IOC Report
http://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 44
PNG image data, 200 x 200, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 45
PNG image data, 920 x 294, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 46
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 47
PNG image data, 200 x 200, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 48
HTML document, Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 49
PNG image data, 920 x 294, 8-bit/color RGBA, non-interlaced
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1900,i,3748212034112894765,15219802471735343631,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0"

URLs

Name
IP
Malicious
http://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0
malicious
http://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0
76.76.21.98
malicious
https://nid.naver.com/login/js/bvsd.1.3.4.min.js
unknown
https://alltheoldknives.autos/team/stv/ns/nid/final.php
unknown
https://ssl.pstatic.net/sstatic/search/common/og_v3.png
unknown
https://nid.naver.com/login/js/v2/default/common_202105.js?v=20210813
unknown
https://nid.naver.com/login/css/global/desktop/w_202105.css?20210812
unknown
https://nid.naver.com/login/js/v2/default/default_202105.js?v=20210910
unknown
https://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0#none
https://ssl.pstatic.net/static/nid/login/banner/m_banner_2step_924x294.png
unknown
https://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0

Domains

Name
IP
Malicious
www.google.com
142.250.186.164
navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app
76.76.21.98
fp2e7a.wpc.phicdn.net
192.229.221.95
ssl.pstatic.net
unknown
nid.naver.com
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.186.164
www.google.com
United States
76.76.21.22
unknown
United States
76.76.21.98
navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app
United States

DOM / HTML

URL
Malicious
https://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0
https://navernewsletter-7fmeelx50-steveappeal77-gmailcom.vercel.app/?user-agent=mozilla/5.0#none