IOC Report
http://www.protocol-app.com/app/module/load.php

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 50
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 51
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 52
TrueType Font data, 17 tables, 1st "GPOS", 27 names, Macintosh, Font data copyright Google 2012RobotoRegularGoogle:Roboto Regular:2013Roboto RegularVersion 1.10
downloaded
Chrome Cache Entry: 53
ASCII text, with very long lines (5265), with no line terminators
downloaded
Chrome Cache Entry: 54
HTML document, ASCII text
downloaded
Chrome Cache Entry: 55
ASCII text, with very long lines (497)
dropped
Chrome Cache Entry: 56
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 57
TrueType Font data, 19 tables, 1st "BASE", 16 names, Macintosh, language 0x2, type 1 string, otCopyright (c) 2018 Swiss Typefaces Sarl. All rights reserved.\266Version 3.001FontEuclid is a
downloaded
Chrome Cache Entry: 58
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 59
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 60
TrueType Font data, 19 tables, 1st "BASE", 16 names, Macintosh, language 0x2, type 1 string, otCopyright (c) 2018 Swiss Typefaces Sarl. All rights reserved.\266Version 3.001FontEuclid is a
downloaded
Chrome Cache Entry: 61
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 62
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 63
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 64
ASCII text, with very long lines (497)
downloaded
Chrome Cache Entry: 65
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 67
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 68
ASCII text, with very long lines (65447)
downloaded
There are 10 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2592 --field-trial-handle=1984,i,12448044304751070973,3669799615233655859,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.protocol-app.com/app/module/load.php"

URLs

Name
IP
Malicious
http://www.protocol-app.com/app/module/load.php
malicious
https://www.protocol-app.com/app/module/load.php
malicious
https://www.protocol-app.com/app/module/img/caret-down.svg
188.114.96.3
https://www.protocol-app.com/app/module/css/carousel.min.css
188.114.96.3
https://www.protocol-app.com/app/module/fonts/Roboto-Regular.ttf
188.114.96.3
https://metacrypto-io.com/wallet/fonts/fa-regular-400.eot
unknown
https://metacrypto-io.com/images/check-green-solid.svg
unknown
https://www.xfive.co/blog/itcss-scalable-maintainable-css-architecture/
unknown
https://metacrypto-io.com/wallet/fonts/EuclidCircularB-RegularItalic-WebXL.ttf
unknown
https://www.protocol-app.com/app/module/img/metamask-fox.svg
188.114.96.3
http://www.creativebloq.com/web-design/manage-large-css-projects-itcss-101517528
unknown
https://fontawesome.com/license/free
unknown
https://metacrypto-io.com/wallet/css/images/icons/collapse.svg
unknown
https://fontawesome.com
unknown
https://metacrypto-io.com/wallet/fonts/fa-solid-900.eot
unknown
https://github.com/banksean
unknown
http://meyerweb.com/eric/tools/css/reset/
unknown
https://metacrypto-io.com/images/qr-blue.svg
unknown
https://metacrypto-io.com/wallet/fonts/fa-regular-400.eot?
unknown
https://metacrypto-io.com/images/icons/disconnect.svg);
unknown
http://www.swisstypefaces.comPlease
unknown
https://metacrypto-io.com/wallet/fonts/Roboto-Black.ttf
unknown
https://metacrypto-io.com/wallet/fonts/fa-solid-900.eot?
unknown
https://www.protocol-app.com/app/module/js/jquery-3.6.0.min.js
188.114.96.3
https://metacrypto-io.com/images/caret-left.svg
unknown
http://chir.ag/projects/name-that-color
unknown
https://www.protocol-app.com/app/module/fonts/EuclidCircularB-Bold-WebXL.ttf
188.114.96.3
https://metacrypto-io.com/images/search-black.svg
unknown
https://metacrypto-io.com/wallet/fonts/Roboto-Light.ttf
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://metacrypto-io.com/wallet/fonts/Roboto-Thin.ttf
unknown
https://metacrypto-io.com/images/close-gray.svg
unknown
https://metacrypto-io.com/wallet/css/images/icons/swap.svg
unknown
https://metacrypto-io.com/wallet/fonts/fa-regular-400.svg
unknown
https://metacrypto-io.com/wallet/fonts/fa-regular-400.ttf
unknown
http://www.swisstypefaces.com/licensing/#retail-font-software-licence
unknown
https://metacrypto-io.com/images/icons/connected-sites.svg);
unknown
https://metacrypto-io.com/images/caret-right.svg
unknown
https://metacrypto-io.com/wallet/fonts/fa-regular-400.woff2
unknown
https://metacrypto-io.com/images/check-white.svg
unknown
https://www.protocol-app.com/app/module/css/connect.css
188.114.96.3
https://www.protocol-app.com/app/module/fonts/EuclidCircularB-Regular-WebXL.ttf
188.114.96.3
https://www.protocol-app.com/app/module/js/logo.js
188.114.96.3
http://www.apache.org/licenses/LICENSE-2.0Font
unknown
https://metacrypto-io.com/images/caret-right.svg);
unknown
https://www.protocol-app.com/app/module/img/favicon.png
188.114.96.3
http://www.math.sci.hiroshima-u.ac.jp/~m-mat/MT/emt.html
unknown
https://metacrypto-io.com/images/permissions-check.svg
unknown
https://metacrypto-io.com/wallet/fonts/fa-regular-400.woff
unknown
https://metacrypto-io.com/images/caret-left-black.svg
unknown
https://metacrypto-io.com/wallet/fonts/fa-solid-900.svg
unknown
https://www.protocol-app.com/app/module/img/metamask-logo-horizontal.svg
188.114.96.3
https://bit.ly/3c3qXzq
unknown
There are 42 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.protocol-app.com
188.114.96.3
malicious
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
142.250.184.196
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
188.114.96.3
www.protocol-app.com
European Union
malicious
142.250.184.196
www.google.com
United States
239.255.255.250
unknown
Reserved
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
https://www.protocol-app.com/app/module/load.php
malicious
https://www.protocol-app.com/app/module/load.php
https://www.protocol-app.com/app/module/load.php
https://www.protocol-app.com/app/module/load.php
https://www.protocol-app.com/app/module/load.php