IOC Report
https://shibe-rium.net/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Dec 21 13:01:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Dec 21 13:01:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Dec 21 13:01:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Dec 21 13:01:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Dec 21 13:01:43 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 102
PNG image data, 3258 x 3258, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
Web Open Font Format, TrueType, length 67904, version 0.0
downloaded
Chrome Cache Entry: 105
ASCII text
downloaded
Chrome Cache Entry: 107
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 108
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 109
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 111
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 112
ASCII text, with very long lines (60819), with no line terminators
downloaded
Chrome Cache Entry: 113
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 119
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 120
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 122
ASCII text
downloaded
Chrome Cache Entry: 123
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 126
HTML document, ASCII text
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (448), with no line terminators
downloaded
Chrome Cache Entry: 128
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 131
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 133
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 134
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 136
ASCII text
downloaded
Chrome Cache Entry: 140
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 141
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 145
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 146
JSON data
downloaded
Chrome Cache Entry: 147
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 149
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (49847)
downloaded
Chrome Cache Entry: 152
ASCII text
downloaded
Chrome Cache Entry: 155
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 157
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 158
Unicode text, UTF-8 text, with very long lines (12127)
dropped
Chrome Cache Entry: 159
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 160
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 162
HTML document, ASCII text
downloaded
Chrome Cache Entry: 163
JSON data
downloaded
Chrome Cache Entry: 165
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 167
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 168
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 170
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 172
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 173
Web Open Font Format (Version 2), TrueType, length 48444, version 1.0
downloaded
Chrome Cache Entry: 84
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 87
ASCII text
downloaded
Chrome Cache Entry: 88
Web Open Font Format (Version 2), TrueType, length 46704, version 1.0
downloaded
Chrome Cache Entry: 89
Unicode text, UTF-8 (with BOM) text, with very long lines (50716)
downloaded
Chrome Cache Entry: 91
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 92
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 93
ASCII text, with very long lines (5474), with no line terminators
downloaded
Chrome Cache Entry: 95
ASCII text, with very long lines (383), with CRLF line terminators
downloaded
Chrome Cache Entry: 96
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 97
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 99
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x400, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
There are 50 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://shibe-rium.net/
malicious
https://shibe-rium.net/

Domains

Name
IP
Malicious
bafybeica3dmqsybrultp7zoqgb3ikcrp6e4ecmh6wknj7lx2zcu7z3rhfm.ipfs.flk-ipfs.xyz
152.42.156.84
malicious
shibe-rium.net
172.67.180.6
malicious
k8s-ingressn-bscmainn-aa4f814ccd-1188470650.ap-northeast-1.elb.amazonaws.com
13.231.40.247
a.nel.cloudflare.com
35.190.80.1
secure.walletconnect.org
104.18.21.250
cdnjs.cloudflare.com
104.17.24.14
api.web3modal.org
104.18.19.237
www.google.com
142.250.181.132
pulse.walletconnect.org
104.18.20.250
ipfs.io
209.94.90.1
cdn.jsdelivr.net
unknown
bsc-dataseed3.bnbchain.org
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.67.180.6
shibe-rium.net
United States
malicious
152.42.156.84
bafybeica3dmqsybrultp7zoqgb3ikcrp6e4ecmh6wknj7lx2zcu7z3rhfm.ipfs.flk-ipfs.xyz
United States
malicious
104.17.24.14
cdnjs.cloudflare.com
United States
172.217.19.206
unknown
United States
1.1.1.1
unknown
Australia
104.18.20.250
pulse.walletconnect.org
United States
104.18.186.31
unknown
United States
104.18.187.31
unknown
United States
104.18.19.237
api.web3modal.org
United States
172.217.17.35
unknown
United States
192.168.2.16
unknown
unknown
142.250.181.132
www.google.com
United States
172.217.19.234
unknown
United States
52.198.55.104
unknown
United States
104.18.21.250
secure.walletconnect.org
United States
239.255.255.250
unknown
Reserved
13.231.40.247
k8s-ingressn-bscmainn-aa4f814ccd-1188470650.ap-northeast-1.elb.amazonaws.com
United States
104.18.18.237
unknown
United States
64.233.162.84
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.181.67
unknown
United States
142.250.181.99
unknown
United States
209.94.90.1
ipfs.io
United States
There are 13 hidden IPs, click here to show them.