IOC Report
http://sellerfifth.eur-tiktokshop.com/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 21:37:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 21:37:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 21:37:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 21:37:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Sep 28 21:37:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 466x466, components 3
downloaded
Chrome Cache Entry: 101
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 899x600, components 3
dropped
Chrome Cache Entry: 102
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1500x1500, components 3
downloaded
Chrome Cache Entry: 103
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1500x1500, components 3
dropped
Chrome Cache Entry: 104
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1500x1500, components 3
downloaded
Chrome Cache Entry: 105
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 106
Unicode text, UTF-8 text, with very long lines (47567)
downloaded
Chrome Cache Entry: 107
HTML document, ASCII text, with very long lines (690), with no line terminators
downloaded
Chrome Cache Entry: 108
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 109
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=12, height=842, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1280], progressive, precision 8, 1000x658, components 3
downloaded
Chrome Cache Entry: 110
JSON data
downloaded
Chrome Cache Entry: 111
Unicode text, UTF-8 text, with very long lines (58296), with no line terminators
dropped
Chrome Cache Entry: 112
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1051x1500, components 3
downloaded
Chrome Cache Entry: 113
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 472x679, components 3
dropped
Chrome Cache Entry: 114
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 472x679, components 3
downloaded
Chrome Cache Entry: 115
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (17039)
downloaded
Chrome Cache Entry: 117
JSON data
dropped
Chrome Cache Entry: 118
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 679x698, components 3
dropped
Chrome Cache Entry: 119
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 899x600, components 3
downloaded
Chrome Cache Entry: 120
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 342x551, components 3
downloaded
Chrome Cache Entry: 121
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 122
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 123
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=12, height=871, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1280], progressive, precision 8, 1000x680, components 3
downloaded
Chrome Cache Entry: 124
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1500x1500, components 3
dropped
Chrome Cache Entry: 125
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 126
Unicode text, UTF-8 text, with very long lines (58296), with no line terminators
downloaded
Chrome Cache Entry: 127
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 950x1075, components 3
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (5341), with no line terminators
downloaded
Chrome Cache Entry: 129
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 679x698, components 3
downloaded
Chrome Cache Entry: 130
JSON data
downloaded
Chrome Cache Entry: 131
Unicode text, UTF-8 text, with very long lines (47567)
dropped
Chrome Cache Entry: 132
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 394x994, components 3
dropped
Chrome Cache Entry: 133
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1069x1500, components 3
downloaded
Chrome Cache Entry: 134
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1297x1500, components 3
dropped
Chrome Cache Entry: 135
Unicode text, UTF-8 text, with very long lines (65336), with no line terminators
dropped
Chrome Cache Entry: 136
Unicode text, UTF-8 text, with very long lines (65336), with no line terminators
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (4540), with no line terminators
downloaded
Chrome Cache Entry: 138
JSON data
downloaded
Chrome Cache Entry: 139
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=12, height=871, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1280], progressive, precision 8, 1000x680, components 3
dropped
Chrome Cache Entry: 140
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (19205), with no line terminators
downloaded
Chrome Cache Entry: 142
Unicode text, UTF-8 text, with very long lines (65264), with no line terminators
downloaded
Chrome Cache Entry: 143
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1297x1500, components 3
downloaded
Chrome Cache Entry: 144
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1080x1500, components 3
dropped
Chrome Cache Entry: 145
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 950x1075, components 3
downloaded
Chrome Cache Entry: 146
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1499x1500, components 3
downloaded
Chrome Cache Entry: 147
JSON data
dropped
Chrome Cache Entry: 148
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1077x1500, components 3
dropped
Chrome Cache Entry: 149
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 342x551, components 3
dropped
Chrome Cache Entry: 150
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 466x466, components 3
dropped
Chrome Cache Entry: 151
Unicode text, UTF-8 text, with very long lines (65264), with no line terminators
dropped
Chrome Cache Entry: 152
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (1098), with no line terminators
downloaded
Chrome Cache Entry: 154
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=12, height=842, bps=0, PhotometricIntepretation=RGB, orientation=upper-left, width=1280], progressive, precision 8, 1000x658, components 3
dropped
Chrome Cache Entry: 155
Web Open Font Format, TrueType, length 28200, version 1.0
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (7697)
downloaded
Chrome Cache Entry: 157
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 394x994, components 3
downloaded
Chrome Cache Entry: 158
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1051x1500, components 3
dropped
Chrome Cache Entry: 159
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1080x1500, components 3
downloaded
Chrome Cache Entry: 160
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (17039)
dropped
Chrome Cache Entry: 162
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 163
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1069x1500, components 3
dropped
Chrome Cache Entry: 98
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1077x1500, components 3
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (7697)
dropped
There are 63 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2508 --field-trial-handle=2060,i,956452513132422349,14809226209336202366,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://sellerfifth.eur-tiktokshop.com/"

URLs

Name
IP
Malicious
http://sellerfifth.eur-tiktokshop.com/
malicious
https://sellerfifth.eur-tiktokshop.com/web/hotSellingProducts
malicious
https://sellerfifth.eur-tiktokshop.com/web/css/chunk-vendors.ccb7d15e.css
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/js/965.21d8ff76.js
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/js/chunk-vendors.c7569f53.js
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/js/app.7731b300.js
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/js/251.5da1f986.js
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/favicon.ico
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/
malicious
https://sellerfifth.eur-tiktokshop.com/web/css/251.70bfbbf4.css
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/css/app.80cefe0d.css
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/static/ulogo.png
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/api/goods/getGoodsList?type=0
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/img/search.3dfe5338.svg
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/fonts/element-icons.ff18efd1.woff
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/api/goods/HotProducts?page=1&limit=15
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/img/camera.37aad76b.svg
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/js/858.2d22548b.js
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/css/858.2575162d.css
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/css/965.02fea288.css
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/api/goods/getGoodsIndex
172.67.169.55
malicious
https://sellerfifth.eur-tiktokshop.com/web/js/212.b96c6fa8.js
172.67.169.55
malicious
https://img.pictrue-tk.com/storage/image/20240920/b28cf6497b85bad87d83e80098796adc.jpg
188.114.97.3
https://img.pictrue-tk.com/storage/image/20240925/25b2db0961360ac9a1d51b1d688c1b35.jpg
188.114.97.3
https://img.pictrue-tk.com/storage/image/20240920/78a8bbf4f45662d09f78339109ebc389.jpg
188.114.97.3
https://a1-tiktokshop-h5.tiktokseller.de/api/
unknown
https://img.pictrue-tk.com/storage/image/20240924/8e60eda02f6c0878f73adad9a53dfa9c.jpg
188.114.97.3
https://img.pictrue-tk.com/storage/image/20240920/e9e2e8bc826dcbca7c8b0ddfe6b4f2cf.jpg
188.114.97.3
https://img.pictrue-tk.com/storage/image/20240925/53e39b609d91ef1c03436d06efe1dfdc.jpg
188.114.97.3
https://img.pictrue-tk.com/storage/image/20240920/b3bd526365c76bbd985c89fa5c3b4a22.jpg
188.114.97.3
https://img.js.design/assets/smartFill/img394164da755928.jpeg
163.181.131.208
https://img.js.design/assets/smartFill/img288164da731af0.jpg
163.181.131.208
https://img.pictrue-tk.com/storage/image/20240920/0f2de9c720f4838d57af1ad6fb5b0aa4.jpg
188.114.97.3
https://img.pictrue-tk.com/storage/image/20240920/de77dbcf2e426a739909b75d9a04b1e6.jpg
188.114.97.3
https://a.nel.cloudflare.com/report/v4?s=1kYqDl8Juc3f%2FI6Ul4kNxHz1Es4CEi60Tv%2BMVkrbhhVSXm%2BNQN92Jm1Qm79w5VICOnaqdFpTeLHXb4I9pFHRgcgYowd1S6disWMGz5IlyQBmHRz5chvxSBXyCm2M8VFLXOUop7o%3D
35.190.80.1
https://img.pictrue-tk.com/storage/image/20240922/7da290f295096c07906c67fddf472a7c.jpg
188.114.97.3
https://img.pictrue-tk.com/storage/image/20240920/a1904f10be2c65dc13308dd0220eac1c.jpg
188.114.97.3
https://a.nel.cloudflare.com/report/v4?s=9itOvjxTLkNw%2FHdnFWSvsJbgC1EM78OQN2xYQpMbOPIbzupXXzF05EHzH2Bfx2eOnanlH9bnNpuvfLDq6c3kUtgbL1XzAnhEPyX%2F6GWMFcwT6trKgnnZBhVhvmWrMNNGUB9%2FCbJdnhYzIXEJa4eNZZM%3D
35.190.80.1
https://pinia.vuejs.org
unknown
https://tktest.tiktokseller.de/socket.io
38.45.125.66
https://img.js.design/assets/smartFill/img409164da755928.jpg
163.181.131.208
https://img.pictrue-tk.com/storage/image/20240920/ecbff25ea0163973058cc27f11465898.jpg
188.114.97.3
https://devtools.vuejs.org/guide/installation.html.
unknown
https://img.pictrue-tk.com/storage/image/20240922/5a4f89655bef79d34e31cc5f38c76637.jpg
188.114.97.3
https://pinia.vuejs.org/logo.svg
unknown
https://img.pictrue-tk.com/storage/image/20240920/8773de758c61acdc4773bae95a0f6478.jpg
188.114.97.3
https://a.nel.cloudflare.com/report/v4?s=1HmYLx8jchwItRlS%2F2cJRxyxo1%2FktMMbAYtmBMfYAyILSp18C51zHVHciPeCd6ez%2FFLVZn6SQtbFcK6Kj8jm8UyYGK3zyXghow9wk%2FkIPxdevTWjpw9MNhKp7vDyrW3FLg2s9yCyC7p2EcCrxkzq6ck%3D
35.190.80.1
https://github.com/emn178/js-md5
unknown
There are 37 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sellerfifth.eur-tiktokshop.com
104.21.79.71
malicious
a.nel.cloudflare.com
35.190.80.1
tktest.tiktokseller.de
38.45.125.66
img.js.design.w.kunlunpi.com
163.181.131.208
www.google.com
142.250.184.196
img.pictrue-tk.com
188.114.97.3
fp2e7a.wpc.phicdn.net
192.229.221.95
img.js.design
unknown

IPs

IP
Domain
Country
Malicious
142.250.184.196
www.google.com
United States
163.181.131.208
img.js.design.w.kunlunpi.com
United States
38.45.125.66
tktest.tiktokseller.de
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
188.114.97.3
img.pictrue-tk.com
European Union
188.114.96.3
unknown
European Union
35.190.80.1
a.nel.cloudflare.com
United States
172.67.169.55
unknown
United States

DOM / HTML

URL
Malicious
https://sellerfifth.eur-tiktokshop.com/
malicious
https://sellerfifth.eur-tiktokshop.com/web/hotSellingProducts
malicious
https://sellerfifth.eur-tiktokshop.com/
https://sellerfifth.eur-tiktokshop.com/