top title background image
flash

https://ziadieinsurance.eb-sites.com/5518707892682752

Status: finished
Submission Time: 2021-05-04 20:27:39 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    404234
  • API (Web) ID:
    710625
  • Analysis Started:
    2021-05-04 20:29:13 +02:00
  • Analysis Finished:
    2021-05-04 20:35:53 +02:00
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 84
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious

IPs

IP Country Detection
100.25.4.145
United States
52.217.89.76
United States
208.90.88.30
United States
Click to see the 9 hidden entries
13.35.253.54
United States
143.110.228.35
United States
35.190.88.7
United States
104.18.11.207
United States
31.210.20.74
Netherlands
142.250.184.243
United States
13.32.23.123
United States
104.16.19.94
United States
13.32.21.90
United States

Domains

Name IP Detection
fox.agentmethods-0820.c66.me
100.25.4.145
www.ziadieinsurance.com
0.0.0.0
agentmethods-production.s3.amazonaws.com
0.0.0.0
Click to see the 18 hidden entries
code.jquery.com
0.0.0.0
cdn2.eb-pages.com
0.0.0.0
app.engagebay.com
0.0.0.0
favicon.ico
0.0.0.0
kit.fontawesome.com
0.0.0.0
ka-f.fontawesome.com
0.0.0.0
ghs.googlehosted.com
142.250.184.243
fitnessfortravel.top
31.210.20.74
ziadieinsurance.eb-sites.com
143.110.228.35
d2p078bqz5urf7.cloudfront.net
13.35.253.54
d2wy8f7a9ursnm.cloudfront.net
13.32.23.123
d3w29h23ietttc.cloudfront.net
13.32.21.90
cdnjs.cloudflare.com
104.16.19.94
s3-1-w.amazonaws.com
52.217.89.76
maxcdn.bootstrapcdn.com
104.18.11.207
sessions.bugsnag.com
35.190.88.7
www.quotit.net
208.90.88.30
stackpath.bootstrapcdn.com
104.18.11.207

URLs

Name Detection
https://agentmethods.com/
https://www.engagebay.com/?utm_source=eb-lps
https://fitnessfortravel.top/spider/xx/8707892682752
Click to see the 97 hidden entries
https://ziadieinsurance.eb-sites.com/5518707892682752
https://www.ziadieinsurance.com/
https://ziadieinsurance.eb-sites.com/5518707892682752Root
https://fitnessfortravel.top/spider/xx/
https://fitnessfortravel.top/spider/xx/8707892682752p
https://fitnessfortravel.top/spider/xx/
https://ziadieinsurance.eb-sites.com/5518707892682752
https://www.engagebay.
https://agentmethods-production.s3.amazonaws.com/oQcerTs5SqZdSUU7TJZ9S8oy
http://browsehappy.com/
https://ziadieinsurance.eb-sites.com/551870789268Root
https://d2p078bqz5urf7.cloudfront.net/cloud/prod/assets/lib/font-family/roboto.css
https://ka-f.fontawesome.com
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry_V2.asp?InsuranceTypeId=D&license_no=
https://d2p078bqz5urf7.cloudfront.net/jsapi
https://agentmethods-production.s3.amazonaws.com/9rMCoz65GNhVQjiFtFZB7x5x
http://github.com/kenwheeler/slick/issues
https://www.engagebay.com/?utm_source=eb-lps2682752
https://github.com/faisalman/ua-parser-js
https://agentmethods.com/e.com/r/xx/8707892682752
https://agentmethods-production.s3.amazonaws.com/jxSxTBQt9wpC9Z1kmUx4U8F5
https://www.ziadieinsurance.com/r/xx/8707892682752e
https://github.com/IanLunn/Hover
https://github.com/twbs/bootstrap/blob/master/LICENSE)
https://d2p078bqz5urf7.cloudfront.net/cloud/landingpage-builder/page/bootstrap.min.css
https://www.ziadieinsurance.com/r/xx/8707892682752b
http://ianlunn.co.uk/
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=X&license_no=
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=X&license_no=H
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=L&license_no=
https://app.engagebay.com/rest/api/signup/signup-user
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=E&license_no=
http://www.bohemiancoding.com/sketch
https://code.jquery.com/jquery-3.1.1.min.js
https://agentmethods-production.s3.amazonaws.com/6eeMuS9eNcBramrNByc8JY9s
https://github.com/twbs/bootstrap/blob/main/LICENSE)
https://notify.bugsnag.com
http://fontawesome.iohttp://fontawesome.iohttp://fontawesome.io/license/http://fontawesome.io/licens
http://kenwheeler.github.io/slick
https://fontawesome.com/license/free
https://agentmethods.com/e.com/r/xx/8707892682752T
https://fitnessfortrave.eb-sites.com/5518707892682752
https://d2p078bqz5urf7.cloudfront.net/cloud/landingpage-builder/page/commons.css
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry_V2.asp?InsuranceTypeId=D&license_no=
https://ziadieinsurance.eb-sites.com/551870789268om/e.com/r/xx/8707892682752Root
https://cdn2.eb-pages.com/uploads/5356667366539264/pdf.png
https://cdnjs.cloudflare.com/ajax/libs/slick-carousel/1.9.0/slick-theme.min.css
https://agentmethods-production.s3.amazonaws.com/f3GY34unAFcsvxZqAfapGaRU
https://agentmethods.com/
https://fontawesome.com
https://d2p078bqz5urf7.cloudfront.net/cloud/assets/img/logo/fav/ab-16x16.ico5:
https://cdnjs.cloudflare.com/ajax/libs/slick-carousel/1.9.0/slick.js
https://www.engagebay.com/?utm_source=eb-lps
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?license_no=
https://agentmethods-production.s3.amazonaws.com/4ALeRBgPdiqBWaQKnSYigUHS
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=N&license_no=
https://app.engagebay.com/signup
https://ziadieinsurance.eb-sites.com/551870789268rance.com/r/xx/8707892682752Root
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=T&license_no=
https://github.com/twbs/bootstrap/graphs/contributors)
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=E&license_no=
http://opensource.org/licenses/MIT).
https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.5.3/js/bootstrap.bundle.min.js
https://fontawesome.comhttps://fontawesome.comFont
https://agentmethods-production.s3.amazonaws.com/9r6aMqZHBbSxF6mYyBXbTmK4
http://github.com/kenwheeler/slick
https://agentmethods-production.s3.amazonaws.com/DXnh2gQGUzsBKDcjrSfahMBG
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=X&license_no=
https://agentmethods-production.s3.amazonaws.com/J6HCMGSsUygUJQvcFZ2XfDaG
https://www.ziadieinsurance.com/
https://images.unsplash.com/photo-1509023464722-18d996393ca8?ixlib=rb-1.2.1&ixid=eyJhcHBfaWQiOjE
https://code.jquery.com/jquery-3.2.1.slim.min.js
https://d2p078bqz5urf7.cloudfront.net/cloud/assets/img/logo/fav/ab-16x16.ico~
https://ziadieinsurance.eb-sites.com/551870789268/ziadieinsurance.eb-sites.com/5518707892682752
https://sessions.bugsnag.com
http://fontawesome.io
https://agentmethods-production.s3.amazonaws.com/PGVP3NWeAPUabnTrTA1PQpn6
https://d2p078bqz5urf7.cloudfront.net/cloud/landingpage-builder/page/iframe.js?86-2.4349062990782067
https://d2p078bqz5urf7.cloudfront.net/cloud/landingpage-builder/page/page-actions.js?=86-2.434906299
https://agentmethods.c
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
https://ziadieinsurance.eb-sites.com/551870789268el.top/spider/xx/8707892682752Root
https://www.engagebay.com/?utm_source=eb-lpsT
https://www.quotit.net/eproIFP/webPages/infoentry/infoEntry.asp?covTypeID=ES&InsuranceTypeId=G&licen
http://kenwheeler.github.io
https://www.quotit.net/eproIFP/webPages/infoentry/infoEntry.asp?covTypeID=ES&InsuranceTypeId=G&a
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=I&license_no=
https://d2p078bqz5urf7.cloudfront.net/cloud/landingpage-builder/page/page.css
http://ianlunn.github.io/Hover/)
https://www.ziadieinsurance.com
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=L&license_no=
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=T&license_no=
https://www.quotit.net/eproIFP/webPages/infoEntry/infoEntry.asp?insuranceTypeID=N&license_no=
https://ziadieinsurance.eb-sites.com/551870789268com/?utm_source=eb-lpsRoot
http://www.ziadieinsurance.com/
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
https://kit.fontawesome.com/585b051251.js

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\xx[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\roboto[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\KFOmCnqEu92Fr1Me5g[1].woff
Web Open Font Format, TrueType, length 65244, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\KFOlCnqEu92Fr1MmSU5vAA[1].woff
Web Open Font Format, TrueType, length 64952, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\KFOlCnqEu92Fr1MmSU5fBBc-[1].woff
Web Open Font Format, TrueType, length 20404, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\KFOjCnqEu92Fr1Mu51TLBCc6CsI[1].woff
Web Open Font Format, TrueType, length 22360, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\KFOjCnqEu92Fr1Mu51S7ABc-[1].woff
Web Open Font Format, TrueType, length 70696, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\KFOiCnqEu92Fr1Mu51QrEzAdKQ[1].woff
Web Open Font Format, TrueType, length 21776, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\J6HCMGSsUygUJQvcFZ2XfDaG[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\1pix[1].png
PNG image data, 1 x 1, 1-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\bullet[2]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\page[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\page-actions[1].js
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\leadgrabbers[1].json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\jxSxTBQt9wpC9Z1kmUx4U8F5[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\iframe[1].js
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\hover[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\free-fa-solid-900[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free Solid family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\free-fa-regular-400[1].eot
Embedded OpenType (EOT), Font Awesome 5 Free Regular family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\fontawesome-webfont[1].eot
Embedded OpenType (EOT), FontAwesome family
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\DXnh2gQGUzsBKDcjrSfahMBG[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\5518707892682752[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\xx[1].htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\tick-07c4e79cc650de31f50404a4d05b260abd05652dd12a56f436e868ed925e9d48[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\slick.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\outlook1[1].png
PNG image data, 26 x 26, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\onedrive-w[1].png
PNG image data, 242 x 167, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\navcancl[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\min_v6[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\jquery.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\info_48[2]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\drag-a79a51ae7c41df2c005cf922050e5260f58d79815ecefda6cc6b9f766577ae29[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\gmail[1].png
PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\free.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\free-v4-shims.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\f3GY34unAFcsvxZqAfapGaRU[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\errorPageStrings[2]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\edit-d8d8448de4acf39f0d205239932f69cebadc8ef71bc2b9c3ac1d78a0cb314053[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\dnserror[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\KFOkCnqEu92Fr1Mu52xM[1].woff
Web Open Font Format, TrueType, length 69460, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\errorPageStrings[2]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\bootstrap.min[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\bootstrap.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\bootstrap.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\application-e06d9cfcef1a4497446791a3c0939f92f16a1aacae9c59de547df02233791822[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\ab-16x16[1].ico
MS Windows icon resource - 9 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\KFOmCnqEu92Fr1Mu4mxM[1].woff
Web Open Font Format, TrueType, length 20332, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\KFOlCnqEu92Fr1MmEU9fBBc-[1].woff
Web Open Font Format, TrueType, length 20532, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\font-awesome.min[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\KFOjCnqEu92Fr1Mu51TjARc-[1].woff
Web Open Font Format, TrueType, length 70440, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\KFOiCnqEu92Fr1Mu51QrIzQ[1].woff
Web Open Font Format, TrueType, length 68740, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\AZJRJN0J.htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\6eeMuS9eNcBramrNByc8JY9s[1].txt
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1080, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\mms\BONICSM1\onedrive[1].dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\wlm7n14\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2E2545EA-AD52-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{2E2545E9-AD52-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{2E2545E7-AD52-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\IB42RK38\www.ziadieinsurance[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\9r6aMqZHBbSxF6mYyBXbTmK4[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\css[1].css
ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\commons[1].css
ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\bugsnag.min[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\bootstrap.min[1].css
ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\application-e787529eaf981cd5a233dbffb4fe8672557b4485af3e5c74e85bac7ae01ac35e[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\album[1].css
assembler source, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\PGVP3NWeAPUabnTrTA1PQpn6[1].txt
[TIFF image data, little-endian, direntries=5, xresolution=74, yresolution=82, resolutionunit=2, software=GIMP 2.10.10, datetime=2020:07:25 07:02:49], progressive, precision 8, 1500x844, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\KFOkCnqEu92Fr1MmgWxM[1].woff
Web Open Font Format, TrueType, length 63872, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\KFOjCnqEu92Fr1Mu51TLBBc-[1].woff
Web Open Font Format, TrueType, length 71384, version 1.1
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\9rMCoz65GNhVQjiFtFZB7x5x[1].css
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\EQAWN5DV\ziadieinsurance.eb-sites[1].xml
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\585b051251[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\v215[1].js
C source, UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\trash-10a167593d2e212f9eb8c8e282a1d3358e9862b45a877aa24a52bcc27dd4c1d1[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\slick-theme.min[1].css
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\popper.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\pdf[1].png
PNG image data, 238 x 238, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\office3651[1].png
PNG image data, 187 x 188, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\navcancl[2]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\navcancl[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\httpErrorPagesScripts[2]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#