IOC Report
https://www.itanhangasaude.com.br/www/1475312998d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT___714820ufgtMx5cBwKyVuzlJn3VAYy1QdJUF0IuhCb1EFSueBwxxR9n7T4VNMSyrZd9kcF9rD67v2lJn3VufgtMP8xfiVl9n3IuhCbR9n7Tx5cBw4VNMSx5cBwi3vtsVl9n3MryfS1EFSuufgtMi3vts7O1AR408519___47741237d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (51734)
downloaded
Chrome Cache Entry: 102
Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
downloaded
Chrome Cache Entry: 103
very short file (no magic)
dropped
Chrome Cache Entry: 104
PNG image data, 420 x 94, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 105
Web Open Font Format, TrueType, length 35970, version 1.0
downloaded
Chrome Cache Entry: 106
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 107
JSON data
dropped
Chrome Cache Entry: 108
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 109
PNG image data, 79 x 26, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 110
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 111
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 112
JSON data
dropped
Chrome Cache Entry: 113
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=14, height=1987, bps=182, compression=LZW, PhotometricIntepretation=CMYK, orientation=upper-left, width=3579], baseline, precision 8, 1920x1066, components 3
downloaded
Chrome Cache Entry: 114
ASCII text, with very long lines (23398), with no line terminators
downloaded
Chrome Cache Entry: 115
HTML document, ASCII text, with very long lines (1445), with CRLF line terminators
downloaded
Chrome Cache Entry: 116
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 117
JSON data
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (10017)
downloaded
Chrome Cache Entry: 119
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 120
Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (1434), with no line terminators
downloaded
Chrome Cache Entry: 122
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 123
HTML document, ASCII text, with very long lines (5140)
downloaded
Chrome Cache Entry: 124
JPEG image data, JFIF standard 1.01, resolution (DPI), density 120x120, segment length 16, baseline, precision 8, 304x72, components 3
dropped
Chrome Cache Entry: 125
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (636)
downloaded
Chrome Cache Entry: 127
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 128
PNG image data, 420 x 94, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 129
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 130
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (48316), with no line terminators
downloaded
Chrome Cache Entry: 72
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 73
Web Open Font Format, TrueType, length 36696, version 1.0
downloaded
Chrome Cache Entry: 74
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 75
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 76
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 77
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 78
ASCII text, with very long lines (1476), with CRLF line terminators
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (45667)
downloaded
Chrome Cache Entry: 80
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 81
PNG image data, 79 x 26, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 82
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 83
JPEG image data, JFIF standard 1.01, resolution (DPI), density 120x120, segment length 16, baseline, precision 8, 304x72, components 3
downloaded
Chrome Cache Entry: 84
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 85
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 86
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=14, height=1987, bps=182, compression=LZW, PhotometricIntepretation=CMYK, orientation=upper-left, width=3579], baseline, precision 8, 1920x1066, components 3
dropped
Chrome Cache Entry: 87
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
downloaded
Chrome Cache Entry: 88
ASCII text, with very long lines (10450)
downloaded
Chrome Cache Entry: 89
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 90
very short file (no magic)
downloaded
Chrome Cache Entry: 91
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 92
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 93
JSON data
dropped
Chrome Cache Entry: 94
HTML document, ASCII text, with very long lines (65209), with CRLF line terminators
downloaded
Chrome Cache Entry: 95
JSON data
downloaded
Chrome Cache Entry: 96
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 97
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (42690)
downloaded
Chrome Cache Entry: 99
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
dropped
There are 52 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2124 --field-trial-handle=2020,i,4672451666164520208,10170229004511272603,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.itanhangasaude.com.br/www/1475312998d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT___714820ufgtMx5cBwKyVuzlJn3VAYy1QdJUF0IuhCb1EFSueBwxxR9n7T4VNMSyrZd9kcF9rD67v2lJn3VufgtMP8xfiVl9n3IuhCbR9n7Tx5cBw4VNMSx5cBwi3vtsVl9n3MryfS1EFSuufgtMi3vts7O1AR408519___47741237d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT"

URLs

Name
IP
Malicious
https://www.itanhangasaude.com.br/www/1475312998d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT___714820ufgtMx5cBwKyVuzlJn3VAYy1QdJUF0IuhCb1EFSueBwxxR9n7T4VNMSyrZd9kcF9rD67v2lJn3VufgtMP8xfiVl9n3IuhCbR9n7Tx5cBw4VNMSx5cBwi3vtsVl9n3MryfS1EFSuufgtMi3vts7O1AR408519___47741237d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT
malicious
https://vkwek.ckyucle.com/uvhQlfoMbJ4XJRFtu2qrnZlpt9TrWXuaMNtQnfO12130
188.114.96.3
malicious
https://vkwek.ckyucle.com/12TvEGAMcd3aPS6720
188.114.96.3
malicious
https://vkwek.ckyucle.com/opQX1gSU09O17E3k10USpNWJby3griWtsKreijbClabV2GbvNaQkTef200
188.114.96.3
malicious
https://vkwek.ckyucle.com/wxygRZbM3kOCvEcFjIDlEKamnOMWqU6ryQDaTnQ90180
188.114.96.3
malicious
https://vkwek.ckyucle.com/btxrhxzoevmhjxgkorrNPJYPJDHLMKWIDHWYHTNWXE?disyrywmnujjxhqewiiecx076493453020648cccxedfpwocfzkfrs
malicious
https://vkwek.ckyucle.com/2DUx/
188.114.96.3
malicious
https://vkwek.ckyucle.com/56NViOjdyBE66K4aemhQsnnijWU2q89KCdOOZ89106
188.114.96.3
malicious
https://vkwek.ckyucle.com/favicon.ico
188.114.96.3
malicious
https://vkwek.ckyucle.com/rfrj4D3IOrBb34OKfQNxY9akOmZckEWxXo9xwrWKJaQReBHFIHg5kn2
188.114.96.3
malicious
https://vkwek.ckyucle.com/2DUx/#-
unknown
malicious
https://vkwek.ckyucle.com/78l8NmRVxJ45fjuJRst60
188.114.96.3
malicious
https://vkwek.ckyucle.com/45TplGCNDXCptZb896Wyz84jpQxy69
188.114.96.3
malicious
https://vkwek.ckyucle.com/ghUQ6Orlc7xuQgWcYlBAqViojmkfQHsxQ81JqDSmnddnAwJvMkE5kY34tjef210
188.114.96.3
malicious
https://vkwek.ckyucle.com/90YOSnhY5T8JbcpfefM5jeqjHMc7G9ab72
188.114.96.3
malicious
https://vkwek.ckyucle.com/qr6FfLhLZ5QwaGe5HJsDHUaandv4RUef6Ia8VBkiV1U467140
188.114.96.3
malicious
https://vkwek.ckyucle.com/mnV1lfGeFEBrSZF3tuYYejMClYOTm2XI5H6CdAfkleMiUWyqFdfMgv4x5mkyLwx220
188.114.96.3
malicious
https://vkwek.ckyucle.com/kldibCibzXsTOdNtNAZcyznJMPZFnrycjnb52eIM56170
188.114.96.3
malicious
https://vkwek.ckyucle.com/mnP7Z0RTacSIM9CxKvK5WayGyklgNKAsEypvOzHpfU2cP90150
188.114.96.3
malicious
https://vkwek.ckyucle.com/2DUx/#-crystal.begin@schulergroup.com
malicious
https://vkwek.ckyucle.com/yzBt71gp856BSdkJ4Qop47
188.114.96.3
malicious
https://vkwek.ckyucle.com/pqJEZxAGJZqUBhc85R9yzrCUwx40
188.114.96.3
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/57uca/0x4AAAAAAAdPpzcgFVvp_PUK/auto/normal
malicious
https://vkwek.ckyucle.com/opyBbj15zt7RBaYZmgGW9bxLK2mu0meuvIDz6YOPBdPPv2mru5dCE8ifyMqnIcd240
188.114.96.3
malicious
https://vkwek.ckyucle.com/2DUx/?W-crystal.begin@schulergroup.com
188.114.96.3
malicious
https://vkwek.ckyucle.com/ijGLf8KcAmo8F8uFMIwMKt5jWtydfJOdOqrh5153ZvUBo56RjXXwgHIOxu3KbwiSDyz230
188.114.96.3
malicious
https://vkwek.ckyucle.com/xy12R7tzrssHzef25
188.114.96.3
malicious
https://vkwek.ckyucle.com/wpn0pH3CIM5nU02jRmQ0L1Y1phPSwbSM0ag
188.114.96.3
malicious
https://vkwek.ckyucle.com/ef6ywsH6ValAwIHzgds78wUwuLf89smkl92
188.114.96.3
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/89d53a759ec80cb4/1719992438382/SmI1HZgyGcJMdmX
104.17.3.184
https://ok4static.oktacdn.com/fs/bcg/4/gfsh9pi7jcWKJKMAs1t7
13.33.187.68
https://code.jquery.com/jquery-3.6.0.min.js
151.101.130.137
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://support.google.com/recaptcha#6262736
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=89d53a759ec80cb4
104.17.3.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/89d53a759ec80cb4/1719992438383/c2633130b86ac0ee267e83463b04f0536de9a1df4bb8645bb21edcc61940ee47/nDxduyEORWLmL4W
104.17.3.184
https://nzd92.6gniu68.ru/5575968202461485388865565DuGzcrTyOZLFNLDIYSVXZDPOLLDSEDNQMSF
188.114.96.3
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://cloud.google.com/contact
unknown
https://ok4static.oktacdn.com/assets/loginpage/css/loginpage-theme.e0d37a504604ef874bad26435d62011f.css
13.33.187.68
https://a.nel.cloudflare.com/report/v4?s=9FyY8jlCi%2F4c38DrlGQVn%2B9cY2SnHA0qSQTJPRz%2F6kjxo3cIRyNG7O38Mbgk9DpOFhZ2EbmUVAyLtUU4H%2F83L1dONhtgfRMoHtDx%2B9CLOkABMcKzLgVVyQIFh0r8kA%3D%3D
35.190.80.1
https://github.com/fent)
unknown
https://s3irk.ativens.com/RYbeTFiWjDZgJJJpLPnlnELgJADpQWZTUKMIVRSXVMLEREXVNPFXMCCJOQKIVpq4KtkJY3tyzyxDzqeuv40
104.21.90.167
https://a.nel.cloudflare.com/report/v4?s=p5f604Do%2BEvEulOYwuBd%2FKN3A2hF8%2FZLsNfHkCqbNoMc3fA19tPlYJK%2B2VBDIjh93MJ2nOaHDSVdEhZGeODgv4NZd5UARcFXKsA1NW%2FTuIYY5HFztj6mYBlYH%2FCTmEeHtdMx4g%3D%3D
35.190.80.1
https://aadcdn.msauthimages.net/c1c6b6c8-d3sb-qm-hhdue0tq8clcu1b-m7tqgv0uyzh6-ekjzwq/logintenantbranding/0/illustration?ts=637292768768790391
152.199.21.175
https://www.google.com/recaptcha/api.js
172.217.18.4
https://support.google.com/recaptcha/#6175971
unknown
https://www.gstatic.c..?/recaptcha/releases/rKbTvxTxwcw5VqzrtN-ICwWt/recaptcha__.
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.3.184
https://ipapi.co/8.46.123.33/json/
104.26.9.44
https://www.google.com/recaptcha/api2/
unknown
https://support.google.com/recaptcha
unknown
https://www.itanhangasaude.com.br/www/1475312998d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT___714820ufgtMx5cBwKyVuzlJn3VAYy1QdJUF0IuhCb1EFSueBwxxR9n7T4VNMSyrZd9kcF9rD67v2lJn3VufgtMP8xfiVl9n3IuhCbR9n7Tx5cBw4VNMSx5cBwi3vtsVl9n3MryfS1EFSuufgtMi3vts7O1AR408519___47741237d8aKqdmPdPNJZi4JNq7WIowwvYGOvuIT
162.241.62.33
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1057242924:1719990587:tl4agvakrAKEFCaNpdhyIRJf0e6GO8XVdySEz6sZojU/89d53a759ec80cb4/e7db8d6cd2b6574
104.17.3.184
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
104.17.24.14
https://a.nel.cloudflare.com/report/v4?s=ntbk1%2B0p%2FKPbnMlpunK%2FF02vxwHxUZE18hSmg6Vb0qrDO1qETED2rd35kRiENcKsGxXLOLDj2AImaw2XunnKdVpn9pEm0zkIHs2vWLzhjlhx9Uq7jOEqVhvsUixkPw%3D%3D
35.190.80.1
https://ok4static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.18.0/css/okta-sign-in.min.css
13.33.187.68
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://recaptcha.net
unknown
https://www.apache.org/licenses/
unknown
https://challenges.cloudflare.com/turnstile/v0/g/d2a97f6b6ec9/api.js
104.17.3.184
https://httpbin.org/ip
3.227.135.8
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://cdn.socket.io/4.6.0/socket.io.min.js
18.245.31.78
https://aadcdn.msauthimages.net/c1c6b6c8-d3sb-qm-hhdue0tq8clcu1b-m7tqgv0uyzh6-ekjzwq/logintenantbranding/0/bannerlogo?ts=637292763121529380
152.199.21.175
There are 56 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
vkwek.ckyucle.com
188.114.96.3
malicious
s3irk.ativens.com
104.21.90.167
a.nel.cloudflare.com
35.190.80.1
nzd92.6gniu68.ru
188.114.96.3
github.com
140.82.121.4
fp2e7a.wpc.phicdn.net
192.229.221.95
itanhangasaude.com.br
162.241.62.33
bg.microsoft.map.fastly.net
199.232.214.172
ipapi.co
104.26.9.44
code.jquery.com
151.101.130.137
d2vgu95hoyrpkh.cloudfront.net
18.245.31.78
cdnjs.cloudflare.com
104.17.24.14
sni1gl.wpc.upsiloncdn.net
152.199.21.175
challenges.cloudflare.com
104.17.3.184
www.google.com
142.250.186.164
d19d360lklgih4.cloudfront.net
13.33.187.68
objects.githubusercontent.com
185.199.109.133
httpbin.org
3.227.135.8
cdn.socket.io
unknown
aadcdn.msauthimages.net
unknown
ok4static.oktacdn.com
unknown
www.itanhangasaude.com.br
unknown
206.23.85.13.in-addr.arpa
unknown
There are 13 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
188.114.96.3
nzd92.6gniu68.ru
European Union
malicious
18.245.31.78
d2vgu95hoyrpkh.cloudfront.net
United States
192.168.2.6
unknown
unknown
151.101.130.137
code.jquery.com
United States
104.17.3.184
challenges.cloudflare.com
United States
185.199.109.133
objects.githubusercontent.com
Netherlands
151.101.66.137
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
104.17.24.14
cdnjs.cloudflare.com
United States
172.217.18.4
unknown
United States
13.33.187.68
d19d360lklgih4.cloudfront.net
United States
140.82.121.4
github.com
United States
104.26.9.44
ipapi.co
United States
104.21.90.167
s3irk.ativens.com
United States
3.227.135.8
httpbin.org
United States
239.255.255.250
unknown
Reserved
162.241.62.33
itanhangasaude.com.br
United States
142.250.186.164
www.google.com
United States
152.199.21.175
sni1gl.wpc.upsiloncdn.net
United States
104.17.2.184
unknown
United States
There are 10 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://vkwek.ckyucle.com/btxrhxzoevmhjxgkorrNPJYPJDHLMKWIDHWYHTNWXE?disyrywmnujjxhqewiiecx076493453020648cccxedfpwocfzkfrs
malicious
https://vkwek.ckyucle.com/btxrhxzoevmhjxgkorrNPJYPJDHLMKWIDHWYHTNWXE?disyrywmnujjxhqewiiecx076493453020648cccxedfpwocfzkfrs
malicious
https://vkwek.ckyucle.com/btxrhxzoevmhjxgkorrNPJYPJDHLMKWIDHWYHTNWXE?disyrywmnujjxhqewiiecx076493453020648cccxedfpwocfzkfrs
malicious
https://vkwek.ckyucle.com/2DUx/#-crystal.begin@schulergroup.com
https://vkwek.ckyucle.com/2DUx/#-crystal.begin@schulergroup.com
https://vkwek.ckyucle.com/2DUx/#-crystal.begin@schulergroup.com
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/57uca/0x4AAAAAAAdPpzcgFVvp_PUK/auto/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/57uca/0x4AAAAAAAdPpzcgFVvp_PUK/auto/normal