Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\2b94de4f-9bbd-4e62-9632-98c1e94a8727.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\33eca64c-fb6b-4732-87e7-79ab08091b75.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\3c27e511-1dcc-43ce-81a7-7ac8ba9b8c8e.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\523449f1-6639-4e45-8736-c141a01c472b.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\9e12fdc3-ea8c-43a7-8104-b8d7d7de6757.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
|
data
|
modified
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\0be36d77-acb2-4556-957d-c84f16ca19fe.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3cc0bcd6-5f8f-4729-8fa5-d976f8523ee7.tmp
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\3fcac083-ce72-4ac1-b7ad-8012a9225c28.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\4375f01c-ae30-4134-a800-6ff93bc60c95.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\59d43e05-b094-474e-aa07-26f958702850.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5eef5b45-b73a-4525-9491-86ded1eb053b.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\6e5d74e9-54d6-4ee3-9120-f3bf36628a93.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\8baa0ac2-0770-4d3b-a14f-5ed2a90629e3.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_1\_metadata\computed_hashes.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\7b539bde8ca0807396a791d6ee4db1189d0e5380\98905483-3512-4dec-a259-e1ada8947b62\556be1bce36d62b7_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\7b539bde8ca0807396a791d6ee4db1189d0e5380\98905483-3512-4dec-a259-e1ada8947b62\index
|
ISO-8859 text, with no line terminators, with escape sequences
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\7b539bde8ca0807396a791d6ee4db1189d0e5380\98905483-3512-4dec-a259-e1ada8947b62\index-dir\temp-index
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\7b539bde8ca0807396a791d6ee4db1189d0e5380\98905483-3512-4dec-a259-e1ada8947b62\index-dir\the-real-index
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\7b539bde8ca0807396a791d6ee4db1189d0e5380\index.txt
(copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\7b539bde8ca0807396a791d6ee4db1189d0e5380\index.txt.tmp
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\000001.dbtmp
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\CURRENT (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\MANIFEST-000001
|
PGP\011Secret Key -
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\2cc80dabc69f58b6_0
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\2cc80dabc69f58b6_1
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index
|
ISO-8859 text, with no line terminators, with escape sequences
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\temp-index
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\the-real-index (copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\072f0b49-0662-4d62-bb32-08856aca6f04.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent
State (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\edf13c28-3f6c-43e8-a91e-8102917b9727.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent
State (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\f727a1b8-3262-4e08-97df-63d91b7c2839.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_nmmhkkegccagdldgiimedpiccmgmieda\Chrome
Web Store Payments.ico (copy)
|
MS Windows icon resource - 13 icons, 8x8, 32 bits/pixel, 10x10, 32 bits/pixel
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_nmmhkkegccagdldgiimedpiccmgmieda\Chrome
Web Store Payments.ico.md5
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_nmmhkkegccagdldgiimedpiccmgmieda\ab59c196-757b-48bc-abcd-e9108dc6a13d.tmp
|
MS Windows icon resource - 13 icons, 8x8, 32 bits/pixel, 10x10, 32 bits/pixel
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a7ebc0c7-6cda-4205-abf0-aacc21c6fd56.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\abc76fb7-3756-4e1c-9838-b513802a525f.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\bd39436f-5bc5-46de-9f71-3d99fb0c9dd0.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d8450db0-5a6f-4c45-84ba-eff45e4ddf5b.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\e88bbe26-09d3-40c1-99bc-7e33d2ed9a25.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ec0a67f9-71cf-4368-b143-64003f7a2c47.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\ec88bed7-1242-4bc2-b50f-7e9889450db1.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\f0034316-3292-4f79-a6a9-12e3cb06c2c5.tmp
|
UTF-8 Unicode text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\aaa39430-1210-48da-915c-dee34e6f7157.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\afa0d115-6f54-4ae3-ac3a-1516acb8d01c.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\b64fe383-e677-442c-9790-1bead984b3fd.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\be78e8cc-c0a5-4210-9b6e-b9a446bb5867.tmp
|
SysEx File -
|
dropped
|
||
C:\Users\user\AppData\Local\Google\Chrome\User Data\d312eb71-cac4-40dc-9d0a-6e6531127fde.tmp
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_pnacl_json
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_for_eh_o
|
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_crtbegin_o
|
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_crtend_o
|
ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV), not stripped
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_ld_nexe
|
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=7511538a3a6a0b862c772eace49075ed1bbe2377,
stripped
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_libcrt_platform_a
|
current ar archive
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_libgcc_a
|
current ar archive
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_shim_a
|
current ar archive
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_libpnacl_irt_shim_dummy_a
|
current ar archive
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_llc_nexe
|
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=309d6d3d463e6b1b0690f39eb226b1e4c469b2ce,
stripped
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\_platform_specific\x86_64\pnacl_public_x86_64_pnacl_sz_nexe
|
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=4b15de4ab227d5e46213978b8518d53c53ce1db9,
stripped
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\4212_1714627765\manifest.json
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\6def0d19-3ad6-42ac-b2ea-8479828cfa84.tmp
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\7ab263a1-9cc0-4892-ad6e-a9d2fd3c1fa3.tmp
|
very short file (no magic)
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\c353d72b-7c0d-4c8f-b7d9-11b230aebd91.tmp
|
Google Chrome extension, version 3
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\cea2846e-1c0a-47c9-bbca-001636f84f28.tmp
|
Google Chrome extension, version 3
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\bg\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\ca\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\cs\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\da\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\de\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\el\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\en\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\en_GB\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\es\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\es_419\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\et\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\fi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\fil\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\fr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\hi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\hr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\hu\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\id\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\it\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\ja\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\ko\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\lt\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\lv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\nb\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\nl\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\pl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\pt_BR\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\pt_PT\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\ro\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\ru\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\sk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\sl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\sr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\sv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\th\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\tr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\uk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\vi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\zh_CN\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_locales\zh_TW\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\_metadata\verified_contents.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\craw_background.js
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\craw_window.js
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\css\craw_window.css
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\html\craw_window.html
|
HTML document, ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\flapper.gif
|
GIF image data, version 89a, 30 x 30
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\icon_128.png
|
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\icon_16.png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\topbar_floating_button.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\topbar_floating_button_close.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\topbar_floating_button_hover.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\topbar_floating_button_maximize.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\images\topbar_floating_button_pressed.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\CRX_INSTALL\manifest.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_1704560113\cea2846e-1c0a-47c9-bbca-001636f84f28.tmp
|
Google Chrome extension, version 3
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\bg\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\ca\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\cs\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\da\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\de\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\el\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\en\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\en_GB\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\es\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\es_419\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\et\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\fi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\fil\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\fr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\hi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\hr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\hu\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\id\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\it\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\ja\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\ko\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\lt\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\lv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\nb\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\nl\messages.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\pl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\pt_BR\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\pt_PT\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\ro\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\ru\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\sk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\sl\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\sr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\sv\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\th\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\tr\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\uk\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\vi\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\zh_CN\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_locales\zh_TW\messages.json
|
UTF-8 Unicode text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\_metadata\verified_contents.json
|
ASCII text, with very long lines, with no line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\craw_background.js
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\craw_window.js
|
ASCII text, with very long lines
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\css\craw_window.css
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\html\craw_window.html
|
HTML document, ASCII text
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\flapper.gif
|
GIF image data, version 89a, 30 x 30
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\icon_128.png
|
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\icon_16.png
|
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\topbar_floating_button.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\topbar_floating_button_close.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\topbar_floating_button_hover.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\topbar_floating_button_maximize.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\images\topbar_floating_button_pressed.png
|
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\CRX_INSTALL\manifest.json
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\scoped_dir4212_280510944\c353d72b-7c0d-4c8f-b7d9-11b230aebd91.tmp
|
Google Chrome extension, version 3
|
dropped
|
There are 185 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1604,10036612460066641009,12631264847609634138,131072
--lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1920 /prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
C:\Program Files\Google\Chrome\Application\chrome.exe" "https://na4.documents.adobe.com/public/esign?tsid=CBFCIBAA3AAABLblqZhCIlJU6Feuc0hETV6RYBr3p6zc-EYkicTEt2WarWwXEr20g_PRd3W5v0_Jmux1_Xb97kQ7gSviGWdMDmKvMNxqk&
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://na4.documents.adobe.com/public/esign?tsid=CBFCIBAA3AAABLblqZhCIlJU6Feuc0hETV6RYBr3p6zc-EYkicTEt2WarWwXEr20g_PRd3W5v0_Jmux1_Xb97kQ7gSviGWdMDmKvMNxqk&
|
|||
https://dns.google
|
unknown
|
||
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
|
unknown
|
||
https://www.google.com/intl/en-US/chrome/blank.html
|
unknown
|
||
https://ogs.google.com
|
unknown
|
||
https://www.google.com/images/cleardot.gif
|
unknown
|
||
https://cm.g.doubleclick.net
|
unknown
|
||
https://play.google.com
|
unknown
|
||
https://payments.google.com/payments/v4/js/integrator.js
|
unknown
|
||
https://chromium.googlesource.com/a/native_client/pnacl-llvm.git
|
unknown
|
||
https://googleads.g.doubleclick.net
|
unknown
|
||
https://sandbox.google.com/payments/v4/js/integrator.js
|
unknown
|
||
https://www.google.com/images/x2.gif
|
unknown
|
||
https://accounts.google.com/MergeSession
|
unknown
|
||
http://llvm.org/):
|
unknown
|
||
https://www.google.com
|
unknown
|
||
https://www.google.com/images/dot2.gif
|
unknown
|
||
https://9212252.fls.doubleclick.net/activityi;dc_pre=CKir5NP9vfkCFS0jBgAdK3MMeg;src=9212252;type=invmedia;cat=stock00;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;ord=1;num=6649563850234.023?
|
|||
https://bit.ly/wb-precache
|
unknown
|
||
https://code.google.com/p/nativeclient/issues/entry%s:
|
unknown
|
||
https://code.google.com/p/nativeclient/issues/entry
|
unknown
|
||
https://www.google.de
|
unknown
|
||
https://accounts.google.com
|
unknown
|
||
https://clients2.googleusercontent.com
|
unknown
|
||
https://apis.google.com
|
unknown
|
||
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
|
unknown
|
||
https://www.google.com/
|
unknown
|
||
https://www-googleapis-staging.sandbox.google.com
|
unknown
|
||
https://9212252.fls.doubleclick.net/activityi;dc_pre=CKWj5NP9vfkCFUe81Qod8gIPgA;src=9212252;type=invmedia;cat=japan000;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;ord=1366023289772.076?
|
|||
https://chromium.googlesource.com/a/native_client/pnacl-clang.git
|
unknown
|
||
https://clients2.google.com
|
unknown
|
||
https://clients2.google.com/service/update2/crx
|
unknown
|
There are 21 hidden URLs, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
192.168.2.1
|
unknown
|
unknown
|
||
204.79.197.200
|
unknown
|
United States
|
||
91.228.74.166
|
unknown
|
United Kingdom
|
||
108.139.229.63
|
unknown
|
United States
|
||
172.217.168.40
|
unknown
|
United States
|
||
54.72.250.99
|
unknown
|
United States
|
||
157.240.17.35
|
unknown
|
United States
|
||
8.8.8.8
|
unknown
|
United States
|
||
185.64.190.80
|
unknown
|
United Kingdom
|
||
15.188.95.229
|
unknown
|
United States
|
||
34.255.225.203
|
unknown
|
United States
|
||
104.16.148.64
|
unknown
|
United States
|
||
202.241.208.57
|
unknown
|
Japan
|
||
142.250.203.98
|
unknown
|
United States
|
||
34.250.172.3
|
unknown
|
United States
|
||
108.139.210.94
|
unknown
|
United States
|
||
216.58.215.226
|
unknown
|
United States
|
||
34.225.63.196
|
unknown
|
United States
|
||
52.49.231.213
|
unknown
|
United States
|
||
172.217.168.14
|
unknown
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
18.65.64.22
|
unknown
|
United States
|
||
185.199.108.153
|
unknown
|
Netherlands
|
||
35.244.174.68
|
unknown
|
United States
|
||
18.65.64.21
|
unknown
|
United States
|
||
52.223.40.198
|
unknown
|
United States
|
||
15.236.176.210
|
unknown
|
United States
|
||
127.0.0.1
|
unknown
|
unknown
|
||
54.154.238.203
|
unknown
|
United States
|
||
35.244.159.8
|
unknown
|
United States
|
||
185.94.180.126
|
unknown
|
Netherlands
|
||
172.64.146.158
|
unknown
|
United States
|
||
37.252.172.123
|
unknown
|
European Union
|
||
18.65.82.67
|
unknown
|
United States
|
||
54.77.179.162
|
unknown
|
United States
|
||
52.17.75.86
|
unknown
|
United States
|
||
108.139.210.107
|
unknown
|
United States
|
||
34.111.234.236
|
unknown
|
United States
|
||
142.250.203.109
|
unknown
|
United States
|
||
142.250.203.100
|
unknown
|
United States
|
||
172.217.168.70
|
unknown
|
United States
|
||
18.65.75.43
|
unknown
|
United States
|
||
172.217.168.35
|
unknown
|
United States
|
||
104.17.27.92
|
unknown
|
United States
|
||
108.139.210.118
|
unknown
|
United States
|
||
18.203.174.165
|
unknown
|
United States
|
There are 36 hidden IPs, click here to show them.
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
|
S-1-5-21-3853321935-2125563209-4053062332-1002
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
ahfgeienlihckogmohjhadlkjgocpleb
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
gdaefkejpgkiemlaofpalmlakkmbjdnl
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
gfdkimpbcpahaombhbimeihdjnejgicl
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
kmendfapggjehodndflmmgagdbamhnfd
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
mfehgcgbbipciphmccgaenjidiccnmng
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
mhjfbmdgcfjbbpaeojofohoefgiehjai
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
neajdppkdcdipfabeoofebfddakdcjhd
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nkeimhogjdpnpccoofpliimaahmaaome
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
pkedcjkdefgpdelpbcmbmeomcjbeemfm
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
prefs.preference_reset_time
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
gfdkimpbcpahaombhbimeihdjnejgicl
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
||
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
|
dr
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
software_reporter.reporting
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
module_blacklist_cache_md5_digest
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
media.storage_id_salt
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
google.services.last_account_id
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
google.services.account_id
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
software_reporter.prompt_seed
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.last_triggered_for_homepage
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
default_search_provider_data.template_url_data
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
safebrowsing.incidents_sent
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
pinned_tabs
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
search_provider_overrides
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.last_triggered_for_default_search
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
prefs.preference_reset_time
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
google.services.last_username
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
session.startup_urls
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
session.restore_on_startup
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
software_reporter.prompt_version
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.last_triggered_for_startup_urls
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.prompt_wave
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
homepage
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
homepage_is_newtabpage
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
browser.show_home_button
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
|
user_experience_metrics.stability.exited_cleanly
|
||
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
|
lastrun
|
||
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
|
lastrun
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
|
S-1-5-21-3853321935-2125563209-4053062332-1002
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
|
GlobalAssocChangedCounter
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
|
Blob
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
|
Blob
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
There are 44 hidden registries, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
E3F57E000
|
stack
|
page read and write
|
||
1BD3E25A000
|
heap
|
page read and write
|
||
19DA4640000
|
heap
|
page read and write
|
||
271CF340000
|
heap
|
page read and write
|
||
2995DFF000
|
stack
|
page read and write
|
||
23AE07D000
|
stack
|
page read and write
|
||
271D4B60000
|
trusted library allocation
|
page read and write
|
||
271D4D18000
|
heap
|
page read and write
|
||
1F257FF0000
|
remote allocation
|
page read and write
|
||
1FD62200000
|
heap
|
page read and write
|
||
1BA44267000
|
heap
|
page read and write
|
||
1BA44230000
|
heap
|
page read and write
|
||
E3F47E000
|
stack
|
page read and write
|
||
1BA44275000
|
heap
|
page read and write
|
||
1FD62229000
|
heap
|
page read and write
|
||
1BD3E266000
|
heap
|
page read and write
|
||
1F257E60000
|
heap
|
page read and write
|
||
1BA44231000
|
heap
|
page read and write
|
||
14DEE0A0000
|
heap
|
page read and write
|
||
299607C000
|
stack
|
page read and write
|
||
1BA44229000
|
heap
|
page read and write
|
||
1BA44278000
|
heap
|
page read and write
|
||
29961FF000
|
stack
|
page read and write
|
||
7CB427B000
|
stack
|
page read and write
|
||
A35357E000
|
stack
|
page read and write
|
||
271CFD59000
|
heap
|
page read and write
|
||
A35377E000
|
stack
|
page read and write
|
||
A3538FB000
|
stack
|
page read and write
|
||
1F257FF0000
|
remote allocation
|
page read and write
|
||
1F257FC0000
|
trusted library allocation
|
page read and write
|
||
1BA44247000
|
heap
|
page read and write
|
||
7CB44FE000
|
stack
|
page read and write
|
||
23ADDFF000
|
stack
|
page read and write
|
||
271D4D0C000
|
heap
|
page read and write
|
||
14DEE0B0000
|
heap
|
page read and write
|
||
1F25803C000
|
heap
|
page read and write
|
||
1BA44249000
|
heap
|
page read and write
|
||
11D4FFE000
|
stack
|
page read and write
|
||
2995F7C000
|
stack
|
page read and write
|
||
1F258002000
|
heap
|
page read and write
|
||
1BA4424B000
|
heap
|
page read and write
|
||
E3F77F000
|
stack
|
page read and write
|
||
14DEE229000
|
heap
|
page read and write
|
||
23AE17D000
|
stack
|
page read and write
|
||
19DA4702000
|
heap
|
page read and write
|
||
11D4DFE000
|
stack
|
page read and write
|
||
271D4B70000
|
remote allocation
|
page read and write
|
||
19DA4700000
|
heap
|
page read and write
|
||
1BA441D0000
|
heap
|
page read and write
|
||
271D4A50000
|
trusted library allocation
|
page read and write
|
||
271D4D08000
|
heap
|
page read and write
|
||
1BA4424E000
|
heap
|
page read and write
|
||
7CB467E000
|
stack
|
page read and write
|
||
1BA44262000
|
heap
|
page read and write
|
||
1FD62255000
|
heap
|
page read and write
|
||
A3539FE000
|
stack
|
page read and write
|
||
271D4D04000
|
heap
|
page read and write
|
||
271D4B70000
|
trusted library allocation
|
page read and write
|
||
1BA44200000
|
heap
|
page read and write
|
||
1FD62202000
|
heap
|
page read and write
|
||
1BD3E264000
|
heap
|
page read and write
|
||
19DA4600000
|
heap
|
page read and write
|
||
A353B7E000
|
stack
|
page read and write
|
||
A35397E000
|
stack
|
page read and write
|
||
271D4D13000
|
heap
|
page read and write
|
||
E3F2FE000
|
stack
|
page read and write
|
||
1BA4423D000
|
heap
|
page read and write
|
||
19DA4613000
|
heap
|
page read and write
|
||
1BD3E302000
|
heap
|
page read and write
|
||
1BA4426A000
|
heap
|
page read and write
|
||
76DDDFE000
|
stack
|
page read and write
|
||
A3536FF000
|
stack
|
page read and write
|
||
1BA44239000
|
heap
|
page read and write
|
||
7CB3E7B000
|
stack
|
page read and write
|
||
23AD7CB000
|
stack
|
page read and write
|
||
1BA4422D000
|
heap
|
page read and write
|
||
11D54FF000
|
stack
|
page read and write
|
||
1BA44250000
|
heap
|
page read and write
|
||
1BA44A02000
|
trusted library allocation
|
page read and write
|
||
1BA44245000
|
heap
|
page read and write
|
||
1F258029000
|
heap
|
page read and write
|
||
1BD3E265000
|
heap
|
page read and write
|
||
271D4A11000
|
trusted library allocation
|
page read and write
|
||
1BA44302000
|
heap
|
page read and write
|
||
76DDCFE000
|
stack
|
page read and write
|
||
1BA44256000
|
heap
|
page read and write
|
||
19DA4668000
|
heap
|
page read and write
|
||
1F257FF0000
|
remote allocation
|
page read and write
|
||
271CF350000
|
heap
|
page read and write
|
||
1FD62030000
|
heap
|
page read and write
|
||
1FD6223C000
|
heap
|
page read and write
|
||
271D4A31000
|
trusted library allocation
|
page read and write
|
||
76DDBFB000
|
stack
|
page read and write
|
||
271D4A1E000
|
trusted library allocation
|
page read and write
|
||
19DA44C0000
|
heap
|
page read and write
|
||
23ADCFE000
|
stack
|
page read and write
|
||
2995B7F000
|
stack
|
page read and write
|
||
271D4A18000
|
trusted library allocation
|
page read and write
|
||
1BA44240000
|
heap
|
page read and write
|
||
1BA4426B000
|
heap
|
page read and write
|
||
271D4EE0000
|
trusted library allocation
|
page read and write
|
||
271D4A10000
|
trusted library allocation
|
page read and write
|
||
11D55FF000
|
stack
|
page read and write
|
||
271D4A54000
|
trusted library allocation
|
page read and write
|
||
1BD3E23D000
|
heap
|
page read and write
|
||
11D51FE000
|
stack
|
page read and write
|
||
19DA44B0000
|
heap
|
page read and write
|
||
1BA44160000
|
heap
|
page read and write
|
||
271D4D04000
|
heap
|
page read and write
|
||
1BD3E26F000
|
heap
|
page read and write
|
||
271CFD18000
|
heap
|
page read and write
|
||
14DEE110000
|
heap
|
page read and write
|
||
A353277000
|
stack
|
page read and write
|
||
23AE1FE000
|
stack
|
page read and write
|
||
1FD61FD0000
|
heap
|
page read and write
|
||
271D4D08000
|
heap
|
page read and write
|
||
1BA44248000
|
heap
|
page read and write
|
||
E3F27E000
|
stack
|
page read and write
|
||
1BA4423A000
|
heap
|
page read and write
|
||
76DDAFB000
|
stack
|
page read and write
|
||
271D4A40000
|
trusted library allocation
|
page read and write
|
||
271CFD18000
|
heap
|
page read and write
|
||
1BD3E213000
|
heap
|
page read and write
|
||
1BA44242000
|
heap
|
page read and write
|
||
1BA44261000
|
heap
|
page read and write
|
||
11D48EC000
|
stack
|
page read and write
|
||
A35337A000
|
stack
|
page read and write
|
||
23ADF7F000
|
stack
|
page read and write
|
||
7CB45FE000
|
stack
|
page read and write
|
||
1FD62213000
|
heap
|
page read and write
|
||
23ADEFD000
|
stack
|
page read and write
|
||
7CB42FE000
|
stack
|
page read and write
|
||
271D4B70000
|
remote allocation
|
page read and write
|
||
E3F67E000
|
stack
|
page read and write
|
||
271CF3E0000
|
trusted library allocation
|
page read and write
|
||
1BD3E275000
|
heap
|
page read and write
|
||
271CFD18000
|
heap
|
page read and write
|
||
1BD3E0E0000
|
heap
|
page read and write
|
||
19DA4628000
|
heap
|
page read and write
|
||
11D4EFD000
|
stack
|
page read and write
|
||
1BA4427F000
|
heap
|
page read and write
|
||
271CF3B0000
|
heap
|
page read and write
|
||
1BD3E140000
|
heap
|
page read and write
|
||
1BD3E202000
|
heap
|
page read and write
|
||
271D4D06000
|
heap
|
page read and write
|
||
1BA44260000
|
heap
|
page read and write
|
||
14DEE240000
|
heap
|
page read and write
|
||
271D4D15000
|
heap
|
page read and write
|
||
A353A7F000
|
stack
|
page read and write
|
||
1BA4427B000
|
heap
|
page read and write
|
||
23ADC7C000
|
stack
|
page read and write
|
||
11D50FD000
|
stack
|
page read and write
|
||
2995EFE000
|
stack
|
page read and write
|
||
1BA4422E000
|
heap
|
page read and write
|
||
271D4AE0000
|
trusted library allocation
|
page read and write
|
||
A35347A000
|
stack
|
page read and write
|
||
19DA467F000
|
heap
|
page read and write
|
||
1BA44297000
|
heap
|
page read and write
|
||
1BA44170000
|
heap
|
page read and write
|
||
11D52FF000
|
stack
|
page read and write
|
||
271CF3F0000
|
trusted library section
|
page read and write
|
||
14DEE200000
|
heap
|
page read and write
|
||
1BA44276000
|
heap
|
page read and write
|
||
271CFD58000
|
heap
|
page read and write
|
||
A35367B000
|
stack
|
page read and write
|
||
19DA4602000
|
heap
|
page read and write
|
||
1BA44285000
|
heap
|
page read and write
|
||
1BD3E200000
|
heap
|
page read and write
|
||
1F257E50000
|
heap
|
page read and write
|
||
7CB407B000
|
stack
|
page read and write
|
||
271CFD58000
|
heap
|
page read and write
|
||
1F258013000
|
heap
|
page read and write
|
||
271D4A14000
|
trusted library allocation
|
page read and write
|
||
1FD62243000
|
heap
|
page read and write
|
||
1FD62243000
|
heap
|
page read and write
|
||
271CFD18000
|
heap
|
page read and write
|
||
1FD61FC0000
|
heap
|
page read and write
|
||
1BA4427C000
|
heap
|
page read and write
|
||
299573B000
|
stack
|
page read and write
|
||
2995D7C000
|
stack
|
page read and write
|
||
271D4ED0000
|
trusted library allocation
|
page read and write
|
||
29962FD000
|
stack
|
page read and write
|
||
7CB417F000
|
stack
|
page read and write
|
||
1BD3E0D0000
|
heap
|
page read and write
|
||
1BA44246000
|
heap
|
page read and write
|
||
29960FB000
|
stack
|
page read and write
|
||
29963FF000
|
stack
|
page read and write
|
||
1BA44930000
|
trusted library allocation
|
page read and write
|
||
19DA4679000
|
heap
|
page read and write
|
||
1BA44231000
|
heap
|
page read and write
|
||
271D4A10000
|
trusted library allocation
|
page read and write
|
||
1BA4424F000
|
heap
|
page read and write
|
||
A353C7E000
|
stack
|
page read and write
|
||
11D53FF000
|
stack
|
page read and write
|
||
1F257EC0000
|
heap
|
page read and write
|
||
19DA4658000
|
heap
|
page read and write
|
||
1F258000000
|
heap
|
page read and write
|
||
1BA44244000
|
heap
|
page read and write
|
||
7CB43FA000
|
stack
|
page read and write
|
||
A35307B000
|
stack
|
page read and write
|
||
19DA4520000
|
heap
|
page read and write
|
||
1BA44241000
|
heap
|
page read and write
|
||
1BD3E229000
|
heap
|
page read and write
|
||
14DEE213000
|
heap
|
page read and write
|
||
271D4A34000
|
trusted library allocation
|
page read and write
|
||
76DD59C000
|
stack
|
page read and write
|
||
271D4B70000
|
remote allocation
|
page read and write
|
||
E3EF9C000
|
stack
|
page read and write
|
||
11D4CFB000
|
stack
|
page read and write
|
||
1BA44213000
|
heap
|
page read and write
|
||
A3537FE000
|
stack
|
page read and write
|
||
1BD3E170000
|
trusted library allocation
|
page read and write
|
||
1BA4426E000
|
heap
|
page read and write
|
There are 203 hidden memdumps, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://na4.documents.adobe.com/public/userMessage?token=A59DBC66ECB7F2734F210B1836E128D1312E52479E1A670A3F336B32E45E910
|
||
https://acrobat.adobe.com/
|
||
https://auth.services.adobe.com/en_US/deeplink.html?deeplink=ssofirst&callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2FEchoSign2%2FAdobeID%2Fcode%3Fredirect_uri%3Dhttps%253A%252F%252Fgps.echosign.com%252Fpublic%252FadobeIDLogin%253Fserver%253Dna4.documents.adobe.com%2526port%253D443%26code_challenge_method%3Dplain%26use_ms_for_expiry%3Dtrue&client_id=EchoSign2&scope=openid%2CAdobeID%2CDCAPI%2Cadditional_info.account_type%2Cskybox%2Cupdate_profile.first_name%2Cupdate_profile.last_name%2Cagreement_send%2Cagreement_sign%2Csign_library_write%2Csign_user_read%2Csign_user_write%2Cagreement_read%2Cagreement_write%2Cwidget_read%2Cwidget_write%2Cworkflow_read%2Cworkflow_write%2Csign_library_read%2Cadditional_info.projectedProductContext%2Csign_webhook_read%2Csign_webhook_write%2Csign_webhook_retention%2Csao.ACOM_ESIGN_TRIAL%2Cee.GROUP_SIGN_WEB&denied_callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fdenied%2FEchoSign2%3Fredirect_uri%3Dhttps%253A%252F%252Fgps.echosign.com%252Fpublic%252FadobeIDLogin%253Fserver%253Dna4.documents.adobe.com%2526port%253D443%26response_type%3Dcode&relay=55e08fa0-6477-46eb-a1cb-aa53c661c93c&locale=en_US&flow_type=code&ctx_id=Adobe_Sign&dctx_id=adobe_document_cloud&idp_flow_type=login&s_p=apple%2Cfacebook%2Cgoogle#/
|
||
https://www.adobe.com/legal/consumer-disclosure-linkfree.html
|
||
https://acrobat.adobe.com/us/en/
|
||
https://status.adobe.com/products/1554
|
||
https://stock.adobe.com/ro/contributor/207793921/amanda-greene?as_channel=adobe_com&as_source=susi&as_campclass=brand&as_campaign=stock_images&as_audience=users&as_content=contributor_page
|
||
https://stock.adobe.com/sandboxed_tags.html
|
||
https://servedby.flashtalking.com/container/13539;99030;10307;iframe/?ftXRef=&ftXValue=&ftXType=&ftXName=&ftXNumItems=&ftXCurrency=&U1=27961541073130129811371368873722366076&U2=&U3=27756316416519834831387387568959241458&U4=stock.adobe.com%3Acontributor%3A207793921%3Aamanda-greene&U5=&U6=&U7=&U8=&U9=&U10=&U11=&U12=&U13=&U14=&U15=&U16=&U17=&U18=&U19=&U20=&ft_referrer=https%3A%2F%2Fstock.adobe.com%2Fro%2Fcontributor%2F&ns=&cb=3432050999411.329
|
||
https://9212252.fls.doubleclick.net/activityi;dc_pre=CKir5NP9vfkCFS0jBgAdK3MMeg;src=9212252;type=invmedia;cat=stock00;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;ord=1;num=6649563850234.023?
|
||
https://9212252.fls.doubleclick.net/activityi;dc_pre=CKWj5NP9vfkCFUe81Qod8gIPgA;src=9212252;type=invmedia;cat=japan000;dc_lat=;dc_rdid=;tag_for_child_directed_treatment=;tfua=;npa=;ord=1366023289772.076?
|
||
https://commerce.adobe.com/checkout/iframe/preload/
|
||
https://commerce.adobe.com/store/iframe/preload
|
There are 3 hidden doms, click here to show them.