IOC Report
osr730ky3m.exe

loading gif

Files

File Path
Type
Category
Malicious
osr730ky3m.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:46:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:46:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:46:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:46:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:46:58 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 180
data
dropped
Chrome Cache Entry: 181
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 182
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 183
ASCII text, with very long lines (1192)
downloaded
Chrome Cache Entry: 184
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 185
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 186
data
dropped
Chrome Cache Entry: 187
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 188
ASCII text, with very long lines (777)
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (574)
downloaded
Chrome Cache Entry: 190
data
dropped
Chrome Cache Entry: 191
PNG image data, 25 x 523, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 192
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 193
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 194
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
downloaded
Chrome Cache Entry: 195
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 196
BS image, Version 30820, Quantization 26995, (Decompresses to 0 words)
dropped
Chrome Cache Entry: 197
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 198
data
dropped
Chrome Cache Entry: 199
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (6328)
downloaded
Chrome Cache Entry: 201
PNG image data, 10 x 10, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 202
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 203
ASCII text, with very long lines (4975)
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (405)
downloaded
Chrome Cache Entry: 205
PNG image data, 189 x 225, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 206
ASCII text, with very long lines (9885)
downloaded
Chrome Cache Entry: 207
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 208
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 209
data
dropped
Chrome Cache Entry: 210
data
downloaded
Chrome Cache Entry: 211
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (777)
downloaded
Chrome Cache Entry: 213
HTML document, ASCII text, with very long lines (687)
downloaded
Chrome Cache Entry: 214
data
downloaded
Chrome Cache Entry: 215
data
downloaded
Chrome Cache Entry: 216
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 217
data
dropped
Chrome Cache Entry: 218
ASCII text, with very long lines (8477)
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (777)
downloaded
Chrome Cache Entry: 220
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 221
data
dropped
Chrome Cache Entry: 222
data
dropped
Chrome Cache Entry: 223
data
dropped
Chrome Cache Entry: 224
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 296x370, components 3
downloaded
Chrome Cache Entry: 225
data
dropped
Chrome Cache Entry: 226
data
downloaded
Chrome Cache Entry: 227
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 228
data
dropped
Chrome Cache Entry: 229
data
downloaded
Chrome Cache Entry: 230
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 231
data
downloaded
Chrome Cache Entry: 232
ASCII text, with very long lines (574)
downloaded
Chrome Cache Entry: 233
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 234
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 235
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
downloaded
Chrome Cache Entry: 236
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 237
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 238
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 239
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 296x370, components 3
dropped
Chrome Cache Entry: 240
data
downloaded
Chrome Cache Entry: 241
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 242
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 243
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 244
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 245
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 246
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 247
ASCII text, with very long lines (1694)
downloaded
Chrome Cache Entry: 248
data
dropped
Chrome Cache Entry: 249
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 250
data
dropped
Chrome Cache Entry: 251
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 252
data
downloaded
Chrome Cache Entry: 253
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
dropped
Chrome Cache Entry: 254
Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
downloaded
Chrome Cache Entry: 255
ASCII text, with very long lines (2362)
downloaded
Chrome Cache Entry: 256
HTML document, ASCII text, with very long lines (687)
downloaded
Chrome Cache Entry: 257
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 258
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 259
data
dropped
Chrome Cache Entry: 260
data
downloaded
Chrome Cache Entry: 261
data
downloaded
Chrome Cache Entry: 262
data
downloaded
Chrome Cache Entry: 263
data
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (10908)
downloaded
Chrome Cache Entry: 265
data
dropped
Chrome Cache Entry: 266
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (6544)
downloaded
Chrome Cache Entry: 268
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 269
data
downloaded
Chrome Cache Entry: 270
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 271
data
downloaded
Chrome Cache Entry: 272
PNG image data, 189 x 225, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 273
ASCII text, with very long lines (2362)
downloaded
Chrome Cache Entry: 274
data
downloaded
Chrome Cache Entry: 275
ASCII text, with very long lines (11069)
downloaded
Chrome Cache Entry: 276
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 277
data
downloaded
Chrome Cache Entry: 278
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
downloaded
Chrome Cache Entry: 279
ASCII text, with very long lines (777)
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (10325)
downloaded
Chrome Cache Entry: 281
BS image, Version 30820, Quantization 26995, (Decompresses to 0 words)
downloaded
Chrome Cache Entry: 282
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 283
ASCII text, with very long lines (11465)
downloaded
Chrome Cache Entry: 284
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 285
ASCII text, with very long lines (9954)
downloaded
Chrome Cache Entry: 286
ASCII text, with very long lines (4478)
downloaded
Chrome Cache Entry: 287
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 288
data
dropped
Chrome Cache Entry: 289
ASCII text, with very long lines (5135)
downloaded
Chrome Cache Entry: 290
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 291
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
downloaded
Chrome Cache Entry: 292
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 293
PNG image data, 25 x 64, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 294
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (58810)
downloaded
Chrome Cache Entry: 296
data
dropped
Chrome Cache Entry: 297
data
downloaded
Chrome Cache Entry: 298
PNG image data, 49 x 74, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 299
ASCII text, with very long lines (467)
downloaded
Chrome Cache Entry: 300
data
dropped
Chrome Cache Entry: 301
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
dropped
Chrome Cache Entry: 302
ASCII text, with very long lines (693)
downloaded
Chrome Cache Entry: 303
PNG image data, 25 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 304
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 305
ASCII text, with very long lines (6078)
downloaded
Chrome Cache Entry: 306
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 307
data
downloaded
Chrome Cache Entry: 308
BS image, Version 30820, Quantization 26995, (Decompresses to 0 words)
downloaded
Chrome Cache Entry: 309
ASCII text, with very long lines (6474)
downloaded
Chrome Cache Entry: 310
data
dropped
Chrome Cache Entry: 311
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 312
PNG image data, 25 x 523, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 313
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
dropped
Chrome Cache Entry: 314
data
dropped
Chrome Cache Entry: 315
ASCII text, with very long lines (467)
downloaded
Chrome Cache Entry: 316
data
downloaded
Chrome Cache Entry: 317
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 318
data
downloaded
Chrome Cache Entry: 319
data
dropped
Chrome Cache Entry: 320
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 321
PNG image data, 10 x 10, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 322
data
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (709)
downloaded
Chrome Cache Entry: 324
data
downloaded
Chrome Cache Entry: 325
ASCII text, with very long lines (20398)
downloaded
Chrome Cache Entry: 326
data
dropped
Chrome Cache Entry: 327
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
dropped
Chrome Cache Entry: 328
data
dropped
Chrome Cache Entry: 329
data
dropped
Chrome Cache Entry: 330
data
downloaded
Chrome Cache Entry: 331
data
downloaded
Chrome Cache Entry: 332
BS image, Version 30820, Quantization 26995, (Decompresses to 0 words)
dropped
Chrome Cache Entry: 333
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 334
ASCII text, with very long lines (405)
downloaded
Chrome Cache Entry: 335
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 336
data
dropped
Chrome Cache Entry: 337
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
dropped
Chrome Cache Entry: 338
ASCII text, with very long lines (12588)
downloaded
Chrome Cache Entry: 339
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
dropped
Chrome Cache Entry: 340
data
downloaded
Chrome Cache Entry: 341
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 342
ASCII text, with very long lines (1694)
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (4478)
downloaded
Chrome Cache Entry: 344
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 345
data
downloaded
Chrome Cache Entry: 346
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 347
ASCII text, with very long lines (3367)
downloaded
Chrome Cache Entry: 348
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
downloaded
Chrome Cache Entry: 349
ASCII text, with very long lines (1192)
downloaded
Chrome Cache Entry: 350
data
dropped
Chrome Cache Entry: 351
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 352
data
dropped
Chrome Cache Entry: 353
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 354
data
downloaded
Chrome Cache Entry: 355
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 356
data
downloaded
Chrome Cache Entry: 357
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 358
data
downloaded
Chrome Cache Entry: 359
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 360
PNG image data, 49 x 74, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 361
ASCII text, with very long lines (693)
downloaded
Chrome Cache Entry: 362
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 363
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 364
data
downloaded
Chrome Cache Entry: 365
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 366
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 367
ASCII text, with very long lines (45939)
downloaded
Chrome Cache Entry: 368
ASCII text, with very long lines (44533)
downloaded
Chrome Cache Entry: 369
data
dropped
Chrome Cache Entry: 370
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
downloaded
Chrome Cache Entry: 371
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 372
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 373
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 374
data
downloaded
Chrome Cache Entry: 375
data
dropped
Chrome Cache Entry: 376
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 377
data
dropped
Chrome Cache Entry: 378
data
downloaded
Chrome Cache Entry: 379
C source, ASCII text, with very long lines (4162)
downloaded
Chrome Cache Entry: 380
data
dropped
Chrome Cache Entry: 381
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 382
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 383
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 384
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 385
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
dropped
Chrome Cache Entry: 386
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 387
data
dropped
Chrome Cache Entry: 388
data
dropped
Chrome Cache Entry: 389
data
downloaded
Chrome Cache Entry: 390
data
dropped
Chrome Cache Entry: 391
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 392
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 393
BS image, Version 30820, Quantization 26995, (Decompresses to 0 words)
downloaded
Chrome Cache Entry: 394
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 395
data
downloaded
Chrome Cache Entry: 396
data
downloaded
Chrome Cache Entry: 397
data
dropped
Chrome Cache Entry: 398
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 399
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 400
data
downloaded
Chrome Cache Entry: 401
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 402
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 403
ASCII text, with very long lines (44533)
downloaded
Chrome Cache Entry: 404
data
downloaded
Chrome Cache Entry: 405
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
Chrome Cache Entry: 406
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 407
ISO Media, MP4 v1 [ISO 14496-1:ch13]
dropped
Chrome Cache Entry: 408
data
downloaded
Chrome Cache Entry: 409
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 410
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
downloaded
Chrome Cache Entry: 411
BS image, Version 30820, Quantization 26995, (Decompresses to 0 words)
dropped
Chrome Cache Entry: 412
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 206x366, components 3
dropped
Chrome Cache Entry: 413
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 50x50, components 3
dropped
Chrome Cache Entry: 414
data
dropped
Chrome Cache Entry: 415
ISO Media, MP4 v1 [ISO 14496-1:ch13]
downloaded
Chrome Cache Entry: 416
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 540x960, components 3
downloaded
There are 234 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Users\user\Desktop\osr730ky3m.exe
"C:\Users\user\Desktop\osr730ky3m.exe"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.youtube.com/account
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://www.facebook.com/video
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://accounts.google.com/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2024 --field-trial-handle=1976,i,17318209000228502612,2237949357977184644,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2460,i,9995763619029275045,8356352571819763688,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2164 --field-trial-handle=2008,i,17384594921740702087,194935732916387498,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4492 --field-trial-handle=2460,i,9995763619029275045,8356352571819763688,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4684 --field-trial-handle=2460,i,9995763619029275045,8356352571819763688,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449398058_1195349098256604_9067563155065100939_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EyMCIsInZpZGVvX2lkIjo0ODM4NTEyMjczNzcxNDl9&_nc_ohc=RPfSCQmAkSEQ7kNvgHESxzA&_nc_ht=video-hou1-1.xx&oh=00_AYAak_kjDxITytKA-YmtmzcobE-dl2vtODfyGcf9jMUsaA&oe=668B1B33&bytestart=0&byteend=825
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449751511_845177986944804_8287809256175764587_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=mjXxrHP1kE4Q7kNvgFBSFZf&_nc_ht=video-hou1-1.xx&oh=00_AYB4GfMz_0iTZ4H2p5URBe2WEpex8Ar6vOL0_DjJz8ZEXA&oe=668B2D27&bytestart=0&byteend=825
157.240.24.20
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/438220461_424871197194934_3396704185190857494_n.jpg?stp=dst-jpg_s960x960&_nc_cat=1&ccb=1-7&_nc_sid=c3bc4c&_nc_ohc=rYamK1Zi3UYQ7kNvgF_kTN7&_nc_ht=scontent-hou1-1.xx&oh=00_AYBC-JiaCx3bZCMFQ1PaIuHFgTdKR9QvXqhvkBZ_t8j1EA&oe=668B1B74
157.240.24.13
https://video.xx.fbcdn.net/v/t39.25447-2/449400216_441070382166231_7996235846170639077_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E0MCIsInZpZGVvX2lkIjoxMDAxNDA0NzU4MzY1NzIxfQ%3D%3D&_nc_ohc=cB3Oue079RsQ7kNvgEZLyDk&_nc_ht=video-hou1-1.xx&oh=00_AYCT__3My20AalVBeIFC2K6dKGjPy7rYUAMG5ruq9MWfaw&oe=668B25EF&bytestart=826&byteend=893
31.13.71.14
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/441997224_449546051214555_5260019720502139937_n.jpg?stp=dst-jpg_p206x206&_nc_cat=1&ccb=1-7&_nc_sid=c3bc4c&_nc_ohc=hZGlU0omaAAQ7kNvgHfdoW5&_nc_ht=scontent-hou1-1.xx&oh=00_AYBKeUbr4JQNlIF3qIQBWI-0ajfoCIj1KBg8bAz59ZEoew&oe=668B32F0
157.240.24.13
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449771776_797140345952587_3754630427050177788_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjozOTk4MjU3NDU4MTEzOTJ9&_nc_ohc=AftcvEajyaAQ7kNvgErNFhz&_nc_ht=video-hou1-1.xx&oh=00_AYDggeoSya7_wkIuwPLCKR5KMSE017d1AM2953HxQkZUYQ&oe=668B2AA8&bytestart=916&byteend=18791
157.240.24.20
https://play.google.com/work/enroll?identifier=
unknown
https://policies.google.com/terms/service-specific
unknown
https://github.com/shaka-project/shaka-packager
unknown
https://video.xx.fbcdn.net/v/t39.25447-2/449751511_845177986944804_8287809256175764587_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=mjXxrHP1kE4Q7kNvgFBSFZf&_nc_ht=video-hou1-1.xx&oh=00_AYB4GfMz_0iTZ4H2p5URBe2WEpex8Ar6vOL0_DjJz8ZEXA&oe=668B2D27&bytestart=826&byteend=917
31.13.71.14
https://policies.google.com/technologies/cookies
unknown
https://www.internalfb.com/intern/invariant/
unknown
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449400216_441070382166231_7996235846170639077_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E0MCIsInZpZGVvX2lkIjoxMDAxNDA0NzU4MzY1NzIxfQ%3D%3D&_nc_ohc=cB3Oue079RsQ7kNvgEZLyDk&_nc_ht=video-hou1-1.xx&oh=00_AYCT__3My20AalVBeIFC2K6dKGjPy7rYUAMG5ruq9MWfaw&oe=668B25EF&bytestart=0&byteend=825
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449751511_845177986944804_8287809256175764587_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=mjXxrHP1kE4Q7kNvgFBSFZf&_nc_ht=video-hou1-1.xx&oh=00_AYB4GfMz_0iTZ4H2p5URBe2WEpex8Ar6vOL0_DjJz8ZEXA&oe=668B2D27&bytestart=826&byteend=917
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449749398_919410706654359_5930299620981928735_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E2MCIsInZpZGVvX2lkIjo3NjU0MTQxNDU2NjkzMzR9&_nc_ohc=rOrpAmpg2qEQ7kNvgHrh-6Y&_nc_ht=video-hou1-1.xx&oh=00_AYCTXVxhfNzeBOavxbvCAUwoD6y6ShLZHvezDgM-zVRHrg&oe=668B327F&bytestart=826&byteend=905
157.240.24.20
https://www.youtube.com/t/terms?chromeless=1&hl=
unknown
https://www.facebook.com/ajax/bz?__a=1&__aaid=0&__ccg=GOOD&__comet_req=15&__hs=19907.HYP%3Acomet_loggedout_pkg.2.1..0.0&__hsi=7387405675209508329&__req=b&__rev=1014647652&__s=hnigsi%3Awf9jed%3Aqcwyo5&__spin_b=trunk&__spin_r=1014647652&__spin_t=1720014418&__user=0&dpr=1&jazoest=2985&lsd=AVqIzvvP8QI&ph=C3
157.240.0.35
https://youradchoices.ca/
unknown
https://video.xx.fbcdn.net/v/t39.25447-2/449694296_1560210191559240_4020235943818543510_n.mp4?_nc_cat=108&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjo3Njc0NDgwNTg2MDIwOTB9&_nc_ohc=G_r6oeHwmwAQ7kNvgG6sqtC&_nc_ht=video-hou1-1.xx&oh=00_AYDS2eQw4y1eaYumABsQPAZWQpmI7avDCc5ri5ShKEtmDA&oe=668B3299&bytestart=0&byteend=825
31.13.71.14
https://static.xx.fbcdn.net/rsrc.php/v3/y_/r/EujyFHnNhhH.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://video.xx.fbcdn.net/v/t39.25447-2/449674164_874555164725584_2448760145427529645_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjoyMjc1Nzc0NTYyODE0Mzk5fQ%3D%3D&_nc_ohc=8rroXHNeUjAQ7kNvgHhLmHL&_nc_ht=video-hou1-1.xx&oh=00_AYARYDY6Y4AYkuTRtfdga0YHpMbfJpH6rSsK7K4Qg6HnnQ&oe=668B2E1F&bytestart=826&byteend=881
31.13.71.14
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449744607_459862283322980_6029144762460813703_n.mp4?_nc_cat=110&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJldmV2cDktcjFnZW4ydnA5X3E1MCIsInZpZGVvX2lkIjo0NTgyNjgxNTAyNzQ4NTh9&_nc_ohc=LlPyzkIP5XEQ7kNvgHJuUCd&_nc_ht=video-hou1-1.xx&oh=00_AYAjW869xKiZoErQUaRNDOrLLWh7lwZOD4IAVkDPOPy1rQ&oe=668B3F79&bytestart=874&byteend=48453
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449771776_797140345952587_3754630427050177788_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjozOTk4MjU3NDU4MTEzOTJ9&_nc_ohc=AftcvEajyaAQ7kNvgErNFhz&_nc_ht=video-hou1-1.xx&oh=00_AYDggeoSya7_wkIuwPLCKR5KMSE017d1AM2953HxQkZUYQ&oe=668B2AA8&bytestart=824&byteend=915
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/448827281_1000449061755355_8485620690939993684_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF80OF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo3Njc0NDgwNTg2MDIwOTB9&_nc_ohc=tmxMzlxytgsQ7kNvgGNvup2&_nc_ht=video-hou1-1.xx&oh=00_AYC3vkKp0JXb8qLN0MZER1vtR4PHP7zT3IQbzeobYJCQ2Q&oe=668B2530&bytestart=1228&byteend=14626
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449178494_787972259986290_5287065104367118752_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo0NTgyNjgxNTAyNzQ4NTh9&_nc_ohc=Okqc0ec779wQ7kNvgGSxSbJ&_nc_ht=video-hou1-1.xx&oh=00_AYA3ox8WBXD_V0qsnAa4MOypYGNXmY1Wh35stftI4T6iPg&oe=668B2BD8&bytestart=904&byteend=18604
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449450069_1948022175632401_5300699791447743925_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoxMDAxNDA0NzU4MzY1NzIxfQ%3D%3D&_nc_ohc=BNS_liS8xuMQ7kNvgH3t1jS&_nc_ht=video-hou1-1.xx&oh=00_AYC7NzW8Tf2T3-SDpTeOzem4P1HpY91CkP_Lc2y6Iv1cSA&oe=668B1021&bytestart=940&byteend=18688
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/448827281_1000449061755355_8485620690939993684_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF80OF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo3Njc0NDgwNTg2MDIwOTB9&_nc_ohc=tmxMzlxytgsQ7kNvgGNvup2&_nc_ht=video-hou1-1.xx&oh=00_AYC3vkKp0JXb8qLN0MZER1vtR4PHP7zT3IQbzeobYJCQ2Q&oe=668B2530&bytestart=824&byteend=1227
157.240.24.20
https://video.xx.fbcdn.net/v/t39.25447-2/449744607_459862283322980_6029144762460813703_n.mp4?_nc_cat=110&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJldmV2cDktcjFnZW4ydnA5X3E1MCIsInZpZGVvX2lkIjo0NTgyNjgxNTAyNzQ4NTh9&_nc_ohc=LlPyzkIP5XEQ7kNvgHJuUCd&_nc_ht=video-hou1-1.xx&oh=00_AYAjW869xKiZoErQUaRNDOrLLWh7lwZOD4IAVkDPOPy1rQ&oe=668B3F79&bytestart=0&byteend=817
31.13.71.14
https://video.xx.fbcdn.net/v/t39.25447-2/449745839_1625389988297537_5965255506811228425_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=nUpM9yYV9IEQ7kNvgFRwSFy&_nc_ht=video-hou1-1.xx&oh=00_AYADDmQRaqjBi1xIuwZIcUt6Iulzb8TMl1WZc9aMDS0vwg&oe=668B2F59&bytestart=824&byteend=1011
31.13.71.14
https://static.xx.fbcdn.net/rsrc.php/v3ieKI4/yR/l/en_GB/0bfveO1rdQO.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449318552_328889630160021_8165757550254973066_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjoyMzc4NzAxNDQyMzI0OTE2fQ%3D%3D&_nc_ohc=j7LF-H9Ghp0Q7kNvgE2E3Ki&_nc_ht=video-hou1-1.xx&oh=00_AYCm58f4d04MDIOt6Tk8GLzljuymdR4VZCM5akROrsWl9A&oe=668B2D29&bytestart=906&byteend=589905
157.240.24.20
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/449712644_816422753527500_4620893420354803502_n.jpg?stp=dst-jpg_s960x960&_nc_cat=1&ccb=1-7&_nc_sid=c3bc4c&_nc_ohc=w3LX7afKrBsQ7kNvgEQ5S8s&_nc_ht=scontent-hou1-1.xx&oh=00_AYDgVlUrnI3YVIhnU4Rtviyi17Z7BWHmT7t4HLp7HtBchg&oe=668B44F5
157.240.24.13
https://apis.google.com/js/api.js
unknown
https://video.xx.fbcdn.net/v/t39.25447-2/449744607_459862283322980_6029144762460813703_n.mp4?_nc_cat=110&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJldmV2cDktcjFnZW4ydnA5X3E1MCIsInZpZGVvX2lkIjo0NTgyNjgxNTAyNzQ4NTh9&_nc_ohc=LlPyzkIP5XEQ7kNvgHJuUCd&_nc_ht=video-hou1-1.xx&oh=00_AYAjW869xKiZoErQUaRNDOrLLWh7lwZOD4IAVkDPOPy1rQ&oe=668B3F79&bytestart=818&byteend=873
31.13.71.14
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/449787338_1668205580611896_7394166591359421737_n.jpg?stp=dst-jpg_s960x960&_nc_cat=1&ccb=1-7&_nc_sid=c3bc4c&_nc_ohc=BUim_norTLQQ7kNvgEK7JpK&_nc_ht=scontent-hou1-1.xx&oh=00_AYDjf2G2a0j2jV1UdQewqITyeaa1J826aL0FRlEI43_NPw&oe=668B281B
157.240.24.13
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449705054_491731483514107_4213972426740765497_n.mp4?_nc_cat=109&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo0ODM4NTEyMjczNzcxNDl9&_nc_ohc=sfLLDPkRnaYQ7kNvgEmsM24&_nc_ht=video-hou1-1.xx&oh=00_AYDKK53K9bXolIEERe7J3ZqtehB6VIGEfx1JVnAXC5q7jw&oe=668B388A&bytestart=824&byteend=927
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449745839_1625389988297537_5965255506811228425_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=nUpM9yYV9IEQ7kNvgFRwSFy&_nc_ht=video-hou1-1.xx&oh=00_AYADDmQRaqjBi1xIuwZIcUt6Iulzb8TMl1WZc9aMDS0vwg&oe=668B2F59&bytestart=1012&byteend=18621
157.240.24.20
https://www.youtube.com/account-o1&
unknown
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/438062513_882312713691783_6862801772264223093_n.jpg?stp=dst-jpg_p206x206&_nc_cat=1&ccb=1-7&_nc_sid=c3bc4c&_nc_ohc=N3lYMSNitWIQ7kNvgFJ4H4B&_nc_ht=scontent-hou1-1.xx&oh=00_AYBi4m8b1qpd5xjF5VU1M1VoiLWeSG3SItPJ3m5NoUmPhg&oe=668B0E37
157.240.24.13
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449771776_797140345952587_3754630427050177788_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjozOTk4MjU3NDU4MTEzOTJ9&_nc_ohc=AftcvEajyaAQ7kNvgErNFhz&_nc_ht=video-hou1-1.xx&oh=00_AYDggeoSya7_wkIuwPLCKR5KMSE017d1AM2953HxQkZUYQ&oe=668B2AA8&bytestart=0&byteend=823
157.240.24.20
https://scontent-hou1-1.xx.fbcdn.net/v/t39.30808-1/244246203_368581291613392_1417098440599807693_n.jpg?stp=c5.0.50.50a_cp0_dst-jpg_p50x50&_nc_cat=1&ccb=1-7&_nc_sid=f4b9fd&_nc_ohc=C0KcJBzniAAQ7kNvgH8NYBv&_nc_ht=scontent-hou1-1.xx&oh=00_AYBOIaa_lTmoE5spXLrfBA0gucmO5IeYRK-zCRENrcYdcQ&oe=668B3AE6
157.240.24.13
https://static.xx.fbcdn.net/rsrc.php/v3/y1/r/VVfVcgNse_k7OBycsxKTmL-41uF-jEkcBzg4GbaorIyr8O0FwF42MYvlh6jit1ncqcXDV2hji4yzQ.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://www.google.com/favicon.ico
142.250.185.132
https://www.facebook.com/data/manifest/
157.240.0.35
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/448827281_1000449061755355_8485620690939993684_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF80OF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo3Njc0NDgwNTg2MDIwOTB9&_nc_ohc=tmxMzlxytgsQ7kNvgGNvup2&_nc_ht=video-hou1-1.xx&oh=00_AYC3vkKp0JXb8qLN0MZER1vtR4PHP7zT3IQbzeobYJCQ2Q&oe=668B2530&bytestart=0&byteend=823
157.240.24.20
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/441934308_773094221360767_7100231602105543691_n.jpg?stp=dst-jpg_p206x206&_nc_cat=1&ccb=1-7&_nc_sid=7965db&_nc_ohc=U8gXjd1OGkIQ7kNvgEAX5RG&_nc_ht=scontent-hou1-1.xx&oh=00_AYC0Xmzs7bnhR3838ubHXK0x1IC-aQE4wMezNbiKTTs_MQ&oe=668B36FC
157.240.24.13
https://fburl.com/wiki/xrzohrqb
unknown
https://www.facebook.com/ajax/bz?__a=1&__aaid=0&__ccg=GOOD&__comet_req=15&__hs=19907.HYP%3Acomet_loggedout_pkg.2.1..0.0&__hsi=7387405675209508329&__req=a&__rev=1014647652&__s=hnigsi%3Awf9jed%3Aqcwyo5&__spin_b=trunk&__spin_r=1014647652&__spin_t=1720014418&__user=0&dpr=1&jazoest=2985&lsd=AVqIzvvP8QI&ph=C3
157.240.0.35
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449674164_874555164725584_2448760145427529645_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjoyMjc1Nzc0NTYyODE0Mzk5fQ%3D%3D&_nc_ohc=8rroXHNeUjAQ7kNvgHhLmHL&_nc_ht=video-hou1-1.xx&oh=00_AYARYDY6Y4AYkuTRtfdga0YHpMbfJpH6rSsK7K4Qg6HnnQ&oe=668B2E1F&bytestart=0&byteend=825
157.240.24.20
https://policies.google.com/privacy
unknown
https://static.xx.fbcdn.net/rsrc.php/v3/y5/r/16tMAVgIV_z.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/446046520_970955458109515_333034421707538801_n.jpg?stp=dst-jpg_s960x960&_nc_cat=1&ccb=1-7&_nc_sid=c3bc4c&_nc_ohc=RS0G25oWr9QQ7kNvgGxHCeo&_nc_ht=scontent-hou1-1.xx&oh=00_AYC-vaZU89WpZdj_BjufXnH3BeZBz93wiAZj1m38xs565g&oe=668B136D
157.240.24.13
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/438227998_963705932159565_7340903352037785771_n.jpg?stp=dst-jpg_p296x100&_nc_cat=1&ccb=1-7&_nc_sid=7965db&_nc_ohc=1xjCnifaTkkQ7kNvgGL-gKy&_nc_ht=scontent-hou1-1.xx&oh=00_AYADlQRqzZ2P08jO-As9NPO_adR-6OwCkbxDjNJ2LcT8sA&oe=668B16B9
157.240.24.13
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449398058_1195349098256604_9067563155065100939_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EyMCIsInZpZGVvX2lkIjo0ODM4NTEyMjczNzcxNDl9&_nc_ohc=RPfSCQmAkSEQ7kNvgHESxzA&_nc_ht=video-hou1-1.xx&oh=00_AYAak_kjDxITytKA-YmtmzcobE-dl2vtODfyGcf9jMUsaA&oe=668B1B33&bytestart=826&byteend=893
157.240.24.20
https://video.xx.fbcdn.net/v/t39.25447-2/448325845_1860632697787170_424171818332402913_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyMzc4NzAxNDQyMzI0OTE2fQ%3D%3D&_nc_ohc=vmP6rYGv8aMQ7kNvgHFR206&_nc_ht=video-hou1-1.xx&oh=00_AYC2Sio-uxqPzwpvxlzJJP4X-jsOz4ggPnlyQrjIWq3OZA&oe=668B3C56&bytestart=824&byteend=963
31.13.71.14
https://video.xx.fbcdn.net/v/t39.25447-2/449694296_1560210191559240_4020235943818543510_n.mp4?_nc_cat=108&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjo3Njc0NDgwNTg2MDIwOTB9&_nc_ohc=G_r6oeHwmwAQ7kNvgG6sqtC&_nc_ht=video-hou1-1.xx&oh=00_AYDS2eQw4y1eaYumABsQPAZWQpmI7avDCc5ri5ShKEtmDA&oe=668B3299&bytestart=1014&byteend=45134
31.13.71.14
https://static.xx.fbcdn.net/rsrc.php/v3/yb/r/7NqDjYL3eb9.png
157.240.0.6
https://static.xx.fbcdn.net/rsrc.php/v3/y0/r/eFZD1KABzRA.png
157.240.0.6
https://video.xx.fbcdn.net/v/t39.25447-2/449815513_985779669957805_3893353821137976724_n.mp4?_nc_cat=107&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EyMCIsInZpZGVvX2lkIjozOTk4MjU3NDU4MTEzOTJ9&_nc_ohc=uHLhfLpiKxIQ7kNvgGFZCP3&_nc_ht=video-hou1-1.xx&oh=00_AYAbpcVpsyLUwD9hIKidj0TCKVN5PwLBcvM2kePW7QMEtg&oe=668B173E&bytestart=826&byteend=881
31.13.71.14
https://scontent-hou1-1.xx.fbcdn.net/v/t39.30808-1/449321335_395689360177909_8550182580164337098_n.jpg?stp=cp0_dst-jpg_p50x50&_nc_cat=102&ccb=1-7&_nc_sid=50d2ac&_nc_ohc=_Xa0Uj6O_nMQ7kNvgGuNcWv&_nc_ht=scontent-hou1-1.xx&oh=00_AYAKGvx2DcfP2mtCRlf1OfbIssA3-V862UHeEWtcU2ZXbg&oe=668B1EAB
157.240.24.13
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449751511_845177986944804_8287809256175764587_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EzMCIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=mjXxrHP1kE4Q7kNvgFBSFZf&_nc_ht=video-hou1-1.xx&oh=00_AYB4GfMz_0iTZ4H2p5URBe2WEpex8Ar6vOL0_DjJz8ZEXA&oe=668B2D27&bytestart=918&byteend=120110
157.240.24.20
https://static.xx.fbcdn.net/rsrc.php/v3/yO/r/q8Uic1K195T.png
157.240.0.6
https://optout.aboutads.info/
unknown
https://video.xx.fbcdn.net/v/t39.25447-2/449469933_999248815154664_2459728092857196365_n.mp4?_nc_cat=107&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E1MCIsInZpZGVvX2lkIjo4MjY5OTY3OTI4OTg1MDh9&_nc_ohc=53ON0wakUEUQ7kNvgH8fCLD&_nc_ht=video-hou1-1.xx&oh=00_AYDI6Iik_LOD4NehQyFV0UzqSJ9I68i96GyPpRl1VB4biA&oe=668B3465&bytestart=906&byteend=89068
31.13.71.14
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449469933_999248815154664_2459728092857196365_n.mp4?_nc_cat=107&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E1MCIsInZpZGVvX2lkIjo4MjY5OTY3OTI4OTg1MDh9&_nc_ohc=53ON0wakUEUQ7kNvgH8fCLD&_nc_ht=video-hou1-1.xx&oh=00_AYDI6Iik_LOD4NehQyFV0UzqSJ9I68i96GyPpRl1VB4biA&oe=668B3465&bytestart=826&byteend=905
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449705054_491731483514107_4213972426740765497_n.mp4?_nc_cat=109&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo0ODM4NTEyMjczNzcxNDl9&_nc_ohc=sfLLDPkRnaYQ7kNvgEmsM24&_nc_ht=video-hou1-1.xx&oh=00_AYDKK53K9bXolIEERe7J3ZqtehB6VIGEfx1JVnAXC5q7jw&oe=668B388A&bytestart=0&byteend=823
157.240.24.20
https://static.xx.fbcdn.net/rsrc.php/v3iZ_a4/yg/l/en_GB/Ob6F3Vt7OqX.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://video.xx.fbcdn.net/v/t39.25447-2/449178494_787972259986290_5287065104367118752_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo0NTgyNjgxNTAyNzQ4NTh9&_nc_ohc=Okqc0ec779wQ7kNvgGSxSbJ&_nc_ht=video-hou1-1.xx&oh=00_AYA3ox8WBXD_V0qsnAa4MOypYGNXmY1Wh35stftI4T6iPg&oe=668B2BD8&bytestart=0&byteend=823
31.13.71.14
https://video.xx.fbcdn.net/v/t39.25447-2/449450069_1948022175632401_5300699791447743925_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoxMDAxNDA0NzU4MzY1NzIxfQ%3D%3D&_nc_ohc=BNS_liS8xuMQ7kNvgH3t1jS&_nc_ht=video-hou1-1.xx&oh=00_AYC7NzW8Tf2T3-SDpTeOzem4P1HpY91CkP_Lc2y6Iv1cSA&oe=668B1021&bytestart=0&byteend=823
31.13.71.14
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/441199429_890954462796791_2599688641654411968_n.jpg?stp=dst-jpg_s960x960&_nc_cat=1&ccb=1-7&_nc_sid=7965db&_nc_ohc=Ci_SargI4XEQ7kNvgG7ebvt&_nc_ht=scontent-hou1-1.xx&oh=00_AYCzsrsVdh2wmh8OT3jXnKLtKOFIQPVdK7rNhsBe6xLOqw&oe=668B12FF
157.240.24.13
https://video.xx.fbcdn.net/v/t39.25447-2/449518986_448740041424809_5919772283050550271_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyMjc1Nzc0NTYyODE0Mzk5fQ%3D%3D&_nc_ohc=23n16DcR66EQ7kNvgHX4UqZ&_nc_ht=video-hou1-1.xx&oh=00_AYCa0PsCLCaN3TaWPeLXaqOCav_pU275cHdSXT7i7EHYZA&oe=668B1C51&bytestart=0&byteend=823
31.13.71.14
https://www.facebook.com/ajax/bz?__a=1&__aaid=0&__ccg=GOOD&__comet_req=15&__hs=19907.HYP%3Acomet_loggedout_pkg.2.1..0.0&__hsi=7387405675209508329&__req=j&__rev=1014647652&__s=%3Awf9jed%3Aqcwyo5&__spin_b=trunk&__spin_r=1014647652&__spin_t=1720014418&__user=0&dpr=1&jazoest=2985&lsd=AVqIzvvP8QI&ph=C3
157.240.0.35
https://static.xx.fbcdn.net/rsrc.php/v3i0Wo4/y4/l/en_GB/p2aYR2TDczj.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://www.youtube.com/accountcrosoft
unknown
https://www.youtube.com/accountqn
unknown
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/448325845_1860632697787170_424171818332402913_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyMzc4NzAxNDQyMzI0OTE2fQ%3D%3D&_nc_ohc=vmP6rYGv8aMQ7kNvgHFR206&_nc_ht=video-hou1-1.xx&oh=00_AYC2Sio-uxqPzwpvxlzJJP4X-jsOz4ggPnlyQrjIWq3OZA&oe=668B3C56&bytestart=964&byteend=18849
157.240.24.20
https://video.xx.fbcdn.net/v/t39.25447-2/449745839_1625389988297537_5965255506811228425_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=nUpM9yYV9IEQ7kNvgFRwSFy&_nc_ht=video-hou1-1.xx&oh=00_AYADDmQRaqjBi1xIuwZIcUt6Iulzb8TMl1WZc9aMDS0vwg&oe=668B2F59&bytestart=0&byteend=823
31.13.71.14
https://video.xx.fbcdn.net/v/t39.25447-2/449749398_919410706654359_5930299620981928735_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E2MCIsInZpZGVvX2lkIjo3NjU0MTQxNDU2NjkzMzR9&_nc_ohc=rOrpAmpg2qEQ7kNvgHrh-6Y&_nc_ht=video-hou1-1.xx&oh=00_AYCTXVxhfNzeBOavxbvCAUwoD6y6ShLZHvezDgM-zVRHrg&oe=668B327F&bytestart=0&byteend=825
31.13.71.14
https://scontent-hou1-1.xx.fbcdn.net/v/t39.30808-1/289004470_580488300108017_2940314955690280756_n.jpg?stp=cp0_dst-jpg_p50x50&_nc_cat=1&ccb=1-7&_nc_sid=f4b9fd&_nc_ohc=FAMyFz7apqoQ7kNvgFhFiWn&_nc_ht=scontent-hou1-1.xx&oh=00_AYDHLxN6yljKnFv_vu2kY2lnm3xovL4hgUVuejOCJYaU0A&oe=668B2C89
157.240.24.13
https://static.xx.fbcdn.net/rsrc.php/v3iPlJ4/yd/l/en_GB/hZ5gcIcWbl3.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449749398_919410706654359_5930299620981928735_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E2MCIsInZpZGVvX2lkIjo3NjU0MTQxNDU2NjkzMzR9&_nc_ohc=rOrpAmpg2qEQ7kNvgHrh-6Y&_nc_ht=video-hou1-1.xx&oh=00_AYCTXVxhfNzeBOavxbvCAUwoD6y6ShLZHvezDgM-zVRHrg&oe=668B327F&bytestart=0&byteend=825
157.240.24.20
https://video.xx.fbcdn.net/v/t39.25447-2/449745839_1625389988297537_5965255506811228425_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=nUpM9yYV9IEQ7kNvgFRwSFy&_nc_ht=video-hou1-1.xx&oh=00_AYADDmQRaqjBi1xIuwZIcUt6Iulzb8TMl1WZc9aMDS0vwg&oe=668B2F59&bytestart=1012&byteend=18621
31.13.71.14
https://scontent-hou1-1.xx.fbcdn.net/v/t39.30808-1/433129071_935133255288704_3257703405738048815_n.jpg?stp=c0.0.50.50a_cp0_dst-jpg_p50x50&_nc_cat=1&ccb=1-7&_nc_sid=f4b9fd&_nc_ohc=otqXuLx_E1EQ7kNvgFnvvly&_nc_ht=scontent-hou1-1.xx&oh=00_AYA6D03wweMwBvay2J7uea18YYF9XZUEe_UiJceuZEtTMA&oe=668B235D
157.240.24.13
https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessage
unknown
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/442058648_1390260634990350_3671320554231620569_n.jpg?stp=dst-jpg_s960x960&_nc_cat=1&ccb=1-7&_nc_sid=7965db&_nc_ohc=YHyfjqs1T0kQ7kNvgGvisSS&_nc_ht=scontent-hou1-1.xx&oh=00_AYBYI33eJMZCXkexmSD0KK_SoAPEM1EGdCY5gNvWJYScLA&oe=668B1CF7
157.240.24.13
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449398058_1195349098256604_9067563155065100939_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EyMCIsInZpZGVvX2lkIjo0ODM4NTEyMjczNzcxNDl9&_nc_ohc=RPfSCQmAkSEQ7kNvgHESxzA&_nc_ht=video-hou1-1.xx&oh=00_AYAak_kjDxITytKA-YmtmzcobE-dl2vtODfyGcf9jMUsaA&oe=668B1B33&bytestart=894&byteend=83807
157.240.24.20
https://static.xx.fbcdn.net/rsrc.php/v3i8xq4/ym/l/en_GB/DKP4VMyHWvT.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://video.xx.fbcdn.net/v/t39.25447-2/449398058_1195349098256604_9067563155065100939_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3EyMCIsInZpZGVvX2lkIjo0ODM4NTEyMjczNzcxNDl9&_nc_ohc=RPfSCQmAkSEQ7kNvgHESxzA&_nc_ht=video-hou1-1.xx&oh=00_AYAak_kjDxITytKA-YmtmzcobE-dl2vtODfyGcf9jMUsaA&oe=668B1B33&bytestart=826&byteend=893
31.13.71.14
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449400216_441070382166231_7996235846170639077_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJhdjEtcjFnZW4ydnA5X3E0MCIsInZpZGVvX2lkIjoxMDAxNDA0NzU4MzY1NzIxfQ%3D%3D&_nc_ohc=cB3Oue079RsQ7kNvgEZLyDk&_nc_ht=video-hou1-1.xx&oh=00_AYCT__3My20AalVBeIFC2K6dKGjPy7rYUAMG5ruq9MWfaw&oe=668B25EF&bytestart=894&byteend=366721
157.240.24.20
https://static.xx.fbcdn.net/rsrc.php/v3iwLy4/yE/l/en_GB/ZpztLkU6jDd.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://scontent-hou1-1.xx.fbcdn.net/v/t39.30808-1/347289288_940658950320773_5181046417556168232_n.jpg?stp=cp6_dst-jpg_p50x50&_nc_cat=1&ccb=1-7&_nc_sid=50d2ac&_nc_ohc=lUai_6JnLsUQ7kNvgGud4pc&_nc_ht=scontent-hou1-1.xx&oh=00_AYCZHvtcBsXaonrh2ASHSgFuSaMRue07RBVkGTtP2PHBEQ&oe=668B288F
157.240.24.13
https://static.xx.fbcdn.net/rsrc.php/v3iWd-4/yP/l/en_GB/M-AHdbpN8xr.js?_nc_x=Ij3Wp8lg5Kz
157.240.0.6
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449745839_1625389988297537_5965255506811228425_n.mp4?_nc_cat=105&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjoyNTExMzYzMzg5MjUxNTU5fQ%3D%3D&_nc_ohc=nUpM9yYV9IEQ7kNvgFRwSFy&_nc_ht=video-hou1-1.xx&oh=00_AYADDmQRaqjBi1xIuwZIcUt6Iulzb8TMl1WZc9aMDS0vwg&oe=668B2F59&bytestart=0&byteend=823
157.240.24.20
https://scontent-hou1-1.xx.fbcdn.net/v/t15.5256-10/446068353_999612811433881_8854588659946229745_n.jpg?stp=dst-jpg_p206x206&_nc_cat=1&ccb=1-7&_nc_sid=c3bc4c&_nc_ohc=RpsbA1wn8ZwQ7kNvgGha4UO&_nc_ht=scontent-hou1-1.xx&oh=00_AYBZ922IFWTLq33N1-vRQM-jp4KhmslU9OrrRaAV8D7U4g&oe=668B1FE7
157.240.24.13
https://policies.google.com/privacy/additional
unknown
https://play.google.com/log?format=json&hasfast=true&authuser=0
142.250.186.46
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449744607_459862283322980_6029144762460813703_n.mp4?_nc_cat=110&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfcjJldmV2cDktcjFnZW4ydnA5X3E1MCIsInZpZGVvX2lkIjo0NTgyNjgxNTAyNzQ4NTh9&_nc_ohc=LlPyzkIP5XEQ7kNvgHJuUCd&_nc_ht=video-hou1-1.xx&oh=00_AYAjW869xKiZoErQUaRNDOrLLWh7lwZOD4IAVkDPOPy1rQ&oe=668B3F79&bytestart=818&byteend=873
157.240.24.20
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449701410_474789018534823_132095418009423402_n.mp4?_nc_cat=1&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF80OF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo3NjU0MTQxNDU2NjkzMzR9&_nc_ohc=a4-7etsBSc0Q7kNvgGNQ-c5&_nc_ht=video-hou1-1.xx&oh=00_AYBddMuxclFe9RyZwMpsaRcIsWvTHMHPaUlXWSkfhVbxJg&oe=668B2AE3&bytestart=964&byteend=14683
157.240.24.20
https://www.facebook.com/ajax/bz?__a=1&__aaid=0&__ccg=GOOD&__comet_req=15&__hs=19907.HYP%3Acomet_loggedout_pkg.2.1..0.0&__hsi=7387405675209508329&__req=8&__rev=1014647652&__s=hnigsi%3Awf9jed%3Aqcwyo5&__spin_b=trunk&__spin_r=1014647652&__spin_t=1720014418&__user=0&dpr=1&jazoest=2985&lsd=AVqIzvvP8QI&ph=C3
157.240.0.35
https://video-hou1-1.xx.fbcdn.net/v/t39.25447-2/449705054_491731483514107_4213972426740765497_n.mp4?_nc_cat=109&ccb=1-7&_nc_sid=9a5d50&efg=eyJ2ZW5jb2RlX3RhZyI6ImRhc2hfYXVkaW9fYWFjcF82NF9mbm9ybTE0X2ZyYWdfMl9hdWRpbyIsInZpZGVvX2lkIjo0ODM4NTEyMjczNzcxNDl9&_nc_ohc=sfLLDPkRnaYQ7kNvgEmsM24&_nc_ht=video-hou1-1.xx&oh=00_AYDKK53K9bXolIEERe7J3ZqtehB6VIGEfx1JVnAXC5q7jw&oe=668B388A&bytestart=928&byteend=18863
157.240.24.20
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
star-mini.c10r.facebook.com
157.240.0.35
youtube-ui.l.google.com
142.250.185.78
scontent.xx.fbcdn.net
157.240.253.1
www3.l.google.com
142.250.186.110
play.google.com
142.250.186.46
scontent-hou1-1.xx.fbcdn.net
157.240.24.13
video.xx.fbcdn.net
157.240.252.22
www.google.com
142.250.185.132
video-hou1-1.xx.fbcdn.net
157.240.24.20
www.facebook.com
unknown
accounts.youtube.com
unknown
www.youtube.com
unknown
static.xx.fbcdn.net
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.46
play.google.com
United States
142.250.185.78
youtube-ui.l.google.com
United States
157.240.24.20
video-hou1-1.xx.fbcdn.net
United States
31.13.71.14
unknown
Ireland
192.168.2.17
unknown
unknown
192.168.2.6
unknown
unknown
157.240.0.6
unknown
United States
192.168.2.5
unknown
unknown
142.250.186.110
www3.l.google.com
United States
157.240.252.35
unknown
United States
157.240.252.13
unknown
United States
142.250.186.78
unknown
United States
157.240.0.35
star-mini.c10r.facebook.com
United States
142.250.185.132
www.google.com
United States
239.255.255.250
unknown
Reserved
142.250.185.174
unknown
United States
157.240.253.1
scontent.xx.fbcdn.net
United States
157.240.24.13
scontent-hou1-1.xx.fbcdn.net
United States
There are 8 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
800000
unkown
page write copy
7CC000
unkown
page readonly
731000
unkown
page execute read
26E6000
heap
page read and write
183E000
stack
page read and write
804000
unkown
page readonly
7FC000
unkown
page write copy
804000
unkown
page readonly
19AF000
heap
page read and write
730000
unkown
page readonly
7FC000
unkown
page read and write
7F2000
unkown
page readonly
1948000
heap
page read and write
1885000
heap
page read and write
4A4E000
stack
page read and write
4E8E000
stack
page read and write
731000
unkown
page execute read
5BBC000
stack
page read and write
196D000
heap
page read and write
165B000
stack
page read and write
196D000
heap
page read and write
213E000
stack
page read and write
26D0000
heap
page read and write
7CC000
unkown
page readonly
7F2000
unkown
page readonly
600F000
stack
page read and write
19AF000
heap
page read and write
26E0000
heap
page read and write
56CE000
stack
page read and write
730000
unkown
page readonly
3E64000
heap
page read and write
167E000
stack
page read and write
1973000
heap
page read and write
57BB000
stack
page read and write
5770000
heap
page read and write
1880000
heap
page read and write
528D000
stack
page read and write
4E4F000
stack
page read and write
3E40000
heap
page read and write
1972000
heap
page read and write
163E000
stack
page read and write
5C0E000
stack
page read and write
166F000
stack
page read and write
49EE000
stack
page read and write
253E000
stack
page read and write
164E000
stack
page read and write
3E60000
heap
page read and write
1840000
heap
page read and write
17FE000
stack
page read and write
41EC000
stack
page read and write
45ED000
stack
page read and write
52CE000
stack
page read and write
1940000
heap
page read and write
16E0000
heap
page read and write
127A000
stack
page read and write
686B000
stack
page read and write
There are 46 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://www.facebook.com/video
https://www.facebook.com/video
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Faccounts.google.com%2F&followup=https%3A%2F%2Faccounts.google.com%2F&ifkv=AS5LTARZKDMTmesad8HK-ikBAHhzz8IST8pWeRddWAkQK0XAluidDpzjNO9jfTEdmgvkZpEHl_iu&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S704733099%3A1720014422110673&ddm=0
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Faccounts.google.com%2F&followup=https%3A%2F%2Faccounts.google.com%2F&ifkv=AS5LTARZKDMTmesad8HK-ikBAHhzz8IST8pWeRddWAkQK0XAluidDpzjNO9jfTEdmgvkZpEHl_iu&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S704733099%3A1720014422110673&ddm=0
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Faccounts.google.com%2F&followup=https%3A%2F%2Faccounts.google.com%2F&ifkv=AS5LTARZKDMTmesad8HK-ikBAHhzz8IST8pWeRddWAkQK0XAluidDpzjNO9jfTEdmgvkZpEHl_iu&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S704733099%3A1720014422110673&ddm=0
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=en&ifkv=AS5LTAR8rEwgmzn0E0Ws0T6gqeUwTHX4Imt7QbDau7pnMUPXJkWdd9l8p-hbflISp2iYLL9ABE70sw&passive=true&service=youtube&uilel=3&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S218795270%3A1720014422347993&ddm=0
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=en&ifkv=AS5LTAR8rEwgmzn0E0Ws0T6gqeUwTHX4Imt7QbDau7pnMUPXJkWdd9l8p-hbflISp2iYLL9ABE70sw&passive=true&service=youtube&uilel=3&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S218795270%3A1720014422347993&ddm=0
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fwww.youtube.com%2Fsignin%3Faction_handle_signin%3Dtrue%26app%3Ddesktop%26hl%3Den%26next%3Dhttps%253A%252F%252Fwww.youtube.com%252Faccount%26feature%3Dredirect_login&hl=en&ifkv=AS5LTAR8rEwgmzn0E0Ws0T6gqeUwTHX4Imt7QbDau7pnMUPXJkWdd9l8p-hbflISp2iYLL9ABE70sw&passive=true&service=youtube&uilel=3&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S218795270%3A1720014422347993&ddm=0
https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1110236877&timestamp=1720014429579
https://accounts.google.com/_/bscframe
https://accounts.youtube.com/accounts/CheckConnection?pmpo=https%3A%2F%2Faccounts.google.com&v=-1756697494&timestamp=1720014433319
There are 1 hidden doms, click here to show them.