IOC Report
http://corporativoentornomedico.com/natwes/natwest3/details.php

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 43
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 44
Web Open Font Format, TrueType, length 26144, version 1.0
downloaded
Chrome Cache Entry: 45
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 46
PNG image data, 120 x 20, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 47
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 48
PNG image data, 22 x 19, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 49
gzip compressed data, from Unix, original size modulo 2^32 2384
downloaded
Chrome Cache Entry: 50
gzip compressed data, from Unix, original size modulo 2^32 47357
downloaded
Chrome Cache Entry: 51
MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
dropped
Chrome Cache Entry: 52
gzip compressed data, from Unix, original size modulo 2^32 5612
downloaded
Chrome Cache Entry: 53
gzip compressed data, from Unix, original size modulo 2^32 1538
downloaded
Chrome Cache Entry: 54
gzip compressed data, from Unix, original size modulo 2^32 135744
downloaded
Chrome Cache Entry: 55
gzip compressed data, from Unix, original size modulo 2^32 32381
downloaded
Chrome Cache Entry: 56
PNG image data, 22 x 19, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 57
MS Windows icon resource - 1 icon, 32x32, 8 bits/pixel
downloaded
Chrome Cache Entry: 58
gzip compressed data, from Unix, original size modulo 2^32 515
downloaded
Chrome Cache Entry: 59
gzip compressed data, from Unix, original size modulo 2^32 76
downloaded
Chrome Cache Entry: 60
Web Open Font Format, TrueType, length 25612, version 1.0
downloaded
Chrome Cache Entry: 61
gzip compressed data, from Unix, original size modulo 2^32 5204
downloaded
Chrome Cache Entry: 62
PNG image data, 120 x 20, 8-bit/color RGBA, non-interlaced
dropped
There are 11 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2332 --field-trial-handle=2256,i,8095886379097499911,17251423474886775732,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://corporativoentornomedico.com/natwes/natwest3/details.php"

URLs

Name
IP
Malicious
http://corporativoentornomedico.com/natwes/natwest3/details.php
malicious
http://corporativoentornomedico.com/natwes/natwest3/details.php
108.179.194.74
malicious
http://corporativoentornomedico.com/natwes/natwest3/security_files/favicon.ico
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/RNHouseSansW03-Bold.woff
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/master.css
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/npc.css
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/jspostcode.js
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/overlayPrompt.css
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/datePicker.css
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/logo.png
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/alert-icon.png
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/exit-icon-white.svg
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/RNHouseSansW03-Regular.woff
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/details.php
http://corporativoentornomedico.com/natwes/natwest3/security_files/NPC_auralstyle.css
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/master_print.css
108.179.194.74
http://corporativoentornomedico.com/natwes/natwest3/security_files/overlayPromptMaster.css
108.179.194.74
There are 6 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
corporativoentornomedico.com
108.179.194.74
www.google.com
142.250.186.100
fp2e7a.wpc.phicdn.net
192.229.221.95
171.39.242.20.in-addr.arpa
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
172.217.18.4
unknown
United States
108.179.194.74
corporativoentornomedico.com
United States
142.250.186.100
www.google.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
http://corporativoentornomedico.com/natwes/natwest3/security_files/details.php