Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Sep 29 10:08:44 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Sep 29 10:08:44 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:00:51 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Sep 29 10:08:44 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Sep 29 10:08:44 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sun Sep 29 10:08:44 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 123
|
ASCII text, with very long lines (60994)
|
dropped
|
||
Chrome Cache Entry: 124
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 125
|
ASCII text, with very long lines (65464)
|
downloaded
|
||
Chrome Cache Entry: 126
|
ASCII text, with very long lines (5945)
|
downloaded
|
||
Chrome Cache Entry: 127
|
ASCII text, with very long lines (11425), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 128
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 129
|
ASCII text, with very long lines (64024)
|
dropped
|
||
Chrome Cache Entry: 130
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 131
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 132
|
ASCII text, with very long lines (5945)
|
dropped
|
||
Chrome Cache Entry: 133
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 134
|
ASCII text, with very long lines (15552), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 135
|
ASCII text, with very long lines (15453), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 136
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 137
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 138
|
ASCII text, with very long lines (60994)
|
downloaded
|
||
Chrome Cache Entry: 139
|
ASCII text, with no line terminators
|
dropped
|
||
Chrome Cache Entry: 140
|
ASCII text, with very long lines (804), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 141
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 142
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 143
|
ASCII text, with very long lines (16442), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 144
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 145
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 146
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 147
|
ASCII text, with very long lines (3111), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 148
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 149
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 150
|
ASCII text, with very long lines (15453), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 151
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 152
|
ASCII text, with very long lines (2528)
|
dropped
|
||
Chrome Cache Entry: 153
|
ASCII text, with very long lines (11425), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 154
|
ASCII text, with very long lines (6913), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 155
|
ASCII text, with very long lines (65467)
|
dropped
|
||
Chrome Cache Entry: 156
|
Unicode text, UTF-8 text, with very long lines (65529), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 157
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 158
|
ASCII text, with very long lines (2528)
|
downloaded
|
||
Chrome Cache Entry: 159
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 160
|
ASCII text, with very long lines (33349), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 161
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 162
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 163
|
ASCII text, with very long lines (804), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 164
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 165
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 166
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 167
|
ASCII text, with very long lines (65464)
|
dropped
|
||
Chrome Cache Entry: 168
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 169
|
ASCII text, with very long lines (897), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 170
|
ASCII text, with very long lines (2343)
|
dropped
|
||
Chrome Cache Entry: 171
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 172
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 173
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 174
|
ASCII text, with very long lines (6913), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 175
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 176
|
ASCII text, with very long lines (2345)
|
downloaded
|
||
Chrome Cache Entry: 177
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 178
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 179
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 180
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 181
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 182
|
ASCII text, with very long lines (21556)
|
dropped
|
||
Chrome Cache Entry: 183
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 184
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 185
|
ASCII text, with very long lines (2343)
|
downloaded
|
||
Chrome Cache Entry: 186
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 187
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 188
|
ASCII text, with very long lines (9813), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 189
|
ASCII text, with very long lines (21556)
|
downloaded
|
||
Chrome Cache Entry: 190
|
ASCII text, with very long lines (15552), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 191
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 192
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 193
|
ASCII text, with very long lines (12175), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 194
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 195
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 196
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 197
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 198
|
ASCII text, with very long lines (65464)
|
downloaded
|
||
Chrome Cache Entry: 199
|
ASCII text, with very long lines (2345)
|
dropped
|
||
Chrome Cache Entry: 200
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 201
|
ASCII text, with very long lines (33349), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 202
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 203
|
ASCII text, with very long lines (65464)
|
dropped
|
||
Chrome Cache Entry: 204
|
ASCII text, with very long lines (12175), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 205
|
ASCII text, with very long lines (3111), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 206
|
ASCII text, with very long lines (11306), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 207
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 208
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 209
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 210
|
ASCII text, with very long lines (9813), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 211
|
ASCII text, with very long lines (65536), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 212
|
ASCII text, with very long lines (65467)
|
downloaded
|
||
Chrome Cache Entry: 213
|
ASCII text, with very long lines (64024)
|
downloaded
|
||
Chrome Cache Entry: 214
|
ASCII text, with very long lines (897), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 215
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 216
|
ASCII text, with very long lines (11306), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 217
|
GIF image data, version 89a, 1 x 1
|
dropped
|
||
Chrome Cache Entry: 218
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 219
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 220
|
GIF image data, version 89a, 1 x 1
|
downloaded
|
||
Chrome Cache Entry: 221
|
JSON data
|
downloaded
|
There are 96 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=1900,i,1157449053875135814,2097530389074965015,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.baystatedigital.com/"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://email.baystatedigital.com/
|
|||
https://www.google.com
|
unknown
|
||
https://www.youtube.com/iframe_api
|
unknown
|
||
https://feross.org
|
unknown
|
||
https://unpkg.com/@elastic/apm-rum@5.16.1/dist/bundles/elastic-apm-rum.umd.min.js
|
104.17.248.203
|
||
https://stats.g.doubleclick.net/g/collect
|
unknown
|
||
https://email.baystatedigital.com/
|
15.197.155.180
|
||
https://www.google.com/ads/ga-audiences
|
unknown
|
||
https://www.google.%/ads/ga-audiences
|
unknown
|
||
https://td.doubleclick.net
|
unknown
|
||
https://sso.secureserver.net/account/reset?app=email&realm=pass
|
|||
https://www.merchant-center-analytics.goog
|
unknown
|
||
https://tagassistant.google.com/
|
unknown
|
||
https://sso.secureserver.net/account/reset?app=email&realm=pass#main
|
|||
https://g.sst.gpl.secureserver.net/csp/collect
|
75.2.72.163
|
||
https://stats.g.doubleclick.net/j/collect
|
unknown
|
||
https://ampcid.google.com/v1/publisher:getClientId
|
unknown
|
||
https://sso.secureserver.net/v1/account/reset?app=email&realm=pass
|
unknown
|
||
https://email.secureserver.net/auth
|
15.197.155.180
|
||
https://sso.secureserver.net/login?app=email&realm=pass
|
|||
https://sso.secureserver.net/login?app=email&realm=pass#main
|
|||
https://cct.google/taggy/agent.js
|
unknown
|
||
https://sso.secureserver.net/v1/account/retrieve?app=email&realm=pass
|
unknown
|
||
https://g.sst.gpl.secureserver.net/gtag/js?id=G-11GY9GPGDG&l=_sGtmDataLayer
|
75.2.72.163
|
||
https://adservice.google.com/pagead/regclk?
|
unknown
|
There are 14 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
g.sst.gpl.secureserver.net
|
75.2.72.163
|
||
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
proxy-nlb-prod-us-west-2-v5-ac4e52c97755301b.elb.us-west-2.amazonaws.com
|
54.212.23.110
|
||
www.google.com
|
172.217.18.100
|
||
reporting.cdndex.io
|
13.32.99.103
|
||
unpkg.com
|
104.17.248.203
|
||
email.secureserver.net
|
15.197.155.180
|
||
fp2e7a.wpc.phicdn.net
|
192.229.221.95
|
||
img1.wsimg.com
|
unknown
|
||
events.api.secureserver.net
|
unknown
|
||
cca039482a104d5d9b04bd2e20f6bb64.apm.us-west-2.aws.found.io
|
unknown
|
||
email.baystatedigital.com
|
unknown
|
||
img6.wsimg.com
|
unknown
|
||
_9243._https.cca039482a104d5d9b04bd2e20f6bb64.apm.us-west-2.aws.found.io
|
unknown
|
||
csp.secureserver.net
|
unknown
|
||
gui.secureserver.net
|
unknown
|
||
sso.secureserver.net
|
unknown
|
There are 7 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
54.212.23.110
|
proxy-nlb-prod-us-west-2-v5-ac4e52c97755301b.elb.us-west-2.amazonaws.com
|
United States
|
||
104.17.248.203
|
unpkg.com
|
United States
|
||
192.168.2.8
|
unknown
|
unknown
|
||
75.2.72.163
|
g.sst.gpl.secureserver.net
|
United States
|
||
192.168.2.9
|
unknown
|
unknown
|
||
15.197.155.180
|
email.secureserver.net
|
United States
|
||
13.32.99.103
|
reporting.cdndex.io
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
142.250.186.100
|
unknown
|
United States
|
||
172.217.18.100
|
www.google.com
|
United States
|
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://sso.secureserver.net/login?app=email&realm=pass
|
||
https://sso.secureserver.net/login?app=email&realm=pass
|
||
https://sso.secureserver.net/login?app=email&realm=pass
|
||
https://sso.secureserver.net/login?app=email&realm=pass
|
||
https://sso.secureserver.net/login?app=email&realm=pass
|
||
https://sso.secureserver.net/login?app=email&realm=pass
|
||
https://sso.secureserver.net/account/reset?app=email&realm=pass
|
||
https://sso.secureserver.net/account/reset?app=email&realm=pass
|
||
https://sso.secureserver.net/login?app=email&realm=pass#main
|
||
https://sso.secureserver.net/login?app=email&realm=pass#main
|
||
https://sso.secureserver.net/account/reset?app=email&realm=pass#main
|
||
https://sso.secureserver.net/account/reset?app=email&realm=pass#main
|
There are 2 hidden doms, click here to show them.