Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:53:30 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:53:30 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:53:30 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:53:30 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 12:53:30 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 100
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 104
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 105
|
TrueType Font data, digitally signed, 19 tables, 1st "DSIG", 26 names, Macintosh, Digitized data copyright \251 2010-2011,
Google Corporation.Open SansRegularAscender - Open Sans
|
downloaded
|
||
Chrome Cache Entry: 107
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 108
|
Unicode text, UTF-8 text, with very long lines (32000)
|
dropped
|
||
Chrome Cache Entry: 109
|
HTML document, ASCII text, with very long lines (487), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 111
|
PNG image data, 562 x 333, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 113
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 115
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 119
|
PNG image data, 800 x 100, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 120
|
HTML document, ASCII text, with very long lines (1528)
|
downloaded
|
||
Chrome Cache Entry: 122
|
ASCII text, with very long lines (2051)
|
downloaded
|
||
Chrome Cache Entry: 123
|
ASCII text, with very long lines (1572)
|
downloaded
|
||
Chrome Cache Entry: 124
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 125
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 126
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 127
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 128
|
Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
|
downloaded
|
||
Chrome Cache Entry: 129
|
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 130
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 131
|
ASCII text, with very long lines (3015), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 132
|
ASCII text, with very long lines (582), with CRLF, LF line terminators
|
downloaded
|
||
Chrome Cache Entry: 134
|
ASCII text, with very long lines (58316), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 135
|
PNG image data, 1000 x 630, 8-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 136
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 137
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 91
|
ASCII text, with very long lines (372), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 92
|
HTML document, ASCII text, with very long lines (478), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 93
|
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 94
|
ASCII text, with very long lines (371), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 95
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 96
|
Web Open Font Format (Version 2), TrueType, length 50296, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 98
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 99
|
Web Open Font Format (Version 2), TrueType, length 35020, version 1.0
|
downloaded
|
There are 31 hidden files, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://u14209785.ct.sendgrid.net/ls/click?upn=u001.7INBLi-2BpMtquNhvHXoCTQDs4I8fdKE9GOHSvdTryAC55LrdgOMctgJTF4aBFIDuUJB9xKyAVKEFqtPWDKRUFfRVL-2BZtxCjl35gXp1OzUaHmIog3KXNno0PoTN23H9BQ1hA1I4Go28GRqYv7PhkfrIKUdo6Jh-2FSBIhY5KlD9FeYRn1L-2B-2BMgQY6LlmMzMXTnvw7UnzwNdVP1PbwypC7fFdExRx58oUXa2-2B-2BalmqLe5W1v8o6qt5REv0B6VFQlHAFmxOrJwwlVAfqpYP-2F2sboiXoQAHvGwJjya8Z0ekRGMG7bMmVlZZUW01i9bQvV2Roks7TGNIp5b8POzZoY7Flnjs8-2BWCKAXUlzsDGMCYn1wZLGEFCYezv5KLt7H-2B6i7jNoux9HEaj0YN-2FsUjM9mCJTgphh38iFRym9tGMNFA-2BOSbTsr97EtmjyJboLtiw1evQHnbbIF-_zqBH9ExdcHz8y5jmZhTFlw0CoZyZAmMI16-2BYnIHsyEPJD-2BoDN2SPQabUJIOnni0R-2B9LuEMQe5DNe-2FjiLt8trXQ-2FOqf4ejJg2VmneQcoqFw-2FOZ9DUuUQCjAGgXC4-2FMsb4ms1HxxS9-2BbcfDfJEAFbMGI1IqwsTqbsLkZk3wna7WxZhO9yKcxiL35UkkPnIa2uIQdto9JuNDufvBk0TMo3qFWmeUNULbncHTxwF-2BPu3KFg6jaF7PfITImZUzMiJ-2BmIExlNmZxhZJkfZzdAqw-2F5Aqwi8V5PS51veG29uQ68vd-2BZeVK-2FPHULwOlPzxq83ylDa
|
|||
https://pp-wfe-100.advancedmd.com/131482/billing?token=T1RXYzdqa3RhcWpGM3htWU45Z0xWL0lyNmpUWXdvaU9nSTlZc09yZ3JoQUJNNzdnNFlBNFUwTTBZMFAyMjZjOTJCcXdDTlpxRUNHZkVDeTU4RlZoamExR28ycG5neHpsT3F3SktvS0dMU01tbjFEWGhmNE01WjdGd1Vta3dFS1FXUWZvVkplTzNIOUFmaHJ2bWVPRnNpVVphN2syWGhvSFJYYngvcWNweDZteGRBSWtyS3RocFhpK1JvODhlQ0s1
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
api2.heartlandportico.com
|
35.211.11.79
|
||
plus.l.google.com
|
172.217.16.206
|
||
api.heartlandportico.com
|
35.211.72.108
|
||
www.google.com
|
142.250.185.132
|
||
u14209785.ct.sendgrid.net
|
167.89.115.58
|
||
d1nn1qnqm7ih5y.cloudfront.net
|
18.244.18.58
|
||
d11ag707s7acdq.cloudfront.net
|
13.227.219.87
|
||
d1he4b11razhen.cloudfront.net
|
13.224.189.97
|
||
patientportal.advancedmd.com
|
unknown
|
||
amds-material-dev.advancedmd.com
|
unknown
|
||
apis.google.com
|
unknown
|
||
pp-wfe-100.advancedmd.com
|
unknown
|
There are 2 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
18.244.18.58
|
d1nn1qnqm7ih5y.cloudfront.net
|
United States
|
||
172.217.16.206
|
plus.l.google.com
|
United States
|
||
35.211.11.79
|
api2.heartlandportico.com
|
United States
|
||
167.89.115.58
|
u14209785.ct.sendgrid.net
|
United States
|
||
192.168.2.16
|
unknown
|
unknown
|
||
74.125.71.84
|
unknown
|
United States
|
||
172.217.18.3
|
unknown
|
United States
|
||
142.250.185.110
|
unknown
|
United States
|
||
142.250.185.132
|
www.google.com
|
United States
|
||
142.250.181.234
|
unknown
|
United States
|
||
13.224.189.97
|
d1he4b11razhen.cloudfront.net
|
United States
|
||
216.58.206.46
|
unknown
|
United States
|
||
18.65.39.83
|
unknown
|
United States
|
||
216.58.206.68
|
unknown
|
United States
|
||
13.227.219.87
|
d11ag707s7acdq.cloudfront.net
|
United States
|
||
18.244.18.3
|
unknown
|
United States
|
||
18.65.39.114
|
unknown
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
142.250.184.227
|
unknown
|
United States
|
||
35.211.72.108
|
api.heartlandportico.com
|
United States
|
||
142.250.186.74
|
unknown
|
United States
|
||
172.217.16.131
|
unknown
|
United States
|
There are 12 hidden IPs, click here to show them.