IOC Report
Fax_Message_04 September, 202411_21_58 AM_564308269612697.htm

loading gif

Files

File Path
Type
Category
Malicious
Fax_Message_04 September, 202411_21_58 AM_564308269612697.htm
HTML document, Unicode text, UTF-8 text, with very long lines (3853), with CRLF line terminators
initial sample
malicious
Chrome Cache Entry: 65
ASCII text, with very long lines (47992), with no line terminators
dropped
Chrome Cache Entry: 66
ASCII text, with very long lines (47992), with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\Fax_Message_04 September, 202411_21_58 AM_564308269612697.htm"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1968,i,3813573641665666415,12442729027054868266,262144 /prefetch:8

URLs

Name
IP
Malicious
https://shih-tzu-fancierson.ru//
188.114.96.3
https://a.nel.cloudflare.com/report/v4?s=BKEuNysdOlkONFSQ8y8j37eYZ%2Fx0chGl5GUF%2Fb0eq1c%2FVCInKH7nBSYolJs3eAC19VP%2FZMRM%2B9a9k4YvhrNikV5w%2F%2FylKgKrwYwU7cie89WDqYEP8doMWDq6EaHtIh3hkphgJu2zW%2BrE
35.190.80.1
file:///C:/Users/user/Desktop/Fax_Message_04%20September,%20202411_21_58%20AM_564308269612697.htm#oZnJhbmNvaXMucml2YXJkQGlubm9jYXAuY29t
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js
104.17.25.14

Domains

Name
IP
Malicious
shih-tzu-fancierson.ru
188.114.96.3
a.nel.cloudflare.com
35.190.80.1
cdnjs.cloudflare.com
104.17.25.14
s-part-0036.t-0009.t-msedge.net
13.107.246.64
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.184.228
s-part-0039.t-0009.t-msedge.net
13.107.246.67

IPs

IP
Domain
Country
Malicious
104.17.24.14
unknown
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
188.114.96.3
shih-tzu-fancierson.ru
European Union
35.190.80.1
a.nel.cloudflare.com
United States
142.250.184.228
www.google.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States

DOM / HTML

URL
Malicious
file:///C:/Users/user/Desktop/Fax_Message_04%20September,%20202411_21_58%20AM_564308269612697.htm#oZnJhbmNvaXMucml2YXJkQGlubm9jYXAuY29t
malicious