IOC Report
Payment copy.HTML

loading gifFilesProcessesURLsDomainsIPsDOM105432Label

Files

File Path
Type
Category
Malicious
Download
Payment copy.HTML
HTML document, ASCII text, with very long lines (17642), with CRLF line terminators
initial sample
malicious
Chrome Cache Entry: 57
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=1, orientation=upper-left], baseline, precision 8, 1119x530, components 3
downloaded
Chrome Cache Entry: 58
PNG image data, 300 x 300, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 59
PNG image data, 300 x 300, 8-bit/color RGBA, non-interlaced
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2056,i,7512422396215173747,8855882059684338427,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2096 /prefetch:3
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "C:\Users\user\Desktop\Payment copy.HTML"

URLs

Name
IP
Malicious
file:///C:/Users/user/Desktop/Payment%20copy.HTML
malicious
https://thynkfinance.co.za/admin/save/mer.php
154.0.165.249
https://simgbb.com/images/favicon.png
172.67.131.251
https://i.ibb.co/favicon.ico
207.174.26.219
https://i.ibb.co/nBXYTs4/wrong-details.jpg

Domains

Name
IP
Malicious
simgbb.com
172.67.131.251
www.google.com
142.250.80.4
thynkfinance.co.za
154.0.165.249
i.ibb.co
207.174.26.219

IPs

IP
Domain
Country
Malicious
207.174.26.219
i.ibb.co
United States
172.67.131.251
simgbb.com
United States
192.168.2.4
unknown
unknown
142.250.80.4
www.google.com
United States
154.0.165.249
thynkfinance.co.za
South Africa

DOM / HTML

URL
Malicious
file:///C:/Users/user/Desktop/Payment%20copy.HTML
malicious
https://i.ibb.co/nBXYTs4/wrong-details.jpg