Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:52:36 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:52:36 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:52:36 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:52:36 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:52:36 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 100
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 101
|
Unicode text, UTF-8 text, with very long lines (32000)
|
dropped
|
||
Chrome Cache Entry: 102
|
PNG image data, 1000 x 630, 8-bit colormap, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 103
|
ASCII text, with very long lines (2051)
|
dropped
|
||
Chrome Cache Entry: 104
|
ASCII text, with very long lines (3015), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 105
|
ASCII text, with very long lines (2051)
|
downloaded
|
||
Chrome Cache Entry: 106
|
ASCII text, with very long lines (1572)
|
downloaded
|
||
Chrome Cache Entry: 107
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 108
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 109
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 110
|
Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
|
downloaded
|
||
Chrome Cache Entry: 111
|
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 112
|
ASCII text, with very long lines (3015), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 113
|
ASCII text, with very long lines (582), with CRLF, LF line terminators
|
downloaded
|
||
Chrome Cache Entry: 114
|
ASCII text, with very long lines (58316), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 115
|
HTML document, ASCII text, with very long lines (1528)
|
downloaded
|
||
Chrome Cache Entry: 116
|
PNG image data, 1000 x 630, 8-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 117
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 87
|
ASCII text, with very long lines (58316), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 88
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 89
|
HTML document, ASCII text, with very long lines (1528)
|
downloaded
|
||
Chrome Cache Entry: 90
|
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 91
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 92
|
Web Open Font Format (Version 2), TrueType, length 50296, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 93
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 94
|
Web Open Font Format (Version 2), TrueType, length 35020, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 95
|
HTML document, ASCII text, with very long lines (1528)
|
downloaded
|
||
Chrome Cache Entry: 96
|
Unicode text, UTF-8 text, with very long lines (32000)
|
downloaded
|
||
Chrome Cache Entry: 97
|
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
|
dropped
|
||
Chrome Cache Entry: 98
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 99
|
TrueType Font data, digitally signed, 19 tables, 1st "DSIG", 26 names, Macintosh, Digitized data copyright \251 2010-2011,
Google Corporation.Open SansRegularAscender - Open Sans
|
downloaded
|
There are 28 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2260 --field-trial-handle=2200,i,13693900937206702595,18110347641911938711,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u14209785.ct.sendgrid.net/ls/click?upn=u001.7INBLi-2BpMtquNhvHXoCTQDs4I8fdKE9GOHSvdTryAC5PZXQZ9gA03e708ehSXElRFWAMCquUixuu8d-2F9mFDBQnVJSO-2FQ5p3KOEaHsw-2BwF-2B66t1gSpBP18kaB03a-2BYCZmDa8BJh6BblQD2znuw0vrQSKmwtONN5audLdA5pMSCL13QSpBrcF68CsDJjpEkC91L8gJOrTpukzoSi35AtpHyGk9Q2gAOkG7qgQg0NnjmzwyLV6SGT2yNGawwXiIYNvNL7Le_7BRaYcrNPL3qMbHOvRrMD9SeD506Z8YVRsIl0RbT-2FjhzNxamZp-2FXEooTSn-2B-2BjBquLiZkJDz-2FEEAps21p4aWZU74tT3vReRlqDPK7zEWp182xmXHpOWbeN2GjhixYCgvD1uMgqqU5ggmL64eTUUPvjmGKq6r-2FVjTHU0J67ea3SNN-2F3zi5d929hZGLe0h6XFurYswkAJcH90hEY-2B4nW4yovbEITLgh6TCU1zUmdhCZj454uvcOROERwU3r589K9B1fIXMXim9A77CldiQKpq14jOFO-2Buykoyd9Rfn0OO-2FxXSyUu2P2oj-2FQxuarWZTRaRQ3"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://u14209785.ct.sendgrid.net/ls/click?upn=u001.7INBLi-2BpMtquNhvHXoCTQDs4I8fdKE9GOHSvdTryAC5PZXQZ9gA03e708ehSXElRFWAMCquUixuu8d-2F9mFDBQnVJSO-2FQ5p3KOEaHsw-2BwF-2B66t1gSpBP18kaB03a-2BYCZmDa8BJh6BblQD2znuw0vrQSKmwtONN5audLdA5pMSCL13QSpBrcF68CsDJjpEkC91L8gJOrTpukzoSi35AtpHyGk9Q2gAOkG7qgQg0NnjmzwyLV6SGT2yNGawwXiIYNvNL7Le_7BRaYcrNPL3qMbHOvRrMD9SeD506Z8YVRsIl0RbT-2FjhzNxamZp-2FXEooTSn-2B-2BjBquLiZkJDz-2FEEAps21p4aWZU74tT3vReRlqDPK7zEWp182xmXHpOWbeN2GjhixYCgvD1uMgqqU5ggmL64eTUUPvjmGKq6r-2FVjTHU0J67ea3SNN-2F3zi5d929hZGLe0h6XFurYswkAJcH90hEY-2B4nW4yovbEITLgh6TCU1zUmdhCZj454uvcOROERwU3r589K9B1fIXMXim9A77CldiQKpq14jOFO-2Buykoyd9Rfn0OO-2FxXSyUu2P2oj-2FQxuarWZTRaRQ3
|
|||
http://www.apache.org/licenses/LICENSE-2.0
|
unknown
|
||
https://classroom.google.com/sharewidget?usegapi=1
|
unknown
|
||
https://apis.google.com/js/api.js
|
142.250.185.174
|
||
https://pp-wfe-100.advancedmd.com/api/configuration/OfficeKeySettings?officeKey=141207
|
18.65.39.10
|
||
https://amds-material-dev.advancedmd.com/8/stable/8.0/amds-theme-default/material-theme.css
|
18.239.69.2
|
||
https://www.youtube.com/subscribe_embed?usegapi=1
|
unknown
|
||
https://api2.heartlandportico.com/SecureSubmit.v1/token/2.1/securesubmit.min.js
|
35.211.11.79
|
||
https://pp-wfe-100.advancedmd.com/assets/images/logo.svg
|
18.65.39.10
|
||
https://pp-wfe-100.advancedmd.com/fontawesome-webfont.e9955780856cf8aa.woff2?v=4.7.0
|
18.65.39.10
|
||
https://dataconnector.corp.google.com/:session_prefix:ui/widgetview?usegapi=1
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/141207/account/logon
|
|||
https://patientportal.advancedmd.com/appointment/reminders?token=U0hSTC9aSHZzQmFZdU1iM3VadENMOFRCUm05dTMwUk4raW5OMmgxQVg3WFI4WEpCSnJaMEZrdThjZEk4OFM1Ug%3D%3D&lk=141207
|
13.227.219.101
|
||
https://pp-wfe-100.advancedmd.com/appointment/reminders?token=U0hSTC9aSHZzQmFZdU1iM3VadENMOFRCUm05dTMwUk4raW5OMmgxQVg3WFI4WEpCSnJaMEZrdThjZEk4OFM1Ug%3D%3D&lk=141207
|
|||
https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
|
unknown
|
||
https://amds-material-dev.advancedmd.com/8/stable/8.0/amds-icons/amds-icons.css
|
18.239.69.2
|
||
https://amds-material-dev.advancedmd.com/8/stable/8.0/amds-icons/font/amds-icons.woff2
|
18.239.69.2
|
||
https://plus.google.com
|
unknown
|
||
https://clients3.google.com/cast/chromecast/home/widget/backdrop?usegapi=1
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/styles.bc20a01cb439f66e.css
|
18.65.39.10
|
||
https://www.google.com/shopping/customerreviews/badge?usegapi=1
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/api/configuration/SystemDefaults?officeKey=141207
|
18.65.39.10
|
||
http://www.ascendercorp.com/http://www.ascendercorp.com/typedesigners.htmlLicensed
|
unknown
|
||
https://u14209785.ct.sendgrid.net/ls/click?upn=u001.7INBLi-2BpMtquNhvHXoCTQDs4I8fdKE9GOHSvdTryAC5PZXQZ9gA03e708ehSXElRFWAMCquUixuu8d-2F9mFDBQnVJSO-2FQ5p3KOEaHsw-2BwF-2B66t1gSpBP18kaB03a-2BYCZmDa8BJh6BblQD2znuw0vrQSKmwtONN5audLdA5pMSCL13QSpBrcF68CsDJjpEkC91L8gJOrTpukzoSi35AtpHyGk9Q2gAOkG7qgQg0NnjmzwyLV6SGT2yNGawwXiIYNvNL7Le_7BRaYcrNPL3qMbHOvRrMD9SeD506Z8YVRsIl0RbT-2FjhzNxamZp-2FXEooTSn-2B-2BjBquLiZkJDz-2FEEAps21p4aWZU74tT3vReRlqDPK7zEWp182xmXHpOWbeN2GjhixYCgvD1uMgqqU5ggmL64eTUUPvjmGKq6r-2FVjTHU0J67ea3SNN-2F3zi5d929hZGLe0h6XFurYswkAJcH90hEY-2B4nW4yovbEITLgh6TCU1zUmdhCZj454uvcOROERwU3r589K9B1fIXMXim9A77CldiQKpq14jOFO-2Buykoyd9Rfn0OO-2FxXSyUu2P2oj-2FQxuarWZTRaRQ3
|
167.89.115.121
|
||
https://pp-wfe-100.advancedmd.com/api/apptreminder/ConfirmCancelAppointment?token=U0hSTC9aSHZzQmFZdU1iM3VadENMOFRCUm05dTMwUk4raW5OMmgxQVg3WFI4WEpCSnJaMEZrdThjZEk4OFM1Ug%3D%3D&officekey=141207
|
18.65.39.10
|
||
https://pay.google.com/gp/v/widget/save
|
unknown
|
||
https://drive.google.com/savetodrivebutton?usegapi=1
|
unknown
|
||
http://www.apache.org/licenses/LICENSE-2.0Digitized
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/141207/account/forgotpassword
|
|||
https://pp-wfe-100.advancedmd.com/api/configuration/Branding?officeKey=141207
|
18.65.39.10
|
||
https://talkgadget.google.com/:session_prefix:talkgadget/_/widget
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/api/configuration/settings?officeKey=141207
|
18.65.39.10
|
||
https://play.google.com/work/embedded/search?usegapi=1&usegapi=1
|
unknown
|
||
https://www.google.com/shopping/customerreviews/optin?usegapi=1
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/main.679ab1521d22507c.js
|
18.65.39.10
|
||
https://pp-wfe-100.advancedmd.com/runtime.828784c1b995f56f.js
|
18.65.39.10
|
||
https://pp-wfe-100.advancedmd.com/api/configuration/Configuration?officeKey=141207
|
18.65.39.10
|
||
https://apis.google.com
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/api/configuration/PatientLocation?officekey=141207
|
18.65.39.10
|
||
https://pp-wfe-100.advancedmd.com/api/configuration/featureAccess?officeKey=141207
|
18.65.39.10
|
||
https://families.google.com/webcreation?usegapi=1&usegapi=1
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/polyfills.55f1c22607bcff8d.js
|
18.65.39.10
|
||
https://pp-wfe-100.advancedmd.com/fullscreen_background.1150f059492003b5.png
|
18.65.39.10
|
||
https://clients6.google.com
|
unknown
|
||
https://pp-wfe-100.advancedmd.com/OpenSans.4543090a37b427da.ttf
|
18.65.39.10
|
||
https://pp-wfe-100.advancedmd.com/favicon.ico?v=2
|
18.65.39.10
|
There are 35 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
api2.heartlandportico.com
|
35.211.11.79
|
||
plus.l.google.com
|
142.250.185.174
|
||
www.google.com
|
142.250.185.68
|
||
u14209785.ct.sendgrid.net
|
167.89.115.121
|
||
d1nn1qnqm7ih5y.cloudfront.net
|
18.65.39.10
|
||
d11ag707s7acdq.cloudfront.net
|
13.227.219.101
|
||
d1he4b11razhen.cloudfront.net
|
18.239.69.2
|
||
fp2e7a.wpc.phicdn.net
|
192.229.221.95
|
||
patientportal.advancedmd.com
|
unknown
|
||
amds-material-dev.advancedmd.com
|
unknown
|
||
apis.google.com
|
unknown
|
||
pp-wfe-100.advancedmd.com
|
unknown
|
There are 3 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
142.250.185.68
|
www.google.com
|
United States
|
||
18.244.18.58
|
unknown
|
United States
|
||
18.239.69.2
|
d1he4b11razhen.cloudfront.net
|
United States
|
||
35.211.11.79
|
api2.heartlandportico.com
|
United States
|
||
167.89.115.121
|
u14209785.ct.sendgrid.net
|
United States
|
||
18.65.39.10
|
d1nn1qnqm7ih5y.cloudfront.net
|
United States
|
||
192.168.2.5
|
unknown
|
unknown
|
||
13.227.219.101
|
d11ag707s7acdq.cloudfront.net
|
United States
|
||
216.58.206.46
|
unknown
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
142.250.185.174
|
plus.l.google.com
|
United States
|
There are 1 hidden IPs, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://pp-wfe-100.advancedmd.com/appointment/reminders?token=U0hSTC9aSHZzQmFZdU1iM3VadENMOFRCUm05dTMwUk4raW5OMmgxQVg3WFI4WEpCSnJaMEZrdThjZEk4OFM1Ug%3D%3D&lk=141207
|
||
https://pp-wfe-100.advancedmd.com/appointment/reminders?token=U0hSTC9aSHZzQmFZdU1iM3VadENMOFRCUm05dTMwUk4raW5OMmgxQVg3WFI4WEpCSnJaMEZrdThjZEk4OFM1Ug%3D%3D&lk=141207
|
||
https://pp-wfe-100.advancedmd.com/appointment/reminders?token=U0hSTC9aSHZzQmFZdU1iM3VadENMOFRCUm05dTMwUk4raW5OMmgxQVg3WFI4WEpCSnJaMEZrdThjZEk4OFM1Ug%3D%3D&lk=141207
|
||
https://pp-wfe-100.advancedmd.com/141207/account/logon
|
||
https://pp-wfe-100.advancedmd.com/141207/account/logon
|
||
https://pp-wfe-100.advancedmd.com/141207/account/forgotpassword
|
||
https://pp-wfe-100.advancedmd.com/141207/account/forgotpassword
|