IOC Report
http://healthytesto.org/

loading gif

Files

File Path
Type
Category
Malicious
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping2816_1858103048\LICENSE
ASCII text
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping2816_1858103048\_metadata\verified_contents.json
JSON data
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping2816_1858103048\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping2816_1858103048\manifest.json
JSON data
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping2816_1858103048\sets.json
JSON data
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (24155), with no line terminators
dropped
Chrome Cache Entry: 110
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (65297)
dropped
Chrome Cache Entry: 112
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=12, height=1000, bps=158, PhotometricIntepretation=RGB, orientation=upper-left, width=1000], progressive, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 113
PNG image data, 318 x 114, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 114
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 115
PNG image data, 318 x 114, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 116
PNG image data, 122 x 114, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 117
HTML document, ASCII text, with very long lines (5622)
dropped
Chrome Cache Entry: 118
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 119
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 120
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 121
JSON data
downloaded
Chrome Cache Entry: 122
HTML document, ASCII text, with very long lines (1238)
downloaded
Chrome Cache Entry: 123
ASCII text
downloaded
Chrome Cache Entry: 124
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=12, height=1000, bps=158, PhotometricIntepretation=RGB, orientation=upper-left, width=1000], progressive, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 125
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 126
JSON data
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (558)
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (65393)
downloaded
Chrome Cache Entry: 129
Web Open Font Format (Version 2), TrueType, length 43772, version 1.0
downloaded
Chrome Cache Entry: 130
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 131
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 132
Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
downloaded
Chrome Cache Entry: 133
PNG image data, 500 x 300, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 134
PNG image data, 500 x 500, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 135
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 136
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (32086)
dropped
Chrome Cache Entry: 138
Web Open Font Format (Version 2), TrueType, length 28076, version 1.0
downloaded
Chrome Cache Entry: 139
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=12, height=230, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1630], progressive, precision 8, 1630x230, components 3
dropped
Chrome Cache Entry: 140
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=12, height=230, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1630], progressive, precision 8, 1630x230, components 3
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (32086)
downloaded
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 123004, version 330.15728
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (558)
downloaded
Chrome Cache Entry: 144
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 145
HTML document, ASCII text, with very long lines (1238)
dropped
Chrome Cache Entry: 146
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65324)
downloaded
Chrome Cache Entry: 148
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 149
HTML document, ASCII text, with very long lines (5622)
downloaded
Chrome Cache Entry: 150
PNG image data, 500 x 300, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 151
PNG image data, 944 x 184, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 152
PNG image data, 500 x 300, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (428)
dropped
Chrome Cache Entry: 154
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 155
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 156
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 157
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (1411), with no line terminators
downloaded
Chrome Cache Entry: 159
Web Open Font Format (Version 2), TrueType, length 28512, version 1.0
downloaded
Chrome Cache Entry: 160
Web Open Font Format (Version 2), TrueType, length 50296, version 1.0
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (30837)
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 163
ASCII text
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 165
ASCII text, with very long lines (1411), with no line terminators
dropped
Chrome Cache Entry: 166
ASCII text
downloaded
Chrome Cache Entry: 167
PNG image data, 500 x 300, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 168
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=12, height=1000, bps=158, PhotometricIntepretation=RGB, orientation=upper-left, width=1000], progressive, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 169
PNG image data, 122 x 114, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 170
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 171
ASCII text, with very long lines (311)
downloaded
Chrome Cache Entry: 172
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 173
ASCII text
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (65297)
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (24155), with no line terminators
downloaded
Chrome Cache Entry: 176
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=12, height=1000, bps=158, PhotometricIntepretation=RGB, orientation=upper-left, width=1000], progressive, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 177
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
dropped
Chrome Cache Entry: 178
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 179
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 180
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1000x1000, components 3
downloaded
Chrome Cache Entry: 181
PNG image data, 944 x 184, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 182
ASCII text
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (428)
downloaded
There are 72 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2348 --field-trial-handle=2284,i,3076136143040423617,4332320429016009007,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://healthytesto.org/"

URLs

Name
IP
Malicious
http://healthytesto.org/
https://wieistmeineip.de
unknown
https://mercadoshops.com.co
unknown
https://gliadomain.com
unknown
https://poalim.xyz
unknown
https://mercadolivre.com
unknown
https://reshim.org
unknown
https://nourishingpursuits.com
unknown
https://medonet.pl
unknown
https://unotv.com
unknown
https://mercadoshops.com.br
unknown
https://joyreactor.cc
unknown
https://zdrowietvn.pl
unknown
https://johndeere.com
unknown
https://fontawesome.com
unknown
https://songstats.com
unknown
https://baomoi.com
unknown
https://supereva.it
unknown
https://elfinancierocr.com
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://bolasport.com
unknown
https://rws1nvtvt.com
unknown
https://desimartini.com
unknown
https://hearty.app
unknown
https://www.healthytesto.org/assets/images/products/product6-1.jpg
104.21.52.23
https://www.healthytesto.org/assets/fonts/porto6e1d.woff2?64334846
104.21.52.23
https://hearty.gift
unknown
https://mercadoshops.com
unknown
https://heartymail.com
unknown
https://nlc.hu
unknown
https://p106.net
unknown
https://radio2.be
unknown
https://finn.no
unknown
https://hc1.com
unknown
https://kompas.tv
unknown
https://mystudentdashboard.com
unknown
https://songshare.com
unknown
https://smaker.pl
unknown
https://mercadopago.com.mx
unknown
https://p24.hu
unknown
https://talkdeskqaid.com
unknown
https://www.healthytesto.org/category
http://benschwarz.github.io/gallery-css
unknown
https://24.hu
unknown
https://mercadopago.com.pe
unknown
https://www.healthytesto.org/assets/images/products/product7-1.jpg
104.21.52.23
https://cardsayings.net
unknown
https://text.com
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css
104.17.24.14
https://mightytext.net
unknown
https://pudelek.pl
unknown
https://hazipatika.com
unknown
https://joyreactor.com
unknown
https://cookreactor.com
unknown
https://wildixin.com
unknown
https://eworkbookcloud.com
unknown
https://cognitiveai.ru
unknown
https://nacion.com
unknown
https://a.nel.cloudflare.com/report/v4?s=HkBqbY7Y0YFzxNxf1GZshOW%2BxwCETL%2Biwd2PFWKUXqzREw0r4owuPWhfOEE2Z4OIFkpK%2FfG6gK8Do%2BWNMV7r6%2B6dyQYUgnWDvIWJF7J2hRTIigab4tixYgK%2Bf%2BQpWzUY%2FzPP9ApX3A%3D%3D
35.190.80.1
https://chennien.com
unknown
https://drimer.travel
unknown
https://deccoria.pl
unknown
https://mercadopago.cl
unknown
https://talkdeskstgid.com
unknown
https://www.healthytesto.org/assets/images/products/product1-1.jpg
104.21.52.23
https://a.nel.cloudflare.com/report/v4?s=70TiZxgCJE%2F0X3TeCeoM98WLlVTmpgcNcTSoopl87q2jJJgaiIed9h8VvHNJzqQ9Mr3yGXb138GOd%2BSOapskyUSRFmz9n%2B5VNSwEX9S%2BBSwlTFK5fQgLAxmfm0SkA%2Btm0V1u2QGdbA%3D%3D
35.190.80.1
https://naukri.com
unknown
https://interia.pl
unknown
https://bonvivir.com
unknown
https://carcostadvisor.be
unknown
https://salemovetravel.com
unknown
https://sapo.io
unknown
https://wpext.pl
unknown
https://welt.de
unknown
https://www.healthytesto.org/
https://poalim.site
unknown
https://drimer.io
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://infoedgeindia.com
unknown
https://blackrockadvisorelite.it
unknown
https://cognitive-ai.ru
unknown
https://cafemedia.com
unknown
https://graziadaily.co.uk
unknown
https://thirdspace.org.au
unknown
https://mercadoshops.com.ar
unknown
https://www.healthytesto.org/assets/js/main.min.js
104.21.52.23
https://www.healthytesto.org/assets/images/logo_red.png
104.21.52.23
https://smpn106jkt.sch.id
unknown
https://elpais.uy
unknown
https://landyrev.com
unknown
https://the42.ie
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0
104.17.24.14
https://commentcamarche.com
unknown
https://tucarro.com.ve
unknown
https://www.healthytesto.org/frontend/storage/modal.html
104.21.52.23
https://rws3nvtvt.com
unknown
https://eleconomista.net
unknown
https://helpdesk.com
unknown
https://www.healthytesto.org/assets/images/products/product2-1.jpg
104.21.52.23
https://mercadolivre.com.br
unknown
https://www.iconsdb.com/icons/preview/white/note-2-xxl.png)
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.healthytesto.org
104.21.52.23
a.nel.cloudflare.com
35.190.80.1
cdnjs.cloudflare.com
104.17.24.14
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.185.132
healthytesto.org
104.21.52.23
fp2e7a.wpc.phicdn.net
192.229.221.95
pro.fontawesome.com
unknown

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
192.168.2.8
unknown
unknown
142.250.185.132
www.google.com
United States
192.168.2.4
unknown
unknown
172.67.194.78
unknown
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
104.21.52.23
www.healthytesto.org
United States
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://www.healthytesto.org/
https://www.healthytesto.org/
https://www.healthytesto.org/
https://www.healthytesto.org/category
https://www.healthytesto.org/category
https://www.healthytesto.org/category
https://www.healthytesto.org/category