Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
test@barclays.com.html
|
HTML document, ISO-8859 text, with very long lines, with CRLF line terminators
|
initial sample
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\5dd7ae69-e6ad-4a15-a5cb-99a213f83493.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\7edfe7eb-47ee-4924-af2b-297a69664551.tmp
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\934a3bab-1920-40b2-aca2-fff43d1629aa.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\05f5fc9d-0b67-4173-b3d0-47807686f7eb.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\425d98ad-f4df-4e13-b8fb-41dff37b5585.tmp
|
very short file (no magic)
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\4b5a2f7e-0423-447f-8da5-5df0d2bb6dd8.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\52d67da0-d354-4a40-bad6-22c5d5bd7bf3.tmp
|
MS Windows icon resource - 13 icons, 8x8, 32 bits/pixel, 10x10, 32 bits/pixel
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\592ac4df-946e-4d99-9532-8cb93f7c5a77.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\7220f273-efaa-47a9-bdff-54e88e0f464d.tmp
|
ASCII text, with very long lines, with no line terminators
|
modified
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\7a4b5349-6aec-4abd-8d0f-8d8b0bc4a6a6.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\LOG
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_1\_metadata\computed_hashes.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption\LOG
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Google Profile.ico (copy)
|
MS Windows icon resource - 13 icons, 8x8, 32 bits/pixel, 10x10, 32 bits/pixel
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\History
|
SQLite 3.x database, last written using SQLite version 3035005
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Login Data For Account
|
SQLite 3.x database, last written using SQLite version 3035005
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000003.log
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Sessions\Session_13301172988058248
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Sessions\Tabs_13301172989165152
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\000001.dbtmp
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Session Storage\MANIFEST-000001
|
PGP\011Secret Key -
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Visited Links
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\Web Data
|
SQLite 3.x database, last written using SQLite version 3035005
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000006.dbtmp
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\f6839c5e-12a8-4271-8c6e-3b1843bbc857.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Default\ffc0ae26-ecd7-4faf-8bc3-14b4ecff9872.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Last Browser
|
data
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Last Version
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\Local State (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Google\Chrome\User Data\a7e5f443-b449-45ad-8e8b-7d84a52d0a3a.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\1bb9848a-13e0-481e-9182-6f8c10c78242.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\cd7b350f-5982-4504-8046-216985eb3307.tmp
|
Google Chrome extension, version 3
|
modified
|
||
C:\Users\alfredo\AppData\Local\Temp\cf3055ee-f737-4238-b99a-ce800a1e765f.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\de7d353a-91ad-46d9-9dca-e1f03ca82a0b.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\e2101325-4ca1-4db2-95b9-c345399cc004.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\e6b0db7b-9f08-487a-a9ef-699c08b3ce7f.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT)
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\bg\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\ca\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\cs\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\da\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\de\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\el\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\en\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\es\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\es_419\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\et\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\fi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\fil\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\fr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\hi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\hr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\hu\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\id\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\it\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\ja\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\ko\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\lt\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\lv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\nb\messages.json
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\nl\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\pl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\pt_BR\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\pt_PT\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\ro\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\ru\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\sk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\sl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\sr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\sv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\th\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\tr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\uk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\vi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\zh_CN\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_locales\zh_TW\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\_metadata\verified_contents.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\craw_background.js
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\craw_window.js
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\css\craw_window.css
|
ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\html\craw_window.html
|
HTML document, ASCII text
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\flapper.gif
|
GIF image data, version 89a, 30 x 30
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\icon_128.png
|
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\icon_16.png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\topbar_floating_button.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\topbar_floating_button_close.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\topbar_floating_button_hover.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\topbar_floating_button_maximize.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\images\topbar_floating_button_pressed.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\alfredo\AppData\Local\Temp\scoped_dir7108_695416080\CRX_INSTALL\manifest.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\alfredo\AppData\Roaming\Microsoft\Spelling\en-US\default.dic
|
Little-endian UTF-16 Unicode text, with no line terminators
|
dropped
|
There are 92 hidden files, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
file:///C:/Users/alfredo/Desktop/test@barclays.com.html
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
gstaticadssl.l.google.com
|
142.250.186.35
|
||
stackpath.bootstrapcdn.com
|
188.114.98.173
|
||
accounts.google.com
|
142.250.186.173
|
||
cdnjs.cloudflare.com
|
104.17.25.14
|
||
maxcdn.bootstrapcdn.com
|
104.18.10.207
|
||
clients.l.google.com
|
142.250.185.238
|
||
clients2.google.com
|
unknown
|
||
ka-f.fontawesome.com
|
unknown
|
||
code.jquery.com
|
unknown
|
||
kit.fontawesome.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
142.250.186.35
|
gstaticadssl.l.google.com
|
United States
|
||
172.67.150.137
|
unknown
|
United States
|
||
34.104.35.123
|
unknown
|
United States
|
||
192.168.2.1
|
unknown
|
unknown
|
||
104.18.10.207
|
maxcdn.bootstrapcdn.com
|
United States
|
||
216.58.212.131
|
unknown
|
United States
|
||
142.250.186.173
|
accounts.google.com
|
United States
|
||
142.250.187.131
|
unknown
|
United States
|
||
142.250.185.238
|
clients.l.google.com
|
United States
|
||
142.250.185.170
|
unknown
|
United States
|
||
69.16.175.42
|
unknown
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
172.217.23.99
|
unknown
|
United States
|
||
188.114.98.173
|
stackpath.bootstrapcdn.com
|
European Union
|
||
104.18.23.52
|
unknown
|
United States
|
||
142.250.186.74
|
unknown
|
United States
|
||
104.17.25.14
|
cdnjs.cloudflare.com
|
United States
|
||
127.0.0.1
|
unknown
|
unknown
|
There are 8 hidden IPs, click here to show them.