IOC Report
http://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.html

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
PNG image data, 54 x 12, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 101
PNG image data, 662 x 664, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 102
JSON data
downloaded
Chrome Cache Entry: 103
PNG image data, 480 x 480, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
JSON data
downloaded
Chrome Cache Entry: 105
HTML document, ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 106
PNG image data, 192 x 192, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 107
TrueType Font data, 13 tables, 1st "GDEF", 8 names, Microsoft, language 0x409
downloaded
Chrome Cache Entry: 108
OpenType font data
downloaded
Chrome Cache Entry: 109
TrueType Font data, 12 tables, 1st "OS/2", 7 names, Microsoft, language 0x409
downloaded
Chrome Cache Entry: 110
TrueType Font data, 13 tables, 1st "GDEF", 8 names, Microsoft, language 0x409
dropped
Chrome Cache Entry: 111
TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409
downloaded
Chrome Cache Entry: 112
WebAssembly (wasm) binary module version 0x1 (MVP)
downloaded
Chrome Cache Entry: 114
JSON data
downloaded
Chrome Cache Entry: 115
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 236x236, segment length 16, progressive, precision 8, 236x236, components 3
downloaded
Chrome Cache Entry: 116
WebAssembly (wasm) binary module version 0x1 (MVP)
dropped
Chrome Cache Entry: 117
JPEG image data, baseline, precision 8, 1920x175, components 3
downloaded
Chrome Cache Entry: 118
PNG image data, 192 x 192, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 119
TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409
downloaded
Chrome Cache Entry: 120
TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409
downloaded
Chrome Cache Entry: 121
ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 122
TrueType Font data, 13 tables, 1st "GDEF", 8 names, Microsoft, language 0x409
dropped
Chrome Cache Entry: 123
JSON data
downloaded
Chrome Cache Entry: 90
data
downloaded
Chrome Cache Entry: 91
TrueType Font data, 18 tables, 1st "GDEF", 13 names, Microsoft, language 0x409, Copyright 2011 Google Inc. All Rights Reserved.RobotoRegularVersion 2.137; 2017Roboto-RegularRob
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (545)
downloaded
Chrome Cache Entry: 93
PNG image data, 480 x 480, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 94
TrueType Font data, 13 tables, 1st "GDEF", 8 names, Microsoft, language 0x409
downloaded
Chrome Cache Entry: 95
TrueType Font data, 13 tables, 1st "GDEF", 8 names, Microsoft, language 0x409
downloaded
Chrome Cache Entry: 96
PNG image data, 54 x 12, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 97
TrueType Font data, 13 tables, 1st "GDEF", 8 names, Microsoft, language 0x409
dropped
Chrome Cache Entry: 98
ASCII text, with very long lines (727)
downloaded
Chrome Cache Entry: 99
ASCII text, with CRLF line terminators
downloaded
There are 24 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=1896,i,14678065025971338511,13714765998862464718,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.html"

URLs

Name
IP
Malicious
http://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.html
malicious
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/#/
malicious
http://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.html
18.65.39.51
malicious
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.html
malicious
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://github.com/itfoundry/Poppins)
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/FontManifest.json
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/packages/font_awesome_flutter/lib/fonts/fa-brands-400.ttf
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/manifest.json
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/main.dart.js
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/icons/Icon-192.png
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/packages/cupertino_icons/assets/CupertinoIcons.ttf
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/AssetManifest.bin
18.65.39.51
https://github.com/flutter/user/blob/main/lib/web_ui/lib/src/user/js_interop/js_loader.dart#L42
unknown
https://scripts.sil.org/OFLPoppins-Regular4.004Poppins
unknown
https://zwillmuqka.onrender.com/email/send
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/assets/images/fbv2.jpg
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/flutter.js
18.65.39.51
https://flutter.dev/docs/cookbook/design/fonts
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/assets/images/bg.jpg
18.65.39.51
https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/fonts/MaterialIcons-Regular.otf
18.65.39.51
https://zwillmuqka.onrender.com/users/update/
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/AssetManifest.json
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/packages/font_awesome_flutter/lib/fonts/fa-regular-400.ttf
18.65.39.51
https://scripts.sil.org/OFLPoppins-SemiBold4.004ITFO;
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/assets/images/avatar.png
18.65.39.51
https://scripts.sil.org/OFLPoppins-Bold4.004Poppins
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/assets/images/metav2.png
18.65.39.51
https://zwillmuqka.onrender.com/users/
unknown
https://developers.google.com/web/fundamentals/primers/service-workers
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/favicon.png
18.65.39.51
https://developer.mozilla.org/en-US/docs/Web/HTML/Element/base
unknown
https://api.flutter.dev/flutter/material/Scaffold/of.html
unknown
https://docs.flutter.dev/development/platform-integration/web/initialization
unknown
https://zwillmuqka.onrender.com/conversations/addConversations
unknown
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/assets/images/meta.png
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/assets/packages/font_awesome_flutter/lib/fonts/fa-solid-900.ttf
18.65.39.51
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/flutter_service_worker.js?v=1157178464
18.65.39.51
https://zwillmuqka.onrender.com/conversations/conversationsDelete/
unknown
https://ipapi.co/json
104.26.8.44
https://github.com/material-foundation/flutter-packages/issues/new/choose.
unknown
There are 31 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ipapi.co
104.26.8.44
bg.microsoft.map.fastly.net
199.232.210.172
www.google.com
142.250.186.132
helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com
18.65.39.51
fp2e7a.wpc.phicdn.net
192.229.221.95
windowsupdatebg.s.llnwi.net
87.248.204.0

IPs

IP
Domain
Country
Malicious
104.26.8.44
ipapi.co
United States
18.65.39.51
helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com
United States
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
18.65.39.113
unknown
United States
142.250.186.132
www.google.com
United States

DOM / HTML

URL
Malicious
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.html
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/index.html
https://helpdesk-advertising-review-id-9865133.d3m7n55z273utf.amplifyapp.com/#/