IOC Report
http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1700,18058039625578469226,10548155103771464637,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=7116 /prefetch:8

URLs

Name
IP
Malicious
http://www.splendidcare.sa.com/Juwqdh/xacwk5957irfeugd/FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
malicious
http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
malicious
http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ&__cf_chl_tk=Qo3onJpX2NN9iqTg6AK3IKQV7zteuSapwy7jedCnmwA-1719993703-0.0.1.1-2537
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/uf02t/0x4AAAAAAADnOjc0PNeA8qVm/light/normal
https://gotropislim.com/#hero
https://widget.trustpilot.com/trustboxes/53aa8807dec7e10d38f59f32/index.html?templateId=53aa8807dec7e10d38f59f32&businessunitId=58d40fc70000ff00059f1303#locale=en-US&styleHeight=130px&styleWidth=100%25&theme=light
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://app.campaignrefinery.com/unsubscribe?c=5b3fb967-1467-4f75-a434-25b537201ad8&b=54d49514-f843-4e2e-94e5-8be2d989695e&f=3d8d1c90-1d43-4590-8dd4-f4a952d057cc
https://www.digistore24.com/
https://gotropislim.com/
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0

IPs

IP
Domain
Country
Malicious
34.110.180.34
unknown
United States
34.107.117.83
unknown
United States
157.240.249.35
unknown
United States
54.230.18.36
unknown
United States
142.250.111.84
unknown
United States
142.250.191.238
unknown
United States
142.251.165.154
unknown
United States
52.84.18.58
unknown
United States
31.25.12.21
unknown
United Kingdom
35.244.212.226
unknown
United States
142.250.190.66
unknown
United States
192.168.11.20
unknown
unknown
172.67.154.9
unknown
United States
54.225.7.157
unknown
United States
35.190.80.1
unknown
United States
162.247.243.39
unknown
United States
31.25.12.17
unknown
United Kingdom
104.17.24.14
unknown
United States
142.250.190.35
unknown
United States
142.250.191.227
unknown
United States
34.120.202.204
unknown
United States
151.101.192.217
unknown
United States
216.239.32.181
unknown
United States
157.240.249.8
unknown
United States
146.75.82.109
unknown
Sweden
23.33.29.89
unknown
United States
23.33.29.83
unknown
United States
239.255.255.250
unknown
Reserved
104.21.44.135
unknown
United States
31.25.12.51
unknown
United Kingdom
162.159.128.61
unknown
United States
162.247.243.29
unknown
United States
142.250.190.106
unknown
United States
52.85.247.89
unknown
United States
104.17.2.184
unknown
United States
172.217.2.40
unknown
United States
142.250.191.164
unknown
United States
172.217.4.206
unknown
United States
142.250.191.163
unknown
United States
There are 29 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
malicious
http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
malicious
http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/uf02t/0x4AAAAAAADnOjc0PNeA8qVm/light/normal
http://www.splendidcare.sa.com/clicks/bpage/topslim.php?sid=1035569&h=FW2HGOqFbIVQssWaWxsuPFbxoA78Qv8umKJQmKBGMM0/enpkwYwNDdxjXCgjy64rbJkHYw5eTv2C-VSAAV3Fufzkb2cfb573zE5R9OTtHCML20yl9BXVgVz_5eGAS31RGQ&__cf_chl_tk=Qo3onJpX2NN9iqTg6AK3IKQV7zteuSapwy7jedCnmwA-1719993703-0.0.1.1-2537
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864134318?h=e3208bb7c4&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://player.vimeo.com/video/864351157?h=75b1f32070&background=1&autoplay=1&title=0&byline=0&wmode=transparent&autopause=0
https://gotropislim.com/
https://gotropislim.com/
https://gotropislim.com/
https://gotropislim.com/#hero
https://gotropislim.com/#hero
https://app.campaignrefinery.com/unsubscribe?c=5b3fb967-1467-4f75-a434-25b537201ad8&b=54d49514-f843-4e2e-94e5-8be2d989695e&f=3d8d1c90-1d43-4590-8dd4-f4a952d057cc
https://www.digistore24.com/
https://www.digistore24.com/
https://www.digistore24.com/
https://widget.trustpilot.com/trustboxes/53aa8807dec7e10d38f59f32/index.html?templateId=53aa8807dec7e10d38f59f32&businessunitId=58d40fc70000ff00059f1303#locale=en-US&styleHeight=130px&styleWidth=100%25&theme=light
https://widget.trustpilot.com/trustboxes/53aa8807dec7e10d38f59f32/index.html?templateId=53aa8807dec7e10d38f59f32&businessunitId=58d40fc70000ff00059f1303#locale=en-US&styleHeight=130px&styleWidth=100%25&theme=light
There are 26 hidden doms, click here to show them.