IOC Report
https://www.66cryptocurrency.com/#/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:37:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:37:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:37:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:37:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:37:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
downloaded
Chrome Cache Entry: 101
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 102
PNG image data, 182 x 182, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (24780)
dropped
Chrome Cache Entry: 104
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 105
Unicode text, UTF-8 text, with very long lines (3824)
dropped
Chrome Cache Entry: 106
HTML document, ASCII text, with very long lines (724), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (1164)
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (19948), with no line terminators
dropped
Chrome Cache Entry: 109
PNG image data, 182 x 182, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 110
PNG image data, 2880 x 1642, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 111
PNG image data, 182 x 182, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 112
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 113
ASCII text, with very long lines (19948), with no line terminators
downloaded
Chrome Cache Entry: 114
MS Windows icon resource - 1 icon, 48x48, 32 bits/pixel
downloaded
Chrome Cache Entry: 115
Unicode text, UTF-8 text, with very long lines (3824)
downloaded
Chrome Cache Entry: 116
JSON data
dropped
Chrome Cache Entry: 117
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (2554)
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 120
PNG image data, 182 x 182, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 121
PNG image data, 182 x 182, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 122
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 123
JSON data
dropped
Chrome Cache Entry: 124
JSON data
dropped
Chrome Cache Entry: 125
PNG image data, 2880 x 1642, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (27807)
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 129
MS Windows icon resource - 1 icon, 48x48, 32 bits/pixel
dropped
Chrome Cache Entry: 130
JSON data
dropped
Chrome Cache Entry: 131
JSON data
downloaded
Chrome Cache Entry: 132
PNG image data, 448 x 494, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 133
JSON data
dropped
Chrome Cache Entry: 134
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 135
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 137
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 138
JSON data
dropped
Chrome Cache Entry: 139
JSON data
dropped
Chrome Cache Entry: 140
PNG image data, 1500 x 736, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 141
PNG image data, 1500 x 736, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 142
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 143
PNG image data, 448 x 494, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (2554)
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (27807)
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (1164)
downloaded
Chrome Cache Entry: 147
JSON data
dropped
Chrome Cache Entry: 148
JSON data
downloaded
Chrome Cache Entry: 149
PNG image data, 2048 x 400, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 150
JSON data
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (24780)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (36529)
downloaded
Chrome Cache Entry: 97
PNG image data, 512 x 512, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 98
PNG image data, 182 x 182, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 99
PNG image data, 512 x 512, 8-bit/color RGB, non-interlaced
dropped
There are 53 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2024,i,17739861868011216194,14799447997415528976,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.66cryptocurrency.com/#/"

URLs

Name
IP
Malicious
https://www.66cryptocurrency.com/#/
https://www.66cryptocurrency.com/pceast/static/js/app.028c8a25fb5139cf3b5b.js
188.114.96.3
https://ksoc.66cryptocurrency.com/handler
188.114.96.3
https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015
104.16.80.73
https://www.66cryptocurrency.com/pceast/static/js/22.0b120ac46f0b24efa0df.js
188.114.96.3
https://cdn.staticfile.org/respond.js/1.4.2/respond.min.js
unknown
https://npms.io/search?q=ponyfill.
unknown
https://www.66cryptocurrency.com/pceast/static/img/20240529007.a6c15b3.png
188.114.96.3
https://www.66cryptocurrency.com/ads/getAdsList;randToken=942861DF005513DD78DA6061F892A91A
188.114.96.3
https://www.66cryptocurrency.com/pceast/static/js/2.c92f5d3aef64d9ae4702.js
188.114.96.3
https://www.66cryptocurrency.com/pceast/static/img/20240529008.b8d1c00.png
188.114.96.3
https://www.66cryptocurrency.com/
188.114.96.3
https://www.66cryptocurrency.com/getOperatorInfo?userLang=en
188.114.96.3
https://www.66cryptocurrency.com/pceast/static/img/20240529006.794c800.png
188.114.96.3
https://lodash.com/
unknown
https://www.66cryptocurrency.com/pceast/static/img/20240529005.62e6fb8.png
188.114.96.3
https://www.66cryptocurrency.com/pceast/static/js/vendor.02ac3a4f41995484632d.js
188.114.96.3
https://www.66cryptocurrency.com/pceast/static/js/0.9cb8ea11f975c98e11a5.js
188.114.96.3
https://www.66cryptocurrency.com/pceast/static/js/17.1ef8a0fb000d7750c4e5.js
188.114.96.3
https://www.66cryptocurrency.com/getOperatorInfo;randToken=942861DF005513DD78DA6061F892A91A?userLang=en
188.114.96.3
https://www.66cryptocurrency.com/appVersion;randToken=942861DF005513DD78DA6061F892A91A
188.114.96.3
https://www.66cryptocurrency.com//apk/manycury/manycury.apk
unknown
https://www.exchange-manycoin.com//uploadfile/p468/ads/t2/2024/09/21/20/46548058771146255.png
172.67.174.173
https://www.66cryptocurrency.com/cms/getArticleListByCmsType;randToken=942861DF005513DD78DA6061F892A91A
188.114.96.3
https://www.66cryptocurrency.com/pceast/static/css/app.49a10c3cfb513eb07a3b5765f7723033.css
188.114.96.3
https://www.66cryptocurrency.com/ads/getAdsList
188.114.96.3
https://www.exchange-manycoin.com//uploadfile/p468/ads/t2/2024/09/21/20/46548027449712264.png
172.67.174.173
https://www.66cryptocurrency.com/favicon.ico
188.114.96.3
http://underscorejs.org/LICENSE
unknown
https://www.66cryptocurrency.com/pceast/static/js/manifest.521d1a335ba340fac413.js
188.114.96.3
https://www.66cryptocurrency.com/appVersion
188.114.96.3
https://www.exchange-manycoin.com//uploadfile/p468/ads/t2/2024/09/21/20/46548031019194981.png
172.67.174.173
https://www.66cryptocurrency.com/logo.png
188.114.96.3
https://www.66cryptocurrency.com/cms/getArticleListByCmsType
188.114.96.3
https://lodash.com/license
unknown
https://www.exchange-manycoin.com//uploadfile/p468/ads/t2/2024/09/21/20/46548098596732792.png
172.67.174.173
https://www.66cryptocurrency.com/cdn-cgi/rum?
188.114.96.3
https://www.66cryptocurrency.com/switchLang;randToken=942861DF005513DD78DA6061F892A91A
188.114.96.3
https://www.exchange-manycoin.com//uploadfile/p468/ads/t2/2024/09/21/01/46541365545970241.png
172.67.174.173
https://cdn.staticfile.org/html5shiv/r29/html5.min.js
unknown
https://www.66cryptocurrency.com/#/
https://www.66cryptocurrency.com/pceast/static/img/20240529004.133aed3.png
188.114.96.3
https://js.foundation/
unknown
https://www.66cryptocurrency.com/pceast/static/js/3.c2814099c3e3adc6f2db.js
188.114.96.3
There are 33 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.exchange-manycoin.com
172.67.174.173
bg.microsoft.map.fastly.net
199.232.210.172
static.cloudflareinsights.com
104.16.80.73
ksoc.66cryptocurrency.com
188.114.96.3
www.66cryptocurrency.com
188.114.96.3
www.google.com
172.217.16.132
fp2e7a.wpc.phicdn.net
192.229.221.95
windowsupdatebg.s.llnwi.net
87.248.204.0

IPs

IP
Domain
Country
Malicious
192.168.2.8
unknown
unknown
172.67.174.173
www.exchange-manycoin.com
United States
192.168.2.5
unknown
unknown
104.16.80.73
static.cloudflareinsights.com
United States
239.255.255.250
unknown
Reserved
188.114.96.3
ksoc.66cryptocurrency.com
European Union
104.16.79.73
unknown
United States
172.217.16.132
www.google.com
United States

DOM / HTML

URL
Malicious
https://www.66cryptocurrency.com/#/
https://www.66cryptocurrency.com/#/
https://www.66cryptocurrency.com/#/
https://www.66cryptocurrency.com/#/
https://www.66cryptocurrency.com/#/
https://www.66cryptocurrency.com/#/