IOC Report
http://www.telegram-korea.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
dropped
Chrome Cache Entry: 101
HTML document, ASCII text, with very long lines (3075), with no line terminators
downloaded
Chrome Cache Entry: 102
MS Windows icon resource - 3 icons, 32x32 with PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 48x48 with PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 103
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 104
Unicode text, UTF-8 text, with very long lines (10089)
downloaded
Chrome Cache Entry: 105
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 106
Unicode text, UTF-8 text, with very long lines (18363)
dropped
Chrome Cache Entry: 107
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 108
Web Open Font Format (Version 2), TrueType, length 11016, version 1.0
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (10884)
downloaded
Chrome Cache Entry: 110
PNG image data, 50 x 50, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 111
PNG image data, 1123 x 2307, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 112
JSON data
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (21341)
dropped
Chrome Cache Entry: 114
ASCII text, with very long lines (27299)
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (45788)
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (10884)
dropped
Chrome Cache Entry: 118
HTML document, Unicode text, UTF-8 text, with very long lines (45662)
downloaded
Chrome Cache Entry: 119
ASCII text
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (21341)
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (27299)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 124
PNG image data, 50 x 50, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 125
Audio file with ID3 version 2.3.0, contains: MPEG ADTS, layer III, v1, 128 kbps, 44.1 kHz, JntStereo
downloaded
Chrome Cache Entry: 126
MS Windows icon resource - 3 icons, 32x32 with PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 48x48 with PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 127
Unicode text, UTF-8 text, with very long lines (18363)
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (2720)
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 130
HTML document, Unicode text, UTF-8 text, with very long lines (1689)
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (12216)
dropped
Chrome Cache Entry: 132
PNG image data, 1 x 1, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (45788)
dropped
Chrome Cache Entry: 134
WebAssembly (wasm) binary module version 0x1 (MVP)
dropped
Chrome Cache Entry: 135
HTML document, Unicode text, UTF-8 text, with very long lines (45662)
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (10797)
downloaded
Chrome Cache Entry: 137
ASCII text
downloaded
Chrome Cache Entry: 138
gzip compressed data, was "PlaneLogoPlain.json", last modified: Fri Dec 17 11:58:31 2021, from Unix, original size modulo 2^32 18810
downloaded
Chrome Cache Entry: 91
WebAssembly (wasm) binary module version 0x1 (MVP)
downloaded
Chrome Cache Entry: 92
Web Open Font Format (Version 2), TrueType, length 11056, version 1.0
downloaded
Chrome Cache Entry: 93
HTML document, ASCII text, with very long lines (413)
dropped
Chrome Cache Entry: 94
PNG image data, 1123 x 2307, 4-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 95
ASCII text, with very long lines (2720)
downloaded
Chrome Cache Entry: 96
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 97
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (12216)
downloaded
Chrome Cache Entry: 99
HTML document, ASCII text, with very long lines (413)
downloaded
There are 39 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2232 --field-trial-handle=2096,i,8483295597015540071,17211286166102633970,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.telegram-korea.com/"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5100 --field-trial-handle=2096,i,8483295597015540071,17211286166102633970,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://tg//login?token=AQJy8vhmN014-7dXpydYSIkLyCbRzXFRyqmbR2raCyxBRw
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2088 --field-trial-handle=1980,i,3693984814097655640,266080906061697423,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
http://www.telegram-korea.com/
malicious
http://www.telegram-korea.com/
104.21.80.160
malicious
https://t.me/
unknown
https://web.telegram.org/a/8287.9cf863b4d9b47c10d271.js
149.154.167.99
https://web.telegram.org/a/notification.mp3
149.154.167.99
https://web.telegram.org/a/icon-192x192.png
149.154.167.99
https://a.nel.cloudflare.com/report/v4?s=%2FUwpJRqmYwbusTb8N4nab%2BJiBz8EigXxrkAcGDq5wgQG3kLR5GeECXrAqFHQV2%2BJruIsRO04XLWF5VWcX434ac0t2v3CVF8MeJTG5WPPGs355IaZNZv0jkEDr61yRpctNc0AXs2lho0C
35.190.80.1
https://www.telegram-korea.com/red.js
104.21.80.160
https://web.telegram.org/k/
unknown
https://web.telegram.org/a/7283.fffaae54cb7b28e809f3.js
149.154.167.99
https://web.telegram.org/a/7784.4e167a928464165e6412.js
149.154.167.99
https://web.telegram.org/a/favicon.ico
149.154.167.99
https://telegram.me/_websync_?authed=0&version=10.9.16+A
149.154.167.99
https://web.telegram.org/a/5193.277e1fb9e38cc39cf421.js
149.154.167.99
https://web.telegram.org/a/QrPlane.a921709f266564f65b7e.tgs
149.154.167.99
https://www.telegram-korea.com/index-vX_PR0Tt.css
104.21.80.160
https://zws2-1.web.telegram.org/apiws
149.154.167.99
https://web.telegram.org/a/3559.e75e88411c413b6642fc.js
149.154.167.99
https://zws2.web.telegram.org/apiws
149.154.167.99
https://telegram.org/tos/mini-apps
unknown
https://web.telegram.org/a/main.9ac4c9044b7b428a4db7.css
149.154.167.99
https://web.telegram.org/a/compatTest.js
149.154.167.99
https://web.telegram.org/a/site.webmanifest
149.154.167.99
https://web.telegram.org/a/6708.457f852af5d5245dd736.js
149.154.167.99
https://www.telegram-korea.com/
104.21.80.160
https://web.telegram.org/a
unknown
https://web.telegram.org/
unknown
https://t.me/_websync_?authed=0&version=10.9.16+A
149.154.167.99
https://www.telegram-korea.com/login.js
104.21.80.160
https://browsehappy.com/
unknown
https://web.telegram.org/a/9722.9631503239ae4a1949cd.js
149.154.167.99
https://web.telegram.org/a/blank.8dd283bceccca95a48d8.png
149.154.167.99
https://web.telegram.org/a/main.9482f3e91e0fa8095fed.js
149.154.167.99
http://telegram.org/dl
unknown
https://github.com/rastikerdar/vazirmatn
unknown
https://web.telegram.org/a/
https://web.telegram.org/a/chat-bg-br.f34cc96fbfb048812820.png
149.154.167.99
https://web.telegram.org/a/KFOlCnqEu92Fr1MmEU9fBBc4AMP6lQ.324b1e6d0f5ae7c6ab42.woff2
149.154.167.99
https://www.telegram-korea.com/index-DMLC1qu5.js
104.21.80.160
https://web.telegram.org/a/rlottie-wasm.wasm
149.154.167.99
https://web.telegram.org/a/9357.cb9c9a71b6859fe151d6.js
149.154.167.99
https://web.telegram.org/a/KFOmCnqEu92Fr1Mu4mxKKTU1Kg.465390c6e54c60f4a15f.woff2
149.154.167.99
https://ss3.4sqi.net/img/categories_v2/
unknown
https://zws2-1.web.telegram.org/apiw1
149.154.167.99
https://web.telegram.org/a/5905.efaeccc9ed0bc890f551.js
149.154.167.99
https://t.me/_websync_
unknown
https://zws2.web.telegram.org/apiw1
149.154.167.99
https://web.telegram.org/a/5284.42d2925da5b1075750df.js
149.154.167.99
https://web.telegram.org/a/3046.1fba2d7e327c53d1e37e.js
149.154.167.99
https://telegram.me/_websync_;
unknown
https://www.telegram-korea.com/jquery-3.6.1.min.js
104.21.80.160
https://web.telegram.org/a/redirect.js
149.154.167.99
https://web.telegram.org/a/rlottie-wasm.f013598f1b2ba719f25e.js
149.154.167.99
https://web.telegram.org/a/chat-bg-pattern-light.ee148af944f6580293ae.png
149.154.167.99
There are 43 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
a.nel.cloudflare.com
35.190.80.1
google.com
142.250.184.206
web.telegram.org
149.154.167.99
zws2.web.telegram.org
149.154.167.99
www.telegram-korea.com
104.21.80.160
telegram.me
149.154.167.99
t.me
149.154.167.99
www.google.com
172.217.16.196
zws2-1.web.telegram.org
149.154.167.99
fp2e7a.wpc.phicdn.net
192.229.221.95
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.80.160
www.telegram-korea.com
United States
192.168.2.4
unknown
unknown
149.154.167.99
web.telegram.org
United Kingdom
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States
172.217.16.196
www.google.com
United States

DOM / HTML

URL
Malicious
https://web.telegram.org/a/
https://web.telegram.org/a/
https://web.telegram.org/a/
https://web.telegram.org/a/