Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
IDM Trial Reset.exe

Overview

General Information

Sample name:IDM Trial Reset.exe
Analysis ID:1433723
MD5:064f82094ae6a6e22c28a6f1ef868a26
SHA1:e034cf1fa855eef53fd46a5ec213ada99e2ece19
SHA256:a2d2b22cd0d5628976eb5996a8b20f3b5ac468907910dbc3f826f1069d435587
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Connects to a pastebin service (likely for C&C)
Connects to many different domains
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Sleep loop found (likely to delay execution)
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • IDM Trial Reset.exe (PID: 7072 cmdline: "C:\Users\user\Desktop\IDM Trial Reset.exe" MD5: 064F82094AE6A6E22C28A6F1EF868A26)
    • chrome.exe (PID: 4204 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://bit.ly/IDMresetTrialForum MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
      • chrome.exe (PID: 6416 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1856,i,13094607731974236556,7479999263952262712,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
  • cleanup
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: http://stvwell.online/api/v1/px?xmlid=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pBAvira URL Cloud: Label: malware
Source: http://stvwell.online/api/v1/pxcheck?impId=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pB&minfo=eyJjb29raWVEaXNhYmxlZCI6ZmFsc2UsInVhIjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV2luNjQ7IHg2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzExNy4wLjAuMCBTYWZhcmkvNTM3LjM2IiwiaWZyYW1lIjpmYWxzZSwiZGV2aWNlUGl4ZWxSYXRpbyI6MSwid25kTG9jSHJlZiI6Imh0dHA6Ly9zdHZ3ZWxsLm9ubGluZS9hcGkvdjEvcHg/eG1saWQ9cUZnWEQzY0UxTGFTYlR4OXBsYUVOVmdBNjhXNnpIZVRJcDRMODVwQiIsImRldmljZVNyZWVuU2l6ZSI6Ijk4NHgxMjgwIiwiZGV2aWNlV2luZG93U2l6ZSI6IjkwN3gxMjgwIiwid25kMnNyY1JhdGlvTHdyMDYiOmZhbHNlLCJlZmZlY3RpdmVUeXBlIjoiNGciLCJpc0JvdCI6Im9mZiJ9Avira URL Cloud: Label: malware
Source: https://acdn.adnxs.com/dmp/async_usersync.htmlHTTP Parser: No favicon
Source: https://autoloversdigest.com/7-fastest-police-cars-in-the-world/?click_id=449f8753-6095-4fcc-b684-958641bbce4cHTTP Parser: No favicon
Source: https://acdn.adnxs.com/dmp/async_usersync.html?gdpr=0&seller_id=8822&pub_id=2335678HTTP Parser: No favicon
Source: https://autoloversdigest.com/what-is-the-best-first-car-for-a-teenager/?click_id=5af72324-a94d-4060-9e5c-21b1d768014aHTTP Parser: No favicon
Source: IDM Trial Reset.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: unknownHTTPS traffic detected: 104.20.3.235:443 -> 192.168.2.16:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49771 version: TLS 1.2

Networking

barindex
Source: unknownDNS query: name: pastebin.com
Source: unknownDNS query: name: pastebin.com
Source: unknownDNS query: name: pastebin.com
Source: unknownDNS query: name: pastebin.com
Source: unknownNetwork traffic detected: DNS query count 37
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /IDMresetTrialForum HTTP/1.1Host: bit.lyConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.html HTTP/1.1Host: www.vn-zoom.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.html?usid=25&utid=6592403207 HTTP/1.1Host: ww1.vn-zoom.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /f247/img.sedoparking.com/images/js_preloader.gif HTTP/1.1Host: ww1.vn-zoom.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ww1.vn-zoom.com/f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.html?usid=25&utid=6592403207Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /search/tsc.php?200=MzM5Nzk0MzU3&21=ODEuMTgxLjYyLjkw&681=MTcxNDQyNjc2MDA3N2YyYzY5YTI0NWJjMDhjNGI1NzczZTYwNmRiNDli&crc=ebe561bc8f3c9c5a9d9842b9df4b344ca64fa44d&cv=1 HTTP/1.1Host: ww1.vn-zoom.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Referer: http://ww1.vn-zoom.com/f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.html?usid=25&utid=6592403207Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /templates/logos/sedo_logo.png HTTP/1.1Host: img.sedoparking.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Referer: http://ww1.vn-zoom.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /search/redirect.php?f=http%3A%2F%2Fxml.sedodna.com%2Fclick%3Fi%3DuO-fsya%2AkQc_0&v=MzkwZmRhYjAxOTZiNzNhYzVhM2M5OWY5MDNkMjk0NzMJMQl3dzEudm4tem9vbS5jb202NjMwMTM4Nzk0MTFmOC4xMDY0MDM5NQl3dzEudm4tem9vbS5jb202NjMwMTM4Nzk0MTY4OC40NTE4NjgyNwkxNzE0NDI2NzYwCWFkXzYzXzA%3D&l=OAkwMDRlM2UzOWFmM2ZjMDQ4NWZmMDI5NWNhYzg2NTU1NgkwCTEzCTAJZDIzYzQ3NDM4ZjAxNjRmODJlMzI4NWQyNzQwMDE5M2QJMzM5Nzk0MzU3CXZuLXpvb20JMAk2Mwk1CTU5CTE3MTQ0MjY3NjAJMC4wMDAyOQlOCTAJMAkwCTEyMDUJOTIyMjA4MDAJODEuMTgxLjYyLjkwCTA%253D HTTP/1.1Host: ww1.vn-zoom.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://ww1.vn-zoom.com/f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.html?usid=25&utid=6592403207Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /search/tcerider.php?f=http%3A%2F%2Fxml.sedodna.com%2Fclick%3Fi%3DuO-fsya%2AkQc_0&v=MzkwZmRhYjAxOTZiNzNhYzVhM2M5OWY5MDNkMjk0NzMJMQl3dzEudm4tem9vbS5jb202NjMwMTM4Nzk0MTFmOC4xMDY0MDM5NQl3dzEudm4tem9vbS5jb202NjMwMTM4Nzk0MTY4OC40NTE4NjgyNwkxNzE0NDI2NzYwCWFkXzYzXzA%3D&l=OAkwMDRlM2UzOWFmM2ZjMDQ4NWZmMDI5NWNhYzg2NTU1NgkwCTEzCTAJZDIzYzQ3NDM4ZjAxNjRmODJlMzI4NWQyNzQwMDE5M2QJMzM5Nzk0MzU3CXZuLXpvb20JMAk2Mwk1CTU5CTE3MTQ0MjY3NjAJMC4wMDAyOQlOCTAJMAkwCTEyMDUJOTIyMjA4MDAJODEuMTgxLjYyLjkwCTA%253D HTTP/1.1Host: ww1.vn-zoom.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://ww1.vn-zoom.com/f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.html?usid=25&utid=6592403207Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /templates/logos/sedo_logo.png HTTP/1.1Host: img.sedoparking.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /search/tsc.php?200=MzM5Nzk0MzU3&21=ODEuMTgxLjYyLjkw&681=MTcxNDQyNjc2MDA3N2YyYzY5YTI0NWJjMDhjNGI1NzczZTYwNmRiNDli&crc=ebe561bc8f3c9c5a9d9842b9df4b344ca64fa44d&cv=1 HTTP/1.1Host: ww1.vn-zoom.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /click?i=uO-fsya*kQc_0 HTTP/1.1Host: xml.sedodna.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://ww1.vn-zoom.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/v1/px?xmlid=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pB HTTP/1.1Host: stvwell.onlineConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://ww1.vn-zoom.com/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /api/v1/pxcheck?impId=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pB&minfo=eyJjb29raWVEaXNhYmxlZCI6ZmFsc2UsInVhIjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV2luNjQ7IHg2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzExNy4wLjAuMCBTYWZhcmkvNTM3LjM2IiwiaWZyYW1lIjpmYWxzZSwiZGV2aWNlUGl4ZWxSYXRpbyI6MSwid25kTG9jSHJlZiI6Imh0dHA6Ly9zdHZ3ZWxsLm9ubGluZS9hcGkvdjEvcHg/eG1saWQ9cUZnWEQzY0UxTGFTYlR4OXBsYUVOVmdBNjhXNnpIZVRJcDRMODVwQiIsImRldmljZVNyZWVuU2l6ZSI6Ijk4NHgxMjgwIiwiZGV2aWNlV2luZG93U2l6ZSI6IjkwN3gxMjgwIiwid25kMnNyY1JhdGlvTHdyMDYiOmZhbHNlLCJlZmZlY3RpdmVUeXBlIjoiNGciLCJpc0JvdCI6Im9mZiJ9 HTTP/1.1Host: stvwell.onlineConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://stvwell.online/api/v1/px?xmlid=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pBAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /click?seat=2872716&i=rfs54wj2c8Y_0 HTTP/1.1Host: xml-v4.sitamedal4.onlineConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Referer: http://stvwell.online/Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /raw/uYr0cstV HTTP/1.1User-Agent: AutoItHost: pastebin.comCache-Control: no-cache
Source: global trafficDNS traffic detected: DNS query: bit.ly
Source: global trafficDNS traffic detected: DNS query: www.vn-zoom.com
Source: global trafficDNS traffic detected: DNS query: ww1.vn-zoom.com
Source: global trafficDNS traffic detected: DNS query: img.sedoparking.com
Source: global trafficDNS traffic detected: DNS query: xml.sedodna.com
Source: global trafficDNS traffic detected: DNS query: stvwell.online
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: cdn.perfdrive.com
Source: global trafficDNS traffic detected: DNS query: xml-v4.sitamedal4.online
Source: global trafficDNS traffic detected: DNS query: route.nightskyclub.com
Source: global trafficDNS traffic detected: DNS query: cas.avalon.perfdrive.com
Source: global trafficDNS traffic detected: DNS query: yjrfhastqtio.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global trafficDNS traffic detected: DNS query: acdn.adnxs.com
Source: global trafficDNS traffic detected: DNS query: ib.adnxs.com
Source: global trafficDNS traffic detected: DNS query: thefusswire.com
Source: global trafficDNS traffic detected: DNS query: d4q53gx106.execute-api.us-east-1.amazonaws.com
Source: global trafficDNS traffic detected: DNS query: static.shareasale.com
Source: global trafficDNS traffic detected: DNS query: ncqjwdlj.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: ezrpirgeqmvy.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: sacrkvtgmmypi.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: pastebin.com
Source: global trafficDNS traffic detected: DNS query: xapqvpzfblfma.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: vjesfyss.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: slrblmwquhn.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: wsnwuhrtpc.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: zegxxtqowpz.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: yfwggqjqwhzfa.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: yirvrbfgvsc.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: nym1-ib.adnxs.com
Source: global trafficDNS traffic detected: DNS query: pxjdyqelpeelmck.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: cxzzvwupybzzs.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: oiwdhtosskcu.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: mtyykkwxhk.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: hmyqbxchyg.autoloversdigest.com
Source: global trafficDNS traffic detected: DNS query: kopuuqiewsph.autoloversdigest.com
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownHTTPS traffic detected: 104.20.3.235:443 -> 192.168.2.16:49766 version: TLS 1.2
Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.16:49771 version: TLS 1.2
Source: IDM Trial Reset.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: classification engineClassification label: mal52.troj.winEXE@19/46@112/379
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Users\user\Desktop\IDM Trial Reset.exeMutant created: \Sessions\1\BaseNamedObjects\IDM Trial Reset.exe
Source: C:\Users\user\Desktop\IDM Trial Reset.exeFile created: C:\Users\user\AppData\Local\Temp\autFD2A.tmp
Source: C:\Users\user\Desktop\IDM Trial Reset.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknownProcess created: C:\Users\user\Desktop\IDM Trial Reset.exe "C:\Users\user\Desktop\IDM Trial Reset.exe"
Source: C:\Users\user\Desktop\IDM Trial Reset.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://bit.ly/IDMresetTrialForum
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1856,i,13094607731974236556,7479999263952262712,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Users\user\Desktop\IDM Trial Reset.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://bit.ly/IDMresetTrialForum
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1856,i,13094607731974236556,7479999263952262712,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: mpr.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: userenv.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: wininet.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: winmm.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: wsock32.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: wldp.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: propsys.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: urlmon.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: iertutil.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: srvcli.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: windows.shell.servicehostbuilder.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: ieframe.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: netapi32.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: winhttp.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: wkscli.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: edputil.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: secur32.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: sspicli.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: mlang.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: profapi.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: policymanager.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: msvcp110_win.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: pcacli.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: sfc_os.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: winhttp.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: mswsock.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: winnsi.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: dnsapi.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: rasadhlp.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: schannel.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: mskeyprotect.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: ntasn1.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: msasn1.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: dpapi.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: cryptsp.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: rsaenh.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: gpapi.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: ncrypt.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeSection loaded: ncryptsslp.dll
Source: C:\Users\user\Desktop\IDM Trial Reset.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1A66AEDC-93C3-4ACC-BA96-08F5716429F7}\InProcServer32
Source: C:\Users\user\Desktop\IDM Trial Reset.exeWindow found: window name: SysTabControl32
Source: initial sampleStatic PE information: section name: UPX0
Source: initial sampleStatic PE information: section name: UPX1
Source: C:\Users\user\Desktop\IDM Trial Reset.exeFile created: C:\Users\user\AppData\Local\Temp\SetACLx32.exeJump to dropped file
Source: C:\Users\user\Desktop\IDM Trial Reset.exeFile created: C:\Users\user\AppData\Local\Temp\SetACLx64.exeJump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Source: C:\Users\user\Desktop\IDM Trial Reset.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\IDM Trial Reset.exeWindow / User API: threadDelayed 410
Source: C:\Users\user\Desktop\IDM Trial Reset.exeWindow / User API: threadDelayed 6856
Source: C:\Users\user\Desktop\IDM Trial Reset.exeWindow / User API: threadDelayed 1109
Source: C:\Users\user\Desktop\IDM Trial Reset.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\SetACLx32.exeJump to dropped file
Source: C:\Users\user\Desktop\IDM Trial Reset.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\SetACLx64.exeJump to dropped file
Source: C:\Users\user\Desktop\IDM Trial Reset.exeThread sleep count: Count: 1109 delay: -10
Source: C:\Users\user\Desktop\IDM Trial Reset.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://bit.ly/IDMresetTrialForum
Source: C:\Users\user\Desktop\IDM Trial Reset.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Registry Run Keys / Startup Folder
11
Process Injection
1
Masquerading
OS Credential Dumping1
Virtualization/Sandbox Evasion
Remote ServicesData from Local System1
Web Service
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Registry Run Keys / Startup Folder
1
Virtualization/Sandbox Evasion
LSASS Memory1
Application Window Discovery
Remote Desktop ProtocolData from Removable Media2
Encrypted Channel
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
11
Process Injection
Security Account Manager2
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
Non-Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Software Packing
LSA SecretsInternet Connection DiscoverySSHKeylogging3
Application Layer Protocol
Scheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
IDM Trial Reset.exe3%ReversingLabs
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\SetACLx32.exe0%ReversingLabs
C:\Users\user\AppData\Local\Temp\SetACLx64.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://xml.sedodna.com/click?i=uO-fsya*kQc_00%Avira URL Cloudsafe
http://stvwell.online/api/v1/px?xmlid=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pB100%Avira URL Cloudmalware
http://stvwell.online/api/v1/pxcheck?impId=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pB&minfo=eyJjb29raWVEaXNhYmxlZCI6ZmFsc2UsInVhIjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV2luNjQ7IHg2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzExNy4wLjAuMCBTYWZhcmkvNTM3LjM2IiwiaWZyYW1lIjpmYWxzZSwiZGV2aWNlUGl4ZWxSYXRpbyI6MSwid25kTG9jSHJlZiI6Imh0dHA6Ly9zdHZ3ZWxsLm9ubGluZS9hcGkvdjEvcHg/eG1saWQ9cUZnWEQzY0UxTGFTYlR4OXBsYUVOVmdBNjhXNnpIZVRJcDRMODVwQiIsImRldmljZVNyZWVuU2l6ZSI6Ijk4NHgxMjgwIiwiZGV2aWNlV2luZG93U2l6ZSI6IjkwN3gxMjgwIiwid25kMnNyY1JhdGlvTHdyMDYiOmZhbHNlLCJlZmZlY3RpdmVUeXBlIjoiNGciLCJpc0JvdCI6Im9mZiJ9100%Avira URL Cloudmalware
http://xml-v4.sitamedal4.online/click?seat=2872716&i=rfs54wj2c8Y_00%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
kopuuqiewsph.autoloversdigest.com
18.238.49.66
truefalse
    unknown
    yirvrbfgvsc.autoloversdigest.com
    52.84.52.72
    truefalse
      unknown
      route.nightskyclub.com
      52.84.18.84
      truefalse
        unknown
        yfwggqjqwhzfa.autoloversdigest.com
        52.84.52.72
        truefalse
          unknown
          www.vn-zoom.com
          69.16.230.228
          truefalse
            high
            static.shareasale.com
            104.16.62.114
            truefalse
              high
              cas.avalon.perfdrive.com
              35.241.15.240
              truefalse
                unknown
                stvwell.online
                3.33.192.145
                truefalse
                  unknown
                  pastebin.com
                  104.20.3.235
                  truefalse
                    high
                    slrblmwquhn.autoloversdigest.com
                    18.238.49.24
                    truefalse
                      unknown
                      cdn.perfdrive.com
                      130.211.29.114
                      truefalse
                        unknown
                        d4q53gx106.execute-api.us-east-1.amazonaws.com
                        18.64.183.52
                        truefalse
                          high
                          vip1.g5.cachefly.net
                          205.234.175.175
                          truefalse
                            high
                            cdnjs.cloudflare.com
                            104.17.25.14
                            truefalse
                              high
                              wsnwuhrtpc.autoloversdigest.com
                              52.84.52.122
                              truefalse
                                unknown
                                www.google.com
                                142.250.190.4
                                truefalse
                                  high
                                  hmyqbxchyg.autoloversdigest.com
                                  52.84.52.61
                                  truefalse
                                    unknown
                                    mtyykkwxhk.autoloversdigest.com
                                    52.84.52.122
                                    truefalse
                                      unknown
                                      sedodna.xml.ak-is2.net
                                      173.239.53.32
                                      truefalse
                                        unknown
                                        sacrkvtgmmypi.autoloversdigest.com
                                        52.84.52.104
                                        truefalse
                                          unknown
                                          yjrfhastqtio.autoloversdigest.com
                                          52.84.52.104
                                          truefalse
                                            unknown
                                            vjesfyss.autoloversdigest.com
                                            52.84.52.72
                                            truefalse
                                              unknown
                                              sedoparking.com
                                              64.190.63.136
                                              truefalse
                                                high
                                                pxjdyqelpeelmck.autoloversdigest.com
                                                52.84.52.122
                                                truefalse
                                                  unknown
                                                  cxzzvwupybzzs.autoloversdigest.com
                                                  52.84.52.72
                                                  truefalse
                                                    unknown
                                                    adventurefeeds.xml-v4.ak-is2.net
                                                    173.239.53.32
                                                    truefalse
                                                      unknown
                                                      thefusswire.com
                                                      3.216.92.102
                                                      truefalse
                                                        unknown
                                                        xapqvpzfblfma.autoloversdigest.com
                                                        52.84.52.122
                                                        truefalse
                                                          unknown
                                                          autoloversdigest.com
                                                          34.199.208.158
                                                          truefalse
                                                            unknown
                                                            bit.ly
                                                            67.199.248.10
                                                            truefalse
                                                              high
                                                              nym1-ib.adnxs.com
                                                              68.67.181.211
                                                              truefalse
                                                                high
                                                                ezrpirgeqmvy.autoloversdigest.com
                                                                52.84.52.104
                                                                truefalse
                                                                  unknown
                                                                  prod.appnexus.map.fastly.net
                                                                  151.101.193.108
                                                                  truefalse
                                                                    unknown
                                                                    zegxxtqowpz.autoloversdigest.com
                                                                    18.238.49.66
                                                                    truefalse
                                                                      unknown
                                                                      ib.anycast.adnxs.com
                                                                      68.67.161.208
                                                                      truefalse
                                                                        high
                                                                        oiwdhtosskcu.autoloversdigest.com
                                                                        52.84.52.61
                                                                        truefalse
                                                                          unknown
                                                                          ncqjwdlj.autoloversdigest.com
                                                                          52.84.52.104
                                                                          truefalse
                                                                            unknown
                                                                            ww1.vn-zoom.com
                                                                            unknown
                                                                            unknownfalse
                                                                              high
                                                                              img.sedoparking.com
                                                                              unknown
                                                                              unknownfalse
                                                                                high
                                                                                acdn.adnxs.com
                                                                                unknown
                                                                                unknownfalse
                                                                                  high
                                                                                  xml.sedodna.com
                                                                                  unknown
                                                                                  unknowntrue
                                                                                    unknown
                                                                                    ib.adnxs.com
                                                                                    unknown
                                                                                    unknownfalse
                                                                                      high
                                                                                      xml-v4.sitamedal4.online
                                                                                      unknown
                                                                                      unknowntrue
                                                                                        unknown
                                                                                        NameMaliciousAntivirus DetectionReputation
                                                                                        http://ww1.vn-zoom.com/search/tsc.php?200=MzM5Nzk0MzU3&21=ODEuMTgxLjYyLjkw&681=MTcxNDQyNjc2MDA3N2YyYzY5YTI0NWJjMDhjNGI1NzczZTYwNmRiNDli&crc=ebe561bc8f3c9c5a9d9842b9df4b344ca64fa44d&cv=1false
                                                                                          high
                                                                                          http://stvwell.online/api/v1/px?xmlid=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pBtrue
                                                                                          • Avira URL Cloud: malware
                                                                                          unknown
                                                                                          http://stvwell.online/api/v1/pxcheck?impId=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pB&minfo=eyJjb29raWVEaXNhYmxlZCI6ZmFsc2UsInVhIjoiTW96aWxsYS81LjAgKFdpbmRvd3MgTlQgMTAuMDsgV2luNjQ7IHg2NCkgQXBwbGVXZWJLaXQvNTM3LjM2IChLSFRNTCwgbGlrZSBHZWNrbykgQ2hyb21lLzExNy4wLjAuMCBTYWZhcmkvNTM3LjM2IiwiaWZyYW1lIjpmYWxzZSwiZGV2aWNlUGl4ZWxSYXRpbyI6MSwid25kTG9jSHJlZiI6Imh0dHA6Ly9zdHZ3ZWxsLm9ubGluZS9hcGkvdjEvcHg/eG1saWQ9cUZnWEQzY0UxTGFTYlR4OXBsYUVOVmdBNjhXNnpIZVRJcDRMODVwQiIsImRldmljZVNyZWVuU2l6ZSI6Ijk4NHgxMjgwIiwiZGV2aWNlV2luZG93U2l6ZSI6IjkwN3gxMjgwIiwid25kMnNyY1JhdGlvTHdyMDYiOmZhbHNlLCJlZmZlY3RpdmVUeXBlIjoiNGciLCJpc0JvdCI6Im9mZiJ9true
                                                                                          • Avira URL Cloud: malware
                                                                                          unknown
                                                                                          https://autoloversdigest.com/what-are-the-common-causes-of-car-overheating-and-how-can-i-prevent-it/?click_id=1fdb229d-f1b3-45a5-b152-90cdbf6cbeaafalse
                                                                                            unknown
                                                                                            http://pastebin.com/raw/uYr0cstVfalse
                                                                                              high
                                                                                              https://autoloversdigest.com/what-is-the-best-first-car-for-a-teenager/?click_id=5af72324-a94d-4060-9e5c-21b1d768014afalse
                                                                                                unknown
                                                                                                https://autoloversdigest.com/what-vehicles-run-on-natural-gas/?click_id=cf919cf3-3aad-447d-bf32-690a79ecd1d7false
                                                                                                  unknown
                                                                                                  http://bit.ly/IDMresetTrialForumfalse
                                                                                                    high
                                                                                                    http://www.vn-zoom.com/f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.htmlfalse
                                                                                                      high
                                                                                                      https://autoloversdigest.com/navigating-the-future-latest-innovations-and-trends-in-the-automotive-industry/?click_id=8fe398ca-9e44-4324-b35c-db8f4f4415cdfalse
                                                                                                        unknown
                                                                                                        https://acdn.adnxs.com/dmp/async_usersync.htmlfalse
                                                                                                          high
                                                                                                          https://acdn.adnxs.com/dmp/async_usersync.html?gdpr=0&seller_id=8822&pub_id=2335678false
                                                                                                            high
                                                                                                            http://ww1.vn-zoom.com/f247/opensource-internet-download-manager-reset-trial-khong-lo-bi-block-and-virus-and-update-thoai-mai-2990590.html?usid=25&utid=6592403207false
                                                                                                              high
                                                                                                              http://img.sedoparking.com/templates/logos/sedo_logo.pngfalse
                                                                                                                high
                                                                                                                https://autoloversdigest.com/7-fastest-police-cars-in-the-world/?click_id=f41b7289-4f8c-418e-8a33-6c676869e89afalse
                                                                                                                  unknown
                                                                                                                  https://autoloversdigest.com/inside-the-garage-tips-for-maintaining-your-classic-car-collection/?click_id=b49202f4-ce1c-4b58-8a68-8c7b8a90f010false
                                                                                                                    unknown
                                                                                                                    http://xml.sedodna.com/click?i=uO-fsya*kQc_0false
                                                                                                                    • Avira URL Cloud: safe
                                                                                                                    unknown
                                                                                                                    https://yjrfhastqtio.autoloversdigest.com/?click_id=b49202f4-ce1c-4b58-8a68-8c7b8a90f010&ref=https%3A%2F%2Fautoloversdigest.com%2Finside-the-garage-tips-for-maintaining-your-classic-car-collection%2F%3Fclick_id%3Db49202f4-ce1c-4b58-8a68-8c7b8a90f010false
                                                                                                                      unknown
                                                                                                                      http://xml-v4.sitamedal4.online/click?seat=2872716&i=rfs54wj2c8Y_0false
                                                                                                                      • Avira URL Cloud: safe
                                                                                                                      unknown
                                                                                                                      https://autoloversdigest.com/7-fastest-police-cars-in-the-world/?click_id=449f8753-6095-4fcc-b684-958641bbce4cfalse
                                                                                                                        unknown
                                                                                                                        https://autoloversdigest.com/what-vehicles-need-emission-test/?click_id=c691699d-633b-489d-8f38-7a5c83b21a2bfalse
                                                                                                                          unknown
                                                                                                                          http://ww1.vn-zoom.com/f247/img.sedoparking.com/images/js_preloader.giffalse
                                                                                                                            high
                                                                                                                            • No. of IPs < 25%
                                                                                                                            • 25% < No. of IPs < 50%
                                                                                                                            • 50% < No. of IPs < 75%
                                                                                                                            • 75% < No. of IPs
                                                                                                                            IPDomainCountryFlagASNASN NameMalicious
                                                                                                                            130.211.29.114
                                                                                                                            cdn.perfdrive.comUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            35.241.15.240
                                                                                                                            cas.avalon.perfdrive.comUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            34.224.159.124
                                                                                                                            unknownUnited States
                                                                                                                            14618AMAZON-AESUSfalse
                                                                                                                            64.190.63.136
                                                                                                                            sedoparking.comUnited States
                                                                                                                            11696NBS11696USfalse
                                                                                                                            173.239.53.32
                                                                                                                            sedodna.xml.ak-is2.netUnited States
                                                                                                                            27257WEBAIR-INTERNETUSfalse
                                                                                                                            151.101.193.108
                                                                                                                            prod.appnexus.map.fastly.netUnited States
                                                                                                                            54113FASTLYUSfalse
                                                                                                                            18.64.183.52
                                                                                                                            d4q53gx106.execute-api.us-east-1.amazonaws.comUnited States
                                                                                                                            3MIT-GATEWAYSUSfalse
                                                                                                                            68.67.161.208
                                                                                                                            ib.anycast.adnxs.comUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            205.234.175.175
                                                                                                                            vip1.g5.cachefly.netUnited States
                                                                                                                            30081CACHENETWORKSUSfalse
                                                                                                                            18.164.124.103
                                                                                                                            unknownUnited States
                                                                                                                            3MIT-GATEWAYSUSfalse
                                                                                                                            52.84.52.72
                                                                                                                            yirvrbfgvsc.autoloversdigest.comUnited States
                                                                                                                            16509AMAZON-02USfalse
                                                                                                                            68.67.179.155
                                                                                                                            unknownUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            142.250.190.4
                                                                                                                            www.google.comUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            3.216.92.102
                                                                                                                            thefusswire.comUnited States
                                                                                                                            14618AMAZON-AESUSfalse
                                                                                                                            18.211.206.94
                                                                                                                            unknownUnited States
                                                                                                                            14618AMAZON-AESUSfalse
                                                                                                                            68.67.161.182
                                                                                                                            unknownUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            172.217.0.170
                                                                                                                            unknownUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            142.250.190.3
                                                                                                                            unknownUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            68.67.160.186
                                                                                                                            unknownUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            142.250.191.110
                                                                                                                            unknownUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            67.199.248.10
                                                                                                                            bit.lyUnited States
                                                                                                                            396982GOOGLE-PRIVATE-CLOUDUSfalse
                                                                                                                            34.199.208.158
                                                                                                                            autoloversdigest.comUnited States
                                                                                                                            14618AMAZON-AESUSfalse
                                                                                                                            104.20.3.235
                                                                                                                            pastebin.comUnited States
                                                                                                                            13335CLOUDFLARENETUSfalse
                                                                                                                            68.67.160.114
                                                                                                                            unknownUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            68.67.160.137
                                                                                                                            unknownUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            104.17.24.14
                                                                                                                            unknownUnited States
                                                                                                                            13335CLOUDFLARENETUSfalse
                                                                                                                            1.1.1.1
                                                                                                                            unknownAustralia
                                                                                                                            13335CLOUDFLARENETUSfalse
                                                                                                                            142.250.190.35
                                                                                                                            unknownUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            142.250.112.84
                                                                                                                            unknownUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            142.250.191.106
                                                                                                                            unknownUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            68.67.181.211
                                                                                                                            nym1-ib.adnxs.comUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            151.101.65.108
                                                                                                                            unknownUnited States
                                                                                                                            54113FASTLYUSfalse
                                                                                                                            18.238.49.24
                                                                                                                            slrblmwquhn.autoloversdigest.comUnited States
                                                                                                                            16509AMAZON-02USfalse
                                                                                                                            52.84.18.84
                                                                                                                            route.nightskyclub.comUnited States
                                                                                                                            16509AMAZON-02USfalse
                                                                                                                            69.16.230.228
                                                                                                                            www.vn-zoom.comUnited States
                                                                                                                            32244LIQUIDWEBUSfalse
                                                                                                                            18.238.49.66
                                                                                                                            kopuuqiewsph.autoloversdigest.comUnited States
                                                                                                                            16509AMAZON-02USfalse
                                                                                                                            104.16.62.114
                                                                                                                            static.shareasale.comUnited States
                                                                                                                            13335CLOUDFLARENETUSfalse
                                                                                                                            52.84.52.61
                                                                                                                            hmyqbxchyg.autoloversdigest.comUnited States
                                                                                                                            16509AMAZON-02USfalse
                                                                                                                            239.255.255.250
                                                                                                                            unknownReserved
                                                                                                                            unknownunknownfalse
                                                                                                                            68.67.179.164
                                                                                                                            unknownUnited States
                                                                                                                            29990ASN-APPNEXUSfalse
                                                                                                                            3.33.192.145
                                                                                                                            stvwell.onlineUnited States
                                                                                                                            8987AMAZONEXPANSIONGBfalse
                                                                                                                            52.84.52.104
                                                                                                                            sacrkvtgmmypi.autoloversdigest.comUnited States
                                                                                                                            16509AMAZON-02USfalse
                                                                                                                            172.217.2.46
                                                                                                                            unknownUnited States
                                                                                                                            15169GOOGLEUSfalse
                                                                                                                            104.17.25.14
                                                                                                                            cdnjs.cloudflare.comUnited States
                                                                                                                            13335CLOUDFLARENETUSfalse
                                                                                                                            52.84.52.122
                                                                                                                            wsnwuhrtpc.autoloversdigest.comUnited States
                                                                                                                            16509AMAZON-02USfalse
                                                                                                                            IP
                                                                                                                            192.168.2.16
                                                                                                                            192.168.2.4
                                                                                                                            Joe Sandbox version:40.0.0 Tourmaline
                                                                                                                            Analysis ID:1433723
                                                                                                                            Start date and time:2024-04-29 23:38:34 +02:00
                                                                                                                            Joe Sandbox product:CloudBasic
                                                                                                                            Overall analysis duration:
                                                                                                                            Hypervisor based Inspection enabled:false
                                                                                                                            Report type:full
                                                                                                                            Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                            Number of analysed new started processes analysed:16
                                                                                                                            Number of new started drivers analysed:0
                                                                                                                            Number of existing processes analysed:0
                                                                                                                            Number of existing drivers analysed:0
                                                                                                                            Number of injected processes analysed:0
                                                                                                                            Technologies:
                                                                                                                            • EGA enabled
                                                                                                                            Analysis Mode:stream
                                                                                                                            Analysis stop reason:Timeout
                                                                                                                            Sample name:IDM Trial Reset.exe
                                                                                                                            Detection:MAL
                                                                                                                            Classification:mal52.troj.winEXE@19/46@112/379
                                                                                                                            Cookbook Comments:
                                                                                                                            • Found application associated with file extension: .exe
                                                                                                                            • Exclude process from analysis (whitelisted): dllhost.exe
                                                                                                                            • Excluded IPs from analysis (whitelisted): 142.250.190.35, 142.250.191.110, 142.250.112.84
                                                                                                                            • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, slscr.update.microsoft.com, clientservices.googleapis.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
                                                                                                                            • HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                            • Not all processes where analyzed, report is missing behavior information
                                                                                                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                            • VT rate limit hit for: IDM Trial Reset.exe
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):167
                                                                                                                            Entropy (8bit):4.43745738033235
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:0104C301C5E02BD6148B8703D19B3A73
                                                                                                                            SHA1:7436E0B4B1F8C222C38069890B75FA2BAF9CA620
                                                                                                                            SHA-256:446A6087825FA73EADB045E5A2E9E2ADF7DF241B571228187728191D961DDA1F
                                                                                                                            SHA-512:84427B656A6234A651A6D8285C103645B861A18A6C5AF4ABB5CB4F3BEB5A4F0DF4A74603A0896C7608790FBB886DC40508E92D5709F44DCA05DD46C8316D15BF
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:<html>..<head><title>301 Moved Permanently</title></head>..<body>..<center><h1>301 Moved Permanently</h1></center>..<hr><center>cloudflare</center>..</body>..</html>..
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:PE32 executable (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):454056
                                                                                                                            Entropy (8bit):6.343666374450724
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:451AE03D3C92777F09840CA56F08AB62
                                                                                                                            SHA1:328D049DA1814CFE7D1C7783691304577854482F
                                                                                                                            SHA-256:D5E779D151772504662E8226EB4107330FFA7A51209EEE42B6D5883D99100BA9
                                                                                                                            SHA-512:76772983A5C9C8C703B5E51F8CA9A0D5594121E42AFA12ADCD2B05753A1F96F97B274CDA9B13251E0DCA0D31AE6A719B2C509AC581BB34C930CCB00141EB9D42
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9YU.}8;.}8;.}8;.t@..|8;..N..y8;.f...g8;.f...G8;.f....8;.t@..h8;.}8:.8;.f...k8;.f...|8;.}8..|8;.f...|8;.Rich}8;.........................PE..L....LNP.............................l....... ....@..........................0............@..................................&..........`........................;..p#.................................@............ ...............................text............................... ..`.rdata..x.... ......................@..@.data....C...@..."...*..............@....rsrc...`............L..............@..@.reloc..Zt.......v...`..............@..B................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):559528
                                                                                                                            Entropy (8bit):6.0903310211485335
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:3E350EB5DF15C06DEC400A39DD1C6F29
                                                                                                                            SHA1:F1434CFEF2C05FDA919922B721EC1A17ADB3194E
                                                                                                                            SHA-256:427FF43693CB3CA2812C4754F607F107A6B2D3F5A8B313ADDEE57D89982DF419
                                                                                                                            SHA-512:B6B6CDFE2B08AA49254E48302385A3A2A8385E2228BDCFFD3032757ACF1A1D4ABFF1270F5488083CFA4480439FF161A9D0EA5F193CABC1EB1E7B1255CE262AB6
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......X..0..c..c..c...c..cs.>c..c.o.c..c.o>c'.c.o?c..c...c..c..c..c.o:c..c.o.c..c...c..c.o.c..cRich..c........................PE..d...QLNP..........".................8..........@.....................................'....@.................................................t...........`....`..|>...r...............................................................................................text............................... ..`.rdata..............................@..@.data....T.......,..................@....pdata..|>...`...@..................@..@.rsrc...`............L..............@..@.reloc..0............`..............@..B........................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):696
                                                                                                                            Entropy (8bit):6.680438805988443
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:D71743C02DF05822F49FF9E232DE76F0
                                                                                                                            SHA1:54AE2EA62CF71A5A8F81F5200B07150EDEF7199D
                                                                                                                            SHA-256:62AAECFD2ECA11B635DDC0AC246F9EFC991A56CAE43E009EABA9367BB287AD89
                                                                                                                            SHA-512:2E95BAD21D8AD63A31B59FA13A2914FF3CDAFA1E82925782986E723078EBB51DF3AE223E291B6CDEE7B1BEAD1A7E86B5EED8C878BFAC68E90E3A79DBA07D718A
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:EA06.........L....@-.......@*P.,...(\..H...y..(....8......X........... M`........!@..n.-.R ...b....(p....R..).....U.T........[..`.b....(.P."......0.".....4..b..........B.N.....c..@&.....2..(..D..A..(..E..0...S...k..... .*`.DP....t...#...@....N..,.........x..A..+..h.AC..) ......e....[?..-.......=........F. ......@".h.q3..&..D..x..q@.L.....t. -..4...2.....*......(.c.0..8. 8*h..N@.)....X.@%...Q9..&..T..0.........H.a ...........l...._...g......M@.. ..0.v&...2.E.....(..-........4..........F..........@.U......@[....c9...C.7D....@sM..@..g.......5. 7...PM@.37....@0?. -......p.l...8.e..Q.-.p.ao..,.....8..f....&$@.E8.P....(...X...0.[.......-.T..+H...1......I.............._...3.}.:..9?.`.
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):534
                                                                                                                            Entropy (8bit):6.3227959879627
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:E68C65421712C99C0FA515EB087B412B
                                                                                                                            SHA1:6E5DEB652022874C4872A932D654B7C2FABCA1DC
                                                                                                                            SHA-256:2CE685037E366A0FD2FF1827C20F1866BCBE23D646DFCE30A459B8FF3C1B4F2E
                                                                                                                            SHA-512:DBC06A4BE5DE4F6B2744028C6175FCA5A3785DB29434C4BAE7309ED4D0B84B3066C05DC4B990A755D3466C0E98D62107303EA7C0DDD990D2B2975EDE5BAF5D9F
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:EA06.........L....@-.......@*P.,...(\..H...y..(....8......X........... M`........!@..n.H.R.........*...H.8.@*...V.S..*P...Ao.Y........Y@.. ..n.[......M..-........R ...9.......z..H....Z..aa...`....B......"....p.P..l..M.....[.....X...*...R....8.$......4.D( .....................\....J...^ ....S.................X..M......,........,.6, .......@....F..Z...S . .1.Hf@.Y..f.....f@...r.T..*....0.R.......p.BY....Sp.*..... ....h..g......@...!S......X.....L........| A...\.J..W.0....Y..2.A...Q. 7....2.O.J....4. .................@._..H.
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1488
                                                                                                                            Entropy (8bit):6.924242718000456
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:90585D687B4426794D2DED4DD0E5FBE2
                                                                                                                            SHA1:1573E365F1DA3050B1C83958E362C7052B30CC4A
                                                                                                                            SHA-256:84DE96E94FEAFB174FD2BF79007F27BC8B43C462FB7B4A1C5137D8BA0EEB8840
                                                                                                                            SHA-512:FFBE7B9C52C12E223A741036E27A2A312F9174B2C6BFCCE3F696C340F446E277C3783090EC054858C9A310BCCB3D1290F143CD2C52A73C5E4EF4E52525416D38
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:EA06..(......L....@-.......@*P.,...(\..H...y..(....8......X........... M`........!@..n.H.R.........*...H.8.@*...V.S..*P...Ao.Y........Y@.. ..n.[......M..-........R(...(..-.....=..) ..4....m .E..0.Pn`......6.0...@-.....p.N...."...K.....p....nU..7F.....D..stP....@[..3y.$...........c..-.....j@...6...Q..(@.D....@&....b..V`.x.\........f.@H.[..Z...a...8....L.&.>......Q...0..D..%.........@...`K`..."j..K@.....7.*&@.D.....i.(....t......X@<+@..x..&.)......%.............n..X....m..2....y..........N..)..P.H..6 ..X.h..3`..b.p.. ........S...j.|K.=...@..L."3b.(.....X..X@.. ..f@.P.3a...@.U..:...S@.h....g.....Ss..jl.1M@.)...d...A.4........>SP.*l.)M.....e7.....3...."...l."..Bl.......@<..b.H.. .....v`.......M@7............j..D@*X..)V@...+.P...\b`..L.,.(..9.......6'.........d...........@........e....c0.F.<.....lX.v....@m..0.@.+ .e3....#`]...\@hH....B...%nn.. .V...a.^.`...Xl....Rg ........,..h.9.H@..a.\...0.~.......A...L@.;2.4..0.e....3.v....`(...V@.....6.....f@.....@W.....L@)............@...
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):234124
                                                                                                                            Entropy (8bit):7.745758618015926
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:2EBB8A2070729BC3CAE5B5E1CC27C963
                                                                                                                            SHA1:CC5A93CDE641744EB82DD37D84F60881265EBB0D
                                                                                                                            SHA-256:B951A1F1EC92F71EEF08E59988267CC19BF35286B90A2CBE50C4B1062C2FD0AC
                                                                                                                            SHA-512:B77F4E12D17362EFD605F0B1D1FD7994857B8996538422F848D3A7047C165AC261B19280FD2DB8AF7AF235F9EE7B82756EE3A6BB7359A7D9FB0944BF3E4119B3
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:EA06.......................Z..F@.~.D....G.P...... 4.l..h........r..d.;...o.H,VY...n.Zm..%>. ...Yt6...."fsY../......WJ..|.."T.....Y..^...".p....G...(..;@..:..@.,.....h@.+..X..Y..`...i........E.@)..,.iL.T..5..@.0..(.... .H...........A..&..c..@ ......j.0.....l....`@.`...#`......h4..... ...L.g.h4.Q...6.h.Bw..\$pX.p.S..m.7...A...}...t..5..(...;. .'. .@,...t.. ..........%..(.............E.@ . ..U..(......c...; .B....)...%.]r..-..%j.........(.(@U......U..0~O..h....&.....7.;...C.@&|LN.I...*uj...j..$...$Y4`......|*.X....T.p.......0.\..!..-.......b....q.........`.....@.`.;..<m.I..z8{..b.....N...j|h/..F.@=.p.....a~.Y.6.$.Tjx...C....,.Y.G.......@`....Y..K?..'....8.`.^10...._.V.....g..R.08./.]....~.......(.%...+.#8..h...b.....F.E.L.8...w...1.....D.n.......14.E..u.bi..MW.3.bi.K6&....a.j/.....a.L@....@a....I.cs`...b..\.1..cn0,_.....0+6..u......G.u.z3. ......!.K....`.3.@.. .a..=........w..M.9...`9.6....=...f....?.8%..G.....................:LL....*h..Z....OG\.P..w.......L
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):275018
                                                                                                                            Entropy (8bit):7.664108665566539
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:715EC543E4A386475E2105954DAD0929
                                                                                                                            SHA1:681B66D17D5B871A1C1679CBE5C993255B96EE41
                                                                                                                            SHA-256:C28E0CB287457A5B00BF34983D00256E263C00231B5CBB0F8BEF4233C47F7D55
                                                                                                                            SHA-512:0EACA6E4F2FABB45A327172272D7B5B864E7F058F17267E1D0D45C8FCDA58BF3810941D74B3104553EC21DF396132A25B0684E81F2B16F873CBF1C918F8431A1
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:EA06.........................Z..F@.~.D....G.P...... 4.l..h........r..d.;...o.H,VY...n.Zm..%>. ...Yt6...."f....#.,....Q\TJ.....xI..0..A...@.".X.......(..8H.....@.)....C..(.....A......i........E.@,.h4..L.T..5..H....*...A`.....R.E.J.....?......X.....5..B.Uo.....P0 ...........@...<.....!...L. .B ....Ar.@5.p.....g .........~..;.A`..(.....Yo.@.....H.....|2...]r.Xn....5...*P...A..Y.@.........P..@%.#......K...8..;.(....P.nW;..*.)......AL.(...x.I0...b...X..G.B.;.......F/.W.`}.....I$.....H..#..M.AH..m.H<..3.R18I'........F6+~....>O.....=.....H..os.D...................1[@......Z..N<...@.. ....^...T.$..7.@...4..0..)._..#L..$..F/...z-`.f/....d ...@..n......4... z1.... .%.$H.H..1x...L........cs.@......)8........|......Z.R.U..5zF6..,@-^=...W.@.X.^^.K.....4Y}#.U.......3.S17X.........(.....=..O.....`........h..52.......nd.@......N...D!.. ....L....'...Y.Z.G.L....m6..V`0.$....O...N....).{....I.z.`....,..7.p..3.....F...........s..?..F$.4..s@.FB.......?...UQ.....U..b@.@....4S1.\..iY
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:Windows Registry little-endian text (Win2K or above)
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):10414
                                                                                                                            Entropy (8bit):3.3424749076235876
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:3DEDFE7770A57CA2BCB76D01D1756EE6
                                                                                                                            SHA1:5B423E29F0B66CEEE9EC7BCCCF23599A280ADC93
                                                                                                                            SHA-256:832134EB65B2A91BE5B6584B48AB69B4B7CE9B6228EA4738F6D1B7A8A0E1915E
                                                                                                                            SHA-512:A3731517343536FA778BBECAAAC04944128B0B30976D4BADF7217045FAF844DAD92123BEE34A46177DC954AB713B1397D13FFE02C333A76039083B006BD2DB0D
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:..W.i.n.d.o.w.s. .R.e.g.i.s.t.r.y. .E.d.i.t.o.r. .V.e.r.s.i.o.n. .5...0.0.........[.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.D.o.w.n.l.o.a.d.M.a.n.a.g.e.r.].....".F.N.a.m.e.".=.".I.D.M. .t.r.i.a.l. .r.e.s.e.t.".....".L.N.a.m.e.".=.".(.h.t.t.p.:././.b.i.t...l.y./.I.D.M.r.e.s.e.t.T.r.i.a.l.F.o.r.u.m.).".....".E.m.a.i.l.".=.".y.o.u.r.@.e.m.a.i.l...c.o.m.".....".S.e.r.i.a.l.".=.".9.Q.N.B.L.-.L.2.6.4.1.-.Y.7.W.V.E.-.Q.E.N.3.I.".........[.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.C.L.S.I.D.\.{.6.D.D.F.0.0.D.B.-.1.2.3.4.-.4.6.E.C.-.8.3.5.6.-.2.7.E.7.B.2.0.5.1.1.9.2.}.].....".M.D.a.t.a.".=.h.e.x.(.0.).:.2.1.,.9.e.,.a.c.,.7.7.,.b.5.,.b.5.,.2.6.,.3.c.,.9.d.,.f.f.,.8.6.,.4.0.,.2.d.,.b.9.,.5.5.,.6.c.,.1.3.,.1.7.,.8.1.,.2.f.,.9.3.,.5.4.,.\..... . .2.e.,.a.b.,.2.c.,.3.4.,.c.a.,.d.c.,.3.2.,.1.f.,.a.4.,.b.0.,.c.6.,.c.c.,.4.c.,.8.3.,.4.8.,.8.4.,.2.c.,.1.e.,.6.8.,.5.f.,.4.d.,.d.7.,.a.c.,.4.1.,.2.e.,.\..... . .5.2.,.5.c.,.6.a.,.4.a.,.7.8.,.7.c.,.3.b.,.3.9.,.8.d.,.
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:Windows Registry little-endian text (Win2K or above)
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4344
                                                                                                                            Entropy (8bit):3.7597429330799566
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:17EBF21FCCAC9756EAB46EB64BA6C029
                                                                                                                            SHA1:8C8EEF0F220777DC9B2DDEE0CAD6C792D98D5487
                                                                                                                            SHA-256:290A3F67BBBDBD5C1101E90921475C2B95E97DC69A3141412FBAC79FCADD3EE8
                                                                                                                            SHA-512:47EED5646FD6E232A7E1DBA9678E9C787CD367CDC71A5330C5F09AEF4EBFF381A5EB3F5A76B4C306E45D3C6CA21FE2C749CE10BD09BB90145B46AB4299F7F4C7
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:..W.i.n.d.o.w.s. .R.e.g.i.s.t.r.y. .E.d.i.t.o.r. .V.e.r.s.i.o.n. .5...0.0.........[.-.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.C.L.S.I.D.\.{.7.B.8.E.9.1.6.4.-.3.2.4.D.-.4.A.2.E.-.A.4.6.D.-.0.1.6.5.F.B.2.0.0.0.E.C.}.].....[.-.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.W.o.w.6.4.3.2.N.o.d.e.\.C.L.S.I.D.\.{.7.B.8.E.9.1.6.4.-.3.2.4.D.-.4.A.2.E.-.A.4.6.D.-.0.1.6.5.F.B.2.0.0.0.E.C.}.].....[.-.H.K.E.Y._.L.O.C.A.L._.M.A.C.H.I.N.E.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.C.L.S.I.D.\.{.7.B.8.E.9.1.6.4.-.3.2.4.D.-.4.A.2.E.-.A.4.6.D.-.0.1.6.5.F.B.2.0.0.0.E.C.}.].....[.-.H.K.E.Y._.L.O.C.A.L._.M.A.C.H.I.N.E.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.W.o.w.6.4.3.2.N.o.d.e.\.C.L.S.I.D.\.{.7.B.8.E.9.1.6.4.-.3.2.4.D.-.4.A.2.E.-.A.4.6.D.-.0.1.6.5.F.B.2.0.0.0.E.C.}.].........[.-.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.C.L.S.I.D.\.{.6.D.D.F.0.0.D.B.-.1.2.3.4.-.4.6.E.C.-.8.3.5.6.-.2.7.E.7.B.2.0.5.1.1.9.2.}.].....[.-.H.K.E.Y._.C.U.R.R.
                                                                                                                            Process:C:\Users\user\Desktop\IDM Trial Reset.exe
                                                                                                                            File Type:Windows Registry little-endian text (Win2K or above)
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2778
                                                                                                                            Entropy (8bit):3.5263426589104574
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:237962E36948F3D0C9EC42EFA289AC52
                                                                                                                            SHA1:83F7E0B993E676DD381863370D1BF80FB84AEEB5
                                                                                                                            SHA-256:40AD93CF424EEE41A0877B11ACB92F7F12D58AB3AA6FA6D64D92CFBBE11695A2
                                                                                                                            SHA-512:BEEAEB083E6533E9410C63B7B3ACF67309F3A3DA80B49F18890E883F4C1D1244383DC227CD93E5A16AAAA8096F4F424D380E3AA5CC600D455B07CD4B6264E4DA
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:..W.i.n.d.o.w.s. .R.e.g.i.s.t.r.y. .E.d.i.t.o.r. .V.e.r.s.i.o.n. .5...0.0.........[.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.D.o.w.n.l.o.a.d.M.a.n.a.g.e.r.].....".S.e.r.i.a.l.".=.".".........[.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.C.L.S.I.D.\.{.5.E.D.6.0.7.7.9.-.4.D.E.2.-.4.E.0.7.-.B.8.6.2.-.9.7.4.C.A.4.F.F.2.E.9.C.}.].....".s.c.a.n.s.k.".=.h.e.x.(.0.).:.9.1.,.1.d.,.a.c.,.d.6.,.9.0.,.5.c.,.4.2.,.e.a.,.b.a.,.1.a.,.a.c.,.0.8.,.1.a.,.1.8.,.2.f.,.1.6.,.2.a.,.a.8.,.0.a.,.a.a.,.2.4.,.b.f.,.\..... . .0.c.,.f.c.,.4.e.,.7.b.,.3.b.,.7.6.,.f.7.,.7.0.,.9.3.,.5.8.,.5.c.,.0.3.,.0.3.,.7.e.,.0.4.,.a.b.,.b.0.,.7.e.,.0.0.,.0.0.,.0.0.,.0.0.,.0.0.,.0.0.,.0.0.,.\..... . .0.0.,.0.0.,.0.0.....[.H.K.E.Y._.C.U.R.R.E.N.T._.U.S.E.R.\.S.o.f.t.w.a.r.e.\.C.l.a.s.s.e.s.\.W.o.w.6.4.3.2.N.o.d.e.\.C.L.S.I.D.\.{.5.E.D.6.0.7.7.9.-.4.D.E.2.-.4.E.0.7.-.B.8.6.2.-.9.7.4.C.A.4.F.F.2.E.9.C.}.].....".s.c.a.n.s.k.".=.h.e.x.(.0.).:.9.1.,.1.d.,.a.c.,.d.6.,.9.0.,.5.c.,.4.2.,.e.a.,.b.a.,.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Apr 29 20:39:20 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2673
                                                                                                                            Entropy (8bit):3.992676133894234
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:D1868246C5A76B80AF87310A7503A654
                                                                                                                            SHA1:4AC90C8FC7922EB0508FF5E09FCF8433FE9FF280
                                                                                                                            SHA-256:96812EF0CE60869E2A3027424D1EADC2A36CC567026492990A55C0280CEC91DE
                                                                                                                            SHA-512:2DE2B597BE96EFC57B3B80FA5A96D248BD74883CDF0A15AC0CBA23DAA1423951D1CD5316155640FC2DEE54DB6165D343AE15287D6E270A10F1A57D45E989AD12
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:L..................F.@.. ...$+.,......}...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........%.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Apr 29 20:39:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2675
                                                                                                                            Entropy (8bit):4.007005424323533
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:D36B2C336722E178E00CC15AA631C03B
                                                                                                                            SHA1:48593B8E9184753ADFC8001B69DE5115D9008167
                                                                                                                            SHA-256:4749C7068CE653AEF3D4509F7962A72A4B4985DA8ECF238BD79B9C8AE49DB44B
                                                                                                                            SHA-512:6F29083CC757FA4CAEAC40E138ECA8A9DB3FDBFF7A1DD3607176C107C3E0F70663AF1B3DE1A09876E5C720184B75DAEE8590D4118C9AC0EF950ACA718C15EF69
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:L..................F.@.. ...$+.,.....8y.}...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........%.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2689
                                                                                                                            Entropy (8bit):4.014582984979904
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:EC235F71EA5EE38B994EE8E5156E2338
                                                                                                                            SHA1:04054519C0601DAEBDE0AFDBA3BCDE85F1944924
                                                                                                                            SHA-256:211B9422F0435E28E48507CDE22D6C229ED6574F6919F172225BD32BBC3CE377
                                                                                                                            SHA-512:3916AE4611B9A871D595E020BEC0A510EC5E0FC3CDA0ACD9B6B36F3A4BBC9038963FF9F0A802AF70E8AFF41CD004C9CF4110EA4E217EBAF875266AF64B558B8F
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:L..................F.@.. ...$+.,.....Y.04...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.VFW.E...........................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........%.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Apr 29 20:39:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2677
                                                                                                                            Entropy (8bit):4.00524359439869
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:AED9654118E02C93E2CC8E86FF0B28F2
                                                                                                                            SHA1:BE9AC650844C074AA9E0D65D33CBF3697199085B
                                                                                                                            SHA-256:758E1A219117EB3A9D7038B5CDD5A0B890E2E620479262C44F839EA6DB5DFFF0
                                                                                                                            SHA-512:74583449A722791EADD2FEA495307D92379982ACA1E48AFD73921ABD49F2EB2383446405D5A81E185850F741CFC8F2AD338BB4046C1792A0C1F822CF3CDD0EFD
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:L..................F.@.. ...$+.,......s.}...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........%.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Apr 29 20:39:20 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2677
                                                                                                                            Entropy (8bit):3.9964134277846624
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:FBEC49518EAE641472F99660830F7E43
                                                                                                                            SHA1:BA3C3D1BF0CE84B6EC19443C63DAA54DC0D6A846
                                                                                                                            SHA-256:F3DA7B18961B5DF1187A792BF4DD95D2DCACA7CA3530FD80C04B3C33F51FE7EA
                                                                                                                            SHA-512:A1082382982B07559C11D096B6AC2FD945DEE69B16FE300B616D3555CB8AF9455F1D6D9C326E234DDFB9C48B7EB6109EB7F5EC5A364F63C4A99173068D560952
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:L..................F.@.. ...$+.,........}...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........%.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Apr 29 20:39:19 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2679
                                                                                                                            Entropy (8bit):4.003656860250662
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:D252E6141148AD67935AF1B5DEE63D27
                                                                                                                            SHA1:685040EC9B01F1BE9A0ABE5513428C49350303F1
                                                                                                                            SHA-256:A8028903F6367D986B916B4D4FAEF4537405361C5985886B3D160288895513BE
                                                                                                                            SHA-512:15FCFAF6FFDE8C5155CF76FCA268456FF3721638A824F9CA1B41BF3DA736588AB2D7EA795BDC5DE4FD31481AC5ADBC74427A83F81C13EA14394595899C9BF98E
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:L..................F.@.. ...$+.,....\.f.}...N.Yr.... w......................1....P.O. .:i.....+00.../C:\.....................1.....FW.J..PROGRA~1..t......O.I.X.....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.V.X.....L.....................p+j.G.o.o.g.l.e.....T.1.....CW.V..Chrome..>......CW.V.X.....M......................8..C.h.r.o.m.e.....`.1.....CW.V..APPLIC~1..H......CW.V.X............................"&.A.p.p.l.i.c.a.t.i.o.n.....n.2. w..;W.+ .CHROME~1.EXE..R......CW.V.X............................H..c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........%.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (353)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4842
                                                                                                                            Entropy (8bit):4.862686827614266
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:0A3D3CD499571725A9089EAE78E323E8
                                                                                                                            SHA1:401D69B4D57D7FE3FD06218996BEBBC80E24E5DD
                                                                                                                            SHA-256:11AAB6F623C53E84977F7945180E6DF88F46DD54D96C80552B275DC327F14B63
                                                                                                                            SHA-512:EE94B99A0BC5DD4728F218C92C511DBDE296036A2F605CB1CA96216333CB70FC221B8FCAB67684DE9B96FF0B99D0C960425CD4B4257BD317B12032E09AC8C3C3
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://slrblmwquhn.autoloversdigest.com/?click_id=cf3b2328-3aef-41c4-a933-f300b78e069e&ref=https%3A%2F%2Fautoloversdigest.com%2Fcustomized-cruisers-crafting-your-perfect-ride-for-the-ultimate-driving-experience%2F%3Fclick_id%3Dcf3b2328-3aef-41c4-a933-f300b78e069e
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (349)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4826
                                                                                                                            Entropy (8bit):4.84954603894267
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:D5BA6EC3F9CEBF699FD3A19D1D29FDA3
                                                                                                                            SHA1:4EA237C629BC73061F4437C8336C0CA19A1BEE87
                                                                                                                            SHA-256:4467D61E0BD82B5B725FD52D2607F3D765C6759908478678183A2A9934E649C6
                                                                                                                            SHA-512:50942237CD649C1DE57011DE2C50238B1E254C131368C78CF4E55FE82DBF81F21FD9503B483E31831AA027B8AEB198619527139FCE46367CF2BA324516F8853E
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://ezrpirgeqmvy.autoloversdigest.com/?click_id=8fe398ca-9e44-4324-b35c-db8f4f4415cd&ref=https%3A%2F%2Fautoloversdigest.com%2Fnavigating-the-future-latest-innovations-and-trends-in-the-automotive-industry%2F%3Fclick_id%3D8fe398ca-9e44-4324-b35c-db8f4f4415cd
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4635
                                                                                                                            Entropy (8bit):4.858876560777041
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:29A99E809DF6747374BE7C6F526100DF
                                                                                                                            SHA1:8E605BF18AF01F92110F7E90936ED9FC5232C14A
                                                                                                                            SHA-256:B4C414294F04ABE61AEE4D10B6333AA0A667CA5154AF8A888206FF51DF82734E
                                                                                                                            SHA-512:3B815E306C8B021566D741A1BB988EB69BF2648638BE4799A9DCCAA9B55CBAAE69928DAF493F5D5E552670164EADA7FA6A13A5A6CAB1A071E8123833424A0366
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://zegxxtqowpz.autoloversdigest.com/?click_id=f41b7289-4f8c-418e-8a33-6c676869e89a&ref=https%3A%2F%2Fautoloversdigest.com%2F7-fastest-police-cars-in-the-world%2F%3Fclick_id%3Df41b7289-4f8c-418e-8a33-6c676869e89a
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):9295
                                                                                                                            Entropy (8bit):4.787950657512217
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:22194F2F23F8577193112EC53C4E296F
                                                                                                                            SHA1:A818A5B71C5EAF4EC7A86D43B9C6F9E04384ED41
                                                                                                                            SHA-256:3AAD8DC73A058F3E4157C8297A2CC0843DA4CE30A1D95B53DACB3249DC75E69E
                                                                                                                            SHA-512:5931294FB179E23F65762D42E82D362208A0DB51765A6979CE4D9F7234FAE13EAF4BA67E15E2D0166822D9B9373510AE28B34B9A59B00D59726CCCBBC597CAAF
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/inside-the-garage-tips-for-maintaining-your-classic-car-collection/?click_id=b49202f4-ce1c-4b58-8a68-8c7b8a90f010
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="https://thefusswire.com/wp-content/uploads/2023/08/cropped-cropped-cropped-FUSS_head-32x32.png" type="image/x-icon">. <title>Inside the Garage: Tips for Maintaining Your Classic Car Collection</title>..</head>.<body style="margin: 0; padding:
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):12235
                                                                                                                            Entropy (8bit):4.7654880272743965
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:FE6328F0207BED7B40A49276290A3977
                                                                                                                            SHA1:25F9677BD3705637E7CEDD7C516EA6067B422CFD
                                                                                                                            SHA-256:E888794B3FE448BEC095139017C9A765C07E2C1A27C384177A2706ADA043D32A
                                                                                                                            SHA-512:0F99476980E2B508F73D4A83E8B8E5F95A117E88FEE25768697D1A455F6CAF6EEB9E251B67C7B23CCE24705E256FFE4D6078CA97B09F9EBFD204627E7C290ABD
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/navigating-the-future-latest-innovations-and-trends-in-the-automotive-industry/?click_id=8fe398ca-9e44-4324-b35c-db8f4f4415cd
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">. <title>Navigating the Future: Latest Innovations and Trends in the Automotive Industry</title>.. <style>. body, html {. margin:
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:gzip compressed data, from Unix, original size modulo 2^32 2221
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):936
                                                                                                                            Entropy (8bit):7.787208437785755
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:F6CA58342B9B4B2909914932CDCF183C
                                                                                                                            SHA1:EFE1238BFF930604FF0DE882A2B9ACD1D88C5DC2
                                                                                                                            SHA-256:2B82B90ECC071E0AF4AACA33EFD25615918615681CF70BA80FDE0C62A97B5AFB
                                                                                                                            SHA-512:2A7FEF591E72C7315CC094F9C63ABE47CEE41FF131B5E2D4FCD88D151B4F25A8A20E23A67707D926BE9B2AECFAA3C4AB54B7E3AF607EC150358682377FF1A7A5
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:http://stvwell.online/api/v1/px?xmlid=qFgXD3cE1LaSbTx9plaENVgA68W6zHeTIp4L85pB
                                                                                                                            Preview:...........VmS.8...X....MzwL..L).@.B.i..t.i....Hr.J..v..N....}vW..........0...x..x ..;@.f...XL[L....-&-&..!.cF.91.l..s5n1.XtC.d.Q..k...6meS1Dqw.F.l....s..h7.y....R..2xw.w.......o..N...;3WNX..._. ....`....C.C.!.B.!..s ..u:.;..(....[..Z?.......&...O..W...9..so..Q.{PP-.Q!....2..y[1.4....=.S..v.X..G.=hA(os\.$.|......}7 .Hi...$.}.\.k..Vk.Q....,...Q.+p.*I.q......@N..."UG`.b..\..1..2R..J.O...-..W..2...y......W|.......2.%..H.R....c1(..>..%c&.4"/(C6...Y.Lw..B.(C.H....3Z..hcF.;.6.ud...z8G.KVy.............yj6.,...B..T.K...i.5.a..4..Z.(:.y.8V.?.).%..r...l.j.8.BA1 .s;7...,Tz.j0..?s.s..6...~.B.K...x..e..H....^./p..:9..|..k}=..>..lU...8.O(...._N..aT....c...9...Sx...(..j..R[.VN .C:g..{F..5.e.o.Tb.{...4......C.L.JG../...D.K#.._.F.P....vW.........w.Mk..LH..z..9........m..5.g.~\N...y..M.^....c...@gE.!.j.OH#.A;y..;...;5..k&Ij..h.c..*r.*=P.CPN.....{....E%0....o%q...o.gc3.}w4.F>...s.U..X.w.....
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:PNG image data, 300 x 250, 8-bit/color RGB, non-interlaced
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):14746
                                                                                                                            Entropy (8bit):7.974553143868004
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BDFF1E784137E09B819ED9C2CF27AB2A
                                                                                                                            SHA1:CA9F3D5CBC618DFD324C4F2AFEE54D25DBA9663C
                                                                                                                            SHA-256:9897A6EC9B00E97269193F6530D93669D4D463B8F45238A03B508A5144FCD9F9
                                                                                                                            SHA-512:D51CDFD075F4C15A052D12AAAE705CBB994D31743D1B156DF529415E59E149A1206B2F79E5405DC97AD426E6D866023FA2252A83FAB9BE21C6452F5FB945BF30
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:.PNG........IHDR...,................sRGB.......9TIDATx...OH.q..q.`._.k...P("...O.CP..E.4s.OVDI.]...a.-.0..6..EA.... Lv.K..u..`.`` ......|?.:m......VT...B.."..4.H..,"9@....."..4.H..,"9@....."..4.H..,"9@....."..4.H..,"9@....."..4.H..,"9@....."..4..Q.z..>85.p.,f.D.Yd..P...Ze:[V...).h.Y..q...&....5...f..<}...f.h..L..4..Z.........Y#...b.v.fA@.H..0.........>......LU....Nl.\.<..fQ......Y.^?.q..4....e.<F...y.;.....h...Z....R..8v..E:.o{M-p[k..Al.4.49.s1....X..r...?....c...E....0.as..3^..,.....#..?../.h...)Se8.H..f...Y...r..>N.b...E.|}.1...IG8.l.^.T..cc.gF..;../.h...uydt_ Z..|...\..9p.........4.H..,"9,.{qC.q.IM(}$.n .....6..hM-v..|.z....V..y^....J..b.>%.G.<-j.2..{..JS.K.s...d>7Y..7....$6w<....6.E.T.."...*n..B.s...w.."Ej.-..T..?.,....i".F.J[.T..$MSc...i.T.6Mk....\/.B.....-..6.fn.w......r.l.^hTN>r..#....?..l..2.[...(^.s:.H..U.Gg....g....Y.z...,........k.<..t..TY%q0...V...T}.(....L...........[1..-......Ou}..4...c.........Q.*..g..x.Q.S.,"..%.{.}...?|o..
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):15086
                                                                                                                            Entropy (8bit):3.090787153125625
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:DEF00C11B1596DB4EFEE6A9FBE64FC27
                                                                                                                            SHA1:BD298981E6D8D7E4FFA18ABCF687041F4246672D
                                                                                                                            SHA-256:95C427FA3143B1896FAF42A6406686CE7602CB39052081BB32D12B51C9E047E4
                                                                                                                            SHA-512:C056E95DBFA1AAB3A50DFF18C6D577DBFFEA72C93316FFC53B6B7AA41DCC7707A810D563894589A7305DE0B76610F88150B2034670DE368773B2B356F14AD30F
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:......00.... ..%..6... .... ......%........ .h....6..(...0...`..... ......$...................................................@...@...@...........................@...A...A. .A. .A. .A...A. .A. .A...@.......................@...@...@...........................................................................@...@...@...............@...A...A.U.@...@...@..@..@..@..@..@...@...@...@..@..@..@..@...@.}.A.U.A. .@...........@...@...............................................................@...........@...A...@.j.@...@..@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@..@.}.A...........@...@...................................................@.......A. .@.}.@..@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...A.G.....@...@...........................................@.......A.U.@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):12224
                                                                                                                            Entropy (8bit):4.7658865201209215
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:1C43B5574BC1A8AC32019F51464693A0
                                                                                                                            SHA1:3A2E94C719CE881FE738C3535D29BCDA036E2482
                                                                                                                            SHA-256:3FFCA03AF10B1F7335E5739E424ABA3FD62930A626C09790C31DE67EC1EF381E
                                                                                                                            SHA-512:6E0C6867EE6EF9F55C21CE6686B32CFE0EDF8C2880060B28FB9C0A6852359F6D31FCEAE4B40A6F75E2F340B6A1E5DC0BBE56EC99A2E56BB9AE131B6D93F3E9F9
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/what-are-the-common-causes-of-car-overheating-and-how-can-i-prevent-it/?click_id=1fdb229d-f1b3-45a5-b152-90cdbf6cbeaa
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">. <title>What Are The Common Causes Of Car Overheating And How Can I Prevent It?</title>.. <style>. body, html {. margin: 0;.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (32074)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):253669
                                                                                                                            Entropy (8bit):5.142891188767758
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:C15B1008DEC3C8967EA657A7BB4BAAEC
                                                                                                                            SHA1:78489E580ADAEF931E6E5B131DAB556C397E4A1A
                                                                                                                            SHA-256:28CE75D953678C4942DF47A11707A15E3C756021CF89090E3E6AA7AD6B6971C3
                                                                                                                            SHA-512:BADA3D9A5433AECE7D57020B70B89161E2CA3CF6D2FDB4FBD5D6BF38405813071D35493C8D8232F83D7BE91628A29D436BE7FD9AF918AE68F93022D9584B50B8
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js
                                                                                                                            Preview:/*! jQuery UI - v1.12.1 - 2016-09-14.* http://jqueryui.com.* Includes: widget.js, position.js, data.js, disable-selection.js, effect.js, effects/effect-blind.js, effects/effect-bounce.js, effects/effect-clip.js, effects/effect-drop.js, effects/effect-explode.js, effects/effect-fade.js, effects/effect-fold.js, effects/effect-highlight.js, effects/effect-puff.js, effects/effect-pulsate.js, effects/effect-scale.js, effects/effect-shake.js, effects/effect-size.js, effects/effect-slide.js, effects/effect-transfer.js, focusable.js, form-reset-mixin.js, jquery-1-7.js, keycode.js, labels.js, scroll-parent.js, tabbable.js, unique-id.js, widgets/accordion.js, widgets/autocomplete.js, widgets/button.js, widgets/checkboxradio.js, widgets/controlgroup.js, widgets/datepicker.js, widgets/dialog.js, widgets/draggable.js, widgets/droppable.js, widgets/menu.js, widgets/mouse.js, widgets/progressbar.js, widgets/resizable.js, widgets/selectable.js, widgets/selectmenu.js, widgets/slider.js, widgets/sortabl
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):9427
                                                                                                                            Entropy (8bit):4.802718650363351
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B08C2436A86D714B0C16808ED6F32558
                                                                                                                            SHA1:F4AB6EC75C1BAF761858846D77BD944757133CB8
                                                                                                                            SHA-256:D02D8892AE8EA57E4D2A2B4E906823578D775B3B6DEF31FF74479D65E1783174
                                                                                                                            SHA-512:7E81341D5F10E881FDCB43591380797A7AF306518DEE7869B61A601F371549FFB24210C4511A4670B1004B017AB56EA8C899A16482E3CA57F3853B0BB71560DB
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/what-vehicles-need-emission-test/?click_id=c691699d-633b-489d-8f38-7a5c83b21a2b
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="https://thefusswire.com/wp-content/uploads/2023/08/cropped-cropped-cropped-FUSS_head-32x32.png" type="image/x-icon">. <title>What Vehicles Need Emission Test ?</title>..</head>.<body style="margin: 0; padding: 0;">.<script type="text/javascri
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):12184
                                                                                                                            Entropy (8bit):4.7642879220937955
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:39B0080AAF29272765D713AAB653B9BC
                                                                                                                            SHA1:D8E165C7078C8A8A9B46B0E9CD2A306EB75EBFFD
                                                                                                                            SHA-256:2D3DCDF2460B6A7E90C52E7C7C3E2B15567A1F3FE6EC071C19B8E05C21EE1755
                                                                                                                            SHA-512:580A8AC3FCBCC4C07C4BD1689DED451E260E5C6EF5E51961494998732D6752DED6F8F209DBF134111A9601EFDD12935F88B8D31178D997EA169F6F9E533D74F8
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/what-vehicles-run-on-natural-gas/?click_id=cf919cf3-3aad-447d-bf32-690a79ecd1d7
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">. <title>What Vehicles Run On Natural Gas?</title>.. <style>. body, html {. margin: 0;. padding: 0;. height: 100%;. }
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (311)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4675
                                                                                                                            Entropy (8bit):4.862120872678028
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:13F6DD971993637FBF949E7B19AC929D
                                                                                                                            SHA1:7ABC91BA47CE068C75F134F4A21C598D6A380B4A
                                                                                                                            SHA-256:43E1113D65CE8BA004E2F44AE9E947ABF35BEE7B68D9370E725873C0E1F19485
                                                                                                                            SHA-512:81C0680EF3D8678FE7A668DAFE3173142FA1E611B4053F07945D2C91A77F739E54155904351877F9DF74A0A57FDEBA8A10D192E052E321B6EA7C0167D79F1050
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://kopuuqiewsph.autoloversdigest.com/?click_id=5af72324-a94d-4060-9e5c-21b1d768014a&ref=https%3A%2F%2Fautoloversdigest.com%2Fwhat-is-the-best-first-car-for-a-teenager%2F%3Fclick_id%3D5af72324-a94d-4060-9e5c-21b1d768014a
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (335)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4772
                                                                                                                            Entropy (8bit):4.849486131799604
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:1D388CAD00A4F5841EB87C87D80DE217
                                                                                                                            SHA1:668C1631EF3E1ABF4264AFD692C04DAF86040302
                                                                                                                            SHA-256:745C0F9C2F0BD0DFDA398920DBEF77DBB9CBE23813771E785DB398CC06791134
                                                                                                                            SHA-512:DE9995A8E33198B614B9DF55E42C46875995E991D5D63477AA3FFF8E9BF4E09C189698B63E7E20BC8A9B1337A5F9AA54F749C103AD7F36252D168B7CF7433268
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://yjrfhastqtio.autoloversdigest.com/?click_id=b49202f4-ce1c-4b58-8a68-8c7b8a90f010&ref=https%3A%2F%2Fautoloversdigest.com%2Finside-the-garage-tips-for-maintaining-your-classic-car-collection%2F%3Fclick_id%3Db49202f4-ce1c-4b58-8a68-8c7b8a90f010
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (55844)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):243045
                                                                                                                            Entropy (8bit):5.587600088216469
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:D4C77F0CA1861167197F946099906C1D
                                                                                                                            SHA1:78B2245B768B8EB049EA87CF8FEB15FDCC4033FE
                                                                                                                            SHA-256:4005533DAFD048DA30042056F7487A26D4A8912FB015D520483AB14F851C733E
                                                                                                                            SHA-512:0D80AB8CA9F73DAE38912C7D9E48F99D6BDECEB1247B4B24FCEF6763DF36A1B4536D0DD364F61482BE7079DBE343754552308ED574472215CDAFD1363365FCF3
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://cdn.perfdrive.com/advanced/stormcaster.js
                                                                                                                            Preview:!function(e){var t={};function n(r){if(t[r])return t[r].exports;var i=t[r]={i:r,l:!1,exports:{}};return e[r].call(i.exports,i,i.exports,n),i.l=!0,i.exports}n.m=e,n.c=t,n.d=function(e,t,r){n.o(e,t)||Object.defineProperty(e,t,{enumerable:!0,get:r})},n.r=function(e){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})},n.t=function(e,t){if(1&t&&(e=n(e)),8&t)return e;if(4&t&&"object"==typeof e&&e&&e.__esModule)return e;var r=Object.create(null);if(n.r(r),Object.defineProperty(r,"default",{enumerable:!0,value:e}),2&t&&"string"!=typeof e)for(var i in e)n.d(r,i,function(t){return e[t]}.bind(null,i));return r},n.n=function(e){var t=e&&e.__esModule?function(){return e.default}:function(){return e};return n.d(t,"a",t),t},n.o=function(e,t){return Object.prototype.hasOwnProperty.call(e,t)},n.p="/",n(n.s=82)}([function(e,t){function n(t){return e.exports=n="function"==typeof Symbol&&"symbol"==ty
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (303)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4644
                                                                                                                            Entropy (8bit):4.860010038515039
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:A70E38B83A175D09A0321522150D536D
                                                                                                                            SHA1:E816FD5F1D1EA206EFFDA5F6753527A2E6333481
                                                                                                                            SHA-256:AB844AABCB4EBA34E4FE24793B8DFA319F694B80129D23997F5DF021962AF42A
                                                                                                                            SHA-512:133025F6FF17277C31DD2E32B96271B3055C34C165AA0760E0E6A3C3BBEE0D9B10A71C875A935B1E7E22C1EC5D6CE4EFA2DCAE6959629A8B5ED6C7F1912C77FE
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://yirvrbfgvsc.autoloversdigest.com/?click_id=449f8753-6095-4fcc-b684-958641bbce4c&ref=https%3A%2F%2Fautoloversdigest.com%2F7-fastest-police-cars-in-the-world%2F%3Fclick_id%3D449f8753-6095-4fcc-b684-958641bbce4c
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (338)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4785
                                                                                                                            Entropy (8bit):4.85303440161623
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:A593725584184C90FA0A47BC9FEA5CB7
                                                                                                                            SHA1:128D934ADF9C6C2DAB1D8CFF377267D63BE3CEF4
                                                                                                                            SHA-256:4985039B5AD93F8BD2A5193D320C65A288F7C56B1921D3BC4E1A58844E0D95C0
                                                                                                                            SHA-512:95BA279C011035BC37A9744B2B677AA6F02221373E436364721025F5A70CD8EDEF6DB8A1CAEBEDCEBC2D6D1DD07AB0D4D15D613B4A4954AD2E8BCC8565850A43
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://mtyykkwxhk.autoloversdigest.com/?click_id=1fdb229d-f1b3-45a5-b152-90cdbf6cbeaa&ref=https%3A%2F%2Fautoloversdigest.com%2Fwhat-are-the-common-causes-of-car-overheating-and-how-can-i-prevent-it%2F%3Fclick_id%3D1fdb229d-f1b3-45a5-b152-90cdbf6cbeaa
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):12210
                                                                                                                            Entropy (8bit):4.76769910837136
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B352D6B996BBBFC981A9D3EE3559207C
                                                                                                                            SHA1:05ED3C3D03FB54B8AFC8D5E9B668016087968021
                                                                                                                            SHA-256:E31131FB4364C30EBD310C31749EBD66C0A4336A99D9C5BB71C96D26F145B445
                                                                                                                            SHA-512:D02C39ADF1EC83C7B4670F6CE49B6197F6A45F6B5D6598A26441A030269D78A36C3BD49179605837AF8ECB7FFCD31701B6D7C5A8DCA7A34F58C3813B4925B1A5
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/what-is-the-best-first-car-for-a-teenager/?click_id=5af72324-a94d-4060-9e5c-21b1d768014a
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">. <title>What Is The Best First Car For A Teenager | 7 Choices</title>.. <style>. body, html {. margin: 0;. padding: 0;.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):9427
                                                                                                                            Entropy (8bit):4.804519516335679
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:A0D60B7E40BD1A5943F3BE3AD9364C63
                                                                                                                            SHA1:2A1EC295B96CABA2F1F5901618B5B557CEC74597
                                                                                                                            SHA-256:3AE12DD4585F478701EFD0A94288AAAC8305FD93CC7F3BB7C4072FA8053B4064
                                                                                                                            SHA-512:D02DF0FB0B5FF4B6DB0695DB5A29BA2B10181F8E0C88F9109D3E9B4B6ADBA0E3AB79E0781247B7D65B65D27443CDCA78457498743B1B5D32B65F987BC5F103DC
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/7-fastest-police-cars-in-the-world/?click_id=f41b7289-4f8c-418e-8a33-6c676869e89a
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="https://thefusswire.com/wp-content/uploads/2023/08/cropped-cropped-cropped-FUSS_head-32x32.png" type="image/x-icon">. <title>7 Fastest Police Cars In The World</title>..</head>.<body style="margin: 0; padding: 0;">.<script type="text/javascri
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (65536), with no line terminators
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):125250
                                                                                                                            Entropy (8bit):5.366459254148267
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:4851F99F7147D56FB954D81055CA2D3D
                                                                                                                            SHA1:8D7982E0B6329C0460F0EE61CCA0151181326F2B
                                                                                                                            SHA-256:97711CF6D03D55D6DFA7BA68473B2D0D3C64C963463100F87F6792A4D0D080C1
                                                                                                                            SHA-512:21F2B58E5FAAF45A80D5E472901A430F3FE49286694991E303939D1280716885F4A31C422411843B02A9CE9F409A8042E0A39320A4CAF0FF1F114870D581F7E8
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://acdn.adnxs.com/ast/ast.js
                                                                                                                            Preview:/*! AST v0.61.2 Updated: 2024-02-13 */!function(e){var t={};function n(a){if(t[a])return t[a].exports;var r=t[a]={i:a,l:!1,exports:{}};return e[a].call(r.exports,r,r.exports,n),r.l=!0,r.exports}n.m=e,n.c=t,n.d=function(e,t,a){n.o(e,t)||Object.defineProperty(e,t,{enumerable:!0,get:a})},n.r=function(e){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(e,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(e,"__esModule",{value:!0})},n.t=function(e,t){if(1&t&&(e=n(e)),8&t)return e;if(4&t&&"object"==typeof e&&e&&e.__esModule)return e;var a=Object.create(null);if(n.r(a),Object.defineProperty(a,"default",{enumerable:!0,value:e}),2&t&&"string"!=typeof e)for(var r in e)n.d(a,r,function(t){return e[t]}.bind(null,r));return a},n.n=function(e){var t=e&&e.__esModule?function(){return e.default}:function(){return e};return n.d(t,"a",t),t},n.o=function(e,t){return Object.prototype.hasOwnProperty.call(e,t)},n.p="",n(n.s=12)}([function(e){e.exports=JSON.parse('{"o":{"UT_IFRAM
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (52990)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):53044
                                                                                                                            Entropy (8bit):5.438374620694402
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:0B6AA3AA07869D5163C8D489F7C66256
                                                                                                                            SHA1:BD32C24DFC6C71AE54BF2E6473AD61FA6F81BE3B
                                                                                                                            SHA-256:3D649C0B3E87FD6ABCB983656A0A1B3923A2A59885C3A30538641FD4F7126CBD
                                                                                                                            SHA-512:D754CB423718F3BC335081D41A88386B58E2EB523635BD15773B43495064B52B0FBB9265DA8DD19E47A97CFAA1FABD40C73C36F9684F6C44F2A18E6502F44E88
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://acdn.adnxs.com/dmp/async_usersync.html?gdpr=0&seller_id=8822&pub_id=2335678
                                                                                                                            Preview:<!DOCTYPE html>.<html>.<head>.</head>.<body>.<script type="text/javascript">!function(t){var e={};function a(n){if(e[n])return e[n].exports;var i=e[n]={i:n,l:!1,exports:{}};return t[n].call(i.exports,i,i.exports,a),i.l=!0,i.exports}a.m=t,a.c=e,a.d=function(t,e,n){a.o(t,e)||Object.defineProperty(t,e,{enumerable:!0,get:n})},a.r=function(t){"undefined"!=typeof Symbol&&Symbol.toStringTag&&Object.defineProperty(t,Symbol.toStringTag,{value:"Module"}),Object.defineProperty(t,"__esModule",{value:!0})},a.t=function(t,e){if(1&e&&(t=a(t)),8&e)return t;if(4&e&&"object"==typeof t&&t&&t.__esModule)return t;var n=Object.create(null);if(a.r(n),Object.defineProperty(n,"default",{enumerable:!0,value:t}),2&e&&"string"!=typeof t)for(var i in t)a.d(n,i,function(e){return t[e]}.bind(null,i));return n},a.n=function(t){var e=t&&t.__esModule?function(){return t.default}:function(){return t};return a.d(e,"a",e),e},a.o=function(t,e){return Object.prototype.hasOwnProperty.call(t,e)},a.p="./",a(a.s=114)}({1:functi
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):1935
                                                                                                                            Entropy (8bit):7.8403135013149905
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:E90F1A0DC21AD678192E74CE8D6DF9BE
                                                                                                                            SHA1:B70537E7BBBB97A2A16C50C83FFD4FC2FDF32C13
                                                                                                                            SHA-256:493361A974858CAFF8BC8DF1F4A8B685D50C79A40D8278B0C02E67EB5D812644
                                                                                                                            SHA-512:D334605B7D78049F93ECEA1312B7E66481C4E4BF81C11B806814C3521D6BFB92A3D9B1EA83363F90B978AAD0F93DD6BEE58434F4E3F97F5D3333722823619008
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://thefusswire.com/wp-content/uploads/2023/08/cropped-cropped-cropped-FUSS_head-32x32.png
                                                                                                                            Preview:.PNG........IHDR... ... .....szz.....pHYs..........+.....AIDATX..Vkl...=.........v....a."..(.I.m.@..).Q+.HQI.4....!Z..%..P.....R.......B..4....2Y..c.`{.k.{f...3../.....}s...{.!...._....S<.EU.|%..w..l|..{mx.b.js.}....b. b.......%h..-...9.?.tn.}o..-....r..}..a.Zl.fx.jW......`./.C3.Ac4.-.\.O*.7....7.K3<3.....O,7._..>.z.{..c;G..)....'..g...S;%c..e........5...S+!....ZH....%.;.9+...u.7f..$i....%.". %.e.....(..@......D@...e P....&.D.PT$\.E...@T.{X*.....@D1. .@. b...1.b.......X ..R....@X ".n.....OY..W>..\T....p./.e..../..@.. ..8Y....UQ\.....B......`Wy.9l....V>.."PJ.<#...I...3@n.KZ#.;.....@F.T..r......fq..3+.I.,...Q"....|;...$.@D9cG....'......T...../.!.%.o..."JP.M........>..(..@....K..I.F.v7..R(.q..8."'m..\..m.J...."f.D.&.S...#..t.b.@J,..!,bq......q.>?p.YDD.P...;!9..A.R.Pa.*.<..v...._D..]..Q.w2&r.......8.8 .L...D.k..... ..)..9?<..RJ`U<.)S.....u>.~).a.@..DI.:....4.t.....q..\er.*.O..f..9.B..If."."".UySb..g%..aS.YId..\V!.b ...<....gY..D.-...-...k./......O...>.....
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (65451)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):86927
                                                                                                                            Entropy (8bit):5.289226719276158
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:A09E13EE94D51C524B7E2A728C7D4039
                                                                                                                            SHA1:0DC32DB4AA9C5F03F3B38C47D883DBD4FED13AAE
                                                                                                                            SHA-256:160A426FF2894252CD7CEBBDD6D6B7DA8FCD319C65B70468F10B6690C45D02EF
                                                                                                                            SHA-512:F8DA8F95B6ED33542A88AF19028E18AE3D9CE25350A06BFC3FBF433ED2B38FEFA5E639CDDFDAC703FC6CAA7F3313D974B92A3168276B3A016CEB28F27DB0714A
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js
                                                                                                                            Preview:/*! jQuery v3.3.1 | (c) JS Foundation and other contributors | jquery.org/license */.!function(e,t){"use strict";"object"==typeof module&&"object"==typeof module.exports?module.exports=e.document?t(e,!0):function(e){if(!e.document)throw new Error("jQuery requires a window with a document");return t(e)}:t(e)}("undefined"!=typeof window?window:this,function(e,t){"use strict";var n=[],r=e.document,i=Object.getPrototypeOf,o=n.slice,a=n.concat,s=n.push,u=n.indexOf,l={},c=l.toString,f=l.hasOwnProperty,p=f.toString,d=p.call(Object),h={},g=function e(t){return"function"==typeof t&&"number"!=typeof t.nodeType},y=function e(t){return null!=t&&t===t.window},v={type:!0,src:!0,noModule:!0};function m(e,t,n){var i,o=(t=t||r).createElement("script");if(o.text=e,n)for(i in v)n[i]&&(o[i]=n[i]);t.head.appendChild(o).parentNode.removeChild(o)}function x(e){return null==e?e+"":"object"==typeof e||"function"==typeof e?l[c.call(e)]||"object":typeof e}var b="3.3.1",w=function(e,t){return new w.fn.init(e,t)},
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:JSON data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):316
                                                                                                                            Entropy (8bit):4.675879688429885
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:1F5F264D17237593FBCD62D579683B03
                                                                                                                            SHA1:23E17A57D01FBC1646D7B922102B69C196E0BDC0
                                                                                                                            SHA-256:E1D50458CB381355FB5CDCE5BAF56E7C7A0B468FDD795CF777DDC6F73CD1BCB8
                                                                                                                            SHA-512:DFBC19D5B39FD1789C367D0E3AC22D3324B77E29472B9557166A8235EDC13ACD8D82BE0CBF33B9CDC3E7C998F8F97A92AFF732D96A6C60B3156CE0E023303C77
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            Preview:{"ssresp":"2","jsrecvd":"true","__uzmaj":"315770c8-58d8-405d-b4c0-69d287ca0347","__uzmbj":"1714426765","__uzmcj":"501331024862","__uzmdj":"1714426765","__uzmlj":"","__uzmfj":"7f6000c5aef4df-585e-4f65-a875-3dd06a1b922317144267654590-bcbb8e5e6b75cbd910","jsbd2":"5764261f-9162-d831-5d43-911e82be3970","mc":{},"mct":""}
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):12236
                                                                                                                            Entropy (8bit):4.766596594093674
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:51112D60612CEBF9CEF0ED010EC0D8AA
                                                                                                                            SHA1:93329BACA9A9D8712599C54BF4F3D6FC8D004C44
                                                                                                                            SHA-256:34E53FBE8F19F12FDB6097FFC8088117951ADF4D77081AB6E282A8FB0F49F283
                                                                                                                            SHA-512:339F88AC215F808BA7EDB2CDF1E25B5D8A81784B04F3F9ED2B941C3718DB53F7CEC191221435B937A0E5107EA4C4BCE1434A48B7823323D639C27DBC6CF0D878
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/customized-cruisers-crafting-your-perfect-ride-for-the-ultimate-driving-experience/?click_id=cf3b2328-3aef-41c4-a933-f300b78e069e
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">. <title>Customized Cruisers: Crafting Your Perfect Ride for the Ultimate Driving Experience</title>.. <style>. body, html {. marg
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):9430
                                                                                                                            Entropy (8bit):4.80418227042212
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:398F1057677DC9C4D8FD64EAB2742FD8
                                                                                                                            SHA1:6DFC323959AB2E1B33B23C7CB970F4B83387F0DC
                                                                                                                            SHA-256:9C8C96D374314B4B9199AD25467695E875E0B760CDA65456838317EE3794F910
                                                                                                                            SHA-512:D6AB68EDBCFB273607CBDE69D9052952024CFB92528531C49EACFF0F9A6F834D6AE4E6BFEF5E7E25F3EAF3378D9A817225A62378AC92B39738C80919C6F198A5
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://autoloversdigest.com/7-fastest-police-cars-in-the-world/?click_id=449f8753-6095-4fcc-b684-958641bbce4c
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en" style="margin: 0; padding: 0;">.<head>. <meta name="viewport" content="width=device-width, initial-scale=1.0, minimum-scale=1.0, maximum-scale=1.0, user-scalable=no, minimal-ui">. <meta charset="UTF-8">. <script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js"></script>. jQueryUI -->. <script type="text/javascript" src="https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js". charset="utf-8"></script>. Bootstrap -->. <script type="text/javascript". src="https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js". charset="utf-8"></script>.. <link rel="icon" href="https://thefusswire.com/wp-content/uploads/2023/08/cropped-cropped-cropped-FUSS_head-32x32.png" type="image/x-icon">. <title>7 Fastest Police Cars In The World</title>..</head>.<body style="margin: 0; padding: 0;">.<script type="text/javascri
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text, with very long lines (301)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4636
                                                                                                                            Entropy (8bit):4.844456344254734
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:ED4E244FBA0C79765A1E013925EACDF2
                                                                                                                            SHA1:81882EA108AEA9214AD6ED9296E6E4A66EB13471
                                                                                                                            SHA-256:52F7732C69856425C3854D68A758B4C55C6B444C96331E49397B20DF55B414F7
                                                                                                                            SHA-512:D82C7A2FFFBC3D6873FF583C37992FADBB9007F03B864AEB14903C38C7AC4CD4D4D5EC9F4AE827558AEDF2714B3E674E39D1DDDCAF6E4518F43C8113BF04A4B3
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://xapqvpzfblfma.autoloversdigest.com/?click_id=cf919cf3-3aad-447d-bf32-690a79ecd1d7&ref=https%3A%2F%2Fautoloversdigest.com%2Fwhat-vehicles-run-on-natural-gas%2F%3Fclick_id%3Dcf919cf3-3aad-447d-bf32-690a79ecd1d7
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:ASCII text, with very long lines (32033)
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):37045
                                                                                                                            Entropy (8bit):5.174934618594778
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:5869C96CC8F19086AEE625D670D741F9
                                                                                                                            SHA1:430A443D74830FE9BE26EFCA431F448C1B3740F9
                                                                                                                            SHA-256:53964478A7C634E8DAD34ECC303DD8048D00DCE4993906DE1BACF67F663486EF
                                                                                                                            SHA-512:8B3B64A1BB2F9E329F02D4CD7479065630184EBAED942EE61A9FF9E1CE34C28C0EECB854458977815CF3704A8697FA8A5D096D2761F032B74B70D51DA3E37F45
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js
                                                                                                                            Preview:/*!. * Bootstrap v3.3.7 (http://getbootstrap.com). * Copyright 2011-2016 Twitter, Inc.. * Licensed under the MIT license. */.if("undefined"==typeof jQuery)throw new Error("Bootstrap's JavaScript requires jQuery");+function(a){"use strict";var b=a.fn.jquery.split(" ")[0].split(".");if(b[0]<2&&b[1]<9||1==b[0]&&9==b[1]&&b[2]<1||b[0]>3)throw new Error("Bootstrap's JavaScript requires jQuery version 1.9.1 or higher, but lower than version 4")}(jQuery),+function(a){"use strict";function b(){var a=document.createElement("bootstrap"),b={WebkitTransition:"webkitTransitionEnd",MozTransition:"transitionend",OTransition:"oTransitionEnd otransitionend",transition:"transitionend"};for(var c in b)if(void 0!==a.style[c])return{end:b[c]};return!1}a.fn.emulateTransitionEnd=function(b){var c=!1,d=this;a(this).one("bsTransitionEnd",function(){c=!0});var e=function(){c||a(d).trigger(a.support.transition.end)};return setTimeout(e,b),this},a(function(){a.support.transition=b(),a.support.transition&&(a.event.
                                                                                                                            Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                            File Type:HTML document, ASCII text
                                                                                                                            Category:downloaded
                                                                                                                            Size (bytes):4633
                                                                                                                            Entropy (8bit):4.861085015663795
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:DC888F4B0652D43FF99B82F7571875EF
                                                                                                                            SHA1:7A3C175985DB42721D1746966C12F7C86BDDBA12
                                                                                                                            SHA-256:332D5E2E05DC066E1BE94C684CA2DDEE4F44EF9137F54E06AB0D6D87EF0701A6
                                                                                                                            SHA-512:7FDC67A704995F277C5589908BB071EAF24528C6261F9132D26EAD6B9CE75F91BB76E821D8E3527198D9B2B207D3BDAC5AD9C603882D337B3F2668BF4AE62FF1
                                                                                                                            Malicious:false
                                                                                                                            Reputation:unknown
                                                                                                                            URL:https://cxzzvwupybzzs.autoloversdigest.com/?click_id=c691699d-633b-489d-8f38-7a5c83b21a2b&ref=https%3A%2F%2Fautoloversdigest.com%2Fwhat-vehicles-need-emission-test%2F%3Fclick_id%3Dc691699d-633b-489d-8f38-7a5c83b21a2b
                                                                                                                            Preview:<!DOCTYPE html>.<html lang="en">.<head>. <meta charset="UTF-8">. <meta name="referrer" content="no-referrer">. <link rel="icon" href="data:image/gif;base64,R0lGODlhAQABAIAAAP///wAAACH5BAEAAAAALAAAAAABAAEAAAICRAEAOw==" type="image/gif">..<script>. function isLoadedInIframe() {. try {. // Check if the window is the top window. if (window.self !== window.top) {. return true;. }.. // The ancestorOrigins check might not be necessary because the previous check covers iframe detection adequately.. // However, keeping it as an additional check doesn't harm but should be inside a try block to catch potential errors.. if (window.location.ancestorOrigins && window.location.ancestorOrigins.length > 0) {. return true;. }.. // This check might cause exceptions due to cross-origin policies, hence it's been moved into its own try-catch block.. try {.
                                                                                                                            File type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
                                                                                                                            Entropy (8bit):7.975548365039864
                                                                                                                            TrID:
                                                                                                                            • Win32 Executable (generic) a (10002005/4) 99.39%
                                                                                                                            • UPX compressed Win32 Executable (30571/9) 0.30%
                                                                                                                            • Win32 EXE Yoda's Crypter (26571/9) 0.26%
                                                                                                                            • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                                                            • DOS Executable Generic (2002/1) 0.02%
                                                                                                                            File name:IDM Trial Reset.exe
                                                                                                                            File size:895'488 bytes
                                                                                                                            MD5:064f82094ae6a6e22c28a6f1ef868a26
                                                                                                                            SHA1:e034cf1fa855eef53fd46a5ec213ada99e2ece19
                                                                                                                            SHA256:a2d2b22cd0d5628976eb5996a8b20f3b5ac468907910dbc3f826f1069d435587
                                                                                                                            SHA512:7fced0980ada793abe81337911d00d6e351ba1e9ce7c6193c9f4af29c1cf210f18240071d33edb237d752dbb7732de205c1d49530ae7bf8aecd2b3147edd3afe
                                                                                                                            SSDEEP:12288:fozGdX0M4ornOmZIzfMwHHQmRROXKFHhFjvVAcJlbqm9is3MjNindDO4FVALS/Bt:f4GHnhIzOarrVuy8jadVFZIV7Um5iJ
                                                                                                                            TLSH:AF152308E5F89217D4A605FD4D752677385F89E2B242BA83D6C1FF48B9A1709DB23238
                                                                                                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........s..R...R...R....C..P.....;.S..._@#.a..._@......_@..g...[j..[...[jo.w...R...r.............#.S..._@'.S...R.k.S.....".S...RichR..
                                                                                                                            Icon Hash:2e67e3f3e66c198e
                                                                                                                            Entrypoint:0x55cac0
                                                                                                                            Entrypoint Section:UPX1
                                                                                                                            Digitally signed:false
                                                                                                                            Imagebase:0x400000
                                                                                                                            Subsystem:windows gui
                                                                                                                            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                                                                                                                            DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                                                                                                                            Time Stamp:0x57CDEFA9 [Mon Sep 5 22:20:25 2016 UTC]
                                                                                                                            TLS Callbacks:
                                                                                                                            CLR (.Net) Version:
                                                                                                                            OS Version Major:5
                                                                                                                            OS Version Minor:1
                                                                                                                            File Version Major:5
                                                                                                                            File Version Minor:1
                                                                                                                            Subsystem Version Major:5
                                                                                                                            Subsystem Version Minor:1
                                                                                                                            Import Hash:fc6683d30d9f25244a50fd5357825e79
                                                                                                                            Instruction
                                                                                                                            pushad
                                                                                                                            mov esi, 00507000h
                                                                                                                            lea edi, dword ptr [esi-00106000h]
                                                                                                                            push edi
                                                                                                                            jmp 00007FD1B5624A5Dh
                                                                                                                            nop
                                                                                                                            mov al, byte ptr [esi]
                                                                                                                            inc esi
                                                                                                                            mov byte ptr [edi], al
                                                                                                                            inc edi
                                                                                                                            add ebx, ebx
                                                                                                                            jne 00007FD1B5624A59h
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            jc 00007FD1B5624A3Fh
                                                                                                                            mov eax, 00000001h
                                                                                                                            add ebx, ebx
                                                                                                                            jne 00007FD1B5624A59h
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            adc eax, eax
                                                                                                                            add ebx, ebx
                                                                                                                            jnc 00007FD1B5624A5Dh
                                                                                                                            jne 00007FD1B5624A7Ah
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            jc 00007FD1B5624A71h
                                                                                                                            dec eax
                                                                                                                            add ebx, ebx
                                                                                                                            jne 00007FD1B5624A59h
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            adc eax, eax
                                                                                                                            jmp 00007FD1B5624A26h
                                                                                                                            add ebx, ebx
                                                                                                                            jne 00007FD1B5624A59h
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            adc ecx, ecx
                                                                                                                            jmp 00007FD1B5624AA4h
                                                                                                                            xor ecx, ecx
                                                                                                                            sub eax, 03h
                                                                                                                            jc 00007FD1B5624A63h
                                                                                                                            shl eax, 08h
                                                                                                                            mov al, byte ptr [esi]
                                                                                                                            inc esi
                                                                                                                            xor eax, FFFFFFFFh
                                                                                                                            je 00007FD1B5624AC7h
                                                                                                                            sar eax, 1
                                                                                                                            mov ebp, eax
                                                                                                                            jmp 00007FD1B5624A5Dh
                                                                                                                            add ebx, ebx
                                                                                                                            jne 00007FD1B5624A59h
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            jc 00007FD1B5624A1Eh
                                                                                                                            inc ecx
                                                                                                                            add ebx, ebx
                                                                                                                            jne 00007FD1B5624A59h
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            jc 00007FD1B5624A10h
                                                                                                                            add ebx, ebx
                                                                                                                            jne 00007FD1B5624A59h
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            adc ecx, ecx
                                                                                                                            add ebx, ebx
                                                                                                                            jnc 00007FD1B5624A41h
                                                                                                                            jne 00007FD1B5624A5Bh
                                                                                                                            mov ebx, dword ptr [esi]
                                                                                                                            sub esi, FFFFFFFCh
                                                                                                                            adc ebx, ebx
                                                                                                                            jnc 00007FD1B5624A36h
                                                                                                                            add ecx, 02h
                                                                                                                            cmp ebp, FFFFFB00h
                                                                                                                            adc ecx, 02h
                                                                                                                            lea edx, dword ptr [edi+ebp]
                                                                                                                            cmp ebp, FFFFFFFCh
                                                                                                                            jbe 00007FD1B5624A60h
                                                                                                                            mov al, byte ptr [edx]
                                                                                                                            Programming Language:
                                                                                                                            • [ASM] VS2013 build 21005
                                                                                                                            • [ C ] VS2013 build 21005
                                                                                                                            • [C++] VS2013 build 21005
                                                                                                                            • [ C ] VS2008 SP1 build 30729
                                                                                                                            • [IMP] VS2008 SP1 build 30729
                                                                                                                            • [ASM] VS2013 UPD5 build 40629
                                                                                                                            • [RES] VS2013 build 21005
                                                                                                                            • [LNK] VS2013 UPD5 build 40629
                                                                                                                            NameVirtual AddressVirtual Size Is in Section
                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x1e13780x424.rsrc
                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x15d0000x84378.rsrc
                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x1e179c0xc.rsrc
                                                                                                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x15cca40x48UPX1
                                                                                                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                            UPX00x10000x1060000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                            UPX10x1070000x560000x55e00f68a1c4e5689e9429bb546afa6cdb758False0.9876245223799127data7.9362599483200365IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                            .rsrc0x15d0000x850000x8480028be3be0dfd4dac1b5877e41f8680db4False0.9838959316037735data7.980098190760565IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                            RT_ICON0x15d3fc0x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishGreat Britain0.3885135135135135
                                                                                                                            RT_ICON0x15d5280x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishGreat Britain0.558402489626556
                                                                                                                            RT_ICON0x15fad40x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishGreat Britain0.6224202626641651
                                                                                                                            RT_ICON0x160b800x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishGreat Britain0.7553191489361702
                                                                                                                            RT_DIALOG0xcafd80xfcemptyEnglishGreat Britain0
                                                                                                                            RT_STRING0xcb0d40x594emptyEnglishGreat Britain0
                                                                                                                            RT_STRING0xcb6680x68aemptyEnglishGreat Britain0
                                                                                                                            RT_STRING0xcbcf40x490emptyEnglishGreat Britain0
                                                                                                                            RT_STRING0xcc1840x5fcemptyEnglishGreat Britain0
                                                                                                                            RT_STRING0xcc7800x65cemptyEnglishGreat Britain0
                                                                                                                            RT_STRING0xccddc0x466emptyEnglishGreat Britain0
                                                                                                                            RT_STRING0xcd2440x158emptyEnglishGreat Britain0
                                                                                                                            RT_RCDATA0x160fec0x7fb17data0.9994130367033695
                                                                                                                            RT_GROUP_ICON0x1e0b080x30dataEnglishGreat Britain0.9166666666666666
                                                                                                                            RT_GROUP_ICON0x1e0b3c0x14dataEnglishGreat Britain1.15
                                                                                                                            RT_VERSION0x1e0b540x430dataEnglishGreat Britain0.4337686567164179
                                                                                                                            RT_MANIFEST0x1e0f880x3efASCII text, with CRLF line terminatorsEnglishGreat Britain0.5074478649453823
                                                                                                                            DLLImport
                                                                                                                            KERNEL32.DLLLoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
                                                                                                                            ADVAPI32.dllGetAce
                                                                                                                            COMCTL32.dllImageList_Remove
                                                                                                                            COMDLG32.dllGetOpenFileNameW
                                                                                                                            GDI32.dllLineTo
                                                                                                                            IPHLPAPI.DLLIcmpSendEcho
                                                                                                                            MPR.dllWNetUseConnectionW
                                                                                                                            ole32.dllCoGetObject
                                                                                                                            OLEAUT32.dllVariantInit
                                                                                                                            PSAPI.DLLGetProcessMemoryInfo
                                                                                                                            SHELL32.dllDragFinish
                                                                                                                            USER32.dllGetDC
                                                                                                                            USERENV.dllLoadUserProfileW
                                                                                                                            UxTheme.dllIsThemeActive
                                                                                                                            VERSION.dllVerQueryValueW
                                                                                                                            WININET.dllFtpOpenFileW
                                                                                                                            WINMM.dlltimeGetTime
                                                                                                                            WSOCK32.dllconnect
                                                                                                                            Language of compilation systemCountry where language is spokenMap
                                                                                                                            EnglishGreat Britain