499897 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.697951078 CEST49715443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.697968960 CEST49716443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:02.710273981 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.710527897 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:02.733795881 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:02.735032082 CEST49713443192.168.2.3216.58.205.77
                                              Aug 4, 2021 00:19:02.754759073 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:02.756025076 CEST44349713216.58.205.77192.168.2.3
                                              Aug 4, 2021 00:19:03.342173100 CEST49715443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:03.342267990 CEST49716443192.168.2.3206.82.195.200
                                              Aug 4, 2021 00:19:03.497426987 CEST44349716206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:03.497459888 CEST44349715206.82.195.200192.168.2.3
                                              Aug 4, 2021 00:19:03.753050089 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.753092051 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.773972988 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.774015903 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.774264097 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.796498060 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.796530962 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.796582937 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.796686888 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.796710014 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.796786070 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.798331976 CEST49712443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.824192047 CEST44349712216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:04.174017906 CEST49729443192.168.2.3216.58.208.161
                                              Aug 4, 2021 00:19:04.195317030 CEST44349729216.58.208.161192.168.2.3
                                              Aug 4, 2021 00:19:04.195417881 CEST49729443192.168.2.3216.58.208.161

                                              UDP Packets

                                              TimestampSource PortDest PortSource IPDest IP
                                              Aug 4, 2021 00:18:51.472256899 CEST5754453192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:51.507651091 CEST53575448.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:52.261013031 CEST5598453192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:52.293298960 CEST53559848.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:53.051296949 CEST6418553192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:53.084857941 CEST53641858.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:53.689048052 CEST6511053192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:53.713737965 CEST53651108.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:54.663119078 CEST5836153192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:54.687859058 CEST53583618.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:56.095016003 CEST6349253192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:56.128806114 CEST53634928.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:56.834116936 CEST6083153192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:56.859061956 CEST53608318.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:57.540385008 CEST6010053192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:57.565294981 CEST53601008.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:58.201637983 CEST5319553192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:58.234349012 CEST53531958.8.8.8192.168.2.3
                                              Aug 4, 2021 00:18:58.936002970 CEST5014153192.168.2.38.8.8.8
                                              Aug 4, 2021 00:18:58.963571072 CEST53501418.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:00.509825945 CEST5302353192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:00.545274019 CEST53530238.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:02.111586094 CEST5934953192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:02.115266085 CEST5708453192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:02.116559029 CEST5882353192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:02.122555971 CEST5756853192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:02.151845932 CEST53588238.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:02.153669119 CEST53593498.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:02.155965090 CEST53570848.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:02.158596992 CEST53575688.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:03.061062098 CEST5436653192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:03.097737074 CEST5303453192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:03.101527929 CEST53543668.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:03.121696949 CEST5776253192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:03.133018017 CEST53530348.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:03.166687012 CEST53577628.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:03.443911076 CEST5071353192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:03.497714996 CEST53507138.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:03.529711962 CEST5898753192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:03.555788994 CEST53589878.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:03.642291069 CEST58988443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.679469109 CEST44358988216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.679518938 CEST44358988216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.679567099 CEST44358988216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.679941893 CEST58988443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.681205988 CEST58988443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.681817055 CEST58988443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.689632893 CEST58988443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.690660000 CEST58988443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.702364922 CEST5657953192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:03.711963892 CEST44358988216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.735646009 CEST44358988216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.744348049 CEST53565798.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:03.752765894 CEST60634443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:03.799608946 CEST44360634216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.806757927 CEST44360634216.58.208.174192.168.2.3
                                              Aug 4, 2021 00:19:03.807337046 CEST60634443192.168.2.3216.58.208.174
                                              Aug 4, 2021 00:19:04.108454943 CEST6129253192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:04.168327093 CEST53612928.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:05.264105082 CEST6361953192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:05.291686058 CEST53636198.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:05.782212973 CEST6194653192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:05.817172050 CEST53619468.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:06.255594969 CEST6491053192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:06.281630993 CEST53649108.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:08.258788109 CEST5942053192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:08.286488056 CEST53594208.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:09.221462011 CEST5878453192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:09.254193068 CEST53587848.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:10.430319071 CEST6397853192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:10.465110064 CEST53639788.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:11.426947117 CEST6293853192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:11.453408957 CEST53629388.8.8.8192.168.2.3
                                              Aug 4, 2021 00:19:17.988269091 CEST5570853192.168.2.38.8.8.8
                                              Aug 4, 2021 00:19:18.038156033 CEST53557088.8.8.8192.168.2.3

                                              ICMP Packets

                                              TimestampSource IPDest IPChecksumCodeType
                                              Aug 4, 2021 00:19:03.712063074 CEST192.168.2.3216.58.208.17468d7(Port unreachable)Destination Unreachable

                                              DNS Queries

                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                              Aug 4, 2021 00:19:02.111586094 CEST192.168.2.38.8.8.80x80c1Standard query (0)accounts.google.comA (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:02.116559029 CEST192.168.2.38.8.8.80xae12Standard query (0)clients2.google.comA (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:02.122555971 CEST192.168.2.38.8.8.80x890fStandard query (0)dw.myemedapps.comA (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:03.702364922 CEST192.168.2.38.8.8.80x5edfStandard query (0)clients2.google.comA (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:04.108454943 CEST192.168.2.38.8.8.80xbc1aStandard query (0)clients2.googleusercontent.comA (IP address)IN (0x0001)

                                              DNS Answers

                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                              Aug 4, 2021 00:19:02.151845932 CEST8.8.8.8192.168.2.30xae12No error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)
                                              Aug 4, 2021 00:19:02.151845932 CEST8.8.8.8192.168.2.30xae12No error (0)clients.l.google.com216.58.208.174A (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:02.153669119 CEST8.8.8.8192.168.2.30x80c1No error (0)accounts.google.com216.58.205.77A (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:02.158596992 CEST8.8.8.8192.168.2.30x890fNo error (0)dw.myemedapps.com206.82.195.200A (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:03.744348049 CEST8.8.8.8192.168.2.30x5edfNo error (0)clients2.google.comclients.l.google.comCNAME (Canonical name)IN (0x0001)
                                              Aug 4, 2021 00:19:03.744348049 CEST8.8.8.8192.168.2.30x5edfNo error (0)clients.l.google.com216.58.208.174A (IP address)IN (0x0001)
                                              Aug 4, 2021 00:19:04.168327093 CEST8.8.8.8192.168.2.30xbc1aNo error (0)clients2.googleusercontent.comgooglehosted.l.googleusercontent.comCNAME (Canonical name)IN (0x0001)
                                              Aug 4, 2021 00:19:04.168327093 CEST8.8.8.8192.168.2.30xbc1aNo error (0)googlehosted.l.googleusercontent.com216.58.208.161A (IP address)IN (0x0001)

                                              Code Manipulations

                                              Statistics

                                              Behavior

                                              Click to jump to process

                                              System Behavior

                                              General

                                              Start time:00:18:58
                                              Start date:04/08/2021
                                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              Wow64 process (32bit):false
                                              Commandline:'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://dw.myemedapps.com/RDWeb/Pages/en-US/Default.aspx'
                                              Imagebase:0x7ff77b960000
                                              File size:2150896 bytes
                                              MD5 hash:C139654B5C1438A95B321BB01AD63EF6
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:low

                                              General

                                              Start time:00:18:59
                                              Start date:04/08/2021
                                              Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                              Wow64 process (32bit):false
                                              Commandline:'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,13672721571603381085,4833477021421495498,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1708 /prefetch:8
                                              Imagebase:0x7ff77b960000
                                              File size:2150896 bytes
                                              MD5 hash:C139654B5C1438A95B321BB01AD63EF6
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:low

                                              Disassembly

                                              Reset < >