IOC Report
http://specsavers.definition-ai.com

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 126
ASCII text, with very long lines (23152), with no line terminators
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (41895)
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (12904), with no line terminators
downloaded
Chrome Cache Entry: 129
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 130
ASCII text, with very long lines (3269), with no line terminators
downloaded
Chrome Cache Entry: 131
Unicode text, UTF-8 text, with very long lines (48660)
dropped
Chrome Cache Entry: 132
ASCII text, with very long lines (426), with no line terminators
downloaded
Chrome Cache Entry: 133
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 134
Web Open Font Format (Version 2), TrueType, length 7848, version 1.0
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (23152), with no line terminators
dropped
Chrome Cache Entry: 136
Web Open Font Format (Version 2), TrueType, length 7900, version 1.0
downloaded
Chrome Cache Entry: 137
Unicode text, UTF-8 text, with very long lines (50649)
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 139
Unicode text, UTF-8 text, with very long lines (50649)
dropped
Chrome Cache Entry: 140
ASCII text, with very long lines (65199)
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (19816)
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (12904), with no line terminators
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (4152)
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (8647), with no line terminators
dropped
Chrome Cache Entry: 145
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 146
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (426), with no line terminators
dropped
Chrome Cache Entry: 148
OpenType font data
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (7532)
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (41895)
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (8647), with no line terminators
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (65199)
dropped
Chrome Cache Entry: 153
Web Open Font Format (Version 2), TrueType, length 7844, version 1.0
downloaded
Chrome Cache Entry: 154
Web Open Font Format (Version 2), TrueType, length 7740, version 1.0
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 156
Unicode text, UTF-8 text, with very long lines (48660)
downloaded
Chrome Cache Entry: 157
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (19816)
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (7532)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (4152)
downloaded
Chrome Cache Entry: 161
PNG image data, 1920 x 1280, 8-bit colormap, non-interlaced
dropped
There are 27 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2352,i,1481569288622164102,13270313291281258887,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://specsavers.definition-ai.com"

URLs

Name
IP
Malicious
http://specsavers.definition-ai.com
malicious
https://specsavers.definition-ai.com/auth/login
malicious
https://specsavers.definition-ai.com/icon?2581566d8d559f65
76.76.21.123
https://specsavers.definition-ai.com/_next/static/media/eafabf029ad39a43-s.p.woff2
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/main-app-92f88ab7472179c3.js
76.76.21.123
https://feross.org
unknown
https://specsavers.definition-ai.com/_next/static/chunks/app/auth/login/page-3b101f329b6b359c.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/801-fa4e08147b8488e8.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/media/4c285fdca692ea22-s.p.woff2
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/951-f1aa8407b94e84d2.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/87bc1fd9-d16e78bf82e324c2.js
76.76.21.123
https://vercel.live/_next-live/feedback/feedback.js
unknown
https://specsavers.definition-ai.com/_next/static/chunks/474-3bd1a5a6f48135db.js
76.76.21.123
http://specsavers.definition-ai.com/
76.76.21.93
https://specsavers.definition-ai.com/
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/app/layout-215d7875994d7c57.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/webpack-731180e865825f4d.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/600-89a05570303bb527.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/media/b957ea75a84b6ea7-s.p.woff2
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/493-e877baf5954405a7.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/294-6cd779f987d1dade.js
76.76.21.123
https://specsavers.definition-ai.com/_next/static/css/b62d8e6afa1ae1f7.css
76.76.21.123
https://specsavers.definition-ai.com/_next/static/media/8888a3826f4a3af4-s.p.woff2
76.76.21.123
https://specsavers.definition-ai.com/_next/static/chunks/199-68a18b52276c86d8.js
76.76.21.123
There are 13 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
specsavers.definition-ai.com
unknown
malicious
cname.vercel-dns.com
76.76.21.93
s3-r-w.eu-west-2.amazonaws.com
52.95.148.114
www.google.com
142.250.185.132
fp2e7a.wpc.phicdn.net
192.229.221.95
definition-ai.s3.eu-west-2.amazonaws.com
unknown

IPs

IP
Domain
Country
Malicious
52.95.148.114
s3-r-w.eu-west-2.amazonaws.com
United States
76.76.21.123
unknown
United States
142.250.185.132
www.google.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
76.76.21.93
cname.vercel-dns.com
United States

DOM / HTML

URL
Malicious
https://specsavers.definition-ai.com/auth/login
malicious
https://specsavers.definition-ai.com/auth/login
https://specsavers.definition-ai.com/auth/login
https://specsavers.definition-ai.com/auth/login