IOC Report
https://www.google.ca/url?q=1120091333775300779273902563687390256368&rct=11200913337753007792&sa=t&url=amp/s/elanpro.net/horeca/dispenc#YnJ1bml0YS5kdW5jYW5AcGFydG5lcnNtZ3UuY29t

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 44
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 45
ASCII text, with very long lines (11651), with CRLF line terminators
downloaded
Chrome Cache Entry: 46
PNG image data, 1871 x 308, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 47
PNG image data, 1871 x 308, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 48
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 49
HTML document, Unicode text, UTF-8 text, with CRLF line terminators
downloaded
Chrome Cache Entry: 50
JSON data
dropped
Chrome Cache Entry: 51
JSON data
downloaded
Chrome Cache Entry: 52
HTML document, Unicode text, UTF-8 text, with very long lines (4070)
downloaded
Chrome Cache Entry: 53
ASCII text, with very long lines (11651), with CRLF line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2208,i,7212603522079191459,456679769172930129,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.google.ca/url?q=1120091333775300779273902563687390256368&rct=11200913337753007792&sa=t&url=amp/s/elanpro.net/horeca/dispenc#YnJ1bml0YS5kdW5jYW5AcGFydG5lcnNtZ3UuY29t"

URLs

Name
IP
Malicious
https://www.google.ca/url?q=1120091333775300779273902563687390256368&rct=11200913337753007792&sa=t&url=amp/s/elanpro.net/horeca/dispenc#YnJ1bml0YS5kdW5jYW5AcGFydG5lcnNtZ3UuY29t
malicious
https://elanpro.net/horeca/dispenc/
85.187.128.58
malicious
https://elanpro.net/horeca/dispenc
85.187.128.58
malicious
https://elanpro.net/horeca/dispenc/script.js
85.187.128.58
malicious
https://elanpro.net/horeca/dispenc/#YnJ1bml0YS5kdW5jYW5AcGFydG5lcnNtZ3UuY29t
malicious
https://elanpro.net/horeca/dispenc/logo.png
85.187.128.58
https://www.google.ca/amp/s/elanpro.net/horeca/dispenc
142.250.181.35
https://www.google.ca/url?q=1120091333775300779273902563687390256368&rct=11200913337753007792&sa=t&url=amp/s/elanpro.net/horeca/dispenc
142.250.181.35
https://elanpro.net/horeca/dispenc/favicon.ico
85.187.128.58
http://cpanel.com/?utm_source=cpanelwhm&utm_medium=cplogo&utm_content=logolink&utm_campaign=404refer
unknown
https://go.cpanel.net/privacy
unknown
https://elanpro.net/horeca/dispenc/style.css
85.187.128.58
https://ipapi.co/json/
104.26.9.44
There are 2 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
elanpro.net
85.187.128.58
malicious
ipapi.co
104.26.9.44
www.google.ca
142.250.181.35
www.google.com
142.250.181.68

IPs

IP
Domain
Country
Malicious
85.187.128.58
elanpro.net
United States
malicious
239.255.255.250
unknown
Reserved
142.250.181.68
www.google.com
United States
142.250.181.35
www.google.ca
United States
192.168.2.6
unknown
unknown
104.26.9.44
ipapi.co
United States

DOM / HTML

URL
Malicious
https://elanpro.net/horeca/dispenc/#YnJ1bml0YS5kdW5jYW5AcGFydG5lcnNtZ3UuY29t
malicious
https://elanpro.net/horeca/dispenc/#YnJ1bml0YS5kdW5jYW5AcGFydG5lcnNtZ3UuY29t
malicious