Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\Downloads\Jahresbericht STaR 2024.zip (copy)
|
Zip archive data, at least v2.0 to extract, compression method=store
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\0f3a824d-4b83-49e5-a15a-33b04ec83496.tmp
|
JSON data
|
modified
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
|
Certificate, Version=3
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
|
Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks,
0x1 compression
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt23.lst (copy)
|
PostScript document text
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt23.lst.5600
|
PostScript document text
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst (copy)
|
PostScript document text
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AcroFnt23.lst (copy)
|
PostScript document text
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AdobeFnt23.lst.5600
|
PostScript document text
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\Edit_InApp_Aug2020
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents
|
SQLite 3.x database, last written using SQLite version 3040000, file counter 25, database pages 3, cookie 0x2, schema 4, UTF-8,
version-valid-for 25
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
|
SQLite Rollback Journal
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\MSI95ebb.LOG
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-16 07-15-59-971.log
|
ASCII text, with very long lines (393)
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
|
ASCII text, with very long lines (393), with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\1c1f3e00-ce3b-4b24-9e60-1b3c1559356a.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 42290
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\4823d41b-a8a5-4bfb-9ff0-ec05c215adf0.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\bdb284c2-a817-4060-adaa-b96861122e39.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\cd236f46-f305-44cd-a246-884e53a8a26f.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx\Jahresbericht STaR 2024\Jahresbericht_STaR_2024.pdf
|
PDF document, version 1.7, 14 pages
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\unarchiver.log
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:20 2025, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:19 2025, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:00:51 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:19 2025, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:20 2025, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Jan 16 11:15:19 2025, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\Downloads\Jahresbericht STaR 2024.zip.crdownload
|
Zip archive data, at least v2.0 to extract, compression method=store
|
dropped
|
||
C:\Users\user\Downloads\d3351d08-a7d6-413e-bd9d-1de38f99d3d9.tmp
|
Zip archive data, at least v2.0 to extract, compression method=store
|
dropped
|
||
Chrome Cache Entry: 217
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 218
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1920x1080,
components 3
|
downloaded
|
||
Chrome Cache Entry: 219
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 220
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 221
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 222
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 223
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 224
|
ASCII text, with very long lines (415)
|
downloaded
|
||
Chrome Cache Entry: 225
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 226
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 227
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 228
|
ASCII text, with very long lines (23584)
|
downloaded
|
||
Chrome Cache Entry: 229
|
Unicode text, UTF-8 text, with very long lines (65435)
|
dropped
|
||
Chrome Cache Entry: 230
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 231
|
ASCII text, with very long lines (788)
|
dropped
|
||
Chrome Cache Entry: 232
|
ASCII text, with very long lines (10457)
|
downloaded
|
||
Chrome Cache Entry: 233
|
ASCII text, with very long lines (3930)
|
downloaded
|
||
Chrome Cache Entry: 234
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 235
|
Unicode text, UTF-8 text, with very long lines (65429)
|
dropped
|
||
Chrome Cache Entry: 236
|
Zip archive data, at least v2.0 to extract, compression method=store
|
downloaded
|
||
Chrome Cache Entry: 237
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 238
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 239
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 240
|
Unicode text, UTF-8 text, with very long lines (65460)
|
dropped
|
||
Chrome Cache Entry: 241
|
ASCII text, with very long lines (47219), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 242
|
ASCII text, with very long lines (10457)
|
dropped
|
||
Chrome Cache Entry: 243
|
ASCII text, with very long lines (12211)
|
downloaded
|
||
Chrome Cache Entry: 244
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 245
|
ASCII text, with very long lines (23584)
|
dropped
|
||
Chrome Cache Entry: 246
|
ASCII text, with very long lines (65467), with escape sequences
|
dropped
|
||
Chrome Cache Entry: 247
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 248
|
HTML document, ASCII text, with very long lines (451)
|
dropped
|
||
Chrome Cache Entry: 249
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 250
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 251
|
Unicode text, UTF-8 text, with very long lines (65459)
|
dropped
|
||
Chrome Cache Entry: 252
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 253
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 254
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 255
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 256
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 257
|
ASCII text, with very long lines (65467), with escape sequences
|
downloaded
|
||
Chrome Cache Entry: 258
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 259
|
ASCII text, with very long lines (2628)
|
downloaded
|
||
Chrome Cache Entry: 260
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 261
|
CSV text
|
downloaded
|
||
Chrome Cache Entry: 262
|
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 1920x1080,
components 3
|
dropped
|
||
Chrome Cache Entry: 263
|
Unicode text, UTF-8 text, with very long lines (56828)
|
dropped
|
||
Chrome Cache Entry: 264
|
ASCII text, with very long lines (47219), with CRLF line terminators
|
dropped
|
||
Chrome Cache Entry: 265
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 266
|
Web Open Font Format, TrueType, length 67164, version 0.0
|
downloaded
|
||
Chrome Cache Entry: 267
|
ASCII text, with very long lines (307)
|
dropped
|
||
Chrome Cache Entry: 268
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 269
|
Unicode text, UTF-8 text, with very long lines (65459)
|
dropped
|
||
Chrome Cache Entry: 270
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 271
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 272
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 273
|
CSV text
|
dropped
|
||
Chrome Cache Entry: 274
|
ASCII text, with very long lines (788)
|
downloaded
|
||
Chrome Cache Entry: 275
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 276
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 277
|
ASCII text, with very long lines (32553)
|
downloaded
|
||
Chrome Cache Entry: 278
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 279
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 280
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 281
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 282
|
Unicode text, UTF-8 text, with very long lines (65460)
|
downloaded
|
||
Chrome Cache Entry: 283
|
ASCII text, with very long lines (65460)
|
dropped
|
||
Chrome Cache Entry: 284
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 285
|
HTML document, ASCII text, with very long lines (451)
|
downloaded
|
||
Chrome Cache Entry: 286
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 287
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 288
|
ASCII text, with very long lines (307)
|
downloaded
|
||
Chrome Cache Entry: 289
|
CSV text
|
downloaded
|
||
Chrome Cache Entry: 290
|
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 291
|
ASCII text, with very long lines (301)
|
downloaded
|
||
Chrome Cache Entry: 292
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 293
|
Unicode text, UTF-8 text, with very long lines (65459)
|
downloaded
|
||
Chrome Cache Entry: 294
|
ASCII text, with very long lines (12211)
|
dropped
|
||
Chrome Cache Entry: 295
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 296
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 297
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 298
|
ASCII text, with very long lines (65460)
|
downloaded
|
||
Chrome Cache Entry: 299
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 300
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 301
|
ASCII text, with very long lines (65455)
|
downloaded
|
||
Chrome Cache Entry: 302
|
Unicode text, UTF-8 text
|
dropped
|
||
Chrome Cache Entry: 303
|
Unicode text, UTF-8 text, with very long lines (65429)
|
downloaded
|
||
Chrome Cache Entry: 304
|
ASCII text, with very long lines (686)
|
dropped
|
||
Chrome Cache Entry: 305
|
ASCII text, with very long lines (495)
|
downloaded
|
||
Chrome Cache Entry: 306
|
ASCII text, with very long lines (686)
|
downloaded
|
||
Chrome Cache Entry: 307
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 308
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 309
|
Unicode text, UTF-8 text
|
downloaded
|
||
Chrome Cache Entry: 310
|
Unicode text, UTF-8 text, with very long lines (65435)
|
downloaded
|
||
Chrome Cache Entry: 311
|
Unicode text, UTF-8 text, with very long lines (65457)
|
downloaded
|
||
Chrome Cache Entry: 312
|
ASCII text, with very long lines (415)
|
dropped
|
||
Chrome Cache Entry: 313
|
Web Open Font Format, TrueType, length 66432, version 0.0
|
downloaded
|
||
Chrome Cache Entry: 314
|
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 315
|
Unicode text, UTF-8 text, with very long lines (65457)
|
dropped
|
||
Chrome Cache Entry: 316
|
Web Open Font Format, TrueType, length 66600, version 0.0
|
downloaded
|
||
Chrome Cache Entry: 317
|
ASCII text, with very long lines (301)
|
dropped
|
||
Chrome Cache Entry: 318
|
ASCII text, with very long lines (6362)
|
downloaded
|
||
Chrome Cache Entry: 319
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 320
|
Unicode text, UTF-8 text, with very long lines (65465)
|
downloaded
|
||
Chrome Cache Entry: 321
|
CSV text
|
dropped
|
||
Chrome Cache Entry: 322
|
Unicode text, UTF-8 text, with very long lines (56828)
|
downloaded
|
||
Chrome Cache Entry: 323
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 324
|
Unicode text, UTF-8 text, with very long lines (65459)
|
downloaded
|
||
Chrome Cache Entry: 325
|
ASCII text
|
dropped
|
||
Chrome Cache Entry: 326
|
ASCII text, with very long lines (1612)
|
downloaded
|
||
Chrome Cache Entry: 327
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 328
|
ASCII text, with very long lines (65467)
|
downloaded
|
||
Chrome Cache Entry: 329
|
ASCII text, with very long lines (495)
|
dropped
|
There are 162 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=1928,i,1694561867751154417,9935033051105612894,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://magentacloud.de/s/2bMe7TmEWH89MxG"
|
||
C:\Windows\SysWOW64\unarchiver.exe
|
"C:\Windows\SysWOW64\unarchiver.exe" "C:\Users\user\Downloads\Jahresbericht STaR 2024.zip"
|
||
C:\Windows\SysWOW64\7za.exe
|
"C:\Windows\System32\7za.exe" x -pinfected -y -o"C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx" "C:\Users\user\Downloads\Jahresbericht
STaR 2024.zip"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\SysWOW64\cmd.exe
|
"cmd.exe" /C "C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx\Jahresbericht STaR 2024\Jahresbericht_STaR_2024.pdf"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
|
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\AppData\Local\Temp\j43hmrmm.3cx\Jahresbericht STaR
2024\Jahresbericht_STaR_2024.pdf"
|
||
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
|
"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
|
||
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
|
"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService
--lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0"
--lang=en-US --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2132
--field-trial-handle=1652,i,6175875331327655432,3573518054454937670,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker
/prefetch:8
|
There are 1 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://magentacloud.de/s/2bMe7TmEWH89MxG
|
|||
https://app.transifex.com/nextcloud/teams/64236/nb_NO/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/pt_BR/)
|
unknown
|
||
https://tags-eu.tiqcdn.com/utag/telekom/mediencenter/prod/utag.js?nmcv=41
|
23.201.253.231
|
||
https://magentacloud.de/apps/files/js/fileactions.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/zh_TW/)
|
unknown
|
||
https://magentacloud.de/apps/files_sharing/js/public.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/viewer/js/viewer-main.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/files/js/file-upload.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/ru/)
|
unknown
|
||
https://magentacloud.de/apps/theming/theme/light-magenta.css?plain=1&v=48d94615
|
80.158.6.204
|
||
https://github.com/zloirock/core-js
|
unknown
|
||
https://magentacloud.de/js/core/merged-template-prepend.js?v=541be914-41
|
80.158.6.204
|
||
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/a
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/it/)
|
unknown
|
||
https://magentacloud.de/apps/files/js/semaphore.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/files/js/keyboardshortcuts.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/ja_JP/)
|
unknown
|
||
https://magentacloud.de/core/css/server.css?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/kab/)
|
unknown
|
||
https://consenthub.utiq.com/
|
unknown
|
||
https://www.telekom.de/impressum
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/ka_GE/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/fi_FI/)
|
unknown
|
||
https://magentacloud.de/customapps/nmctheme/js/nmctheme-mimetypes.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/cs_CZ/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/sr/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/sv/)
|
unknown
|
||
https://ebs10.telekom.de/opt-in/icon/utiq.svg
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/fo/)
|
unknown
|
||
https://magentacloud.de/s/2bMe7TmEWH89MxG/download
|
80.158.6.204
|
||
https://magentacloud.de/apps/theming/theme/default.css?plain=1&v=48d94615
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/hr/)
|
unknown
|
||
https://magentacloud.de/apps/files/css/merged.css?v=d233662f-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/gl/)
|
unknown
|
||
https://magentacloud.de/dist/core-public.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/files/js/fileinfomodel.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/files/js/newfilemenu.js?v=541be914-41
|
80.158.6.204
|
||
https://ebs10.telekom.de/opt-in/set.php?consent=
|
unknown
|
||
https://magentacloud.de/customapps/nmctheme/fonts/TeleNeoWeb/TeleNeoWeb-Bold.woff
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/kn/)
|
unknown
|
||
https://magentacloud.de/dist/core-files_fileinfo.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/index.php/apps/nmctheme/lang/core/l10n/en.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/files_pdfviewer/js/files_pdfviewer-public.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/gd/)
|
unknown
|
||
https://magentacloud.de/apps/theming/theme/dark-magenta.css?plain=0&v=48d94615
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/ig/)
|
unknown
|
||
https://consenthub.utiq.com/pages/privacy-statement
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/de_DE/)
|
unknown
|
||
http://stackoverflow.com/a/20448357
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/la/)
|
unknown
|
||
https://github.com/blueimp/jQuery-File-Upload
|
unknown
|
||
https://magentacloud.de/customapps/nmctheme/fonts/TeleNeoWeb/TeleNeoWeb-Regular.woff
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/eo/)
|
unknown
|
||
https://magentacloud.de/customapps/nmctheme/js/nmctheme-nmcheader.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/ps/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/es/)
|
unknown
|
||
https://magentacloud.de/apps/richdocuments/js/richdocuments-reference.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/files_sharing/js/templates.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/s/2bMe7TmEWH89MxG
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/de/)
|
unknown
|
||
https://www.telekom.de/ueber-das-unternehmen/datenschutz#drittland-verarbeitung
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/ta/)
|
unknown
|
||
https://magentacloud.de/index.php/apps/nmctheme/lang/nmctheme/l10n/en.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/nl/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/ur_PK/)
|
unknown
|
||
https://magentacloud.de/index.php/apps/nmctheme/lang/nmcsharing/l10n/en.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/text/js/text-viewer.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/text/js/text-public.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/da/)
|
unknown
|
||
https://blueimp.net
|
unknown
|
||
https://magentacloud.de/apps/files/js/breadcrumb.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/ast/)
|
unknown
|
||
https://magentacloud.de/customapps/nmcsettings/js/nmcsettings-nmcsettings.js?v=541be914-41
|
80.158.6.204
|
||
https://www.telekom.de/ueber-das-unternehmen/datenschutz
|
unknown
|
||
https://static.magentacloud.de/analytics/mc_login_tracking.html
|
unknown
|
||
https://magentacloud.de/dist/icons.css
|
80.158.6.204
|
||
https://magentacloud.de/core/js/public/publicpage.js?v=541be914-41
|
80.158.6.204
|
||
http://www.opensource.org/licenses/MIT
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/sw/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/uz/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/ko/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/mr/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/zh_CN/)
|
unknown
|
||
https://github.com/zloirock/core-js/blob/v3.25.5/LICENSE
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/kk/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/mn/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/sc/)
|
unknown
|
||
https://github.com/zloirock/core-js/blob/v3.37.0/LICENSE
|
unknown
|
||
https://magentacloud.de/customapps/nmcsharing/js/nmcsharing-sharing.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/ga/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/id/)
|
unknown
|
||
https://magentacloud.de/apps/files/js/filemultiselectmenu.js?v=541be914-41
|
80.158.6.204
|
||
https://magentacloud.de/apps/files_sharing/js/public_note.js?v=541be914-41
|
80.158.6.204
|
||
https://app.transifex.com/nextcloud/teams/64236/lb/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/ne/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/ar/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/pl/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/ro/)
|
unknown
|
||
https://app.transifex.com/nextcloud/teams/64236/tr/)
|
unknown
|
||
https://magentacloud.de/dist/core-main.js?v=541be914-41
|
80.158.6.204
|
There are 90 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
e8652.dscx.akamaiedge.net
|
2.23.197.184
|
||
magentacloud.de
|
80.158.6.204
|
||
www.google.com
|
142.250.186.132
|
||
e8091.e3.akamaiedge.net
|
23.201.253.231
|
||
tags-eu.tiqcdn.com
|
unknown
|
||
x1.i.lencr.org
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
80.158.3.186
|
unknown
|
Germany
|
||
192.168.2.8
|
unknown
|
unknown
|
||
23.201.253.231
|
e8091.e3.akamaiedge.net
|
United States
|
||
2.23.197.184
|
e8652.dscx.akamaiedge.net
|
European Union
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
142.250.186.132
|
www.google.com
|
United States
|
||
80.158.6.204
|
magentacloud.de
|
Germany
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
|
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe.FriendlyAppName
|
||
HKEY_CURRENT_USER_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
|
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe.ApplicationCompany
|
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
960000
|
heap
|
page read and write
|
||
4EDD000
|
stack
|
page read and write
|
||
F0E000
|
stack
|
page read and write
|
||
5630000
|
heap
|
page read and write
|
||
2BE0000
|
trusted library allocation
|
page read and write
|
||
587E000
|
stack
|
page read and write
|
||
4CEE000
|
stack
|
page read and write
|
||
DB0000
|
heap
|
page read and write
|
||
ADE000
|
stack
|
page read and write
|
||
2C18000
|
trusted library allocation
|
page read and write
|
||
36DE000
|
stack
|
page read and write
|
||
C62000
|
trusted library allocation
|
page execute and read and write
|
||
4D10000
|
trusted library allocation
|
page execute and read and write
|
||
C40000
|
trusted library allocation
|
page read and write
|
||
59BE000
|
stack
|
page read and write
|
||
3231000
|
heap
|
page read and write
|
||
561D000
|
stack
|
page read and write
|
||
2A20000
|
heap
|
page read and write
|
||
3BB1000
|
trusted library allocation
|
page read and write
|
||
2C10000
|
trusted library allocation
|
page read and write
|
||
3237000
|
heap
|
page read and write
|
||
DC0000
|
heap
|
page read and write
|
||
B1E000
|
heap
|
page read and write
|
||
2BB1000
|
trusted library allocation
|
page read and write
|
||
324F000
|
heap
|
page read and write
|
||
2C0C000
|
trusted library allocation
|
page read and write
|
||
CBE000
|
stack
|
page read and write
|
||
4D00000
|
trusted library allocation
|
page read and write
|
||
515E000
|
stack
|
page read and write
|
||
1088000
|
heap
|
page read and write
|
||
5880000
|
heap
|
page read and write
|
||
33D0000
|
heap
|
page read and write
|
||
2EDC000
|
stack
|
page read and write
|
||
C77000
|
trusted library allocation
|
page execute and read and write
|
||
3405000
|
heap
|
page read and write
|
||
DD0000
|
trusted library allocation
|
page read and write
|
||
323F000
|
heap
|
page read and write
|
||
573E000
|
stack
|
page read and write
|
||
B1B000
|
heap
|
page read and write
|
||
4DDE000
|
stack
|
page read and write
|
||
3400000
|
heap
|
page read and write
|
||
C32000
|
trusted library allocation
|
page execute and read and write
|
||
127F000
|
stack
|
page read and write
|
||
107F000
|
stack
|
page read and write
|
||
D4E000
|
stack
|
page read and write
|
||
325A000
|
heap
|
page read and write
|
||
323F000
|
heap
|
page read and write
|
||
C4C000
|
trusted library allocation
|
page execute and read and write
|
||
2BEC000
|
trusted library allocation
|
page read and write
|
||
8F9000
|
stack
|
page read and write
|
||
8FB000
|
stack
|
page read and write
|
||
CD0000
|
heap
|
page read and write
|
||
2C0A000
|
trusted library allocation
|
page read and write
|
||
3790000
|
heap
|
page read and write
|
||
2FDC000
|
stack
|
page read and write
|
||
D90000
|
heap
|
page read and write
|
||
3340000
|
heap
|
page read and write
|
||
5580000
|
heap
|
page read and write
|
||
B10000
|
heap
|
page read and write
|
||
D00000
|
heap
|
page read and write
|
||
2C1E000
|
trusted library allocation
|
page read and write
|
||
505E000
|
stack
|
page read and write
|
||
323F000
|
heap
|
page read and write
|
||
100E000
|
stack
|
page read and write
|
||
33CD000
|
stack
|
page read and write
|
||
C42000
|
trusted library allocation
|
page execute and read and write
|
||
C7B000
|
trusted library allocation
|
page execute and read and write
|
||
3760000
|
heap
|
page read and write
|
||
980000
|
heap
|
page read and write
|
||
1080000
|
heap
|
page read and write
|
||
4F1E000
|
stack
|
page read and write
|
||
55A0000
|
heap
|
page read and write
|
||
D00000
|
heap
|
page read and write
|
||
950000
|
heap
|
page read and write
|
||
CFD000
|
stack
|
page read and write
|
||
577E000
|
stack
|
page read and write
|
||
2C30000
|
trusted library allocation
|
page read and write
|
||
2B60000
|
heap
|
page read and write
|
||
2C2E000
|
trusted library allocation
|
page read and write
|
||
7F730000
|
trusted library allocation
|
page execute and read and write
|
||
C6A000
|
trusted library allocation
|
page execute and read and write
|
||
2C05000
|
trusted library allocation
|
page read and write
|
||
3770000
|
heap
|
page read and write
|
||
323F000
|
heap
|
page read and write
|
||
2BFF000
|
trusted library allocation
|
page read and write
|
||
99C000
|
stack
|
page read and write
|
||
324F000
|
heap
|
page read and write
|
||
C3A000
|
trusted library allocation
|
page execute and read and write
|
||
3237000
|
heap
|
page read and write
|
||
C20000
|
trusted library allocation
|
page read and write
|
||
8F6000
|
stack
|
page read and write
|
||
5EC000
|
stack
|
page read and write
|
||
3766000
|
heap
|
page read and write
|
||
985000
|
heap
|
page read and write
|
||
338E000
|
unkown
|
page read and write
|
||
1010000
|
heap
|
page read and write
|
||
3234000
|
heap
|
page read and write
|
||
2C13000
|
trusted library allocation
|
page read and write
|
||
B00000
|
heap
|
page execute and read and write
|
||
2C22000
|
trusted library allocation
|
page read and write
|
||
DF0000
|
trusted library allocation
|
page read and write
|
||
323F000
|
heap
|
page read and write
|
||
E0E000
|
stack
|
page read and write
|
||
5ABF000
|
stack
|
page read and write
|
||
D8E000
|
stack
|
page read and write
|
||
2BFA000
|
trusted library allocation
|
page read and write
|
||
4BEE000
|
stack
|
page read and write
|
||
B4E000
|
heap
|
page read and write
|
||
B38000
|
heap
|
page read and write
|
||
2C16000
|
trusted library allocation
|
page read and write
|
||
A9E000
|
stack
|
page read and write
|
||
2B65000
|
heap
|
page read and write
|
||
501D000
|
stack
|
page read and write
|
||
C4A000
|
trusted library allocation
|
page execute and read and write
|
||
35DE000
|
unkown
|
page read and write
|
||
3220000
|
heap
|
page read and write
|
||
10C0000
|
heap
|
page read and write
|
There are 107 hidden memdumps, click here to show them.