IOC Report
https://online.systems.com.pk/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue May 28 03:35:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue May 28 03:35:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue May 28 03:35:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue May 28 03:35:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue May 28 03:35:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (833), with no line terminators
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (2294)
downloaded
Chrome Cache Entry: 102
Web Open Font Format (Version 2), TrueType, length 22308, version 1.0
downloaded
Chrome Cache Entry: 103
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (549)
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (2429), with no line terminators
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (2124)
downloaded
Chrome Cache Entry: 107
ASCII text
downloaded
Chrome Cache Entry: 74
ASCII text, with very long lines (8010)
downloaded
Chrome Cache Entry: 75
HTML document, ASCII text, with very long lines (17209)
downloaded
Chrome Cache Entry: 76
ASCII text, with very long lines (593)
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 78
JSON data
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (8010)
dropped
Chrome Cache Entry: 80
PNG image data, 272 x 92, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 81
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (833), with no line terminators
downloaded
Chrome Cache Entry: 83
ASCII text
dropped
Chrome Cache Entry: 84
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 85
HTML document, ASCII text, with very long lines (13904)
downloaded
Chrome Cache Entry: 86
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 87
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 88
ASCII text, with very long lines (2200)
downloaded
Chrome Cache Entry: 89
PNG image data, 272 x 92, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 90
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 91
PNG image data, 192 x 142, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 92
ASCII text, with very long lines (1684), with no line terminators
downloaded
Chrome Cache Entry: 93
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 94
PNG image data, 192 x 142, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 95
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 96
ASCII text, with very long lines (7408)
downloaded
Chrome Cache Entry: 97
ASCII text, with very long lines (519)
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (521)
downloaded
Chrome Cache Entry: 99
RIFF (little-endian) data, Web/P image
dropped
There are 31 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://online.systems.com.pk/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=1932,i,11302382915843023677,13515464872013767238,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://online.systems.com.pk/
malicious
https://be-isabel-6-eu-online.com/
91.215.85.79
malicious
https://online.systems.com.pk/
37.27.57.153
malicious
https://ogs.google.com/
unknown
https://www.google.com/gen_204?atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&s=jsa&jsi=hd,st.24086,tni.0,atni.1,et.click,n.vZr2rb,cn.2,ie.0,vi.1&zx=1716870978798&opi=89978449
142.250.186.68
http://www.broofa.com
unknown
https://www.google.com/client_204?atyp=i&biw=1280&bih=907&ei=MF9VZorPINzq7_UPwf2YoA4&opi=89978449
142.250.186.68
https://ogs.google.com/widget/app/so?awwd=1
unknown
https://www.google.com/xjs/_/js/md=3/k=xjs.hd.en.n-jycPV9838.O/am=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAIQACgAAQAEAAAgAAAAAAAAAIQAAAgAQgPcAQAggAAQCAGAAiCAAD2UCAAQwAQAAAAQABAIgCAAABAAAAFAAAAAAAAAAAAAAABxAgAAAAAAAAAAAAAAAOgEABAAAAsAAgwAAEAAAAIA8AAQHwCAFAQAAAAAAAAAAAABAABIEcyEBBREQAAAAAAAAAAAAAAAApKQTCxs/rs=ACT90oEYfXmAmlb35bMIgcRlfCgBc-nLQQ
142.250.186.68
https://www.google.com/intl/en/about/products
unknown
https://www.google.com/xjs/_/js/k=xjs.hd.en.n-jycPV9838.O/am=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAIQACgAAQAEAAAgAAAAAAAAAIQAAAgAQgPcAQAggAAQCAGAAiCAAD2UCAAQwAQAAAAQABAIgCAAABAAAAFAAAAAAAAAAAAAAABxAgAAAAAAAAAAAAAAAOgEABAAAAsAAgwAAEAAAAIA8AAQHwCAFAQAAAAAAAAAAAABAABIEcyEBBREQAAAAAAAAAAAAAAAApKQTCxs/d=0/dg=0/br=1/rs=ACT90oEYfXmAmlb35bMIgcRlfCgBc-nLQQ/m=kMFpHd,sy8x,bm51tf?xjs=s3
142.250.186.68
https://www.google.com/images/branding/googlelogo/1x/googlelogo_color_272x92dp.png
142.250.186.68
https://www.google.com/complete/search?q&cp=0&client=gws-wiz&xssi=t&gs_pcrt=2&hl=en&authuser=0&psi=MF9VZorPINzq7_UPwf2YoA4.1716870962202&dpr=1&nolsbt=1
142.250.186.68
https://www.google.com/log?format=json&hasfast=true
unknown
https://lens.google.com
unknown
https://www.google.com/images/hpp/ic_wahlberg_product_core_48.png8.png
142.250.186.68
https://ogs.google.com/widget/callout
unknown
https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
unknown
http://schema.org/WebPage
unknown
https://lens.google.com/gen204
unknown
https://support.google.com/
unknown
https://www.google.com
unknown
https://www.google.com/gen_204?s=webhp&t=cap&atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&rt=wsrt.5175,cbt.92,hst.91&opi=89978449
142.250.186.68
https://www.google.com/url?q
unknown
https://www.google.com/gen_204?atyp=i&ei=MF9VZorPINzq7_UPwf2YoA4&dt19=2&zx=1716870964057&opi=89978449
142.250.186.68
https://csp.withgoogle.com/csp/lcreport/
unknown
https://ogs.google.com/widget/callout?prid=19037050&pgid=19037049&puid=9ceb59a7585b55bd&cce=1&dc=1&origin=https%3A%2F%2Fwww.google.com&cn=callout&pid=1&spid=538&hl=en
https://www.google.com/gen_204?atyp=csi&ei=Nl9VZviTJduA9u8PxbKskAQ&s=async&astyp=hpba&ima=0&imn=0&mem=ujhs.6,tjhs.10,jhsl.2173,dm.8&nv=ne.1,feid.6192e56c-22dd-43d1-a29a-aec2417b2275&hp=&rt=ttfb.1874,st.1875,bs.27,aaft.1876,acrt.1877,art.1877&zx=1716870965929&opi=89978449
142.250.186.68
https://www.google.com/async/hpba?vet=10ahUKEwiKp-ndwq-GAxVc9bsIHcE-BuQQj-0KCBU..i&ei=MF9VZorPINzq7_UPwf2YoA4&opi=89978449&yv=3&cs=0&async=isImageHp:false,eventId:MF9VZorPINzq7_UPwf2YoA4,_basejs:%2Fxjs%2F_%2Fjs%2Fk%3Dxjs.hd.en.n-jycPV9838.O%2Fam%3DAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAIQACgAAQAEAAAgAAAAAAAAAIQAAAgAQgPcAQAggAAQCAGAAiCAAD2UCAAQwAQAAAAQABAIgCAAABAAAAFAAAAAAAAAAAAAAABxAgAAAAAAAAAAAAAAAOgEABAAAAsAAgwAAEAAAAIA8AAQHwCAFAQAAAAAAAAAAAABAABIEcyEBBREQAAAAAAAAAAAAAAAApKQTCxs%2Fdg%3D0%2Fbr%3D1%2Frs%3DACT90oEYfXmAmlb35bMIgcRlfCgBc-nLQQ,_basecss:%2Fxjs%2F_%2Fss%2Fk%3Dxjs.hd.p0rTci6WNV8.L.B1.O%2Fam%3DAEYBAAAAAAAABgAAAAAAAAAAAAAAAAAQAAABAAAAAKAA8AkHQACwIQAAAEAAAAAAAAAAAgAAAOMEAACAAAQCAGAAACAAAAAAAAQCAAEQQASQBAIZCABABGMYgFQAYAAAAAACJAAAAABAQAACAyIAAh5CAAABOkEAEgAAEMAAgwAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAABQAAAAAAAAAAAAAAAAAAgA%2Fbr%3D1%2Frs%3DACT90oGE-pNkmUMzklMXqlDm_p6pMIqxLw,_basecomb:%2Fxjs%2F_%2Fjs%2Fk%3Dxjs.hd.en.n-jycPV9838.O%2Fck%3Dxjs.hd.p0rTci6WNV8.L.B1.O%2Fam%3DAEYBAAAAAAAABgAAAAAAAAAAAAAAAAAQAAABAAAAAKQA-gkHQAGwIQgAAEAAAAAAIQAAAgAQgPcEQAigAAQCAGAAiCAAD2UCAAQyAQEQQASQBAI5CABABGMYgFQAYAAAAAACJAAAABxAwAACAyIAAh5CAAABOkEAFgAAEsAAgwAAEAAAAIA8AAQHwCAFAQAAAAAAAAAAAABAABIEcyEBBREQAAAAAAAAAAAAAAAApKQTCxs%2Fd%3D1%2Fed%3D1%2Fdg%3D0%2Fbr%3D1%2Fujg%3D1%2Frs%3DACT90oHImSEwQ9-p7fjPGqD0ykhIDf0pzg,_fmt:prog,_id:a3JU5b
142.250.186.68
https://www.google.com/gen_204?atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&s=jsa&jsi=hd,st.23579,t.0,at.1,et.click,n.vZr2rb,cn.1,ie.0,vi.1&zx=1716870978292&opi=89978449
142.250.186.68
https://www.google.com/xjs/_/js/k=xjs.hd.en.n-jycPV9838.O/am=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAIQACgAAQAEAAAgAAAAAAAAAIQAAAgAQgPcAQAggAAQCAGAAiCAAD2UCAAQwAQAAAAQABAIgCAAABAAAAFAAAAAAAAAAAAAAABxAgAAAAAAAAAAAAAAAOgEABAAAAsAAgwAAEAAAAIA8AAQHwCAFAQAAAAAAAAAAAABAABIEcyEBBREQAAAAAAAAAAAAAAAApKQTCxs/d=0/dg=0/br=1/rs=ACT90oEYfXmAmlb35bMIgcRlfCgBc-nLQQ/m=sy1c7,P10Owf,sypl,sy1at,sy1av,gSZvdb,syva,syvb,WlNQGd,syvo,syvq,nabPbb,sypk,sypm,sypn,sypq,DPreE,syk9,syv3,syv5,CnSW2d,kQvlef,syvp,fXO0xe?xjs=s3
142.250.186.68
https://apis.google.com
unknown
https://domains.google.com/suggest/flow
unknown
https://www.google.com/tools/feedback
unknown
https://support.google.com/websearch/answer/106230
unknown
https://apis.google.com/js/api.js
unknown
https://www.google.com/_/og/promos/
unknown
https://www.google.com/xjs/_/ss/k=xjs.hd.p0rTci6WNV8.L.B1.O/am=AEYBAAAAAAAABgAAAAAAAAAAAAAAAAAQAAABAAAAAKAA8AkHQACwIQAAAEAAAAAAAAAAAgAAAOMEAACAAAQCAGAAACAAAAAAAAQCAAEQQASQBAIZCABABGMYgFQAYAAAAAACJAAAAABAQAACAyIAAh5CAAABOkEAEgAAEMAAgwAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAABQAAAAAAAAAAAAAAAAAAgA/d=0/br=1/rs=ACT90oGE-pNkmUMzklMXqlDm_p6pMIqxLw/m=syk9?xjs=s3
142.250.186.68
https://www.google.com/client_204?cs=1&opi=89978449
142.250.186.68
https://www.google.com/favicon.ico
142.250.186.68
https://google.com/
172.217.16.206
https://plus.google.com
unknown
https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
unknown
https://play.google.com/log?format=json&hasfast=true
216.58.206.46
https://www.google.com/gen_204?atyp=i&ct=psnt&cad=&nt=navigate&ei=MF9VZorPINzq7_UPwf2YoA4&zx=1716870967073&opi=89978449
142.250.186.68
https://www.google.com/xjs/_/js/k=xjs.hd.en.n-jycPV9838.O/am=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAIQACgAAQAEAAAgAAAAAAAAAIQAAAgAQgPcAQAggAAQCAGAAiCAAD2UCAAQwAQAAAAQABAIgCAAABAAAAFAAAAAAAAAAAAAAABxAgAAAAAAAAAAAAAAAOgEABAAAAsAAgwAAEAAAAIA8AAQHwCAFAQAAAAAAAAAAAABAABIEcyEBBREQAAAAAAAAAAAAAAAApKQTCxs/d=0/dg=0/br=1/rs=ACT90oEYfXmAmlb35bMIgcRlfCgBc-nLQQ/m=syf9,aLUfP?xjs=s3
142.250.186.68
https://www.google.com/gen_204?atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&s=webhp&nt=navigate&t=fi&st=23478&fid=1&zx=1716870978293&opi=89978449
142.250.186.68
https://ogs.google.com/widget/callout?prid=19037050
unknown
https://www.google.com/images/hpp/us-flag.png
142.250.186.68
https://www.google.com/gen_204?atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&s=promo&rt=hpbas.4166,hpbarr.1878&zx=1716870965930&opi=89978449
142.250.186.68
https://push.clients6.google.com/upload/
unknown
https://www.google.com"
unknown
https://www.google.com/images/searchbox/desktop_searchbox_sprites318_hr.webp
142.250.186.68
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.SCWmpDDGjPk.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo_Pl64J0IIHlj2zBtEJ3ZwdaJC3HA/cb=gapi.loaded_0
216.58.206.78
https://www.google.com/xjs/_/ss/k=xjs.hd.p0rTci6WNV8.L.B1.O/am=AEYBAAAAAAAABgAAAAAAAAAAAAAAAAAQAAABAAAAAKAA8AkHQACwIQAAAEAAAAAAAAAAAgAAAOMEAACAAAQCAGAAACAAAAAAAAQCAAEQQASQBAIZCABABGMYgFQAYAAAAAACJAAAAABAQAACAyIAAh5CAAABOkEAEgAAEMAAgwAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAEAAAABQAAAAAAAAAAAAAAAAAAgA/d=1/ed=1/br=1/rs=ACT90oGE-pNkmUMzklMXqlDm_p6pMIqxLw/m=cdos,hsm,jsa,mb4ZUb,d,csi,cEt90b,SNUn3,qddgKe,sTsDMc,dtl0hd,eHDfl
142.250.186.68
https://www.google.com/gen_204?atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&s=promo&rt=hpbas.4166&zx=1716870964052&opi=89978449
142.250.186.68
https://www.google.com/gen_204?s=webhp&t=aft&atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&rt=wsrt.5175,aft.2163,afti.2163,cbt.92,hst.91,prt.1158&imn=12&ima=2&imad=0&imac=1&wh=907&aft=1&aftp=907&opi=89978449
142.250.186.68
https://www.google.com/
https://www.google.com/gen_204?atyp=csi&ei=MF9VZorPINzq7_UPwf2YoA4&s=webhp&t=all&imn=12&ima=2&imad=0&imac=1&wh=907&aft=1&aftp=907&adh=&ime=2&imeae=0&imeap=0&imex=2&imeh=0&imeha=0&imehb=0&imea=0&imeb=0&imel=0&imed=0&imeeb=0&scp=0&mem=ujhs.6,tjhs.10,jhsl.2173,dm.8&nv=ne.1,feid.6192e56c-22dd-43d1-a29a-aec2417b2275&net=dl.1500,ect.3g,rtt.300&hp=&sys=hc.4&p=bs.true&rt=hst.91,cbt.92,prt.1158,afti.2163,aft.2163,aftqf.2164,xjses.2238,xjsee.2282,xjs.2282,lcp.1410,fcp.1162,wsrt.5175,cst.658,dnst.8,rqst.695,rspt.350,sslt.657,rqstt.4830,unt.4162,cstt.4172,dit.6344&zx=1716870962174&opi=89978449
142.250.186.68
https://clients6.google.com
unknown
There are 49 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
google.com
172.217.16.206
online.systems.com.pk
37.27.57.153
www3.l.google.com
216.58.206.78
plus.l.google.com
216.58.206.78
play.google.com
216.58.206.46
be-isabel-6-eu-online.com
91.215.85.79
www.google.com
142.250.186.68
ogs.google.com
unknown
apis.google.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
37.27.57.153
online.systems.com.pk
Iran (ISLAMIC Republic Of)
172.217.16.206
google.com
United States
216.58.206.78
www3.l.google.com
United States
192.168.2.16
unknown
unknown
142.250.185.132
unknown
United States
142.250.185.100
unknown
United States
216.58.206.46
play.google.com
United States
91.215.85.79
be-isabel-6-eu-online.com
Russian Federation
239.255.255.250
unknown
Reserved

DOM / HTML

URL
Malicious
https://www.google.com/
https://www.google.com/
https://www.google.com/
https://ogs.google.com/widget/callout?prid=19037050&pgid=19037049&puid=9ceb59a7585b55bd&cce=1&dc=1&origin=https%3A%2F%2Fwww.google.com&cn=callout&pid=1&spid=538&hl=en