IOC Report
https://spotify-reactjs-dfe19.web.app/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Aug 27 21:14:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Aug 27 21:14:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Aug 27 21:14:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Aug 27 21:14:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Aug 27 21:14:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 101
JPEG image data, baseline, precision 8, 3159x1600, components 3
dropped
Chrome Cache Entry: 102
RIFF (little-endian) data, Web/P image, VP8 encoding, 3159x1600, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (65462)
downloaded
Chrome Cache Entry: 104
HTML document, ASCII text, with very long lines (3020), with no line terminators
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (7446)
dropped
Chrome Cache Entry: 106
JSON data
dropped
Chrome Cache Entry: 107
ASCII text, with very long lines (7446)
downloaded
Chrome Cache Entry: 108
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 109
Web Open Font Format (Version 2), TrueType, length 35596, version 1.6553
downloaded
Chrome Cache Entry: 110
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 111
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 112
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 113
Web Open Font Format (Version 2), TrueType, length 383268, version 1.6553
downloaded
Chrome Cache Entry: 114
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 115
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (1617), with no line terminators
downloaded
Chrome Cache Entry: 117
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 118
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (17796)
downloaded
Chrome Cache Entry: 120
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 121
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 122
JSON data
downloaded
Chrome Cache Entry: 123
MS Windows icon resource - 4 icons, 16x16 with PNG image data, 16 x 16, 8-bit colormap, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit colormap, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 124
data
downloaded
Chrome Cache Entry: 125
JSON data
downloaded
Chrome Cache Entry: 126
Web Open Font Format (Version 2), TrueType, length 44360, version 1.6553
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 128
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 83
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 84
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (1617), with no line terminators
dropped
Chrome Cache Entry: 86
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 87
ASCII text, with very long lines (17796)
dropped
Chrome Cache Entry: 88
data
dropped
Chrome Cache Entry: 89
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 90
ASCII text, with very long lines (65462)
dropped
Chrome Cache Entry: 91
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 92
Web Open Font Format (Version 2), TrueType, length 49948, version 1.6553
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (3460)
downloaded
Chrome Cache Entry: 94
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 95
MS Windows icon resource - 4 icons, 16x16 with PNG image data, 16 x 16, 8-bit colormap, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit colormap, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 96
ASCII text, with very long lines (56359), with no line terminators
downloaded
Chrome Cache Entry: 97
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 98
data
downloaded
Chrome Cache Entry: 99
Web Open Font Format (Version 2), TrueType, length 41412, version 1.6553
downloaded
There are 43 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2548 --field-trial-handle=2280,i,7565043867655982996,6664749042120349753,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://spotify-reactjs-dfe19.web.app/"

URLs

Name
IP
Malicious
https://spotify-reactjs-dfe19.web.app/
malicious
https://spotify-reactjs-dfe19.web.app/
malicious
https://music-b26f.kxcdn.com/wp-content/uploads/2017/06/635963274692858859903160895_spotify-logo-horizontal-black.jpg
185.172.148.128
https://www.google.com/js/bg/sr2BvsM2R_OZKHX83mSXJ8YBPDmTxOV2dVCuSpL6Gdo.js
172.217.16.196
https://www.google.com/recaptcha/enterprise/reload?k=6LfCVLAUAAAAALFwwRnnCJ12DalriUGbj8FW_J39
172.217.16.196
https://www.google.com/recaptcha/enterprise/
unknown
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://www.google.com/recaptcha/enterprise/webworker.js?hl=en&v=i7X0JrnYWy9Y_5EYdoFM79kV
172.217.16.196
https://github.com/zloirock/core-js/blob/v3.28.0/LICENSE
unknown
https://spotify-reactjs-dfe19.web.app/static/css/main.37722c5c.chunk.css
199.36.158.100
https://accounts.scdn.co/sso/images/new-google-icon.72fd940a229bc94cf9484a3320b3dccb.svg
199.232.210.248
https://github.com/zloirock/core-js
unknown
https://gue1-spclient.spotify.com/gabo-receiver-service/public/v3/events
35.186.224.9
https://support.google.com/recaptcha#6262736
unknown
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://recaptcha.net
unknown
https://accounts.spotify.com/en/login?continue=https%3A%2F%2Faccounts.spotify.com%2Fauthorize%3Fscope%3Duser-read-currently-playing%2Buser-read-recently-played%2Buser-read-playback-state%2Buser-top-read%2Buser-modify-playback-state%26response_type%3Dtoken%26redirect_uri%3Dhttps%253A%252F%252Fspotify-reactjs-dfe19.web.app%252F%26client_id%3D81a8fffed8b2423596544c5c0b04f9c8%26show_dialog%3Dtrue
https://spotify-reactjs-dfe19.web.app/static/js/2.7c16784d.chunk.js
199.36.158.100
https://accounts.scdn.co/sso/images/new-apple-icon.e356139ea90852da2e60f1ff738f3cbb.svg
199.232.210.248
https://accounts.scdn.co/sso/images/favicon.ace4d8543bbb017893402a1e9d1ac1fa.ico
199.232.210.248
https://spotify-reactjs-dfe19.web.app/static/js/main.bca06c34.chunk.js
199.36.158.100
https://accounts.scdn.co/sso/images/new-facebook-icon.eae8e1b6256f7ccf01cf81913254e70b.svg
199.232.210.248
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://cloud.google.com/contact
unknown
https://accounts.spotify.com/authorize?client_id=81a8fffed8b2423596544c5c0b04f9c8&redirect_uri=https://spotify-reactjs-dfe19.web.app/&scope=user-read-currently-playing%20user-read-recently-played%20user-read-playback-state%20user-top-read%20user-modify-playback-state&response_type=token&show_dialog=true
35.186.224.24
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://www.gstatic.c..?/recaptcha/releases/i7X0JrnYWy9Y_5EYdoFM79kV/recaptcha__.
unknown
https://gue1-spclient.spotify.com/remote-config-resolver/v3/unauth/configuration
35.186.224.9
https://www.google.com/recaptcha/enterprise/clr?k=6LfCVLAUAAAAALFwwRnnCJ12DalriUGbj8FW_J39
172.217.16.196
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://apresolve.spotify.com/?type=dealer&type=spclient
35.186.224.24
https://support.google.com/recaptcha/#6175971
unknown
https://accounts.scdn.co/sso/js/indexReact.d3eadb9576aa104d2004.js
199.232.210.248
https://www.google.com/recaptcha/enterprise.js?render=6LfCVLAUAAAAALFwwRnnCJ12DalriUGbj8FW_J39
142.250.185.196
https://spotify-reactjs-dfe19.web.app/favicon.ico
199.36.158.100
https://www.google.com/recaptcha/enterprise/anchor?ar=1&k=6LfCVLAUAAAAALFwwRnnCJ12DalriUGbj8FW_J39&co=aHR0cHM6Ly9hY2NvdW50cy5zcG90aWZ5LmNvbTo0NDM.&hl=en&v=i7X0JrnYWy9Y_5EYdoFM79kV&size=invisible&cb=ocz5estvidkm
172.217.16.196
https://www.google.com/recaptcha/api2/
unknown
https://www.google.com/recaptcha/enterprise/bcn?k=6LfCVLAUAAAAALFwwRnnCJ12DalriUGbj8FW_J39
172.217.16.196
https://spotify-reactjs-dfe19.web.app/manifest.json
199.36.158.100
https://support.google.com/recaptcha
unknown
https://spotify-reactjs-dfe19.web.app/logo192.png
199.36.158.100
There are 31 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
scdnco.spotify.map.fastly.net
199.232.210.248
p-defr00.kxcdn.com
185.172.148.128
bg.microsoft.map.fastly.net
199.232.214.172
edge-web-gue1.dual-gslb.spotify.com
35.186.224.9
www.google.com
142.250.185.68
apresolve.spotify.com
35.186.224.24
spotify-reactjs-dfe19.web.app
199.36.158.100
edge-web.dual-gslb.spotify.com
35.186.224.24
fp2e7a.wpc.phicdn.net
192.229.221.95
music-b26f.kxcdn.com
unknown
gue1-spclient.spotify.com
unknown
accounts.spotify.com
unknown
accounts.scdn.co
unknown
encore.scdn.co
unknown
There are 4 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
unknown
United States
142.250.185.68
www.google.com
United States
35.186.224.9
edge-web-gue1.dual-gslb.spotify.com
United States
192.168.2.4
unknown
unknown
35.186.224.24
apresolve.spotify.com
United States
192.168.2.5
unknown
unknown
199.36.158.100
spotify-reactjs-dfe19.web.app
United States
239.255.255.250
unknown
Reserved
185.172.148.128
p-defr00.kxcdn.com
Germany
142.250.185.196
unknown
United States
199.232.210.248
scdnco.spotify.map.fastly.net
United States
172.217.16.196
unknown
United States
There are 2 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://spotify-reactjs-dfe19.web.app/
https://accounts.spotify.com/en/login?continue=https%3A%2F%2Faccounts.spotify.com%2Fauthorize%3Fscope%3Duser-read-currently-playing%2Buser-read-recently-played%2Buser-read-playback-state%2Buser-top-read%2Buser-modify-playback-state%26response_type%3Dtoken%26redirect_uri%3Dhttps%253A%252F%252Fspotify-reactjs-dfe19.web.app%252F%26client_id%3D81a8fffed8b2423596544c5c0b04f9c8%26show_dialog%3Dtrue
https://accounts.spotify.com/en/login?continue=https%3A%2F%2Faccounts.spotify.com%2Fauthorize%3Fscope%3Duser-read-currently-playing%2Buser-read-recently-played%2Buser-read-playback-state%2Buser-top-read%2Buser-modify-playback-state%26response_type%3Dtoken%26redirect_uri%3Dhttps%253A%252F%252Fspotify-reactjs-dfe19.web.app%252F%26client_id%3D81a8fffed8b2423596544c5c0b04f9c8%26show_dialog%3Dtrue
https://accounts.spotify.com/en/login?continue=https%3A%2F%2Faccounts.spotify.com%2Fauthorize%3Fscope%3Duser-read-currently-playing%2Buser-read-recently-played%2Buser-read-playback-state%2Buser-top-read%2Buser-modify-playback-state%26response_type%3Dtoken%26redirect_uri%3Dhttps%253A%252F%252Fspotify-reactjs-dfe19.web.app%252F%26client_id%3D81a8fffed8b2423596544c5c0b04f9c8%26show_dialog%3Dtrue
https://accounts.spotify.com/en/login?continue=https%3A%2F%2Faccounts.spotify.com%2Fauthorize%3Fscope%3Duser-read-currently-playing%2Buser-read-recently-played%2Buser-read-playback-state%2Buser-top-read%2Buser-modify-playback-state%26response_type%3Dtoken%26redirect_uri%3Dhttps%253A%252F%252Fspotify-reactjs-dfe19.web.app%252F%26client_id%3D81a8fffed8b2423596544c5c0b04f9c8%26show_dialog%3Dtrue