IOC Report
https://spatterjointposition.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\0a573f8e-bd08-4920-8498-e5c7053e5ca3.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\25f82938-ee41-4f40-9e6c-18c30ac62ada.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\5c0070c2-6756-422a-bed5-359dd6946545.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\5cc06899-b404-40bb-9912-447e6526c319.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\6407301f-2944-473a-a98b-406abc9eb29b.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\67766df0-1589-4501-a1e4-47170e46c919.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\79c829ea-58df-49d0-b7b7-b3d8bbd3be57.tmp
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\906f612a-faf8-4e40-9854-60460b5be071.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
modified
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0498d8d1-998e-4aee-b8a8-5b426a0a1c56.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\06e9b1b8-b1d9-45a0-b2e8-f0e6c8f4f1d8.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\078edded-353d-4e52-b959-05f9076e9ba2.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0d6da62f-a154-49fe-8eaa-ed2edc2c87d5.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\153de007-3e71-43d7-a576-3a47475081a4.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\380ad8f8-bfd5-4529-a024-948ab59738b0.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3b95c536-2787-469a-92fe-4110bdc6db58.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3e35ca23-d733-4921-b152-31cbac549ba1.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\50dc6200-9d3b-44eb-a267-f16cc4296171.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\52c535f4-1515-4338-8400-b9e7ea56a616.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5960d875-92fc-4fe5-9a6f-d66e299973b2.tmp
ASCII text, with very long lines, with no line terminators
modified
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\80771ced-65a4-4539-8578-d57ff99918ee.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\91cc80f6-5ef4-4a97-a5cf-80fbfda4b929.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\94b40b6d-c495-4f3d-8e49-978879b4338a.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\94b44d5f-e7cd-4a45-96ed-526273df694a.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.youtube.com_0.indexeddb.leveldb\000001.dbtmp
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.youtube.com_0.indexeddb.leveldb\CURRENT (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.youtube.com_0.indexeddb.leveldb\MANIFEST-000001
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\ae478fa7-70c5-4e36-b39b-4be498dc31c7\index
ISO-8859 text, with no line terminators, with escape sequences
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\ae478fa7-70c5-4e36-b39b-4be498dc31c7\index-dir\temp-index
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\ae478fa7-70c5-4e36-b39b-4be498dc31c7\index-dir\the-real-index (copy)
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\index.txt (copy)
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\379f1cbab5b08b6fc9e08681e42d8be311441c88\index.txt.tmp
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\ea3d7a3a-1959-4235-bac5-e3894f7e2431.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\3059c87a-6592-453b-a83b-7efd9ea88152.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\aa2a95b0-bf77-4388-8452-3b2282038708.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\b7fbad58-f0aa-4441-9a85-fe27e9e0ed77.tmp
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\b8689bd8-874f-4663-8900-5cd354e668ce.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d66d4c49-2e56-4c40-b3c7-b4283c8599d2.tmp
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e45ba11d-f760-4aa2-902c-2c2f4639e799.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\a63e5fd8-a01d-4e45-9c44-7330264d4008.tmp
SysEx File -
dropped
C:\Users\user\AppData\Local\Google\Chrome\User Data\d2919e16-2e5f-4d2d-b26b-f93daf9d6b3c.tmp
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\02bf7525-dc4c-4c93-a8a6-85a18a8cc3ca.tmp
Google Chrome extension, version 3
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_pnacl_json
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_for_eh_o
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_o
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_crtend_o
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_ld_nexe
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=7511538a3a6a0b862c772eace49075ed1bbe2377, stripped
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_libcrt_platform_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_libgcc_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_shim_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_shim_dummy_a
current ar archive
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_llc_nexe
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=309d6d3d463e6b1b0690f39eb226b1e4c469b2ce, stripped
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_sz_nexe
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=4b15de4ab227d5e46213978b8518d53c53ce1db9, stripped
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6060_1494985660\manifest.json
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\6060_1654857163\Recovery.crx3
Google Chrome extension, version 3
dropped
C:\Users\user\AppData\Local\Temp\6060_1654857163\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6060_1654857163\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\6060_1654857163\manifest.json
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\d5fcf379-0e69-4ef2-b6f1-ad49e4693103.tmp
very short file (no magic)
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\02bf7525-dc4c-4c93-a8a6-85a18a8cc3ca.tmp
Google Chrome extension, version 3
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\bg\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\ca\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\cs\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\da\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\de\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\el\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\en\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\en_GB\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\es\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\es_419\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\et\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\fi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\fil\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\fr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\hi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\hr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\hu\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\id\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\it\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\ja\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\ko\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\lt\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\lv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\nb\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\nl\messages.json
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\pl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\pt_BR\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\pt_PT\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\ro\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\ru\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\sk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\sl\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\sr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\sv\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\th\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\tr\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\uk\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\vi\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\zh_CN\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_locales\zh_TW\messages.json
UTF-8 Unicode text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\craw_background.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\craw_window.js
ASCII text, with very long lines
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\css\craw_window.css
ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\html\craw_window.html
HTML document, ASCII text
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\flapper.gif
GIF image data, version 89a, 30 x 30
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\icon_128.png
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\icon_16.png
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\topbar_floating_button.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\topbar_floating_button_close.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\topbar_floating_button_hover.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\topbar_floating_button_maximize.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\images\topbar_floating_button_pressed.png
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
C:\Users\user\AppData\Local\Temp\scoped_dir6060_68835047\CRX_INSTALL\manifest.json
ASCII text, with CRLF line terminators
dropped
There are 126 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1612,17434451715936591080,16828468669034620011,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1920 /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "https://spatterjointposition.com
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1612,17434451715936591080,16828468669034620011,131072 --lang=en-US --service-sandbox-type=audio --enable-audio-service-sandbox --mojo-platform-channel-handle=6248 /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --field-trial-handle=1612,17434451715936591080,16828468669034620011,131072 --lang=en-US --service-sandbox-type=video_capture --enable-audio-service-sandbox --mojo-platform-channel-handle=6236 /prefetch:8

URLs

Name
IP
Malicious
https://spatterjointposition.com
https://dns.google
unknown
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
unknown
https://www.google.com/intl/en-US/chrome/blank.html
unknown
https://www.google.com/
https://ogs.google.com
unknown
https://about.google/stories/timelapse-planetary-changes/
https://www.youtube.com/embed/by-kTJ0DOLc?rel=0&vq=hd720&start=0&cc_load_policy=1&playsinline=1&origin=https%3A%2F%2Fabout.google&enablejsapi=1&widgetid=1
https://www.google.com/images/cleardot.gif
unknown
https://play.google.com
unknown
https://www.google.de/imghp?hl=de&ogbl
https://payments.google.com/payments/v4/js/integrator.js
unknown
https://chromium.googlesource.com/a/native_client/pnacl-llvm.git
unknown
https://sandbox.google.com/payments/v4/js/integrator.js
unknown
https://www.google.com/images/x2.gif
unknown
https://www.youtube.com/
unknown
https://accounts.google.com/MergeSession
unknown
http://llvm.org/):
unknown
https://www.google.com
unknown
https://www.google.com/images/dot2.gif
unknown
https://accounts.google.com/signin/v2/identifier?hl=de&passive=true&continue=https%3A%2F%2Fwww.google.com%2F&ec=GAZAmgQ&flowName=GlifWebSignIn&flowEntry=ServiceLogin
https://code.google.com/p/nativeclient/issues/entry%s:
unknown
https://about.google/products/
https://code.google.com/p/nativeclient/issues/entry
unknown
https://accounts.google.com
unknown
https://clients2.googleusercontent.com
unknown
https://apis.google.com
unknown
https://www.google.com/intl/de/gmail/about/#
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
unknown
https://www.google.com/
unknown
https://www-googleapis-staging.sandbox.google.com
unknown
https://store.google.com/DE?utm_source=hp_header&utm_medium=google_ooo&utm_campaign=GS100042&hl=de-DE
https://chromium.googlesource.com/a/native_client/pnacl-clang.git
unknown
https://clients2.google.com
unknown
https://clients2.google.com/service/update2/crx
unknown
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gstaticadssl.l.google.com
142.250.184.195
scone-pa.clients6.google.com
142.250.185.138
www.google.de
172.217.18.3
google.com
172.217.16.206
csp.withgoogle.com
172.217.16.209
accounts.google.com
142.250.185.205
plus.l.google.com
216.58.212.142
stats.l.doubleclick.net
66.102.1.156
www-googletagmanager.l.google.com
142.250.186.168
i.ytimg.com
142.250.185.214
mail.google.com
142.250.186.165
store.google.com
172.217.16.142
spatterjointposition.com
192.243.59.12
static-doubleclick-net.l.google.com
142.250.186.134
about.google
216.239.32.29
youtube-ui.l.google.com
142.250.186.110
googleads.g.doubleclick.net
142.250.185.162
play.google.com
142.250.186.142
www3.l.google.com
172.217.23.110
photos-ugc.l.googleusercontent.com
142.250.186.33
www.google.com
142.250.185.196
clients.l.google.com
142.250.186.110
googlehosted.l.googleusercontent.com
172.217.23.97
kstatic.googleusercontent.com
35.241.11.240
yt3.ggpht.com
unknown
lh3.googleusercontent.com
unknown
static.doubleclick.net
unknown
stats.g.doubleclick.net
unknown
clients2.google.com
unknown
accounts.youtube.com
unknown
www.youtube.com
unknown
apis.google.com
unknown
There are 22 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.168.2.1
unknown
unknown
216.58.212.142
plus.l.google.com
United States
142.250.185.205
accounts.google.com
United States
172.217.23.110
www3.l.google.com
United States
172.217.23.97
googlehosted.l.googleusercontent.com
United States
66.102.1.156
stats.l.doubleclick.net
United States
192.168.2.23
unknown
unknown
142.250.185.162
googleads.g.doubleclick.net
United States
142.250.186.110
youtube-ui.l.google.com
United States
142.250.186.134
static-doubleclick-net.l.google.com
United States
35.241.11.240
kstatic.googleusercontent.com
United States
142.250.186.33
photos-ugc.l.googleusercontent.com
United States
172.217.16.142
store.google.com
United States
142.250.184.195
gstaticadssl.l.google.com
United States
216.239.32.29
about.google
United States
172.217.16.206
google.com
United States
172.217.18.3
www.google.de
United States
172.217.16.209
csp.withgoogle.com
United States
142.250.185.138
scone-pa.clients6.google.com
United States
142.250.185.214
i.ytimg.com
United States
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
192.243.59.12
spatterjointposition.com
Dominica
142.250.186.165
mail.google.com
United States
142.250.186.168
www-googletagmanager.l.google.com
United States
127.0.0.1
unknown
unknown
There are 16 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blacklist_cache_md5_digest
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Microsoft\ActiveMovie\devenum 64-bit
Version
There are 41 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
25E14464000
heap
page read and write
1B044DE7000
heap
page read and write
21AE4913000
heap
page read and write
21AE4074000
heap
page read and write
7234D7C000
stack
page read and write
21AE4802000
heap
page read and write
16655800000
heap
page read and write
1CC31BC0000
remote allocation
page read and write
1B044D43000
heap
page read and write
1B04423C000
heap
page read and write
32C50FA000
stack
page read and write
A4A687E000
stack
page read and write
21AE9713000
heap
page read and write
21AE4958000
heap
page read and write
16655828000
heap
page read and write
1C7D9202000
trusted library allocation
page read and write
1B044BC7000
heap
page read and write
1C7D8A84000
heap
page read and write
1745E100000
heap
page read and write
3355FE000
unkown
page read and write
1B044200000
heap
page read and write
1B04B285000
unkown
page read and write
21AE4113000
heap
page read and write
1B044D69000
heap
page read and write
1B049E10000
unkown
page read and write
25E14460000
heap
page read and write
1C7D89D0000
unkown
page readonly
A4A6E7E000
stack
page read and write
21AE3FD0000
trusted library section
page read and write
BC091FE000
stack
page read and write
1B04422A000
heap
page read and write
32C51FF000
stack
page read and write
1B044DBD000
heap
page read and write
25E1447F000
heap
page read and write
166555C0000
heap
page read and write
21AE9824000
trusted library allocation
page read and write
1CC31BC0000
remote allocation
page read and write
25E14473000
heap
page read and write
32C547F000
unkown
page read and write
23577053000
heap
page read and write
1C7D8AE6000
heap
page read and write
72352FC000
stack
page read and write
1C7D8AFF000
heap
page read and write
1B044BD6000
heap
page read and write
72354FC000
stack
page read and write
2357704E000
heap
page read and write
1745D902000
heap
page read and write
1B044B2C000
heap
page read and write
21AE9940000
trusted library allocation
page read and write
1B044B90000
heap
page read and write
1745D800000
heap
page read and write
1B04B013000
unkown
page read and write
1B044B54000
heap
page read and write
21AE9735000
heap
page read and write
1B0443EB000
heap
page read and write
1B04B196000
unkown
page read and write
21AE499D000
heap
page read and write
25E14484000
heap
page read and write
1B044B6F000
heap
page read and write
25E14444000
heap
page read and write
1B0443C2000
heap
page read and write
BC08D7A000
stack
page read and write
1CC31C02000
trusted library allocation
page read and write
32C557F000
unkown
page read and write
21AE971B000
heap
page read and write
21AE9820000
trusted library allocation
page read and write
23577680000
trusted library allocation
page read and write
21AE4918000
heap
page read and write
1C7D8850000
heap
page read and write
21AE50D0000
trusted library section
page readonly
237AD180000
heap
page read and write
1B0457D0000
unkown
page readonly
23577108000
heap
page read and write
3356F8000
unkown
page read and write
1B04B05F000
unkown
page read and write
16655813000
heap
page read and write
A4A677D000
stack
page read and write
1B0457E0000
unkown
page read and write
21AE40A0000
heap
page read and write
1B04B244000
unkown
page read and write
7234F7C000
stack
page read and write
21AE47C1000
trusted library allocation
page read and write
21AE4026000
heap
page read and write
DB884FE000
stack
page read and write
1CC31602000
heap
page read and write
DB87D4C000
stack
page read and write
1B04B04F000
unkown
page read and write
A4A657B000
stack
page read and write
5D985F7000
stack
page read and write
33547F000
stack
page read and write
1B04B323000
unkown
page read and write
1745D829000
heap
page read and write
25E14320000
heap
page read and write
1C7D9356000
trusted library allocation
page read and write
1B044BF1000
heap
page read and write
1B04B13A000
unkown
page read and write
21AE499D000
heap
page read and write
21AE95F0000
trusted library allocation
page read and write
1B044D92000
heap
page read and write
23576F20000
heap
page read and write
32C4C7F000
stack
page read and write
21AE9661000
heap
page read and write
1B0458C0000
unkown
page read and write
21AE4815000
heap
page read and write
1B0459A0000
unkown
page read and write
23577100000
heap
page read and write
1B049EB0000
unkown
page read and write
DB882FE000
stack
page read and write
1B049A40000
unkown
page read and write
1B044130000
heap
page read and write
1745D86D000
heap
page read and write
1B04B32D000
unkown
page read and write
23577092000
heap
page read and write
237AD170000
heap
page read and write
21AE4094000
heap
page read and write
21AE970A000
heap
page read and write
1B049D70000
unkown
page read and write
21AE9805000
trusted library allocation
page read and write
33527B000
stack
page read and write
32C597E000
unkown
page read and write
25E14447000
heap
page read and write
21AE9821000
trusted library allocation
page read and write
1B044D54000
heap
page read and write
21AE9702000
heap
page read and write
1C7D8A13000
heap
page read and write
334D4B000
stack
page read and write
1745D8C1000
heap
page read and write
1B04B14A000
unkown
page read and write
1B04B160000
unkown
page read and write
32C4EF9000
stack
page read and write
33507E000
stack
page read and write
1B04438E000
heap
page read and write
21AE50C0000
trusted library section
page readonly
5D97F4B000
stack
page read and write
1B044D9A000
heap
page read and write
25E14476000
heap
page read and write
BC092FE000
stack
page read and write
21AE9808000
trusted library allocation
page read and write
1B049D20000
unkown
page read and write
1C7D937A000
trusted library allocation
page read and write
21AE95F0000
trusted library allocation
page read and write
23576EC0000
heap
page read and write
25E1447C000
heap
page read and write
1C7D936C000
trusted library allocation
page read and write
1B044BC5000
heap
page read and write
21AE4079000
heap
page read and write
21AE94E0000
trusted library allocation
page read and write
1C7D8B02000
heap
page read and write
BC0927F000
stack
page read and write
723517D000
stack
page read and write
1B04B219000
unkown
page read and write
21AE4E00000
trusted library allocation
page read and write
1B049F30000
unkown
page read and write
21AE96F7000
heap
page read and write
1B044C23000
heap
page read and write
21AE4126000
heap
page read and write
1B044A02000
heap
page read and write
2357706E000
heap
page read and write
1B04B148000
unkown
page read and write
BD6F58B000
stack
page read and write
1B04B1DD000
unkown
page read and write
BD6FBFE000
stack
page read and write
BC08B78000
stack
page read and write
BC0917F000
stack
page read and write
16655802000
heap
page read and write
1C7D8A00000
heap
page read and write
21AE403D000
heap
page read and write
1B044B02000
heap
page read and write
25E14467000
heap
page read and write
1B044D77000
heap
page read and write
16655E02000
trusted library allocation
page read and write
7234CFF000
stack
page read and write
1CC31430000
heap
page read and write
16655620000
heap
page read and write
23577076000
heap
page read and write
4957C7E000
stack
page read and write
A4A6C7F000
stack
page read and write
1B049D60000
unkown
page read and write
1B04B000000
unkown
page read and write
25E14457000
heap
page read and write
25E1444E000
heap
page read and write
1B044243000
heap
page read and write
25E14440000
heap
page read and write
1B0440D0000
heap
page read and write
25E1446E000
heap
page read and write
32C52FA000
stack
page read and write
1745D813000
heap
page read and write
23577113000
heap
page read and write
72351FB000
stack
page read and write
166557F0000
trusted library allocation
page read and write
1745E132000
heap
page read and write
25E14468000
heap
page read and write
1B04B14D000
unkown
page read and write
23577029000
heap
page read and write
1B04B221000
unkown
page read and write
25E14432000
heap
page read and write
21AE9706000
heap
page read and write
BD6FCFD000
stack
page read and write
32C4A7B000
stack
page read and write
21AE9830000
trusted library allocation
page read and write
21AE5460000
trusted library allocation
page read and write
21AE4013000
heap
page read and write
21AE972C000
heap
page read and write
1B044D49000
heap
page read and write
1B04427C000
heap
page read and write
723491B000
stack
page read and write
21AE5100000
trusted library section
page readonly
237AD25B000
heap
page read and write
1B04B053000
unkown
page read and write
BC090FF000
stack
page read and write
A4A6A7F000
stack
page read and write
1B0440C0000
heap
page read and write
1B049A20000
unkown
page read and write
21AE980A000
trusted library allocation
page read and write
21AE9713000
heap
page read and write
1C7D8AF2000
heap
page read and write
1B049B60000
unkown
page read and write
1B049DE0000
unkown
page read and write
21AE96E1000
heap
page read and write
23577000000
heap
page read and write
21AE970B000
heap
page read and write
1B04B121000
unkown
page read and write
23576EB0000
heap
page read and write
21AE9950000
trusted library allocation
page read and write
BC0870B000
stack
page read and write
1B049BE0000
unkown
page read and write
1B04B1D4000
unkown
page read and write
25E1446A000
heap
page read and write
1B04B32A000
unkown
page read and write
495787C000
stack
page read and write
25E14446000
heap
page read and write
21AE4918000
heap
page read and write
1745D8CA000
heap
page read and write
21AE9806000
trusted library allocation
page read and write
21AE9950000
remote allocation
page read and write
1C7D9800000
unkown
page read and write
1B04B23A000
unkown
page read and write
BD6FE7D000
stack
page read and write
21AE404E000
heap
page read and write
25E1448C000
heap
page read and write
25E1443D000
heap
page read and write
1B045688000
unkown
page read and write
25E1445A000
heap
page read and write
21AE4959000
heap
page read and write
21AE499A000
heap
page read and write
4957B7B000
stack
page read and write
32C5C7D000
unkown
page read and write
1B044DB4000
heap
page read and write
1CC31613000
heap
page read and write
1B044A15000
heap
page read and write
21AE4900000
heap
page read and write
1B0457C0000
unkown
page readonly
1B044B1D000
heap
page read and write
BD6FF7D000
stack
page read and write
1B044C0A000
heap
page read and write
1665583E000
heap
page read and write
32C5B7E000
unkown
page read and write
72353FE000
stack
page read and write
23577102000
heap
page read and write
21AE9707000
heap
page read and write
1B04B1AB000
unkown
page read and write
1B049A30000
unkown
page read and write
1B04B185000
unkown
page read and write
1665587B000
heap
page read and write
BC0957C000
stack
page read and write
25E1443B000
heap
page read and write
723507F000
stack
page read and write
21AE980E000
trusted library allocation
page read and write
16655857000
heap
page read and write
21AE50E0000
trusted library section
page readonly
4957E7B000
stack
page read and write
237AD255000
heap
page read and write
21AE971D000
heap
page read and write
21AE9711000
heap
page read and write
21AE9600000
heap
page read and write
21AE9493000
trusted library allocation
page read and write
21AE9711000
heap
page read and write
1B045400000
unkown
page read and write
5D986FF000
stack
page read and write
1B04B117000
unkown
page read and write
21AE4918000
heap
page read and write
1B04B15B000
unkown
page read and write
21AE9A80000
trusted library allocation
page read and write
1B044C1B000
heap
page read and write
21AE9834000
trusted library allocation
page read and write
1B04428B000
heap
page read and write
1B04425A000
heap
page read and write
1B04B198000
unkown
page read and write
1B045698000
unkown
page read and write
21AE971E000
heap
page read and write
32C5A7E000
unkown
page read and write
1B044DD4000
heap
page read and write
BC0967F000
stack
page read and write
25E1447B000
heap
page read and write
21AE47E3000
trusted library allocation
page read and write
1B045690000
unkown
page read and write
BC08A7F000
stack
page read and write
237AD200000
heap
page read and write
21AE96A5000
heap
page read and write
1C7D8ACA000
heap
page read and write
1B04B354000
unkown
page read and write
BC08F7A000
stack
page read and write
1B044B36000
heap
page read and write
1C7D8AC4000
heap
page read and write
25E14461000
heap
page read and write
21AE971B000
heap
page read and write
21AEA000000
heap
page read and write
1B049CB0000
unkown
page read and write
1C7D8A3C000
heap
page read and write
21AE9800000
trusted library allocation
page read and write
1B044B33000
heap
page read and write
1CC31600000
heap
page read and write
1C7D8B13000
heap
page read and write
237AD229000
heap
page read and write
1B044290000
heap
page read and write
1CC31629000
heap
page read and write
1B044C00000
heap
page read and write
21AE47E0000
trusted library allocation
page read and write
1B049D30000
unkown
page read and write
21AE3FC0000
trusted library allocation
page read and write
21AE963F000
heap
page read and write
1745D8B9000
heap
page read and write
1CC3165C000
heap
page read and write
1CC31640000
heap
page read and write
5D984FE000
stack
page read and write
33517C000
stack
page read and write
1B044BCC000
heap
page read and write
1B044270000
heap
page read and write
1B044D8C000
heap
page read and write
DB8807E000
stack
page read and write
1B045680000
unkown
page read and write
1B049D10000
unkown
page read and write
21AE50F0000
trusted library section
page readonly
21AE5110000
trusted library section
page readonly
A4A6D7F000
stack
page read and write
25E14A80000
trusted library allocation
page read and write
1C7D8840000
heap
page read and write
1B04B1C6000
unkown
page read and write
32C4BFF000
stack
page read and write
A4A697D000
stack
page read and write
21AE40FE000
heap
page read and write
23577802000
trusted library allocation
page read and write
1B044DF5000
heap
page read and write
21AE49DE000
heap
page read and write
5D97FCE000
stack
page read and write
BD6F97E000
stack
page read and write
32C5875000
unkown
page read and write
1B044DC9000
heap
page read and write
32C4D7F000
stack
page read and write
32C577B000
unkown
page read and write
1B04B167000
unkown
page read and write
21AE9613000
heap
page read and write
25E14478000
heap
page read and write
1CC31702000
heap
page read and write
237AD276000
heap
page read and write
1CC313D0000
heap
page read and write
1B049DB0000
unkown
page read and write
21AE964C000
heap
page read and write
21AE3F20000
heap
page read and write
25E14429000
heap
page read and write
25E14470000
heap
page read and write
1B04B12D000
unkown
page read and write
21AE9A70000
trusted library allocation
page read and write
25E14C02000
trusted library allocation
page read and write
21AE96B4000
heap
page read and write
21AE9950000
remote allocation
page read and write
335377000
stack
page read and write
21AE971E000
heap
page read and write
1CC313C0000
heap
page read and write
1C7D931F000
trusted library allocation
page read and write
237AD302000
heap
page read and write
1B04B288000
unkown
page read and write
72355FF000
stack
page read and write
21AE408B000
heap
page read and write
1C7D8AB9000
heap
page read and write
32C4E7C000
stack
page read and write
21AE9717000
heap
page read and write
21AE4FE0000
trusted library allocation
page read and write
BC0907B000
stack
page read and write
21AE4058000
heap
page read and write
A4A6B7E000
stack
page read and write
21AE961F000
heap
page read and write
1745D5F0000
heap
page read and write
1B044C02000
heap
page read and write
21AE98C0000
trusted library allocation
page read and write
21AE9807000
trusted library allocation
page read and write
1745D5E0000
heap
page read and write
21AE9910000
trusted library allocation
page read and write
1B044D00000
heap
page read and write
21AE3F30000
heap
page read and write
21AE4800000
heap
page read and write
23577013000
heap
page read and write
16655868000
heap
page read and write
21AE971B000
heap
page read and write
1CC31BC0000
remote allocation
page read and write
21AE9708000
heap
page read and write
25E1447E000
heap
page read and write
1C7D8A29000
heap
page read and write
21AE9950000
remote allocation
page read and write
21AE3F90000
heap
page read and write
21AE9708000
heap
page read and write
A4A667F000
stack
page read and write
DB87DCE000
stack
page read and write
21AE9800000
trusted library allocation
page read and write
1B04B300000
unkown
page read and write
1B04B1A5000
unkown
page read and write
21AE9460000
trusted library allocation
page read and write
237AD1E0000
heap
page read and write
1745D913000
heap
page read and write
32C537E000
unkown
page read and write
25E14459000
heap
page read and write
32C4FFB000
stack
page read and write
1B044180000
trusted library allocation
page read and write
32C54FE000
unkown
page read and write
21AE9702000
heap
page read and write
1B044290000
heap
page read and write
21AE9820000
trusted library allocation
page read and write
32C53FE000
unkown
page read and write
1C7D8AB0000
heap
page read and write
1745D650000
heap
page read and write
1B044D7E000
heap
page read and write
21AE4958000
heap
page read and write
32C567D000
unkown
page read and write
21AE9930000
trusted library allocation
page read and write
21AE4102000
heap
page read and write
21AE96E6000
heap
page read and write
23577083000
heap
page read and write
21AE971B000
heap
page read and write
1B044243000
heap
page read and write
21AE47F0000
trusted library allocation
page read and write
1B044D45000
heap
page read and write
25E14465000
heap
page read and write
16655913000
heap
page read and write
BC0937F000
stack
page read and write
5D9827E000
stack
page read and write
16655900000
heap
page read and write
1B044313000
heap
page read and write
1B045790000
unkown
page readonly
23577049000
heap
page read and write
21AE4076000
heap
page read and write
21AE96FF000
heap
page read and write
21AE4029000
heap
page read and write
1B049D80000
unkown
page read and write
2357702C000
heap
page read and write
21AE408F000
heap
page read and write
1745E002000
heap
page read and write
21AE9490000
trusted library allocation
page read and write
1B044C58000
heap
page read and write
1C7D931D000
trusted library allocation
page read and write
1745D750000
trusted library allocation
page read and write
5D9837B000
stack
page read and write
166555B0000
heap
page read and write
2357704B000
heap
page read and write
21AE4918000
heap
page read and write
21AE970A000
heap
page read and write
237AD202000
heap
page read and write
DB881FE000
stack
page read and write
1745D8E2000
heap
page read and write
21AE9665000
heap
page read and write
237AD23D000
heap
page read and write
BD6FAFE000
stack
page read and write
21AE40BC000
heap
page read and write
25E14413000
heap
page read and write
1B0457B0000
unkown
page readonly
21AE9704000
heap
page read and write
16655902000
heap
page read and write
DB883FE000
stack
page read and write
21AE94D0000
trusted library allocation
page read and write
21AE96A1000
heap
page read and write
BD6FA7E000
stack
page read and write
2357703C000
heap
page read and write
1B044BDE000
heap
page read and write
1B044A00000
heap
page read and write
25E14474000
heap
page read and write
25E14400000
heap
page read and write
21AE406F000
heap
page read and write
25E1445C000
heap
page read and write
21AE9960000
trusted library allocation
page read and write
1B04B279000
unkown
page read and write
1B04B002000
unkown
page read and write
1745D8C8000
heap
page read and write
25E14475000
heap
page read and write
1B044213000
heap
page read and write
BC08C7B000
stack
page read and write
1B044227000
heap
page read and write
A4A610C000
stack
page read and write
4957D7E000
stack
page read and write
335578000
stack
page read and write
BC0947A000
stack
page read and write
1B0456A0000
unkown
page read and write
21AE970D000
heap
page read and write
25E14462000
heap
page read and write
21AE9801000
trusted library allocation
page read and write
1B04B200000
unkown
page read and write
1C7D936F000
trusted library allocation
page read and write
25E14458000
heap
page read and write
21AE4918000
heap
page read and write
1B0499A0000
unkown
page read and write
1C7D88B0000
heap
page read and write
1C7D8AB4000
heap
page read and write
1B044286000
heap
page read and write
16655880000
heap
page read and write
1745D842000
heap
page read and write
21AE970E000
heap
page read and write
25E14502000
heap
page read and write
1B04B18F000
unkown
page read and write
1CC31635000
heap
page read and write
25E14442000
heap
page read and write
1B0499B0000
unkown
page read and write
21AE9900000
trusted library allocation
page read and write
1B044BC2000
heap
page read and write
237AD940000
trusted library allocation
page read and write
1B044D61000
heap
page read and write
1B044C5A000
heap
page read and write
21AE9708000
heap
page read and write
1B04B132000
unkown
page read and write
21AE40B5000
heap
page read and write
21AE49DD000
heap
page read and write
1C7D8A7A000
heap
page read and write
1B04B1FE000
unkown
page read and write
32C4B7A000
stack
page read and write
BC08E7E000
stack
page read and write
25E142C0000
heap
page read and write
1C7D9327000
trusted library allocation
page read and write
1C7D938F000
trusted library allocation
page read and write
237ADA02000
trusted library allocation
page read and write
25E1447A000
heap
page read and write
21AE9706000
heap
page read and write
25E14445000
heap
page read and write
1C7D9300000
trusted library allocation
page read and write
1B044277000
heap
page read and write
237AD213000
heap
page read and write
1B04B1E2000
unkown
page read and write
1C7D89B0000
trusted library allocation
page read and write
21AE4B81000
trusted library allocation
page read and write
21AE4000000
heap
page read and write
1B044B00000
heap
page read and write
1B0449D1000
unkown
page read and write
1B04B100000
unkown
page read and write
25E14441000
heap
page read and write
237AD264000
heap
page read and write
21AE962C000
heap
page read and write
1B044BAF000
heap
page read and write
21AE9920000
trusted library allocation
page read and write
237AD313000
heap
page read and write
5D987FF000
stack
page read and write
1B044B1D000
heap
page read and write
1B044256000
heap
page read and write
1B0457A0000
unkown
page readonly
1B045780000
unkown
page readonly
1B044160000
trusted library allocation
page read and write
334DCE000
stack
page read and write
21AE9706000
heap
page read and write
25E142B0000
heap
page read and write
25E1445F000
heap
page read and write
1CC31B90000
trusted library allocation
page read and write
21AE9713000
heap
page read and write
1C7D8A6F000
heap
page read and write
16655864000
heap
page read and write
1C7D9060000
unkown
page write copy
1B044DDF000
heap
page read and write
1B049DA0000
unkown
page read and write
5D9847B000
stack
page read and write
25E14463000
heap
page read and write
BD6FD7F000
stack
page read and write
1B04B037000
unkown
page read and write
There are 556 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://www.google.com/
https://store.google.com/DE?utm_source=hp_header&utm_medium=google_ooo&utm_campaign=GS100042&hl=de-DE
https://www.google.com/intl/de/gmail/about/#
https://about.google/stories/timelapse-planetary-changes/
https://www.google.de/imghp?hl=de&ogbl
https://about.google/products/
https://www.youtube.com/embed/by-kTJ0DOLc?rel=0&vq=hd720&start=0&cc_load_policy=1&playsinline=1&origin=https%3A%2F%2Fabout.google&enablejsapi=1&widgetid=1
https://accounts.google.com/signin/v2/identifier?hl=de&passive=true&continue=https%3A%2F%2Fwww.google.com%2F&ec=GAZAmgQ&flowName=GlifWebSignIn&flowEntry=ServiceLogin