IOC Report
https://singingfiles.com/show.php?l=0&u=2156442&id=64574

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 133
HTML document, ASCII text
downloaded
Chrome Cache Entry: 134
ASCII text
downloaded
Chrome Cache Entry: 135
PNG image data, 1 x 370, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (590)
downloaded
Chrome Cache Entry: 137
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 138
JSON data
dropped
Chrome Cache Entry: 139
JSON data
dropped
Chrome Cache Entry: 140
JSON data
dropped
Chrome Cache Entry: 141
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 142
assembler source, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 143
Web Open Font Format (Version 2), TrueType, length 45300, version 1.0
downloaded
Chrome Cache Entry: 144
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (47203)
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (582)
downloaded
Chrome Cache Entry: 147
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 148
PNG image data, 768 x 370, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 150
HTML document, ASCII text, with very long lines (2319), with no line terminators
downloaded
Chrome Cache Entry: 151
ASCII text
downloaded
Chrome Cache Entry: 152
PNG image data, 1 x 370, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 153
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 154
ASCII text, with very long lines (590)
downloaded
Chrome Cache Entry: 155
ASCII text
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (65366)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (376), with no line terminators
downloaded
Chrome Cache Entry: 158
HTML document, ASCII text, with very long lines (1143), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (62342)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (65474)
downloaded
Chrome Cache Entry: 161
PNG image data, 768 x 370, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 162
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 163
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 164
ASCII text
downloaded
There are 23 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2260 --field-trial-handle=2180,i,4682610930534376281,12712548623362568672,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://singingfiles.com/show.php?l=0&u=2156442&id=64574"

URLs

Name
IP
Malicious
https://singingfiles.com/show.php?l=0&u=2156442&id=64574
malicious
https://free2try.com/favicon.ico
172.67.68.254
malicious
https://free2try.com/?config=9179&src=WC-291454aaa668729bd4830bd0001a8790b_100_2156442:1598122:&wsclid=5de0b3ae-2882-4116-bd49-387b28f8d7a5
172.67.68.254
malicious
https://free2try.com/9179/registration/bg_header.png
172.67.68.254
malicious
https://free2try.com/pushnami/pushnami.html
malicious
https://free2try.com/demo_optimize.js
172.67.68.254
malicious
https://free2try.com/9179/registration//main_header.png
172.67.68.254
malicious
https://free2try.com/images/bootstrap.min.css
172.67.68.254
malicious
https://free2try.com/9179/registration//colors-2016.css
172.67.68.254
malicious
https://free2try.com/images/styles-2016.css
172.67.68.254
malicious
https://free2try.com/?session_id=531dd1e83a5911ef8dd1bff723d6de30
malicious
https://free2try.com/images/js_fl.js
172.67.68.254
malicious
https://free2try.com/pushnami/service-worker.js
172.67.68.254
malicious
https://singingfiles.com/show.php?l=0&u=2156442&id=64574
188.114.97.3
https://api.pushnami.com/scripts/v1/pushnami-two-step-styles/60521c272bf0240010135168
unknown
https://cdn.pushnami.com/js/modules
unknown
https://api.pushnami.com/scripts/v1/hub
https://api.pushnami.com/scripts/v1/pushnami-two-step/60521c272bf0240010135168
unknown
https://cdn.pushnami.com/js/opt-in/
unknown
https://wsjmp.com/c/s=291454/c=1598122/m=668729bd4830bd0001a8790b_100_2156442/
172.67.73.137
https://rtpd.pushnami.com
unknown
https://api.pushnami.com/api/push/unsubscribe
unknown
https://api.pushnami.com/api/push/waterfall/enrollment
unknown
https://trc.pushnami.com/api/push/track
18.211.221.201
https://api.pushnami.com
unknown
http://a.websponsors.com/c/c=
unknown
https://api.pushnami.com/api/push/image/id/654d251715c286001361bac4
18.239.50.108
http://www.free2try.com/privacy.cgi?config=9179
unknown
https://mr.macgsapptrck.com/click?pid=100&offer_id=24516&sub6=1266093652&sub2=100_2156442
34.91.234.242
https://trc.pushnami.com
unknown
https://cdn.pushnami.com/js/workers/sw.355e010fef1d4bf4045b.bundle.js
18.244.18.23
https://github.com/zendesk/cross-storage/blob/master/dist/client.min.js
unknown
https://api.pushnami.com/api/push/icon/ext?url=https%3A%2F%2Fapi.pushnami.com%2Fapi%2Fpush%2Ficon%2Fid%2F6570f8e91fd96a00136b0f37%23.png&fallback=%2Fapi%2Fpush%2Ficon%2F605a1b2ddf8629037ec0e584
18.239.50.108
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Proxy
unknown
https://api.pushnami.com/api/push/subscribe
18.239.50.108
https://cdn.pushnami.com/css/opt-in/
unknown
https://cdn.pushnami.com/js/modules/fcm-v1-module.019781ec7a1c97363e85.bundle.js
18.244.18.23
https://psp.pushnami.com/psfp/data
34.203.90.74
http://getbootstrap.com)
unknown
https://api.pushnami.com/scripts/v1/push/60521c272bf0240010135168
18.66.218.121
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://api.pushnami.com/api/push/waterfall/enrollment?psid=
unknown
https://api.pushnami.com/scripts/v1/pushnami-adv/60521c272bf0240010135168
18.66.218.121
https://psp.pushnami.com/api/psp
34.203.90.74
https://api.pushnami.com/scripts/v2/pushnami-sw/60521c272bf0240010135168
18.66.218.121
http://www.free2try.com/terms.cgi?config=9179&qid=
unknown
http://www.free2try.com/contact.cgi?config=9179
unknown
There are 36 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
free2try.com
172.67.68.254
malicious
android.l.google.com
172.217.23.110
stun4.l.google.com
74.125.250.129
cdn.pushnami.com
18.244.18.23
stun3.l.google.com
74.125.250.129
trc.pushnami.com
18.211.221.201
psp.pushnami.com
34.203.90.74
wsjmp.com
172.67.73.137
singingfiles.com
188.114.97.3
mobile-gtalk.l.google.com
74.125.71.188
fp2e7a.wpc.phicdn.net
192.229.221.95
bg.microsoft.map.fastly.net
199.232.210.172
wdigital.g2afse.com
34.91.234.242
www.google.com
142.250.186.164
api.pushnami.com
18.66.218.121
mr.macgsapptrck.com
unknown
There are 6 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.67.68.254
free2try.com
United States
malicious
18.244.18.23
cdn.pushnami.com
United States
13.32.99.40
unknown
United States
107.21.125.170
unknown
United States
18.239.50.73
unknown
United States
18.239.50.108
unknown
United States
192.168.2.6
unknown
unknown
34.91.234.242
wdigital.g2afse.com
United States
34.193.230.73
unknown
United States
18.205.31.41
unknown
United States
172.217.23.110
android.l.google.com
United States
74.125.250.129
stun4.l.google.com
United States
172.67.73.137
wsjmp.com
United States
74.125.71.188
mobile-gtalk.l.google.com
United States
18.211.221.201
trc.pushnami.com
United States
239.255.255.250
unknown
Reserved
188.114.97.3
singingfiles.com
European Union
142.250.186.164
www.google.com
United States
34.203.90.74
psp.pushnami.com
United States
18.66.218.121
api.pushnami.com
United States
There are 10 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://free2try.com/?session_id=531dd1e83a5911ef8dd1bff723d6de30
malicious
https://free2try.com/?session_id=531dd1e83a5911ef8dd1bff723d6de30
https://free2try.com/?session_id=531dd1e83a5911ef8dd1bff723d6de30
https://free2try.com/?session_id=531dd1e83a5911ef8dd1bff723d6de30
https://free2try.com/?session_id=531dd1e83a5911ef8dd1bff723d6de30
https://api.pushnami.com/scripts/v1/hub
https://free2try.com/pushnami/pushnami.html