top title background image
flash

eLVzfyydCC.exe

Status: finished
Submission Time: 2022-01-12 09:27:17 +01:00
Malicious
Trojan
Ursnif

Comments

Tags

  • exe
  • Gozi

Details

  • Analysis ID:
    551536
  • API (Web) ID:
    919033
  • Analysis Started:
    2022-01-12 09:55:27 +01:00
  • Analysis Finished:
    2022-01-12 10:05:38 +01:00
  • MD5:
    f5b2750348fc459bb7da5c62d9e78959
  • SHA1:
    4d16ea637bf1c62716ad0905b07661e78d1908fd
  • SHA256:
    1d01909e17918dfcf1f39c280bb67b0b0a36f10163f021944df87c657b56f7f5
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 92
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 20/43
malicious

IPs

IP Country Detection
64.70.19.203
United States
185.85.15.46
Russian Federation
104.18.12.5
United States
Click to see the 22 hidden entries
104.16.126.175
United States
52.211.244.253
United States
142.250.186.142
United States
142.250.185.195
United States
77.74.178.40
Russian Federation
35.186.249.72
United States
34.102.147.248
United States
93.159.228.11
Russian Federation
18.192.164.101
United States
13.36.218.177
United States
108.177.15.157
United States
142.250.186.36
United States
185.85.15.26
Russian Federation
185.85.15.47
Russian Federation
216.58.212.136
United States
13.226.159.97
United States
13.226.159.34
United States
54.228.170.24
United States
52.16.52.14
United States
157.240.17.15
United States
64.70.19.170
United States
54.195.126.67
United States

Domains

Name IP Detection
blancs.ws
64.70.19.203
www.website.ws
0.0.0.0
unpkg.com
104.16.126.175
Click to see the 37 hidden entries
www.google.ch
142.250.185.195
multisite2.geo.kaspersky.com
185.85.15.47
kaspersky.demdex.net
0.0.0.0
cm.everesttech.net
0.0.0.0
stats.g.doubleclick.net
0.0.0.0
service.maxymiser.net
0.0.0.0
dpm.demdex.net
0.0.0.0
vt.myvisualiq.net
0.0.0.0
api-router.kaspersky-labs.com
0.0.0.0
t.contentsquare.net
13.226.159.97
resources.xg4ken.com
0.0.0.0
www.kaspersky.com
0.0.0.0
connect.facebook.net
0.0.0.0
content.kaspersky-labs.com
0.0.0.0
media.kaspersky.com
0.0.0.0
snap.licdn.com
0.0.0.0
t.myvisualiq.net
0.0.0.0
update.fortinet.com
0.0.0.0
elb-aws-fr-visualiq-1583280815.eu-central-1.elb.amazonaws.com
18.192.164.101
kaspersky.d3.sc.omtrdc.net
13.36.218.177
s.tribalfusion.com
104.18.12.5
www-google-analytics.l.google.com
142.250.186.142
stats.l.doubleclick.net
108.177.15.157
www-googletagmanager.l.google.com
216.58.212.136
multisite-support.geo.kaspersky.com
93.159.228.11
tag.rmp.rakuten.com
34.102.147.248
dcs-edge-irl1-876252164.eu-west-1.elb.amazonaws.com
52.211.244.253
awseb-e-g-awsebloa-nt5wfb9wmmft-1397624435.eu-west-1.elb.amazonaws.com
54.228.170.24
gstaticadssl.l.google.com
172.217.18.99
w.usabilla.com
54.195.126.67
website.ws
64.70.19.170
d360616xvwhw9g.cloudfront.net
13.226.159.34
scontent.xx.fbcdn.net
157.240.17.15
update.kaspersky.com
185.85.15.26
d.impactradius-event.com
35.186.249.72
www.google.com
142.250.186.36
webcn2.geo.kaspersky.com
77.74.178.40

URLs

Name Detection
https://www.kaspersky.com/siterenderer/_next/static/chunks/137.b867e461b87783f36945.js
https://unpkg.com/web-vitals
http://www.amazon.com/
Click to see the 97 hidden entries
https://kaspersky.d3.sc.omtrdc.net/id?d_visid_ver=4.4.0&d_fieldgroup=A&mcorgid=983502BE532960BE0A490D4C%40AdobeOrg&mid=19200230165318792082030216481562829755&ts=1642010216707
https://www.kaspersky.com/siterenderer/_next/static/runtime/polyfills-4cd59183e7ac72a5e1c7.js
https://www.website.ws/newnav/js/roboto.cufonfonts.js
https://www.kaspersky.com/siterenderer/_next/static/chunks/322.f151cd6a7db61edfbb02.js
https://www.website.ws/newdesign/newnav/images/btn-q-search.png
https://www.kaspersky.com/siterenderer/_next/static/css/d4badb8db511cd24e95e.css
https://t.myvisualiq.net/ul_cb/activity_pixel?pt=i&et=a&ago=212&ao=537&px=235&ord=1032722821&u1=Global|ALL|Traffic&r=2090721056
https://www.kaspersky.com/about/press-releases/2021_kaspersky-recognized-as-a-2021-gartner-peer-insi
https://www.kaspersky.com/content/en-global/images/baseline/media-cards/ent-1.jpg
https://www.kaspersky.com/content/en-global/images/baseline/masthead-home/home-award-4.png
https://www.website.ws/js/js-loader.js
https://me.kaspersky.com/?ignoreredirects=true
https://www.website.ws/newdesign/newnav/images/header-bg.jpg
https://www.website.ws/newdesign/newnav/images/nav-login.png
https://www.kaspersky.com/siterenderer/_next/static/runtime/main-52c9dd25e850a6bbe3d1.js
https://www.kaspersky.com/content/en-global/images/baseline/masthead-home/home-award-5.png
https://www.website.ws/newdesign/newnav/images/btn-create-acc-sm.png
https://www.website.ws/js/emoji.js
https://stats.g.doubleclick.net/g/collect?v=2&
https://www.kaspersky.co.jp/
https://www.awin1.com/sread.img?tt=ns&tv=2&
https://www.kaspersky.com/siterenderer/_next/static/css/a9ed3a1594363c6938f8.css
https://stats.g.doubleclick.net/j/collect?t=dc&aip=1&_r=3&v=1&_v=j96&tid=UA-63997723-2&cid=388491555.1642010231&jid=27385254&uid=19200230165318792082030216481562829755&gjid=1869784295&_gid=1932271643.1642010231&_u=YEBAAEAAAAAAAC~&z=1109340552
https://www.website.ws/newnav/js/iepngfix_tilebg.js
https://www.kaspersky.rs/
https://www.website.ws/newdesign/newnav/images/form-field-l.png
https://www.website.ws/newdesign/newnav/images/content-t.png
https://www.kaspersky.com/siterenderer/_next/static/fonts/KasperskySans/KasperskySans-Bold.woff
http://www.nytimes.com/
https://www.kaspersky.com/siterenderer/_next/static/media/kaspersky-logo.e79ac6c57fcaf0a58fbb62a8a5d56786.svg
https://www.kaspersky.com/siterenderer/_next/static/eI2qEMPWp5Vb-YNsYp7i9/pages/index.js
https://www.google.com/ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j96&tid=UA-63997723-28&cid=388491555.1642010231&jid=1545619336&_u=aEDAAEQAAAAAAC~&z=1372287311
https://www.kaspersky.com/content/en-global/images/baseline/masthead-home/business-award-2.png
https://www.website.ws/newdesign/newnav/images/btn-sec-bg.png
https://www.kaspersky.com/siterenderer/_next/static/fonts/museo-sans/museosans-300-webfont.woff
https://www.kaspersky.co.kr/
https://t.contentsquare.net/uxa/2c47087421d0b.js
https://vt.myvisualiq.net/2/7hrBnrmZAM5n6cl1WjyOsg%3D%3D/vt-132.js
https://www.kaspersky.com/siterenderer/_next/static/chunks/framework.09fd0d83a8f910ba0251.js
https://www.kaspersky.com/siterenderer/_next/static/css/c5c20187bc88132abb4a.css
https://www.kaspersky.com/siterenderer/_next/static/chunks/107.adad7052b448169ab6ff.js
https://www.kaspersky.com.tr/?ignoreredirects=true
https://kaspersky-mkt-prod1-m.adobe-campaign.com
https://www.kaspersky.com/siterenderer/_next/static/fonts/museo-sans/museosans-500italic-webfont.woff
https://s.kk-resources.com/kst.js
https://www.website.ws/newdesign/newnav/images/bottom-logo.png
http://www.twitter.com/
https://ampcid.google.com/v1/publisher:getClientId
https://www.kaspersky.com/siterenderer/_next/static/chunks/109.3cf8601568ee32d2037f.js
https://www.kaspersky.com/siterenderer/_next/static/css/bfdf68743177ecbb5a22.css
https://px.ads.linkedin.com/collect?
https://www.website.ws/newdesign/newnav/images/form-q-bg.png
https://www.kaspersky.com/siterenderer/_next/static/fonts/museo-sans/museosans-100italic-webfont.woff
https://www.kaspersky.com/content/en-global/images/baseline/masthead-home/home.png
https://www.website.ws/newdesign/newnav/images/h-motto.png
https://www.kaspersky.pl/
https://www.kaspersky.dk/?ignoreredirects=true
https://content.kaspersky-labs.com/se/com/content/en-global/images/baseline/masthead-home/business-a
https://www.website.ws/newnav/images/main-logo.png
https://www.kaspersky.be/?ignoreredirects=true
https://www.kaspersky.com/siterenderer/_next/static/fonts/museo-sans/museosans-100-webfont.woff
https://www.kaspersky.pt/?ignoreredirects=true
https://www.website.ws/wc_landing.dhtml?domain=blancs.ws
https://www.kaspersky.com/siterenderer/_next/static/media/quote-bottom.e2312833966dba730cd5a06f774284f2.svg
https://unpkg.com/web-vitals@2.1.3
https://app.appsflyer.com/com.kms.free?pid=klsite
https://www.kaspersky.com/content/en-global/images/baseline/masthead-home/business-award-1.png
https://me-en.kaspersky.com/?ignoreredirects=true
https://www.website.ws/idn-orderflow/css/jquery.emojipicker.css
https://www.website.ws/js/jquery-3.5.0.min.js
https://stats.g.doubleclick.net/g/collect
https://tag.rmp.rakuten.com/122870.ct.js
http://www.reddit.com/
https://africa.kaspersky.com/?ignoreredirects=true
https://www.website.ws/newdesign/newnav/images/body-bg.jpg
https://s.tribalfusion.com/i.cid?c=705083&ev=0&page=Global
https://www.kaspersky.com
https://www.kaspersky.de/?ignoreredirects=true
http://blancs.ws/drew/SVohbxNR_2FyCYmenSW7CXy/mnUNl0_2BA/r7aNUwhQrLgjTBURN/to2yS6Hh74Jd/I8HRX9nlHVK/
https://www.kaspersky.nl/?ignoreredirects=true
https://www.kaspersky.com.hk/
https://www.kaspersky.ro/
http://www.kaspersky.com/?domain=update.kaspersky.com
https://www.kaspersky.it/?ignoreredirects=true
https://www.kaspersky.co.in/?ignoreredirects=true
https://www.kaspersky.com/siterenderer/_next/static/chunks/61.bc1dd900b92bc9d80767.js
https://www.website.ws/js/cookie-alert.js
https://dpm.demdex.net/id?d_visid_ver=4.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_orgid=983502BE532960BE0A490D4C%40AdobeOrg&d_nsid=0&ts=1642010216469
https://stats.g.doubleclick.net/j/collect
https://www.website.ws/newdesign/newnav/images/h-register-own.png
https://www.kaspersky.com/siterenderer/_next/static/images/assets/map.png
https://www.website.ws/newdesign/newnav/images/content-b-emp.png
https://www.website.ws/newnav/css/layout.css
https://www.website.ws/newdesign/newnav/images/h-bg.png
https://www.kaspersky.com/favicon.ico
https://www.kaspersky.com/siterenderer/_next/static/chunks/470.11485af6ac94049be322.js
https://store.kaspersky.com/store/kasperuk/en_GB/DisplayCustomerServiceOrderSearchPage

Dropped files

Name File Type Hashes Detection
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\analytics[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\web-vitals[1].txt
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\web-vitals@2.1[1].3
ASCII text, with no line terminators
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\vt-132[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\layout[1].css
assembler source, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\ktag[1].js
C source, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\js[3].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\js[2].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\insight.min[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\fbevents[1].js
ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\favicon[1].ico
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\bat[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\KasperskySans-Bold[1].woff
Web Open Font Format, TrueType, length 40676, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\NewErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\A2336411-46c8-4f83-96b6-294966496d651[1].js
C source, ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\6i[1].htm
HTML document, ASCII text
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\2c47087421d0b[1].js
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\122870.ct[1].js
C source, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\webpack-9d64c724fee92863bf94[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\s_code_single_suite[1].js
UTF-8 Unicode text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\polyfills-4cd59183e7ac72a5e1c7[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\optimum-security-card[1].png
PNG image data, 225 x 322, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\map[1].png
PNG image data, 1080 x 531, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\main-52c9dd25e850a6bbe3d1[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-300-webfont[1].woff
Web Open Font Format, TrueType, length 15876, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\8HUE4E45.htm
HTML document, ASCII text, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\730c637540e857733f76[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\2de41e69d7c1a5e11097[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\PEJLKQA8\2b763e44c355fc014556[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\white.e75902539fce0c72d67a5f0cc24440dc[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\quote-top.3c6c597940fefe5371e9522767e0ebae[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\quote-bottom.e2312833966dba730cd5a06f774284f2[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-900-webfont[1].woff
Web Open Font Format, TrueType, length 15464, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-700-webfont[1].woff
Web Open Font Format, TrueType, length 15908, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-500italic-webfont[1].woff
Web Open Font Format, TrueType, length 16460, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-500-webfont[1].woff
Web Open Font Format, TrueType, length 15736, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-300italic-webfont[1].woff
Web Open Font Format, TrueType, length 16556, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\ksos-card[1].png
PNG image data, 225 x 409, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-100italic-webfont[1].woff
Web Open Font Format, TrueType, length 16112, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\museosans-100-webfont[1].woff
Web Open Font Format, TrueType, length 15648, version 1.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\kaspersky-logo.e79ac6c57fcaf0a58fbb62a8a5d56786[1].svg
SVG Scalable Vector Graphics image
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\gtm[1].js
UTF-8 Unicode text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\eugene_bg[1].png
PNG image data, 526 x 460, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\ent-2[1].jpg
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 348x196, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\ent-1[1].jpg
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 348x196, frames 3
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\dest5[1].htm
HTML document, ASCII text, with very long lines
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\daily-dark[1].png
PNG image data, 348 x 196, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\KasperskySans-Regular[1].woff
Web Open Font Format, TrueType, length 41148, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\NUEPGTR9\KasperskySans-Light[1].woff
Web Open Font Format, TrueType, length 41376, version 0.0
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\470.11485af6ac94049be322[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\322.f151cd6a7db61edfbb02[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\316695c6.209da53eb2f66e625fe4[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\161.7bb93c182f3aee250b4e[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\137.b867e461b87783f36945[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\112.72680c3d02b12dbcfc70[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\109.3cf8601568ee32d2037f[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\107.adad7052b448169ab6ff[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\61.bc1dd900b92bc9d80767[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{FBB47D09-73D0-11EC-90E5-ECF4BB570DC9}.dat
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{39E1AB7A-73D1-11EC-90E5-ECF4BB570DC9}.dat
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{293D228C-73D1-11EC-90E5-ECF4BB570DC9}.dat
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{FBB47D07-73D0-11EC-90E5-ECF4BB570DC9}.dat
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{39E1AB78-73D1-11EC-90E5-ECF4BB570DC9}.dat
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{293D228A-73D1-11EC-90E5-ECF4BB570DC9}.dat
Composite Document File V2 Document, Cannot read section info
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\c78d26b1.ce9e1553326496a1c9e2[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\kis-card[1].png
PNG image data, 225 x 322, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\kaspersky-ransomware-test-dark[1].jpg
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CC 2019 (Windows), datetime=2021:11:15 16:32:12], baseline, precision 8, 12 (…)
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\index[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\home[1].png
PNG image data, 804 x 560, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\home-mobile[1].png
PNG image data, 360 x 152, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\home-award-5[1].png
PNG image data, 137 x 52, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\home-award-4[1].png
PNG image data, 109 x 54, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\home-award-3[1].png
PNG image data, 54 x 60, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\framework.09fd0d83a8f910ba0251[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\fe5b2601695152ff1fad[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\dc64fc9dfc4c6e33bad5[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\commons.e62962d42a6055f15f9a[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\DURNCK2N\www.kaspersky[1].xml
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\c5412e1b22c148871c80[1].css
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\business-award-3[1].png
PNG image data, 100 x 80, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\business-award-2[1].png
PNG image data, 100 x 80, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\business-award-1[1].png
PNG image data, 100 x 80, 8-bit colormap, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\av-2020[1].png
PNG image data, 124 x 64, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\_ssgManifest[1].js
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\_buildManifest[1].js
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\_app[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\MRG_Effitas[1].png
PNG image data, 38 x 63, 8-bit/color RGBA, non-interlaced
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\80.2da60d8f88d5016b2bb7[1].js
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\4PB7FJMT\74.aff6e43f31266e4ba1e4[1].js
ASCII text, with very long lines, with no line terminators
#