IOC Report
http://services.business-manange.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 116
ASCII text
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (32072)
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (52276)
downloaded
Chrome Cache Entry: 119
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 120
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 121
Web Open Font Format (Version 2), TrueType, length 150020, version 772.1280
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (32061)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (65348)
downloaded
Chrome Cache Entry: 124
HTML document, ASCII text, with very long lines (31629), with CRLF line terminators
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (32180)
downloaded
Chrome Cache Entry: 126
Web Open Font Format (Version 2), TrueType, length 15744, version 1.0
downloaded
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 15860, version 1.0
downloaded
There are 3 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1948,i,8796025102651777367,770518745413845529,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://services.business-manange.com/"

URLs

Name
IP
Malicious
http://services.business-manange.com/
malicious
https://services.business-manange.com/actions/
malicious
https://services.business-manange.com/actions/fonts/ttf-regular.woff2
172.67.138.117
malicious
https://services.business-manange.com/actions/fonts/ttf-bold.woff2
172.67.138.117
malicious
https://services.business-manange.com/
172.67.138.117
malicious
https://fontawesome.com
unknown
https://a.nel.cloudflare.com/report/v4?s=bmKNUZb6Qdm%2Bt%2B7WSCyxzL9JdetyMN%2FeRVrnYZ%2BXqBnliyBUFWZstZOetRRoJeg9JP%2BhR%2F2nJZ5H2pOaZBaKaZJ%2Bi7zYFNNL8%2FwscKz4IkLvVomoY31o5R6PYIpvlT19N%2BZWbegV5xyxtXFy0O7PSg%3D%3D
35.190.80.1
https://code.jquery.com/jquery-1.10.2.min.js
151.101.194.137
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.2/webfonts/fa-solid-900.woff2
104.17.24.14
https://genius.anakembok.de/service/
unknown
https://static.xx.fbcdn.net/rsrc.php/yT/r/aGT3gskzWBf.ico
157.240.0.6
https://cdnjs.cloudflare.com/ajax/libs/animate.css/4.1.1/animate.min.css
104.17.24.14
http://opensource.org/licenses/MIT
unknown
https://animate.style/
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.4.2/css/all.min.css
104.17.24.14
https://fontawesome.com/license/free
unknown
There are 5 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
services.business-manange.com
172.67.138.117
malicious
a.nel.cloudflare.com
35.190.80.1
scontent.xx.fbcdn.net
157.240.0.6
code.jquery.com
151.101.194.137
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.18
cdnjs.cloudflare.com
104.17.24.14
www.google.com
142.250.186.164
static.xx.fbcdn.net
unknown

IPs

IP
Domain
Country
Malicious
172.67.138.117
services.business-manange.com
United States
malicious
104.17.24.14
cdnjs.cloudflare.com
United States
192.168.2.7
unknown
unknown
157.240.0.6
scontent.xx.fbcdn.net
United States
239.255.255.250
unknown
Reserved
142.250.186.164
www.google.com
United States
151.101.194.137
code.jquery.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
157.240.252.13
unknown
United States

DOM / HTML

URL
Malicious
https://services.business-manange.com/actions/
malicious