IOC Report
https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 115
PNG image data, 45 x 45, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 116
PNG image data, 45 x 45, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 117
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 118
HTML document, ASCII text, with very long lines (410)
downloaded
Chrome Cache Entry: 119
Web Open Font Format (Version 2), TrueType, length 18596, version 1.0
downloaded
Chrome Cache Entry: 120
troff or preprocessor input, ASCII text, with very long lines (372)
downloaded
Chrome Cache Entry: 121
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 122
HTML document, ASCII text, with very long lines (410)
downloaded
Chrome Cache Entry: 123
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1324x900, components 3
downloaded
Chrome Cache Entry: 124
PNG image data, 1000 x 750, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 125
Web Open Font Format (Version 2), TrueType, length 18588, version 1.0
downloaded
Chrome Cache Entry: 126
PNG image data, 1000 x 750, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 127
JSON data
dropped
Chrome Cache Entry: 128
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 129
ASCII text
downloaded
Chrome Cache Entry: 130
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 131
JSON data
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 133
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1324x900, components 3
dropped
Chrome Cache Entry: 134
ASCII text, with no line terminators
downloaded
There are 11 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1980,i,12944064432080657643,2785131983954265400,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq"

URLs

Name
IP
Malicious
https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq
malicious
http://fontawesome.io
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.css
104.17.25.14
https://locate.ipinit.workers.dev/
unknown
http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd
unknown
https://cdn.jsdelivr.net/gh/uihkdslijsjd/captivating-app-lyoubgs5
unknown
https://onedrive.live.com/?authkey=%21AP4dQQ7hoSgcKIBIw%26cid=28E9EC3AAC12FF13%26id=28E9EC3AAC12FF13
unknown
http://www.inkscape.org/namespaces/inkscape
unknown
https://6481f63faf008522217341.cotradifyu.workers.dev/checkDomain
unknown
http://www.inkscape.org/)
unknown
https://ipapi.co/json/
104.26.9.44
http://creativecommons.org/ns#
unknown
http://fontawesome.io/license
unknown
There are 2 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sharefile8.pages.dev
188.114.97.3
malicious
ipapi.co
104.26.9.44
cdnjs.cloudflare.com
104.17.25.14
www.google.com
142.250.185.68
cdn.jsdelivr.net
unknown

IPs

IP
Domain
Country
Malicious
188.114.97.3
sharefile8.pages.dev
European Union
malicious
142.250.185.68
www.google.com
United States
192.168.2.7
unknown
unknown
104.26.9.44
ipapi.co
United States
239.255.255.250
unknown
Reserved
104.17.25.14
cdnjs.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://sharefile8.pages.dev/xit56kt7w1jt5s3mhgrdsk6odhghtvrycrdxoty84z4sucsd08bsbepa6wv52edrjl8mwcfcknpbcycsjetq74hex+dscntrcvkhpm4lzymvx+4sbhzddbr7tddsma1l785uupaxpd2t0gwjyuyrmto2jztaw84au7zieflszmmbu1leyxxtwf0ehetluu1jdzjigzq?ef5cb60b3eb712165be9aa2e8432255dm0haqp1l=U2FsdGVkX1%2F54Vi5k0fpJopgxlpTE%2Fwt1JbQBXUwtHI23IsXwilEibczOtXIyEafGUqvIxelPBKzraUcUZYsXddxVc0shoqZRiLuOtEQo8KQVHVVuhOjGpqAXb2ikXZcbMrR3pLVYbbERPy3QEAprq0jX%2F8t0p34IN%2BfftC4hK3%2Bs1g90JwifgjP3PTpK1aoAXRSeuyZNO%2BH9gJzHQNdJE58%2F1O7kPWQUEDNBeiPMexEwjzhqyPS9sJwf0XY9a6%2BVhLlq7y81V6%2FcHskp%2BgdCzxqfr2n7lQ1IzSUDClcGHZRzUhWfautY7xVjrLnzgh7ZdWqSUKbXwS23VjXs%2FdDRWpe82DNrAmaKQbf9Na%2B%2Bp6FxgINSz%2FMl0rbKTfp%2F%2FB8Lz5SQtpMofgzRCNhzPatp%2BV5xmEtnUqea565l6q9U5MRShooxYUyXTQVvbgAlt0sKy1Zn%2BcT%2FslFRCHHR0zWoJWY3C6nqLsoAd%2F%2FoO4Kuru019imWUO6zMl%2Bck5uBY464whKgUjunYedrNn084WCIbOmkMucwZLKqm3bOAd%2FibGCLBme5AHdSITb2ryus7xe9v4kpSTw2biTnqZDObxiPxx%2FlIUJVqeZ3GCPECdUF8rVpu8FzjC3cJ9NKqT7zzV6mx%2FvZ%2FeytMk04I%2BoShNpqBGNK%2F6JWx25ptmkQXmET2SmB3YR9%2BoDTAQc
malicious