IOC Report
http://ionl.ca

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Dec 24 11:43:35 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\Downloads\downloaded.pdf (copy)
PDF document, version 1.7
dropped
C:\Users\user\Downloads\downloaded.pdf.crdownload (copy)
PDF document, version 1.7
dropped
C:\Users\user\Downloads\e325695b-ea4a-4ebe-9499-10a61d315959.tmp
PDF document, version 1.7
dropped
Chrome Cache Entry: 112
PNG image data, 236 x 236, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 113
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 115
gzip compressed data, from Unix, original size modulo 2^32 139894
downloaded
Chrome Cache Entry: 116
gzip compressed data, from Unix, original size modulo 2^32 112427
downloaded
Chrome Cache Entry: 119
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1950x675, components 3
downloaded
Chrome Cache Entry: 120
gzip compressed data, from Unix, original size modulo 2^32 1059
dropped
Chrome Cache Entry: 121
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 122
gzip compressed data, from Unix, original size modulo 2^32 58023
downloaded
Chrome Cache Entry: 123
very short file (no magic)
dropped
Chrome Cache Entry: 124
gzip compressed data, from Unix, original size modulo 2^32 28266
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (6075), with no line terminators
downloaded
Chrome Cache Entry: 132
gzip compressed data, from Unix, original size modulo 2^32 30302
downloaded
Chrome Cache Entry: 134
PNG image data, 249 x 130, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (1146)
downloaded
Chrome Cache Entry: 140
gzip compressed data, from Unix, original size modulo 2^32 47104
downloaded
Chrome Cache Entry: 141
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 810x440, components 3
dropped
Chrome Cache Entry: 145
gzip compressed data, from Unix, original size modulo 2^32 458836
downloaded
Chrome Cache Entry: 147
gzip compressed data, from Unix, original size modulo 2^32 13577
dropped
Chrome Cache Entry: 149
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 82", baseline, precision 8, 400x450, components 3
dropped
Chrome Cache Entry: 150
gzip compressed data, from Unix, original size modulo 2^32 149934
downloaded
Chrome Cache Entry: 151
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 855x525, components 3
downloaded
Chrome Cache Entry: 153
gzip compressed data, from Unix, original size modulo 2^32 87553
downloaded
Chrome Cache Entry: 155
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1350x300, components 3
dropped
Chrome Cache Entry: 157
gzip compressed data, from Unix, original size modulo 2^32 323042
downloaded
Chrome Cache Entry: 158
gzip compressed data, max compression, original size modulo 2^32 46274
downloaded
Chrome Cache Entry: 159
gzip compressed data, from Unix, original size modulo 2^32 14560
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (2019)
dropped
Chrome Cache Entry: 164
gzip compressed data, from Unix, original size modulo 2^32 17478
downloaded
Chrome Cache Entry: 166
gzip compressed data, from Unix, original size modulo 2^32 50394
downloaded
Chrome Cache Entry: 168
PNG image data, 30 x 30, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 170
gzip compressed data, from Unix, original size modulo 2^32 23409
downloaded
Chrome Cache Entry: 171
Web Open Font Format (Version 2), TrueType, length 24268, version 1.0
downloaded
Chrome Cache Entry: 174
ASCII text
dropped
Chrome Cache Entry: 175
Web Open Font Format (Version 2), TrueType, length 25948, version 1.0
downloaded
Chrome Cache Entry: 177
gzip compressed data, from Unix, original size modulo 2^32 24998
downloaded
Chrome Cache Entry: 180
ASCII text
downloaded
Chrome Cache Entry: 181
gzip compressed data, from Unix, original size modulo 2^32 59946
downloaded
Chrome Cache Entry: 182
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 183
gzip compressed data, from Unix, original size modulo 2^32 119386
dropped
There are 40 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://ionl.ca
http://ionl.ca/wp-content/plugins/js_composer/assets/css/js_composer.min.css?ver=7.9
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/2016/11/bk-testimonials.jpg?id=551
69.49.101.51
malicious
http://ionl.ca/favicon-32x32.png
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/revslider/public/assets/assets/loader.gif
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap.min.css?ver=20150930
69.49.101.51
malicious
http://ionl.ca/wp-includes/css/dist/block-library/style.min.css?ver=6.6.2
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/style.css?ver=20150930
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rbtools.min.js?ver=6.2.17
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/assets/js/skip-link-focus-fix.js?ver=20151112
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/2021/06/Global-Seating-7-Day-Quick-Ship-Program3.pdf
malicious
http://ionl.ca/favicon-16x16.png
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/2016/11/header01.jpg
69.49.101.51
malicious
http://ionl.ca/favicon-96x96.png
69.49.101.51
malicious
http://ionl.ca/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/animate.css?ver=5.0.5
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/ays-popup-box/public/css/ays-pb-public-min.css?ver=5.0.5
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/js_composer/custom.css?ver=7.9
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/2016/11/500-IMG_2508_855x525.jpg
69.49.101.51
malicious
http://ionl.ca/
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/2016/11/circleFit.png
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rs6.min.js?rev=6.2.17
69.49.101.51
malicious
http://ionl.ca/wp-includes/images/w-logo-blue-white-bg.png
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/assets/img/logo-top.png
69.49.101.51
malicious
http://ionl.ca/wp-admin/admin-ajax.php
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/assets/img/facebook-30.png
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/assets/js/bootstrap.min.js?ver=20151204
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rbtools.min.js?rev=6.2.17
69.49.101.51
malicious
http://ionl.ca/android-icon-192x192.png
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/ays-popup-box/public/js/ays-pb-public.js?ver=5.0.5
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/2016/11/mkt_workplace_810x440.jpg
69.49.101.51
malicious
http://ionl.ca/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/assets/genericons/genericons.css?ver=3.4.1
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/style.css?ver=6.6.2
69.49.101.51
malicious
http://ionl.ca/wp-content/uploads/2016/11/installation-400x450.jpg
69.49.101.51
malicious
http://ionl.ca/wp-content/themes/prime/assets/css/bootstrap-theme.min.css?ver=20150930
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/revslider/public/assets/css/rs6.css?ver=6.2.17
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/revslider/public/assets/js/rs6.min.js?ver=6.2.17
69.49.101.51
malicious
http://ionl.ca/wp-content/plugins/js_composer/assets/js/dist/js_composer_front.min.js?ver=7.9
69.49.101.51
malicious
http://ionl.ca/favicon.ico
69.49.101.51
malicious
file:///C:/Users/user/Downloads/downloaded.pdf
http://count.carrierzone.com/track/ctin.php?t=1735044226030&custnum=c291e5e867c41a37&sname=ionl.ca&pagename=php5-cgi&group=%2Fservices%2Fwebpages%2Fi%2Fo%2Fionl.ca%2Fcgi-bin&version=%24Rev%3A%207840%20%24&js=1&jv=0&resolution=1280x1024&color_depth=24&campaign=&referrer=&page_url=http%253A%252F%252Fionl.ca%252F&plugins=PDF%20Viewer%3BChrome%20PDF%20Viewer%3BChromium%20PDF%20Viewer%3BMicrosoft%20Edge%20PDF%20Viewer%3BWebKit%20built-in%20PDF%3B
66.175.41.113
There are 31 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ionl.ca
69.49.101.51
fast.fonts.net
104.16.40.28
www.google.com
172.217.21.36
count.carrierzone.com
66.175.41.113

IPs

IP
Domain
Country
Malicious
172.217.19.206
unknown
United States
172.217.19.238
unknown
United States
1.1.1.1
unknown
Australia
172.217.17.35
unknown
United States
192.168.2.17
unknown
unknown
192.168.2.16
unknown
unknown
216.58.208.227
unknown
United States
69.49.101.51
ionl.ca
United States
142.250.181.104
unknown
United States
239.255.255.250
unknown
Reserved
66.175.41.113
count.carrierzone.com
United States
172.217.21.35
unknown
United States
64.233.161.84
unknown
United States
172.217.17.40
unknown
United States
172.217.21.36
www.google.com
United States
142.250.181.78
unknown
United States
172.217.19.10
unknown
United States
216.239.36.178
unknown
United States
104.16.40.28
fast.fonts.net
United States
There are 9 hidden IPs, click here to show them.