IOC Report
http://www.cjblore.org/js/slicknav.min.js

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 44
HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (513)
dropped
Chrome Cache Entry: 45
HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (513)
downloaded
Chrome Cache Entry: 46
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 9293
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2456 --field-trial-handle=2372,i,6601818289214465769,10156119719555974518,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.cjblore.org/js/slicknav.min.js"

URLs

Name
IP
Malicious
http://www.cjblore.org/js/slicknav.min.js
https://stc.utdstc.com/1721384227486/detail.css
unknown
https://en.uptodown.com
unknown
https://img.utdstc.com/icon/367/c07/367c07a62d78fa7d0253ec501c789b8251ac8fb62e2d0185ed38c9417af1bed0
unknown
https://stc.utdstc.com/img/icons-nolazy.svg#icon-bar-arrow
unknown
https://stc.utdstc.com/img/svgs/icon-24-turbo2.svg
unknown
https://stc.utdstc.com/img/icons-nolazy.svg#icon-20-windows
unknown
https://ssm.codes/smart-tag/uptodown.js
unknown
https://en.uptodown.com/mac
unknown
https://en.uptodown.com/windows
unknown
http://www.cjblore.org/favicon.ico
103.189.173.168
https://en.uptodown.com/android/search
unknown
https://stc.utdstc.com/img/icons-nolazy.svg#icon-24-login
unknown
https://stc.utdstc.com/img/svgs/logo-uptodown-dark.svg
unknown
https://fundingchoicesmessages.google.com/i/pub-0337387298854186?ers=1
unknown
https://scripts.ssm.codes/uptodown.js
unknown
https://stc.utdstc.com/fonts/geomanist-medium-webfont-test.woff2
unknown
https://stc.utdstc.com/img/icons-nolazy.svg#icon-bar-search
unknown
https://stc.utdstc.com/img/icons-nolazy.svg#icon-bar-menu
unknown
https://stc.utdstc.com/img/icons-nolazy.svg#icon-20-android
unknown
https://stc.utdstc.com/img/icons-nolazy.svg#icon-20-mac
unknown
https://stc.utdstc.com/img/svgs/icon-bar-close.svg
unknown
https://stc.utdstc.com/fonts/geomanist-regular-webfont-test.woff2
unknown
https://stc.utdstc.com/img/svgs/logo-uptodown.svg
unknown
https://stc.utdstc.com/1721384227486/vendor.css
unknown
http://www.cjblore.org/js/slicknav.min.js
There are 15 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.cjblore.org
103.189.173.168
www.google.com
142.250.186.68
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.18

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
239.255.255.250
unknown
Reserved
103.189.173.168
www.cjblore.org
unknown
192.168.2.7
unknown
unknown

DOM / HTML

URL
Malicious
http://www.cjblore.org/js/slicknav.min.js