Windows Analysis Report
https://archducal-cyclist-b8075b9946a7.herokuapp.com/b?y=49ii4eh26or36chn6pi68c9l60rmce1g60o3epj6cco3id925gh748hq49k78t3gect2ubr4dthn6bj7dtnmer355phmur9fe1p6asr5dpq62t39dtn2up1f65l32dj5a4s54dbjc994isaib1m6mqbba9d3ipjqc542qijg71b42pr66orkmuavc9jj8ppfcli6it1velpn0fbjd1gn4qbecsh0====

Overview

General Information

Sample URL: https://archducal-cyclist-b8075b9946a7.herokuapp.com/b?y=49ii4eh26or36chn6pi68c9l60rmce1g60o3epj6cco3id925gh748hq49k78t3gect2ubr4dthn6bj7dtnmer355phmur9fe1p6asr5dpq62t39dtn2up1f65l32dj5a4s54dbjc994isa
Analysis ID: 1444465
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Found iframes
HTML body contains password input but no form action
HTML body with high number of embedded SVGs detected
Program does not show much activity (idle)
Stores files to the Windows start menu directory

Classification

AV Detection

barindex
Source: https://archducal-cyclist-b8075b9946a7.herokuapp.com/b?y=49ii4eh26or36chn6pi68c9l60rmce1g60o3epj6cco3id925gh748hq49k78t3gect2ubr4dthn6bj7dtnmer355phmur9fe1p6asr5dpq62t39dtn2up1f65l32dj5a4s54dbjc994isaib1m6mqbba9d3ipjqc542qijg71b42pr66orkmuavc9jj8ppfcli6it1velpn0fbjd1gn4qbecsh0==== Avira URL Cloud: detection malicious, Label: malware
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=1336165138&timestamp=1716227396431
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=1336165138&timestamp=1716227396431
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=1928492493&timestamp=1716227408040
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=1928492493&timestamp=1716227408040
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: Iframe src: https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=1928492493&timestamp=1716227408040
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: Iframe src: /_/bscframe
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: <input type="password" .../> found but no <form action="...
Source: https://docs.google.com/presentation/d/1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g/edit#slide=id.g241b18db845_2_75 HTTP Parser: Total embedded SVG size: 1119910
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: <input type="password" .../> found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: <input type="password" .../> found
Source: https://docs.google.com/presentation/d/1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g/edit?usp=sharing HTTP Parser: No favicon
Source: about:blank HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%26foreignService%3Dpunch%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdocs.google.com&followup=https%3A%2F%2Fdocs.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%26foreignService%3Dpunch%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdocs.google.com&ifkv=AaSxoQyexmeQHFbRIG1ZW57o_Ufu5RwbINDGP0y8lTpfszXT0HbCpYWBuojIjog3fqG4yF21X_Quzw&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-117396592%3A1716227357840852&ddm=0 HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No favicon
Source: https://contacts.google.com/widget/hovercard/v/2?origin=https%3A%2F%2Fdocs.google.com&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.gapi.en.SCWmpDDGjPk.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA%2Fm%3D__features__#id=I__HC_94253229&_gfid=I__HC_94253229&parent=https%3A%2F%2Fdocs.google.com&pfname=&rpctoken=18298457 HTTP Parser: No favicon
Source: https://contacts.google.com/widget/hovercard/v/2?origin=https%3A%2F%2Fdocs.google.com&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.gapi.en.SCWmpDDGjPk.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA%2Fm%3D__features__#id=I__HC_94253229&_gfid=I__HC_94253229&parent=https%3A%2F%2Fdocs.google.com&pfname=&rpctoken=18298457 HTTP Parser: No favicon
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No <meta name="author".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2F%3Fusp%3Dslides_web&ifkv=AaSxoQxjCGTZ4XzN7QXmXJ3mKfnFjpk-iYg-rKiJ4cUvVz2wSMPTiE0Fo7FJHrGzFCzj0xcl4fBgJg&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-1409281289%3A1716227390460498&ddm=0 HTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No <meta name="copyright".. found
Source: https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ec=GAZAmQI&followup=https%3A%2F%2Fdocs.google.com%2Fpresentation%2Fd%2F1j16eQ8R5sbRIqRXlkikRZ9fzaH-Jp8VAgf67Ky_bg4g%2Fedit%3Fusp%3Dsharing&ifkv=AaSxoQzWRJ8pgg71I-ZZ0s1aazXX4g3vdObQcNyguVZVvGg3SnWEEEEsnuO82mN6B1lOC7VagkGNKw&ltmpl=slides&osid=1&passive=1209600&service=wise&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-83637150%3A1716227405287923&ddm=0 HTTP Parser: No <meta name="copyright".. found
Source: chrome.exe Memory has grown: Private usage: 1MB later: 232MB
Source: chromecache_354.2.dr String found in binary or memory: _.Aw(p);break;case "PuZJUb":a+="https://www.youtube.com/t/terms?chromeless=1&hl="+_.Aw(m);break;case "fxTQxb":a+="https://youtube.com/t/terms?gl="+_.Aw(_.Jw(c))+"&hl="+_.Aw(d)+"&override_hl=1"+(f?"&linkless=1":"");break;case "prAmvd":a+="https://www.google.com/intl/"+_.Aw(m)+"/chromebook/termsofservice.html?languageCode="+_.Aw(d)+"&regionCode="+_.Aw(c);break;case "NfnTze":a+="https://policies.google.com/privacy/google-partners"+(f?"/embedded":"")+"?hl="+_.Aw(d)+"&gl="+_.Aw(c)+(g?"&color_scheme="+ equals www.youtube.com (Youtube)
Source: chromecache_768.2.dr, chromecache_759.2.dr, chromecache_552.2.dr String found in binary or memory: http://cipa.jp/exif/1.0/
Source: chromecache_768.2.dr, chromecache_759.2.dr, chromecache_552.2.dr String found in binary or memory: http://ns.camerabits.com/photomechanic/1.0/
Source: chromecache_354.2.dr String found in binary or memory: https://accounts.google.com
Source: chromecache_354.2.dr String found in binary or memory: https://accounts.google.com/TOS?loc=
Source: chromecache_354.2.dr String found in binary or memory: https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessage
Source: chromecache_354.2.dr String found in binary or memory: https://families.google.com/intl/
Source: chromecache_354.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/drive_2020q4/v10/192px.svg
Source: chromecache_354.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/gmail_2020q4/v10/web-48dp/logo_gmail_2020q4_color_2x_web_
Source: chromecache_354.2.dr String found in binary or memory: https://fonts.gstatic.com/s/i/productlogos/maps/v7/192px.svg
Source: chromecache_354.2.dr String found in binary or memory: https://g.co/recover
Source: chromecache_354.2.dr String found in binary or memory: https://play.google.com/log?format=json&hasfast=true
Source: chromecache_354.2.dr String found in binary or memory: https://play.google.com/work/enroll?identifier=
Source: chromecache_354.2.dr String found in binary or memory: https://play.google/intl/
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/privacy
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/privacy/additional
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/privacy/additional/embedded?gl=kr
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/privacy/google-partners
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/technologies/cookies
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/technologies/location-data
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/terms
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/terms/location/embedded
Source: chromecache_354.2.dr String found in binary or memory: https://policies.google.com/terms/service-specific
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-email-pin.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-password.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-sms-or-voice-pin.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-sms-pin.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/account-recovery-stop-go-landing-page_1x.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/animation/
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/ble_device.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/ble_pin.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_1x.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/contacts_backup_sync_2x.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/continue_on_your_phone.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_phone_number_verification.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/device_prompt_tap_yes.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kid_success.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_updated.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidfork_who_will_use_updated_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_not_ready.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_stick_around_darkmode_v1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignin_stick_around_v1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_account_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_account_darkmode_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_privacy_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_child_privacy_darkmode_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_created.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_double_device.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_double_device_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_full_house.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_link_accounts.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_link_accounts_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_app_decision.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_app_decision_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_supervision_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_parent_supervision_darkmode_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_respect_others_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_respect_others_darkmode_1.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_single_device.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_single_device_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/kidsignup_stop.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/personalization_reminders.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/phone_number_sign_in_2x.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_ios_center.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_laptop.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_nfc_discovered.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_nfc_discovered_darkmode.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/security_key_phone.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_googleapp_ios.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_googleapp_pulldown.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/signin_tapyes.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/smart_lock_2x.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/usb_key.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/web_and_app_activity.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/embedded/you_tube_history.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/feature_not_available.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/gmail_ios_authzen.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/paaskey.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_challenge.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_challenge_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_cross_device.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_cross_device_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_error.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_error_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_reauth.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_enrollment_reauth_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_success.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkey_success_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkeyerror.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/passkeyerror_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/red_globe_light.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/screenlock.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_ipad.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone_nfc.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_iphone_usb.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_key_phone.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/security_keys.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/success_checkmark_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/marc/success_checkmark_2_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/ui/loading_spinner_gm.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/ui/progress_spinner_color_20dp_4x.gif
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/accounts/ui/success-gm-default_2x.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/apps/signup/resources/custom-email-address.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/images/hpp/shield_security_checkup_green_2x_web_96dp.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/account_setup_chapter.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/device_setup_chapter.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/chaptering/parental_control_chapter.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_childneedshelp.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_childneedshelp_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_nextstepsforparents.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/conversion/conversion_nextstepsforparents_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_allset.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_apps_devices.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_areyousurekid.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_birthdayemail.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_choose_apps.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_confirmation.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_exploremore.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_intro.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_privacyterms.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_review_settings.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_safe_search.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervision_choice.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/graduation/graduation_supervisiongrad.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/guardianlinking/linking_complete_0.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/ads_personalization.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/confirmation.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/eligibility_error.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/fork.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/intro.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/personal_results.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/minormodeexit/safe_search.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/get_family_link_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/get_family_link_dark_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_installing_family_link_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_installing_family_link_dark_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_location_sharing_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_location_sharing_dark_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_parental_controls_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_parental_controls_dark_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_school_time_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/kid_watch_set_up_school_time_dark_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/location_sharing_enabled_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/location_sharing_enabled_dark_3.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/parent_sign_in_prologue_0.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/parent_sign_in_prologue_dark_0.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_complete_0.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_complete_dark_0.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_contacts_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/onboarding/set_up_contacts_dark_2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/all_set.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/are_you_sure_parent.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/content_restriction.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/error.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/how_controls_work.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/next_steps.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/setup_controls.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_parent.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/teensupervisionreview/who_teen.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/kid_setup_parent_escalation.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/send_email_confirmation.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/ulp_appblock/success_sent_email.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/ulpupgrade/kidprofileupgrade_all_set.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/images/ulpupgrade/kidprofileupgrade_all_set_darkmode.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/all_set.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/all_set_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/almost_done_kids_space_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/almost_done_kids_space_v2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/alreadyinstalledfamilylink.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/alreadyinstalledfamilylink_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_tablet_v2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_tablet_v2_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_v2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/devices_connected_v2_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/emailinstallfamilylink.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/emailinstallfamilylink_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/familylinkinstalling.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/familylinkinstalling_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/hand_over_device.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/hand_over_device_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/installfamilylink.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/installfamilylink_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/linking_accounts_v2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/linking_accounts_v2_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/locationsetup.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/locationsetup_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_email_v2_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_v2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/manage_parental_controls_v2_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/open_family_link_v2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/open_family_link_v2_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/parents_help.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/parents_help_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/set_up_kids_space.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/set_up_kids_space_dark.png
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setupcontrol.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuplocation.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuplocation_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuptimelimits.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/setuptimelimits_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/supervision_ready_v2.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/supervision_ready_v2_dark.svg
Source: chromecache_354.2.dr String found in binary or memory: https://ssl.gstatic.com/kids/onboarding/illustrations/youtubeaccess.svg
Source: chromecache_354.2.dr String found in binary or memory: https://support.google.com/accounts?hl=
Source: chromecache_354.2.dr String found in binary or memory: https://support.google.com/accounts?p=new-si-ui
Source: chromecache_354.2.dr String found in binary or memory: https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=3285072
Source: chromecache_354.2.dr String found in binary or memory: https://www.google.com
Source: chromecache_354.2.dr String found in binary or memory: https://www.google.com/intl/
Source: chromecache_354.2.dr String found in binary or memory: https://www.gstatic.com/accounts/speedbump/authzen_optin_illustration.gif
Source: chromecache_354.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/product/2x/chrome_48dp.png
Source: chromecache_354.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/product/2x/googleg_48dp.png
Source: chromecache_354.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/product/2x/gsa_48dp.png
Source: chromecache_354.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/product/2x/play_prism_48dp.png
Source: chromecache_354.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/product/2x/youtube_48dp.png
Source: chromecache_354.2.dr String found in binary or memory: https://www.gstatic.com/images/branding/productlogos/googleg/v6/36px.svg
Source: chromecache_354.2.dr String found in binary or memory: https://www.youtube.com/t/terms?chromeless=1&hl=
Source: chromecache_354.2.dr String found in binary or memory: https://youtube.com/t/terms?gl=
Source: classification engine Classification label: mal48.win@26/710@0/32
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=2012,i,14224229965217511269,6168956873226259102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "https://archducal-cyclist-b8075b9946a7.herokuapp.com/b?y=49ii4eh26or36chn6pi68c9l60rmce1g60o3epj6cco3id925gh748hq49k78t3gect2ubr4dthn6bj7dtnmer355phmur9fe1p6asr5dpq62t39dtn2up1f65l32dj5a4s54dbjc994isaib1m6mqbba9d3ipjqc542qijg71b42pr66orkmuavc9jj8ppfcli6it1velpn0fbjd1gn4qbecsh0===="
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3480 --field-trial-handle=2012,i,14224229965217511269,6168956873226259102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5972 --field-trial-handle=2012,i,14224229965217511269,6168956873226259102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=2012,i,14224229965217511269,6168956873226259102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3480 --field-trial-handle=2012,i,14224229965217511269,6168956873226259102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5972 --field-trial-handle=2012,i,14224229965217511269,6168956873226259102,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: Google Drive.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: YouTube.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Sheets.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Gmail.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Slides.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Docs.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files\Google\Chrome\Application\chrome_proxy.exe
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk Jump to behavior
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
Source: all processes Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs