Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB
--service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1764,i,17311812855738133621,17887974914451854333,131072
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.30fe.com/
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://www.30fe.com/
|
|||
https://www.30fe.com/news/
|
|||
https://www.30fe.com/wp-content/themes/30forensics/assets/images/30logo_CropE.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF0248-Edit-copy-2-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/testimonials/
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/elementor/css/post-4870.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF9169-Edit-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/about-us/
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/20220117-Antone-Dabeet_5204111-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/30fe_homepage_May2017.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Matt-Hartog-Final-web-3-2-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Sparling_Rob-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF9541-copy-3-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF7763-Crop-center-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF7991_edit2-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF0796_AI-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/css/slick-theme.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/images/30logo_cropC.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/30fe-f-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF1339-Edit4-crop-2-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/elementor/assets/css/frontend-legacy.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Chris-Ciasnocha-FinalDSCF5912-Edit-highres-e1505313763214-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Sinclair-Brittany-Final-DSCF5431-Edit-highres-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/30fe-f-150x150.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/js/30f.main.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Fabbroni_Mark-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/FUJI0990-22-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF2814-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/images/30logo_cropA.png
|
35.206.111.91
|
||
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
|
142.250.203.110
|
||
https://www.30fe.com/wp-content/plugins/formidable/css/formidableforms.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/gp-premium/general/icons/icons.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/elementor/assets/lib/font-awesome/fonts/fontawesome-webfont.woff2?v=4.7.0
|
35.206.111.91
|
||
http://www.30fe.com/
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/2017/03/subscribe-bg.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/2017/04/30Logo_White_RGB.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF6937_ps-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF6328-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/generatepress/assets/css/unsemantic-grid.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/gp-premium/menu-plus/functions/css/sticky.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF6593-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/people/
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF3966-2_AI-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Saleh_Emily-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF9905-copy-crop-size.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/v4-shims.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Rhode_John-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/font-awesome.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.min.js
|
35.206.111.91
|
||
https://www.30fe.com/#content
|
|||
https://www.30fe.com/wp-content/uploads/Muir_Brad-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/js/slick.min.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Paquette_Mark-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/iStock-520410819_Testimonials_1920x200.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/enable-jquery-migrate-helper/js/jquery/jquery-1.12.4-wp.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/gp-premium/menu-plus/functions/js/sticky.min.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/gp-premium/menu-plus/functions/css/menu-logo.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/css/magnific-popup.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/CivilStructural-Failure.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Jamie_Final_Web-Main-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/FUJI2327-editse-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Robalino_Pablo-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/about-us/
|
|||
https://www.30fe.com/wp-content/uploads/FUJI3217-copy-3-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/gp-premium/menu-plus/functions/js/offside.min.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/images/social/twitter.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/gp-premium/sections/functions/js/parallax.min.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/FUJI1444-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/style.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/images/30logo_cropB.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF6999-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/generatepress/assets/css/mobile.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF5151-cc-crop-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF5137-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF6501crop-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-includes/css/dist/block-library/style.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/css/slick.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Fire-Electrical.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/js/jquery.magnific-popup.min.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Aquino_Paul-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF7468-copy-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF3067-Recovered-copy-4-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF9289-copy-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/gp-premium/sections/functions/css/style.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/FUJI2992-copy-2-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/images/social/linkedin.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Jim_Rob3-360x352.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/jfabmedia-15-edit-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/elementor/css/global.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/General_April25.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Parkinson_Rob-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-includes/css/classic-themes.min.css
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF7323-edit-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/DSCF4467-Edit-360x360.png
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Toughlouian_Jennifer-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/themes/30forensics/assets/js/list.min.js
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/plugins/elementor/assets/lib/font-awesome/css/all.min.css
|
35.206.111.91
|
||
https://www.30fe.com/associations/
|
|||
https://www.30fe.com/wp-content/uploads/FUJI1354-edit2-crop-360x360.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/iStock-530188857_AboutUs_1920x200.jpg
|
35.206.111.91
|
||
https://www.30fe.com/wp-content/uploads/Fisher_Derek-360x360.jpg
|
35.206.111.91
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
accounts.google.com
|
172.217.168.45
|
||
30fe.com
|
35.206.111.91
|
||
www.google.com
|
172.217.168.68
|
||
clients.l.google.com
|
142.250.203.110
|
||
clients2.google.com
|
unknown
|
||
www.30fe.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
192.168.2.1
|
unknown
|
unknown
|
||
142.250.203.110
|
clients.l.google.com
|
United States
|
||
172.217.168.68
|
www.google.com
|
United States
|
||
172.217.168.45
|
accounts.google.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
35.206.111.91
|
30fe.com
|
United States
|
||
127.0.0.1
|
unknown
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
ahfgeienlihckogmohjhadlkjgocpleb
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
gdaefkejpgkiemlaofpalmlakkmbjdnl
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
kmendfapggjehodndflmmgagdbamhnfd
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
mhjfbmdgcfjbbpaeojofohoefgiehjai
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
neajdppkdcdipfabeoofebfddakdcjhd
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nkeimhogjdpnpccoofpliimaahmaaome
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
prefs.preference_reset_time
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
|
S-1-5-21-3853321935-2125563209-4053062332-1002
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
gdaefkejpgkiemlaofpalmlakkmbjdnl
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
kmendfapggjehodndflmmgagdbamhnfd
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
neajdppkdcdipfabeoofebfddakdcjhd
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nkeimhogjdpnpccoofpliimaahmaaome
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
|
nmmhkkegccagdldgiimedpiccmgmieda
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
||
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
|
dr
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
|
user_experience_metrics.stability.exited_cleanly
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
media.cdm.origin_data
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
software_reporter.reporting
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
media.storage_id_salt
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
google.services.last_account_id
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
google.services.account_id
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.last_triggered_for_startup_urls
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.last_triggered_for_homepage
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
module_blocklist_cache_md5_digest
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
software_reporter.prompt_seed
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
default_search_provider_data.template_url_data
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
safebrowsing.incidents_sent
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
pinned_tabs
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
browser.show_home_button
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
search_provider_overrides
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.last_triggered_for_default_search
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
prefs.preference_reset_time
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
software_reporter.prompt_version
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
google.services.last_username
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
session.startup_urls
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
session.restore_on_startup
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
settings_reset_prompt.prompt_wave
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
homepage
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
|
homepage_is_newtabpage
|
||
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
|
lastrun
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
|
Blob
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8
|
Blob
|
||
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
|
lastrun
|
||
HKEY_USERSS-1-5-19\Software\Microsoft\Cryptography\TPM\Telemetry
|
TraceTimeLast
|
||
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
|
S-1-5-21-3853321935-2125563209-4053062332-1002
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
|
StatusCodes
|
||
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
|
state
|
There are 44 hidden registries, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://www.30fe.com/
|
||
https://www.30fe.com/#content
|
||
https://www.30fe.com/about-us/
|
||
https://www.30fe.com/people/
|
||
https://www.30fe.com/testimonials/
|
||
https://www.30fe.com/people/
|
||
https://www.30fe.com/associations/
|
||
https://www.30fe.com/news/
|