IOC Report
https://esign.apple.com/viewer/esign/Package?sign=474896356b2b6d7e948018c4d85a4f294c4f6798a5684a9e0acaea6d5a0c4620152395

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (61121)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (61121)
dropped
Chrome Cache Entry: 102
MS Windows icon resource - 4 icons, 32x32, 8 bits/pixel, 16x16, 8 bits/pixel
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (1383), with no line terminators
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (464), with no line terminators
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (61816)
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (60050)
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (60050)
dropped
Chrome Cache Entry: 108
Unicode text, UTF-8 text, with very long lines (46964), with NEL line terminators
dropped
Chrome Cache Entry: 109
Unicode text, UTF-8 text, with very long lines (46673)
dropped
Chrome Cache Entry: 110
TrueType Font data, 15 tables, 1st "FFTM", 14 names, Macintosh, Copyright (c) 2018, Gurpreet Kaur Balgir1shared-iconsiconsFontForge 2.0 : shared-icons : 23-7-20
downloaded
Chrome Cache Entry: 111
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 112
ASCII text
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (65453)
dropped
Chrome Cache Entry: 114
MS Windows icon resource - 4 icons, 32x32, 8 bits/pixel, 16x16, 8 bits/pixel
downloaded
Chrome Cache Entry: 115
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 116
HTML document, Unicode text, UTF-8 text, with very long lines (11857)
dropped
Chrome Cache Entry: 117
Unicode text, UTF-8 text, with very long lines (46673)
downloaded
Chrome Cache Entry: 118
Web Open Font Format (Version 2), TrueType, length 117056, version 1.0
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (12505)
dropped
Chrome Cache Entry: 120
Web Open Font Format (Version 2), TrueType, length 219668, version 1.0
downloaded
Chrome Cache Entry: 121
Unicode text, UTF-8 text, with very long lines (45262)
downloaded
Chrome Cache Entry: 122
Unicode text, UTF-8 text, with very long lines (47124), with NEL line terminators
downloaded
Chrome Cache Entry: 123
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (65453)
downloaded
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (46964), with NEL line terminators
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (1621)
dropped
Chrome Cache Entry: 78
ASCII text, with very long lines (5809), with no line terminators
dropped
Chrome Cache Entry: 79
ASCII text
dropped
Chrome Cache Entry: 80
Unicode text, UTF-8 text, with very long lines (47124), with NEL line terminators
dropped
Chrome Cache Entry: 81
Unicode text, UTF-8 text, with very long lines (65366), with no line terminators
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (61816)
dropped
Chrome Cache Entry: 83
ASCII text, with very long lines (65457)
dropped
Chrome Cache Entry: 84
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (464), with no line terminators
downloaded
Chrome Cache Entry: 86
ASCII text, with very long lines (44491), with no line terminators
dropped
Chrome Cache Entry: 87
ASCII text, with very long lines (1621)
downloaded
Chrome Cache Entry: 88
Unicode text, UTF-8 text, with very long lines (64979), with no line terminators
downloaded
Chrome Cache Entry: 89
ASCII text
downloaded
Chrome Cache Entry: 90
Web Open Font Format (Version 2), TrueType, length 220536, version 1.0
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (44491), with no line terminators
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (5809), with no line terminators
downloaded
Chrome Cache Entry: 93
Unicode text, UTF-8 text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 94
ASCII text, with very long lines (12505)
downloaded
Chrome Cache Entry: 95
ASCII text
dropped
Chrome Cache Entry: 96
Unicode text, UTF-8 text, with very long lines (64945), with no line terminators
downloaded
Chrome Cache Entry: 97
HTML document, Unicode text, UTF-8 text, with very long lines (11857)
downloaded
Chrome Cache Entry: 98
Web Open Font Format (Version 2), TrueType, length 14140, version 1.0
downloaded
Chrome Cache Entry: 99
Unicode text, UTF-8 text, with very long lines (64142), with no line terminators
downloaded
There are 40 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2668 --field-trial-handle=2248,i,9712547824399784724,7215601815386536474,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://esign.apple.com/viewer/esign/Package?sign=474896356b2b6d7e948018c4d85a4f294c4f6798a5684a9e0acaea6d5a0c4620152395"

URLs

Name
IP
Malicious
https://esign.apple.com/viewer/esign/Package?sign=474896356b2b6d7e948018c4d85a4f294c4f6798a5684a9e0acaea6d5a0c4620152395
http://www.apache.org/licenses/LICENSE-2.0
unknown
http://baris.aydinoglu.info)
unknown
https://web.archive.org/web/20180602074607/https://daneden.me/2011/12/14/putting-up-with-androids-bu
unknown
https://github.com/zloirock/core-js
unknown
https://paulirish.com/demo/inline-svg
unknown
https://developer.mozilla.org/en-US/docs/Web/CSS/filter
unknown
https://stackoverflow.com/questions/3952009/defer-attribute-chrome#answer-3982619
unknown
http://barisaydinoglu.github.com/Detectizr/
unknown
https://developer.mozilla.org/en-US/docs/Web/API/Window/scrollTo
unknown
https://codepen.io/eltonmesquita/full/GgXbvo/
unknown
https://developer.mozilla.org/en/docs/HTML/Using_the_application_cache
unknown
https://github.com/zloirock/core-js/blob/v3.36.0/LICENSE
unknown
http://github.com/Modernizr/Modernizr/issues/1182
unknown
https://dev.w3.org/csswg/css3-conditional/#the-csssupportsrule-interface
unknown
http://canjs.com/
unknown
https://jquery.org/license
unknown
http://srufaculty.sru.edu/david.dailey/svg/newstuff/clipPath4.svg
unknown
https://bugs.chromium.org/p/chromium/issues/detail?id=129004
unknown
https://css-tricks.com/almanac/properties/a/appearance/
unknown
https://developers.whatwg.org/links.html#downloading-resources
unknown
https://developer.mozilla.org/en-US/docs/Web/CSS/-moz-appearance
unknown
https://feross.org/opensource
unknown
https://html.spec.whatwg.org/multipage/semantics.html#attr-style-scoped
unknown
https://jquery.com/
unknown
https://github.com/Modernizr/Modernizr/issues/648
unknown
https://developer.mozilla.org/en-US/docs/Web/API/HTMLCanvasElement.toDataURL
unknown
https://w3c.github.io/FileAPI/#constructorBlob
unknown
https://html.spec.whatwg.org/multipage/interaction.html#contenteditable
unknown
https://drafts.fxtf.org/compositing-1/
unknown
http://feross.org
unknown
https://developer.mozilla.org/en-US/docs/Web/API/Clipboard_API
unknown
https://dev.w3.org/csswg/css3-conditional/#at-supports
unknown
http://yepnopejs.com.
unknown
https://developer.mozilla.org/en-US/docs/Web/API/Clipboard
unknown
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
s-part-0017.t-0009.t-msedge.net
13.107.246.45
s-part-0015.t-0009.t-msedge.net
13.107.246.43
www.google.com
142.250.186.68
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved

DOM / HTML

URL
Malicious
https://idmsa.apple.com/signin?appIdKey=bc554407d96ae443427dc03543d6eb6f0a5f88faaa68f2b2b62b090e2bde5bc9&Env=PROD&view=6&language=US-EN&rv=2&path=/esign/Package?sign=474896356b2b6d7e948018c4d85a4f294c4f6798a5684a9e0acaea6d5a0c4620152395
https://idmsa.apple.com/signin?appIdKey=bc554407d96ae443427dc03543d6eb6f0a5f88faaa68f2b2b62b090e2bde5bc9&Env=PROD&view=6&language=US-EN&rv=2&path=/esign/Package?sign=474896356b2b6d7e948018c4d85a4f294c4f6798a5684a9e0acaea6d5a0c4620152395
https://idmsa.apple.com/signin?appIdKey=bc554407d96ae443427dc03543d6eb6f0a5f88faaa68f2b2b62b090e2bde5bc9&Env=PROD&view=6&language=US-EN&rv=2&path=/esign/Package?sign=474896356b2b6d7e948018c4d85a4f294c4f6798a5684a9e0acaea6d5a0c4620152395
https://idmsa.apple.com/signin?appIdKey=bc554407d96ae443427dc03543d6eb6f0a5f88faaa68f2b2b62b090e2bde5bc9&Env=PROD&view=6&language=US-EN&rv=2&path=/esign/Package?sign=474896356b2b6d7e948018c4d85a4f294c4f6798a5684a9e0acaea6d5a0c4620152395