Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Chrome Cache Entry: 60
|
ASCII text, with very long lines (48316), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 61
|
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 62
|
ASCII text, with very long lines (47671)
|
dropped
|
||
Chrome Cache Entry: 63
|
ASCII text, with very long lines (47671)
|
downloaded
|
||
Chrome Cache Entry: 64
|
PNG image data, 646 x 606, 8-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 65
|
ASCII text, with very long lines (513), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 66
|
ASCII text, with very long lines (48316), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 67
|
very short file (no magic)
|
dropped
|
||
Chrome Cache Entry: 68
|
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 69
|
ASCII text, with very long lines (65447)
|
dropped
|
||
Chrome Cache Entry: 70
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 71
|
ASCII text, with very long lines (65447)
|
downloaded
|
||
Chrome Cache Entry: 72
|
ASCII text, with very long lines (513), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 73
|
ASCII text, with very long lines (41651)
|
dropped
|
||
Chrome Cache Entry: 74
|
HTML document, ASCII text, with very long lines (955), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 75
|
PNG image data, 60 x 95, 8-bit/color RGB, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 76
|
very short file (no magic)
|
downloaded
|
||
Chrome Cache Entry: 77
|
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
|
downloaded
|
||
Chrome Cache Entry: 78
|
PNG image data, 646 x 606, 8-bit colormap, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 79
|
PNG image data, 60 x 95, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 80
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 81
|
HTML document, ASCII text
|
downloaded
|
||
Chrome Cache Entry: 82
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 83
|
ASCII text, with very long lines (32089)
|
dropped
|
||
Chrome Cache Entry: 84
|
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 85
|
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
|
dropped
|
||
Chrome Cache Entry: 86
|
PNG image data, 300 x 169, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 87
|
ASCII text, with very long lines (41651)
|
downloaded
|
||
Chrome Cache Entry: 88
|
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 89
|
ASCII text, with very long lines (32089)
|
downloaded
|
||
Chrome Cache Entry: 90
|
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 91
|
HTML document, ASCII text
|
downloaded
|
||
Chrome Cache Entry: 92
|
Web Open Font Format, TrueType, length 26288, version 0.0
|
downloaded
|
||
Chrome Cache Entry: 93
|
HTML document, ASCII text, with very long lines (5517), with CRLF line terminators
|
downloaded
|
||
Chrome Cache Entry: 94
|
Unicode text, UTF-8 text, with very long lines (64241)
|
downloaded
|
There are 26 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2016,i,9771467438753913643,17733773661878227230,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://track.reviewmgr.com/ls/click?upn=u001.W5y-2Fhe84rCuLxXDO470nfuKD2Iz98QeQpE-2BkxRR0H-2BqB5cDKklujIJ5FLru7QrAASOSa17vR-2FSCLVAx4lWyy5Q-3D-3DNnGv_Yp4ydSxZWNatis3HtI6bBrJjg57JYwT6kbyY2f89Z-2FBhxNJZyCBl9w6yXNV0YfiKUAGjaILaAN0mF43Ydvv3aAXjCPBMrYvHXhqj-2F90M8IWSluK-2FDr0h4-2FIbAXpExZIWOjtRSKBCrpvm-2BHKZd6Q2itOPvvv8Wh8uHJq1rbQgzA92MMGG0eeFCZzQMnosAWydLTI7R4yQPl90fJpGVjewvRcCF77tY5-2B3PAHwq6SU-2Fc2kSK8E1mMumIEdp0dsw2BfptVK6-2FXO4Hh-2FAV8-2FJ5YFUs6qp3oyRx3LiWrBnDVYrVE-3D"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://track.reviewmgr.com/ls/click?upn=u001.W5y-2Fhe84rCuLxXDO470nfuKD2Iz98QeQpE-2BkxRR0H-2BqB5cDKklujIJ5FLru7QrAASOSa17vR-2FSCLVAx4lWyy5Q-3D-3DNnGv_Yp4ydSxZWNatis3HtI6bBrJjg57JYwT6kbyY2f89Z-2FBhxNJZyCBl9w6yXNV0YfiKUAGjaILaAN0mF43Ydvv3aAXjCPBMrYvHXhqj-2F90M8IWSluK-2FDr0h4-2FIbAXpExZIWOjtRSKBCrpvm-2BHKZd6Q2itOPvvv8Wh8uHJq1rbQgzA92MMGG0eeFCZzQMnosAWydLTI7R4yQPl90fJpGVjewvRcCF77tY5-2B3PAHwq6SU-2Fc2kSK8E1mMumIEdp0dsw2BfptVK6-2FXO4Hh-2FAV8-2FJ5YFUs6qp3oyRx3LiWrBnDVYrVE-3D
|
|||
https://outlook.live.com/owa/
|
unknown
|
||
https://challenges.cloudflare.com/turnstile/v0/b/22755d9a86c9/api.js
|
104.18.95.41
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/580186821:1731486799:L15uSl2S2oz7sSBzYo9oO64Bd3brU5IorAMRCUVOQ2Y/8e1d7e7cfa6ce976/y4eeYO8EAvmSo5_Ut9Johd9NjIP02ufcG_1sSXienuA-1731487615-1.1.1.1-iOUHIjqfFP8b3VHxwElRmM.zBfHWMduDV76h2tLJ.6krXvSTVE7i1FmX_aGlP2hx
|
104.18.94.41
|
||
https://code.jquery.com/jquery-3.6.0.min.js
|
151.101.194.137
|
||
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
|
104.17.24.14
|
||
https://www.skype.com/en/
|
unknown
|
||
https://products.office.com/en-us/home
|
unknown
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/r3uc1/0x4AAAAAAAzp36y1dwMj6-Na/auto/fbE/normal/auto/
|
104.18.94.41
|
||
https://assets.onestore.ms/cdnfiles/external/mwf/long/v1/v1.25.0/css/mwf-west-european-default.min.c
|
unknown
|
||
https://a0lbahle9srt6glzryjiewm5r8vuhn2g0my1vsksssdezcuuewoegs31uioa.pafcoedru.com/YmSgfQKuAjCpKLPowScJtInfuhWEMLQGKYCCMWHBOIDYMBSRGMEWD
|
188.114.97.3
|
||
https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.9.1.min.js
|
unknown
|
||
https://y16.erdleptalmi.com/FN84h/
|
172.67.175.208
|
||
https://www.yoca.be/wp-content/uploads/2020/05/Onedrive-logo.png
|
188.208.37.13
|
||
https://y16.erdleptalmi.com/favicon.ico
|
172.67.175.208
|
||
https://onedrive.live.com/
|
13.107.137.11
|
||
https://onedrive.live.com/about/en-us/
|
unknown
|
||
https://products.office.com/en-us/microsoft-teams/free?icid=SSM_AS_Promo_Apps_MicrosoftTeams
|
unknown
|
||
https://www.onenote.com/
|
unknown
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1
|
104.18.94.41
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8e1d7e7cfa6ce976&lang=auto
|
104.18.94.41
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8e1d7e7cfa6ce976/1731487618133/qJ473e5fMMYdkWx
|
104.18.94.41
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8e1d7e7cfa6ce976/1731487618129/c7c5c9753bb562d2050c85a30c531ed3442b5f281b767323f55e1ba2a4fff4d4/qmNCpGDY_884fg1
|
104.18.94.41
|
||
https://a.nel.cloudflare.com/report/v4?s=WiHpK7qX2Ys6UNWUX5JbNg8tg%2FNZOSSVCQrdzYKORZQZVAaOeGN8bSYAqHZMkuuRCuW2%2B%2BztD7jKiPAJbcuU0AqFhjx6r0ewucbfkI1d%2BDBnrREbl2VJh2DdYJOvwg%3D%3D
|
35.190.80.1
|
||
https://www.qlicnfp.com/wp-content/uploads/2023/03/onedrive-300x169.png
|
141.193.213.21
|
||
https://media.istockphoto.com/id/1176645479/vector/abstract-modern-background-with-hexagonal-pattern
|
unknown
|
||
https://www.xbox.com/
|
unknown
|
||
http://schema.org/Organization
|
unknown
|
||
http://github.com/requirejs/almond/LICENSE
|
unknown
|
||
https://y16.erdleptalmi.com/FN84h/#Tx0qcve%40lhhg.net
|
|||
https://media.istockphoto.com/id/1176645479/vector/abstract-modern-background-with-hexagonal-pattern.jpg
|
13.224.189.91
|
There are 20 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
a.nel.cloudflare.com
|
35.190.80.1
|
||
d2eyuaod6pyfet.cloudfront.net
|
52.85.49.39
|
||
a0lbahle9srt6glzryjiewm5r8vuhn2g0my1vsksssdezcuuewoegs31uioa.pafcoedru.com
|
188.114.97.3
|
||
s-part-0017.t-0009.t-msedge.net
|
13.107.246.45
|
||
81zzmywdsyna.wpeproxy.com
|
141.193.213.21
|
||
fp2e7a.wpc.phicdn.net
|
192.229.221.95
|
||
bg.microsoft.map.fastly.net
|
199.232.214.172
|
||
dual-spov-0006.spov-msedge.net
|
13.107.137.11
|
||
www.yoca.be
|
188.208.37.13
|
||
media.istockphoto.com
|
13.224.189.91
|
||
code.jquery.com
|
151.101.194.137
|
||
cdnjs.cloudflare.com
|
104.17.24.14
|
||
challenges.cloudflare.com
|
104.18.95.41
|
||
www.google.com
|
142.250.185.164
|
||
y16.erdleptalmi.com
|
172.67.175.208
|
||
www.qlicnfp.com
|
unknown
|
||
www.onedrive.com
|
unknown
|
||
assets.onestore.ms
|
unknown
|
||
ajax.aspnetcdn.com
|
unknown
|
||
c.s-microsoft.com
|
unknown
|
||
onedrive.live.com
|
unknown
|
||
track.reviewmgr.com
|
unknown
|
There are 12 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
104.18.94.41
|
unknown
|
United States
|
||
192.168.2.4
|
unknown
|
unknown
|
||
141.193.213.21
|
81zzmywdsyna.wpeproxy.com
|
United States
|
||
142.250.185.164
|
www.google.com
|
United States
|
||
192.168.2.23
|
unknown
|
unknown
|
||
141.193.213.20
|
unknown
|
United States
|
||
151.101.194.137
|
code.jquery.com
|
United States
|
||
35.190.80.1
|
a.nel.cloudflare.com
|
United States
|
||
104.17.24.14
|
cdnjs.cloudflare.com
|
United States
|
||
13.107.137.11
|
dual-spov-0006.spov-msedge.net
|
United States
|
||
172.67.175.208
|
y16.erdleptalmi.com
|
United States
|
||
104.18.95.41
|
challenges.cloudflare.com
|
United States
|
||
52.85.49.39
|
d2eyuaod6pyfet.cloudfront.net
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
188.114.97.3
|
a0lbahle9srt6glzryjiewm5r8vuhn2g0my1vsksssdezcuuewoegs31uioa.pafcoedru.com
|
European Union
|
||
192.168.2.13
|
unknown
|
unknown
|
||
13.224.189.91
|
media.istockphoto.com
|
United States
|
||
192.168.2.14
|
unknown
|
unknown
|
||
188.208.37.13
|
www.yoca.be
|
Belgium
|
There are 9 hidden IPs, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://statementshare.z13.web.core.windows.net/
|
||
https://y16.erdleptalmi.com/FN84h/#Tx0qcve%40lhhg.net
|
||
https://y16.erdleptalmi.com/FN84h/#Tx0qcve%40lhhg.net
|
||
https://www.microsoft.com/en-us/microsoft-365/onedrive/online-cloud-storage
|