=
We are hiring! Windows Kernel Developer (Remote), apply here!
flash

mimecast portal Server Maintenance.pdf

Status: finished
Submission Time: 2022-05-13 14:42:39 +02:00
Malicious
Phishing
HTMLPhisher

Comments

Tags

Details

  • Analysis ID:
    626055
  • API (Web) ID:
    993559
  • Analysis Started:
    2022-05-13 14:43:42 +02:00
  • Analysis Finished:
    2022-05-13 14:54:50 +02:00
  • MD5:
    ac404af44a269d02efa470af136fff7d
  • SHA1:
    742adee8b08cb1467f78712c56a80f26d8910bdf
  • SHA256:
    b1bac52fc5dad9dcd3a240b679e909e75737f806ac331a2901d3abd843d9ee92
  • Technologies:
Full Report Management Report IOC Report Engine Info Verdict Score Reports

System: Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211

malicious
80/100

malicious

IPs

IP Country Detection
188.114.97.10
European Union
172.67.194.70
United States
142.250.185.238
United States
Click to see the 7 hidden entries
13.107.246.60
United States
104.16.125.175
United States
199.36.158.100
United States
239.255.255.250
Reserved
152.199.23.37
United States
142.250.186.77
United States
104.17.25.14
United States

Domains

Name IP Detection
cs1100.wpc.omegacdn.net
152.199.23.37
holy-sun-e797.harmony232.workers.dev
172.67.194.70
accounts.google.com
142.250.186.77
Click to see the 9 hidden entries
vaps.quatiappcn.pw
188.114.97.10
cdnjs.cloudflare.com
104.17.25.14
nanmmachineapcnds.web.app
199.36.158.100
part-0032.t-0009.t-msedge.net
13.107.246.60
workers.dev
104.18.40.50
clients.l.google.com
142.250.185.238
unpkg.com
104.16.125.175
clients2.google.com
0.0.0.0
aadcdn.msftauth.net
0.0.0.0

URLs

Name Detection
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas#/2
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas#/xc0mJmP6ydEkvCg3s5L-!@&LH84Fdvujw2I5C&!Iu1NoVelDrFYWPc0n&@!-j5EVZtm3fllyufXl7WBP0leU6hjIq1eZmjk0DLoYUssoIdAKbUQom1d-UhGzv6ZeTDZJk60He1zjX6b51v2aRxflDZ/kTWGnZ6KpUi0ZlKktEK9Md4lqN
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas2
Click to see the 83 hidden entries
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas)
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas#/cUjGMBBbEOAZ1A1trUW8e3VbW20C4UOpd0ehr
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas#/cUjGMBBbEOAZ1A1trUW8e3VbW20C4UOpd0ehrM4-!@&LH84Fdvujw2I5C&!Iu1NoVelDrFYWPc0n&@!-rIOkyagFeRrpfkpu863jviY06vtNzd0wl6bdqtgcBCiFkJBNFM2cjK60kHJsv1cStzrMuJluVaYTTZe83P3ipaSduZvypfp-R9Nl7wnyni6bRrZSlpVqmcL4vXfoyA5jqb8tt2Ttt99UqNWmQ5mVPvJ5gelcSZwaFn0pI9qAD2/wo12vkbsOpyYljv5qbHp741G76PIeZ6FtwtpdE5j9i8wetmbUtVaw21r1SGEL4JtTI
https://holy-sun-e797.harmony232.workers.dev/
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas
https://holy-sun-e797.harmony232.workers.dev/?bbre=xzodiszxas#Jjik8mbLYCdEaKzVGfB0
https://cdnjs.cloudflare.com/ajax/libs/vee-validate/2.0.0-rc.3/vee-validate.min.js
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/f
https://www.google.com/images/cleardot.gif
http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/H
http://www.aiim.org/pdfa/ns/schema#
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/imgs/microsoft_logo.svg
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/js/c0f5e0dd4f642062f92481ef2bb438191652375488.js
https://www.amazon.co.uk/Office-2016-Home-Student-Original/dp/B093kCCXWB1/ref=sr_1_7?crid=RFTEXHS50R
http://cipa.jp/exif/1.0/
https://sandbox.google.com/payments/v4/js/integrator.js
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/3dd3f0a4b26facac349e2acbdc6bb40bnbr1652375496.js
https://api.echosign.comgso
https://accounts.google.com/MergeSession
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/js/a3107e4d4ae0ea783cd1177c52f1e6301652375486.js
https://www.google.com
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/imgs/ellipsis_grey.svg
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/i
http://www.aiim.org/pdfa/ns/type#
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/957104c6b9b5615ff19f8784c7d27586.js
http://www.aiim.org/pdfe/ns/id/G
http://iptc.org/std/Iptc4xmpExt/2008-02-29/0
https://api.echosign.com
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/css/91003913e52edf331292b68b833ff0cdnbr1652375496.css
https://accounts.google.com
http://www.npes.org/pdfx/ns/id/
https://cdnjs.cloudflare.com/ajax/libs/vue-i18n/7.0.3/vue-i18n.min.js
http://www.aiim.org/pdfa/ns/extension/
https://apis.google.com
http://www.aiim.org/pdfa/ns/extension/p
https://ims-na1.adobelogin.comx
https://www.google.com/accounts/OAuthLogin?issueuberauth=1
http://www.aiim.org/pdfa/ns/id/n
https://unpkg.com/vue@2.6.11/dist/vue.min.js
https://www-googleapis-staging.sandbox.google.com
https://unpkg.com/lodash@4.17.4/lodash.min.js
https://clients2.google.com
https://vaps.quatiappcn.pw/627d3fc97d9c24192c2124f3.js
https://nanmmachineapcnds.web.app/nyrjthsfdzxxz/themes/css/3dd3f0a4b26facac349e2acbdc6bb40bnbr1652375496.css
https://holy-sun-e797.harmony232.workers.dev/
http://www.aiim.org/pdfa/ns/property#
https://dns.google
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
https://www.google.com/intl/en-US/chrome/blank.html
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/4x
https://ogs.google.com
http://ns.useplus.org/ldf/xmp/1.0/
https://cdnjs.cloudflare.com/ajax/libs/vuex/2.3.1/vuex.min.js
http://www.aiim.org/pdfa/ns/id/
http://iptc.org/std/Iptc4xmpExt/2008-02-29/P
http://iptc.org/std/Iptc4xmpExt/2008-02-29/
http://www.aiim.org/pdfa/ns/property#:
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
https://payments.google.com/payments/v4/js/integrator.js
http://iptc.org/std/Iptc4xmpCore/1.0/xmlns/
http://www.aiim.org/pdfe/ns/id/
https://www.google.com/images/x2.gif
https://www.google.com/images/dot2.gif
https://unpkg.com/vue-router@2.7.0/dist/vue-router.min.js
http://ns.useplus.org/ldf/xmp/1.0/=
https://aadcdn.msftauth.net/shared/1.0/content/images/signin-options_4e48046ce74f4b89d45037c90576bfac.svg
http://www.aiim.org/pdfa/ns/field#
https://unpkg.com/axios@0.16.1/dist/axios.min.js
http://cipa.jp/exif/1.0/Map_1
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/y
http://www.aiim.org/pdfa/ns/id/)
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/
https://clients2.googleusercontent.com
https://PrefSyncJob/com.adobe.acrobat.ADotCom/Resource/Sync/Upload/i:
http://www.quicktime.com.Acrobat
https://ims-na1.adobelogin.com
http://www.aiim.org/pdfa/ns/id/0
https://www.google.com/
https://cdnjs.cloudflare.com/ajax/libs/mobile-detect/1.3.6/mobile-detect.min.js
https://clients2.google.com/service/update2/crx

Dropped files

Name File Type Hashes Detection
C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0
data
#
Click to see the 97 hidden entries
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0ace9ee3d914a5c0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\3a4ae3940784292a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\71febec55d5c75cd_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\86b8040b7132b608_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c159cc5880890bc_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8c84d92a9dbce3e0_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\91cec06bb2836fa5_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\927a1596c37ebe5e_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\92c56fa2a6c4d5ba_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\983b7a3da8f39a46_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf0ac66ae1eb4a7f_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\cf3e34002cde7e9c_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d449e58cb15daaf1_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d88192ac53852604_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\de789e80edd740d6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f4a0d4ca2f3b95da_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f941376b2efdd6e6_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f971b7eda7fa05c3_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fd17b2d8331c91e8_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fdd733564de6fbcb_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\febb41df4ea2b63a_0
data
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\temp-index
Maple help database
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\the-real-index (copy)
Maple help database
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
ASCII text
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Visited Links
data
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-220513233011Z-256.bmp
PC bitmap, Windows 3.x format, 164 x -114 x 32
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages
SQLite 3.x database, last written using SQLite version 3024000
#
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
SQLite Rollback Journal
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache.bin
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\054af81c-bda0-4ab4-94f3-36a7dd7755ee.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\0a2c07e7-7b57-476c-9c7b-840de8aee8bb.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\31cb003b-8570-4ed7-8c9e-99b4d8b3dc25.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\39058e36-dcd9-49a8-b9ea-0bdf8c396614.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\4ffc3edd-2302-4ac4-a69a-bb3e5bf6cee1.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\7f023d9d-0e1f-4701-9cc5-d59da7ab631b.tmp
SysEx File -
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\823bd28e-2f34-4b0e-b30b-967fdfddbf04.tmp
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\8d35d5ce-46b2-4596-b182-28840128da20.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\93ab8163-43de-4f8d-b5d9-a68db876b53a.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\1af9bf5c-bfd1-4c4c-a066-e1854ca461c6.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\33c57a0d-2917-43c0-bac0-7e5284682ffe.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\384d4146-ae84-4446-a567-a7b33aa2487a.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\58cbff26-8a06-4725-afd9-ea57a186fd29.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\5905fd16-373b-427c-a525-fe3ebf5c5b8d.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\627f1063-9cbd-460f-a0f4-12c5a49b3059.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\8cddd485-59a3-4a45-a755-51788feeb07b.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.6_0\_metadata\computed_hashes.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\000003.log
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB\LOG.old (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
zlib compressed data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Preferences (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences (copy)
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\3b407d31-7fd1-4a89-9d15-68b4bcc58f42.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\gfdkimpbcpahaombhbimeihdjnejgicl\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\3a66a687-1c3a-4bd2-9992-2bfb992fbdef.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache\data_1
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network Persistent State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\a03fb4a3-1ff0-4bd2-a52b-2b071e9aae57.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\d6733edf-04fa-4b23-9195-a01a6d0e4982.tmp
UTF-8 Unicode text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000004.dbtmp
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT (copy)
ASCII text
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\fdfe3599-b56d-46c5-bfff-7013c7b0f23e.tmp
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State (copy)
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\Module Info Cache (copy)
data
#
C:\Users\user\AppData\Local\Google\Chrome\User Data\a064ff61-728e-406f-9544-e4b91cf3f191.tmp
data
#
C:\Users\user\AppData\Local\Temp\32e6d00c-8836-498f-abc6-66b41373c34b.tmp
very short file (no magic)
#
C:\Users\user\AppData\Local\Temp\5672_1945570872\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\5672_1945570872\download_file_types.pb
data
#
C:\Users\user\AppData\Local\Temp\5672_1945570872\manifest.fingerprint
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\5672_1945570872\manifest.json
ASCII text
#
C:\Users\user\AppData\Local\Temp\5672_638631764\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
#
C:\Users\user\AppData\Local\Temp\5672_638631764\manifest.fingerprint
ASCII text, with no line terminators
#
C:\Users\user\AppData\Local\Temp\5672_638631764\manifest.json
ASCII text
#
C:\Users\user\AppData\Local\Temp\5672_638631764\ssl_error_assistant.pb
data
#
C:\Users\user\AppData\Local\Temp\5672_862278569\_metadata\verified_contents.json
ASCII text, with very long lines, with no line terminators
#