IOC Report
https://www.google.com.ai/amp/clck.ru/3DSSCz?hghghghHGVGvbbgffGFHGJdgddghfhghfgdgdgdgfhgg?sdfsewsrewrettfg

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:05:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:05:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:05:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:05:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:05:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 103
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 104
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 106
PNG image data, 453 x 452, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 107
PNG image data, 800 x 800, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 108
Java source, ASCII text
dropped
Chrome Cache Entry: 109
HTML document, ASCII text
downloaded
Chrome Cache Entry: 110
Java source, ASCII text
downloaded
Chrome Cache Entry: 111
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 112
JSON data
dropped
Chrome Cache Entry: 113
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 120
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 121
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 256x256, components 3
dropped
Chrome Cache Entry: 122
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 123
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 127
Java source, ASCII text
dropped
Chrome Cache Entry: 128
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 129
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 256x256, components 3
dropped
Chrome Cache Entry: 131
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 132
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 133
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (328)
downloaded
Chrome Cache Entry: 137
Java source, ASCII text
downloaded
Chrome Cache Entry: 140
C++ source, ASCII text
downloaded
Chrome Cache Entry: 141
gzip compressed data, from Unix, original size modulo 2^32 2183
downloaded
Chrome Cache Entry: 145
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 146
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 147
JSON data
downloaded
Chrome Cache Entry: 148
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 256x256, components 3
dropped
Chrome Cache Entry: 150
Java source, ASCII text
downloaded
Chrome Cache Entry: 152
PNG image data, 217 x 182, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 154
C++ source, ASCII text, with very long lines (1008)
downloaded
Chrome Cache Entry: 155
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 157
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 158
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 160
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 161
PNG image data, 126 x 127, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 162
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 79
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 80
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 81
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 256x256, components 3
dropped
Chrome Cache Entry: 83
Java source, Unicode text, UTF-8 text, with very long lines (923)
dropped
Chrome Cache Entry: 84
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 85
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 86
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 256x256, components 3
dropped
Chrome Cache Entry: 87
Java source, Unicode text, UTF-8 text, with very long lines (1623)
dropped
Chrome Cache Entry: 88
Java source, ASCII text
downloaded
Chrome Cache Entry: 89
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 92
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 256x256, components 3
dropped
Chrome Cache Entry: 93
Java source, ASCII text
downloaded
Chrome Cache Entry: 94
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 99
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
dropped
There are 48 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://www.google.com.ai/amp/clck.ru/3DSSCz?hghghghHGVGvbbgffGFHGJdgddghfhghfgdgdgdgfhgg?sdfsewsrewrettfg
malicious
https://bitcheff.fun/payouts/
malicious
https://bitcheff.fun/payouts/account/
malicious
http://a1034295.xsph.ru/vew/ye/worke/
141.8.192.26
malicious
http://a1034295.xsph.ru/favicon.ico
141.8.192.26
malicious
http://clck.ru/3DSSCz
213.180.204.221

Domains

Name
IP
Malicious
perisalpingitis.xyz
104.21.27.6
malicious
bitcheff.fun
104.21.5.185
malicious
a1034295.xsph.ru
141.8.192.26
malicious
www.google.com.ai
142.250.186.99
api.coingecko.com
104.22.79.164
a.nel.cloudflare.com
35.190.80.1
clck.ru
213.180.204.221
i.postimg.cc
46.105.222.81
www.google.com
142.250.184.196
dualstack.com.imgix.map.fastly.net
151.101.2.208
sba.yandex.net
213.180.193.232
www.google.ad
172.217.18.99
plus.unsplash.com
unknown
sba.yandex.ru
unknown
images.unsplash.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
141.8.192.26
a1034295.xsph.ru
Russian Federation
malicious
104.21.5.185
bitcheff.fun
United States
malicious
104.21.27.6
perisalpingitis.xyz
United States
malicious
216.58.206.74
unknown
United States
142.250.74.206
unknown
United States
192.168.2.17
unknown
unknown
192.168.2.16
unknown
unknown
104.22.79.164
api.coingecko.com
United States
142.250.185.106
unknown
United States
74.125.206.84
unknown
United States
104.22.78.164
unknown
United States
213.180.204.221
clck.ru
Russian Federation
142.250.186.110
unknown
United States
172.217.18.99
www.google.ad
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.186.99
www.google.com.ai
United States
142.250.184.202
unknown
United States
46.105.222.81
i.postimg.cc
France
142.250.184.196
www.google.com
United States
1.1.1.1
unknown
Australia
142.250.186.163
unknown
United States
151.101.2.208
dualstack.com.imgix.map.fastly.net
United States
162.249.168.129
unknown
United States
239.255.255.250
unknown
Reserved
172.217.16.195
unknown
United States
213.180.193.232
sba.yandex.net
Russian Federation
There are 16 hidden IPs, click here to show them.