IOC Report
https://logg_koonbase.godaddysites.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (516)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (51853)
downloaded
Chrome Cache Entry: 102
HTML document, Unicode text, UTF-8 text, with very long lines (10137)
downloaded
Chrome Cache Entry: 103
ASCII text
downloaded
Chrome Cache Entry: 104
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (12251)
dropped
Chrome Cache Entry: 106
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 107
Web Open Font Format (Version 2), TrueType, length 12608, version 1.0
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (330)
downloaded
Chrome Cache Entry: 109
ASCII text
dropped
Chrome Cache Entry: 110
ASCII text, with very long lines (3043)
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (330)
dropped
Chrome Cache Entry: 112
ASCII text, with very long lines (516)
dropped
Chrome Cache Entry: 113
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Google], baseline, precision 8, 1240x1035, components 3
dropped
Chrome Cache Entry: 114
ASCII text, with very long lines (786)
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (32950), with no line terminators
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (3043)
downloaded
Chrome Cache Entry: 117
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 118
ASCII text
dropped
Chrome Cache Entry: 119
JSON data
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (1211)
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (829)
dropped
Chrome Cache Entry: 122
ASCII text, with very long lines (23126)
dropped
Chrome Cache Entry: 123
Unicode text, UTF-8 text, with very long lines (63425)
dropped
Chrome Cache Entry: 124
Unicode text, UTF-8 text, with very long lines (20947)
dropped
Chrome Cache Entry: 125
ASCII text, with very long lines (522)
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (6969)
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (12251)
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (1824)
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (829)
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (522)
dropped
Chrome Cache Entry: 131
ASCII text
downloaded
Chrome Cache Entry: 132
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 133
HTML document, ASCII text, with very long lines (1781)
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (1824)
downloaded
Chrome Cache Entry: 135
Web Open Font Format (Version 2), TrueType, length 46448, version 1.0
downloaded
Chrome Cache Entry: 136
Web Open Font Format (Version 2), TrueType, length 7816, version 1.0
downloaded
Chrome Cache Entry: 73
HTML document, ASCII text, with very long lines (1781)
dropped
Chrome Cache Entry: 74
ASCII text, with very long lines (1352)
downloaded
Chrome Cache Entry: 75
Web Open Font Format (Version 2), TrueType, length 7840, version 1.0
downloaded
Chrome Cache Entry: 76
ASCII text, with very long lines (905)
dropped
Chrome Cache Entry: 77
ASCII text, with very long lines (1352)
dropped
Chrome Cache Entry: 78
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (6969)
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 81
ASCII text, with very long lines (23126)
downloaded
Chrome Cache Entry: 82
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 83
ASCII text
dropped
Chrome Cache Entry: 84
Unicode text, UTF-8 text, with very long lines (63425)
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (786)
downloaded
Chrome Cache Entry: 86
ASCII text, with very long lines (1211)
dropped
Chrome Cache Entry: 87
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 88
Unicode text, UTF-8 text, with very long lines (20947)
downloaded
Chrome Cache Entry: 89
ASCII text
downloaded
Chrome Cache Entry: 90
ASCII text, with very long lines (905)
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (383)
dropped
Chrome Cache Entry: 92
ASCII text
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (51853)
dropped
Chrome Cache Entry: 94
Web Open Font Format (Version 2), TrueType, length 8000, version 1.0
downloaded
Chrome Cache Entry: 95
ASCII text, with very long lines (383)
downloaded
Chrome Cache Entry: 96
ASCII text
downloaded
Chrome Cache Entry: 97
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 98
Web Open Font Format (Version 2), TrueType, length 7884, version 1.0
downloaded
Chrome Cache Entry: 99
ASCII text
dropped
There are 55 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2544 --field-trial-handle=2364,i,18366499957688085511,10167160284856967565,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://logg_koonbase.godaddysites.com/"
malicious

URLs

Name
IP
Malicious
https://logg_koonbase.godaddysites.com/
malicious
https://ms.godaddy.com/r?e=eyJ2IjoiMS4xMiIsImF2IjoxMzc5NjY0LCJhdCI6MjQ0NywiYnQiOjAsImNtIjozNjk2
unknown
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiByp8kv8JHgFVrLCz7Z1xlFQ.woff2)
unknown
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiByp8kv8JHgFVrLEj6Z1xlFQ.woff2)
unknown
https://ms.godaddy.com/i.gif?e=eyJ2IjoiMS4xMiIsImF2IjoxMzc5NjY0LCJhdCI6MjQ0NywiYnQiOjAsImNtIjoz
unknown
https://github.com/FAlthausen/Vollkorn-Typeface)
unknown
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiByp8kv8JHgFVrLCz7Z1JlFc-K.woff2)
unknown
https://img1.wsimg.com/gfonts/s/vollkorn/v23/0yb9GDoxxrvAnPhYGxkkaE0GrQ.woff2)
unknown
https://img1.wsimg.com/gfonts/s/vollkorn/v23/0yb9GDoxxrvAnPhYGxkmaE0GrQ.woff2)
unknown
https://logg_koonbase.godaddysites.com/
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiEyp8kv8JHgFVrJJfecg.woff2)
unknown
https://logg_koonbase.godaddysites.com/sw.js
13.248.243.5
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiByp8kv8JHgFVrLEj6Z1JlFc-K.woff2)
unknown
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiEyp8kv8JHgFVrJJnecmNE.woff2)
unknown
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiByp8kv8JHgFVrLDz8Z1JlFc-K.woff2)
unknown
https://logg_koonbase.godaddysites.com/manifest.webmanifest
13.248.243.5
https://img1.wsimg.com/poly/v3/polyfill.min.js?rum=0&unknown=polyfill&flags=gated&features=Intl.~loc
unknown
https://ms.godaddy.com/i.gif?e=eyJ2IjoiMS4xMiIsImF2IjoxMzc5NjY0LCJhdCI6MjQ0NywiYnQiOjAsImNtIjozNjk2NjY5OTcsImNoIjo1NDQ0NSwiY2siOnt9LCJjciI6NDA4ODkzMDIyLCJkaSI6IjBkMTcyMzQ5ZmRkMTQzYjViODBmZGM0OWVhMjI1ZDYyIiwiZGoiOjAsImlpIjoiNWUxNmY5NjE3ZjY4NDRmODllZGQxN2VmMTY3Yzk2MjEiLCJkbSI6MywiZmMiOjU4Mzk1MjEyMywiZmwiOjU3MTk5NDU0MywiaXAiOiI2NC4yMDIuMTYwLjAiLCJrdyI6Int7a2V5d29yZH19IiwibnciOjEwNjYzLCJwYyI6MCwib3AiOjAsIm1wIjowLCJlYyI6MCwiZ20iOjAsImVwIjpudWxsLCJwciI6MjE4NDY1LCJydCI6MSwicnMiOjUwMCwic2EiOiI1MiIsInNiIjoiaS0wZjJkNDAyYmMxYmMwNjJjMyIsInNwIjoyMjUxOTk5LCJzdCI6MTI3NjI2NCwidWsiOiJ1ZTEtMzdlMmMzYTE2YjdmNGVkMTgzYTQ0ZTlmZmU5YmE1ZmEiLCJ6biI6MzA3NDk1LCJ0cyI6MTcyNzU5MDEzMDQ0MiwicG4iOiJ3YW0iLCJnYyI6dHJ1ZSwiZ0MiOnRydWUsImdzIjoibm9uZSIsImRjIjoxLCJ0eiI6IlVUQyIsImJhIjoxLCJmcSI6MH0&s=TsH1hKr6YSUj6GVyz_A0XSt2THE&publisher_website_key=wam.md5.a16fc9606dd4c9d27a764a3bb277b01f
34.250.180.246
https://www.fontsquirrel.com/license/league-spartan
unknown
https://img1.wsimg.com/gfonts/s/poppins/v21/pxiByp8kv8JHgFVrLDz8Z1xlFQ.woff2)
unknown
https://img1.wsimg.com/gfonts/s/vollkorn/v23/0yb9GDoxxrvAnPhYGxkqaE0GrQ.woff2)
unknown
https://img1.wsimg.com/blobby/go/font/LeagueSpartan/LeagueSpartan.woff)
unknown
https://logg_koonbase.godaddysites.com/markup/ad
13.248.243.5
https://img1.wsimg.com/gfonts/s/vollkorn/v23/0yb9GDoxxrvAnPhYGxknaE0GrQ.woff2)
unknown
https://img1.wsimg.com/gfonts/s/vollkorn/v23/0yb9GDoxxrvAnPhYGxkpaE0.woff2)
unknown
http://scripts.sil.org/OFL
unknown
https://img1.wsimg.com/gfonts/s/vollkorn/v23/0yb9GDoxxrvAnPhYGxktaE0GrQ.woff2)
unknown
https://img1.wsimg.com/blobby/go/font/LeagueSpartan/LeagueSpartan.woff2)
unknown
http://jedwatson.github.io/classnames
unknown
There are 18 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sytfbklsdabx.xyz
unknown
malicious
google.com
142.250.184.238
logg_koonbase.godaddysites.com
13.248.243.5
e-prod-alb-s102-eu-west-1-02.adzerk.net
34.250.180.246
www.google.com
142.250.184.196
isteam.wsimg.com
3.64.248.63
fp2e7a.wpc.phicdn.net
192.229.221.95
img1.wsimg.com
unknown
ms.godaddy.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.184.196
www.google.com
United States
13.248.243.5
logg_koonbase.godaddysites.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
3.64.248.63
isteam.wsimg.com
United States
34.250.180.246
e-prod-alb-s102-eu-west-1-02.adzerk.net
United States

DOM / HTML

URL
Malicious
https://logg_koonbase.godaddysites.com/
malicious
https://logg_koonbase.godaddysites.com/
malicious