Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Chrome Cache Entry: 47
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 48
|
PNG image data, 1500 x 600, 8-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 49
|
PNG image data, 290 x 68, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 50
|
PNG image data, 290 x 68, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 51
|
HTML document, ASCII text, with very long lines (14131)
|
downloaded
|
||
Chrome Cache Entry: 52
|
ASCII text, with very long lines (1932)
|
dropped
|
||
Chrome Cache Entry: 53
|
HTML document, ASCII text, with very long lines (7758)
|
downloaded
|
||
Chrome Cache Entry: 54
|
ASCII text, with very long lines (1932)
|
downloaded
|
||
Chrome Cache Entry: 55
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 56
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 57
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 58
|
ASCII text, with very long lines (1932)
|
downloaded
|
||
Chrome Cache Entry: 59
|
ASCII text, with very long lines (1932)
|
dropped
|
||
Chrome Cache Entry: 60
|
PNG image data, 1500 x 600, 8-bit colormap, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 61
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 62
|
ASCII text, with very long lines (400), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 63
|
ASCII text, with very long lines (400), with no line terminators
|
dropped
|
There are 8 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2244,i,8099980794678803507,1081557334116841257,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.vpn2.ottawamedicalcenter.com/"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://www.vpn2.ottawamedicalcenter.com/
|
|||
https://www.google.com/adsense/domains/caf.js?abp=1&adsdeli=true
|
142.250.186.164
|
||
https://www.vpn2.ottawamedicalcenter.com/favicon.ico
|
75.2.115.196
|
||
https://www.vpn2.ottawamedicalcenter.com/track.php?domain=ottawamedicalcenter.com&toggle=browserjs&uid=MTcyOTgwODQ3Ni42MDkxOjU4MTYxMTJlMmMwNmU1MjdiMzZmNGZhYWI0N2EyZTIxNjZlYzgxZjQyYWMyYzA1YWMxMzYyMjhjNGMxN2FkNzE6NjcxYWM4NWM5NGIzYw%3D%3D
|
75.2.115.196
|
||
https://www.dynadot.com
|
unknown
|
||
https://syndicatedsearch.goog/afs/gen_204?client=dp-teaminternet09_3ph&output=uds_ads_only&zx=yntkqt9w4p74&aqid=YMgaZ9uGN_vejuwPkfX14Qc&psid=7840396037&pbt=bv&adbx=375&adby=178&adbh=496&adbw=530&adbah=160%2C160%2C160&adbn=master-1&eawp=partner-dp-teaminternet09_3ph&errv=688160506&csala=7%7C0%7C1825%7C2203%7C1051&lle=0&ifv=1&hpt=1
|
142.250.185.206
|
||
https://syndicatedsearch.goog
|
unknown
|
||
https://syndicatedsearch.goog/adsense/domains/caf.js?pac=0
|
142.250.185.110
|
||
https://syndicatedsearch.goog/afs/gen_204?client=dp-teaminternet09_3ph&output=uds_ads_only&zx=o91tjeezeync&aqid=YMgaZ9uGN_vejuwPkfX14Qc&psid=7840396037&pbt=bs&adbx=375&adby=178&adbh=496&adbw=530&adbah=160%2C160%2C160&adbn=master-1&eawp=partner-dp-teaminternet09_3ph&errv=688160506&csala=7%7C0%7C1825%7C2203%7C1051&lle=0&ifv=1&hpt=1
|
142.250.185.206
|
||
https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/search.svg?c=%23ffffff
|
172.217.23.97
|
||
https://www.vpn2.ottawamedicalcenter.com/track.php?domain=ottawamedicalcenter.com&caf=1&toggle=answercheck&answer=yes&uid=MTcyOTgwODQ3Ni42MDkxOjU4MTYxMTJlMmMwNmU1MjdiMzZmNGZhYWI0N2EyZTIxNjZlYzgxZjQyYWMyYzA1YWMxMzYyMjhjNGMxN2FkNzE6NjcxYWM4NWM5NGIzYw%3D%3D
|
75.2.115.196
|
||
https://d38psrni17bvxu.cloudfront.net/themes/cleanPeppermintBlack_657d9013/img/arrows.png
|
18.66.121.190
|
||
https://www.vpn2.ottawamedicalcenter.com/ls.php?t=671ac85c&token=4bf7ea6c231ce8a041130a66167be7a8c6b7287d
|
75.2.115.196
|
||
https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/chevron.svg?c=%23ffffff
|
172.217.23.97
|
||
https://www.dynadot.com/tr/mainsite2023/navbar-logo-dark-2023.png
|
104.16.152.132
|
||
https://www.vpn2.ottawamedicalcenter.com/
|
|||
https://www.google.com/pagead/1p-conversion/16521530460/?gad_source=1&adview_type=5
|
unknown
|
There are 6 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
www.vpn2.ottawamedicalcenter.com
|
75.2.115.196
|
||
syndicatedsearch.goog
|
142.250.185.206
|
||
s-part-0017.t-0009.t-msedge.net
|
13.107.246.45
|
||
www.google.com
|
142.250.186.164
|
||
googlehosted.l.googleusercontent.com
|
172.217.23.97
|
||
d38psrni17bvxu.cloudfront.net
|
18.66.121.190
|
||
s-part-0032.t-0009.t-msedge.net
|
13.107.246.60
|
||
www.dynadot.com
|
104.16.152.132
|
||
afs.googleusercontent.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
142.250.185.206
|
syndicatedsearch.goog
|
United States
|
||
142.250.185.110
|
unknown
|
United States
|
||
192.168.2.4
|
unknown
|
unknown
|
||
75.2.115.196
|
www.vpn2.ottawamedicalcenter.com
|
United States
|
||
172.217.23.97
|
googlehosted.l.googleusercontent.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
18.66.121.190
|
d38psrni17bvxu.cloudfront.net
|
United States
|
||
192.168.2.14
|
unknown
|
unknown
|
||
142.250.186.164
|
www.google.com
|
United States
|
||
142.250.186.100
|
unknown
|
United States
|
||
142.250.184.206
|
unknown
|
United States
|
||
104.16.152.132
|
www.dynadot.com
|
United States
|
||
142.250.186.65
|
unknown
|
United States
|
There are 3 hidden IPs, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://www.vpn2.ottawamedicalcenter.com/
|
||
https://www.vpn2.ottawamedicalcenter.com/
|
||
https://www.vpn2.ottawamedicalcenter.com/
|
||
https://www.vpn2.ottawamedicalcenter.com/
|
||
https://www.vpn2.ottawamedicalcenter.com/
|
||
https://www.vpn2.ottawamedicalcenter.com/
|