Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Malicious Chrome extension IDs (Socket report - 108 total)
- $extensionIds = @(
- "aaaljjgdoaocjjjplplfopjpdhbmbfek",
- "aabnnhjefnphbplhgjkddpbnjbcbekgf",
- "aadmacdlmfafhkkddjknacahmklkpeij",
- "aapocclcgogkmnckokdopfmhonfmgoek",
- "abfijhddgjbdeedojgbifkbnkdlhbnnf",
- "abmohcnlldaiaodkpacnldcdnjjgldfh",
- "acmfnomgphggonodopogfbmkneepfgnh",
- "adbbhmdcnljkkfjbbkldfpfkgkoffbnn",
- "adnljgpbkcljlkjckehfklfflccfemdm",
- "aeijljhpnjkgfphgljnddnkkmjjifdnj",
- "afapdghddghjchhkkgncbbdnjflkhepj",
- "afdfpkhbdpioonfeknablodaejkklbdn",
- "afkggdpkhnbjokdkkhphbgjbbjppfjmh",
- "agfddnbnjflbpgkpimnfdedmmdkcckpm",
- "ahkdhfngcbbnjkljflkgnmddndcbbhkm",
- "ajhfjkdbklkflkmjljhgjgkppphkchcc",
- "akbpmfepnbgppjjfbcdfbdfpjpjijngp",
- "aklckgfmhdddfhjkmbkglkcmfbdjdbbd",
- "alfgjmbobkmbhfgfbdfodckapgdcgnhn",
- "amjfjkcepgjfghnmfmjcbfgbpkhnbcdb",
- "anbdfkcgofgdbpdkbghmbdbkkpkgljgl",
- "aogfblgplcldjcbjdcfpgkhlhfjkgnfn",
- "apbkgmdkphjhhckcdeefcokgnbdbbghp",
- "apfpjkbemgkndbdbfkmnklpplbcbkbfd",
- "bbdkkhglcngnbjefejokjkhfjgfgodko",
- "bbpbcnghgncplcfkdbnckokoggnkjhnh",
- "bchdcegkmjnhkcbhjpjpmmjdmhngpjaf",
- "bclmnhpplmmbchcpgfdbpcknppbnddkg",
- "bdhknchfgkhhblhbbbjhlnjibldhdfok",
- "bdlkkghcchkjjpcfegfcbgkmobdkmppp",
- "bffnjdpejgnfcbgjahpbhhbncghblmcc",
- "bfpfgljhlklddcnhnhhfjgkbbjndobob",
- "bggmnjgffcdopbbpccpofbghnkjdclfd",
- "bhhkkfgehpjdppgdcgbjnglkkfpkfngb",
- "bhnddggedppgkpehmbkfgkhjmbbnfbpl",
- "bjepkfcpmffhghppcchhngfbdlpkfjcc",
- "bkflgkhcghcgbbjpddmkljokfghmfbnp",
- "bldfnlkhhajpnhglfhfpgemlmbbgdncd",
- "bmddhmdcdbokdfjepjipgclbghhbbhfd",
- "bnhfgkgnpbhmjflfllkpkjgnjphnppok",
- "bnmbhkmnhdmdhcldbndgpdjplfdfnhpj",
- "bocdmpgfbiafkjplgpkofgdfklddbfdi",
- "bohlnkfhgljhjkhkglmbdlfkpnpmmlfg",
- "bpfnpfnhblnkgjhgjcgjkglfdfkplkcf",
- "bplnkhbknfknkghhdfjpbjjbbgdlodkd",
- "bpmkchjdfnjgkdfkgjhjjgkbjlgkhkmb",
- "bpnhcbcfjbfifgdhgmnkclffgpmjgnap",
- "bppbjaffljgkffjpmjhhgkcmncmkbbhn",
- "ccfkgkhpjbhjgjcgbpnhkmpkcpdfnllb",
- "cdmbfpjnbdnbhkpibbnmjcogkbbkdfbh",
- "ceflkbljghbchdphbnflfkkmnjpjnhmc",
- "cfdhgjpbkchlhfpfkflffklnkpnljnmb",
- "cfkgkkjghmdmdblbhdcibplkjbjhdbaf",
- "cgggkpgmhlbbjnddflgjphdjbppbldfd",
- "chfgdfmnhncfjhdgcbkjgkfhffkdfmbd",
- "cjbdjnnncfngbblhdfghjhpkncgglpgj",
- "ckbggpnfphkdfbjcbjfjhchbbkmbkddh",
- "cljbbkhhfjghnbjpphdfnkkdddkngjpn",
- "clmcfmhplhkjcpldfddffkgkbnfdfmch",
- "cmdbkldkfhjndodfhgkhlbbkddpjhbdg",
- "cmfndfmbjphcgnbjgdbfhkdbpkdpppkk",
- "cnbfhfkghfpncdgkphmddhnhkddjpbob",
- "cnfkjjcfphbgbjhhdfkplkfjghnmbhgg",
- "cpmbkjffgkphdfdjjdfgjkghgfgdmbmk",
- "cpmcdbkbhjkmdbpghgcfahpgjddfmpjp",
- "cpnhhgdfkbhfndpfgdmbfgkdbkkgjbbh",
- "cpplkfdcclmcknmkfmbdnjjndgkkhngh",
- "cptngkfpglgblglbndbdfgkhdbpgfbgh",
- "dbbnkphkglgfpgnbkfnfdfmblkjhbbdj",
- "dbfjkngplppkndjchhdbdpnjfhkpnmnj",
- "dcjljkgnmcckndndjplfgjfdkkdgjdkk",
- "ddbbdfhkjhddpplfgmpfhhjgnmbbgbcf",
- "ddgphffgfljghgddhdkhndddnflpplff",
- "ddkpbjcllbbhdbdpghhmbgnppdfkmbhj",
- "ddmlkhdfkpgkgbmpmjppbmnpghdfgkpp",
- "dfbnmfgkfflghhkflnkmhhkdkpjbnjij",
- "dffjdhhbbmmjflnkhfdblgmpjdfjkkhg",
- "dfkmbhddfgljppffkmpplddphhjmbhij",
- "dfppjmkbngkbkfdjkhplghgkmpdfdgbb",
- "dgfjpbfdlgbhnbnpljpcbbpghgdplfmb",
- "dgkkhhjkklcgnbhbnhlpphkhjnghplpl",
- "dhkngmcckdhdfpbkfjkgbfdjngkkhddp",
- "dhpgbkmfdbfdkhgjbklphgklddkbbhfp",
- "djdbbhhdddfkkpblgclbppbdfmkkbmkh",
- "djgbchkkcglfdbnbhndgpnjmlngljkgn",
- "dkgkpbkdbjdfkgjgjpnddmbjpjhndhfn",
- "dknbnnjgbgdfdfgbnbhglgkghdppppgj",
- "dldnhnkgpbbkphnngpddkgbhplckjhdf",
- "dmbjlpbnngpddpjkblkgdpmjnhdpgkhl",
- "dmdkpgjdfnjgnmbnfdflpkbchjgbffgh",
- "dmgkfdhflhjplngkghnfdnnbkghpkpdb",
- "dmjpnfjlgpmbgkjbplbdbdkdfpgldkcf",
- "dmkpjnhkffgkdfpbfbgbcchgljgjhmbn",
- "dmpnnhcblhngcchkhpbbkbbbpjjjkpdd",
- "dnchhnphngcdgcfpbhhcdgjjjhbbhmbp",
- "dndgkdfkhhghgppkbbnjlgbgjfgkphbf",
- "dngkndgfbdbfdfggdfkpbnhhglklbnhg",
- "dnhgpbkddgjkdfhgnpkkhnbpjjdbpmjp",
- "dnjhggpghbphgjffgnbmbhflplgmpggd",
- "dnjjdfhnbkppgdfhgbppkndmbplghdfn",
- "dnlpkkpjflkpgkdbnhhdbplgjjfjhkkk",
- "dnpdbkkhphkdbjflmbkfgdfghmndjmbd",
- "dnpnphngdfbdfgkhkgggjgpnjddbjppg",
- "dodjbfkpbgnbdfgddplhnghgjpkkmbch",
- "dogpjfjgkfgplgdhjdbdgbgkjfhgkbbn",
- "dolpnnfgghfdfdphgbpljkbmbpbchhfp"
- )
- # Chrome user data path
- $chromeUserData = "$env:LOCALAPPDATA\Google\Chrome\User Data"
- # Get all profiles
- $profiles = Get-ChildItem -Path $chromeUserData -Directory | Where-Object {
- $_.Name -match "Default|Profile"
- }
- $results = @()
- foreach ($profile in $profiles) {
- $extPath = Join-Path $profile.FullName "Extensions"
- if (Test-Path $extPath) {
- $installed = Get-ChildItem -Path $extPath -Directory | Select-Object -ExpandProperty Name
- foreach ($id in $extensionIds) {
- if ($installed -contains $id) {
- $results += [PSCustomObject]@{
- Profile = $profile.Name
- ExtensionId = $id
- }
- }
- }
- }
- }
- if ($results.Count -gt 0) {
- Write-Host "Matches found:`n"
- $results | Format-Table -AutoSize
- } else {
- Write-Host "No matching extensions found."
- }
Advertisement
Add Comment
Please, Sign In to add comment