IOC Report
http://t1.global.clubavolta.com/r/?id=h53ebcb4b,29506a5f,2988b9de&e=cDE9UkVEX0dMX0xveWFsdHlMYXVuY2hTb2x1cy1OT0NPTS1BTEwtMDExMDIwMjQtMV9YWCZwMj1kNzEwNWE1Zi00NjE3LWVmMTEtOWY4OS0wMDBkM2EyMmNlYTE&s=-xp-260ih6zExbqpOebvhe5u79N7KVTM1gNLcwjEM2E

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 21:24:33 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 21:24:33 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 21:24:33 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 21:24:33 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 21:24:33 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 184
C source, ASCII text, with very long lines (65103)
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 186
gzip compressed data, was "tmpyiylrfjd", last modified: Tue Sep 17 11:16:29 2024, max compression, original size modulo 2^32 473
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (65269), with CRLF line terminators
downloaded
Chrome Cache Entry: 188
TrueType Font data, 11 tables, 1st "OS/2", 14 names, Macintosh, type 1 string, icomoon
downloaded
Chrome Cache Entry: 189
JSON data
dropped
Chrome Cache Entry: 190
gzip compressed data, was "tmpkg97jlww", last modified: Tue Sep 17 11:16:38 2024, max compression, original size modulo 2^32 1740
dropped
Chrome Cache Entry: 191
Web Open Font Format (Version 2), CFF, length 41740, version 1.0
downloaded
Chrome Cache Entry: 192
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (49093)
dropped
Chrome Cache Entry: 194
JSON data
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (65352), with CRLF line terminators
downloaded
Chrome Cache Entry: 196
Web Open Font Format (Version 2), CFF, length 41740, version 1.0
downloaded
Chrome Cache Entry: 197
HTML document, Unicode text, UTF-8 text, with very long lines (4252), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (11924)
dropped
Chrome Cache Entry: 199
ASCII text, with very long lines (30636)
downloaded
Chrome Cache Entry: 200
gzip compressed data, was "tmp_fdb7c0w", last modified: Tue Sep 17 11:16:30 2024, max compression, original size modulo 2^32 2217
downloaded
Chrome Cache Entry: 201
GIF image data, version 89a, 800 x 243
dropped
Chrome Cache Entry: 202
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1920x600, components 3
dropped
Chrome Cache Entry: 203
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 204
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 205
HTML document, Unicode text, UTF-8 text, with very long lines (4252), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 206
Unicode text, UTF-8 text, with very long lines (64399)
downloaded
Chrome Cache Entry: 207
JSON data
dropped
Chrome Cache Entry: 208
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 209
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 1920x600, components 3
downloaded
Chrome Cache Entry: 210
gzip compressed data, was "tmpmdgyjxbt", last modified: Tue Sep 17 11:16:30 2024, max compression, original size modulo 2^32 4399
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (32058)
dropped
Chrome Cache Entry: 212
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 1920x600, components 3
downloaded
Chrome Cache Entry: 213
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 805x580, components 3
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (49093)
downloaded
Chrome Cache Entry: 215
Web Open Font Format, TrueType, length 17280, version 2.0
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (32001)
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 218
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 219
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 1920x600, components 3
dropped
Chrome Cache Entry: 220
Web Open Font Format (Version 2), CFF, length 43000, version 1.0
downloaded
Chrome Cache Entry: 221
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 222
JSON data
downloaded
Chrome Cache Entry: 223
ASCII text
downloaded
Chrome Cache Entry: 224
ASCII text
downloaded
Chrome Cache Entry: 225
ASCII text
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (2134)
dropped
Chrome Cache Entry: 227
ASCII text, with very long lines (32746)
dropped
Chrome Cache Entry: 228
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 229
JSON data
downloaded
Chrome Cache Entry: 230
gzip compressed data, was "tmplia6_9k8", last modified: Tue Sep 17 11:16:34 2024, max compression, original size modulo 2^32 159833
dropped
Chrome Cache Entry: 231
HTML document, Unicode text, UTF-8 text, with very long lines (4252), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 232
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 233
gzip compressed data, was "tmp0yrdjd2n", last modified: Tue Sep 17 11:16:31 2024, max compression, original size modulo 2^32 1728
dropped
Chrome Cache Entry: 234
TrueType Font data, 11 tables, 1st "OS/2", 14 names, Macintosh, type 1 string, icomoon
downloaded
Chrome Cache Entry: 235
gzip compressed data, was "tmpkijf5vvx", last modified: Tue Sep 17 11:16:39 2024, max compression, original size modulo 2^32 5128
downloaded
Chrome Cache Entry: 236
gzip compressed data, was "tmphejarc7e", last modified: Tue Sep 17 11:16:32 2024, max compression, original size modulo 2^32 1513
dropped
Chrome Cache Entry: 237
ASCII text
dropped
Chrome Cache Entry: 238
gzip compressed data, was "tmpz39m4eqo", last modified: Tue Sep 17 11:16:31 2024, max compression, original size modulo 2^32 2937
dropped
Chrome Cache Entry: 239
ASCII text, with very long lines (32058)
downloaded
Chrome Cache Entry: 240
ASCII text, with very long lines (65352), with CRLF line terminators
dropped
Chrome Cache Entry: 241
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 242
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 243
ASCII text, with very long lines (5258)
downloaded
Chrome Cache Entry: 244
JSON data
downloaded
Chrome Cache Entry: 245
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 246
ASCII text, with very long lines (4269)
downloaded
Chrome Cache Entry: 247
gzip compressed data, was "tmpyiylrfjd", last modified: Tue Sep 17 11:16:29 2024, max compression, original size modulo 2^32 473
downloaded
Chrome Cache Entry: 248
ASCII text, with very long lines (11924)
downloaded
Chrome Cache Entry: 249
ASCII text, with very long lines (5258)
dropped
Chrome Cache Entry: 250
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 251
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 805x580, components 3
downloaded
Chrome Cache Entry: 252
ASCII text, with very long lines (32746)
downloaded
Chrome Cache Entry: 253
JSON data
dropped
Chrome Cache Entry: 254
gzip compressed data, was "tmp_fdb7c0w", last modified: Tue Sep 17 11:16:30 2024, max compression, original size modulo 2^32 2217
dropped
Chrome Cache Entry: 255
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 256
PNG image data, 5000 x 13, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 257
Web Open Font Format (Version 2), TrueType, length 128352, version 1.0
downloaded
Chrome Cache Entry: 258
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 1920x600, components 3
dropped
Chrome Cache Entry: 259
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 805x580, components 3
downloaded
Chrome Cache Entry: 260
ASCII text, with very long lines (3877)
downloaded
Chrome Cache Entry: 261
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 805x580, components 3
dropped
Chrome Cache Entry: 262
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 1920x600, components 3
dropped
Chrome Cache Entry: 263
gzip compressed data, was "tmpuhnqew5e", last modified: Tue Sep 17 11:16:31 2024, max compression, original size modulo 2^32 5491
dropped
Chrome Cache Entry: 264
JSON data
downloaded
Chrome Cache Entry: 265
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 266
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (44877), with CRLF line terminators
downloaded
Chrome Cache Entry: 268
JSON data
downloaded
Chrome Cache Entry: 269
gzip compressed data, was "tmpkijf5vvx", last modified: Tue Sep 17 11:16:39 2024, max compression, original size modulo 2^32 5128
dropped
Chrome Cache Entry: 270
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 271
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 272
ASCII text, with very long lines (2343)
dropped
Chrome Cache Entry: 273
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 274
PNG image data, 20 x 11, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 275
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 276
MS Windows icon resource - 6 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 277
Web Open Font Format (Version 2), CFF, length 47544, version 1.0
downloaded
Chrome Cache Entry: 278
gzip compressed data, was "tmpl5u_ed55", last modified: Tue Sep 17 11:16:32 2024, max compression, original size modulo 2^32 567
dropped
Chrome Cache Entry: 279
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 805x580, components 3
dropped
Chrome Cache Entry: 280
ASCII text, with very long lines (441)
downloaded
Chrome Cache Entry: 281
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 282
PNG image data, 5000 x 13, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (441)
dropped
Chrome Cache Entry: 284
JSON data
dropped
Chrome Cache Entry: 285
JSON data
dropped
Chrome Cache Entry: 286
gzip compressed data, was "tmphejarc7e", last modified: Tue Sep 17 11:16:32 2024, max compression, original size modulo 2^32 1513
downloaded
Chrome Cache Entry: 287
C source, ASCII text, with very long lines (65103)
downloaded
Chrome Cache Entry: 288
ASCII text, with very long lines (29422)
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (2134)
downloaded
Chrome Cache Entry: 290
ASCII text, with very long lines (9217)
downloaded
Chrome Cache Entry: 291
ASCII text, with very long lines (65352), with CRLF line terminators
downloaded
Chrome Cache Entry: 292
gzip compressed data, was "tmpjb_3iwb1", last modified: Tue Sep 17 11:16:17 2024, max compression, original size modulo 2^32 5482
downloaded
Chrome Cache Entry: 293
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 294
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 295
ASCII text
downloaded
Chrome Cache Entry: 296
JSON data
dropped
Chrome Cache Entry: 297
gzip compressed data, was "tmp55kknrum", last modified: Tue Sep 17 11:16:40 2024, max compression, original size modulo 2^32 450160
dropped
Chrome Cache Entry: 298
JSON data
dropped
Chrome Cache Entry: 299
ASCII text, with very long lines (18179), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 300
ASCII text
downloaded
Chrome Cache Entry: 301
ASCII text, with very long lines (5552)
downloaded
Chrome Cache Entry: 302
ASCII text, with very long lines (3877)
dropped
Chrome Cache Entry: 303
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (4269)
dropped
Chrome Cache Entry: 305
JSON data
downloaded
Chrome Cache Entry: 306
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 805x580, components 3
dropped
Chrome Cache Entry: 307
ASCII text, with very long lines (17158)
downloaded
Chrome Cache Entry: 308
ASCII text, with very long lines (5552)
dropped
Chrome Cache Entry: 309
Web Open Font Format (Version 2), CFF, length 43060, version 1.0
downloaded
Chrome Cache Entry: 310
JSON data
dropped
Chrome Cache Entry: 311
ASCII text
downloaded
Chrome Cache Entry: 312
HTML document, ASCII text, with very long lines (4252), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 313
ASCII text, with very long lines (65450)
dropped
Chrome Cache Entry: 314
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1920x600, components 3
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (830)
downloaded
Chrome Cache Entry: 316
gzip compressed data, was "tmpCfWGAE", last modified: Fri May 8 09:06:08 2020, max compression, original size modulo 2^32 489
dropped
Chrome Cache Entry: 317
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 318
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 319
gzip compressed data, was "tmp0yrdjd2n", last modified: Tue Sep 17 11:16:31 2024, max compression, original size modulo 2^32 1728
downloaded
Chrome Cache Entry: 320
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 321
gzip compressed data, was "tmp5ay73b4h", last modified: Tue Sep 17 11:17:07 2024, max compression, original size modulo 2^32 33954
dropped
Chrome Cache Entry: 322
JSON data
dropped
Chrome Cache Entry: 323
JSON data
downloaded
Chrome Cache Entry: 324
JSON data
downloaded
Chrome Cache Entry: 325
ASCII text, with very long lines (5552)
downloaded
Chrome Cache Entry: 326
JSON data
downloaded
Chrome Cache Entry: 327
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 328
ASCII text, with very long lines (65226)
downloaded
Chrome Cache Entry: 329
ASCII text
dropped
Chrome Cache Entry: 330
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 331
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 1920x600, components 3
dropped
Chrome Cache Entry: 332
MS Windows icon resource - 6 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 333
gzip compressed data, was "tmpkg97jlww", last modified: Tue Sep 17 11:16:38 2024, max compression, original size modulo 2^32 1740
downloaded
Chrome Cache Entry: 334
ASCII text, with very long lines (32001)
dropped
Chrome Cache Entry: 335
gzip compressed data, was "tmp_cgccsit", last modified: Tue Sep 17 11:16:33 2024, max compression, original size modulo 2^32 1270
dropped
Chrome Cache Entry: 336
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 337
ASCII text
downloaded
Chrome Cache Entry: 338
Web Open Font Format (Version 2), CFF, length 47544, version 1.0
downloaded
Chrome Cache Entry: 339
ASCII text, with very long lines (65269), with CRLF line terminators
dropped
Chrome Cache Entry: 340
ASCII text
downloaded
Chrome Cache Entry: 341
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 342
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 343
JSON data
dropped
Chrome Cache Entry: 344
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 345
gzip compressed data, was "tmpuhnqew5e", last modified: Tue Sep 17 11:16:31 2024, max compression, original size modulo 2^32 5491
downloaded
Chrome Cache Entry: 346
GIF image data, version 89a, 800 x 243
downloaded
Chrome Cache Entry: 347
JSON data
dropped
Chrome Cache Entry: 348
ASCII text
dropped
Chrome Cache Entry: 349
ASCII text, with very long lines (65450)
downloaded
Chrome Cache Entry: 350
C source, ASCII text, with very long lines (65103)
downloaded
Chrome Cache Entry: 351
Web Open Font Format (Version 2), CFF, length 43060, version 1.0
downloaded
Chrome Cache Entry: 352
JSON data
downloaded
Chrome Cache Entry: 353
Unicode text, UTF-8 text, with very long lines (64399)
dropped
Chrome Cache Entry: 354
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 355
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 356
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (5552)
dropped
Chrome Cache Entry: 358
gzip compressed data, was "tmp55kknrum", last modified: Tue Sep 17 11:16:40 2024, max compression, original size modulo 2^32 450160
downloaded
Chrome Cache Entry: 359
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 360
ASCII text
dropped
Chrome Cache Entry: 361
gzip compressed data, was "tmp5ay73b4h", last modified: Tue Sep 17 11:17:07 2024, max compression, original size modulo 2^32 33954
downloaded
Chrome Cache Entry: 362
gzip compressed data, was "tmpl5u_ed55", last modified: Tue Sep 17 11:16:32 2024, max compression, original size modulo 2^32 567
downloaded
Chrome Cache Entry: 363
ASCII text, with very long lines (17158)
dropped
Chrome Cache Entry: 364
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 1920x600, components 3
downloaded
Chrome Cache Entry: 365
HTML document, Unicode text, UTF-8 text, with very long lines (4252), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 366
JSON data
dropped
Chrome Cache Entry: 367
ASCII text, with very long lines (65226)
dropped
Chrome Cache Entry: 368
gzip compressed data, was "tmpz39m4eqo", last modified: Tue Sep 17 11:16:31 2024, max compression, original size modulo 2^32 2937
downloaded
Chrome Cache Entry: 369
ASCII text
downloaded
Chrome Cache Entry: 370
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 371
ASCII text, with very long lines (9217)
dropped
Chrome Cache Entry: 372
gzip compressed data, was "tmplia6_9k8", last modified: Tue Sep 17 11:16:34 2024, max compression, original size modulo 2^32 159833
downloaded
Chrome Cache Entry: 373
gzip compressed data, was "tmpCfWGAE", last modified: Fri May 8 09:06:08 2020, max compression, original size modulo 2^32 489
downloaded
Chrome Cache Entry: 374
gzip compressed data, was "tmpmdgyjxbt", last modified: Tue Sep 17 11:16:30 2024, max compression, original size modulo 2^32 4399
dropped
Chrome Cache Entry: 375
ASCII text, with very long lines (438)
downloaded
Chrome Cache Entry: 376
PNG image data, 20 x 11, 4-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 377
gzip compressed data, was "tmp_cgccsit", last modified: Tue Sep 17 11:16:33 2024, max compression, original size modulo 2^32 1270
downloaded
Chrome Cache Entry: 378
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 379
C source, ASCII text, with very long lines (65103)
dropped
Chrome Cache Entry: 380
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, progressive, precision 8, 1920x600, components 3
downloaded
Chrome Cache Entry: 381
ASCII text, with very long lines (30636)
dropped
Chrome Cache Entry: 382
JSON data
downloaded
There are 196 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2568 --field-trial-handle=2512,i,13780221225709633851,4419667238433277468,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://t1.global.clubavolta.com/r/?id=h53ebcb4b,29506a5f,2988b9de&e=cDE9UkVEX0dMX0xveWFsdHlMYXVuY2hTb2x1cy1OT0NPTS1BTEwtMDExMDIwMjQtMV9YWCZwMj1kNzEwNWE1Zi00NjE3LWVmMTEtOWY4OS0wMDBkM2EyMmNlYTE&s=-xp-260ih6zExbqpOebvhe5u79N7KVTM1gNLcwjEM2E"

URLs

Name
IP
Malicious
http://t1.global.clubavolta.com/r/?id=h53ebcb4b,29506a5f,2988b9de&e=cDE9UkVEX0dMX0xveWFsdHlMYXVuY2hTb2x1cy1OT0NPTS1BTEwtMDExMDIwMjQtMV9YWCZwMj1kNzEwNWE1Zi00NjE3LWVmMTEtOWY4OS0wMDBkM2EyMmNlYTE&s=-xp-260ih6zExbqpOebvhe5u79N7KVTM1gNLcwjEM2E
https://stats.g.doubleclick.net/g/collect
unknown
https://dpm.demdex.net/id?d_visid_ver=5.0.1&d_fieldgroup=AAM&d_rtbd=json&d_ver=2&d_orgid=B72759175BC87D800A495D6D%40AdobeOrg&d_nsid=0&d_mid=31468726474390896630132246887632732159&ts=1727821477459
18.202.39.134
https://avolta-go.euwest01.umbraco.io/fi/yhteistyoekumppanimme/lounget
unknown
https://s2.go-mpulse.net/boomerang/
unknown
https://consent-api.service.consent.usercentrics.eu/consent/uw/3
35.201.111.240
https://avolta-go.euwest01.umbraco.io/ko/club-avolta-소개
unknown
https://app.usercentrics.eu/browser-ui/3.55.0/VirtualServiceItem-d95151cb.js
35.190.14.188
http://www.allaboutcookies.org/
unknown
https://flagcdn.com/w20/us.png
172.67.180.104
https://avolta-go.euwest01.umbraco.io/fr/a-propos-du-club-avolta/les-membres-economisent-plus
unknown
https://avolta-go.euwest01.umbraco.io/fr/nos-partenaires/lounges
unknown
https://avolta-go.euwest01.umbraco.io/it/i-nostri-partner/lounge
unknown
https://app.usercentrics.eu/session/1px.png?settingsId=HzbbJ_HfNrjwq0
35.190.14.188
https://code.google.com/p/chromium/issues/detail?id=378607
unknown
https://www.facebook.com/tr/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fwww.clubavolta.com%2Fabout-club-avolta%2Fmembers-save-more%3Futm_source%3Dnewsletter%26utm_medium%3Demail%26utm_campaign%3DRED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX%26utm_term%3Dd7105a5f-4617-ef11-9f89-000d3a22cea1&rl=&if=false&ts=1727821482272&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821480875&coo=false&eid=1727821475149.1&rqm=GET
157.240.253.35
https://app.usercentrics.eu/browser-ui/3.55.0/FirstLayerCustomization-de8ec6f3-0ed66d66.js
35.190.14.188
https://ampcid.google.com/v1/publisher:getClientId
unknown
https://avolta-go.euwest01.umbraco.io/es_ar/nuestros-socios/salas-vip
unknown
https://swiperjs.com
unknown
https://www.facebook.com/tr/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fwww.clubavolta.com%2Fabout-club-avolta&rl=&if=false&ts=1727821515382&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821514182&coo=false&eid=1727821512421.1&rqm=GET
157.240.253.35
http://dev.w3.org/csswg/cssom/#resolved-values
unknown
https://app.usercentrics.eu/browser-ui/3.55.0/index-4d0d6d10.js
35.190.14.188
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
unknown
https://avolta-go.euwest01.umbraco.io/de/unsere-partner/lounges
unknown
https://dufry.demdex.net/dest5.html?d_nsid=0
18.202.150.204
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
unknown
https://code.google.com/p/chromium/issues/detail?id=229280
unknown
https://stats.g.doubleclick.net/j/collect
unknown
https://app.usercentrics.eu/browser-ui/3.55.0/ButtonsCustomization-5698ac85-5d43b15f.js
35.190.14.188
https://assets.adobedtm.com/31339f9326f3/e6bbf611b75f/launch-ENaf3fff48ad204db9aade144b2c043fee.min.
unknown
https://www.facebook.com/privacy_sandbox/pixel/register/trigger/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fwww.clubavolta.com%2F&rl=&if=false&ts=1727821524289&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821523748&coo=false&eid=1727821523026.1&rqm=FGET
157.240.253.35
https://avolta-go.euwest01.umbraco.io/about-club-avolta/members-save-more
unknown
https://github.com/google/closure-library/wiki/goog.module:-an-ES6-module-like-alternative-to-goog.p
unknown
http://bugs.jquery.com/ticket/12359
unknown
https://app.usercentrics.eu/browser-ui/latest/loader.js
35.190.14.188
https://bugzilla.mozilla.org/show_bug.cgi?id=649285
unknown
https://app.usercentrics.eu/browser-ui/3.55.0/DefaultData-fa10cf7f-3d7db9aa.js
35.190.14.188
https://content.hotjar.io/?site_id=5148378&gzip=1
54.73.193.221
https://avolta-go.euwest01.umbraco.io/ru/o-club-avolta
unknown
https://uct.service.usercentrics.eu/uct?v=1&sid=HzbbJ_HfNrjwq0&t=1&abv=&r=https%3A%2F%2Fwww.clubavolta.com%2Fabout-club-avolta&cb=1727821513885
34.95.108.180
https://avolta-go.euwest01.umbraco.io/de/home
unknown
https://sso.dufry.com/detailedTerms?country=68281cb0-6ef7-e611-8100-5065f38bf4f1&language=en&amp
unknown
https://www.facebook.com/privacy_sandbox/pixel/register/trigger/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fwww.clubavolta.com%2Fabout-club-avolta%2Fmembers-save-more%3Futm_source%3Dnewsletter%26utm_medium%3Demail%26utm_campaign%3DRED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX%26utm_term%3Dd7105a5f-4617-ef11-9f89-000d3a22cea1&rl=&if=false&ts=1727821482272&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821480875&coo=false&eid=1727821475149.1&rqm=FGET
157.240.253.35
https://uct.service.usercentrics.eu/uct?v=1&sid=HzbbJ_HfNrjwq0&t=1&abv=&r=https%3A%2F%2Fsso.clubavolta.com%2Fregister&cb=1727821508161
34.95.108.180
https://avolta-go.euwest01.umbraco.io/es/nuestros-partners/hoteles
unknown
https://avolta-go.euwest01.umbraco.io/fi/yhteistyoekumppanimme/hotellit
unknown
https://www.clubavolta.com/our-partners/lounges
https://avolta-go.euwest01.umbraco.io/fi/tietoa-club-avoltasta
unknown
https://avolta-go.euwest01.umbraco.io/zh/我们的合作伙伴/&#
unknown
https://www.avoltaworld.com/en
unknown
https://avolta-go.euwest01.umbraco.io/zh_tw/關於club-avolta/會員可&#x7
unknown
https://connect.facebook.net/
unknown
https://web.cmp.usercentrics.eu/ui/loader.js
unknown
https://avolta-go.euwest01.umbraco.io/it/informazioni-sul-club-avolta/i-membri-risparmiano-ancora-di
unknown
https://avolta-go.euwest01.umbraco.io/es/acerca-de-club-avolta
unknown
https://bugzilla.mozilla.org/show_bug.cgi?id=491668
unknown
https://avolta-go.euwest01.umbraco.io/pt/nossos-parceiros/hoteis
unknown
https://app.usercentrics.eu/browser-ui/3.55.0/index-3ff76a26.js
35.190.14.188
https://code.google.com/p/chromium/issues/detail?id=470258
unknown
https://avolta-go.euwest01.umbraco.io/sv/om-club-avolta
unknown
https://use.typekit.net
unknown
https://assets.adobedtm.com/launch-ENaf3fff48ad204db9aade144b2c043fee.js
unknown
https://www.akamai.com/us/en/multimedia/documents/akamai/akamai-privacy-statement.pdf
unknown
http://jsperf.com/getall-vs-sizzle/2
unknown
https://sso.dufry.com/register?source=ctOnline-scAvolta_website-coGBR-arLGW#
unknown
https://api.usercentrics.eu/settings/HzbbJ_HfNrjwq0/latest/en.json
35.241.3.184
http://www.google.com/intl/en_uk/analytics/tos.html
unknown
https://avolta-go.euwest01.umbraco.io/fr/a-propos-du-club-avolta
unknown
https://github.com/jquery/jquery/pull/557)
unknown
https://avolta-go.euwest01.umbraco.io/es/inicio
unknown
https://avolta-go.euwest01.umbraco.io/zh/home
unknown
https://app.usercentrics.eu/browser-ui/3.55.0/PrivacyButton-62ab6c78.js
35.190.14.188
https://www.facebook.com/privacy_sandbox/pixel/register/trigger/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fwww.clubavolta.com%2Four-partners%2Fhotels&rl=&if=false&ts=1727821535214&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821535132&coo=false&eid=1727821533475.1&rqm=FGET
157.240.253.35
https://avolta-go.euwest01.umbraco.io/zh_tw/關於club-avolta
unknown
https://avolta-go.euwest01.umbraco.io/zh/关于club-avolta
unknown
https://avolta-go.euwest01.umbraco.io/ko/home
unknown
https://www.facebook.com/privacy_sandbox/pixel/register/trigger/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fwww.clubavolta.com%2Four-partners%2Flounges&rl=&if=false&ts=1727821545072&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821544671&coo=false&eid=1727821541370.1&rqm=FGET
157.240.0.35
https://avolta-go.euwest01.umbraco.io/zh_tw/home
unknown
https://avolta-go.euwest01.umbraco.io/pt/sobre-o-club-avolta/os-membros-do-programa-economizam-mais
unknown
https://script.hotjar.com/browser-perf.8417c6bba72228fa2e29.js
13.32.27.19
https://avolta-go.euwest01.umbraco.io/gr/home
unknown
http://materializecss.com)
unknown
https://www.facebook.com/tr/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fwww.clubavolta.com%2F&rl=&if=false&ts=1727821524289&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821523748&coo=false&eid=1727821523026.1&rqm=GET
157.240.253.35
https://avolta-go.euwest01.umbraco.io/es/nuestros-partners/salas
unknown
https://static.hotjar.com/c/hotjar-
unknown
https://images.clubavolta.com/media/hlei1tzc/home-header-banner-desktop.png?width=1200&height=63
unknown
https://images.clubavolta.com/media/hlei1tzc/home-header-banner-desktop.png?width=1200&height=62
unknown
https://getbootstrap.com/)
unknown
https://avolta-go.euwest01.umbraco.io/pt/home
unknown
https://avolta-go.euwest01.umbraco.io/sv/om-club-avolta/som-medlem-sparar-du-mer
unknown
https://avolta-go.euwest01.umbraco.io/sv/vaara-partner/hotell
unknown
https://www.facebook.com/privacy_sandbox/pixel/register/trigger/?id=1083686203427969&ev=PageView&dl=https%3A%2F%2Fsso.clubavolta.com%2Fregister%3Fsource%3DctOnline-scAvolta_website%26lang%3Den&rl=&if=false&ts=1727821507336&sw=1280&sh=1024&v=2.9.170&r=stable&ec=0&o=4126&fbp=fb.1.1727821482266.813230382770870091&ler=empty&cdl=API_unavailable&it=1727821505473&coo=false&eid=1727821499120.1&rqm=FGET
157.240.253.35
http://bugs.jquery.com/ticket/13378
unknown
http://jsperf.com/thor-indexof-vs-for/5
unknown
https://avolta-go.euwest01.umbraco.io/pt/nossos-parceiros/lounges
unknown
https://td.doubleclick.net
unknown
https://avolta-go.euwest01.umbraco.io/de/mehr-ueber-club-avolta/mitglieder-sparen-mehr
unknown
https://avolta-go.euwest01.umbraco.io/fr/home
unknown
https://github.com/jackocnr/intl-tel-input.git
unknown
https://avolta-go.euwest01.umbraco.io/home
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
api.usercentrics.eu
35.241.3.184
star-mini.c10r.facebook.com
157.240.253.35
flagcdn.com
172.67.180.104
app.usercentrics.eu
35.190.14.188
pacman-content-live.live.eks.hotjar.com
54.73.193.221
fp2e7a.wpc.phicdn.net
192.229.221.95
pacman-metrics-live.live.eks.hotjar.com
52.18.77.11
adobetarget.data.adobedc.net
66.235.152.225
scontent.xx.fbcdn.net
157.240.253.1
aggregator.service.usercentrics.eu
34.120.28.121
code.jquery.com
151.101.2.137
script.hotjar.com
13.32.27.19
uct.service.usercentrics.eu
34.95.108.180
consent-api.service.consent.usercentrics.eu
35.201.111.240
pro.ip-api.com
51.77.64.70
dufry-mkt-prod1-yruh3-1226087420.eu-west-1.elb.amazonaws.com
34.251.58.245
www.google.com
142.250.184.228
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
18.202.39.134
wsky-live.live.eks.hotjar.com
34.241.237.157
static-cdn.hotjar.com
18.66.102.53
02179918.akstat.io
unknown
8-46-123-33_s-2-16-241-7_ts-1727821485-clienttons-s.akamaihd.net
unknown
dufryinternationalag.tt.omtrdc.net
unknown
s.go-mpulse.net
unknown
baxhwiiccjaayzx4o3oq-f-4803cc3e6-clientnsv4-s.akamaihd.net
unknown
baxhwiiccjaayzx4o3ea-f-971c8c62d-clientnsv4-s.akamaihd.net
unknown
sso.clubavolta.com
unknown
cm.everesttech.net
unknown
684dd331.akstat.io
unknown
static.hotjar.com
unknown
trial-eum-clientnsv4-s.akamaihd.net
unknown
dpm.demdex.net
unknown
ws.hotjar.com
unknown
t1.global.clubavolta.com
unknown
www.facebook.com
unknown
684dd32f.akstat.io
unknown
metrics.hotjar.io
unknown
assets.adobedtm.com
unknown
baxhwiiccn7jgzx4o3dq-pisd5y-7124b882c-clientnsv4-s.akamaihd.net
unknown
trial-eum-clienttons-s.akamaihd.net
unknown
02179912.akstat.io
unknown
connect.facebook.net
unknown
content.hotjar.io
unknown
8-46-123-33_s-2-16-241-7_ts-1727821511-clienttons-s.akamaihd.net
unknown
www.clubavolta.com
unknown
baxhwiiccn7jgzx4o2wq-pzijs8-dbb6038f8-clientnsv4-s.akamaihd.net
unknown
c.go-mpulse.net
unknown
dufry.demdex.net
unknown
There are 38 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
18.66.102.53
static-cdn.hotjar.com
United States
18.66.102.11
unknown
United States
52.18.77.11
pacman-metrics-live.live.eks.hotjar.com
United States
13.32.27.19
script.hotjar.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
66.235.152.225
adobetarget.data.adobedc.net
United States
34.251.154.115
unknown
United States
51.77.64.70
pro.ip-api.com
France
34.241.237.157
wsky-live.live.eks.hotjar.com
United States
52.210.250.156
unknown
United States
142.250.184.228
www.google.com
United States
34.120.28.121
aggregator.service.usercentrics.eu
United States
18.202.39.134
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
United States
34.95.108.180
uct.service.usercentrics.eu
United States
157.240.0.35
unknown
United States
52.215.101.83
unknown
United States
35.190.14.188
app.usercentrics.eu
United States
239.255.255.250
unknown
Reserved
66.235.152.156
unknown
United States
157.240.253.35
star-mini.c10r.facebook.com
United States
35.201.111.240
consent-api.service.consent.usercentrics.eu
United States
18.66.102.51
unknown
United States
172.67.180.104
flagcdn.com
United States
18.66.102.106
unknown
United States
54.73.193.221
pacman-content-live.live.eks.hotjar.com
United States
35.241.3.184
api.usercentrics.eu
United States
151.101.194.137
unknown
United States
18.202.150.204
unknown
United States
157.240.252.35
unknown
United States
13.32.27.21
unknown
United States
34.251.58.245
dufry-mkt-prod1-yruh3-1226087420.eu-west-1.elb.amazonaws.com
United States
51.195.5.58
unknown
France
151.101.2.137
code.jquery.com
United States
18.202.109.49
unknown
United States
157.240.253.1
scontent.xx.fbcdn.net
United States
There are 26 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.clubavolta.com/about-club-avolta/members-save-more?utm_source=newsletter&utm_medium=email&utm_campaign=RED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX&utm_term=d7105a5f-4617-ef11-9f89-000d3a22cea1
https://www.clubavolta.com/about-club-avolta/members-save-more?utm_source=newsletter&utm_medium=email&utm_campaign=RED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX&utm_term=d7105a5f-4617-ef11-9f89-000d3a22cea1
https://www.clubavolta.com/about-club-avolta/members-save-more?utm_source=newsletter&utm_medium=email&utm_campaign=RED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX&utm_term=d7105a5f-4617-ef11-9f89-000d3a22cea1
https://www.clubavolta.com/about-club-avolta/members-save-more?utm_source=newsletter&utm_medium=email&utm_campaign=RED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX&utm_term=d7105a5f-4617-ef11-9f89-000d3a22cea1
https://www.clubavolta.com/about-club-avolta/members-save-more?utm_source=newsletter&utm_medium=email&utm_campaign=RED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX&utm_term=d7105a5f-4617-ef11-9f89-000d3a22cea1
https://www.clubavolta.com/about-club-avolta/members-save-more?utm_source=newsletter&utm_medium=email&utm_campaign=RED_GL_LoyaltyLaunchSolus-NOCOM-ALL-01102024-1_XX&utm_term=d7105a5f-4617-ef11-9f89-000d3a22cea1
https://sso.clubavolta.com/register?source=ctOnline-scAvolta_website&lang=en
https://sso.clubavolta.com/register?source=ctOnline-scAvolta_website&lang=en
https://www.clubavolta.com/about-club-avolta
https://www.clubavolta.com/about-club-avolta
https://www.clubavolta.com/about-club-avolta
https://www.clubavolta.com/
https://www.clubavolta.com/
https://www.clubavolta.com/our-partners/hotels
https://www.clubavolta.com/our-partners/hotels
https://www.clubavolta.com/our-partners/lounges
https://www.clubavolta.com/our-partners/lounges
There are 7 hidden doms, click here to show them.