IOC Report
http://forwardink.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 48
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 18:59:48], baseline, precision 8, 190x456, components 3
dropped
Chrome Cache Entry: 49
PNG image data, 130 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 50
ASCII text
downloaded
Chrome Cache Entry: 51
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 19:00:10], baseline, precision 8, 190x456, components 3
dropped
Chrome Cache Entry: 52
PNG image data, 24 x 22, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 53
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 18:57:35], baseline, precision 8, 190x456, components 3
dropped
Chrome Cache Entry: 54
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:10 13:15:29], baseline, precision 8, 635x1, components 3
downloaded
Chrome Cache Entry: 55
HTML document, ASCII text
downloaded
Chrome Cache Entry: 56
PNG image data, 130 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 57
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 19:02:52], baseline, precision 8, 190x456, components 3
downloaded
Chrome Cache Entry: 58
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 19:00:43], baseline, precision 8, 190x456, components 3
downloaded
Chrome Cache Entry: 59
ASCII text
downloaded
Chrome Cache Entry: 60
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:10 13:16:38], baseline, precision 8, 635x12, components 3
downloaded
Chrome Cache Entry: 61
PNG image data, 50 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 62
PNG image data, 351 x 456, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 63
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 19:00:43], baseline, precision 8, 190x456, components 3
dropped
Chrome Cache Entry: 64
PNG image data, 351 x 456, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 65
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 19:00:10], baseline, precision 8, 190x456, components 3
downloaded
Chrome Cache Entry: 66
PNG image data, 220 x 60, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 67
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 18:57:35], baseline, precision 8, 190x456, components 3
downloaded
Chrome Cache Entry: 68
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:10 13:17:39], baseline, precision 8, 635x12, components 3
downloaded
Chrome Cache Entry: 69
PNG image data, 23 x 22, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 70
PNG image data, 220 x 60, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 71
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:10 13:15:29], baseline, precision 8, 635x1, components 3
dropped
Chrome Cache Entry: 72
PNG image data, 23 x 22, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 73
assembler source, ASCII text
downloaded
Chrome Cache Entry: 74
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:10 13:17:39], baseline, precision 8, 635x12, components 3
dropped
Chrome Cache Entry: 75
HTML document, Unicode text, UTF-8 text, with very long lines (372)
downloaded
Chrome Cache Entry: 76
PNG image data, 50 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 77
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 18:59:48], baseline, precision 8, 190x456, components 3
downloaded
Chrome Cache Entry: 78
PNG image data, 50 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 79
PNG image data, 24 x 22, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 80
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:09 19:02:52], baseline, precision 8, 190x456, components 3
dropped
Chrome Cache Entry: 81
PNG image data, 50 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 82
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS5 Windows, datetime=2013:05:10 13:16:38], baseline, precision 8, 635x12, components 3
dropped
There are 26 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2280,i,2309978341261577593,16207992106877362438,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://forwardink.com/"

URLs

Name
IP
Malicious
http://forwardink.com/
https://forwardink.com/images/p2.png
198.54.116.25
https://forwardink.com/images/leftbg.png
198.54.116.25
https://forwardink.com/customInput.jquery.js
198.54.116.25
https://forwardink.com/images/sc.png
198.54.116.25
https://forwardink.com/images/topbg01.jpg
198.54.116.25
https://forwardink.com/images/bottombg01.jpg
198.54.116.25
https://forwardink.com/validations.js
198.54.116.25
https://forwardink.com/css/global.css
198.54.116.25
https://forwardink.com/images/02.jpg
198.54.116.25
https://forwardink.com/images/p.png
198.54.116.25
https://forwardink.com/images/05-.jpg
198.54.116.25
https://forwardink.com/images/logo.png
198.54.116.25
https://forwardink.com/contact.html
https://forwardink.com/images/03.jpg
198.54.116.25
https://forwardink.com/demo.css
198.54.116.25
https://forwardink.com/images/bore.jpg
198.54.116.25
http://html5shiv.googlecode.com/svn/trunk/html5.js
unknown
https://forwardink.com/images/middlebg01.jpg
198.54.116.25
https://forwardink.com/images/f2.png
198.54.116.25
http://pinterest.com/forwardink/
unknown
https://forwardink.com/images/04.jpg
198.54.116.25
http://forwardink.com/
198.54.116.25
https://forwardink.com/
https://forwardink.com/favicon.ico
198.54.116.25
https://forwardink.com/images/f.png
198.54.116.25
https://forwardink.com/css/stylesheet.css
198.54.116.25
https://forwardink.com/css/index.css
198.54.116.25
There are 17 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
142.250.74.196
forwardink.com
198.54.116.25
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
198.54.116.25
forwardink.com
United States
192.168.2.9
unknown
unknown
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
142.250.74.196
www.google.com
United States

DOM / HTML

URL
Malicious
https://forwardink.com/
https://forwardink.com/contact.html