Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
WI_EMT.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
initial sample
|
||
Chrome Cache Entry: 170
|
ASCII text, with very long lines (20426), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 171
|
ASCII text, with very long lines (23865), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 172
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 173
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 174
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 175
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 176
|
ASCII text, with very long lines (7215), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 177
|
ASCII text, with very long lines (27881), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 178
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 179
|
ASCII text, with very long lines (4401), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 180
|
ASCII text, with very long lines (13063), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 181
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 182
|
ASCII text, with very long lines (499), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 183
|
ASCII text, with very long lines (48986), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 184
|
HTML document, ASCII text, with very long lines (1551), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 185
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 186
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 187
|
ASCII text, with very long lines (21215)
|
downloaded
|
||
Chrome Cache Entry: 188
|
ASCII text, with very long lines (553)
|
dropped
|
||
Chrome Cache Entry: 189
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 190
|
ASCII text, with very long lines (32034)
|
dropped
|
||
Chrome Cache Entry: 191
|
ASCII text, with very long lines (571)
|
downloaded
|
||
Chrome Cache Entry: 192
|
ASCII text, with very long lines (2047)
|
dropped
|
||
Chrome Cache Entry: 193
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 194
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 195
|
ASCII text, with very long lines (8798), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 196
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 197
|
ASCII text, with very long lines (36995), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 198
|
ASCII text, with very long lines (8065)
|
dropped
|
||
Chrome Cache Entry: 199
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 200
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 201
|
C source, ASCII text, with very long lines (754)
|
downloaded
|
||
Chrome Cache Entry: 202
|
ASCII text, with very long lines (17003), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 203
|
ASCII text, with very long lines (571)
|
dropped
|
||
Chrome Cache Entry: 204
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 205
|
HTML document, Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 206
|
Web Open Font Format (Version 2), TrueType, length 2412, version 331.-31196
|
downloaded
|
||
Chrome Cache Entry: 207
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 208
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 209
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 210
|
ASCII text, with very long lines (347)
|
downloaded
|
||
Chrome Cache Entry: 211
|
ASCII text, with no line terminators
|
dropped
|
||
Chrome Cache Entry: 212
|
C source, ASCII text, with very long lines (754)
|
dropped
|
||
Chrome Cache Entry: 213
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 214
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 215
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 216
|
ASCII text, with very long lines (65397)
|
downloaded
|
||
Chrome Cache Entry: 217
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 218
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 219
|
ASCII text, with very long lines (760)
|
downloaded
|
||
Chrome Cache Entry: 220
|
ASCII text, with very long lines (3114), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 221
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 222
|
ASCII text, with very long lines (30837)
|
downloaded
|
||
Chrome Cache Entry: 223
|
ASCII text, with very long lines (32038)
|
dropped
|
||
Chrome Cache Entry: 224
|
ASCII text, with very long lines (32762)
|
downloaded
|
||
Chrome Cache Entry: 225
|
ASCII text, with no line terminators
|
dropped
|
||
Chrome Cache Entry: 226
|
ASCII text, with very long lines (63529), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 227
|
ASCII text, with very long lines (1686)
|
dropped
|
||
Chrome Cache Entry: 228
|
ASCII text, with very long lines (60452)
|
downloaded
|
||
Chrome Cache Entry: 229
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 230
|
ASCII text, with very long lines (31410), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 231
|
ASCII text, with very long lines (12736)
|
dropped
|
||
Chrome Cache Entry: 232
|
Web Open Font Format (Version 2), TrueType, length 3236, version 331.-31196
|
downloaded
|
||
Chrome Cache Entry: 233
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 234
|
ASCII text, with very long lines (17065), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 235
|
ASCII text, with very long lines (25600), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 236
|
ASCII text, with very long lines (64779)
|
dropped
|
||
Chrome Cache Entry: 237
|
C source, ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 238
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 239
|
ASCII text, with very long lines (20426), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 240
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 241
|
ASCII text, with very long lines (538)
|
downloaded
|
||
Chrome Cache Entry: 242
|
ASCII text, with very long lines (7085)
|
downloaded
|
||
Chrome Cache Entry: 243
|
ASCII text, with very long lines (8065)
|
downloaded
|
||
Chrome Cache Entry: 244
|
ASCII text, with very long lines (63529), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 245
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 246
|
ASCII text, with very long lines (553)
|
downloaded
|
||
Chrome Cache Entry: 247
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 248
|
ASCII text, with very long lines (1686)
|
downloaded
|
||
Chrome Cache Entry: 249
|
ASCII text, with very long lines (26366)
|
dropped
|
||
Chrome Cache Entry: 250
|
Web Open Font Format (Version 2), TrueType, length 36209, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 251
|
PNG image data, 256 x 240, 8-bit colormap, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 252
|
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
|
dropped
|
||
Chrome Cache Entry: 253
|
ASCII text, with very long lines (7611)
|
downloaded
|
||
Chrome Cache Entry: 254
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 255
|
ASCII text, with very long lines (857)
|
downloaded
|
||
Chrome Cache Entry: 256
|
ASCII text, with very long lines (4456)
|
dropped
|
||
Chrome Cache Entry: 257
|
ASCII text, with very long lines (36995), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 258
|
Web Open Font Format (Version 2), TrueType, length 916, version 331.-31196
|
downloaded
|
||
Chrome Cache Entry: 259
|
ASCII text, with very long lines (23897), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 260
|
ASCII text, with very long lines (52883), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 261
|
ASCII text, with very long lines (2009)
|
dropped
|
||
Chrome Cache Entry: 262
|
ASCII text, with very long lines (32762)
|
dropped
|
||
Chrome Cache Entry: 263
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 264
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 265
|
ASCII text, with very long lines (64779)
|
downloaded
|
||
Chrome Cache Entry: 266
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 267
|
ASCII text, with very long lines (48986), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 268
|
ASCII text, with very long lines (28376)
|
downloaded
|
||
Chrome Cache Entry: 269
|
HTML document, ASCII text, with very long lines (1551), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 270
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 271
|
ASCII text, with very long lines (47358), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 272
|
ASCII text, with very long lines (45175), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 273
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 274
|
ASCII text, with very long lines (760)
|
dropped
|
||
Chrome Cache Entry: 275
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 276
|
ASCII text, with very long lines (65464)
|
downloaded
|
||
Chrome Cache Entry: 277
|
ASCII text, with very long lines (17065), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 278
|
ASCII text, with very long lines (47358), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 279
|
ASCII text, with very long lines (21016), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 280
|
RIFF (little-endian) data, Web/P image, VP8 encoding, 255x95, Scaling: [none]x[none], YUV color, decoders should clamp
|
dropped
|
||
Chrome Cache Entry: 281
|
ASCII text, with very long lines (16436), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 282
|
ASCII text, with very long lines (52883), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 283
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 284
|
ASCII text, with very long lines (608)
|
downloaded
|
||
Chrome Cache Entry: 285
|
TrueType Font data, 15 tables, 1st "GSUB", 15 names, Microsoft, language 0x409, Copyright 2016 Google Inc. All Rights Reserved.Space
MonoRegular1.000;CF ;SpaceMono-RegularVers
|
downloaded
|
||
Chrome Cache Entry: 286
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 287
|
ASCII text, with very long lines (32743)
|
dropped
|
||
Chrome Cache Entry: 288
|
Web Open Font Format (Version 2), TrueType, length 63540, version 2.0
|
downloaded
|
||
Chrome Cache Entry: 289
|
Unicode text, UTF-8 (with BOM) text, with very long lines (65529), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 290
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 291
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 292
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 293
|
ASCII text, with no line terminators
|
dropped
|
||
Chrome Cache Entry: 294
|
Web Open Font Format (Version 2), TrueType, length 62720, version 2.0
|
downloaded
|
||
Chrome Cache Entry: 295
|
ASCII text, with very long lines (26366)
|
downloaded
|
||
Chrome Cache Entry: 296
|
ASCII text, with very long lines (28875)
|
dropped
|
||
Chrome Cache Entry: 297
|
ASCII text, with very long lines (535)
|
downloaded
|
||
Chrome Cache Entry: 298
|
ASCII text, with very long lines (984)
|
dropped
|
||
Chrome Cache Entry: 299
|
ASCII text, with very long lines (2003)
|
dropped
|
||
Chrome Cache Entry: 300
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 301
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 302
|
ASCII text, with very long lines (65371)
|
downloaded
|
||
Chrome Cache Entry: 303
|
ASCII text, with very long lines (2009)
|
downloaded
|
||
Chrome Cache Entry: 304
|
HTML document, Unicode text, UTF-8 text, with very long lines (834), with CRLF, LF line terminators
|
downloaded
|
||
Chrome Cache Entry: 305
|
ASCII text, with very long lines (21215)
|
dropped
|
||
Chrome Cache Entry: 306
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 307
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 308
|
PNG image data, 256 x 240, 8-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 309
|
ASCII text, with very long lines (2550), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 310
|
ASCII text, with very long lines (35552), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 311
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 312
|
ASCII text, with very long lines (2003)
|
downloaded
|
||
Chrome Cache Entry: 313
|
ASCII text, with very long lines (41615), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 314
|
ASCII text, with very long lines (23865), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 315
|
ASCII text, with very long lines (32743)
|
downloaded
|
||
Chrome Cache Entry: 316
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 317
|
ASCII text, with very long lines (535)
|
dropped
|
||
Chrome Cache Entry: 318
|
ASCII text, with very long lines (65451)
|
downloaded
|
||
Chrome Cache Entry: 319
|
ASCII text, with very long lines (15746), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 320
|
ASCII text, with very long lines (8586), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 321
|
ASCII text, with very long lines (538)
|
dropped
|
||
Chrome Cache Entry: 322
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 323
|
ASCII text, with very long lines (32034)
|
downloaded
|
||
Chrome Cache Entry: 324
|
ASCII text, with very long lines (4456)
|
downloaded
|
||
Chrome Cache Entry: 325
|
ASCII text, with very long lines (33094), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 326
|
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 327
|
ASCII text, with very long lines (2047)
|
downloaded
|
||
Chrome Cache Entry: 328
|
ASCII text, with very long lines (365), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 329
|
ASCII text, with very long lines (2550), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 330
|
ASCII text, with very long lines (499), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 331
|
ASCII text, with very long lines (8065)
|
dropped
|
||
Chrome Cache Entry: 332
|
ASCII text, with very long lines (3114), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 333
|
ASCII text, with very long lines (610)
|
dropped
|
||
Chrome Cache Entry: 334
|
ASCII text, with very long lines (570)
|
dropped
|
||
Chrome Cache Entry: 335
|
ASCII text, with very long lines (32035)
|
downloaded
|
||
Chrome Cache Entry: 336
|
ASCII text, with very long lines (7215), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 337
|
ASCII text, with very long lines (32038)
|
downloaded
|
||
Chrome Cache Entry: 338
|
ASCII text, with very long lines (17003), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 339
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 340
|
ASCII text, with very long lines (64779)
|
dropped
|
||
Chrome Cache Entry: 341
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 342
|
ASCII text, with very long lines (12736)
|
downloaded
|
||
Chrome Cache Entry: 343
|
ASCII text, with very long lines (857)
|
dropped
|
||
Chrome Cache Entry: 344
|
ASCII text, with very long lines (11808), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 345
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 346
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 347
|
ASCII text, with very long lines (610)
|
downloaded
|
||
Chrome Cache Entry: 348
|
ASCII text, with very long lines (6145), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 349
|
ASCII text, with very long lines (32035)
|
dropped
|
||
Chrome Cache Entry: 350
|
ASCII text, with very long lines (33094), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 351
|
ASCII text, with very long lines (984)
|
downloaded
|
||
Chrome Cache Entry: 352
|
ASCII text, with very long lines (8065)
|
downloaded
|
||
Chrome Cache Entry: 353
|
ASCII text, with very long lines (570)
|
downloaded
|
||
Chrome Cache Entry: 354
|
ASCII text, with very long lines (7085)
|
dropped
|
||
Chrome Cache Entry: 355
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 356
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 357
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 358
|
ASCII text, with very long lines (65464)
|
dropped
|
||
Chrome Cache Entry: 359
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 360
|
ASCII text, with very long lines (13063), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 361
|
C source, ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 362
|
ASCII text, with very long lines (2594), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 363
|
ASCII text, with very long lines (11808), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 364
|
ASCII text, with no line terminators
|
dropped
|
||
Chrome Cache Entry: 365
|
ASCII text, with very long lines (15746), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 366
|
ASCII text, with very long lines (1835)
|
downloaded
|
||
Chrome Cache Entry: 367
|
Web Open Font Format (Version 2), TrueType, length 35422, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 368
|
ASCII text, with very long lines (2594), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 369
|
ASCII text, with very long lines (7555), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 370
|
ASCII text, with very long lines (8798), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 371
|
ASCII text, with very long lines (608)
|
dropped
|
||
Chrome Cache Entry: 372
|
ASCII text, with very long lines (2783), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 373
|
Web Open Font Format (Version 2), TrueType, length 37796, version 331.-31196
|
downloaded
|
||
Chrome Cache Entry: 374
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 375
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 376
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 377
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 378
|
ASCII text, with very long lines (3980), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 379
|
RIFF (little-endian) data, Web/P image, VP8 encoding, 255x95, Scaling: [none]x[none], YUV color, decoders should clamp
|
downloaded
|
||
Chrome Cache Entry: 380
|
ASCII text, with very long lines (27881), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 381
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 382
|
ASCII text, with very long lines (3980), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 383
|
ASCII text, with very long lines (64779)
|
downloaded
|
||
Chrome Cache Entry: 384
|
ASCII text, with very long lines (65451)
|
dropped
|
||
Chrome Cache Entry: 385
|
ASCII text, with very long lines (28875)
|
downloaded
|
||
Chrome Cache Entry: 386
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 387
|
HTML document, Unicode text, UTF-8 text, with very long lines (65156), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 388
|
ASCII text, with very long lines (41615), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 389
|
ASCII text, with very long lines (23897), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 390
|
HTML document, Unicode text, UTF-8 text, with very long lines (65156), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 391
|
ASCII text, with very long lines (6145), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 392
|
ASCII text, with very long lines (25600), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 393
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 394
|
Web Open Font Format (Version 2), TrueType, length 18028, version 1.589
|
downloaded
|
||
Chrome Cache Entry: 395
|
ASCII text, with very long lines (35552), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 396
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 397
|
ASCII text, with very long lines (7611)
|
dropped
|
There are 219 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\WI_EMT.exe
|
"C:\Users\user\Desktop\WI_EMT.exe"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://www.ni.com/rteFinder?dest=lvrte&version=21.0&platform=Win7_32&lang=en
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=1892,i,10304342425602357759,2820890992521272206,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US
--service-sandbox-type=audio --mojo-platform-channel-handle=4064 --field-trial-handle=1892,i,10304342425602357759,2820890992521272206,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://js.driftt.com/core/assets/css/28.812d5a7c.chunk.css
|
18.245.86.77
|
||
https://www.ni.com/favicon-16x16.png
|
unknown
|
||
https://www.ni.com/70533feeace8/ceda31ca7e5d/launch-fa701911ef13-development.min.js
|
unknown
|
||
http://www.ni.com/70533feeace8/484b70bb80b7/052f9be7bd2e/RC7fc977963c7349388e50b250e954cdf2-source.j
|
unknown
|
||
https://fontawesome.com
|
unknown
|
||
https://metrics.api.drift.com
|
unknown
|
||
https://www.ni.com/zh-cn/support/downloads/software-products/download.labview-runtime.html
|
unknown
|
||
https://js.driftt.com/core/assets/js/22.6b9a301a.chunk.js
|
18.245.86.77
|
||
https://lumen.ni.com/nicif/us/header_login/content.xhtml?action=login&du=https://www.ni.com/en/suppo
|
unknown
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html
|
unknown
|
||
https://smetrics.ni.com/b/ss/ni-prd/1/JS-2.22.0-LEWM/s67406695564657
|
63.140.62.27
|
||
https://www.ni.com/docs/
|
unknown
|
||
http://getbootstrap.com)
|
unknown
|
||
https://www.ni.com/en/partners.html
|
unknown
|
||
https://bs.serving-sys.com/BurstingPipe/ActivityServer.bs?cn=as&vn=omn&activityID=787854&advID=125764&var=s_3_Integrate_Sizmek_ACM_get_0&rnd=7476232606137
|
35.156.207.107
|
||
https://www.ni.com/en/search.html?pg=1&ps=10&sn=catnav:sup.dwl.pdl
|
unknown
|
||
https://js.driftt.com/core/assets/css/27.b5e8f5e1.chunk.css
|
18.245.86.77
|
||
https://www.ni.com/70533feeace8/484b70bb80b7/launch-a69e4f3a49c6-development.js
|
unknown
|
||
https://js.driftt.com/core/assets/css/39.eeb001f3.chunk.css
|
18.245.86.77
|
||
https://www.ni.com/en/shop/compactrio.html
|
unknown
|
||
https://www.ni.com/site.webmanifest
|
unknown
|
||
https://www.ni.com/es/support/downloads/software-products/download.labview-runtime.html
|
unknown
|
||
https://js.driftt.com/core/assets/js/1.50f0b6c5.chunk.js
|
18.245.86.77
|
||
https://bootstrap.driftapi.com/widget_bootstrap
|
18.172.112.40
|
||
https://www.ni.com/70533feeace8/ceda31ca7e5d/launch-fa701911ef13-development.js
|
unknown
|
||
https://js.driftt.com/core/assets/js/25.e0454b9f.chunk.js
|
18.245.86.77
|
||
https://www.ni.com/apple-touch-icon.png
|
unknown
|
||
https://1421715-15.chat.api.drift.com/ws/websocket?session_token=SFMyNTY.g2gDdAAAAAVkAAJpZG0AAAAVMTQyMTcxNS0yMzEzMDAyNjI2OC00ZAAGb3JnX2lkbQAAAAcxNDIxNzE1ZAAJc2NvcGVfc2V0bQAAAARsZWFkZAAHdXNlcl9pZG0AAAALMjMxMzAwMjYyNjhkAAl1c2VyX3R5cGVkAARsZWFkbgYAKHOeMpIBYgABUYA._EqYlDXnaHGrMRrGc7HiDvPt7E4n9LEJgko0nn9S5lo&remote_ip=52.205.21.197&vsn=2.0.0
|
54.88.130.168
|
||
https://www.ni.com/70533feeace8/484b70bb80b7/launch-a6259a07e4ab-development.min.js
|
unknown
|
||
https://siteintercept.qualtrics.com
|
unknown
|
||
http://www.ni.com/70533feeace8/484b70bb80b7/launch-92d1a8272fcb.js
|
unknown
|
||
http://www.ni.com/rteFinder?dest=lvrte&version=21.0&platform=Win7_32&lang=en
|
unknown
|
||
https://schema.org
|
unknown
|
||
http://www.ni.com/rteFinder?dest=lvrte&version=21.0&platform=Win7_32&lang=en&
|
unknown
|
||
https://ni.scene7.com/is/image/ni/emerson_footer_white?fmt=png-alpha
|
unknown
|
||
http://www.ni.com/rteFinder?dest=lvrte&version=21.0&platform=Win7_32&lang=en(
|
unknown
|
||
https://ni.scene7.com/is/image/ni/LabVIEW?$ni-icon-pm$
|
unknown
|
||
http://sine.ni.com/apps/utf8/nios.store?action=view_cart
|
unknown
|
||
https://github.com/gnarf37/jquery-requestAnimationFrame
|
unknown
|
||
https://www.ni.com/cookies
|
unknown
|
||
https://www.ni.com/ja/support/downloads/software-products/download.labview-runtime.html
|
unknown
|
||
https://www.ni.com/en/shop.html#pinned-nav-section1
|
unknown
|
||
https://customer.api.drift.com
|
unknown
|
||
https://js.driftt.com/core/assets/css/1.fdc718c4.chunk.css
|
18.245.86.77
|
||
https://www.ni.com/en/shop/pxi.html
|
unknown
|
||
https://github.com/twbs/bootstrap/blob/master/LICENSE)
|
unknown
|
||
http://www.ni.com/70533feeace8/484b70bb80b7/052f9be7bd2e/RC9d1bf0d6c16e40e6bf8a02207d77804e-source.j
|
unknown
|
||
https://www.ni.com/ko/support/downloads/software-products/download.labview-runtime.html
|
unknown
|
||
https://www.ni.com/en/about-ni/legal/service-terms.html
|
unknown
|
||
https://www.ni.com/en/shop/data-acquisition/miodaq-devices.html
|
unknown
|
||
https://www.ni.com/my-support/s/service-requests
|
unknown
|
||
http://www.ni.com/70533feeace8/484b70bb80b7/052f9be7bd2e/EXf111162c5acd422892eda1f607ac206b-libraryC
|
unknown
|
||
https://www.ni.com/en/about-ni/legal/terms-of-use.html
|
unknown
|
||
https://log.api.drift.com/log
|
34.193.113.164
|
||
https://cdn.cookielaw.org
|
unknown
|
||
http://jqueryui.com/themeroller/?ffDefault=Trebuchet%20MS%2CTahoma%2CVerdana%2CArial%2Csans-serif&fw
|
unknown
|
||
https://www.ni.com/en/shop/labview/select-edition.html
|
unknown
|
||
http://www.ni.com/rteFinder?dest=lvrte&version=&platform=Win7_&lang=shell32.dllole32.dllCoInitialize
|
unknown
|
||
https://zn3dtdyc8qsewhj6t-nidx.siteintercept.qualtrics.com/WRSiteInterceptEngine/?Q_ZID=ZN_3DTdyc8qs
|
unknown
|
||
https://www.ni.com/70533feeace8/484b70bb80b7/launch-92d1a8272fcb.min.js
|
unknown
|
||
https://www.ni.com/en.html
|
unknown
|
||
https://conversation.api.drift.com
|
unknown
|
||
https://cdn.cookielaw.org/vendorlist/googleData.json
|
unknown
|
||
https://ni500z.btttag.com/btt.js
|
172.67.37.210
|
||
https://ni.scene7.com/is/image/ni/play_button?fmt=png-alpha)
|
unknown
|
||
https://fontawesome.com/license
|
unknown
|
||
https://www.ni.com/70533feeace8/484b70bb80b7/launch-4c2e40cfd60e-development.min.js
|
unknown
|
||
https://cdn.cookielaw.org/vendorlist/iab2Data.json
|
unknown
|
||
https://js.driftt.com/core/assets/css/8.6ac3976b.chunk.css
|
18.245.86.77
|
||
http://www.ni.com/rteFinder?dest=lvrte
|
unknown
|
||
https://kit-uploads.fontawesome.com
|
unknown
|
||
https://www.ni.com/en/support/downloads/software-products/download.academic-volume-license.html
|
unknown
|
||
https://js.driftt.com/core/assets/js/runtime~main.901f3121.js
|
18.245.86.77
|
||
https://www.ni.com/niassets/js/survey.js
|
unknown
|
||
https://metrics.api.drift.com/monitoring/metrics/event3/bulk
|
54.147.21.139
|
||
https://www.ni.com/privacy
|
unknown
|
||
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLUppercase
|
unknown
|
||
https://www.ni.com/70533feeace8/484b70bb80b7/launch-4c2e40cfd60e-development.js
|
unknown
|
||
http://www.ni.com/70533feeace8/484b70bb80b7/052f9be7bd2e/RC5c86d9d81d6941a7ac9f3b637ea15f4a-source.j
|
unknown
|
||
https://ni.scene7.com/is/image/ni/Icon
|
unknown
|
||
https://getbootstrap.com/)
|
unknown
|
||
https://js.driftt.com/core/assets/js/16.e4031a09.chunk.js
|
18.245.86.77
|
||
https://dpm.demdex.net/id/rd?d_visid_ver=5.5.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=B3902DB45388D9620A490D4C%40AdobeOrg&d_nsid=0&ts=1727426078668
|
52.49.164.251
|
||
http://fontawesome.io/license
|
unknown
|
||
https://kit.fontawesome.com
|
unknown
|
||
https://js.driftt.com/core/assets/js/17.defc9e4a.chunk.js
|
18.245.86.77
|
||
https://www.ni.com/70533feeace8/484b70bb80b7/launch-7b1333090b24-development.js
|
unknown
|
||
https://www.ni.com/70533feeace8/484b70bb80b7/launch-66e1cff30f54-development.min.js
|
unknown
|
||
https://s.qualtrics.com/spoke/all/jam
|
unknown
|
||
https://www.ni.com/fr/support/downloads/software-products/download.labview-runtime.html
|
unknown
|
||
https://kit.fontawesome.com/5806b6a478.js
|
unknown
|
||
https://js.driftt.com/core/assets/js/9.4a3e9801.chunk.js
|
18.245.86.77
|
||
https://js.driftt.com/core/assets/js/42.f634da7c.chunk.js
|
18.245.86.77
|
||
https://smetrics.ni.com/id?d_visid_ver=5.5.0&d_fieldgroup=A&mcorgid=B3902DB45388D9620A490D4C%40AdobeOrg&mid=39291510826587166440356522923596182223&ts=1727426080843
|
63.140.62.27
|
||
https://js.driftt.com/include/1727426100000/fm4fbdf7nvk9.js
|
18.245.86.14
|
||
https://ni.scene7.com/is/image/ni/Multisim_BG?$ni-icon-pm$
|
unknown
|
||
https://dpm.demdex.net/id?d_visid_ver=5.5.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=B3902DB45388D9620A490D4C%40AdobeOrg&d_nsid=0&ts=1727426078668
|
52.49.164.251
|
||
http://jquery.com/
|
unknown
|
||
https://cdn.cookielaw.org/vendorlist/iab2V2Data.json
|
unknown
|
||
https://js.driftt.com/core/assets/js/3.2a4c7561.chunk.js
|
18.245.86.77
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
ni.com.ssl.d2.sc.omtrdc.net
|
63.140.62.27
|
||
afe79c04fd8464db69f453355c110684-6aa967fe209738b1.elb.us-east-1.amazonaws.com
|
3.94.218.138
|
||
ee15ba61-wschat-wschatalb-6fcf-2062696737.us-east-1.elb.amazonaws.com
|
54.88.130.168
|
||
ni500z.btttag.com
|
172.67.37.210
|
||
dl7g9llrghqi1.cloudfront.net
|
18.245.86.14
|
||
adobetarget.data.adobedc.net
|
66.235.152.156
|
||
d1nie5ipy0d64w.cloudfront.net
|
18.172.112.40
|
||
adserver-prod-alb-2056226458.eu-central-1.elb.amazonaws.com
|
35.156.207.107
|
||
www.google.com
|
142.250.186.36
|
||
location.l.force.com
|
160.8.191.31
|
||
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
|
52.49.164.251
|
||
fls.doubleclick.net
|
142.250.186.70
|
||
geolocation.onetrust.com
|
172.64.155.119
|
||
metrics.api.drift.com
|
unknown
|
||
target.ni.com
|
unknown
|
||
nationalinsturments.demdex.net
|
unknown
|
||
siteintercept.qualtrics.com
|
unknown
|
||
cm.everesttech.net
|
unknown
|
||
js.driftt.com
|
unknown
|
||
customer.api.drift.com
|
unknown
|
||
www.ni.com
|
unknown
|
||
bootstrap.driftapi.com
|
unknown
|
||
dpm.demdex.net
|
unknown
|
||
1421715-15.chat.api.drift.com
|
unknown
|
||
conversation.api.drift.com
|
unknown
|
||
ni.scene7.com
|
unknown
|
||
log.api.drift.com
|
unknown
|
||
zn8l9hquzk9i3pdgd-nidx.siteintercept.qualtrics.com
|
unknown
|
||
delta.ni.com
|
unknown
|
||
kit.fontawesome.com
|
unknown
|
||
targeting.api.drift.com
|
unknown
|
||
service.force.com
|
unknown
|
||
ni.tt.omtrdc.net
|
unknown
|
||
api.ni.com
|
unknown
|
||
bs.serving-sys.com
|
unknown
|
||
zn3dtdyc8qsewhj6t-nidx.siteintercept.qualtrics.com
|
unknown
|
||
smetrics.ni.com
|
unknown
|
||
ka-p.fontawesome.com
|
unknown
|
There are 28 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
192.168.2.4
|
unknown
|
unknown
|
||
54.147.21.139
|
unknown
|
United States
|
||
192.168.2.6
|
unknown
|
unknown
|
||
192.168.2.5
|
unknown
|
unknown
|
||
66.235.152.225
|
unknown
|
United States
|
||
104.18.32.137
|
unknown
|
United States
|
||
66.235.152.221
|
unknown
|
United States
|
||
142.250.186.70
|
fls.doubleclick.net
|
United States
|
||
172.67.37.210
|
ni500z.btttag.com
|
United States
|
||
142.250.186.36
|
www.google.com
|
United States
|
||
52.49.164.251
|
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
|
United States
|
||
63.140.62.17
|
unknown
|
United States
|
||
54.165.29.223
|
unknown
|
United States
|
||
52.16.68.25
|
unknown
|
United States
|
||
172.64.155.119
|
geolocation.onetrust.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
18.185.41.142
|
unknown
|
United States
|
||
66.235.152.156
|
adobetarget.data.adobedc.net
|
United States
|
||
160.8.236.22
|
unknown
|
Sweden
|
||
142.250.186.102
|
unknown
|
United States
|
||
18.245.86.14
|
dl7g9llrghqi1.cloudfront.net
|
United States
|
||
35.156.207.107
|
adserver-prod-alb-2056226458.eu-central-1.elb.amazonaws.com
|
United States
|
||
54.88.130.168
|
ee15ba61-wschat-wschatalb-6fcf-2062696737.us-east-1.elb.amazonaws.com
|
United States
|
||
63.140.62.27
|
ni.com.ssl.d2.sc.omtrdc.net
|
United States
|
||
18.245.86.77
|
unknown
|
United States
|
||
18.245.86.73
|
unknown
|
United States
|
||
34.193.113.164
|
unknown
|
United States
|
||
18.172.112.40
|
d1nie5ipy0d64w.cloudfront.net
|
United States
|
||
52.214.161.17
|
unknown
|
United States
|
||
160.8.191.31
|
location.l.force.com
|
Sweden
|
||
3.94.218.138
|
afe79c04fd8464db69f453355c110684-6aa967fe209738b1.elb.us-east-1.amazonaws.com
|
United States
|
||
104.22.58.128
|
unknown
|
United States
|
There are 22 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
32D000
|
unkown
|
page readonly
|
||
744E000
|
stack
|
page read and write
|
||
173C000
|
unkown
|
page readonly
|
||
6B10000
|
trusted library allocation
|
page read and write
|
||
1C39000
|
stack
|
page read and write
|
||
1DC5000
|
heap
|
page read and write
|
||
1DC6000
|
heap
|
page read and write
|
||
D3C000
|
unkown
|
page readonly
|
||
32D000
|
unkown
|
page readonly
|
||
1D3A000
|
stack
|
page read and write
|
||
33C000
|
unkown
|
page readonly
|
||
1DC1000
|
heap
|
page read and write
|
||
1DC1000
|
heap
|
page read and write
|
||
1DB5000
|
heap
|
page read and write
|
||
3A10000
|
heap
|
page read and write
|
||
338000
|
unkown
|
page write copy
|
||
2F0000
|
unkown
|
page readonly
|
||
1EE5000
|
heap
|
page read and write
|
||
3DDB000
|
stack
|
page read and write
|
||
754F000
|
stack
|
page read and write
|
||
3A74000
|
heap
|
page read and write
|
||
3A50000
|
heap
|
page read and write
|
||
2F1000
|
unkown
|
page execute read
|
||
3B50000
|
heap
|
page read and write
|
||
1EE0000
|
heap
|
page read and write
|
||
1DA0000
|
heap
|
page read and write
|
||
1DA8000
|
heap
|
page read and write
|
||
1D90000
|
heap
|
page read and write
|
||
20C0000
|
heap
|
page read and write
|
||
3C5D000
|
stack
|
page read and write
|
||
3A30000
|
heap
|
page read and write
|
||
33C000
|
unkown
|
page readonly
|
||
3A70000
|
heap
|
page read and write
|
||
38BE000
|
stack
|
page read and write
|
||
1DC1000
|
heap
|
page read and write
|
||
D3C000
|
unkown
|
page readonly
|
||
3B55000
|
heap
|
page read and write
|
||
1EDE000
|
stack
|
page read and write
|
||
2F0000
|
unkown
|
page readonly
|
||
338000
|
unkown
|
page read and write
|
||
3B3E000
|
stack
|
page read and write
|
||
2F1000
|
unkown
|
page execute read
|
||
3D9F000
|
stack
|
page read and write
|
||
3EDA000
|
stack
|
page read and write
|
||
1DBE000
|
heap
|
page read and write
|
||
740D000
|
stack
|
page read and write
|
||
6ADC000
|
stack
|
page read and write
|
||
1DB9000
|
heap
|
page read and write
|
||
3C9E000
|
stack
|
page read and write
|
||
D3C000
|
unkown
|
page readonly
|
||
33C000
|
unkown
|
page readonly
|
||
402F000
|
stack
|
page read and write
|
||
3F2E000
|
stack
|
page read and write
|
||
33A000
|
unkown
|
page read and write
|
||
3B59000
|
heap
|
page read and write
|
||
39BE000
|
stack
|
page read and write
|
||
173C000
|
unkown
|
page readonly
|
||
20BE000
|
stack
|
page read and write
|
||
1DB9000
|
heap
|
page read and write
|
There are 49 hidden memdumps, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|
||
https://www.ni.com/en/support/downloads/software-products/download.labview-runtime.html#544052
|