IOC Report
https://daftar-limit-paylater-24.xcxcx.my.id/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
HTML document, Unicode text, UTF-8 text, with very long lines (304), with CRLF line terminators
downloaded
Chrome Cache Entry: 101
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 103
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 67
PNG image data, 500 x 203, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 68
ASCII text
downloaded
Chrome Cache Entry: 69
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 877x350, components 3
dropped
Chrome Cache Entry: 70
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 71
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 720x288, components 3
dropped
Chrome Cache Entry: 72
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 73
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=4, orientation=[*0*], software=Google], baseline, precision 8, 1200x360, components 3
downloaded
Chrome Cache Entry: 74
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 75
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 76
PNG image data, 1200 x 522, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 77
Web Open Font Format, CFF, length 1380, version 1.0
downloaded
Chrome Cache Entry: 78
ASCII text, with very long lines (42862)
downloaded
Chrome Cache Entry: 79
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 767x400, components 3
downloaded
Chrome Cache Entry: 80
GIF image data, version 89a, 32 x 32
downloaded
Chrome Cache Entry: 81
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 82
PNG image data, 1200 x 522, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 83
GIF image data, version 89a, 32 x 32
dropped
Chrome Cache Entry: 84
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=4, orientation=[*0*], software=Google], baseline, precision 8, 1200x360, components 3
dropped
Chrome Cache Entry: 85
Unicode text, UTF-8 text, with very long lines (65300)
downloaded
Chrome Cache Entry: 86
PNG image data, 500 x 203, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 87
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 767x400, components 3
dropped
Chrome Cache Entry: 88
ASCII text, with very long lines (65371)
downloaded
Chrome Cache Entry: 89
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 877x350, components 3
dropped
Chrome Cache Entry: 90
Unicode text, UTF-8 text, with very long lines (50806)
downloaded
Chrome Cache Entry: 91
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 720x288, components 3
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 93
PNG image data, 1633 x 606, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 94
PNG image data, 1633 x 606, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 95
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 96
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 877x350, components 3
downloaded
Chrome Cache Entry: 97
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 877x350, components 3
downloaded
Chrome Cache Entry: 98
Web Open Font Format (Version 2), TrueType, length 18720, version 1.0
downloaded
Chrome Cache Entry: 99
RIFF (little-endian) data, Web/P image, VP8 encoding, 1100x439, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
There are 28 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2432 --field-trial-handle=2104,i,2251674092471254415,1588843786538767319,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://daftar-limit-paylater-24.xcxcx.my.id/"

URLs

Name
IP
Malicious
https://daftar-limit-paylater-24.xcxcx.my.id/
malicious
https://daftar-limit-paylater-24.xcxcx.my.id/
malicious
https://a.m.dana.id/danaweb/cms/1659493953_Cover_Referral_30_K_bf4fb92f03.png?x-oss-process=image/fo
unknown
https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/fonts/slick.woff
151.101.65.229
https://github.com/google/material-design-icons
unknown
https://cdn.jsdelivr.net/npm/bootstrap
unknown
https://upload.wikimedia.org/wikipedia/commons/8/83/OJK_Logo.png
185.15.59.240
https://a.m.dana.id/danaweb/cms/1651050647_Biller_2_ac560596b5.png?x-oss-process=image/format
unknown
https://a.m.dana.id/danaweb/cms/1667543220_Web_Banner_BNI_Get_Benefit_Up_To_190_K_1440x575px_f4a1db6
unknown
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://www.dana.id/_nuxt/img/dana-logo.fe46647.png
unknown
https://code.ionicframework.com/ionicons/2.0.1/css/ionicons.min.css
104.26.7.173
https://twitter.com/benjsperry
unknown
https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.css
151.101.65.229
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0-pNg29yt7xWxle-UX11R4E3LkM8tDWfYo1ugaMB
unknown
https://api2.branch.io
unknown
https://www.dana.id
unknown
http://ionicons.com/
unknown
https://getbootstrap.com/)
unknown
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/jquery.min.js
104.17.25.14
https://github.com/driftyco/ionicons
unknown
https://www.dana.id/favicon.ico
unknown
https://maxcdn.bootstrapcdn.com/bootstrap/3.3.5/css/bootstrap.min.css
104.18.10.207
https://e-formulir.mwebs.id/BotikaTTS%20_5_.mp3
unknown
https://twitter.com/ionicframework
unknown
https://app.link
unknown
https://a.m.dana.id
unknown
https://cdn.jsdelivr.net/npm/bootstrap@5.2.0-beta1/dist/css/bootstrap.min.css
151.101.65.229
https://a.m.dana.id/danaweb/cms/1665753414_Website_Banner_Natuna_Mart_eaa4679cd6.png?x-oss-process=i
unknown
https://cdn.jsdelivr.net/npm/slick-carousel
unknown
http://getbootstrap.com)
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick.min.js
151.101.65.229
https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/ajax-loader.gif
151.101.65.229
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7H3AZHRJ8VHqTtUQZVi0MP9fnWfj4q8PXBGeCY8H
unknown
https://sentry.io
unknown
https://www.dana.id/
unknown
https://youtube.com
unknown
https://infobanknews.com/wp-content/uploads/2019/04/logo-lps.png
34.36.71.3
https://assets.bukalapak.com/daisy/compro/images/about/logo-mitra.png
unknown
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7H3AZHRJ8VHqTtUQZVi0MP9fnWfj4q8PXBGeCY8H7TOzwmQBfZrRZ_mqq50lFLvTZTHCnzIR-stdV2Gg_CjT6XUCTdj0fZw4TGq8gC4AJn2kF9vk5O7Doxi0Ove7_b-eIh4dxbvhC0L3BkjGQSSSgtaD5TxImeKlEqfZlhlx2aI-kHD1R5_XSTCQl1k0/s1200/IMG_20230827_160252.jpg
216.58.206.33
https://cdn.lr-ingest.io
unknown
http://creativecommons.org/licenses/by/4.0/
unknown
https://cdn.jsdelivr.net/npm/slick-carousel@1.8.1/slick/slick-theme.css
151.101.65.229
There are 33 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
daftar-limit-paylater-24.xcxcx.my.id
104.21.34.94
malicious
jsdelivr.map.fastly.net
151.101.65.229
app.link
99.86.4.74
sentry.io
35.186.247.156
maxcdn.bootstrapcdn.com
104.18.10.207
cdn.lr-ingest.io
188.114.96.3
fp2e7a.wpc.phicdn.net
192.229.221.95
youtube.com
142.250.185.110
bg.microsoft.map.fastly.net
199.232.210.172
cdnjs.cloudflare.com
104.17.25.14
www.google.com
142.250.185.228
upload.wikimedia.org
185.15.59.240
googlehosted.l.googleusercontent.com
216.58.206.33
code.ionicframework.com
104.26.7.173
infobanknews.com
34.36.71.3
api2.branch.io
108.156.60.57
cdn.jsdelivr.net
unknown
a.m.dana.id
unknown
www.dana.id
unknown
e-formulir.mwebs.id
unknown
blogger.googleusercontent.com
unknown
assets.bukalapak.com
unknown
There are 12 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.34.94
daftar-limit-paylater-24.xcxcx.my.id
United States
malicious
142.250.185.228
www.google.com
United States
104.18.10.207
maxcdn.bootstrapcdn.com
United States
151.101.129.229
unknown
United States
99.86.4.74
app.link
United States
35.186.247.156
sentry.io
United States
216.58.206.33
googlehosted.l.googleusercontent.com
United States
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
185.15.59.240
upload.wikimedia.org
Netherlands
142.250.184.225
unknown
United States
34.36.71.3
infobanknews.com
United States
151.101.65.229
jsdelivr.map.fastly.net
United States
142.250.185.110
youtube.com
United States
239.255.255.250
unknown
Reserved
108.156.60.57
api2.branch.io
United States
188.114.96.3
cdn.lr-ingest.io
European Union
104.26.7.173
code.ionicframework.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States
There are 9 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://daftar-limit-paylater-24.xcxcx.my.id/
malicious