Browser Forensics - Cryptominer
2# C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Preferences
$ cat Preferences | jq
"theme": {
"id": "iiihlpikmpijdopbaegjibndhpgjmjfe",
"pack": "C:\\Users\\IEUser\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\iiihlpikmpijdopbaegjibndhpgjmjfe\\1.6_0"
},
# C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\iiihlpikmpijdopbaegjibndhpgjmjfe\1.6_0\manifest.json
$ cat manifest.json
{
"app": {
"launch": {
"web_url": "http://atavi.com/browser-themes/?from=chrome-themes&tid=earth_in_space"
},
"urls": [ "http://atavi.com/browser-themes/" ]
},
"default_locale": "ru",
# google it http://atavi.com/browser-themes/?from=chrome-themes&tid=earth_in_space
earth in spaceLast updated