IOC Report
https://hr.economictimes.indiatimes.com/etl.php?url=https://hr.economictimes.indiatimes.com/etl.php?url=//maansaa.com/new/auth//xp8tpwsulfhjn/%2F/YW5keS5ncmVmcmF0aEBrcHMuY29t

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jul 3 12:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 101
HTML document, ASCII text, with very long lines (65209), with CRLF line terminators
downloaded
Chrome Cache Entry: 102
very short file (no magic)
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (45667)
downloaded
Chrome Cache Entry: 104
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 105
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.30, datetime=2022:01:05 12:09:15], progressive, precision 8, 1920x1080, components 3
dropped
Chrome Cache Entry: 106
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 107
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 108
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 109
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 110
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (10450)
downloaded
Chrome Cache Entry: 112
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 113
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 114
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 115
PNG image data, 82 x 13, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 116
very short file (no magic)
downloaded
Chrome Cache Entry: 117
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 118
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (51734)
downloaded
Chrome Cache Entry: 120
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 121
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 122
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 123
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 124
JSON data
dropped
Chrome Cache Entry: 125
JSON data
downloaded
Chrome Cache Entry: 126
HTML document, ASCII text, with very long lines (1445), with CRLF line terminators
downloaded
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
downloaded
Chrome Cache Entry: 128
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (636)
downloaded
Chrome Cache Entry: 130
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.30, datetime=2022:01:05 12:09:15], progressive, precision 8, 1920x1080, components 3
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (42690)
downloaded
Chrome Cache Entry: 132
Web Open Font Format, TrueType, length 35970, version 1.0
downloaded
Chrome Cache Entry: 133
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 134
PNG image data, 420 x 94, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 135
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 136
JSON data
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (48316), with no line terminators
downloaded
Chrome Cache Entry: 138
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 139
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 140
JSON data
dropped
Chrome Cache Entry: 141
Web Open Font Format, TrueType, length 36696, version 1.0
downloaded
Chrome Cache Entry: 142
PNG image data, 420 x 94, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (1434), with no line terminators
downloaded
Chrome Cache Entry: 144
PNG image data, 82 x 13, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 145
Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
downloaded
Chrome Cache Entry: 146
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (10017)
downloaded
Chrome Cache Entry: 148
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 149
PNG image data, 117 x 60, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 150
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 91
JSON data
downloaded
Chrome Cache Entry: 92
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 93
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 94
ASCII text, with very long lines (23398), with no line terminators
downloaded
Chrome Cache Entry: 95
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 96
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 97
ASCII text, with very long lines (1476), with CRLF line terminators
downloaded
Chrome Cache Entry: 98
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 99
PNG image data, 117 x 60, 8-bit/color RGBA, non-interlaced
dropped
There are 57 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2380 --field-trial-handle=2248,i,11952637479509226495,10468588811913034076,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://hr.economictimes.indiatimes.com/etl.php?url=https://hr.economictimes.indiatimes.com/etl.php?url=//maansaa.com/new/auth//xp8tpwsulfhjn/%2F/YW5keS5ncmVmcmF0aEBrcHMuY29t"

URLs

Name
IP
Malicious
https://hr.economictimes.indiatimes.com/etl.php?url=https://hr.economictimes.indiatimes.com/etl.php?url=//maansaa.com/new/auth//xp8tpwsulfhjn/%2F/YW5keS5ncmVmcmF0aEBrcHMuY29t
malicious
https://orlamin.intinhag.com/ekcn/?WMandy.grefrath@kps.com
188.114.97.3
malicious
https://orlamin.intinhag.com/qrkcxZqEs9XQHEq9crg9ZnYxhiYtmtUD2i0GdIFuPIN1xouvkbxx1PKKW5kY2QiSnJ2PTMFef240
188.114.97.3
malicious
https://orlamin.intinhag.com/ijwDAXHF9m5p4FFRXJCoLLGouboiFWmPMoqWAHVNJGCYSW89bgsZzphsbyNBopgk83bA5JdygjFmfGhyz225
188.114.97.3
malicious
https://orlamin.intinhag.com/rsFsOcDaEe2tx5Wyzrruv40
188.114.97.3
malicious
https://orlamin.intinhag.com/mns6PabxzlNYPmSnjP3ng9pEaCyNyHBdoG8LNRCegDK41MklHBBuNn6tE05c4Boa0MbnzMPHaZuv213
188.114.97.3
malicious
https://orlamin.intinhag.com/rs0bawlC2mRh86A2cFnwN5gbnV6y8Wr1wA4ghLL6R4ndJzLMvkLyCzGLrhitlFDNzcd200
188.114.97.3
malicious
https://orlamin.intinhag.com/ekcn/#Mandy.grefrath@kps.com
malicious
https://orlamin.intinhag.com/dpdfjjshRC3IrYk8A7PQOd9IO3ciWR2oi1e9knzkPxuZvJuRvGGVIi091v
188.114.97.3
malicious
https://orlamin.intinhag.com/klmq9EeSBWp8fSbEmOgSKhJrpRPHJuyzCPByzOWlMkOS1Kn56169
188.114.97.3
malicious
https://orlamin.intinhag.com/xyRmJySMrsLWcYcd25
188.114.97.3
malicious
https://orlamin.intinhag.com/dxvknfqNTYrsTc654THMY5Yua7JBUAgzEyK3bn
188.114.97.3
malicious
https://orlamin.intinhag.com/wxZEyk2i1ahELiKo2eqruwDOQAR95b12130
188.114.97.3
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/e1seg/0x4AAAAAAAeIAyMxtqEKlN0x/auto/normal
malicious
https://orlamin.intinhag.com/0700631297382243851313oygfxusyynyzusifevlwtuikt?sgroobwwrxtzrwnnor35813292546327648936MEPZLGSHPBQHDPAZUJWAUFJ
malicious
https://orlamin.intinhag.com/yz2GQlY127p6h0Lh0giGGM6xaopE5786rd0QB67aw77G90180
188.114.97.3
malicious
https://orlamin.intinhag.com/uvfPO8OJoyh5KyGugUd0hiSmHry0PG9Wdcrs4A6FXmdRfCVGJRabmnoRGDxk7noNVnNDV4DAkrwxolKqj7FZABhWSTLYSgh260
188.114.97.3
malicious
https://orlamin.intinhag.com/favicon.ico
188.114.97.3
malicious
https://orlamin.intinhag.com/12LAmEHVrLWnUxyDoBM6720
188.114.97.3
malicious
https://orlamin.intinhag.com/56l5XMlnhXjVkQhUWFxklwP3M5JhQN8pOXnO89104
188.114.97.3
malicious
https://orlamin.intinhag.com/ekcn/
188.114.97.3
malicious
https://orlamin.intinhag.com/894tOCwB8A3NcJeyVqokcdQUc9hGtUab80
188.114.97.3
malicious
https://orlamin.intinhag.com/12EHPXuFGFNzcn568BkgKWWqr50
188.114.97.3
malicious
https://orlamin.intinhag.com/23b6hDm3Y62vO903vOApZrfClvw66
188.114.97.3
malicious
https://orlamin.intinhag.com/cdZaJdisKa4BSb0IDRyoSrER34344EEHH6hNjjmn96
188.114.97.3
malicious
https://orlamin.intinhag.com/qrsCUnjJyWeneROA9JhZSvGBRVefixU6IqR99jG67136
188.114.97.3
malicious
https://ok4static.oktacdn.com/fs/bcg/4/gfsh9pi7jcWKJKMAs1t7
65.9.86.83
https://code.jquery.com/jquery-3.6.0.min.js
151.101.2.137
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=89d74e91380a7cfc
104.17.2.184
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
http://www.gimp.org/xmp/
unknown
https://support.google.com/recaptcha#6262736
unknown
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://cloud.google.com/contact
unknown
https://ok4static.oktacdn.com/assets/loginpage/css/loginpage-theme.e0d37a504604ef874bad26435d62011f.css
65.9.86.83
https://github.com/fent)
unknown
https://a.nel.cloudflare.com/report/v4?s=iwc7yqPwyC6XD9IEfXI3I%2FftOfkS5vgnap1xv9RAMYr%2BbrAbiGUEIQt%2BvK0lNAOHM4FLtW35BICWtgVh4ZDu8bbAiR2kQ4qHItWQxg%2F7uICfFrn7ZE7jz5DzQJabwLBTI1I%3D
35.190.80.1
https://www.google.com/recaptcha/api.js
142.250.185.132
https://support.google.com/recaptcha/#6175971
unknown
https://www.gstatic.c..?/recaptcha/releases/rKbTvxTxwcw5VqzrtN-ICwWt/recaptcha__.
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.2.184
https://ipapi.co/8.46.123.33/json/
172.67.69.226
https://www.google.com/recaptcha/api2/
unknown
https://support.google.com/recaptcha
unknown
https://oxb.ingstio.com/776453589930422284679765gPTnGfJLMOYGRLPHIVYGPMQGRTOOBCQZCCQSWLVXHERYBEQBGPQOHHPXKJINQCTPpqFSyG6hAugIDxxxz34oh8K0Kwx31
172.67.143.252
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
104.17.24.14
https://maansaa.com/favicon.ico
103.110.127.196
https://aadcdn.msauthimages.net/c1c6b6c8-ml-kewji4bxrpdzhmtuenemujrib3fuskwyzrnk9t-0/logintenantbranding/0/bannerlogo?ts=637769780035847380
152.199.21.175
https://ok4static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.18.0/css/okta-sign-in.min.css
65.9.86.83
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://recaptcha.net
unknown
https://www.apache.org/licenses/
unknown
https://challenges.cloudflare.com/turnstile/v0/g/d2a97f6b6ec9/api.js
104.17.3.184
https://httpbin.org/ip
18.214.17.35
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://cdn.socket.io/4.6.0/socket.io.min.js
18.245.31.89
https://a.nel.cloudflare.com/report/v4?s=8SyYnRw%2B5bq7mHelUaJPHQ6Ezz%2FqLCMy1FVTQ%2FF5ogvE%2BQT9V2hp%2B3GN04HCm3mYQzbvSRx0obFuxUYwPAll7bL%2Fpnd5dQjdAuhZ3ZW0CJ31B1KRyYzRrUpbIpoqvA%3D%3D
35.190.80.1
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/89d74e91380a7cfc/1720014233245/b5af31c0a0d717bde570d060f1a47fa570d313837b5f355bd1d5473507108478/vLb0Ntyfurt4DQA
104.17.2.184
https://aadcdn.msauthimages.net/c1c6b6c8-ml-kewji4bxrpdzhmtuenemujrib3fuskwyzrnk9t-0/logintenantbranding/0/illustration?ts=637769777992165483
152.199.21.175
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1265780653:1720012421:gj6b64ZxTswty7TasS4F6-L_njhzBWIQFQvX4w52L44/89d74e91380a7cfc/552f4cb98d3b5b2
104.17.2.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/89d74e91380a7cfc/1720014233243/Ad8_92jYGRGAhgz
104.17.2.184
There are 52 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
orlamin.intinhag.com
188.114.97.3
malicious
a.nel.cloudflare.com
35.190.80.1
maansaa.com
103.110.127.196
github.com
140.82.121.3
oxb.ingstio.com
172.67.143.252
fsobs.25bvnw8.ru
188.114.97.3
fp2e7a.wpc.phicdn.net
192.229.221.95
ipapi.co
172.67.69.226
code.jquery.com
151.101.2.137
d2vgu95hoyrpkh.cloudfront.net
18.245.31.89
cdnjs.cloudflare.com
104.17.24.14
sni1gl.wpc.upsiloncdn.net
152.199.21.175
challenges.cloudflare.com
104.17.3.184
www.google.com
142.250.74.196
d19d360lklgih4.cloudfront.net
65.9.86.83
objects.githubusercontent.com
185.199.109.133
httpbin.org
18.214.17.35
hr.economictimes.indiatimes.com
unknown
cdn.socket.io
unknown
aadcdn.msauthimages.net
unknown
ok4static.oktacdn.com
unknown
There are 11 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
188.114.97.3
fsobs.25bvnw8.ru
European Union
malicious
103.110.127.196
maansaa.com
China
65.9.86.83
d19d360lklgih4.cloudfront.net
United States
192.168.2.17
unknown
unknown
192.168.2.16
unknown
unknown
18.214.17.35
httpbin.org
United States
192.168.2.5
unknown
unknown
104.17.3.184
challenges.cloudflare.com
United States
185.199.109.133
objects.githubusercontent.com
Netherlands
108.157.194.11
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.74.196
www.google.com
United States
172.67.69.226
ipapi.co
United States
104.17.24.14
cdnjs.cloudflare.com
United States
140.82.121.3
github.com
United States
142.250.185.132
unknown
United States
18.245.31.89
d2vgu95hoyrpkh.cloudfront.net
United States
151.101.2.137
code.jquery.com
United States
3.227.135.8
unknown
United States
239.255.255.250
unknown
Reserved
152.199.21.175
sni1gl.wpc.upsiloncdn.net
United States
104.21.71.85
unknown
United States
172.67.143.252
oxb.ingstio.com
United States
104.17.2.184
unknown
United States
There are 14 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://orlamin.intinhag.com/0700631297382243851313oygfxusyynyzusifevlwtuikt?sgroobwwrxtzrwnnor35813292546327648936MEPZLGSHPBQHDPAZUJWAUFJ
malicious
https://orlamin.intinhag.com/0700631297382243851313oygfxusyynyzusifevlwtuikt?sgroobwwrxtzrwnnor35813292546327648936MEPZLGSHPBQHDPAZUJWAUFJ
malicious
https://maansaa.com/new/auth//xp8tpwsulfhjn///YW5keS5ncmVmcmF0aEBrcHMuY29t?utm_source=promotions&utm_medium=email&utm_campaign=
https://orlamin.intinhag.com/ekcn/#Mandy.grefrath@kps.com
https://orlamin.intinhag.com/ekcn/#Mandy.grefrath@kps.com
https://orlamin.intinhag.com/ekcn/#Mandy.grefrath@kps.com
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/e1seg/0x4AAAAAAAeIAyMxtqEKlN0x/auto/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/e1seg/0x4AAAAAAAeIAyMxtqEKlN0x/auto/normal