IOC Report
http://www.macwestlosangeles.com/sa.html

loading gif

Files

File Path
Type
Category
Malicious
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\4849b0c0-26be-442a-b8fe-efc88689e4b7.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\4984aa72-13ec-4b58-830e-4c0056482930.tmp
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\713730f6-823b-4b9f-ae34-e8810414adfa.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\8b2accd4-3d2b-4442-8fbb-153095857d71.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\921371d4-96ad-4605-b131-374a50ca0312.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\98d2f5c4-a5f6-4f9f-8e34-7418475072b4.tmp
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\01557e94-30a0-4001-8d51-ce449d066619.tmp
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\020fa1cf-4b0e-434b-a3a0-679a28e6d6f8.tmp
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\18cb52ac-cf0d-4bb9-a446-5091bd187f14.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\1b19cf7e-5859-45fb-8ccb-919b332cbdf8.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\295d8723-6db5-45d0-b580-bade456635e2.tmp
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\38ddceaa-344a-4fa2-9e14-c0013279d0c6.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3bb6fc9f-dd02-40d0-ad1e-b96440673dc7.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\512915c8-452c-4d62-bb25-580a653e6480.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\53271281-b0ab-4084-a8cd-de5f74fc7822.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\7e088695-5db1-4017-bdfe-2ff83aeebe1e.tmp
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\8080c98f-9c6e-47fb-9a1e-d1790042d5eb.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\2a55cd80-2737-40e7-a0a2-632e0fa7a93c.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ab703e25-99f2-422c-8918-d15f97fa25d0.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\bcdea540-b44b-4e46-86b3-082654ee5ab1.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\dd26c0e8-d6e0-442f-9164-422c82cd9273.tmp
ASCII text, with no line terminators
modified
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\c33fb2cc-9d82-4cd5-8d39-e22492191cd8.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\c904d8a3-9058-4b37-a2f7-f12bb9ca3122.tmp
SysEx File -
dropped
C:\Users\user\AppData\Local\Temp\5fe0adac-6f24-4332-850e-935b8f09affa.tmp
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\e71f085a-6328-4788-8bf6-80df6cfa0a49.tmp
Google Chrome extension, version 3
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
modified
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\pl\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\pt_BR\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\pt_PT\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\ro\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\ru\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\sk\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\sl\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\sr\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\sv\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\th\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\tr\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\uk\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\vi\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\zh_CN\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_locales\zh_TW\messages.json
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\craw_background.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\craw_window.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\css\craw_window.css
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\html\craw_window.html
HTML document, ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\flapper.gif
GIF image data, version 89a, 30 x 30
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\topbar_floating_button.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\topbar_floating_button_close.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\topbar_floating_button_hover.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\topbar_floating_button_maximize.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\images\topbar_floating_button_pressed.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6068_1611117744\e71f085a-6328-4788-8bf6-80df6cfa0a49.tmp
Google Chrome extension, version 3
dropped
There are 88 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --enable-automation "http://www.macwestlosangeles.com/sa.html
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1568,5519994032537552519,8327954877297158107,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1920 /prefetch:8

URLs

Name
IP
Malicious
http://www.macwestlosangeles.com/sa.html
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/Los-Angeles-Mac-Data-Recovery.jpg
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/uploads/2021/11/macwest-data-recovery-mac-repair-losangeles-logo-default-1.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/macbook-pro-repair-losangeles-400x266.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/harddrive-recovery-los-angeles.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/mac-apple-repair-service-400x340.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/mac-apple-repair-service.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/macwest-data-recovery-mac-repair-losangeles-logo-@2x-1.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/macbook-pro-repair-losangeles-300x200.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/mac-pro-repair-losangeles-1-300x200.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/plugins/whatsapp-for-wordpress/assets/dist/js/njt-whatsapp.js?ver=3.1.4
192.185.16.233
malicious
https://www.macwestlosangeles.com/data-recovery-mac-datarecovery/
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-styles/78db3eb54f764650043200620fcf84f8.min.css?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-scripts/a3749f7845239cd37c1026ef784fcfb2.min.js?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-gfonts/xn7gYHE41ni1AdIRggexSg.woff2
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2020/08/hero-women-accountant.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-solid-900.woff2
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-brands-400.woff2
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/lacie-data-recovery-logo.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-scripts/9e4875563e3d1793bd72af5d4ea87c00.min.js?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/plugins/whatsapp-for-wordpress/assets/img/whatsapp_logo.svg
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/plugins/whatsapp-for-wordpress/assets/dist/js/njt-whatsapp.js?ver=3.1.4
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/seagate-data-recovery-logo.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-includes/js/wp-emoji-release.min.js?ver=6.0
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-scripts/c7e84c195846ead0dfbc8cfad0152b76.min.js?ver=3.7.1
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-solid-900.woff2
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-regular-400.woff2
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-icons/digital-agency-icon-set/fonts/digital.ttf?exhcqw
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-scripts/abc5eb259d415054112915a746638e90.min.js?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-brands-400.woff2
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/plugins/wpforms-lite/assets/css/wpforms-full.min.css?ver=1.7.4.2
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/drobo-raid-data-recovery-logo.png
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-includes/css/dist/block-library/style.min.css?ver=6.0
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/icomoon/awb-icons.woff
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/imac-repair-losangeles-300x200.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/data-recovery-mac-datarecovery/hard-drive-data-recovery/
malicious
https://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/fontawesome/webfonts/fa-regular-400.woff2
192.185.16.233
malicious
https://www.macwestlosangeles.com/best-data-recovery-service-in-los-angeles/
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/Los-Angeles-Mac-Data-Recovery-600x600.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/mac-mini-repair-losangeles-300x199.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/mac-pro-repair-losangeles-1-400x267.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-styles/38503625c038287d404dd6e9c203a3df.min.css?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-icons/Accountant-Pro-v2.0/fonts/Accountant-Pro.ttf?ym7fev
192.185.16.233
malicious
http://www.macwestlosangeles.com/sa.html
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/wd-data-recovery-logo.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-styles/133c61d024919dfc96b08de9bf48456d.min.css?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/mac-repair-service-los-angeles/
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/imac-repair-losangeles-400x266.jpg
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/plugins/whatsapp-for-wordpress/assets/dist/css/style.css?ver=6.0
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/uploads/2021/11/favicon-iphone.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/plugins/whatsapp-for-wordpress/assets/js/whatsapp-button.js?ver=3.1.4
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/gtech-graid-data-recovery-logo.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/plugins/whatsapp-for-wordpress/assets/js/whatsapp-popup.js?ver=6.0
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/harddrive-recovery-los-angeles-600x531.jpg
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2022/03/mac-mini-repair-losangeles-400x266.jpg
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/uploads/fusion-scripts/e689b1ad686296513c868ce5372e3fa7.min.js?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-admin/admin-ajax.php
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/favicon-iphone.png
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2020/09/error-page.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/macwest-data-recovery-mac-repair-losangeles-logo-default-1.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/favicon.png
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-scripts/ed9ca1d6a2e2b0c6adb13b2192822629.min.js?ver=3.7.1
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/2021/11/samsung-data-recovery-logo.png
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-content/uploads/fusion-styles/d2904833172cad1cd7a1a3787e0955d3.min.css?ver=3.7.1
192.185.16.233
malicious
http://www.macwestlosangeles.com/wp-includes/js/wp-emoji-release.min.js?ver=6.0
192.185.16.233
malicious
http://www.macwestlosangeles.com/sa.html
malicious
http://www.macwestlosangeles.com/wp-content/themes/Avada/includes/lib/assets/fonts/icomoon/awb-icons.woff
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/uploads/fusion-icons/Accountant-Pro-v2.0/fonts/Accountant-Pro.woff?ym7fev
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-content/plugins/wpforms-lite/assets/css/wpforms-full.min.css?ver=1.7.4.2
192.185.16.233
malicious
https://www.macwestlosangeles.com/wp-includes/css/dist/block-library/style.min.css?ver=6.0
192.185.16.233
malicious
https://www.macwestlosangeles.com/data-recovery-mac-datarecovery/hard-drive-data-recovery/
192.185.16.233
https://www.google.com
unknown
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
unknown
https://dns.google
unknown
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
unknown
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
142.250.185.238
https://payments.google.com/payments/v4/js/integrator.js
unknown
https://www.google.com/images/x2.gif
unknown
https://www.google.com/images/dot2.gif
unknown
https://www.macwestlosangeles.com/mac-repair-service-los-angeles/
192.185.16.233
https://www.google.com/
unknown
https://www.macwestlosangeles.com/best-data-recovery-service-in-los-angeles/
192.185.16.233
https://www.macwestlosangeles.com/data-recovery-mac-datarecovery/
192.185.16.233
https://www.google.com/images/cleardot.gif
unknown
https://play.google.com
unknown
https://sandbox.google.com/payments/v4/js/integrator.js
unknown
https://accounts.google.com/MergeSession
unknown
https://accounts.google.com
unknown
https://apis.google.com
unknown
https://www-googleapis-staging.sandbox.google.com
unknown
https://clients2.google.com
unknown
https://www.google.com/intl/en-US/chrome/blank.html
unknown
https://ogs.google.com
unknown
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
142.250.185.109
https://www.macwestlosangeles.com/
192.185.16.233
https://clients2.googleusercontent.com
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
mmx-ds.cdn.whatsapp.net
157.240.17.60
ninjateam.org
104.26.15.122
accounts.google.com
142.250.185.109
www-googletagmanager.l.google.com
172.217.16.136
bit.ly
67.199.248.10
macwestlosangeles.com
192.185.16.233
clients.l.google.com
142.250.185.238
s.w.org
192.0.77.48
www.macwestlosangeles.com
unknown
clients2.google.com
unknown
api.whatsapp.com
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.109
accounts.google.com
United States
172.217.16.136
www-googletagmanager.l.google.com
United States
192.168.2.1
unknown
unknown
142.250.185.238
clients.l.google.com
United States
239.255.255.250
unknown
Reserved
192.185.16.233
macwestlosangeles.com
United States
127.0.0.1
unknown
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blacklist_cache_md5_digest
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
There are 32 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
1945EE13000
heap
page read and write
AE1EB7F000
stack
page read and write
2AD6D080000
heap
page read and write
57A0FFF000
stack
page read and write
AE1EF7F000
stack
page read and write
1F866D80000
remote allocation
page read and write
1F866AA0000
trusted library allocation
page read and write
1F866F13000
heap
page read and write
1F86169E000
heap
page read and write
1F861702000
heap
page read and write
1F866D70000
trusted library allocation
page read and write
1F866D30000
trusted library allocation
page read and write
E94FC7F000
stack
page read and write
E94F8FB000
stack
page read and write
255E88BF000
heap
page read and write
AFD25F7000
stack
page read and write
255E888B000
heap
page read and write
2AD6D010000
heap
page read and write
37C567E000
stack
page read and write
2AD6D260000
heap
page read and write
19F2F3D0000
heap
page read and write
1FB71FF0000
heap
page read and write
26FD224C000
heap
page read and write
255E886E000
heap
page read and write
19F2F430000
heap
page read and write
1945EE42000
heap
page read and write
1FB7227F000
heap
page read and write
2275BE10000
heap
page read and write
1F866C21000
trusted library allocation
page read and write
1F866EFE000
heap
page read and write
1F866D60000
trusted library allocation
page read and write
AFD26FE000
stack
page read and write
255E8913000
heap
page read and write
26FD2249000
heap
page read and write
19F2F675000
heap
page read and write
AFD27FF000
stack
page read and write
1F866F22000
heap
page read and write
1F861600000
heap
page read and write
1F866EF3000
heap
page read and write
1FB72308000
heap
page read and write
4DF50FE000
stack
page read and write
26FD2213000
heap
page read and write
1FB72000000
heap
page read and write
1F866C44000
trusted library allocation
page read and write
1F861F02000
heap
page read and write
B074D7F000
stack
page read and write
1F86168A000
heap
page read and write
57A0B0B000
stack
page read and write
1FB72202000
heap
page read and write
1945EE56000
heap
page read and write
2275C002000
heap
page read and write
1945EE66000
heap
page read and write
983ECFB000
stack
page read and write
AE1F07D000
stack
page read and write
255E8813000
heap
page read and write
255E8800000
heap
page read and write
24F1D23C000
heap
page read and write
1F866E00000
heap
page read and write
1F866C60000
trusted library allocation
page read and write
1F8615F0000
trusted library allocation
page read and write
4DF49FF000
stack
page read and write
1945EE41000
heap
page read and write
24F1D257000
heap
page read and write
255E88E2000
heap
page read and write
24F1D324000
heap
page read and write
24F1D279000
heap
page read and write
1F866F1B000
heap
page read and write
1F866A90000
trusted library allocation
page read and write
24F1D202000
heap
page read and write
2275C102000
heap
page read and write
1F861E15000
heap
page read and write
26FD20B0000
heap
page read and write
1F866C2E000
trusted library allocation
page read and write
255E88D0000
heap
page read and write
2AD6D266000
heap
page read and write
2AD6D27A000
heap
page read and write
1F861F18000
heap
page read and write
19F2F713000
heap
page read and write
1F866F0C000
heap
page read and write
B07467E000
stack
page read and write
1F866E9F000
heap
page read and write
AE1EC7E000
stack
page read and write
1945EE3B000
heap
page read and write
57A0E7E000
stack
page read and write
1F862180000
trusted library allocation
page read and write
26FD2313000
heap
page read and write
1F8616BB000
heap
page read and write
1F866B00000
trusted library allocation
page read and write
983E79C000
stack
page read and write
1FB72264000
heap
page read and write
1F866F19000
heap
page read and write
19F2F641000
heap
page read and write
19F2F667000
heap
page read and write
1F866F0C000
heap
page read and write
57A13FF000
stack
page read and write
1945EE24000
heap
page read and write
1945EF02000
heap
page read and write
1F866E54000
heap
page read and write
AE1EA7E000
stack
page read and write
4DF447B000
stack
page read and write
1F866ED8000
heap
page read and write
B8FB97C000
stack
page read and write
1F866C50000
trusted library allocation
page read and write
1945EE7E000
heap
page read and write
24F1D100000
heap
page read and write
2AD6D302000
heap
page read and write
1F862730000
trusted library section
page readonly
1945EE59000
heap
page read and write
AFD247B000
stack
page read and write
24F1D229000
heap
page read and write
1945EE5E000
heap
page read and write
983EFFF000
stack
page read and write
4DF4EFE000
stack
page read and write
1FB7225E000
heap
page read and write
37C53FE000
stack
page read and write
1F86163D000
heap
page read and write
255E8902000
heap
page read and write
2275C040000
heap
page read and write
37C5AFF000
stack
page read and write
B8FBCFF000
stack
page read and write
255E8829000
heap
page read and write
37C59FE000
stack
page read and write
1F866E48000
heap
page read and write
1FB7228C000
heap
page read and write
AE1E7EC000
stack
page read and write
26FD2880000
trusted library allocation
page read and write
4DF4AFE000
stack
page read and write
1F862700000
trusted library section
page readonly
57A10FB000
stack
page read and write
1945EE67000
heap
page read and write
1F866F0C000
heap
page read and write
255E9002000
heap
page read and write
E94FA7F000
stack
page read and write
2AD6D22A000
heap
page read and write
1945EE6D000
heap
page read and write
2AD6D213000
heap
page read and write
1F866D80000
remote allocation
page read and write
B8FB47B000
stack
page read and write
E94FB77000
stack
page read and write
1F861F00000
heap
page read and write
1F861693000
heap
page read and write
1F861F13000
heap
page read and write
1F868000000
heap
page read and write
2AD6D279000
heap
page read and write
1F866F1B000
heap
page read and write
1F862A80000
trusted library allocation
page read and write
2AD6D253000
heap
page read and write
1FB72213000
heap
page read and write
255E8823000
heap
page read and write
1F8626F0000
trusted library section
page readonly
2AD6D308000
heap
page read and write
37C537C000
stack
page read and write
26FD20C0000
heap
page read and write
255E8844000
heap
page read and write
1945EE4E000
heap
page read and write
2275BF70000
trusted library allocation
page read and write
2AD6D286000
heap
page read and write
1945EE00000
heap
page read and write
1F866F03000
heap
page read and write
1F866D70000
trusted library allocation
page read and write
B8FBAFC000
stack
page read and write
983EEFB000
stack
page read and write
E94F4DB000
stack
page read and write
1FB7225B000
heap
page read and write
B07507C000
stack
page read and write
1945ECE0000
heap
page read and write
B074B7A000
stack
page read and write
37C58FE000
stack
page read and write
B074DFE000
stack
page read and write
24F1D200000
heap
page read and write
19F2F677000
heap
page read and write
1F861F18000
heap
page read and write
1F866D40000
trusted library allocation
page read and write
AFD237B000
stack
page read and write
37C57FE000
stack
page read and write
26FD2263000
heap
page read and write
B074F7F000
stack
page read and write
E94F9FB000
stack
page read and write
57A0F7C000
stack
page read and write
983EDFE000
stack
page read and write
1FB72262000
heap
page read and write
1FB72300000
heap
page read and write
1F862600000
trusted library allocation
page read and write
255E88C8000
heap
page read and write
1F8626E0000
trusted library section
page readonly
4DF47FF000
stack
page read and write
1945EE74000
heap
page read and write
1F866F06000
heap
page read and write
1F861E02000
heap
page read and write
24F1DA02000
trusted library allocation
page read and write
2AD6D313000
heap
page read and write
1F866D50000
trusted library allocation
page read and write
1FB72160000
trusted library allocation
page read and write
1945EE79000
heap
page read and write
19F2F613000
heap
page read and write
2275C013000
heap
page read and write
AE1F17E000
stack
page read and write
26FD228E000
heap
page read and write
1F862501000
trusted library allocation
page read and write
1945EE64000
heap
page read and write
26FD2286000
heap
page read and write
19F2F600000
heap
page read and write
26FD2253000
heap
page read and write
1945EE5F000
heap
page read and write
2275BFA0000
remote allocation
page read and write
B07537C000
stack
page read and write
1F866B10000
trusted library allocation
page read and write
1F867090000
trusted library allocation
page read and write
26FD224E000
heap
page read and write
19F2FC02000
trusted library allocation
page read and write
1F866D80000
trusted library allocation
page read and write
1FB72258000
heap
page read and write
B07487A000
stack
page read and write
B074777000
stack
page read and write
1F86168C000
heap
page read and write
1F866E2D000
heap
page read and write
1F866EDA000
heap
page read and write
57A11F7000
stack
page read and write
1FB7223C000
heap
page read and write
26FD228C000
heap
page read and write
1945EE44000
heap
page read and write
4DF48FD000
stack
page read and write
B074EFF000
stack
page read and write
1F8615C0000
heap
page read and write
1945EE58000
heap
page read and write
1F866EDE000
heap
page read and write
1F866CF0000
trusted library allocation
page read and write
2AD6D020000
heap
page read and write
1945EE69000
heap
page read and write
1FB72200000
heap
page read and write
26FD2200000
heap
page read and write
1F866E3B000
heap
page read and write
1F866C40000
trusted library allocation
page read and write
B8FBBFC000
stack
page read and write
1F866C50000
trusted library allocation
page read and write
2275BFA0000
remote allocation
page read and write
1945EE29000
heap
page read and write
1F861613000
heap
page read and write
1945EE63000
heap
page read and write
1F861F18000
heap
page read and write
1945EE77000
heap
page read and write
26FD2120000
heap
page read and write
19F2F702000
heap
page read and write
4DF4DFF000
stack
page read and write
1FB72060000
heap
page read and write
24F1D160000
heap
page read and write
1F861674000
heap
page read and write
2AD6D300000
heap
page read and write
4DF4BFD000
stack
page read and write
1F862720000
trusted library section
page readonly
4DF4FFF000
stack
page read and write
1F866AC0000
trusted library allocation
page read and write
1FB7225C000
heap
page read and write
1FB72302000
heap
page read and write
26FD2308000
heap
page read and write
E94F5DE000
stack
page read and write
1F866EEF000
heap
page read and write
B07434C000
stack
page read and write
1FB72248000
heap
page read and write
26FD222D000
heap
page read and write
1F866C20000
trusted library allocation
page read and write
19F2F602000
heap
page read and write
2AD6DA02000
trusted library allocation
page read and write
1945EE57000
heap
page read and write
26FD226A000
heap
page read and write
1945EE6F000
heap
page read and write
1F866F08000
heap
page read and write
B07517F000
stack
page read and write
1F861E00000
heap
page read and write
AFD1F4B000
stack
page read and write
1F866C41000
trusted library allocation
page read and write
B074E7F000
stack
page read and write
57A0B8E000
stack
page read and write
2275BE70000
heap
page read and write
1F866F1F000
heap
page read and write
AFD1FCE000
stack
page read and write
B0743CE000
stack
page read and write
B074CFF000
stack
page read and write
1F861F58000
heap
page read and write
1F866D80000
remote allocation
page read and write
255E8620000
heap
page read and write
26FD2229000
heap
page read and write
1F861678000
heap
page read and write
1945EE40000
heap
page read and write
1FB72A02000
trusted library allocation
page read and write
1F866C28000
trusted library allocation
page read and write
1F861D30000
trusted library section
page read and write
1F866EA2000
heap
page read and write
26FD2A02000
trusted library allocation
page read and write
2AD6D200000
heap
page read and write
B0750FD000
stack
page read and write
24F1D190000
trusted library allocation
page read and write
1F8616AE000
heap
page read and write
1F8616FD000
heap
page read and write
24F1D0F0000
heap
page read and write
19F2F3C0000
heap
page read and write
AE1ECFE000
stack
page read and write
1FB72313000
heap
page read and write
2275BE00000
heap
page read and write
26FD223C000
heap
page read and write
B8FB8FF000
stack
page read and write
2275C05C000
heap
page read and write
19F2FB90000
trusted library allocation
page read and write
1945F602000
trusted library allocation
page read and write
57A12FF000
stack
page read and write
1945EE62000
heap
page read and write
19F2F65B000
heap
page read and write
B8FBEFF000
stack
page read and write
1F861713000
heap
page read and write
B07497A000
stack
page read and write
1F861550000
heap
page read and write
B074A7F000
stack
page read and write
B07527D000
stack
page read and write
1945EE61000
heap
page read and write
26FD2263000
heap
page read and write
B8FBA7D000
stack
page read and write
1945EE5A000
heap
page read and write
4DF467A000
stack
page read and write
1F866EFE000
heap
page read and write
1F861629000
heap
page read and write
1F861560000
heap
page read and write
1F866C64000
trusted library allocation
page read and write
1FB72260000
heap
page read and write
1945EE45000
heap
page read and write
1F862710000
trusted library section
page readonly
B074C7B000
stack
page read and write
2AD6D279000
heap
page read and write
255E8690000
heap
page read and write
1945EE3D000
heap
page read and write
AE1EDFF000
stack
page read and write
1FB72229000
heap
page read and write
26FD2302000
heap
page read and write
1945EE60000
heap
page read and write
1945ED70000
trusted library allocation
page read and write
1FB72254000
heap
page read and write
2275C000000
heap
page read and write
4DF4CFF000
stack
page read and write
B8FB7FE000
stack
page read and write
1945EE75000
heap
page read and write
1945EE83000
heap
page read and write
AFD227D000
stack
page read and write
2275C029000
heap
page read and write
1F866F2A000
heap
page read and write
E94F55E000
stack
page read and write
1F866F1C000
heap
page read and write
2275C802000
trusted library allocation
page read and write
1F861DF3000
trusted library allocation
page read and write
B8FB67C000
stack
page read and write
24F1D300000
heap
page read and write
26FD2300000
heap
page read and write
1F866F1F000
heap
page read and write
19F2F629000
heap
page read and write
1945EE5C000
heap
page read and write
1F862400000
trusted library allocation
page read and write
1FB72257000
heap
page read and write
AFD24FF000
stack
page read and write
1945EE47000
heap
page read and write
2AD6D23C000
heap
page read and write
2AD6D180000
trusted library allocation
page read and write
1F86166F000
heap
page read and write
1F861657000
heap
page read and write
1F866A80000
trusted library allocation
page read and write
1945EE7B000
heap
page read and write
1F866E21000
heap
page read and write
1F866F25000
heap
page read and write
1945EE32000
heap
page read and write
1F866E87000
heap
page read and write
255E8630000
heap
page read and write
24F1D271000
heap
page read and write
1945ECD0000
heap
page read and write
255E8790000
trusted library allocation
page read and write
2275BFA0000
remote allocation
page read and write
1945ED40000
heap
page read and write
26FD227A000
heap
page read and write
1F861DF0000
trusted library allocation
page read and write
1F866E12000
heap
page read and write
B8FBDFD000
stack
page read and write
1F861F9A000
heap
page read and write
AE1EAFE000
stack
page read and write
255E9100000
heap
page read and write
24F1D213000
heap
page read and write
1F866C20000
trusted library allocation
page read and write
1945EE7A000
heap
page read and write
E94FD7F000
stack
page read and write
AE1EEFD000
stack
page read and write
1F866E60000
heap
page read and write
1F866F1D000
heap
page read and write
1F866F02000
heap
page read and write
24F1D302000
heap
page read and write
There are 379 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
http://www.macwestlosangeles.com/sa.html
https://www.macwestlosangeles.com/
https://www.macwestlosangeles.com/best-data-recovery-service-in-los-angeles/
https://www.macwestlosangeles.com/mac-repair-service-los-angeles/
https://www.macwestlosangeles.com/data-recovery-mac-datarecovery/
https://www.macwestlosangeles.com/data-recovery-mac-datarecovery/hard-drive-data-recovery/