Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Aug 28 04:07:22 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Aug 28 04:07:22 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Aug 28 04:07:22 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Aug 28 04:07:22 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Aug 28 04:07:22 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 100
|
ASCII text, with very long lines (5632)
|
downloaded
|
||
Chrome Cache Entry: 101
|
PNG image data, 130 x 130, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 102
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 103
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 104
|
Unicode text, UTF-8 text, with very long lines (65297)
|
dropped
|
||
Chrome Cache Entry: 105
|
Unicode text, UTF-8 text, with very long lines (2258)
|
downloaded
|
||
Chrome Cache Entry: 106
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 107
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 108
|
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 109
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 110
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1278, components
3
|
downloaded
|
||
Chrome Cache Entry: 111
|
PNG image data, 130 x 130, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 112
|
ASCII text, with very long lines (2904)
|
downloaded
|
||
Chrome Cache Entry: 113
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 114
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 115
|
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
|
dropped
|
||
Chrome Cache Entry: 116
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 117
|
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 118
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 119
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 120
|
Web Open Font Format (Version 2), CFF, length 29924, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 121
|
HTML document, Unicode text, UTF-8 text, with very long lines (28494)
|
downloaded
|
||
Chrome Cache Entry: 122
|
Unicode text, UTF-8 text, with very long lines (2258)
|
dropped
|
||
Chrome Cache Entry: 123
|
Web Open Font Format (Version 2), CFF, length 29980, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 124
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 125
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 126
|
Web Open Font Format (Version 2), CFF, length 41556, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 127
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 128
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 129
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 130
|
Unicode text, UTF-8 text, with very long lines (65297)
|
downloaded
|
||
Chrome Cache Entry: 131
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 132
|
Web Open Font Format (Version 2), CFF, length 78776, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 133
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 134
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1278, components
3
|
dropped
|
||
Chrome Cache Entry: 135
|
ASCII text, with very long lines (65134)
|
dropped
|
||
Chrome Cache Entry: 136
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 137
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 138
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 139
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 140
|
Web Open Font Format (Version 2), CFF, length 75984, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 141
|
ASCII text, with very long lines (13689), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 142
|
PNG image data, 176 x 168, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 143
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 144
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 145
|
ASCII text, with very long lines (45810)
|
dropped
|
||
Chrome Cache Entry: 146
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 147
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 148
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 149
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 150
|
PNG image data, 176 x 168, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 151
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 152
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 153
|
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 154
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 155
|
ASCII text, with very long lines (65519)
|
downloaded
|
||
Chrome Cache Entry: 156
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 157
|
ASCII text, with very long lines (65134)
|
downloaded
|
||
Chrome Cache Entry: 158
|
ASCII text, with very long lines (45810)
|
downloaded
|
||
Chrome Cache Entry: 159
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 160
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 161
|
Web Open Font Format (Version 2), CFF, length 29752, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 162
|
Unicode text, UTF-8 text, with very long lines (2258)
|
downloaded
|
||
Chrome Cache Entry: 163
|
Web Open Font Format (Version 2), CFF, length 76192, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 164
|
Web Open Font Format (Version 2), CFF, length 77784, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 165
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 166
|
ASCII text, with very long lines (2904)
|
dropped
|
||
Chrome Cache Entry: 167
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 168
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 92
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 93
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 94
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 95
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 96
|
Unicode text, UTF-8 text, with very long lines (2258)
|
dropped
|
||
Chrome Cache Entry: 97
|
ASCII text, with very long lines (65519)
|
dropped
|
||
Chrome Cache Entry: 98
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 99
|
SVG Scalable Vector Graphics image
|
downloaded
|
There are 74 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=2080,i,4616497776670431106,16504508632005767747,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://na4.documents.adobe.com/public/esign?tsid=CBFCIBAACBSCTBABDUAAABACAABAA5tR3-VKwfTm2oK1ZFsGY4F1bMY0OocfkOty0_NR8WPsvGcqcPMX99hsfyAX0DyWSeccTdFVfZvOduC-3ChA5AMz28_30EDGfKA5OdbfA3lP90ySigWqVPyIMzXTGFx2E&"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://na4.documents.adobe.com/public/esign?tsid=CBFCIBAACBSCTBABDUAAABACAABAA5tR3-VKwfTm2oK1ZFsGY4F1bMY0OocfkOty0_NR8WPsvGcqcPMX99hsfyAX0DyWSeccTdFVfZvOduC-3ChA5AMz28_30EDGfKA5OdbfA3lP90ySigWqVPyIMzXTGFx2E&
|
|||
https://sso.behance.net/ims
|
unknown
|
||
https://jqueryvalidation.org/
|
unknown
|
||
http://jquery.org/license
|
unknown
|
||
https://lodash.com/
|
unknown
|
||
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/
|
unknown
|
||
https://static.adobelogin.com/clients/adobe-sign-2020/4x_f39219ea552b8fc1c7b42c6a2d0290c2.png
|
13.224.189.8
|
||
http://sizzlejs.com/
|
unknown
|
||
https://static.adobelogin.com/clients/adobe-sign-2020/2x_f39219ea552b8fc1c7b42c6a2d0290c2.png
|
unknown
|
||
http://jqueryui.com
|
unknown
|
||
http://api.jqueryui.com/position/
|
unknown
|
||
https://use.typekit.net/af/e301c6/0000000000000000000149e7/27/
|
unknown
|
||
https://github.com/jquery/jquery-color
|
unknown
|
||
http://typekit.com/eulas/0000000000000000000149e7
|
unknown
|
||
https://use.typekit.net/af/cb695f/000000000000000000017701/27/
|
unknown
|
||
http://underscorejs.org/LICENSE
|
unknown
|
||
http://eightmedia.github.com/hammer.js
|
unknown
|
||
https://jquery.org/license
|
unknown
|
||
https://github.com/gabceb/jquery-browser-plugin
|
unknown
|
||
https://jquery.com/
|
unknown
|
||
https://dpm.demdex.net/id/rd?d_visid_ver=5.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1724821684601
|
52.50.19.120
|
||
https://p.typekit.net/p.gif
|
unknown
|
||
http://typekit.com/eulas/0000000000000000000176ff
|
unknown
|
||
https://github.com/gabceb
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017701
|
unknown
|
||
https://static.adobelogin.com/clients/adobe-sign-2020/f39219ea552b8fc1c7b42c6a2d0290c2.png
|
unknown
|
||
https://dpm.demdex.net/id?d_visid_ver=5.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1724821684601
|
52.50.19.120
|
||
http://typekit.com/eulas/000000000000000000017702
|
unknown
|
||
http://flesler.blogspot.com
|
unknown
|
||
http://typekit.com/eulas/000000000000000000017703
|
unknown
|
||
https://lodash.com/license
|
unknown
|
||
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/
|
unknown
|
||
https://static.adobelogin.com/clients/adobe-sign-2020/1x_f39219ea552b8fc1c7b42c6a2d0290c2.png
|
unknown
|
||
http://flesler.blogspot.com/2007/10/jqueryscrollto.html
|
unknown
|
||
https://openjsf.org/
|
unknown
|
||
https://use.typekit.net/af/74ffb1/000000000000000000017702/27/
|
unknown
|
||
https://github.com/websanova/mousestop
|
unknown
|
||
https://sizzlejs.com/
|
unknown
|
||
https://js.foundation/
|
unknown
|
||
https://github.com/facebook/regenerator/blob/main/LICENSE
|
unknown
|
||
http://jedwatson.github.io/classnames
|
unknown
|
||
http://trentrichardson.com/examples/timepicker
|
unknown
|
There are 31 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
dd20fzx9mj46f.cloudfront.net
|
13.224.189.8
|
||
adobe.com.ssl.d1.sc.omtrdc.net
|
63.140.36.51
|
||
www.google.com
|
142.250.185.68
|
||
secure.na4.adobesign.com
|
52.35.253.84
|
||
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
|
52.50.19.120
|
||
secure.na4dc2.echosign.com
|
52.35.253.84
|
||
fp2e7a.wpc.phicdn.net
|
192.229.221.95
|
||
windowsupdatebg.s.llnwi.net
|
87.248.204.0
|
||
use.typekit.net
|
unknown
|
||
p.typekit.net
|
unknown
|
||
ims-na1.adobelogin.com
|
unknown
|
||
secure.na4.echocdn.com
|
unknown
|
||
dpm.demdex.net
|
unknown
|
||
static.adobelogin.com
|
unknown
|
||
static.echocdn.com
|
unknown
|
There are 5 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
13.224.189.15
|
unknown
|
United States
|
||
34.253.116.68
|
unknown
|
United States
|
||
192.168.2.5
|
unknown
|
unknown
|
||
63.140.62.222
|
unknown
|
United States
|
||
13.224.189.8
|
dd20fzx9mj46f.cloudfront.net
|
United States
|
||
142.250.185.68
|
www.google.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
63.140.36.51
|
adobe.com.ssl.d1.sc.omtrdc.net
|
United States
|
||
52.50.19.120
|
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
|
United States
|
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://na4.documents.adobe.com/public/userMessage?token=8F41FF26F12919E9531A301AF40203A748454A5676ECC7EEEA79CA2FD3AA03B
|
||
https://na4.documents.adobe.com/public/userMessage?token=8F41FF26F12919E9531A301AF40203A748454A5676ECC7EEEA79CA2FD3AA03B
|
||
https://auth.services.adobe.com/en_US/deeplink.html?deeplink=ssofirst&callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2FEchoSign2%2FAdobeID%2Fcode%3Fredirect_uri%3Dhttps%253A%252F%252Fgps.echosign.com%252Fpublic%252FadobeIDLogin%253Fserver%253Dna4.documents.adobe.com%2526isAdobeSignAuth%253Dfalse%2526port%253D443%26state%3D8660432c950d9e06b585396d4b2f1bad1cd7c9a50ae2ce0a50cf2260cfc55866%26code_challenge_method%3Dplain%26use_ms_for_expiry%3Dtrue&client_id=EchoSign2&scope=openid%2CAdobeID%2CDCAPI%2Cadditional_info.account_type%2Cskybox%2Cupdate_profile.first_name%2Cupdate_profile.last_name%2Cagreement_send%2Cagreement_sign%2Csign_library_write%2Csign_user_read%2Csign_user_write%2Cagreement_read%2Cagreement_write%2Cwidget_read%2Cwidget_write%2Cworkflow_read%2Cworkflow_write%2Csign_addressbook_read%2Csign_library_read%2Cadditional_info.projectedProductContext%2Csign_webhook_read%2Csign_webhook_write%2Csign_webhook_retention%2Csao.ACOM_ESIGN_TRIAL%2Cee.GROUP_SIGN_WEB%2Cadditional_info.ownerOrg%2Caddi
|