IOC Report
https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pss

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 63
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 64
HTML document, ASCII text
downloaded
Chrome Cache Entry: 65
ASCII text, with very long lines (8127)
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (42526)
downloaded
Chrome Cache Entry: 67
PNG image data, 83 x 22, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 68
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 69
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 1440x1018, components 3
dropped
Chrome Cache Entry: 70
ASCII text, with very long lines (65462)
downloaded
Chrome Cache Entry: 71
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 72
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 73
ASCII text, with very long lines (7043), with no line terminators
downloaded
Chrome Cache Entry: 74
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 75
PNG image data, 136 x 136, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 76
HTML document, ASCII text, with very long lines (3999), with no line terminators
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (4962)
downloaded
Chrome Cache Entry: 78
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 79
JSON data
dropped
Chrome Cache Entry: 80
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 81
PNG image data, 83 x 22, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 82
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 83
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 84
PNG image data, 136 x 136, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 85
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 86
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 87
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 88
ASCII text, with very long lines (33677)
downloaded
Chrome Cache Entry: 89
JSON data
downloaded
Chrome Cache Entry: 90
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (6557)
downloaded
Chrome Cache Entry: 92
HTML document, ASCII text, with very long lines (4020)
downloaded
Chrome Cache Entry: 93
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 1440x1018, components 3
downloaded
Chrome Cache Entry: 94
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
There are 23 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2124,i,15610489227219973770,6492909471332572734,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pss"

URLs

Name
IP
Malicious
https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pss
malicious
https://gth.miconlinestickbu.store/6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f75fLOG6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f760#
malicious
https://gth.miconlinestickbu.store/
malicious
https://gth.miconlinestickbu.store/6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f75fLOG6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f760
malicious
https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pss
malicious
https://gth.miconlinestickbu.store/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=887db9822f538c41
104.21.21.44
https://gth.miconlinestickbu.store/cdn-cgi/challenge-platform/h/b/flow/ov1/364841505:1716387000:8tvraBwrX2ERNb1OqE2uDzGzv0lTgOfSzC-a3cgAOkk/887db9822f538c41/18215035ea345db
104.21.21.44
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=887db996294478e1
104.17.2.184
https://getbootstrap.com/)
unknown
https://gth.miconlinestickbu.store/boot/617b5a702a34daddd03071650f95cbe6664e0aa35f139
104.21.21.44
https://gth.miconlinestickbu.store/1
104.21.21.44
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1564193166:1716387281:lZ0loq2aY3ZcNtXwgsQeLDV2LUjFlVl_FzsscFgqUA0/887db996294478e1/e2c69a9cf6a5b67
104.17.2.184
https://vakspecialisten.store/noki/x-cp-Ruytfvb6hnx.php
172.67.146.167
https://gth.miconlinestickbu.store/jq/617b5a702a34daddd03071650f95cbe6664e0aa35f135
104.21.21.44
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/887db996294478e1/1716390545215/fdcd7d549205ee077dcead15de05e39851605c03eb2db3a456277fbb95e594a1/I2uC-N-gD_nQrj8
104.17.2.184
https://gth.miconlinestickbu.store/ASSETS/img/sig-op.svg
104.21.21.44
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://gth.miconlinestickbu.store/js/617b5a702a34daddd03071650f95cbe6664e0aa35f13a
104.21.21.44
https://gth.miconlinestickbu.store/favicon.ico
104.21.21.44
https://a.nel.cloudflare.com/report/v4?s=qVRIKX92qaRfJ6gaBUntmAPdh1Gwu3PvCRc3bNwsPhnTsilQ5DZU4Um%2B7FhcPbmw5rS%2FuybWvO1YxIIbCiiaJDTmsIr9eqHJy%2FRBl67sy9FO5QyJv%2Bk9%2FbuWnA4%2BsCQk4oY9veVPX4QDP0cfbw%3D%3D
35.190.80.1
https://a.nel.cloudflare.com/report/v4?s=CrtbplJ7Ts50Ffwf6vozefv3cO5hcbSp1dY35h%2B1vnVp8C%2BTOBbW0Hu3WR10kmnw3cxMfskrN3XrfVP91I%2FAsF97vlawby2SsmBs8QbOgeKWURONYgE%2BZDfEhjfU5xxw4ZAg0%2FV9VVJipSh0rg%3D%3D
35.190.80.1
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/887db996294478e1/1716390545214/yhIQ4Kim04yJILu
104.17.2.184
https://gth.miconlinestickbu.store/ASSETS/img/m_.svg
104.21.21.44
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.2.184
https://gth.miconlinestickbu.store/o/617b5a702a34daddd03071650f95cbe6664e0aa557579
104.21.21.44
https://a.nel.cloudflare.com/report/v4?s=0IwYs16BqjdC9UTsglWvKBt1Ntc568lsx9VkFcXyxBxndNRCRQhgf9nhelPmj764DdU0LaKE2Vk0WDve7hL6KRFFs9X9xEmplyk1PBZNDyDoxKbI5hNUkpBA%2BhKbk2LZQH9kJA6jtQtpNY1gyg%3D%3D
35.190.80.1
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://gth.miconlinestickbu.store/x/617b5a702a34daddd03071650f95cbe6664e0aa557460
104.21.21.44
https://gth.miconlinestickbu.store/APP-617b5a702a34daddd03071650f95cbe6664e0aa557459/617b5a702a34daddd03071650f95cbe6664e0aa55745b
104.21.21.44
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/9c7p6/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
There are 19 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gth.miconlinestickbu.store
104.21.21.44
malicious
a.nel.cloudflare.com
35.190.80.1
challenges.cloudflare.com
104.17.3.184
www.google.com
142.250.185.132
vakspecialisten.store
172.67.146.167
fp2e7a.wpc.phicdn.net
192.229.221.95
windowsupdatebg.s.llnwi.net
87.248.205.0
url12.mailanyone.net
unknown

IPs

IP
Domain
Country
Malicious
104.21.21.44
gth.miconlinestickbu.store
United States
malicious
172.67.146.167
vakspecialisten.store
United States
142.250.185.132
www.google.com
United States
192.168.2.4
unknown
unknown
104.17.3.184
challenges.cloudflare.com
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States
104.17.2.184
unknown
United States

DOM / HTML

URL
Malicious
https://gth.miconlinestickbu.store/6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f75fLOG6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f760
malicious
https://gth.miconlinestickbu.store/6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f75fLOG6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f760#
malicious
https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pss
https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pss
https://url12.mailanyone.net/scanner?m=1s9N28-0000qa-3G&d=4%7Cmail%2F90%2F1716288000%2F1s9N28-0000qa-3G%7Cin12d%7C57e1b682%7C11949542%7C14589158%7C664C7BD820EF00EA9CDA64C5861AF4A9&o=%2Fphta%3A%2Fvtslekssiaipcr.te%2Ftoenscino-x-pk%2F6tRunvbhyfphp.x&s=qPX4ToIpiLV6GTYf9V69nGT5pss
https://gth.miconlinestickbu.store/
https://gth.miconlinestickbu.store/
https://gth.miconlinestickbu.store/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/9c7p6/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/9c7p6/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://gth.miconlinestickbu.store/6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f75fLOG6fc27ea7f3db2fd9787a0f6b674d5bc4664e0aa26f760
There are 1 hidden doms, click here to show them.