Windows Analysis Report
http://topfivedubai.com/atv

Overview

General Information

Sample URL: http://topfivedubai.com/atv
Analysis ID: 612094
Infos:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

No high impact signatures.

Classification

There are no high impact signatures.

Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: global traffic HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-85.0.4183.121Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /atv HTTP/1.1Host: topfivedubai.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /atv/ HTTP/1.1Host: topfivedubai.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Host: topfivedubai.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: image/avif,image/webp,image/apng,image/*,*/*;q=0.8Referer: http://topfivedubai.com/atv/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: PHPSESSID=80034ff189609451c7edf55b6d4ece15
Source: unknown DNS traffic detected: queries for: clients2.google.com
Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 20 Apr 2022 13:07:10 GMTServer: nginx/1.19.10Content-Type: text/html; charset=UTF-8Content-Length: 4184Vary: Accept-EncodingContent-Encoding: gzipX-Server-Cache: falseData Raw: 1f 8b 08 00 00 00 00 00 00 03 15 52 77 3c 14 8e 03 3d 91 95 75 59 67 73 8a 8c 9c 73 c8 9e 67 cb de 9b b3 ca de 64 64 54 dc 19 19 d9 64 64 cf 70 9c c2 a1 9c ec b3 ca 08 71 44 f6 5e 21 bf ef ef 7d 3e ef bd 7f de fb e7 7d 1e d2 40 4f 83 9a 92 95 12 00 00 50 6b 69 c2 8d fe 73 83 ff 93 9c f4 3f 4d 01 1e d5 03 00 b4 4b 5a 70 65 93 d0 f9 df b6 14 a1 a6 38 46 1a eb de 01 33 ba 09 41 81 7c 1d 8f 7a dc bc 59 bd 47 2b 9b b6 ed 73 1d 35 4f c5 d3 da d6 40 0c c9 7d 1e 8a 70 06 e1 e2 52 a0 5a dc 1c 7d 73 6a 2a 47 ba 52 cf c7 57 1f d5 53 1f 92 90 c7 d0 dd 57 61 ba df ac b7 d1 1d 96 31 52 18 92 fd e9 bc 2b 5e 2b 1c eb 83 3d 58 ca 97 1d fe 14 b0 5e 70 5c 04 8b cb 9e 31 d7 9c c1 27 b2 dd d6 97 0f 42 a6 9a 5f a8 f8 4e 66 f9 08 5b 98 1f 9d 46 e7 e4 c5 b4 f0 5a 75 b9 be 01 62 23 bc 82 e1 c7 e3 d2 13 cc ea a4 fd ec a5 f8 f2 64 f2 a4 b0 da 22 9f 8b 96 13 0c d4 ee f6 89 38 cc 73 76 16 47 d1 b8 74 19 3c b4 c1 4b 8c 60 53 e3 3b 74 99 5d 70 37 85 d6 84 27 bf 5c bb 3b b4 4c fe 77 bf 1a 4d 75 69 8f b0 ba bd 32 77 e9 0c be 9a 3c c5 11 bb be 0e 39 a0 e7 6a 79 14 73 2d 19 71 cf b2 73 93 5b 4b 26 34 6f e7 71 23 1f 33 6b 43 6a 0a 0d 01 7e 41 d3 5d 42 b3 45 60 91 4b 94 bc 90 dc ac f1 fc 74 96 5c 65 f2 77 5f 00 7d b2 dd 1a d1 71 53 7f ca 5b 74 fd c0 8d 83 11 63 a6 47 35 98 51 b4 96 4e 8b e1 e2 e1 87 48 d2 85 00 e7 55 f2 dd d9 22 3f fe 23 bd 54 33 3b 3b a5 3e 2e bf e5 9c f7 00 3d 01 73 bb fe 89 dc 2f d7 a0 89 e2 ad 49 7e ba 76 25 34 35 b0 b5 ab 31 58 5e c1 44 78 a6 c2 f5 67 7b 8f b1 da 36 69 47 51 a8 33 eb df e9 07 5c 07 7f e2 f3 22 0d 95 66 26 83 87 e3 23 a4 ff 6a c7 6d 9a eb 4f 3a 4f d6 b6 1b d1 e9 5f 37 20 69 a3 0f 19 51 39 7c ec 52 6a f7 69 df 83 37 e3 f1 a9 9d ab 8c 65 ed a5 6f c4 c5 31 da 98 78 2c 94 34 25 8d f1 64 1f cd f9 ad 63 c6 98 92 eb 03 aa 24 9d fa a4 e9 fb 9c 33 3e f7 f9 d7 41 5b ef 67 0f 59 ec b3 32 a4 59 c2 07 f5 15 e7 35 ab 48 25 4d 18 22 94 17 35 54 9b 33 dd 5a de 16 98 82 7c e0 6a 81 c2 8a 97 a2 1d db 97 31 51 c0 fc cd 5f 7e f2 b1 61 f8 a8 36 e9 35 ab db 2a 91 f2 68 46 04 fa cb 97 e0 ec 54 fb 86 c1 de 7f 0f 46 45 5b c4 7a 9a 30 ea 7b d2 8e 03 ba 49 c9 02 1c 35 9e 22 53 dd 53 dd 62 fd c9 ef 99 43 76 69 7f 69 fd c2 f3 1d 56 5e 70 94 99 b9 bd bd 6a 6e ce 1a d1 5c d0 22 c5 23 fd d9 a6 4e 28 bf f7 ac 41 d0 8d e9 35 2f 46 9b 1c 92 40 42 e7 23 ac 56 a4 76 a6 eb f2 ac e9 12 8e 2a be 4e d4 a4 a2 72 dc 6f ea 20 0a f5 d2 b3 08 e6 ad 81 7d f0 91 16 d7 2f d1 b7 30 3d e1 c8 c8 af 83 d3 07 11 b6 ea 4e 6f 71 b3 86 18 fc c8 47 8e 93 fd aa da 2f 9d e6 04 4a ce 92 5a 7d 43 86 5f 61 b2 af d9 1b 6b a6 22 86 61 4f 76 fa 2b 22 bf b3 54 ae f4 3e 42 4c 34 03 0e 62 f7 2d b2 08 0e a1 16 02 37 b2 13 1f 46 ee 8d 2c 5c c9 49 18 cf 4f ac e0 15 e6 cb a4 ab 92 35 f0 32 2c 18 f9 92 85 4e 51 3b 96 fc ac b9 e3 8b ad 64 4f 7b 39 8d db 25 02 70 7d 54 73 e1 10 74 aa ca a8 1f 2b 48 33 b9
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: angular.js.0.dr String found in binary or memory: http://angularjs.org
Source: angular.js.0.dr String found in binary or memory: http://errors.angularjs.org/1.6.4-local
Source: pnacl_public_x86_64_pnacl_sz_nexe.0.dr, pnacl_public_x86_64_pnacl_llc_nexe.0.dr String found in binary or memory: http://llvm.org/):
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://tools.ietf.org/html/rfc1950
Source: History Provider Cache.0.dr String found in binary or memory: http://topfivedubai.com/atv/2
Source: History Provider Cache.0.dr String found in binary or memory: http://topfivedubai.com/atv/2:
Source: History Provider Cache.0.dr String found in binary or memory: http://topfivedubai.com/atv2
Source: History Provider Cache.0.dr String found in binary or memory: http://topfivedubai.com/atv2:
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions
Source: mirroring_hangouts.js.0.dr String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr, manifest.json0.0.dr String found in binary or memory: https://accounts.google.com
Source: craw_window.js.0.dr String found in binary or memory: https://accounts.google.com/MergeSession
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr, manifest.json0.0.dr String found in binary or memory: https://apis.google.com
Source: pnacl_public_x86_64_crtend_o.0.dr, pnacl_public_x86_64_ld_nexe.0.dr String found in binary or memory: https://chromium.googlesource.com/a/native_client/pnacl-clang.git
Source: pnacl_public_x86_64_crtend_o.0.dr, pnacl_public_x86_64_ld_nexe.0.dr String found in binary or memory: https://chromium.googlesource.com/a/native_client/pnacl-llvm.git
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr String found in binary or memory: https://clients2.google.com
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://clients2.google.com/cr/report
Source: manifest.json1.0.dr, manifest.json0.0.dr, manifest.json.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://clients6.google.com
Source: pnacl_public_x86_64_ld_nexe.0.dr String found in binary or memory: https://code.google.com/p/nativeclient/issues/entry
Source: pnacl_public_x86_64_ld_nexe.0.dr String found in binary or memory: https://code.google.com/p/nativeclient/issues/entry%s:
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://creativecommons.org/publicdomain/zero/1.0/.
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr, df3222a3-ee15-46d7-9b79-b03d8e658b4b.tmp.1.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: material_css_min.css.0.dr, angular.js.0.dr String found in binary or memory: https://github.com/angular/material
Source: craw_window.js.0.dr, craw_background.js.0.dr String found in binary or memory: https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://github.com/madler/zlib/blob/master/zlib.h
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://hangouts.clients6.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://hangouts.google.com/hangouts/_/logpref
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://meetings.clients6.google.com
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr String found in binary or memory: https://ogs.google.com
Source: craw_window.js.0.dr, manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://preprod-hangouts-googleapis.sandbox.google.com
Source: craw_window.js.0.dr, manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr String found in binary or memory: https://ssl.gstatic.com
Source: feedback.html.0.dr, messages.json33.0.dr, messages.json35.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: feedback.html.0.dr, messages.json33.0.dr, messages.json35.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: craw_window.js.0.dr, craw_background.js.0.dr String found in binary or memory: https://www-googleapis-staging.sandbox.google.com
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr, manifest.json0.0.dr String found in binary or memory: https://www.google.com
Source: manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/accounts/OAuthLogin?issueuberauth=1
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/images/cleardot.gif
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/images/dot2.gif
Source: craw_window.js.0.dr String found in binary or memory: https://www.google.com/images/x2.gif
Source: craw_background.js.0.dr String found in binary or memory: https://www.google.com/intl/en-US/chrome/blank.html
Source: mirroring_hangouts.js.0.dr String found in binary or memory: https://www.google.com/log?format=json&hasfast=true
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr, craw_window.js.0.dr, craw_background.js.0.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 26789665-ada4-4262-b855-fc3456293fd8.tmp.1.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown HTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\8830ad4d-bbde-4e73-9a01-26cea6c6ce16.tmp Jump to behavior
Source: classification engine Classification label: clean0.win@32/185@4/8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation "http://topfivedubai.com/atv
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1568,18204870535390972507,10787447930455822583,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1916 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1568,18204870535390972507,10787447930455822583,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1916 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-62608407-B8C.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs