IOC Report

loading gif

Files

File Path
Type
Category
Malicious
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\0a1bc4ae-dd57-4190-99b5-439e151fb82f.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\20341a16-2700-4268-b41a-59f5659b1c78.tmp
SysEx File -
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\6ae27d30-de20-40e5-b9ed-71d5d590f36e.tmp
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\74f95dce-cbca-4e96-95cc-fa61705f26fd.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\7de54a08-669a-4803-97ab-e12820718386.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\8b154e20-1d1b-4a9f-84f2-e2beef0647b8.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\97d8972c-6b5a-44fd-bb9e-9a5018fe7784.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0133e892-2634-4158-a317-23128c66daa2.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\090a761e-befd-4e8f-92f6-27d001ce54f6.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\122d556a-d8c1-44e2-90dc-8219c78414a8.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\2c33d287-1446-4117-8bce-861462388027.tmp
ASCII text, with no line terminators
modified
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\40171857-e87f-4d3c-a526-9275c3ce3799.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\4a3aebc2-cf05-42ed-85f3-46549de543e5.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\575c095b-4b7e-4f5a-b52a-ebfbe5f5a731.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5f08fc45-e336-4c62-8b80-403450062262.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\64d0eb7f-c1bc-42a8-a0f8-b801e5644dcf.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\9a09c0dd-d742-4dd6-a223-9025a1c05e4a.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old1 (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cookies
SQLite 3.x database, last written using SQLite version 3032001
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Session
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Current Tabs
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG.old. (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State\LOG.oldo (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\8520.615.0.5_1\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Favicons
SQLite 3.x database, last written using SQLite version 3032001
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
data
modified
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History
SQLite 3.x database, last written using SQLite version 3032001
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Session]. (copy)
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Last Tabsfi (copy)
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Action Predictor
SQLite 3.x database, last written using SQLite version 3032001
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State. (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State} (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Platform Notifications\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Reporting and NEL
SQLite 3.x database, last written using SQLite version 3032001
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences. (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.oldP (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State.. (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Platform Notifications\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\LOG.olde/ (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\a64abc49-7a00-4663-91da-21f7e2eed701.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\c81b15c3-b0e9-4bd9-b021-568c5f4b0dca.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\226ae0f1-2e8e-4860-b080-80686b934b8b.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent Statemp (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Platform Notifications\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old.. (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old0 (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Visited Links
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a285c470-8d09-42b6-be97-d04c075fe56e.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a507cb8e-80c2-4902-9038-b462d112c0be.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\af65c1b9-0492-453c-a7ce-33b8ab9a5ebe.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\bf94a1b3-84a1-4646-8296-b728b2ab9f36.tmp
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d58482be-76ff-4d37-a9d1-1b3466a418d8.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT0 (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old00 (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\MANIFEST-000004
MPEG-4 LOAS
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata\LOG.old8f (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local StateMP (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local Stateo (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Subresource Filter\Indexed Rules\27\scoped_dir6704_1419033611\Ruleset Data
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\a52617b6-319e-4d15-ad29-387ea8682110.tmp
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\a6e9ceda-2211-4fc2-b79b-ccb9c9661d89.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\b6ada14a-595b-493f-ab7f-aa270215875c.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\c7999ff3-ac0c-4277-950c-53415c905c29.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\cf52c5c3-4468-439c-b6f2-2e126862ef43.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\174f070e-7724-4588-98e3-6e95da07c0eb.tmp
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\6704_122479829\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6704_122479829\download_file_types.pb
data
dropped
C:\Users\user\AppData\Local\Temp\6704_122479829\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6704_122479829\manifest.json
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_pnacl_json
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_for_eh_o
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_o
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_crtend_o
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_ld_nexe
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=7511538a3a6a0b862c772eace49075ed1bbe2377, stripped
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_libcrt_platform_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_libgcc_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_shim_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_shim_dummy_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_llc_nexe
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=309d6d3d463e6b1b0690f39eb226b1e4c469b2ce, stripped
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_sz_nexe
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=4b15de4ab227d5e46213978b8518d53c53ce1db9, stripped
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6704_1600531649\manifest.json
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\6704_58154863\Filtering Rules
data
dropped
C:\Users\user\AppData\Local\Temp\6704_58154863\LICENSE.txt
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\6704_58154863\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6704_58154863\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6704_58154863\manifest.json
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\8b03c528-a298-4ad7-8c28-f30effb98468.tmp
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\b9a0ede5-378a-48c1-b073-d622a0b71fa3.tmp
Google Chrome extension, version 3
dropped
C:\Users\user\AppData\Local\Temp\browser-sslkeys.log
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\d4a4a18f-4374-43e4-9210-854a67a6d0d8.tmp
Google Chrome extension, version 3
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\craw_background.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\craw_window.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\css\craw_window.css
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\html\craw_window.html
HTML document, ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\flapper.gif
GIF image data, version 89a, 30 x 30
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\topbar_floating_button.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\topbar_floating_button_close.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\topbar_floating_button_hover.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\topbar_floating_button_maximize.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\images\topbar_floating_button_pressed.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1515226785\b9a0ede5-378a-48c1-b073-d622a0b71fa3.tmp
Google Chrome extension, version 3
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\am\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ar\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\bn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\en\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\fa\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\fil\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\gu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\id\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\iw\messages.json
HTML document, ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\kn\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ml\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\mr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ms\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\nl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\pt\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\sw\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\ta\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\te\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\zh\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\angular.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\background_script.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\cast_sender.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\common.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\feedback.css
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\feedback.html
HTML document, ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\feedback_script.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\manifest.json
ASCII text, with very long lines, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\material_css_min.css
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\mirroring_cast_streaming.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\mirroring_common.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\mirroring_hangouts.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\CRX_INSTALL\mirroring_webrtc.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6704_1714530227\d4a4a18f-4374-43e4-9210-854a67a6d0d8.tmp
Google Chrome extension, version 3
dropped
There are 261 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation "https://encrypt.barracudanetworks.com/login?nid=U2FsdGVkX19jn%2BswjNmjPOFUGF7aenvGc%2BN7YjQ8pfKg0kttK6Y440qX3KJfMt63Z3TTinQbPwg1cJFRP9dPhh0i%2FK9AO2w79aklG%2F2rTl2yBEuJhjxNBZDHT428aml71RvOK4SQx%2FD7ffQNCLeiDg56vdpYNcVsSoOlwQULBm1Vj888CrQT2ogwYhMUUohQtqGML9w9HcF5y9PuxiKR%2Bb6ryLDNwwRCNgLrHxcgjYHjSXcLI0NIeSQ4f%2Fe7%2FfqKMXjnznYvYF7Kf38E8sNLQQ%3D%3D
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1576,17956472061859813481,6639794930409539142,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1920 /prefetch:8

URLs

Name
IP
Malicious
https://encrypt.barracudanetworks.com/login?nid=U2FsdGVkX19jn%2BswjNmjPOFUGF7aenvGc%2BN7YjQ8pfKg0kttK6Y440qX3KJfMt63Z3TTinQbPwg1cJFRP9dPhh0i%2FK9AO2w79aklG%2F2rTl2yBEuJhjxNBZDHT428aml71RvOK4SQx%2FD7ffQNCLeiDg56vdpYNcVsSoOlwQULBm1Vj888CrQT2ogwYhMUUohQtqGML9w9HcF5y9PuxiKR%2Bb6ryLDNwwRCNgLrHxcgjYHjSXcLI0NIeSQ4f%2Fe7%2FfqKMXjnznYvYF7Kf38E8sNLQQ%3D%3D
https://encrypt.barracudanetworks.com/js/stats.js?screen=1280x1024&win=1280x869&cdi=24&java=false&shk=n&svg=y&fla=n&rp=n&mov=n&wma=n&pdf=n&uid=awsuser_id1643449923306r3352&sid=awssession_id1643449923306r3352
3.23.174.26
https://apis.google.com/js/client.js
unknown
https://developer.livehelpnow.net/js/lhn-jquery-3.5.1.min.js
unknown
https://bam.nr-data.net/resources/1/9583f6425f?a=152029436&sa=1&v=1118.0c07c19&t=Unnamed%20Transaction&rst=5805&ref=https://encrypt.barracudanetworks.com/faq&st=1643449918896
162.247.242.32
https://easylist.to/)
unknown
https://cdn.cookielaw.org/consent/aee8f648-186a-4267-b808-6efdd7d84e9c/a5731440-40d1-4e86-9cd7-c6cb5
unknown
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
unknown
https://www.barracuda.com/assets/images/common/svg_icons/icon_partner-login.svg
unknown
https://www.barracuda.com/assets/images/common/down-arrow-icon.svg
99.86.3.25
https://preprod-hangouts-googleapis.sandbox.google.com
unknown
https://encrypt.barracudanetworks.com/js/stats.js
3.23.174.26
https://www.barracuda.com/assets/images/homepage/quick_link_cards/icon_support.svg
99.86.3.25
https://encrypt.barracudanetworks.com/login?nid=U2FsdGVkX19jn%2BswjNmjPOFUGF7aenvGc%2BN7YjQ8pfKg0kttK6Y440qX3KJfMt63Z3TTinQbPwg1cJFRP9dPhh0i%2FK9AO2w79aklG%2F2rTl2yBEuJhjxNBZDHT428aml71RvOK4SQx%2FD7ffQNCLeiDg56vdpYNcVsSoOlwQULBm1Vj888CrQT2ogwYhMUUohQtqGML9w9HcF5y9PuxiKR%2Bb6ryLDNwwRCNgLrHxcgjYHjSXcLI0NIeSQ4f%2Fe7%2FfqKMXjnznYvYF7Kf38E8sNLQQ%3D%3D
https://www.barracuda.com/css/lang/en.css
99.86.3.25
http://crls.pki.goog/gts1c3/QOvJ0N1sT2A.crl0
unknown
https://www.barracuda.com/assets/images/common/footer_icons/icon_instagram.svg
unknown
https://encrypt.barracudanetworks.com/loginBarracuda
unknown
https://www.barracuda.com/assets/images/common/footer_icons/icon_twitter.svgUc
unknown
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
unknown
https://www.barracuda.com/Content-Type:
unknown
https://www.barracuda.com/assets/images/common/footer_icons/icon_linkedin.svg
unknown
https://www.google.com/tools/feedback
unknown
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
unknown
http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions
unknown
https://cdn.cookielaw.org/scripttemplates/6.5.0/assets/otPcTab.json
unknown
https://payments.google.com/payments/v4/js/integrator.js
unknown
https://encrypt.barracudanetworks.com/login?nid=U2FsdGVkX19jn%2BswjNmjPOFUGF7aenvGc%2BN7YjQ8pfKg0kttK6Y440qX3KJfMt63Z3TTinQbPwg1cJFRP9dPhh0i%2FK9AO2w79aklG%2F2rTl2yBEuJhjxNBZDHT428aml71RvOK4SQx%2FD7ffQNCLeiDg56vdpYNcVsSoOlwQULBm1Vj888CrQT2ogwYhMUUohQtqGML9w9HcF5y9PuxiKR%2Bb6ryLDNwwRCNgLrHxcgjYHjSXcLI0NIeSQ4f%2Fe7%2FfqKMXjnznYvYF7Kf38E8sNLQQ%3D%3D
3.23.174.26
https://www.barracuda.com/css/cuda/fonts/optimize/proxima-nova800.woff2
unknown
https://pki.goog/repository/0
unknown
https://www.google.com/images/dot2.gif
unknown
https://www.barracuda.com/assets/images/homepage/carousel_refresh/slider-email@2x.jpg
99.86.3.25
https://www.barracuda.com/assets/images/common/footer_icons/icon_barracuda_blog.svg
unknown
https://bam.nr-data.net/1/9583f6425f?a=152029436&sa=1&v=1118.0c07c19&t=Unnamed%20Transaction&rst=529
unknown
https://bam.nr-data.net/1/9583f6425f?a=152029436&sa=1&v=1118.0c07c19&t=Unnamed%20Transaction&rst=528
unknown
https://www.barracuda.com/assets/images/common/livechat/img_live-chat-person_1.jpg
unknown
http://tools.ietf.org/html/rfc1950
unknown
https://cdn.cookielaw.org/
unknown
https://cdn.cookielaw.org/consent/aee8f648-186a-4267-b808-6efdd7d84e9c/aee8f648-186a-4267-b808-6efdd
unknown
https://encrypt.barracudanetworks.com/js/jquery-1.8.0.min.js
3.23.174.26
https://www.barracuda.com/assets/images/common/footer_icons/icon_youtube.svg
unknown
https://www.barracuda.com/assets/images/homepage/carousel_refresh/slider-network
unknown
https://feedback.googleusercontent.com
unknown
https://developer.livehelpnow.net/api/ui/hoc/a73388ac-1ddf-4a57-bf10-9ab970764ac8/init/?current_url=
unknown
https://cdn.cookielaw.org/scripttemplates/otSDKStub.js
unknown
https://www.livehelpnow.net/lhn/images/spacer.gif
unknown
https://encrypt.barracudanetworks.com/include/images/cloud/logo.png
3.23.174.26
http://crl.pki.goog/gsr1/gsr1.crl0;
unknown
https://www.barracuda.com/assets/images/common/livechat/img_live-chat-person_16.jpg5g
unknown
https://www.barracuda.com/assets/images/common/logo_barracuda_primary_reversed.svg_
unknown
https://encrypt.barracudanetworks.com/main/
unknown
https://developer.livehelpnow.net/oauth/token/?client_id=9ffebe61-5df4-4648-b008-eb3f0cf596a5&client
unknown
https://encrypt.barracudanetworks.com/js/lml.js
3.23.174.26
https://www.google.com/images/cleardot.gif
unknown
https://www.barracuda.com/assets/images/common/svg_icons/icon_contact.svg
99.86.3.25
https://play.google.com
unknown
https://www.barracuda.com/assets/images/homepage/hp-TEP_resized.jpg
unknown
https://www.barracuda.com/assets/images/common/svg_icons/icon_contact.svgB
unknown
https://www.barracuda.com/
https://www.barracuda.com/js/cuda/main.min.js?v=1643414133
99.86.3.25
https://www.google.com/log?format=json&hasfast=true
unknown
https://encrypt.barracudanetworks.com/
unknown
https://encrypt.barracudanetworks.com/faqBarracuda
unknown
https://assets.barracuda.com/assets/docs/dms/docimage/original/ac12564535cc14ef1ac75ecd334df1a6.png
99.86.3.121
https://encrypt.barracudanetworks.com/login
https://www.barracuda.com/assets/images/homepage/carousel_refresh/slider-data
unknown
https://assets.barracuda.com/assets/blogs/COVID-19-test-email-scams.jpg
unknown
https://www.barracuda.com/assets/images/common/svg_icons/icon_search.svg
99.86.3.25
https://accounts.google.com/MergeSession
unknown
https://bam.nr-data.net/events/1/9583f6425f?a=152029436&sa=1&v=1118.0c07c19&t=Unnamed%20Transaction&rst=5815&ref=https://encrypt.barracudanetworks.com/faq
162.247.242.32
https://developer.livehelpnow.net/images/button-closer.svg
unknown
https://www.barracuda.com/assets/img/layout/logo/favicon_barracuda.ico5
unknown
https://meet.google.com
unknown
https://www.barracuda.com/assets/images/common/footer_icons/icon_twitter.svg
unknown
https://cdn.cookielaw.org/vendorlist/iab2Data.json
unknown
https://apis.google.com
unknown
https://cdn.vidyard.com/thumbnails/14396470/407-ILPbiZoKazQnY49QuGvFOEVBCMep.gif4
unknown
https://assets.barracuda.com/assets/docs/dms/docimage/original/a4d6794e612b64780d140745cbe3894f.png
99.86.3.121
https://www.barracuda.com/assets/images/common/svg_icons/icon_contact_blue.svg
99.86.3.25
https://www.livehelpnow.net/lhn/handler/e.ashx?c=1288&e=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20Wi
unknown
https://encrypt.barracudanetworks.com/login?nid=U2FsdGVkX19jn%2BswjNmjPOFUGF7aenvGc%2BN7YjQ8pfKg0ktt
unknown
https://encrypt.barracudanetworks.com/images/home_white.png
3.23.174.26
https://www.google.com/intl/en-US/chrome/blank.html
unknown
https://www.barracuda.com/assets/images/common/icon_barracuda.svg
99.86.3.25
https://www.barracuda.com/assets/images/homepage/carousel_refresh/homepage_web.pngS%9
unknown
https://www.barracuda.com/assets/images/homepage/diagonal_arrow.svg
99.86.3.25
https://www.barracuda.com/assets/images/homepage/quick_link_cards/icon_try-free.svg
99.86.3.25
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
142.250.203.109
https://chromium.googlesource.com/a/native_client/pnacl-llvm.git
unknown
https://www.barracuda.com/css/cuda/fonts/optimize/proxima-nova600.woff2
unknown
http://pki.goog/gsr1/gsr1.crt02
unknown
https://www.barracuda.com/assets/images/common/logo_barracuda_primary_strapline_reversed.svg
99.86.3.25
https://encrypt.barracudanetworks.com/css/pattern.css
3.23.174.26
https://assets.barracuda.com/assets/docs/dms/docimage/original/University_of_California_LA_Logo.png
99.86.3.121
https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location~
unknown
https://www.barracuda.com/
99.86.3.25
https://www.barracuda.com/assets/images/common/svg_icons/icon_search_v2.svg
99.86.3.25
https://www.barracuda.com/css/cuda/fonts/optimize/proxima-nova300.woff2
unknown
https://encrypt.barracudanetworks.com/faq
3.23.174.26
https://www.barracuda.com/assets/images/homepage/carousel_refresh/slider-cloud-app
unknown
https://www.barracuda.com/js/cuda/public/cuda.header_video_play.js?v=1643414133
99.86.3.25
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
d1otsuyu42p7qj.cloudfront.net
99.86.3.25
accounts.google.com
142.250.203.109
www-googletagmanager.l.google.com
172.217.168.8
app.livehelpnow.net
184.106.10.77
bam.nr-data.net
162.247.242.32
www.barracudanetworks.com
198.35.20.82
developer.livehelpnow.net
23.253.188.26
cs6.wpc.omegacdn.net
93.184.221.26
www.livehelpnow.net
184.106.10.72
d3lz6gesenfpcv.cloudfront.net
99.86.3.121
stack-tracking.corpweb.aws.cudasvc.com
3.131.58.201
encrypt.barracudanetworks.com
3.23.174.26
dualstack.polyfill.map.fastly.net
151.101.1.26
clients.l.google.com
142.250.203.110
googlehosted.l.googleusercontent.com
172.217.168.33
cdn.cookielaw.org
104.16.149.64
geolocation.onetrust.com
104.20.184.68
www.barracuda.com
unknown
js-agent.newrelic.com
unknown
assets.barracuda.com
unknown
clients2.googleusercontent.com
unknown
play.vidyard.com
unknown
cdn.polyfill.io
unknown
clients2.google.com
unknown
a.barracuda.com
unknown
cdn.vidyard.com
unknown
There are 16 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
3.131.58.201
stack-tracking.corpweb.aws.cudasvc.com
United States
192.168.2.1
unknown
unknown
172.217.168.8
www-googletagmanager.l.google.com
United States
23.253.188.26
developer.livehelpnow.net
United States
104.20.184.68
geolocation.onetrust.com
United States
184.106.10.72
www.livehelpnow.net
United States
162.247.242.20
unknown
United States
99.86.3.121
d3lz6gesenfpcv.cloudfront.net
United States
184.106.10.77
app.livehelpnow.net
United States
198.35.20.82
www.barracudanetworks.com
United States
142.250.203.109
accounts.google.com
United States
3.23.174.26
encrypt.barracudanetworks.com
United States
93.184.221.26
cs6.wpc.omegacdn.net
European Union
151.101.1.26
dualstack.polyfill.map.fastly.net
United States
99.86.3.25
d1otsuyu42p7qj.cloudfront.net
United States
104.16.149.64
cdn.cookielaw.org
United States
162.247.242.32
bam.nr-data.net
United States
239.255.255.250
unknown
Reserved
172.217.168.33
googlehosted.l.googleusercontent.com
United States
127.0.0.1
unknown
unknown
There are 10 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blacklist_cache_md5_digest
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
There are 35 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1F40B062000
unkown
page read and write
228673C0000
heap
page read and write
11337850000
heap
page read and write
2286765B000
unkown
page read and write
572F4FE000
stack
page read and write
1F40B04E000
unkown
page read and write
B43BFE000
stack
page read and write
2728CC20000
heap
page read and write
B436FE000
stack
page read and write
2728D57D000
unkown
page read and write
23AA0C02000
unkown
page read and write
235BFC3C000
unkown
page read and write
1A34EEC0000
heap
page read and write
249FEF13000
unkown
page read and write
2728D51D000
unkown
page read and write
C71C3F7000
stack
page read and write
11337989000
heap
page read and write
2728CEA5000
unkown
page read and write
B437FD000
stack
page read and write
1CACDFE0000
unkown
page read and write
2728D57B000
unkown
page read and write
36B3FB000
stack
page read and write
1A34F900000
unkown
page read and write
1A34F802000
unkown
page read and write
1A34F065000
unkown
page read and write
2728D552000
unkown
page read and write
1133798D000
heap
page read and write
249FEE3C000
unkown
page read and write
249FEE71000
unkown
page read and write
1133798C000
heap
page read and write
F8D7D7B000
stack
page read and write
D838AFE000
stack
page read and write
23AA045F000
unkown
page read and write
36AB5C000
stack
page read and write
11D67902000
unkown
page read and write
2728D5A5000
unkown
page read and write
C71C7FF000
stack
page read and write
2728D59D000
unkown
page read and write
1F40B06E000
unkown
page read and write
2286762A000
unkown
page read and write
D36D37D000
stack
page read and write
2728D558000
unkown
page read and write
1F40B046000
unkown
page read and write
11D6785B000
unkown
page read and write
235BFC6A000
unkown
page read and write
2286763D000
unkown
page read and write
28C0EFC0000
remote allocation
page read and write
B72C0FF000
stack
page read and write
2728CE4A000
unkown
page read and write
2728CF16000
unkown
page read and write
1F40B05F000
unkown
page read and write
23AA0488000
unkown
page read and write
11D67889000
unkown
page read and write
1A34F102000
unkown
page read and write
B438FF000
stack
page read and write
2728D59C000
unkown
page read and write
2286771B000
unkown
page read and write
2728D592000
unkown
page read and write
249FEDA0000
heap
page read and write
23AA0459000
unkown
page read and write
249FEF08000
unkown
page read and write
2728CEC6000
unkown
page read and write
2728D5C8000
unkown
page read and write
28C0EFC0000
remote allocation
page read and write
B4327B000
stack
page read and write
23AA0200000
heap
page read and write
28C0F802000
unkown
page read and write
1FC2F9000
stack
page read and write
1A34F113000
unkown
page read and write
1FC3FF000
stack
page read and write
C71C0FE000
stack
page read and write
2728D560000
unkown
page read and write
228675C0000
trusted library allocation
page read and write
2728D57F000
unkown
page read and write
1FC37E000
stack
page read and write
2728CE52000
unkown
page read and write
23AA0513000
unkown
page read and write
1F40AFF0000
unkown
page read and write
1A34F0CD000
unkown
page read and write
22867665000
unkown
page read and write
2728CE53000
unkown
page read and write
2728DA02000
unkown
page read and write
235BFD02000
unkown
page read and write
2728CE58000
unkown
page read and write
2728CDF0000
unkown
page read and write
2728CE4B000
unkown
page read and write
1A34EF30000
heap
page read and write
1CACE067000
unkown
page read and write
572F37E000
stack
page read and write
2728CE8C000
unkown
page read and write
11D67802000
unkown
page read and write
4C325CE000
stack
page read and write
1F40B047000
unkown
page read and write
B72C2FF000
stack
page read and write
22867580000
trusted library allocation
page read and write
1F40B07C000
unkown
page read and write
1F40B078000
unkown
page read and write
249FEDD0000
unkown
page read and write
11D67877000
unkown
page read and write
1CACE013000
unkown
page read and write
B72BB3B000
stack
page read and write
D36D3FE000
stack
page read and write
235BFC29000
unkown
page read and write
23AA046E000
unkown
page read and write
1CACE070000
unkown
page read and write
2728CBC0000
heap
page read and write
11D67841000
unkown
page read and write
1CACE024000
unkown
page read and write
2286768C000
unkown
page read and write
2728D5AE000
unkown
page read and write
2728CE55000
unkown
page read and write
2728CF02000
unkown
page read and write
1F40AE90000
heap
page read and write
11337962000
heap
page read and write
2728D51F000
unkown
page read and write
11D67854000
unkown
page read and write
11D67829000
unkown
page read and write
2728D5A6000
unkown
page read and write
2728D57D000
unkown
page read and write
B434FC000
stack
page read and write
1F40B802000
unkown
page read and write
23AA0370000
unkown
page read and write
249FEE77000
unkown
page read and write
1CACE05D000
unkown
page read and write
1A34F013000
unkown
page read and write
572F2FE000
stack
page read and write
2728D5B0000
unkown
page read and write
1CACE09A000
unkown
page read and write
28C0F102000
unkown
page read and write
23AA0270000
heap
page read and write
36B7FE000
stack
page read and write
28C0EE30000
heap
page read and write
1F40B075000
unkown
page read and write
572F7FE000
stack
page read and write
11D67600000
heap
page read and write
235BFD13000
unkown
page read and write
2728CE57000
unkown
page read and write
2728CE4E000
unkown
page read and write
2728D58E000
unkown
page read and write
1F40B013000
unkown
page read and write
22867600000
unkown
page read and write
B72C4FC000
stack
page read and write
C71C07E000
stack
page read and write
235BFB60000
unkown
page read and write
4C3254B000
stack
page read and write
2728D3F0000
remote allocation
page read and write
1F40B040000
unkown
page read and write
D36D17E000
stack
page read and write
22867718000
unkown
page read and write
1CACE04D000
unkown
page read and write
C71CAFF000
stack
page read and write
2728CE4F000
unkown
page read and write
C71C2F7000
stack
page read and write
28C0EFC0000
remote allocation
page read and write
22868FE0000
remote allocation
page read and write
2728D402000
unkown
page read and write
B72C6FD000
stack
page read and write
28C0EE20000
heap
page read and write
1FC27F000
stack
page read and write
36B27C000
stack
page read and write
228673D0000
heap
page read and write
2728D59D000
unkown
page read and write
1F40B045000
unkown
page read and write
2728D555000
unkown
page read and write
2728D583000
unkown
page read and write
1CACDE10000
heap
page read and write
2728D5AD000
unkown
page read and write
235BFA60000
heap
page read and write
2728D571000
unkown
page read and write
11D68002000
unkown
page read and write
D8387FC000
stack
page read and write
249FF602000
unkown
page read and write
D838CFB000
stack
page read and write
C71BDEC000
stack
page read and write
11337845000
heap
page read and write
2728CE51000
unkown
page read and write
F8D807E000
stack
page read and write
11D67660000
heap
page read and write
4C32A7B000
stack
page read and write
2728D5B0000
unkown
page read and write
1A34F0C3000
unkown
page read and write
1F40B06C000
unkown
page read and write
2728D5A5000
unkown
page read and write
4C32BF7000
stack
page read and write
1F40B07A000
unkown
page read and write
11D67856000
unkown
page read and write
C71C47E000
stack
page read and write
28C0F03D000
unkown
page read and write
11337967000
heap
page read and write
2728D59D000
unkown
page read and write
1A34F02A000
unkown
page read and write
F8D7A7C000
stack
page read and write
2728CF08000
unkown
page read and write
572F5FE000
stack
page read and write
22868FE0000
remote allocation
page read and write
2728D5AE000
unkown
page read and write
1A34F089000
unkown
page read and write
28C0F000000
unkown
page read and write
C71C67A000
stack
page read and write
2728D5B8000
unkown
page read and write
2728D57E000
unkown
page read and write
1133798C000
heap
page read and write
23AA0502000
unkown
page read and write
1CACE053000
unkown
page read and write
B43AFF000
stack
page read and write
23AA0413000
unkown
page read and write
C71C778000
stack
page read and write
2286765A000
unkown
page read and write
1133798C000
heap
page read and write
11D67800000
unkown
page read and write
2728D596000
unkown
page read and write
2728CEA8000
unkown
page read and write
11D67888000
unkown
page read and write
2728D5AD000
unkown
page read and write
2728D57D000
unkown
page read and write
D36D27F000
stack
page read and write
23AA047D000
unkown
page read and write
1F40B000000
unkown
page read and write
249FEE4B000
unkown
page read and write
1FBF5A000
stack
page read and write
2728D582000
unkown
page read and write
11D67866000
unkown
page read and write
22867550000
trusted library allocation
page read and write
2728D500000
unkown
page read and write
28C0F013000
unkown
page read and write
249FEF00000
unkown
page read and write
2286765B000
unkown
page read and write
28C0F029000
unkown
page read and write
2728CE00000
unkown
page read and write
1F40B064000
unkown
page read and write
1CACE05D000
unkown
page read and write
1A34F067000
unkown
page read and write
2728D5C8000
unkown
page read and write
23AA043C000
unkown
page read and write
28C0F058000
unkown
page read and write
1CACE102000
unkown
page read and write
572F6FE000
stack
page read and write
22867700000
unkown
page read and write
2728CBB0000
heap
page read and write
2728D52A000
unkown
page read and write
B72BF7E000
stack
page read and write
69298FF000
stack
page read and write
235BFC58000
unkown
page read and write
23AA046E000
unkown
page read and write
D838A7E000
stack
page read and write
22867702000
unkown
page read and write
2728D59C000
unkown
page read and write
1CACE000000
unkown
page read and write
23AA0400000
unkown
page read and write
22867613000
unkown
page read and write
2728D5A5000
unkown
page read and write
1F40B102000
unkown
page read and write
2728CE4C000
unkown
page read and write
2728D5C6000
unkown
page read and write
2728D55B000
unkown
page read and write
2728CF13000
unkown
page read and write
28C0EF90000
unkown
page read and write
2728CE48000
unkown
page read and write
1F40B060000
unkown
page read and write
2728CE3C000
unkown
page read and write
69296F7000
stack
page read and write
C71C8FE000
stack
page read and write
1F40B085000
unkown
page read and write
2728CEE1000
unkown
page read and write
1F40B031000
unkown
page read and write
1F40B041000
unkown
page read and write
28C0F002000
unkown
page read and write
22867602000
unkown
page read and write
11337700000
heap
page read and write
D36D0FE000
stack
page read and write
1CACE113000
unkown
page read and write
249FED30000
heap
page read and write
1F40B044000
unkown
page read and write
2728D5CF000
unkown
page read and write
2728D594000
unkown
page read and write
B433FF000
stack
page read and write
C71C9FF000
stack
page read and write
249FEE82000
unkown
page read and write
2728D54B000
unkown
page read and write
2728D5BC000
unkown
page read and write
1133795B000
heap
page read and write
249FEE13000
unkown
page read and write
2728D59C000
unkown
page read and write
11D67813000
unkown
page read and write
2728DA00000
unkown
page read and write
36B5FF000
stack
page read and write
36B1FF000
stack
page read and write
2728D581000
unkown
page read and write
36B37D000
stack
page read and write
1A34F03E000
unkown
page read and write
11337980000
heap
page read and write
B72C1FF000
stack
page read and write
1A34F06E000
unkown
page read and write
11337975000
heap
page read and write
69297FF000
stack
page read and write
1F40B07F000
unkown
page read and write
1A34F0BC000
unkown
page read and write
23AA045C000
unkown
page read and write
28C0F025000
unkown
page read and write
22868FE0000
remote allocation
page read and write
1CACE07B000
unkown
page read and write
2728D58E000
unkown
page read and write
B4307B000
stack
page read and write
249FEE2A000
unkown
page read and write
28C0EE90000
heap
page read and write
2728DA02000
unkown
page read and write
235BFC13000
unkown
page read and write
11337870000
heap
page read and write
2728CE6E000
unkown
page read and write
B439FF000
stack
page read and write
22867713000
unkown
page read and write
2728D5C4000
unkown
page read and write
2728D57D000
unkown
page read and write
D36D4FD000
stack
page read and write
249FEF02000
unkown
page read and write
1F40B059000
unkown
page read and write
23AA0429000
unkown
page read and write
2286764B000
unkown
page read and write
1CACDDA0000
heap
page read and write
235C0402000
unkown
page read and write
36AF7C000
stack
page read and write
1F40B076000
unkown
page read and write
1CACE100000
unkown
page read and write
235BFD00000
unkown
page read and write
2728CED6000
unkown
page read and write
2728CEBF000
unkown
page read and write
1F40B02A000
unkown
page read and write
1FBFDF000
stack
page read and write
2728CEE3000
unkown
page read and write
22867530000
unkown
page read and write
1F40B058000
unkown
page read and write
2728D5C3000
unkown
page read and write
2728D3F0000
remote allocation
page read and write
692916E000
stack
page read and write
11D67760000
unkown
page read and write
1A34EED0000
heap
page read and write
1CACE067000
unkown
page read and write
1F40B03D000
unkown
page read and write
2728D5A3000
unkown
page read and write
D838DF7000
stack
page read and write
235BFC7B000
unkown
page read and write
2728CEFD000
unkown
page read and write
2286764A000
unkown
page read and write
2728D560000
unkown
page read and write
F8D7F7B000
stack
page read and write
2728D59C000
unkown
page read and write
2728DA02000
unkown
page read and write
2728D57D000
unkown
page read and write
2728D58D000
unkown
page read and write
23AA0464000
unkown
page read and write
11D67913000
unkown
page read and write
69291EE000
stack
page read and write
69295FB000
stack
page read and write
23AA0210000
heap
page read and write
2728D59D000
unkown
page read and write
22867430000
heap
page read and write
235BF9F0000
heap
page read and write
11337988000
heap
page read and write
235BFA00000
heap
page read and write
2728D559000
unkown
page read and write
1CACDDB0000
heap
page read and write
2728DA63000
unkown
page read and write
4C32AFE000
stack
page read and write
2286764B000
unkown
page read and write
2728D5BC000
unkown
page read and write
B43CFF000
stack
page read and write
69294FC000
stack
page read and write
1F40B025000
unkown
page read and write
11D6789B000
unkown
page read and write
1CACE602000
unkown
page read and write
2728D5D5000
unkown
page read and write
249FEE53000
unkown
page read and write
2728D562000
unkown
page read and write
249FEE4E000
unkown
page read and write
235BFC00000
unkown
page read and write
1F40B042000
unkown
page read and write
2728D3F0000
remote allocation
page read and write
11D675F0000
heap
page read and write
11337840000
heap
page read and write
1F40B06A000
unkown
page read and write
D838EFF000
stack
page read and write
D36CFFC000
stack
page read and write
2728D57F000
unkown
page read and write
11337980000
heap
page read and write
2728D5AF000
unkown
page read and write
2728D572000
unkown
page read and write
B72C5FE000
stack
page read and write
4C32CFF000
stack
page read and write
28C0F066000
unkown
page read and write
1133798C000
heap
page read and write
1F40B063000
unkown
page read and write
1F40B05C000
unkown
page read and write
4C32DFE000
stack
page read and write
235BFC02000
unkown
page read and write
2728DA02000
unkown
page read and write
2728D5C3000
unkown
page read and write
22869002000
unkown
page read and write
1CACE108000
unkown
page read and write
249FEE00000
unkown
page read and write
2728D5B9000
unkown
page read and write
36B4FD000
stack
page read and write
11337950000
heap
page read and write
2728CE13000
unkown
page read and write
2728D5A1000
unkown
page read and write
D838FFF000
stack
page read and write
1A34EF60000
unkown
page read and write
23AA0454000
unkown
page read and write
36B0FF000
stack
page read and write
1F40B07B000
unkown
page read and write
2728DA02000
unkown
page read and write
2728D5C7000
unkown
page read and write
11D67865000
unkown
page read and write
2728CEAF000
unkown
page read and write
11337976000
heap
page read and write
249FED40000
heap
page read and write
1F40B05A000
unkown
page read and write
1F40B065000
unkown
page read and write
1F40B061000
unkown
page read and write
1F40B068000
unkown
page read and write
249FEE48000
unkown
page read and write
2728CE29000
unkown
page read and write
23AA0500000
unkown
page read and write
23AA044B000
unkown
page read and write
11337980000
heap
page read and write
B72C3FC000
stack
page read and write
36B6FD000
stack
page read and write
1F40B057000
unkown
page read and write
69290EB000
stack
page read and write
1CACE03C000
unkown
page read and write
1FC47E000
stack
page read and write
2728CE2C000
unkown
page read and write
572F27C000
stack
page read and write
2728CE85000
unkown
page read and write
1A34F000000
unkown
page read and write
D36CE7B000
stack
page read and write
2728CE49000
unkown
page read and write
2728D5CE000
unkown
page read and write
D838BFB000
stack
page read and write
1F40AE80000
heap
page read and write
11337957000
heap
page read and write
23AA0508000
unkown
page read and write
2728CE9E000
unkown
page read and write
1F40B03A000
unkown
page read and write
4C3287E000
stack
page read and write
2728D5C6000
unkown
page read and write
F8D7E7E000
stack
page read and write
4C3297C000
stack
page read and write
1F40AEF0000
heap
page read and write
C71C57E000
stack
page read and write
There are 439 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://encrypt.barracudanetworks.com/login?nid=U2FsdGVkX19jn%2BswjNmjPOFUGF7aenvGc%2BN7YjQ8pfKg0kttK6Y440qX3KJfMt63Z3TTinQbPwg1cJFRP9dPhh0i%2FK9AO2w79aklG%2F2rTl2yBEuJhjxNBZDHT428aml71RvOK4SQx%2FD7ffQNCLeiDg56vdpYNcVsSoOlwQULBm1Vj888CrQT2ogwYhMUUohQtqGML9w9HcF5y9PuxiKR%2Bb6ryLDNwwRCNgLrHxcgjYHjSXcLI0NIeSQ4f%2Fe7%2FfqKMXjnznYvYF7Kf38E8sNLQQ%3D%3D
https://encrypt.barracudanetworks.com/faq
https://www.barracuda.com/
https://encrypt.barracudanetworks.com/login
https://www.barracuda.com/