IOC Report
https://interface01.nsxtlmv.workers.dev/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 45
HTML document, ASCII text, with very long lines (65534)
downloaded
Chrome Cache Entry: 46
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 47
HTML document, ASCII text, with very long lines (65534)
downloaded
Chrome Cache Entry: 48
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 49
HTML document, ASCII text, with very long lines (65534)
dropped
Chrome Cache Entry: 50
PNG image data, 50 x 50, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 51
HTML document, ASCII text, with very long lines (65534)
downloaded
Chrome Cache Entry: 52
PNG image data, 50 x 50, 8-bit/color RGBA, non-interlaced
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2400 --field-trial-handle=2360,i,9441452327642718650,10753621916115848608,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://interface01.nsxtlmv.workers.dev/"

URLs

Name
IP
Malicious
https://interface01.nsxtlmv.workers.dev/
malicious
https://interface01.nsxtlmv.workers.dev/
malicious
https://interface01.nsxtlmv.workers.dev/style.css
188.114.97.3
https://interface01.nsxtlmv.workers.dev/favicon.ico
188.114.97.3
https://img.icons8.com/color/50/000000/google-logo.png
195.181.175.16
https://api.ipify.org/?format=jsonp&callback=getIP
104.26.13.205

Domains

Name
IP
Malicious
interface01.nsxtlmv.workers.dev
188.114.97.3
malicious
1004834818.rsc.cdn77.org
195.181.175.16
www.google.com
142.250.184.196
api.ipify.org
104.26.13.205
fp2e7a.wpc.phicdn.net
192.229.221.95
img.icons8.com
unknown

IPs

IP
Domain
Country
Malicious
188.114.97.3
interface01.nsxtlmv.workers.dev
European Union
malicious
142.250.184.196
www.google.com
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown
212.102.56.179
unknown
Italy
195.181.175.16
1004834818.rsc.cdn77.org
United Kingdom
239.255.255.250
unknown
Reserved
188.114.96.3
unknown
European Union
104.26.13.205
api.ipify.org
United States

DOM / HTML

URL
Malicious
https://interface01.nsxtlmv.workers.dev/
malicious