IOC Report
https://coiinbase-pro-loggin.godaddysites.com/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 02:05:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 02:05:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 02:05:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 02:05:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 02:05:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (905)
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (651)
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (1352)
dropped
Chrome Cache Entry: 103
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (13540)
dropped
Chrome Cache Entry: 105
Web Open Font Format (Version 2), TrueType, length 11644, version 1.0
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 107
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 108
Web Open Font Format (Version 2), TrueType, length 23040, version 1.0
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (23126)
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (21556)
downloaded
Chrome Cache Entry: 111
ASCII text
dropped
Chrome Cache Entry: 112
Unicode text, UTF-8 text, with very long lines (63425)
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (1211)
dropped
Chrome Cache Entry: 114
HTML document, Unicode text, UTF-8 text, with very long lines (6628)
downloaded
Chrome Cache Entry: 115
Web Open Font Format (Version 2), TrueType, length 11728, version 1.0
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (51853)
dropped
Chrome Cache Entry: 117
Unicode text, UTF-8 text, with very long lines (20947)
downloaded
Chrome Cache Entry: 118
ASCII text
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (905)
downloaded
Chrome Cache Entry: 121
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=6, orientation=upper-left, xresolution=86, yresolution=94, resolutionunit=2], baseline, precision 8, 1535x1021, components 3
dropped
Chrome Cache Entry: 122
ASCII text, with very long lines (383)
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (13834)
dropped
Chrome Cache Entry: 124
ASCII text
downloaded
Chrome Cache Entry: 125
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 126
HTML document, Unicode text, UTF-8 text, with very long lines (7840)
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (383)
downloaded
Chrome Cache Entry: 128
ASCII text
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (516)
downloaded
Chrome Cache Entry: 130
ASCII text
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (51853)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (367)
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (32978), with no line terminators
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (651)
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (8076)
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (330)
downloaded
Chrome Cache Entry: 138
ASCII text
dropped
Chrome Cache Entry: 139
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 140
ASCII text, with very long lines (3043)
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (21556)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (367)
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (330)
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (516)
dropped
Chrome Cache Entry: 145
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (3043)
downloaded
Chrome Cache Entry: 147
ASCII text
dropped
Chrome Cache Entry: 148
ASCII text, with very long lines (1211)
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (5534)
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (829)
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (23126)
dropped
Chrome Cache Entry: 152
ASCII text, with very long lines (442)
dropped
Chrome Cache Entry: 153
Unicode text, UTF-8 text, with very long lines (63425)
dropped
Chrome Cache Entry: 154
Unicode text, UTF-8 text, with very long lines (20947)
dropped
Chrome Cache Entry: 155
Web Open Font Format (Version 2), TrueType, length 23580, version 1.0
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (522)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (13834)
downloaded
Chrome Cache Entry: 158
JPEG image data, baseline, precision 8, 192x192, components 3
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (1824)
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (829)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (522)
dropped
Chrome Cache Entry: 163
ASCII text
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (8076)
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (1824)
downloaded
Chrome Cache Entry: 166
RIFF (little-endian) data, Web/P image, VP8 encoding, 192x192, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (13540)
downloaded
Chrome Cache Entry: 95
RIFF (little-endian) data, Web/P image, VP8 encoding, 1535x1021, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 96
ASCII text, with very long lines (442)
downloaded
Chrome Cache Entry: 97
ASCII text, with very long lines (5534)
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (1352)
downloaded
Chrome Cache Entry: 99
JSON data
downloaded
There are 70 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2120 --field-trial-handle=2040,i,8116814915728366846,5434360114479643371,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://coiinbase-pro-loggin.godaddysites.com/"

URLs

Name
IP
Malicious
https://coiinbase-pro-loggin.godaddysites.com/
malicious
https://coiinbase-pro-loggin.godaddysites.com/404
unknown
https://img1.wsimg.com/gfonts/s/lato/v24/S6u9w4BMUTPHh6UVSwiPGQ.woff2)
unknown
https://img1.wsimg.com/gfonts/s/lusitana/v13/CSR74z9ShvucWzsMKyDmafctaNY.woff2)
unknown
https://img1.wsimg.com/gfonts/s/lato/v24/S6uyw4BMUTPHjx4wXg.woff2)
unknown
https://img1.wsimg.com/poly/v3/polyfill.min.js?rum=0&unknown=polyfill&flags=gated&features=Intl.~loc
unknown
https://img1.wsimg.com/isteam/stock/107927
unknown
https://img1.wsimg.com/gfonts/s/lato/v24/S6u9w4BMUTPHh6UVSwaPGR_p.woff2)
unknown
https://img1.wsimg.com/gfonts/s/lusitana/v13/CSR84z9ShvucWzsMKyhdTOI.woff2)
unknown
https://coiinbase-pro-loggin.godaddysites.com/sw.js
13.248.243.5
http://scripts.sil.org/OFL
unknown
https://img1.wsimg.com/gfonts/s/lato/v24/S6uyw4BMUTPHjxAwXjeu.woff2)
unknown
https://coiinbase-pro-loggin.godaddysites.com/
https://coiinbase-pro-loggin.godaddysites.com/favicon.ico
13.248.243.5
http://jedwatson.github.io/classnames
unknown
https://coiinbase-pro-loggin.godaddysites.com/manifest.webmanifest
13.248.243.5
There are 5 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
142.250.186.164
coiinbase-pro-loggin.godaddysites.com
13.248.243.5
isteam.wsimg.com
3.121.64.201
fp2e7a.wpc.phicdn.net
192.229.221.95
img1.wsimg.com
unknown
csp.secureserver.net
unknown
events.api.secureserver.net
unknown
18.31.95.13.in-addr.arpa
unknown

IPs

IP
Domain
Country
Malicious
3.121.64.201
isteam.wsimg.com
United States
13.248.243.5
coiinbase-pro-loggin.godaddysites.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
216.58.206.68
unknown
United States
239.255.255.250
unknown
Reserved
142.250.186.164
www.google.com
United States

DOM / HTML

URL
Malicious
https://coiinbase-pro-loggin.godaddysites.com/
malicious
https://coiinbase-pro-loggin.godaddysites.com/
malicious