IOC Report
http://coinbaspaswordrecovery.gitbook.io/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (34267)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (34267)
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (6926)
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (63937)
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (3596)
dropped
Chrome Cache Entry: 105
PNG image data, 22 x 22, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 106
JSON data
downloaded
Chrome Cache Entry: 107
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (63937)
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (8396)
downloaded
Chrome Cache Entry: 110
JSON data
dropped
Chrome Cache Entry: 111
JSON data
dropped
Chrome Cache Entry: 112
PNG image data, 22 x 22, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (6247)
downloaded
Chrome Cache Entry: 114
ASCII text, with very long lines (25336)
dropped
Chrome Cache Entry: 115
ASCII text
downloaded
Chrome Cache Entry: 116
Unicode text, UTF-8 text, with very long lines (28477)
dropped
Chrome Cache Entry: 117
ASCII text, with very long lines (11638)
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (6247)
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (14941)
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (28774)
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (1146)
dropped
Chrome Cache Entry: 122
ASCII text, with very long lines (8827)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (56462)
dropped
Chrome Cache Entry: 124
ASCII text, with very long lines (18153)
downloaded
Chrome Cache Entry: 125
JSON data
dropped
Chrome Cache Entry: 126
Unicode text, UTF-8 text, with very long lines (59073)
dropped
Chrome Cache Entry: 127
Unicode text, UTF-8 text, with very long lines (59073)
downloaded
Chrome Cache Entry: 128
HTML document, Unicode text, UTF-8 text, with very long lines (41358)
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (11638)
dropped
Chrome Cache Entry: 130
ASCII text, with very long lines (40811)
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (12105)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (3227)
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 134
ASCII text, with very long lines (1146)
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (40811)
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (3907)
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (28198)
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (6926)
downloaded
Chrome Cache Entry: 139
ASCII text
downloaded
Chrome Cache Entry: 140
Unicode text, UTF-8 text, with very long lines (29907)
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (14941)
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (18153)
dropped
Chrome Cache Entry: 143
JSON data
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (60328)
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (65472)
downloaded
Chrome Cache Entry: 146
Unicode text, UTF-8 text, with very long lines (28477)
downloaded
Chrome Cache Entry: 147
ASCII text
downloaded
Chrome Cache Entry: 148
ISO Media, AVIF Image
dropped
Chrome Cache Entry: 149
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 151
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (8827)
dropped
Chrome Cache Entry: 153
PNG image data, 22 x 22, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 154
Unicode text, UTF-8 text, with very long lines (29907)
downloaded
Chrome Cache Entry: 155
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (311)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (3907)
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (12105)
dropped
Chrome Cache Entry: 93
Web Open Font Format (Version 2), TrueType, length 48556, version 1.0
downloaded
Chrome Cache Entry: 94
JSON data
dropped
Chrome Cache Entry: 95
ASCII text, with very long lines (3596)
downloaded
Chrome Cache Entry: 96
ASCII text, with very long lines (25336)
downloaded
Chrome Cache Entry: 97
ASCII text, with very long lines (56462)
downloaded
Chrome Cache Entry: 98
JSON data
downloaded
Chrome Cache Entry: 99
JSON data
downloaded
There are 58 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2340 --field-trial-handle=2220,i,3288088959569305603,18412864913433259694,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://coinbaspaswordrecovery.gitbook.io/"

URLs

Name
IP
Malicious
http://coinbaspaswordrecovery.gitbook.io/
malicious
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/8381-2f754da8e779eeab.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/1698-e89c19bbf0c8e05d.js
172.64.147.209
https://tailwindcss.com
unknown
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/594af977d5a2878d.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/~gitbook/image?url=https%3A%2F%2F4052259958-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252F2pyJXGFXE3arlJetSoz5%252Ficon%252FKhuuX0QshgLx2AncPwmg%252Fcoin_icon_1.png%3Falt%3Dmedia%26token%3D42cfc460-d777-4ac3-b5f2-6af7bfba9abc&width=32&dpr=1&quality=100&sign=4067b2d1&sv=1
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/2632-58a8169263096f76.js
172.64.147.209
https://www.gitbook.com/?utm_source=content&utm_medium=trademark&utm_campaign=2pyJXGFXE3arlJ
unknown
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/ebf7d0073b0092ea.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/2189598b7c705dde.css
172.64.147.209
https://app.gitbook.com/__session?proposed=12ac3125-76e2-4055-a970-013f12597292R
104.18.41.89
https://app.gitbook.com/__session?proposed=bf5e7a6d-5f31-42f6-924c-025c3d543049R
104.18.41.89
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/829150f9e3c1e921.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/us
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/webpack-ed8f5a60dc0318fb.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/app/global-error-ae0a7781226b5f7c.js
172.64.147.209
https://unpkg.com/
unknown
https://coinbaspaswordrecovery.gitbook.io/us#h_01fyvaxjqt914hcheyfpnmejea
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/bf7df5d7c6de54ec.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/3546-983d8e659994cb93.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/main-app-7fe2ade0fc9c0065.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/0f891de5863d7182.css
172.64.147.209
http://jedwatson.github.io/classnames
unknown
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/app/(space)/(content)/%5B%5B...pathname%5D%5D/page-80dffb20e3f68740.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/b5d5b83b-79880c6c180a831f.js
172.64.147.209
https://api.gitbook.com/v1/orgs/eT980wuBr6R8RvawJiaL/sites/site_1XoQI/insights/track_view
104.18.41.89
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/4037-4d151b686812ceb4.js
172.64.147.209
https://app.gitbook.com/__session?proposed=b47ad078-4db4-4db5-b7a3-fbf9d483aa2dR
104.18.41.89
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/6985-24d17eba2c4006cb.js
172.64.147.209
https://docs.gitbook.com/published-documentation/custom-domain/configure-dns#are-you-using-cloudflar
unknown
https://coinbaspaswordrecovery.gitbook.io/us/
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/84671c0b86c5eace.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/1dd3208c-65f236513d05994f.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/4377-f33ce08f4cf11496.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/e11f1c6a6568d9ab.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/app/(space)/(content)/layout-e6c9e9cb143d3791.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/026444ec630b65a2.css
172.64.147.209
https://feross.org
unknown
https://app.gitbook.com/__session?proposed=9a4bd797-2e00-47c1-a166-721c0dfb5678R
104.18.41.89
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/8731-301749ee030e10bf.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/6445-f44ccdfb3d68c36a.js
172.64.147.209
https://4052259958-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2pyJXGFXE3arlJetSoz5%2Fuploads%2Fil9CUTGZLRHgdMAFR3p6%2Ffile.excalidraw.svg?alt=media&token=469a9dc3-496e-4958-86ce-376d448435dc
104.18.40.47
https://coinbaspaswordrecovery.gitbook.io/_next/static/media/a34f9d1faa5f3315-s.woff2
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/~gitbook/image?url=https%3A%2F%2F4052259958-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252F2pyJXGFXE3arlJetSoz5%252Fuploads%252Fbers6RcGcTUIVziuApoK%252Fcoinbase-header.jpg%3Falt%3Dmedia%26token%3D09aa1588-f61a-48f8-af42-9857e3c836f1&width=1248&dpr=1&quality=100&sign=90d02e3b&sv=1
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/app/(space)/error-e13e0b765fd3fff7.js
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/c311d6484335995a.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/css/19ad1175bf75e201.css
172.64.147.209
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/6718-c9b90b1ba43809dd.js
172.64.147.209
https://4052259958-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F2pyJXGFXE3arlJetSoz5%2Ficon%2FKhuuX0QshgLx2AncPwmg%2Fcoin_icon_1.png?alt=media&token=42cfc460-d777-4ac3-b5f2-6af7bfba9abc
104.18.40.47
https://coinbaspaswordrecovery.gitbook.io/us#id-01grvgew4ety4b98kwx25faqxr
https://coinbaspaswordrecovery.gitbook.io/_next/static/chunks/app/(space)/layout-777f498210738e71.js
172.64.147.209
There are 41 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
4052259958-files.gitbook.io
104.18.40.47
www.google.com
172.217.18.4
app.gitbook.com
104.18.41.89
coinbaspaswordrecovery.gitbook.io
172.64.147.209
api.gitbook.com
104.18.41.89

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
104.18.40.47
4052259958-files.gitbook.io
United States
104.18.41.89
app.gitbook.com
United States
172.217.18.4
www.google.com
United States
192.168.2.7
unknown
unknown
172.64.147.209
coinbaspaswordrecovery.gitbook.io
United States
172.217.16.132
unknown
United States

DOM / HTML

URL
Malicious
https://coinbaspaswordrecovery.gitbook.io/us
malicious
https://coinbaspaswordrecovery.gitbook.io/us
malicious
https://coinbaspaswordrecovery.gitbook.io/us
malicious
https://coinbaspaswordrecovery.gitbook.io/us
malicious
https://coinbaspaswordrecovery.gitbook.io/us#h_01fyvaxjqt914hcheyfpnmejea
malicious
https://coinbaspaswordrecovery.gitbook.io/us#id-01grvgew4ety4b98kwx25faqxr
malicious