IOC Report
https://rmshg.amplified.training/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon May 6 15:41:50 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon May 6 15:41:50 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 09:52:18 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon May 6 15:41:50 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon May 6 15:41:50 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon May 6 15:41:50 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 212
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x332, components 3
dropped
Chrome Cache Entry: 213
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 1024x1024, components 3
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (29149), with CRLF line terminators
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (1224), with no line terminators
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (1787), with no line terminators
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (2531), with no line terminators
downloaded
Chrome Cache Entry: 218
ASCII text, with very long lines (29149), with CRLF line terminators
dropped
Chrome Cache Entry: 219
JSON data
downloaded
Chrome Cache Entry: 220
ASCII text, with very long lines (2970)
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (400), with no line terminators
downloaded
Chrome Cache Entry: 222
PNG image data, 479 x 320, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 223
PNG image data, 419 x 320, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 224
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 800x500, components 3
dropped
Chrome Cache Entry: 225
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (4269), with no line terminators
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (65356)
downloaded
Chrome Cache Entry: 228
ASCII text, with very long lines (19781), with no line terminators
downloaded
Chrome Cache Entry: 229
ASCII text, with very long lines (593), with no line terminators
downloaded
Chrome Cache Entry: 230
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 231
PNG image data, 480 x 319, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 232
PNG image data, 479 x 320, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 233
PNG image data, 480 x 219, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 234
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 235
ASCII text
downloaded
Chrome Cache Entry: 236
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 237
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 238
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 2200x945, components 3
dropped
Chrome Cache Entry: 239
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 240
PNG image data, 179 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 241
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (30175), with no line terminators
downloaded
Chrome Cache Entry: 243
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 244
ASCII text, with very long lines (1848), with no line terminators
downloaded
Chrome Cache Entry: 245
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 246
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 2200x945, components 3
downloaded
Chrome Cache Entry: 247
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 248
ASCII text, with very long lines (789)
downloaded
Chrome Cache Entry: 249
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 250
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 1024x1024, components 3
dropped
Chrome Cache Entry: 251
Unicode text, UTF-8 text, with very long lines (64800), with no line terminators
downloaded
Chrome Cache Entry: 252
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 253
GIF image data, version 89a, 160 x 78
downloaded
Chrome Cache Entry: 254
JSON data
dropped
Chrome Cache Entry: 255
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 256
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 257
Web Open Font Format, TrueType, length 20792, version 1.1
downloaded
Chrome Cache Entry: 258
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (4553), with no line terminators
downloaded
Chrome Cache Entry: 260
PNG image data, 479 x 319, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 261
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 2200x945, components 3
dropped
Chrome Cache Entry: 262
PNG image data, 178 x 72, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 263
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 264
ASCII text, with very long lines (7543), with no line terminators
downloaded
Chrome Cache Entry: 265
PNG image data, 480 x 320, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 266
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 267
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (32026), with CRLF line terminators
downloaded
Chrome Cache Entry: 269
Web Open Font Format (Version 2), TrueType, length 28600, version 1.0
downloaded
Chrome Cache Entry: 270
PNG image data, 429 x 286, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 271
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 272
Web Open Font Format, TrueType, length 20216, version 1.1
downloaded
Chrome Cache Entry: 273
PNG image data, 480 x 320, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 274
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 275
ASCII text, with very long lines (58940), with CRLF line terminators
downloaded
Chrome Cache Entry: 276
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 277
GIF image data, version 89a, 96 x 200
dropped
Chrome Cache Entry: 278
ASCII text, with very long lines (9179), with no line terminators
downloaded
Chrome Cache Entry: 279
Web Open Font Format (Version 2), TrueType, length 33092, version 1.0
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (43395), with no line terminators
downloaded
Chrome Cache Entry: 281
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 282
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 283
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 284
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=18, height=2336, bps=230, compression=none, PhotometricIntepretation=RGB, manufacturer=Canon, model=Canon EOS 20D, orientation=upper-left, width=3504], baseline, precision 8, 1254x836, components 3
downloaded
Chrome Cache Entry: 285
HTML document, ASCII text, with very long lines (1238)
downloaded
Chrome Cache Entry: 286
gzip compressed data, was "login-558.min.js", last modified: Tue Mar 12 10:12:06 2024, from Unix, original size modulo 2^32 418677
downloaded
Chrome Cache Entry: 287
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 288
ASCII text
downloaded
Chrome Cache Entry: 289
gzip compressed data, was "main-558.min.js", last modified: Tue Mar 12 10:12:06 2024, from Unix, original size modulo 2^32 990709
downloaded
Chrome Cache Entry: 290
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 291
PNG image data, 1170 x 450, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 292
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=10, description=Happy people drinking beer at brewery bar out doors - Multicultural life style concept with genuine friends enjoying time toget, manufacturer=SONY, model=ILCE-7M3, orientation=upper-left, xresolution=344, yresolution=352, resolutionunit=2, software=Adobe Photoshop Lightroom Classic 11.0 (Windows), datetime=2021:10:27 15:41:59], baseline, precision 8, 1254x836, components 3
dropped
Chrome Cache Entry: 293
PNG image data, 220 x 38, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 294
Web Open Font Format (Version 2), TrueType, length 33092, version 1.0
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (27287), with CRLF line terminators
downloaded
Chrome Cache Entry: 296
Web Open Font Format, TrueType, length 27376, version 1.1
downloaded
Chrome Cache Entry: 297
ASCII text, with very long lines (3302), with CRLF line terminators
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 299
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 300
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 2200x945, components 3
downloaded
Chrome Cache Entry: 301
GIF image data, version 89a, 160 x 78
dropped
Chrome Cache Entry: 302
ASCII text, with very long lines (3840), with no line terminators
downloaded
Chrome Cache Entry: 303
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1900x700, components 3
downloaded
Chrome Cache Entry: 304
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 305
gzip compressed data, was "formenhancements-558.min.js", last modified: Tue Mar 12 10:12:08 2024, from Unix, original size modulo 2^32 646
downloaded
Chrome Cache Entry: 306
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 307
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1900x700, components 3
dropped
Chrome Cache Entry: 308
ASCII text, with very long lines (30406)
downloaded
Chrome Cache Entry: 309
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 310
ASCII text, with very long lines (4112)
downloaded
Chrome Cache Entry: 311
JSON data
downloaded
Chrome Cache Entry: 312
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 313
PNG image data, 479 x 319, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 314
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 315
Unicode text, UTF-8 text, with very long lines (1202)
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (7288), with no line terminators
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (13479)
downloaded
Chrome Cache Entry: 318
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 319
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 320
PNG image data, 479 x 320, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 321
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 322
ASCII text, with very long lines (1071)
downloaded
Chrome Cache Entry: 323
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 324
ASCII text, with very long lines (4610)
downloaded
Chrome Cache Entry: 325
PNG image data, 480 x 320, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 326
ASCII text, with very long lines (31165)
downloaded
Chrome Cache Entry: 327
ASCII text, with very long lines (1822)
downloaded
Chrome Cache Entry: 328
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 329
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 330
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 331
JSON data
downloaded
Chrome Cache Entry: 332
ASCII text, with very long lines (65446), with CRLF line terminators
downloaded
Chrome Cache Entry: 333
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 334
PNG image data, 220 x 38, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 335
ASCII text, with very long lines (884)
downloaded
Chrome Cache Entry: 336
ASCII text, with very long lines (4847)
downloaded
Chrome Cache Entry: 337
PNG image data, 178 x 72, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 338
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x332, components 3
dropped
Chrome Cache Entry: 339
PNG image data, 234 x 82, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 340
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 341
ASCII text, with very long lines (1197), with no line terminators
downloaded
Chrome Cache Entry: 342
ASCII text, with very long lines (64569), with CRLF line terminators
downloaded
Chrome Cache Entry: 343
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 344
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 345
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 346
ASCII text, with very long lines (31996)
downloaded
Chrome Cache Entry: 347
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 348
ASCII text, with very long lines (9949), with no line terminators
downloaded
Chrome Cache Entry: 349
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=11, manufacturer=Canon, model=Canon EOS 5DS, orientation=upper-left, xresolution=166, yresolution=174, resolutionunit=2, software=Adobe Photoshop CS6 (Macintosh), datetime=2016:06:25 13:39:44], baseline, precision 8, 1254x836, components 3
dropped
Chrome Cache Entry: 350
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 351
Web Open Font Format, TrueType, length 306868, version 1.0
downloaded
Chrome Cache Entry: 352
JSON data
dropped
Chrome Cache Entry: 353
ASCII text, with very long lines (10917)
downloaded
Chrome Cache Entry: 354
PNG image data, 419 x 320, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 355
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 356
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 800x500, components 3
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (8089), with CRLF line terminators
downloaded
Chrome Cache Entry: 358
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 359
Unicode text, UTF-8 text, with very long lines (65302), with CRLF line terminators
downloaded
Chrome Cache Entry: 360
ASCII text, with very long lines (31591), with no line terminators
downloaded
Chrome Cache Entry: 361
JSON data
downloaded
Chrome Cache Entry: 362
PNG image data, 479 x 320, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 363
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 2200x945, components 3
dropped
Chrome Cache Entry: 364
JSON data
dropped
Chrome Cache Entry: 365
PNG image data, 429 x 286, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 366
PNG image data, 479 x 319, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 367
ASCII text, with very long lines (55687), with CRLF line terminators
dropped
Chrome Cache Entry: 368
JSON data
downloaded
Chrome Cache Entry: 369
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 1024x1024, components 3
dropped
Chrome Cache Entry: 370
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=10, description=Happy people drinking beer at brewery bar out doors - Multicultural life style concept with genuine friends enjoying time toget, manufacturer=SONY, model=ILCE-7M3, orientation=upper-left, xresolution=344, yresolution=352, resolutionunit=2, software=Adobe Photoshop Lightroom Classic 11.0 (Windows), datetime=2021:10:27 15:41:59], baseline, precision 8, 1254x836, components 3
downloaded
Chrome Cache Entry: 371
JSON data
dropped
Chrome Cache Entry: 372
ASCII text, with very long lines (41626), with no line terminators
downloaded
Chrome Cache Entry: 373
ASCII text, with very long lines (64381)
downloaded
Chrome Cache Entry: 374
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x332, components 3
downloaded
Chrome Cache Entry: 375
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 376
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 377
Web Open Font Format (Version 2), TrueType, length 31972, version 1.0
downloaded
Chrome Cache Entry: 378
Unicode text, UTF-8 text, with very long lines (24292)
downloaded
Chrome Cache Entry: 379
ASCII text, with very long lines (631)
downloaded
Chrome Cache Entry: 380
JSON data
downloaded
Chrome Cache Entry: 381
Web Open Font Format, TrueType, length 20964, version 1.1
downloaded
Chrome Cache Entry: 382
PNG image data, 480 x 320, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 383
ASCII text, with very long lines (9156), with no line terminators
downloaded
Chrome Cache Entry: 384
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 385
GIF image data, version 89a, 96 x 200
downloaded
Chrome Cache Entry: 386
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 387
PNG image data, 480 x 320, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 388
ASCII text, with very long lines (55687), with CRLF line terminators
downloaded
Chrome Cache Entry: 389
PNG image data, 480 x 319, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 390
HTML document, Unicode text, UTF-8 text, with very long lines (5737), with CRLF line terminators
downloaded
Chrome Cache Entry: 391
ASCII text, with very long lines (56412), with no line terminators
downloaded
Chrome Cache Entry: 392
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=11, manufacturer=Canon, model=Canon EOS 5DS, orientation=upper-left, xresolution=166, yresolution=174, resolutionunit=2, software=Adobe Photoshop CS6 (Macintosh), datetime=2016:06:25 13:39:44], baseline, precision 8, 1254x836, components 3
downloaded
Chrome Cache Entry: 393
ASCII text, with very long lines (8089), with CRLF line terminators
dropped
Chrome Cache Entry: 394
ASCII text, with very long lines (32000), with CRLF line terminators
downloaded
Chrome Cache Entry: 395
ASCII text, with very long lines (6576)
downloaded
Chrome Cache Entry: 396
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 397
PNG image data, 234 x 82, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 398
PNG image data, 479 x 319, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 399
JSON data
dropped
Chrome Cache Entry: 400
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 401
ASCII text, with very long lines (17691)
downloaded
Chrome Cache Entry: 402
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 403
ASCII text, with very long lines (631)
downloaded
Chrome Cache Entry: 404
JSON data
dropped
Chrome Cache Entry: 405
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 406
HTML document, ASCII text, with very long lines (9462), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 407
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 408
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 409
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 410
PNG image data, 480 x 219, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 411
ASCII text, with very long lines (57196)
downloaded
Chrome Cache Entry: 412
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 413
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 414
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x332, components 3
dropped
Chrome Cache Entry: 415
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 2200x945, components 3
downloaded
Chrome Cache Entry: 416
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 417
PNG image data, 179 x 64, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 418
ASCII text, with very long lines (6454), with CR line terminators
downloaded
Chrome Cache Entry: 419
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "Compressed by jpeg-recompress", progressive, precision 8, 1024x1024, components 3
downloaded
Chrome Cache Entry: 420
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=18, height=2336, bps=230, compression=none, PhotometricIntepretation=RGB, manufacturer=Canon, model=Canon EOS 20D, orientation=upper-left, width=3504], baseline, precision 8, 1254x836, components 3
dropped
Chrome Cache Entry: 421
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 422
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 423
ASCII text, with very long lines (51324)
downloaded
Chrome Cache Entry: 424
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x332, components 3
downloaded
Chrome Cache Entry: 425
PNG image data, 480 x 320, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 426
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 427
PNG image data, 1170 x 450, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 428
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x332, components 3
downloaded
Chrome Cache Entry: 429
ASCII text, with very long lines (28306), with no line terminators
downloaded
Chrome Cache Entry: 430
Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
downloaded
Chrome Cache Entry: 431
ASCII text, with very long lines (2846), with CRLF line terminators
downloaded
Chrome Cache Entry: 432
ASCII text, with very long lines (5607), with CRLF line terminators
downloaded
There are 218 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2460,i,14899353169943493930,12871650326961900512,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rmshg.amplified.training/"

URLs

Name
IP
Malicious
https://rmshg.amplified.training/
http://greensock.com/club/
unknown
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/google-review.webp
13.107.246.41
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/logo-white.webp
13.107.246.41
https://d3j0t7vrtr92dk.cloudfront.net/images/loading-small.gif
18.173.145.206
https://fortis-site.com/wp-content/uploads/2018/04/trusted-choice-logo-234x62.png
104.21.49.115
https://fortis-site.com/wp-content/cache/min/1/wp-content/plugins/parallax_video_backgrounds_vc/assets/css/animate-7490004261602226c037e62260c39c8e.css
104.21.49.115
https://ampcid.google.com/v1/publisher:getClientId
unknown
https://rmshg.amplified.training/pages/themes/default/css/toastr.min.css?v=558
3.217.205.239
about:blank
https://rmshg.amplified.training/pages/themes/default/css/font/Open_Sans_700.woff
3.217.205.239
https://fortis-site.com/wp-content/plugins/revslider/public/assets/js/jquery.themepunch.tools.min.js?ver=5.4.6.4
104.21.49.115
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/favicon.ico?v=014020240840136914499
13.107.246.41
https://rmshg.amplified.training/pages/themes/default/css/font/Open_Sans_300.woff
3.217.205.239
https://fortis-site.com/wp-content/cache/min/1/wp-content/themes/fortuna/stylesheets/grid-896199530817a6736ba181d5858c9463.css
104.21.49.115
https://fortis-site.com/wp-content/plugins/gravityforms/js/jquery.maskedinput.min.js?ver=2.3.4
104.21.49.115
https://rmshg.amplified.training/
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/google
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://support.google.com/recaptcha/#6175971
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/js/recent-blo
unknown
https://www.gstatic.c..?/recaptcha/releases/V6_85qpc2Xf2sbe3xTnRte7m/recaptcha__.
unknown
https://fortis-site.com/#breadcrumb
unknown
https://fortis-site.com/wp-content/cache/min/1/wp-content/plugins/parallax_video_backgrounds_vc/assets/js/jparallax-7d021341b99ed81aaf7377dd90a3097a.js
104.21.49.115
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/js/form-validation.js?v=145820231158259990808
13.107.246.41
https://search.google.com/local/writereview?placeid=ChIJJ8qJHn19wokR6lUxh4-0Z_o
unknown
https://stats.g.doubleclick.net/j/collect
unknown
https://fortis-site.com/wp-content/cache/min/1/wp-content/plugins/parallax_video_backgrounds_vc/assets/css/background-style-0f44168bd3d23e9e7fdbf608efe91d3c.css
104.21.49.115
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/logo-f
unknown
https://fortis-site.com/wp-content/uploads/hm_custom_css_js/custom.css?ver=1522749326
104.21.49.115
https://d3j0t7vrtr92dk.cloudfront.net/images/empty_states/noCatalog.svg
18.173.145.206
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/css/header.cs
unknown
https://support.google.com/recaptcha
unknown
https://d3j0t7vrtr92dk.cloudfront.net/rmshg/1576790499_slicertraining.png
18.173.145.206
https://fortis-site.com/wp-content/uploads/2018/10/consulting2.jpg
104.21.49.115
https://fortis-site.com/wp-content/cache/min/1/wp-content/plugins/parallax_video_backgrounds_vc/assets/css/style-b40bed06cbf66bb43c63a21c111befe2.css
104.21.49.115
https://fortis-site.com/#webpage
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/logo-w
unknown
https://ka-p.fontawesome.com/assets/00bf593261/112787936/kit.css?token=00bf593261);
unknown
https://fortis-site.com/commercial-umbrella-insurance-small-business/
unknown
https://api.userway.org/api/tunings/D0JSP1avgg
44.234.218.238
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/js/common.js?v=082720230227518133675
13.107.246.41
https://fortis-site.com/wp-content/cache/min/1/font-awesome/4.7.0/css/font-awesome.min-f3c95ec7959d6de503c73e1f51f186af.css
104.21.49.115
http://labs.skinkers.com/touchSwipe/
unknown
https://fortis-site.com/wp-content/plugins/gravityforms/images/spinner.gif
unknown
https://fortis-site.com/wp-content/plugins/gravityforms/css/browsers.min.css?ver=2.3.4
104.21.49.115
https://www.apache.org/licenses/
unknown
https://rmshg.amplified.training/index
https://schema.org
unknown
https://fortis-site.com/wp-content/plugins/gravityforms/css/formsmain.min.css?ver=2.3.4
104.21.49.115
https://rmshg.amplified.training/pages/images/rating/star-solid.svg
3.217.205.239
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://fortis-site.com/refer-friend-help-us-support-charity-cc4c/
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/js/jquery-3.7.0.min.js?v=081420231114354913937
13.107.246.41
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/logo.w
unknown
https://fortis-site.com/wp-content/cache/min/1/ajax/libs/jquery-easing/1.4.1/jquery.easing.min-5fbd6a69fa350237d507240b81a6abed.js
104.21.49.115
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/servic
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/css/owl.carousel.min.css?v=082020231220461627960
13.107.246.41
https://cdn.userway.org/remediation/2024-04-30-12-14-34/free/remediation-tool-free.js?ts=1714479274721
89.187.173.23
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/js/owl.carousel.min.js?v=081420231114354913921
13.107.246.41
https://oss.maxcdn.com/libs/respond.js/1.4.2/respond.min.js
unknown
https://rmshg.amplified.training/pages/scripts/lib/formenhancements-558.min.js
3.217.205.239
https://cdnjs.cloudflare.com/ajax/libs/jquery-validation-unobtrusive/3.2.12/jquery.validate.unobtrusive.min.js
104.17.24.14
https://goo.gl/maps/whR4WcLdR422
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/css/home.css?v=015820240858469386724
13.107.246.41
https://cdn.userway.org/
unknown
https://fortis-site.com/wp-content/plugins/google-analytics-for-wordpress/assets/js/frontend-gtag.min.js?ver=7.18.0
104.21.49.115
https://fortis-site.com/wp-content/uploads/2018/10/home2.jpg
unknown
https://fortis-site.com/wp-content/uploads/2017/12/Logo-179x64.png
104.21.49.115
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/testim
unknown
https://rmshg.amplified.training/pages/scripts/lib/main-558.min.js
3.217.205.239
https://www.istockphoto.com/photo/license-gm1350660376-?utm_medium=organic&utm_source=google&amp
unknown
https://d3j0t7vrtr92dk.cloudfront.net/amplifiedhr/1563760228_ProtectYourAssets.png
18.173.145.206
https://www.youtube.com/channel/UCRgLZ5OmT9gI7sGPSEUnckA/feed?view_as=public
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/css/home.css?
unknown
https://rmshg.amplified.training/pages/scripts/lib/login-558.min.js
3.217.205.239
https://fortis-site.com/wp-content/cache/min/1/wp-content/plugins/parallax_video_backgrounds_vc/assets/js/jquery.appear-01c0b6095409fd502bc0f13168cfdd74.js
104.21.49.115
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/istock-1350660376.jpg
13.107.246.41
https://cdn77.api.userway.org/api/img-dscr/v2/D0JSP1avgg/3527403/RLqwMG7OTpTSzPtD/alts.json?dto=%7B%22sorted%22%3A%5B%7B%22src%22%3A%22https%3A%2F%2Fcdn.stratospherewebsites.com%2Fsource%2Fsites%2F3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b%2Fimages%2Flogo.webp%22%2C%22alt%22%3A%22RMS%20Hospitality%20Group%22%2C%22dir%22%3A%22RO%22%7D%5D%2C%22tier%22%3A%22FREE_QUOTA_TIER%22%7D
89.187.173.22
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/logo.webp
13.107.246.41
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/night-
unknown
https://cloud.google.com/contact
unknown
https://fortis-site.com/wp-content/uploads/2017/12/slider3.jpg
104.21.49.115
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/covid-bg.svg
13.107.246.41
http://daneden.me/animate
unknown
https://userway.org
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/program-bg.jpg
13.107.246.41
https://d3j0t7vrtr92dk.cloudfront.net/rmshg/1576789110_slipstripsfallsmall.png
18.173.145.206
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/e0de52
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/a581c3
unknown
https://cdn.stratospherewebsites.com/source/sites/3c517dd6-6fa6-438a-8d47-e7a9cdca3e3b/images/adult-
unknown
https://fortis-site.com/wp-content/cache/min/1/wp-content/plugins/parallax_video_backgrounds_vc/assets/js/custom-d568b807ee8bd8c276f949ed58c0dcee.js
104.21.49.115
https://d3j0t7vrtr92dk.cloudfront.net/rmshg/1576583896_newRMSbanner.png
18.173.145.206
https://www.google.com/recaptcha/api2/
unknown
https://fortis-site.com/wp-content/uploads/2018/10/about2.jpg
104.21.49.115
https://rmshg.amplified.training/pages/themes/default/css/images/icons.gif
3.217.205.239
https://www.linkedin.com/company/9205751?trk=tyah&trkInfo=idx%3A2-2-3%2CtarId%3A1424725448600%2C
unknown
https://cdn.userway.org/widgetapp/2024-04-30-12-14-34/widget_app_base_1714479274721.js
89.187.173.23
http://materializecss.com)
unknown
https://rmshg.amplified.training/pages/images/rating/star-solid-grey.svg
3.217.205.239
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
jsdelivr.map.fastly.net
151.101.65.229
1667503734.rsc.cdn77.org
89.187.173.23
1784939676.rsc.cdn77.org
89.187.173.22
maxcdn.bootstrapcdn.com
104.18.11.207
googletagmanager.com
142.250.189.136
rmshg.talentlms.com
3.217.205.239
api.userway.org
44.234.218.238
d3j0t7vrtr92dk.cloudfront.net
18.173.145.206
part-0013.t-0009.t-msedge.net
13.107.246.41
cdnjs.cloudflare.com
104.17.24.14
www.google.com
142.250.217.196
fortis-site.com
104.21.49.115
fortissite.wpengine.com
35.188.55.83
cdn.jsdelivr.net
unknown
kit.fontawesome.com
unknown
www.rmshg.com
unknown
cdn77.api.userway.org
unknown
cdn.userway.org
unknown
rmshg.amplified.training
unknown
cdn.stratospherewebsites.com
unknown
ka-p.fontawesome.com
unknown
There are 11 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.41
part-0013.t-0009.t-msedge.net
United States
44.234.218.238
api.userway.org
United States
142.250.64.164
unknown
United States
104.21.49.115
fortis-site.com
United States
3.217.205.239
rmshg.talentlms.com
United States
89.187.173.23
1667503734.rsc.cdn77.org
Czech Republic
89.187.173.22
1784939676.rsc.cdn77.org
Czech Republic
104.17.24.14
cdnjs.cloudflare.com
United States
192.178.50.68
unknown
United States
18.173.145.206
d3j0t7vrtr92dk.cloudfront.net
United States
151.101.65.229
jsdelivr.map.fastly.net
United States
35.188.55.83
fortissite.wpengine.com
United States
142.250.189.136
googletagmanager.com
United States
104.18.11.207
maxcdn.bootstrapcdn.com
United States
192.168.2.11
unknown
unknown
34.208.13.132
unknown
United States
142.250.217.196
www.google.com
United States
239.255.255.250
unknown
Reserved
18.173.145.84
unknown
United States
89.187.173.14
unknown
Czech Republic
There are 10 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://rmshg.amplified.training/
https://rmshg.amplified.training/index
https://rmshg.amplified.training/catalog
https://rmshg.amplified.training/catalog
https://www.rmshg.com/
https://www.rmshg.com/
https://www.rmshg.com/
https://www.rmshg.com/
https://www.rmshg.com/
https://www.rmshg.com/
https://www.rmshg.com/
about:blank
https://fortis-site.com/
https://fortis-site.com/
https://fortis-site.com/
https://fortis-site.com/
https://fortis-site.com/
https://fortis-site.com/
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6Ld7KXUUAAAAAAknjFUvMThz44a8gU2bvUq0YFw-&co=aHR0cHM6Ly9mb3J0aXMtc2l0ZS5jb206NDQz&hl=en&v=V6_85qpc2Xf2sbe3xTnRte7m&theme=light&size=normal&cb=fwww2nyjhy7o
https://www.google.com/recaptcha/api2/bframe?hl=en&v=V6_85qpc2Xf2sbe3xTnRte7m&k=6Ld7KXUUAAAAAAknjFUvMThz44a8gU2bvUq0YFw-
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6Ld7KXUUAAAAAAknjFUvMThz44a8gU2bvUq0YFw-&co=aHR0cHM6Ly9mb3J0aXMtc2l0ZS5jb206NDQz&hl=en&v=V6_85qpc2Xf2sbe3xTnRte7m&theme=light&size=normal&cb=ppya948ml626
There are 11 hidden doms, click here to show them.