IOC Report
http://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 122
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 222x227, components 3
dropped
Chrome Cache Entry: 123
PNG image data, 1000 x 1000, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 124
GIF image data, version 89a, 200 x 200
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (4798)
downloaded
Chrome Cache Entry: 126
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 804x513, components 3
dropped
Chrome Cache Entry: 127
HTML document, ASCII text
downloaded
Chrome Cache Entry: 128
GIF image data, version 89a, 200 x 200
dropped
Chrome Cache Entry: 129
PNG image data, 1000 x 1000, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 130
PNG image data, 1652 x 411, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (32010)
downloaded
Chrome Cache Entry: 132
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 225x225, components 3
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (30837)
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (32058)
downloaded
Chrome Cache Entry: 135
ASCII text
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 137
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 139
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 550x999, components 3
dropped
Chrome Cache Entry: 140
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 225x225, components 3
downloaded
Chrome Cache Entry: 141
Web Open Font Format (Version 2), TrueType, length 15744, version 1.0
downloaded
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 38812, version 1.0
downloaded
Chrome Cache Entry: 143
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 222x227, components 3
downloaded
Chrome Cache Entry: 144
Web Open Font Format (Version 2), TrueType, length 15860, version 1.0
downloaded
Chrome Cache Entry: 145
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 550x999, components 3
downloaded
Chrome Cache Entry: 146
PNG image data, 1652 x 411, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 147
ASCII text
downloaded
Chrome Cache Entry: 148
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 804x513, components 3
downloaded
Chrome Cache Entry: 149
ASCII text, with no line terminators
downloaded
There are 19 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2016,i,6664779081059254972,7231676484794704864,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/"

URLs

Name
IP
Malicious
http://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/
malicious
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/
malicious
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/img/logowa.png
188.114.96.3
http://fontawesome.io
unknown
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/img/fb-login.png
188.114.96.3
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/img/01.jpg
188.114.96.3
https://www.jsdelivr.com/using-sri-with-dynamic-files
unknown
https://cdnjs.cloudflare.com/ajax/libs/material-design-iconic-font/2.1.2/css/material-design-iconic-font.min.css
104.17.24.14
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css
104.17.24.14
https://cloud.githubusercontent.com/assets/398893/15136779/4e765036-1639-11e6-9201-67e728e86f39.jpg
185.199.110.133
https://www.starratings.com.au/assets/img/loading.gif
54.252.28.172
https://rawcdn.githack.com/AlexHostX/all.asset/c529c239acac01cd8bc1a76f349f7c3caebba766/580b57fcd9996e24bc43c543.png
104.21.234.230
https://rawcdn.githack.com/AlexHostX/all.asset/38984972fb20a70d711e86ac3e6f19e60ea8adc3/AlexHostWA.ttf
104.21.234.230
https://a.nel.cloudflare.com/report/v4?s=c6RIc6ACdz56YDTQYa5xnbXhr9YhF6DxZf3AhdLSysB4jl5fj%2Bnfoy3ilwZDPm4J8c3zapAM0wZUUiHjRn0eSF1g4t8Kiui7%2FOXI83DChGjxdJh%2BZlYB4mgfDWuddcZTPndrniYnq1BCAxjddQg%3D
35.190.80.1
https://rawcdn.githack.com/AlexHostX/protect/a64076479559076b6e31356a0fb6188d291204ce/watermark.css
104.21.234.230
https://raw.githubusercontent.com/AlexHostX/all.asset/c529c239acac01cd8bc1a76f349f7c3caebba766/580b57fcd9996e24bc43c543.png
185.199.108.133
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/img/maria.jpg
188.114.96.3
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/img/bahan1.jpg
188.114.96.3
https://cdnjs.cloudflare.com/ajax/libs/moment.js/2.13.0/moment.min.js
104.17.24.14
https://a.nel.cloudflare.com/report/v4?s=oUTLFvZiTMRAoK3Q93kizLBJ0hjl6jJKmwAUq%2ByJgtbCAC5MaNw%2BrPwdruGI22QcS0CFWdFYPpq3vlpyyniKdBb5IgK7XY3Bq2JL7ttD8hM0RFcCBZWo9Btb9hnLcuGWqiOI5ug%3D
35.190.80.1
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/img/jquery.min.js
188.114.96.3
https://cdnjs.cloudflare.com/ajax/libs/material-design-iconic-font/2.1.2/fonts/Material-Design-Iconic-Font.woff2?v=2.1.0
104.17.24.14
http://fontawesome.io/license
unknown
There are 12 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
rawcdn.githack.com
104.21.234.230
bg.microsoft.map.fastly.net
199.232.210.172
cloud.githubusercontent.com
185.199.110.133
a.nel.cloudflare.com
35.190.80.1
cdnjs.cloudflare.com
104.17.24.14
raw.githubusercontent.com
185.199.108.133
www.google.com
142.250.184.196
joinchat8g7135b.12trm.my.id
188.114.96.3
www.starratings.com.au
54.252.28.172
fp2e7a.wpc.phicdn.net
192.229.221.95
cdn.jsdelivr.net
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
142.250.184.196
www.google.com
United States
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
188.114.97.3
unknown
European Union
54.252.28.172
www.starratings.com.au
United States
104.21.234.230
rawcdn.githack.com
United States
188.114.96.3
joinchat8g7135b.12trm.my.id
European Union
185.199.108.133
raw.githubusercontent.com
Netherlands
35.190.80.1
a.nel.cloudflare.com
United States
185.199.110.133
cloud.githubusercontent.com
Netherlands
There are 2 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://joinchat8g7135b.12trm.my.id/vhsfhqpdhdsih6/
malicious