IOC Report
https://mychaseexclusive.ru/case?token

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 106
gzip compressed data, from Unix, original size modulo 2^32 24051
downloaded
Chrome Cache Entry: 107
PNG image data, 54 x 54, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 108
gzip compressed data, from Unix, original size modulo 2^32 4405
downloaded
Chrome Cache Entry: 109
PNG image data, 54 x 54, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 110
ASCII text, with very long lines (7842), with no line terminators
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (7847), with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2080 --field-trial-handle=2036,i,9328697437574807042,17108672982110021698,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mychaseexclusive.ru/case?token"

URLs

Name
IP
Malicious
https://mychaseexclusive.ru/case?token
malicious
https://mychaseexclusive.ru/cdn-cgi/challenge-platform/scripts/jsd/main.js
104.21.7.89
https://a.nel.cloudflare.com/report/v4?s=rxlO9UktNCk1WpZt%2FRaLyVhjO9TyCiJJCa50qqChPRe%2FipDkm8B8exLp0dwMNty1umuPXK0xfftqKtHo3qa6HzvRCxRh9%2F%2FOS1KcFW1ypy33u3haqq%2FnV0XK4JvezsmF9UfwpJIU
35.190.80.1
https://a.nel.cloudflare.com/report/v4?s=mdahbD%2FjwG7qm03aphoIs4bAVE42ANheSYBpOhJZMKaukDh3aC6hoM02nvcC%2BuyBuXzk4y3S74v8eiXUsc2dQUdpBPxBvlRWV7vGyVHTmSRB6C2HEyHwhORilGfKhKN9%2Bb%2BvRWup
35.190.80.1
http://mychaseexclusive.ru/case/?token
https://mychaseexclusive.ru/cdn-cgi/challenge-platform/h/g/scripts/jsd/e7cf9275f425/main.js?
104.21.7.89
https://mychaseexclusive.ru/cdn-cgi/images/icon-exclamation.png?1376755637
104.21.7.89
http://mychaseexclusive.ru/cdn-cgi/styles/cf.errors.css
172.67.135.236
http://mychaseexclusive.ru/cdn-cgi/images/icon-exclamation.png?1376755637
172.67.135.236
https://mychaseexclusive.ru/case?token
https://a.nel.cloudflare.com/report/v4?s=ldypmoCwgyqJ%2FHVWxHY419f5RqLdMoOKP2p8kXZHnMnhfuFj%2FOvuriyxS9qDPyUNFh2b2nzi4DK2OwNMprh4v9ORGkD3Q7zY6FWCOJrDc%2FZTLX3cUbM%2Bpw4qaDYwSJRQ6xV8Cytz
35.190.80.1
http://mychaseexclusive.ru/favicon.ico
172.67.135.236
https://mychaseexclusive.ru/cdn-cgi/challenge-platform/h/g/jsd/r/8bc1ea757ae2437f
104.21.7.89
https://mychaseexclusive.ru/favicon.ico
104.21.7.89
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
www.google.com
142.250.185.132
mychaseexclusive.ru
104.21.7.89
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
104.21.7.89
mychaseexclusive.ru
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States
142.250.185.132
www.google.com
United States
172.67.135.236
unknown
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
http://mychaseexclusive.ru/case/?token
malicious
https://mychaseexclusive.ru/case?token
https://mychaseexclusive.ru/case?token