Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1008761586\Google.Widevine.CDM.dll
|
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1008761586\_metadata\verified_contents.json
|
JSON data
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1008761586\manifest.fingerprint
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1008761586\manifest.json
|
JSON data
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1405382660\LICENSE
|
ASCII text
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1405382660\_metadata\verified_contents.json
|
JSON data
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1405382660\manifest.fingerprint
|
ASCII text, with no line terminators
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1405382660\manifest.json
|
JSON data
|
dropped
|
||
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6316_1405382660\sets.json
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 156
|
ASCII text, with very long lines (5162), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 157
|
PNG image data, 432 x 200, 8-bit colormap, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 158
|
Web Open Font Format (Version 2), TrueType, length 22180, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 159
|
ASCII text, with very long lines (3139)
|
downloaded
|
||
Chrome Cache Entry: 160
|
Unicode text, UTF-8 text, with very long lines (1738)
|
dropped
|
||
Chrome Cache Entry: 161
|
ASCII text, with very long lines (2287)
|
downloaded
|
||
Chrome Cache Entry: 166
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 168
|
ASCII text, with very long lines (6413)
|
downloaded
|
||
Chrome Cache Entry: 169
|
ASCII text, with very long lines (2134)
|
dropped
|
||
Chrome Cache Entry: 170
|
ASCII text, with very long lines (1572)
|
downloaded
|
||
Chrome Cache Entry: 171
|
ASCII text, with very long lines (65531)
|
downloaded
|
||
Chrome Cache Entry: 173
|
ASCII text, with very long lines (1302)
|
downloaded
|
||
Chrome Cache Entry: 174
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 175
|
PNG image data, 2445 x 200, 8-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 176
|
Web Open Font Format (Version 2), TrueType, length 46156, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 177
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 178
|
ASCII text, with very long lines (9068)
|
downloaded
|
||
Chrome Cache Entry: 179
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 180
|
HTML document, ASCII text, with very long lines (65194)
|
downloaded
|
||
Chrome Cache Entry: 181
|
ASCII text, with very long lines (65531)
|
downloaded
|
||
Chrome Cache Entry: 183
|
Web Open Font Format (Version 2), TrueType, length 15996, version 1.0
|
downloaded
|
There are 22 hidden files, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://https:/click.mailchimp.com/track/click/30010842/docsend.com?p=eyJzIjoiT2RaN0hwNHlyY2E3VXl5TWcwMlA2eFpHVlN3IiwidiI6MSwicCI6IntcInVcIjozMDAxMDg0MixcInZcIjoxLFwidXJsXCI6XCJodHRwczpcXFwvXFxcL2RvY3NlbmQuY29tXFxcL3ZpZXdcXFwvZzZnYzZjazdtNHlkYTRpa1wiLFwiaWRcIjpcImNhZDg3NzI1Y2UzMjRiMzI4Yzk1ZGVkYWUyMzc4ZTZjXCIsXCJ1cmxfaWRzXCI6W1wiYzE5ZWU5NGJiMzA5YmZhOGQ2MDU3OGI1Mjk5NTFmOWE4NDQ0ODNhYVwiXX0ifQ*steven.davis@tu.edu
|
|||
chrome://newtab/
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
google.com
|
172.217.18.14
|
||
plus.l.google.com
|
216.58.206.78
|
||
play.google.com
|
142.250.186.142
|
||
www.google.com
|
142.250.185.132
|
||
apis.google.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
142.250.186.68
|
unknown
|
United States
|
||
142.250.186.67
|
unknown
|
United States
|
||
142.250.186.78
|
unknown
|
United States
|
||
34.104.35.123
|
unknown
|
United States
|
||
1.1.1.1
|
unknown
|
Australia
|
||
142.250.186.170
|
unknown
|
United States
|
||
142.250.186.163
|
unknown
|
United States
|
||
216.58.206.78
|
plus.l.google.com
|
United States
|
||
192.168.2.16
|
unknown
|
unknown
|
||
142.250.185.234
|
unknown
|
United States
|
||
142.250.185.132
|
www.google.com
|
United States
|
||
8.8.8.8
|
unknown
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
142.250.185.195
|
unknown
|
United States
|
||
142.250.186.142
|
play.google.com
|
United States
|
||
142.250.186.164
|
unknown
|
United States
|
||
172.217.18.10
|
unknown
|
United States
|
||
142.250.186.74
|
unknown
|
United States
|
||
142.250.186.99
|
unknown
|
United States
|
||
66.102.1.84
|
unknown
|
United States
|
There are 10 hidden IPs, click here to show them.