IOC Report
http://demettei.com

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 121
Unicode text, UTF-8 text, with very long lines (28860)
dropped
Chrome Cache Entry: 122
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 123
MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 124
PNG image data, 1440 x 225, 8-bit/color RGBA, interlaced
downloaded
Chrome Cache Entry: 125
gzip compressed data, from Unix, original size modulo 2^32 44434
downloaded
Chrome Cache Entry: 126
Unicode text, UTF-8 text, with very long lines (64880), with no line terminators
downloaded
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 20920, version 1.0
downloaded
Chrome Cache Entry: 128
Unicode text, UTF-8 text, with very long lines (28860)
downloaded
Chrome Cache Entry: 129
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 130
MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (36846)
downloaded
Chrome Cache Entry: 133
Web Open Font Format (Version 2), TrueType, length 20848, version 1.0
downloaded
Chrome Cache Entry: 134
Web Open Font Format, TrueType, length 35241, version 0.0
downloaded
Chrome Cache Entry: 135
Web Open Font Format (Version 2), TrueType, length 26180, version 1.0
downloaded
Chrome Cache Entry: 136
PNG image data, 219 x 43, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 137
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 138
Web Open Font Format (Version 2), TrueType, length 18128, version 1.0
downloaded
Chrome Cache Entry: 139
Unicode text, UTF-8 text, with very long lines (64880), with no line terminators
dropped
Chrome Cache Entry: 140
PNG image data, 1440 x 225, 8-bit/color RGBA, interlaced
dropped
Chrome Cache Entry: 141
Unicode text, UTF-8 text, with very long lines (36846)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (31921), with no line terminators
downloaded
Chrome Cache Entry: 143
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 144
PNG image data, 219 x 43, 8-bit colormap, non-interlaced
downloaded
There are 15 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2352 --field-trial-handle=2028,i,15076331900883378116,17662837165647517080,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://demettei.com"

URLs

Name
IP
Malicious
http://demettei.com
malicious
http://demettei.com/
malicious
http://g.co/ng/security#xss).
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://angular.io/license
unknown
https://www.namecheap.com/
unknown
http://g.co/ng/security#xss)
unknown
https://www.namecheap.com/support/live-chat/general.aspx?loc
unknown
https://angular.io/
unknown

Domains

Name
IP
Malicious
demettei.com
198.54.117.242
malicious
bg.microsoft.map.fastly.net
199.232.210.172
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
www.google.com
172.217.16.196
fp2e7a.wpc.phicdn.net
192.229.221.95
www.namecheap.com
unknown
static.nc-img.com
unknown

IPs

IP
Domain
Country
Malicious
198.54.117.242
demettei.com
United States
malicious
239.255.255.250
unknown
Reserved
192.168.2.4
unknown
unknown
172.217.16.196
www.google.com
United States

DOM / HTML

URL
Malicious
http://demettei.com/
malicious
http://demettei.com/