IOC Report
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (355), with CRLF line terminators
downloaded
Chrome Cache Entry: 101
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 102
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (2659), with CRLF line terminators
downloaded
Chrome Cache Entry: 104
PNG image data, 28 x 28, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 105
assembler source, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 106
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=3, manufacturer=NIKON CORPORATION, model=NIKON D600], baseline, precision 8, 2000x1335, components 3
dropped
Chrome Cache Entry: 107
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 108
PNG image data, 43 x 43, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 109
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 110
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 111
PNG image data, 28 x 28, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 112
PNG image data, 43 x 43, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 113
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1600x1067, components 3
dropped
Chrome Cache Entry: 114
ASCII text, with very long lines (65460)
downloaded
Chrome Cache Entry: 115
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 116
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 117
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
dropped
Chrome Cache Entry: 118
PNG image data, 13 x 14, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 119
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 120
Unicode text, UTF-8 text, with very long lines (20732), with CRLF line terminators
downloaded
Chrome Cache Entry: 121
Unicode text, UTF-8 text, with very long lines (58078), with CRLF line terminators
downloaded
Chrome Cache Entry: 122
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
downloaded
Chrome Cache Entry: 123
PNG image data, 1 x 8, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 124
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1333x889, components 3
dropped
Chrome Cache Entry: 125
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 126
JPEG image data, JFIF standard 1.00, resolution (DPI), density 90x90, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1536x1024, components 3
dropped
Chrome Cache Entry: 127
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x943, components 3
downloaded
Chrome Cache Entry: 128
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 129
ISO-8859 text, with very long lines (3601), with CRLF line terminators
downloaded
Chrome Cache Entry: 130
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 131
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
downloaded
Chrome Cache Entry: 132
PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 133
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
dropped
Chrome Cache Entry: 134
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 135
JPEG image data, JFIF standard 1.00, resolution (DPI), density 120x120, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1536x863, components 3
dropped
Chrome Cache Entry: 136
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
dropped
Chrome Cache Entry: 137
GIF image data, version 89a, 31 x 31
downloaded
Chrome Cache Entry: 138
HTML document, ASCII text, with very long lines (63078), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 139
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1067x711, components 3
downloaded
Chrome Cache Entry: 140
PNG image data, 28 x 28, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 141
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x723, components 3
dropped
Chrome Cache Entry: 142
JPEG image data, JFIF standard 1.00, resolution (DPI), density 120x120, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1536x863, components 3
downloaded
Chrome Cache Entry: 143
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=3, manufacturer=NIKON CORPORATION, model=NIKON D600], baseline, precision 8, 2000x1335, components 3
downloaded
Chrome Cache Entry: 74
PNG image data, 1 x 8, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 75
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 76
JPEG image data, JFIF standard 1.00, resolution (DPI), density 90x90, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1536x1024, components 3
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (32069), with CRLF line terminators
downloaded
Chrome Cache Entry: 78
JSON data
dropped
Chrome Cache Entry: 79
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1333x889, components 3
downloaded
Chrome Cache Entry: 80
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 81
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1600x1067, components 3
downloaded
Chrome Cache Entry: 82
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
downloaded
Chrome Cache Entry: 83
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
downloaded
Chrome Cache Entry: 84
PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (4606), with CRLF line terminators
downloaded
Chrome Cache Entry: 86
PNG image data, 1 x 8, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 87
PNG image data, 1 x 8, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 88
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x943, components 3
dropped
Chrome Cache Entry: 89
PNG image data, 13 x 14, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 90
GIF image data, version 89a, 31 x 31
dropped
Chrome Cache Entry: 91
PNG image data, 28 x 28, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 92
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 93
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x723, components 3
downloaded
Chrome Cache Entry: 94
PNG image data, 43 x 43, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 95
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
downloaded
Chrome Cache Entry: 96
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1067x711, components 3
dropped
Chrome Cache Entry: 97
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
dropped
Chrome Cache Entry: 98
PNG image data, 43 x 43, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 99
JPEG image data, JFIF standard 1.00, resolution (DPI), density 100x100, segment length 16, comment: "LEAD Technologies Inc. V1.01", baseline, precision 8, 1280x853, components 3
dropped
There are 61 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2216,i,11169313987286946116,6565829810031115236,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true"

URLs

Name
IP
Malicious
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true
https://www.gtp-marketplace.com/Content/images/Slider/10.jpg
172.66.42.234
https://a.nel.cloudflare.com/report/v4?s=bQWs08OxUwNtM%2FbAUuP1TtCKl%2Bz3zjVjAr%2FXU5lJd2pTRNfE5733EpKSlsktu3FiTrWAMtNvtrO0COu%2BJkYR76B2tZqTWO5QBJNSGm8X8U%2FLQcr7cbGsQFBaZ7iqiXx18XYtEZfjmDwO
35.190.80.1
https://www.gtp-marketplace.com/Scripts/jquery.validate.unobtrusive.min.js
172.66.42.234
http://fontawesome.io
unknown
https://github.com/jzaefferer/jquery-validation
unknown
https://www.gtp-marketplace.com/Content/supersized/bg-black.png
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/7.jpg
172.66.42.234
https://www.gtp-marketplace.com/Content/LoginStyle.css
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/11.jpg
172.66.42.234
http://es5.github.com/#x15.3.4.5
unknown
https://www.gtp-marketplace.com/Content/images/eye.svg
172.66.42.234
https://www.gtp-marketplace.com/Scripts/jquery-2.2.0.min.js
172.66.42.234
https://www.gtp-marketplace.com/Scripts/jquery.unobtrusive-ajax.min.js
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/6.jpg
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/12.jpg
172.66.42.234
https://www.gtp-marketplace.com/Content/supersized/back.png
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/5.jpg
172.66.42.234
https://js-agent.newrelic.com/nr-spa-1.261.1.min.js
162.247.243.39
https://bam.eu01.nr-data.net/events/1/ce8da51da0?a=441268465&v=1.261.1&to=MhBSZQoZDEpZUE1RCwtafWc7VyNaW1xMVhAmGl5FChcOVV1BFmoBFhBEYRkLEU5XQV17CwsTWUMVGRZQV10%3D&rst=42622&ck=0&s=0&ref=https://www.gtp-marketplace.com//account/ResetPasswordConfirmation&ptid=012dfd706f2d66f5
185.221.87.23
http://www.opensource.org/licenses/mit-license.php
unknown
https://www.gtp-marketplace.com/Content/supersized/thumb-forward.png
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/13.jpg
172.66.42.234
https://github.com/kriskowal/es5-shim/blob/master/es5-shim.js
unknown
http://www.gnu.org/licenses/gpl-2.0.html
unknown
https://www.gtp-marketplace.com/Content/images/Slider/4.jpg
172.66.42.234
http://www.quirksmode.org/css/box.html
unknown
http://www.woothemes.com/flexslider/
unknown
https://www.gtp-marketplace.com/Scripts/modernizr-2.5.3.js
172.66.42.234
https://www.gtp-marketplace.com//content/images/Moshik_Clean.svg
172.66.42.234
https://www.gtp-marketplace.com/Content/styles/common?v=EBRAHquLMZHr0AmUwWUYu_8aL6dJM2SV2MpuqIUy0L41
172.66.42.234
https://www.gtp-marketplace.com/Content/images/logo/new-logo-atriis.svg
172.66.42.234
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://www.gtp-marketplace.com/Scripts/supersized/supersized.shutter.js
172.66.42.234
http://ianlunn.github.io/Hover/)
unknown
https://www.gtp-marketplace.com/Content/images/notvalid.png
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/3.jpg
172.66.42.234
https://github.com/blueimp/jQuery-File-Upload
unknown
https://www.gtp-marketplace.com/Scripts/jquery.validate.min.js
172.66.42.234
https://www.gtp-marketplace.com/Content/supersized/thumb-back.png
172.66.42.234
http://phiras.wordpress.com/2007/04/08/password-strength-meter-a-jquery-plugin/
unknown
https://www.gtp-marketplace.com/Content/images/Slider/1.jpg
172.66.42.234
https://www.gtp-marketplace.com/Content/images/Slider/2.jpg
172.66.42.234
https://www.gtp-marketplace.com/Content/supersized/progress-bar.png
172.66.42.234
https://blueimp.net
unknown
http://fontawesome.io/license
unknown
http://gsgd.co.uk/sandbox/jquery/easing/
unknown
https://www.gtp-marketplace.com/Content/supersized/supersized.shutter.css
172.66.42.234
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true
https://www.gtp-marketplace.com/Content/supersized/progress.gif
172.66.42.234
https://github.com/jdewit/bootstrap-timepicker/graphs/contributors
unknown
https://www.gtp-marketplace.com/Content/supersized/supersized.css
172.66.42.234
https://www.gtp-marketplace.com/favicon.ico
172.66.42.234
https://www.gtp-marketplace.com/Scripts/supersized/supersized.3.2.7.js
172.66.42.234
http://www.opensource.org/licenses/MIT
unknown
http://ianlunn.co.uk/
unknown
https://www.gtp-marketplace.com/Content/images/Slider/9.jpg
172.66.42.234
https://www.gtp-marketplace.com/Content/supersized/progress-back.png
172.66.42.234
https://github.com/IanLunn/Hover
unknown
https://www.gtp-marketplace.com/Scripts/supersized/jquery.easing.min.js
172.66.42.234
https://www.gtp-marketplace.com/Scripts/passwordStrengthMeter.js
172.66.42.234
http://mths.be/placeholder
unknown
https://bam.eu01.nr-data.net/1/ce8da51da0?a=441268465&v=1.261.1&to=MhBSZQoZDEpZUE1RCwtafWc7VyNaW1xMVhAmGl5FChcOVV1BFmoBFhBEYRkLEU5XQV17CwsTWUMVGRZQV10%3D&rst=11476&ck=0&s=0&ref=https://www.gtp-marketplace.com//account/ResetPasswordConfirmation&ptid=012dfd706f2d66f5&af=err,spa,xhr,stn,ins&ap=575&be=1536&fe=7788&dc=4411&perf=%7B%22timing%22:%7B%22of%22:1719993072639,%22n%22:0,%22f%22:3,%22dn%22:43,%22dne%22:43,%22c%22:43,%22s%22:44,%22ce%22:509,%22rq%22:509,%22rp%22:1536,%22rpe%22:1715,%22di%22:5920,%22ds%22:5920,%22de%22:5947,%22dc%22:9316,%22l%22:9316,%22le%22:9324%7D,%22navigation%22:%7B%7D%7D&fp=4128&fcp=6127
185.221.87.23
https://www.gtp-marketplace.com/Scripts/jquery.placeholder.min.js
172.66.42.234
http://jsapi.info/jquery/1.7.1/val#L2363
unknown
https://www.gtp-marketplace.com/Content/images/Slider/8.jpg
172.66.42.234
https://www.gtp-marketplace.com/Content/supersized/forward.png
172.66.42.234
There are 56 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
js-agent.newrelic.com
162.247.243.39
fastly-tls12-bam.eu01.nr-data.net
185.221.87.23
www.gtp-marketplace.com
172.66.42.234
www.google.com
142.250.186.164
fp2e7a.wpc.phicdn.net
192.229.221.95
bam.eu01.nr-data.net
unknown

IPs

IP
Domain
Country
Malicious
185.221.87.23
fastly-tls12-bam.eu01.nr-data.net
Germany
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
172.66.42.234
www.gtp-marketplace.com
United States
142.250.186.164
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
162.247.243.39
js-agent.newrelic.com
United States

DOM / HTML

URL
Malicious
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true
https://www.gtp-marketplace.com//account/ResetPasswordConfirmation?token=f7220991-6ff1-45c7-a765-0ccb51e03eee&isWelcomeResetPassword=true