IOC Report

loading gif

Files

File Path
Type
Category
Malicious
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\1b0ce77e-42f4-4f86-b0f7-cfb07eec78c4.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\7e90888b-d6fc-42b7-98a3-3124be7811d4.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\8a9997cd-fccc-4164-9ffe-b7527f444a15.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\8b595e86-570d-4281-9d22-2e6f700b909c.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\075ff711-1020-4ba6-babb-ce40a063312c.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\20f26a91-a288-4f42-841e-192b19693387.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\26a31f6b-2e06-4e36-8492-4da0999a2ca0.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\473fdca5-775f-4ebd-8ff4-6fb26b936cfa.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\515de975-ea33-400e-9526-cffb22458f9a.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\6e6ea224-ad85-4de1-8238-74ee8dffd9dd.tmp
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\79f65a89-2b97-4da3-b741-ad693718527a.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\8c3c02c8-05e3-47dc-b779-7a8dbca6aa5d.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old.. (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State.. (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences\ (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences\* (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\063cbb27-8a91-48d1-a58e-a2cb8ba912da.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent StateMP (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\3ae95ac5-f762-4df9-9b77-ad0c33161ad2.tmp
ASCII text, with very long lines, with no line terminators
modified
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent StateMP (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.oldng (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000003.log
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a0dbebac-2a35-432f-9acb-811448de85d0.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\bd2333ca-9be1-4a73-8a28-11b3c0ae0bef.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\c158838d-046a-4065-bcc9-82b21d23da4a.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\c333d62a-10dd-4e8b-9669-57d40d6fb40b.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\cd22c5c6-def7-4e95-b4d2-d45c0c301e12.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENTaa (copy)
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e54a1543-0767-4343-b2f8-1320689cb912.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local Statew (copy)
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
SysEx File -
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\c61591d3-c343-453d-9f25-4a438ec6fb93.tmp
data
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\c7893c37-b5fd-4f56-937c-4868231288db.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\ce8988cc-d0d0-454a-8566-6b6031bb8a0b.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\e946104e-5fcb-4aa2-aa90-ddc356e24840.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\ecc44176-9b7e-4ae7-9e70-2e9e93888a86.tmp
SysEx File -
dropped
clean
C:\Users\user\AppData\Local\Google\Chrome\User Data\fbb9b33b-b635-4493-b664-ea76a33626c3.tmp
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\03318ba8-0792-4389-80ea-22ab98943fcd.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\06c46bb2-9c5b-4320-9530-1e4acb6eac46.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\668_1447074127\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\668_1447074127\download_file_types.pb
data
dropped
clean
C:\Users\user\AppData\Local\Temp\668_1447074127\manifest.fingerprint
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\668_1447074127\manifest.json
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\6b264268-5628-4600-8dc4-64e516e786ec.tmp
very short file (no magic)
dropped
clean
C:\Users\user\AppData\Local\Temp\773c2380-9258-4235-be06-94e4cfe1fda2.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\773c2380-9258-4235-be06-94e4cfe1fda2.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\am\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ar\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\bn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\en\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\fa\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\fil\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\gu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\id\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\iw\messages.json
HTML document, ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\kn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ml\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\mr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ms\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\nl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\pt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\sw\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\ta\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\te\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\zh\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\angular.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\background_script.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\cast_sender.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\common.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\feedback.css
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\feedback.html
HTML document, ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\feedback_script.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\manifest.json
ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\material_css_min.css
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\mirroring_cast_streaming.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\mirroring_common.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\mirroring_hangouts.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1004838962\CRX_INSTALL\mirroring_webrtc.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\06c46bb2-9c5b-4320-9530-1e4acb6eac46.tmp
Google Chrome extension, version 3
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\craw_background.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\craw_window.js
ASCII text, with very long lines
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\css\craw_window.css
ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\html\craw_window.html
HTML document, ASCII text
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\flapper.gif
GIF image data, version 89a, 30 x 30
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\topbar_floating_button.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\topbar_floating_button_close.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\topbar_floating_button_hover.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\topbar_floating_button_maximize.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\images\topbar_floating_button_pressed.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
clean
C:\Users\user\AppData\Local\Temp\scoped_dir668_1750152559\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
clean
There are 177 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation "https://alliance-bokiau.odoo.com/
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1564,7280486331179565442,18425855827197029187,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1936 /prefetch:8
clean
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1564,7280486331179565442,18425855827197029187,131072 --lang=en-US --service-sandbox-type=audio --enable-audio-service-sandbox --mojo-platform-channel-handle=5956 /prefetch:8
clean

URLs

Name
IP
Malicious
https://alliance-bokiau.odoo.com/
malicious
https://me-media.com/wp-includes/contract/viewdoc/0fflink.php#authoriz3?cli3nt_k3y=6w1zh-qy7iy-x9rit1642165510916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954wb4ch-32t7a-m2duu
malicious
https://alliance-bokiau.odoo.com/website/social/twitter
clean
https://alliance-bokiau.odoo.com/contactus
clean
https://stats.g.doubleclick.net
unknown
clean
https://apis.google.com/js/client.js
unknown
clean
https://www.google.com/images/cleardot.gif
unknown
clean
https://alliance-bokiau.odoo.com/saas_trial/static/xml/trial.xml
34.76.138.44
clean
https://www.odoo.com/?utm_source=db&utm_medium=website
clean
https://crash.corp.google.com/samples?reportid=&q=
unknown
clean
https://www.google.com/log?format=json&hasfast=true
unknown
clean
https://alliance-bokiau.odoo.com/web/image/website/1/favicon?unique=589931b
34.76.138.44
clean
https://www.odoo.com/app/website?utm_source=db&utm_medium=website
clean
http://www.odoo.com/?utm_source=db&utm_medium=website
178.33.40.43
clean
http://www.odoo.com/app/website?utm_source=db&utm_medium=website
178.33.40.43
clean
https://sandbox.google.com/payments/v4/js/integrator.js
unknown
clean
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
unknown
clean
https://accounts.google.com/MergeSession
unknown
clean
https://preprod-hangouts-googleapis.sandbox.google.com
unknown
clean
https://alliance-bokiau.odoo.com/
34.76.138.44
clean
https://clients2.googleusercontent.com/crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx
142.250.181.225
clean
https://www.google.com
unknown
clean
https://alliance-bokiau.odoo.com/web/assets/194-df48839/1/web.assets_frontend.min.css
34.76.138.44
clean
https://hangouts.clients6.google.com
unknown
clean
https://meet.google.com
unknown
clean
https://hangouts.google.com/hangouts/_/logpref
unknown
clean
https://accounts.google.com
unknown
clean
https://clients2.google.com/cr/report
unknown
clean
https://alliance-bokiau.odoo.com/web/webclient/qweb/1642197894348?bundle=web.assets_frontend
34.76.138.44
clean
http://angularjs.org
unknown
clean
https://alliance-bokiau.odoo.com/website/static/src/xml/website.xml
34.76.138.44
clean
https://alliance-bokiau.odoo.com/web/login
clean
https://creativecommons.org/publicdomain/zero/1.0/.
unknown
clean
https://github.com/angular/material
unknown
clean
https://apis.google.com
unknown
clean
https://alliance-bokiau.odoo.com/web/static/img/odoo_logo_tiny.png
34.76.138.44
clean
https://alliance-bokiau.odoo.com/web/assets/190-25a9f43/1/web.assets_common_lazy.min.js
34.76.138.44
clean
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
unknown
clean
https://github.com/madler/zlib/blob/master/zlib.h
unknown
clean
https://www-googleapis-staging.sandbox.google.com
unknown
clean
https://alliance-bokiau.odoo.com/website/social/facebook
clean
https://alliance-bokiau.odoo.com/web/static/lib/fontawesome/fonts/fontawesome-webfont.woff2?v=4.7.0
34.76.138.44
clean
https://clients2.google.com
unknown
clean
https://alliance-bokiau.odoo.com/2
unknown
clean
https://alliance-bokiau.odoo.com/web/image/website/1/logo/alliance-bokiau?unique=589931b
34.76.138.44
clean
https://www.google.com/tools/feedback
unknown
clean
https://alliance-bokiau.odoo.com/web/assets/191-20376a7/1/web.assets_frontend_lazy.min.js
34.76.138.44
clean
http://www.apache.org/licenses/LICENSE-2.0
unknown
clean
https://dns.google
unknown
clean
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
unknown
clean
https://www.google.com/intl/en-US/chrome/blank.html
unknown
clean
https://alliance-bokiau.odoo.com/
clean
https://ogs.google.com
unknown
clean
https://alliance-bokiau.odoo.com/saas_worker/trial_info
34.76.138.44
clean
https://support.google.com/chromecast/troubleshooter/2995236
unknown
clean
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions
unknown
clean
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
172.217.16.142
clean
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
142.250.184.205
clean
https://payments.google.com/payments/v4/js/integrator.js
unknown
clean
https://www.google.com;
unknown
clean
https://hangouts.google.com/
unknown
clean
https://alliance-bokiau.odoo.com/web/assets/188-f875f43/1/web.assets_common_minimal.min.js
34.76.138.44
clean
https://www.google.com/images/x2.gif
unknown
clean
https://www.google.com/images/dot2.gif
unknown
clean
https://meetings.clients6.google.com
unknown
clean
https://play.google.com/log?format=json&hasfast=true
unknown
clean
http://tools.ietf.org/html/rfc1950
unknown
clean
https://alliance-bokiau.odoo.com/website/translations/63c39b9719623b23090242bff39258f3aa29fe2b
34.76.138.44
clean
https://alliance-bokiau.odoo.com/website/social/linkedin
clean
https://support.google.com/chromecast/answer/2998456
unknown
clean
https://alliance-bokiau.odoo.com/web/assets/189-83f6bc7/1/web.assets_frontend_minimal.min.js
34.76.138.44
clean
https://clients2.googleusercontent.com
unknown
clean
https://docs.google.com
unknown
clean
https://www.google.com/
unknown
clean
https://alliance-bokiau.odoo.com/web/assets/185-0cacbc7/1/web.assets_common.min.css
34.76.138.44
clean
https://feedback.googleusercontent.com
unknown
clean
https://www.google.co.uk
unknown
clean
https://clients2.google.com/service/update2/crx
unknown
clean
https://clients6.google.com
unknown
clean
There are 68 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gstaticadssl.l.google.com
142.250.186.163
clean
a.nel.cloudflare.com
35.190.80.1
clean
alliance-bokiau.odoo.com
34.76.138.44
clean
accounts.google.com
142.250.184.205
clean
www-google-analytics.l.google.com
142.250.186.78
clean
stats.l.doubleclick.net
74.125.140.155
clean
odoo.com
178.33.40.43
clean
me-media.com
217.160.0.253
clean
odoocdn.com
104.26.6.148
clean
download.odoocdn.com
172.67.69.4
clean
www.google.co.uk
142.250.186.99
clean
www.google.com
142.250.185.164
clean
clients.l.google.com
172.217.16.142
clean
googlehosted.l.googleusercontent.com
142.250.181.225
clean
ka-f.fontawesome.com
unknown
clean
www.linkedin.com
unknown
clean
px.ads.linkedin.com
unknown
clean
stats.g.doubleclick.net
unknown
clean
clients2.googleusercontent.com
unknown
clean
clients2.google.com
unknown
clean
snap.licdn.com
unknown
clean
www.odoo.com
unknown
clean
There are 12 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.168.2.1
unknown
unknown
clean
217.160.0.253
me-media.com
Germany
clean
178.33.40.43
odoo.com
France
clean
142.250.185.164
www.google.com
United States
clean
34.76.138.44
alliance-bokiau.odoo.com
United States
clean
172.67.69.4
download.odoocdn.com
United States
clean
142.250.184.205
accounts.google.com
United States
clean
35.190.80.1
a.nel.cloudflare.com
United States
clean
104.26.6.148
odoocdn.com
United States
clean
142.250.186.99
www.google.co.uk
United States
clean
172.217.16.142
clients.l.google.com
United States
clean
142.250.186.78
www-google-analytics.l.google.com
United States
clean
142.250.186.163
gstaticadssl.l.google.com
United States
clean
142.250.181.225
googlehosted.l.googleusercontent.com
United States
clean
74.125.140.155
stats.l.doubleclick.net
United States
clean
239.255.255.250
unknown
Reserved
clean
192.168.2.255
unknown
unknown
clean
127.0.0.1
unknown
unknown
clean
There are 8 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
clean
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
clean
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
clean
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
clean
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
clean
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blacklist_cache_md5_digest
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
clean
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
clean
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
clean
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
clean
There are 31 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1FF81A3A000
unkown
page read and write
clean
7708A7B000
stack
page read and write
clean
7FF516235000
unkown image
page readonly
clean
7FF5AB908000
unkown image
page readonly
clean
7FF513B16000
unkown image
page readonly
clean
7FF516093000
unkown image
page readonly
clean
2CAB9713000
unkown
page read and write
clean
7FF5161C7000
unkown image
page readonly
clean
2A9E9FE0000
unkown image
page readonly
clean
7DF56F292000
unkown image
page readonly
clean
2CAB9650000
unkown
page read and write
clean
7FF5ABE2B000
unkown image
page readonly
clean
7FF5AB285000
unkown image
page readonly
clean
1FF81A13000
unkown
page read and write
clean
D66A1F7000
stack
page read and write
clean
1DCE6313000
unkown
page read and write
clean
1DCE6A02000
unkown
page read and write
clean
2CAB94E0000
unkown image
page readonly
clean
7FF5160BE000
unkown image
page readonly
clean
7FF513A89000
unkown image
page readonly
clean
2CAB94B0000
unkown image
page readonly
clean
1DCE6308000
unkown
page read and write
clean
7DF529440000
unkown image
page readonly
clean
7DF568F70000
unkown image
page readonly
clean
1FF81A6C000
unkown
page read and write
clean
1FF81A64000
unkown
page read and write
clean
7DF52BBD0000
unkown image
page readonly
clean
1FF81CD0000
unkown image
page readonly
clean
2CAB9A00000
unkown image
page readonly
clean
184DB526000
unkown
page read and write
clean
1DCE6200000
unkown
page read and write
clean
1FF81A7E000
unkown
page read and write
clean
7DF568F62000
unkown image
page readonly
clean
7FF51629B000
unkown image
page readonly
clean
7FF513A5C000
unkown image
page readonly
clean
1DCE6150000
unkown image
page readonly
clean
1DCE625A000
unkown
page read and write
clean
1FF81B02000
unkown
page read and write
clean
1FF81A41000
unkown
page read and write
clean
BE8697E000
stack
page read and write
clean
7FF5ABCA4000
unkown image
page readonly
clean
1FF81A46000
unkown
page read and write
clean
7DF57BE10000
unkown image
page readonly
clean
7FF5162AD000
unkown image
page readonly
clean
1DCE625F000
unkown
page read and write
clean
2CAB9680000
unkown
page read and write
clean
7DF5C1720000
unkown image
page readonly
clean
28E95079000
unkown
page read and write
clean
7DF529452000
unkown image
page readonly
clean
1FF81A65000
unkown
page read and write
clean
7FF5ABD3C000
unkown image
page readonly
clean
7DF56F2B0000
unkown image
page readonly
clean
7FF516125000
unkown image
page readonly
clean
2A9EA918000
unkown
page read and write
clean
1DCE6300000
unkown
page read and write
clean
7FF515DA8000
unkown image
page readonly
clean
28E94EF0000
unkown image
page readonly
clean
770897C000
stack
page read and write
clean
2CAB9702000
unkown
page read and write
clean
7DF5C1722000
unkown image
page readonly
clean
2A9EF6D0000
unkown
page read and write
clean
7DF530DA2000
unkown image
page readonly
clean
7FF5ABAE3000
unkown image
page readonly
clean
7FF5ABD5D000
unkown image
page readonly
clean
7FF513A93000
unkown image
page readonly
clean
7FF5ABE2F000
unkown image
page readonly
clean
7FF51611F000
unkown image
page readonly
clean
2CAB9613000
unkown
page read and write
clean
7DF5C1740000
unkown image
page readonly
clean
7FF5ABD37000
unkown image
page readonly
clean
7FF5AB656000
unkown image
page readonly
clean
7708BF7000
stack
page read and write
clean
7FF5160E3000
unkown image
page readonly
clean
7DF52BBD2000
unkown image
page readonly
clean
1DCE6020000
unkown image
page readonly
clean
7FF5161D7000
unkown image
page readonly
clean
7DF530DC0000
unkown image
page readonly
clean
7DF5C1720000
unkown image
page readonly
clean
1FF81A76000
unkown
page read and write
clean
7DF529452000
unkown image
page readonly
clean
7FF5ABE2F000
unkown image
page readonly
clean
1FF81A85000
unkown
page read and write
clean
184DB6D0000
unkown
page read and write
clean
7DF57BE20000
unkown image
page readonly
clean
7FF51609E000
unkown image
page readonly
clean
7FF5ABE0D000
unkown image
page readonly
clean
7FF515E9C000
unkown image
page readonly
clean
7FF5ABD23000
unkown image
page readonly
clean
1FF81A67000
unkown
page read and write
clean
1DCE6254000
unkown
page read and write
clean
7FF513723000
unkown image
page readonly
clean
7FF513B3B000
unkown image
page readonly
clean
7FF513AB5000
unkown image
page readonly
clean
1FF81950000
unkown image
page readonly
clean
1FF81A3B000
unkown
page read and write
clean
7708AFE000
stack
page read and write
clean
1FF81A00000
unkown
page read and write
clean
2A9EF760000
unkown
page read and write
clean
7FF5ABBCD000
unkown image
page readonly
clean
7FF5ABC43000
unkown image
page readonly
clean
7DF52BBE0000
unkown image
page readonly
clean
1FF818E0000
heap private
page read and write
clean
184DB4FE000
unkown
page read and write
clean
D669B3B000
unkown
page read and write
clean
7DF52BBC0000
unkown image
page readonly
clean
1FF81A59000
unkown
page read and write
clean
1FF81ED0000
unkown image
page readonly
clean
7FF5ABBFE000
unkown image
page readonly
clean
1FF81A45000
unkown
page read and write
clean
1DCE6258000
unkown
page read and write
clean
7708CFE000
stack
page read and write
clean
1FF81A31000
unkown
page read and write
clean
1DCE6264000
unkown
page read and write
clean
183305C0000
unkown
page read and write
clean
2CAB9671000
unkown
page read and write
clean
7FF515F83000
unkown image
page readonly
clean
BE869FE000
stack
page read and write
clean
184DB526000
unkown
page read and write
clean
7FF513B4F000
unkown image
page readonly
clean
1FF81A3D000
unkown
page read and write
clean
7FF516205000
unkown image
page readonly
clean
7FF516213000
unkown image
page readonly
clean
1DCE623C000
unkown
page read and write
clean
2A9EF8E1000
unkown
page read and write
clean
7FF513A7D000
unkown image
page readonly
clean
7FF513A68000
unkown image
page readonly
clean
2A9EF7F0000
unkown
page read and write
clean
2CAB9602000
unkown
page read and write
clean
1FF81A60000
unkown
page read and write
clean
7FF513B34000
unkown image
page readonly
clean
2CAB9500000
heap default
page read and write
clean
7FF5ABD95000
unkown image
page readonly
clean
2A9EA918000
unkown
page read and write
clean
7FF513A9A000
unkown image
page readonly
clean
1FF81910000
unkown image
page readonly
clean
2CAB968C000
unkown
page read and write
clean
1DCE6600000
unkown image
page readonly
clean
BE86F7E000
stack
page read and write
clean
7DF522B80000
unkown image
page readonly
clean
1FF81A42000
unkown
page read and write
clean
1DCE622A000
unkown
page read and write
clean
2A9EF6B4000
unkown
page read and write
clean
7FF50D27F000
unkown image
page readonly
clean
7FF5ABD73000
unkown image
page readonly
clean
2CAB9646000
unkown
page read and write
clean
2A9EF902000
unkown
page read and write
clean
1FF818F0000
unkown image
page readonly
clean
2A9EF690000
unkown
page read and write
clean
7FF5AB8F3000
unkown image
page readonly
clean
BE86E7E000
stack
page read and write
clean
18330510000
unkown image
page readonly
clean
1FF81A70000
unkown
page read and write
clean
7DF427310000
unkown image
page readonly
clean
BE8707F000
stack
page read and write
clean
7DF52BBD0000
unkown image
page readonly
clean
7DF568F50000
unkown image
page readonly
clean
7FF5161FD000
unkown image
page readonly
clean
1FF81A7F000
unkown
page read and write
clean
7DF429A90000
unkown image
page readonly
clean
7DF529440000
unkown image
page readonly
clean
1FF81A68000
unkown
page read and write
clean
2CAB94B0000
unkown image
page readonly
clean
D66A3FE000
stack
page read and write
clean
2A9EF7F0000
unkown
page read and write
clean
1FF81A6E000
unkown
page read and write
clean
7DF5C1732000
unkown image
page readonly
clean
7FF516296000
unkown image
page readonly
clean
2CAB9700000
unkown
page read and write
clean
1FF82202000
unkown
page read and write
clean
7DF52BBE0000
unkown image
page readonly
clean
2A9EF6B1000
unkown
page read and write
clean
1DCE6000000
unkown image
page read and write
clean
7FF5161C3000
unkown image
page readonly
clean
7FF51B4AF000
unkown image
page readonly
clean
7DF522B70000
unkown image
page readonly
clean
2A9EF690000
unkown
page read and write
clean
7DF530DA0000
unkown image
page readonly
clean
7708DFE000
stack
page read and write
clean
1DCE6020000
unkown image
page readonly
clean
1FF81A57000
unkown
page read and write
clean
2CAB9490000
unkown image
page read and write
clean
2CAB962A000
unkown
page read and write
clean
1DCE6213000
unkown
page read and write
clean
1FF82050000
unkown image
page readonly
clean
7FF513B0F000
unkown image
page readonly
clean
183305C0000
unkown
page read and write
clean
1FF81A26000
unkown
page read and write
clean
1FF81920000
unkown image
page readonly
clean
BE868FB000
unkown
page read and write
clean
7DF4BF5F0000
unkown image
page readonly
clean
BE86D7E000
stack
page read and write
clean
1DCE625C000
unkown
page read and write
clean
7FF5161E8000
unkown image
page readonly
clean
7DF529460000
unkown image
page readonly
clean
2CAB94D0000
unkown image
page readonly
clean
7FF515D99000
unkown image
page readonly
clean
7DF56F290000
unkown image
page readonly
clean
2CAB95E0000
unkown image
page readonly
clean
7DF5C1730000
unkown image
page readonly
clean
D669BBE000
stack
page read and write
clean
7FF5ABE1B000
unkown image
page readonly
clean
7DF568F52000
unkown image
page readonly
clean
1DCE6170000
unkown
page read and write
clean
2CAB963C000
unkown
page read and write
clean
1FF81A4E000
unkown
page read and write
clean
1DCE627C000
unkown
page read and write
clean
7FF5162CF000
unkown image
page readonly
clean
7FF5162CB000
unkown image
page readonly
clean
21E67A00000
unkown image
page readonly
clean
D66A0FE000
stack
page read and write
clean
1DCE6400000
unkown image
page readonly
clean
7FF513A47000
unkown image
page readonly
clean
7FF513B4B000
unkown image
page readonly
clean
2A9EA918000
unkown
page read and write
clean
7FF5ABBF3000
unkown image
page readonly
clean
7FF5ABD69000
unkown image
page readonly
clean
1FF81A7C000
unkown
page read and write
clean
7FF516209000
unkown image
page readonly
clean
1FF81A29000
unkown
page read and write
clean
2A9EF8C5000
unkown
page read and write
clean
7FF5162B4000
unkown image
page readonly
clean
2CAB94A0000
heap private
page read and write
clean
28E9506C000
unkown
page read and write
clean
77085AE000
stack
page read and write
clean
184DB526000
unkown
page read and write
clean
1FF81A5C000
unkown
page read and write
clean
7DF522B82000
unkown image
page readonly
clean
7DF52BBC0000
unkown image
page readonly
clean
7DF568F60000
unkown image
page readonly
clean
2A9EF69E000
unkown
page read and write
clean
184DC3B0000
unkown
page read and write
clean
7FF5ABDE8000
unkown image
page readonly
clean
7FF513B4F000
unkown image
page readonly
clean
2A9EF691000
unkown
page read and write
clean
7FF5ABC7F000
unkown image
page readonly
clean
D66A2FE000
stack
page read and write
clean
2A9EF7E0000
unkown
page read and write
clean
184DB4FE000
unkown
page read and write
clean
1FF81970000
unkown
page read and write
clean
7FF5161DC000
unkown image
page readonly
clean
7FF5ABDFB000
unkown image
page readonly
clean
7DF529450000
unkown image
page readonly
clean
2A9EF90D000
unkown
page read and write
clean
184DB51F000
unkown
page read and write
clean
7DF530DB2000
unkown image
page readonly
clean
1FF81A40000
unkown
page read and write
clean
7FF5ABD65000
unkown image
page readonly
clean
7DF529442000
unkown image
page readonly
clean
7DF56F2A0000
unkown image
page readonly
clean
2CAB9600000
unkown
page read and write
clean
2A9EF7F0000
unkown
page read and write
clean
2A9EF7F0000
unkown
page read and write
clean
2A9EF698000
unkown
page read and write
clean
7FF513B20000
unkown image
page readonly
clean
1FF81A5F000
unkown
page read and write
clean
28E95068000
unkown
page read and write
clean
D669F7B000
stack
page read and write
clean
7FF5138ED000
unkown image
page readonly
clean
7DF57BE02000
unkown image
page readonly
clean
7FF5ABC1E000
unkown image
page readonly
clean
7DF5C1730000
unkown image
page readonly
clean
7DF529460000
unkown image
page readonly
clean
7FF5ABDEF000
unkown image
page readonly
clean
7FF5ABC85000
unkown image
page readonly
clean
1FF81940000
heap default
page read and write
clean
184DB4FE000
unkown
page read and write
clean
7FF5162BB000
unkown image
page readonly
clean
1FF81A61000
unkown
page read and write
clean
7FF515D93000
unkown image
page readonly
clean
7FF513803000
unkown image
page readonly
clean
7DF522B72000
unkown image
page readonly
clean
7FF5ABE1E000
unkown image
page readonly
clean
1FF81A62000
unkown
page read and write
clean
7FF5AB8F9000
unkown image
page readonly
clean
1FF81A6A000
unkown
page read and write
clean
7FF5133C5000
unkown image
page readonly
clean
7FF513399000
unkown image
page readonly
clean
7FF5162CF000
unkown image
page readonly
clean
1DCE6070000
heap default
page read and write
clean
2A9EF8DF000
unkown
page read and write
clean
7DF5C1740000
unkown image
page readonly
clean
2A9EF8E5000
unkown
page read and write
clean
7DF522B90000
unkown image
page readonly
clean
2A9EA959000
unkown
page read and write
clean
1FF818F0000
unkown image
page readonly
clean
1FF81A44000
unkown
page read and write
clean
1DCE6050000
unkown image
page readonly
clean
7FF5AB27F000
unkown image
page readonly
clean
1FF81A63000
unkown
page read and write
clean
2A9EF6D4000
unkown
page read and write
clean
7FF5162BE000
unkown image
page readonly
clean
1DCE6040000
unkown image
page readonly
clean
2CAB9E02000
unkown
page read and write
clean
1FF818D0000
unkown image
page read and write
clean
7FF5162A0000
unkown image
page readonly
clean
184DB512000
unkown
page read and write
clean
7FF5ABD27000
unkown image
page readonly
clean
7FF516288000
unkown image
page readonly
clean
7FF513B08000
unkown image
page readonly
clean
2CAB9656000
unkown
page read and write
clean
7DF5C1732000
unkown image
page readonly
clean
7FF54D64E000
unkown image
page readonly
clean
7FF513680000
unkown image
page readonly
clean
1DCE6780000
unkown image
page readonly
clean
770852C000
unkown
page read and write
clean
7FF513A85000
unkown image
page readonly
clean
7FF51606D000
unkown image
page readonly
clean
2A9EA959000
unkown
page read and write
clean
7FF55999F000
unkown image
page readonly
clean
770887D000
stack
page read and write
clean
1FF81A58000
unkown
page read and write
clean
1DCE629B000
unkown
page read and write
clean
7DF529442000
unkown image
page readonly
clean
7FF5ABDF6000
unkown image
page readonly
clean
7FF5ABD48000
unkown image
page readonly
clean
184DB410000
unkown image
page readonly
clean
7FF55365F000
unkown image
page readonly
clean
7FF5ABE14000
unkown image
page readonly
clean
7DF52BBC2000
unkown image
page readonly
clean
183305C0000
unkown
page read and write
clean
184DB4F6000
unkown
page read and write
clean
1FF81A75000
unkown
page read and write
clean
7FF513B1B000
unkown image
page readonly
clean
7FF516144000
unkown image
page readonly
clean
7DF52BBD2000
unkown image
page readonly
clean
2CAB9800000
unkown image
page readonly
clean
D669E7E000
stack
page read and write
clean
D66A07B000
stack
page read and write
clean
2CAB9C60000
unkown
page read and write
clean
2A9EF8F4000
unkown
page read and write
clean
28E95077000
unkown
page read and write
clean
7FF51621A000
unkown image
page readonly
clean
7FF5ABE00000
unkown image
page readonly
clean
7FF513B3E000
unkown image
page readonly
clean
7DF5C1722000
unkown image
page readonly
clean
2A9EF908000
unkown
page read and write
clean
7DF530DB0000
unkown image
page readonly
clean
7FF56650F000
unkown image
page readonly
clean
7DF529450000
unkown image
page readonly
clean
7DF52BBC2000
unkown image
page readonly
clean
1DCE6302000
unkown
page read and write
clean
1FF81A5A000
unkown
page read and write
clean
7FF5ABD7A000
unkown image
page readonly
clean
7DF56F2A2000
unkown image
page readonly
clean
7FF51628F000
unkown image
page readonly
clean
7DF57BE12000
unkown image
page readonly
clean
2CAB9B80000
unkown image
page readonly
clean
7DF57BE00000
unkown image
page readonly
clean
1DCE6010000
heap private
page read and write
clean
2A9EF6C0000
unkown
page read and write
clean
1FF81A47000
unkown
page read and write
clean
2CAB9708000
unkown
page read and write
clean
There are 342 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://me-media.com/wp-includes/contract/viewdoc/0fflink.php#authoriz3?cli3nt_k3y=6w1zh-qy7iy-x9rit1642165510916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954916611227e5faa3b2fdd214c11fa6954wb4ch-32t7a-m2duu
malicious
https://alliance-bokiau.odoo.com/
clean
https://alliance-bokiau.odoo.com/contactus
clean
https://alliance-bokiau.odoo.com/web/login
clean
https://alliance-bokiau.odoo.com/website/social/facebook
clean
https://alliance-bokiau.odoo.com/website/social/twitter
clean
https://alliance-bokiau.odoo.com/website/social/linkedin
clean
https://www.odoo.com/?utm_source=db&utm_medium=website
clean
https://www.odoo.com/app/website?utm_source=db&utm_medium=website
clean