Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 18:58:27 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 18:58:27 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 18:58:27 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 18:58:27 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 18:58:27 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 58
|
PNG image data, 272 x 92, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 59
|
PNG image data, 272 x 92, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 60
|
ASCII text, with very long lines (621)
|
dropped
|
||
Chrome Cache Entry: 61
|
ASCII text, with very long lines (4238), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 62
|
ASCII text, with very long lines (621)
|
downloaded
|
There are 2 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=1920,i,18229727737564372191,15849254334998728646,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://Saic.anastaclooverseas.com/zwfgemvfcbcitui/xivyvjldaquzs/Zgktmgjdfgpirwe89g0xmaersk/ixiswwcbzmfgee/jebqtppyunp/random.bby/inpoxqhfiww/gmail.com/ozwunijponqp8"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://Saic.anastaclooverseas.com/zwfgemvfcbcitui/xivyvjldaquzs/Zgktmgjdfgpirwe89g0xmaersk/ixiswwcbzmfgee/jebqtppyunp/random.bby/inpoxqhfiww/gmail.com/ozwunijponqp8
|
|||
https://saic.anastaclooverseas.com/zwfgemvfcbcitui/xivyvjldaquzs/Zgktmgjdfgpirwe89g0xmaersk/ixiswwcbzmfgee/jebqtppyunp/random.bby/inpoxqhfiww/gmail.com/ozwunijponqp8
|
104.21.71.35
|
||
https://lensfrontend-pa.clients6.google.com/v1/crupload
|
unknown
|
||
https://play.google.com/log?format=json&hasfast=true
|
unknown
|
||
https://support.google.com/websearch/answer/106230
|
unknown
|
||
http://www.broofa.com
|
unknown
|
||
https://csp.withgoogle.com/csp/lcreport/
|
unknown
|
||
https://lensfrontend-pa.clients6.google.com/v1/gsessionid
|
unknown
|
||
https://www.google.com/xjs/_/ss/k=xjs.hd.OgBVQ9b8hgU.L.B1.O/am=CKkCAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAIAAAAAAAAAAEGAngUAYAGAXIEAAAAAAAAYAAAAgAAIAAAAAGABUAAAAAAAABACAAgACAAoAAACBUQAAICADgBKABABAACgIAEAAQAAggAwaAlEBiAIAAAAAAAAAEAAAADAEgEAAgA6AADAARAIAIHogAAAAAIAgAICZABgCBiAAAAAAAACADAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAgAKA/d=1/ed=1/br=1/rs=ACT90oFr81bXyZW_m8tv0lZMRLMnWXBrzQ/m=cdos,hsm,jsa,mb4ZUb,cEt90b,SNUn3,qddgKe,sTsDMc,dtl0hd,eHDfl,YV5bee,d,csi
|
142.250.181.100
|
||
https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_272x92dp.png
|
142.250.181.100
|
||
https://www.google.com/log?format=json&hasfast=true
|
unknown
|
||
https://lens.google.com
|
unknown
|
||
https://www.google.com/gen_204?s=webhp&t=cap&atyp=csi&ei=7tZEZ8bNONKE7M8Pnc6z0Q4&rt=wsrt.12880,cbt.374,hst.44&opi=89978449&dt=&ts=300
|
142.250.181.100
|
||
https://www.google.com/
|
142.250.181.100
|
||
https://google.com/
|
142.250.181.142
|
||
https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
|
unknown
|
There are 5 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
google.com
|
142.250.181.142
|
||
saic.anastaclooverseas.com
|
104.21.71.35
|
||
www.google.com
|
142.250.181.100
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
104.21.71.35
|
saic.anastaclooverseas.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
192.168.2.16
|
unknown
|
unknown
|
||
142.250.181.142
|
google.com
|
United States
|
||
142.250.181.100
|
www.google.com
|
United States
|