IOC Report
https://metrics.send.hotmart.com/v2/events/click/64ec6af4-7b81-4abf-9e97-fe7d70d45255?d=1nFwG70sgZqlXE

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 48
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 49
ASCII text, with very long lines (8093), with no line terminators
dropped
Chrome Cache Entry: 50
ASCII text, with very long lines (47261)
downloaded
Chrome Cache Entry: 51
ASCII text, with very long lines (47261)
dropped
Chrome Cache Entry: 52
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 53
PNG image data, 53 x 100, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 54
PNG image data, 53 x 100, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 55
ASCII text, with very long lines (8032), with no line terminators
downloaded
Chrome Cache Entry: 56
HTML document, ASCII text, with very long lines (1195), with no line terminators
downloaded
Chrome Cache Entry: 57
HTML document, ASCII text, with very long lines (17577)
downloaded
Chrome Cache Entry: 58
HTML document, ASCII text, with no line terminators
downloaded
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2284 --field-trial-handle=2208,i,6234584823592615281,13955222929844979888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://metrics.send.hotmart.com/v2/events/click/64ec6af4-7b81-4abf-9e97-fe7d70d45255?d=1nFwG70sgZqlXE"

URLs

Name
IP
Malicious
https://metrics.send.hotmart.com/v2/events/click/64ec6af4-7b81-4abf-9e97-fe7d70d45255?d=1nFwG70sgZqlXE
malicious
https://ailix.ca/cdn-cgi/challenge-platform/h/g/scripts/jsd/ec4b873d446c/main.js?
199.34.228.59
https://a.nel.cloudflare.com/report/v4?s=hpzPtE4nQZ2%2BRghJ4IqcA5%2BEQsNzIVQQSwVopgel1XElR0nXisYxaCEtitFlP6m6XMj1dCTeZhvHQJ3JeeLGB%2FgwgJIIiaMJzV%2FoNXu73nGz%2FWgjfIXxqpFAmg%3D%3D
35.190.80.1
https://ailix.ca/SWISSCRD/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=8cb364705e970c74&lang=auto
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8cb364705e970c74/1727690705340/79a05e5771d9f138da1fa786b3c9401d723d075a4fd88e30c0753c6d341b78d2/fjrDY1mgwnQAtQ2
104.18.94.41
https://a.nel.cloudflare.com/report/v4?s=XHN0IFx7y6yO5ZRV5OKSf8ZBp8DGZMm6PoeEYdv%2F5hE2Cyux%2FHLPQ%2F3GmfB4nrCsYz3mWIDVz%2Bugp6x%2BBMZRHXITYLsi1OlzCh6pyUh6MT%2FM6RQWQ29WOqH0ig%3D%3D
35.190.80.1
https://ailix.ca/cdn-cgi/challenge-platform/h/g/flow/ov1/1121818049:1727687596:u04N2tx6ZhVDdsrsXldjO0ZOHQHPfk5Tbwpa6edSUJE/8cb3645eefce41d2/99e81aaf43bf070
199.34.228.59
https://a.nel.cloudflare.com/report/v4?s=bh9b2hDvSar15npv%2BuQ%2FiNOVlLIaugVe%2FkvjjeMHS3eJkqPBmxwg5Z3EosW0QDqvW9PH6Q%2BKLVVMGClmaBnQdYdhsED8Ww7T2PHUI46lRb9EnLEEVarkol1uHg%3D%3D
35.190.80.1
https://ailix.ca/favicon.ico
199.34.228.59
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/r83kz/0x4AAAAAAAAjq6WYeRDKmebM/light/fbE/normal/auto/
104.18.94.41
https://ailix.ca/cdn-cgi/challenge-platform/h/g/orchestrate/chl_page/v1?ray=8cb3645eefce41d2
199.34.228.59
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/1972469579:1727687737:pnNd1XWPNMwwL3y3zwhykYmtP36AIv0neYK-wF8KSIE/8cb364705e970c74/96b0c515c674238
104.18.94.41
https://metrics.send.hotmart.com/v2/events/click/64ec6af4-7b81-4abf-9e97-fe7d70d45255?d=1nFwG70sgZqlXE
35.170.189.25
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8cb364705e970c74/1727690705338/YsbGRj68w4ao0SO
104.18.94.41
https://hotm.art/23857239523588
100.28.19.90
https://ailix.ca/cdn-cgi/challenge-platform/scripts/jsd/main.js
199.34.228.59
https://ailix.ca/cdn-cgi/challenge-platform/h/g/jsd/r/8cb365288c9a42b0
199.34.228.59
There are 8 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
a.nel.cloudflare.com
35.190.80.1
hotm.art
100.28.19.90
ailix.ca
199.34.228.59
challenges.cloudflare.com
104.18.95.41
metrics.send.hotmart.com
35.170.189.25
www.google.com
142.250.185.68
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
199.34.228.59
ailix.ca
United States
142.250.185.68
www.google.com
United States
100.28.19.90
hotm.art
United States
104.18.94.41
unknown
United States
104.18.95.41
challenges.cloudflare.com
United States
192.168.2.6
unknown
unknown
35.170.189.25
metrics.send.hotmart.com
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://ailix.ca/SWISSCRD/
https://ailix.ca/SWISSCRD/
https://ailix.ca/SWISSCRD/
https://ailix.ca/SWISSCRD/
https://ailix.ca/SWISSCRD/