IOC Report
http://microsoft.biosency.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 121
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
dropped
Chrome Cache Entry: 122
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 123
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 124
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 125
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 126
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 127
HTML document, Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (3637)
downloaded
Chrome Cache Entry: 129
HTML document, ASCII text, with very long lines (3450), with CRLF line terminators
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (56994)
downloaded
Chrome Cache Entry: 131
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 132
PNG image data, 1704 x 1188, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (27557)
downloaded
Chrome Cache Entry: 134
PNG image data, 964 x 604, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (65402)
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (2824)
downloaded
Chrome Cache Entry: 137
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 138
Unicode text, UTF-8 (with BOM) text, with very long lines (5167), with no line terminators
downloaded
Chrome Cache Entry: 139
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 140
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (2674)
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (503)
downloaded
Chrome Cache Entry: 143
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 145
JSON data
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (65398)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65398)
dropped
Chrome Cache Entry: 148
Unicode text, UTF-8 text, with very long lines (45900)
downloaded
Chrome Cache Entry: 149
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (2230), with no line terminators
downloaded
Chrome Cache Entry: 151
Unicode text, UTF-8 (with BOM) text, with very long lines (65513), with no line terminators
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (2663), with no line terminators
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 154
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 155
Web Open Font Format (Version 2), TrueType, length 45108, version 1.0
downloaded
Chrome Cache Entry: 156
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (65402)
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (65394)
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (3637)
dropped
Chrome Cache Entry: 160
PNG image data, 297 x 166, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 161
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 162
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 163
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 886947
dropped
Chrome Cache Entry: 164
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 149676
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (46090)
dropped
Chrome Cache Entry: 166
PNG image data, 964 x 604, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 167
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (4873), with no line terminators
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (65460)
dropped
Chrome Cache Entry: 170
Web Open Font Format (Version 2), TrueType, length 13576, version 330.-16253
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (2824)
dropped
Chrome Cache Entry: 172
Unicode text, UTF-8 text, with very long lines (45900)
dropped
Chrome Cache Entry: 173
ASCII text, with very long lines (34235), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 174
PNG image data, 297 x 166, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 175
ASCII text, with very long lines (2663), with no line terminators
downloaded
Chrome Cache Entry: 176
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 149676
dropped
Chrome Cache Entry: 177
Web Open Font Format (Version 2), TrueType, length 36748, version 0.0
downloaded
Chrome Cache Entry: 178
Unicode text, UTF-8 (with BOM) text, with very long lines (26071), with no line terminators
downloaded
Chrome Cache Entry: 179
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 180
ASCII text, with very long lines (65460)
downloaded
Chrome Cache Entry: 181
HTML document, ASCII text, with very long lines (2623), with CRLF line terminators
downloaded
Chrome Cache Entry: 182
Unicode text, UTF-8 (with BOM) text, with very long lines (10387), with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (2344), with no line terminators
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (13140)
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (65297)
downloaded
Chrome Cache Entry: 186
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 187
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 188
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
dropped
Chrome Cache Entry: 189
Unicode text, UTF-8 text, with very long lines (64241)
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (1789), with no line terminators
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (4370), with no line terminators
downloaded
Chrome Cache Entry: 192
ASCII text, with very long lines (2974), with no line terminators
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (17287), with no line terminators
dropped
Chrome Cache Entry: 194
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 195
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 196
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 197
Unicode text, UTF-8 (with BOM) text, with very long lines (12305), with no line terminators
downloaded
Chrome Cache Entry: 198
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (65394)
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (65297)
dropped
Chrome Cache Entry: 201
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 202
JSON data
dropped
Chrome Cache Entry: 203
ASCII text, with very long lines (2674)
dropped
Chrome Cache Entry: 204
ASCII text, with very long lines (30651)
dropped
Chrome Cache Entry: 205
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 206
JSON data
dropped
Chrome Cache Entry: 207
ASCII text, with very long lines (6125), with no line terminators
downloaded
Chrome Cache Entry: 208
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 886947
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (780), with no line terminators
downloaded
Chrome Cache Entry: 210
ASCII text, with very long lines (17287), with no line terminators
downloaded
Chrome Cache Entry: 211
PNG image data, 3840 x 2158, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 212
ASCII text, with very long lines (42133)
downloaded
Chrome Cache Entry: 213
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 214
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 215
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 216
PNG image data, 262 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 217
Unicode text, UTF-8 text, with very long lines (56015)
downloaded
Chrome Cache Entry: 218
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 219
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 90678
dropped
Chrome Cache Entry: 220
HTML document, Unicode text, UTF-8 text, with very long lines (23170), with CRLF line terminators
downloaded
Chrome Cache Entry: 221
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 222
Unicode text, UTF-8 text, with very long lines (56015)
dropped
Chrome Cache Entry: 223
HTML document, ASCII text, with very long lines (918)
downloaded
Chrome Cache Entry: 224
ASCII text, with very long lines (65324)
downloaded
Chrome Cache Entry: 225
Web Open Font Format (Version 2), TrueType, length 29888, version 0.0
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (503)
dropped
Chrome Cache Entry: 227
Web Open Font Format, TrueType, length 26288, version 0.0
downloaded
Chrome Cache Entry: 228
PNG image data, 3840 x 2158, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 229
PNG image data, 262 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 230
ASCII text, with very long lines (30651)
downloaded
Chrome Cache Entry: 231
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 90678
downloaded
Chrome Cache Entry: 232
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 233
ASCII text, with very long lines (46090)
downloaded
Chrome Cache Entry: 234
ASCII text, with very long lines (42133)
dropped
Chrome Cache Entry: 235
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 236
ASCII text, with very long lines (34235), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 237
ASCII text, with very long lines (13140)
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (3385), with no line terminators
downloaded
There are 109 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2248 --field-trial-handle=2196,i,4525585386826145495,10144725593978225122,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://microsoft.biosency.com/"

URLs

Name
IP
Malicious
http://microsoft.biosency.com/
malicious
https://microsoft.biosency.com/
malicious
https://microsoft.biosency.com/assets/img/background.png
130.93.125.135
malicious
http://microsoft.biosency.com/
130.93.125.135
malicious
https://microsoft.biosency.com/assets/img/favicon32.svg
130.93.125.135
malicious
https://microsoft.biosency.com/assets/img/microsoft_logo.svg
130.93.125.135
malicious
https://microsoft.biosency.com/assets/css/styles.min.css
130.93.125.135
malicious
https://microsoft.biosency.com/assets/js/script.min.js
130.93.125.135
malicious
https://icons8.com/good-boy-license/
unknown
https://icons8.com/
unknown
https://signup.live.com/?lic=1
https://mem.gfx.ms/scripts/me/MeControl/10.24228.4/en-US/meCore.min.js
13.107.246.45
https://use.fontawesome.com/releases/v5.12.0/css/all.css
unknown
https://github.com/FontCustom/fontcustom
unknown
https://mem.gfx.ms/meversion?partner=SMCConvergence&market=en-us&uhf=1
13.107.246.45
https://github.com/icons8
unknown
http://knockoutjs.com/
unknown
https://client.hsprotect.net/PXzC5j78di/main.min.js
unknown
https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.5.0/js/bootstrap.bundle.min.js
104.17.25.14
https://github.com/douglascrockford/JSON-js
unknown
https://getbootstrap.com/)
unknown
https://login.windows-ppe.net
unknown
https://fpt.live.com/
unknown
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.5.1/jquery.min.js
104.17.25.14
https://maxcdn.icons8.com/fonts/line-awesome/1.1/css/line-awesome.min.css
195.181.170.18
https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/4.5.0/css/bootstrap.min.css
104.17.25.14
https://icons8.com/contact
unknown
https://fontawesome.com/license/free
unknown
https://icons8.com/line-awesome
unknown
https://twitter.com/icons_8
unknown
https://fontawesome.com
unknown
https://plus.google.com/
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://login.microsoftonline.com
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://aadcdn.msftauth.net/shared/1.0/content/js/BssoInterrupt_Core_JQnUxWSvwsd9FrpspQmznw2.js
152.199.21.175
https://maxcdn.icons8.com/fonts/line-awesome/1.1/fonts/line-awesome.woff2?v=1.1.
195.181.170.18
https://stk.hsprotect.net/ns?c=029dbc40-7e2b-11ef-856f-85724689caa7
34.107.199.61
https://collector-pxzc5j78di.hsprotect.net/api/v2/msft
35.190.10.96
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
http://github.com/requirejs/almond/LICENSE
unknown
https://logincdn.msftauth.net/16.000/content/js/MeControl_byKfhfjpuoP7eXmeHHGYoA2.js
152.199.21.175
https://mem.gfx.ms/scripts/me/MeControl/10.24228.4/en-US/meBoot.min.js
13.107.246.45
https://js.monitor.azure.com/scripts/c/ms.shared.analytics.mectrl-3.gbl.min.js
13.107.246.67
There are 33 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0016.t-0009.t-msedge.net
13.107.246.44
sni1gl.wpc.alphacdn.net
152.199.21.175
s-part-0017.t-0009.t-msedge.net
13.107.246.45
s-part-0039.t-0009.t-msedge.net
13.107.246.67
fp2e7a.wpc.phicdn.net
192.229.221.95
s-part-0029.t-0009.t-msedge.net
13.107.246.57
bg.microsoft.map.fastly.net
199.232.210.172
inbound-weighted.protechts.net
35.190.10.96
cdnjs.cloudflare.com
104.17.25.14
s-part-0036.t-0009.t-msedge.net
13.107.246.64
sni1gl.wpc.omegacdn.net
152.199.21.175
www.google.com
216.58.206.68
stk.hsprotect.net
34.107.199.61
microsoft.biosency.com
130.93.125.135
1220595937.rsc.cdn77.org
195.181.170.18
s-part-0032.t-0009.t-msedge.net
13.107.246.60
js.monitor.azure.com
unknown
signup.live.com
unknown
collector-pxzc5j78di.hsprotect.net
unknown
aadcdn.msftauth.net
unknown
logincdn.msftauth.net
unknown
mem.gfx.ms
unknown
use.fontawesome.com
unknown
client.hsprotect.net
unknown
c.s-microsoft.com
unknown
maxcdn.icons8.com
unknown
msft.hsprotect.net
unknown
support.content.office.net
unknown
login.microsoftonline.com
unknown
fpt.live.com
unknown
acctcdn.msftauth.net
unknown
There are 21 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.64
s-part-0036.t-0009.t-msedge.net
United States
35.190.10.96
inbound-weighted.protechts.net
United States
13.107.246.67
s-part-0039.t-0009.t-msedge.net
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
13.107.246.44
s-part-0016.t-0009.t-msedge.net
United States
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
34.107.199.61
stk.hsprotect.net
United States
13.107.246.57
s-part-0029.t-0009.t-msedge.net
United States
195.181.170.18
1220595937.rsc.cdn77.org
United Kingdom
130.93.125.135
microsoft.biosency.com
France
216.58.206.68
www.google.com
United States
239.255.255.250
unknown
Reserved
152.199.21.175
sni1gl.wpc.alphacdn.net
United States
104.17.25.14
cdnjs.cloudflare.com
United States
There are 6 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://microsoft.biosency.com/
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://signup.live.com/?lic=1
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
https://support.microsoft.com/en-us/windows/configure-windows-hello-dae28983-8242-bb2a-d3d1-87c9d265a5f0
There are 8 hidden doms, click here to show them.