IOC Report
https://inpzk.useringimportdulcimer.ink/?=vxkncwole9

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 47
ASCII text, with very long lines (42690)
downloaded
Chrome Cache Entry: 48
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 49
PNG image data, 7 x 46, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 50
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 51
PNG image data, 7 x 46, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 52
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 53
ASCII text, with very long lines (16862), with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=1996,i,4856771794578444014,547560397401803930,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://inpzk.useringimportdulcimer.ink/?=vxkncwole9"

URLs

Name
IP
Malicious
https://inpzk.useringimportdulcimer.ink/?=vxkncwole9
malicious
https://cartevitale-ameli.santeassures-informations.eu/?authentification&uri=/Fi4bPy-N3Rtv-5zOg8-QNWuj-sbXEl-blGhi-4CWIj-zDacF-Pn/index.html&search=
102.48.55.178
malicious
https://cartevitale-ameli.santeassures-informations.eu/Fi4bPy-N3Rtv-5zOg8-QNWuj-sbXEl-blGhi-4CWIj-zDacF-Pn/index.html
malicious
https://cartevitale-ameli.santeassures-informations.eu/favicon.ico
102.48.55.178
malicious
https://cartevitale-ameli.santeassures-informations.eu/websockets
102.48.55.178
malicious
https://cartevitale-ameli.santeassures-informations.eu/?iauthentification
102.48.55.178
malicious
https://cartevitale-ameli.santeassures-informations.eu/assurance/index.html
102.48.55.178
malicious
https://cartevitale-ameli.santeassures-informations.eu/index.php?authentification
102.48.55.178
malicious
https://cartevitale-ameli.santeassures-informations.eu/?js_challenge
102.48.55.178
malicious
https://inpzk.useringimportdulcimer.ink/?=vxkncwole9
188.114.96.3
malicious
https://cartevitale-ameli.santeassures-informations.eu/?captcha_image
102.48.55.178
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/89d6efe14aad728f/1720010354548/f6b3f694799fbd2dd6b2412977b9f8009ebec1e6b44163290b73627a156132ba/xjaWdIKTKn7go5y
104.17.3.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/2115433930:1720008719:mWbT4_enhs2h_w32qRfd66TmkEtkTYfuBx_guyabV0E/89d6efe14aad728f/0228ee3c2a32d26
104.17.3.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/89d6efe14aad728f/1720010354549/WnI_HOuueg-89DS
104.17.3.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=89d6efe14aad728f
104.17.3.184
https://challenges.cloudflare.com/turnstile/v0/g/d2a97f6b6ec9/api.js
104.17.2.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.3.184
https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback
104.17.2.184
about:srcdoc
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/wtoc0/0x4AAAAAAAeHHZ3q51Y71L9P/light/normal
There are 9 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cartevitale-ameli.santeassures-informations.eu
unknown
malicious
bg.microsoft.map.fastly.net
199.232.214.172
challenges.cloudflare.com
104.17.2.184
inpzk.useringimportdulcimer.ink
188.114.96.3
www.google.com
142.250.186.164
megatasklines.freemyip.com
102.48.55.178
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
188.114.96.3
inpzk.useringimportdulcimer.ink
European Union
142.250.186.164
www.google.com
United States
102.48.55.178
megatasklines.freemyip.com
Morocco
104.17.2.184
challenges.cloudflare.com
United States
192.168.2.6
unknown
unknown
104.17.3.184
unknown
United States

DOM / HTML

URL
Malicious
https://cartevitale-ameli.santeassures-informations.eu/Fi4bPy-N3Rtv-5zOg8-QNWuj-sbXEl-blGhi-4CWIj-zDacF-Pn/index.html
malicious
https://cartevitale-ameli.santeassures-informations.eu/Fi4bPy-N3Rtv-5zOg8-QNWuj-sbXEl-blGhi-4CWIj-zDacF-Pn/index.html
malicious
about:srcdoc
https://cartevitale-ameli.santeassures-informations.eu/Fi4bPy-N3Rtv-5zOg8-QNWuj-sbXEl-blGhi-4CWIj-zDacF-Pn/index.html
https://cartevitale-ameli.santeassures-informations.eu/Fi4bPy-N3Rtv-5zOg8-QNWuj-sbXEl-blGhi-4CWIj-zDacF-Pn/index.html
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/wtoc0/0x4AAAAAAAeHHZ3q51Y71L9P/light/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/wtoc0/0x4AAAAAAAeHHZ3q51Y71L9P/light/normal