IOC Report
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:45:14 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:45:14 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 08:59:33 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:45:14 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:45:14 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:45:14 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 101
PNG image data, 768 x 768, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 102
PNG image data, 2124 x 540, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 103
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 104
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 106
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 107
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 108
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 109
ASCII text
downloaded
Chrome Cache Entry: 110
PNG image data, 30 x 13, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 111
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 112
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 113
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 114
PNG image data, 768 x 768, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 115
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 116
PNG image data, 2124 x 540, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 117
HTML document, ASCII text, with very long lines (460)
downloaded
Chrome Cache Entry: 118
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 119
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 120
ASCII text
downloaded
Chrome Cache Entry: 121
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 122
HTML document, ASCII text, with very long lines (945), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 123
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (47261)
downloaded
Chrome Cache Entry: 125
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 126
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 82
ASCII text, with very long lines (8023), with no line terminators
dropped
Chrome Cache Entry: 83
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 84
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 85
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 86
PNG image data, 768 x 768, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 87
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 88
ASCII text, with very long lines (7994), with no line terminators
downloaded
Chrome Cache Entry: 89
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 90
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 91
PNG image data, 2124 x 540, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 92
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 93
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 94
ASCII text, with very long lines (47261)
dropped
Chrome Cache Entry: 95
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 96
HTML document, ASCII text, with very long lines (5391)
downloaded
Chrome Cache Entry: 97
PNG image data, 30 x 13, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 98
ASCII text
downloaded
Chrome Cache Entry: 99
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 120x40, components 3
downloaded
There are 43 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2144 --field-trial-handle=1912,i,613442065323464903,15756170246525982075,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ=="

URLs

Name
IP
Malicious
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/img/works/5.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/images/f5.jpg
172.67.145.77
https://sitespecfics.net/captcha?t=
unknown
http://mixitup.io
unknown
https://sitespecfics.net/public/assets/css/style.css?v=TQcsfkXzcifx
172.67.145.77
https://sitespecfics.net/goodlawyer/images/p7.jpg
172.67.145.77
https://a.nel.cloudflare.com/report/v4?s=TGA0WqweLg0yG5LJRL4nzDwH8gabCZbl%2BtrPnOswe8T0aOBbFWOQ4aEgMB%2ByWSN%2FY49kLR%2FFYsqo9R%2B6fxg1mwtQy8oCV92zCPOfh0T8wwN4%2BBCaQOPlLq8X4GrR1XVf%2BLGb
35.190.80.1
https://sitespecfics.net/goodlawyer/js/jquery.magnific-popup.js
172.67.145.77
https://sitespecfics.net/goodlawyer/css/animate.css
172.67.145.77
https://sitespecfics.net/goodlawyer/img/works/3.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/modernizr.custom.28468.js
172.67.145.77
http://creativecommons.org/licenses/by/3.0/
unknown
https://sitespecfics.net/goodlawyer/js/jquery.scrollTo.js
172.67.145.77
https://sitespecfics.net/cdn-cgi/challenge-platform/scripts/jsd/main.js
172.67.145.77
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==#service
https://sitespecfics.net/goodlawyer/images/p5.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/img/works/7.jpg
172.67.145.77
https://sitespecfics.net/verify-captcha
unknown
https://a.nel.cloudflare.com/report/v4?s=QYaVMDSqDp550fDtRSB7u%2BoDWJ9%2Byxmc9hM74h%2FEZ93et3QC0gFDasqMfDdvsOjhfWpMrEoowOVYHOA7jM8eeUBoMkxQCNLRUtIYemvM8vt96mDOYv%2BADlwQ9a7X2ZwBVl6X
35.190.80.1
https://sitespecfics.net/goodlawyer/css/flexslider.css
172.67.145.77
https://sitespecfics.net/goodlawyer/css/magnific-popup.css
172.67.145.77
https://sitespecfics.net/goodlawyer/css/bootstrap.min.css
172.67.145.77
http://w3layouts.com
unknown
https://sitespecfics.net/public/assets/images/auth/4ohtJD7FTpULVac.png
172.67.145.77
https://sitespecfics.net/public/assets/css/style.css?v=HoMYhVOadege
172.67.145.77
https://sitespecfics.net/public/assets/images/logo/zpwY2cwM.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/images/p2.jpg
172.67.145.77
https://sitespecfics.net/public/assets/images/logo/UtlQz7eF.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/images/f2.jpg
172.67.145.77
https://code.jquery.com/jquery-3.7.1.min.js
151.101.2.137
https://sitespecfics.net/cdn-cgi/challenge-platform/h/g/flow/ov1/907130782:1727882822:JoWnLZl3Dahx4dgR8oJrH6CfrdGXwysqmiGMshHvp-o/8cc5d1937c90437a/796dc299c519a21
172.67.145.77
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==?__cf_chl_tk=kzaak0pUaPMAo9PoYNMhO39tPnRhJ2FModzsiIpeWzo-1727883917-0.0.1.1-5438
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8cc5d1b31e4472a4/1727883924816/24fcf336a5990340efa5f6db96d63db4837b5d913b28f567ebe85a5d55a73f36/-0PpSBNP8A8JuF1
104.18.95.41
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==#contact
https://sitespecfics.net/goodlawyer/img/works/2.jpg
172.67.145.77
https://sitespecfics.net/favicon.ico
172.67.145.77
https://sitespecfics.net/goodlawyer/js/hover.zoom.js
172.67.145.77
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8cc5d1b31e4472a4/1727883924820/DFLx4heTiC9mutP
104.18.95.41
https://sitespecfics.net/cdn-cgi/challenge-platform/h/g/orchestrate/chl_page/v1?ray=8cc5d1937c90437a
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.mixitup.min.js
172.67.145.77
https://sitespecfics.net/goodlawyer/css/jquery.mmenu.all.css
172.67.145.77
https://sitespecfics.net/goodlawyer/img/2.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/uisearch.js
172.67.145.77
https://sitespecfics.net/goodlawyer/js/wow.min.js
172.67.145.77
https://sitespecfics.net/goodlawyer/images/f4.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.sticky.js
172.67.145.77
https://sitespecfics.net/goodlawyer/images/p8.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.appear.js
172.67.145.77
https://sitespecfics.net/cdn-cgi/challenge-platform/h/g/scripts/jsd/ec4b873d446c/main.js?
172.67.145.77
https://sitespecfics.net/goodlawyer/img/works/4.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.flexisel.js
172.67.145.77
https://sitespecfics.net/goodlawyer/images/p6.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/custom.js
172.67.145.77
https://sitespecfics.net/goodlawyer/css/owl.theme.css
172.67.145.77
https://sitespecfics.net/goodlawyer/css/owl.carousel.css
172.67.145.77
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/images/f6.jpg
172.67.145.77
https://eeinvestorse.za.com/YsXjf/#Zearl.martin
unknown
https://sitespecfics.net/captcha
172.67.145.77
https://sitespecfics.net/goodlawyer/js/modernizr.custom.js
172.67.145.77
https://sitespecfics.net/public/assets/images/logo/RxFnCOy5.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/css/nivo-lightbox.css
172.67.145.77
https://sitespecfics.net/public/assets/css/style.css?v=DhwqnJYBErKB
172.67.145.77
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.18.95.41
https://sitespecfics.net/goodlawyer/images/logo.png
172.67.145.77
https://sitespecfics.net/public/assets/images/auth/2vUSIeV7rN0G9OG.png
172.67.145.77
https://sitespecfics.net/goodlawyer/img/works/6.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/images/p4.jpg
172.67.145.77
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=8cc5d1b31e4472a4&lang=auto
104.18.95.41
https://sitespecfics.net/goodlawyer/img/dummy1.jpg
172.67.145.77
https://a.nel.cloudflare.com/report/v4?s=4wR3e1%2B8cmGcKROaeXyNEEygOJOYrs7jXf1AsiD%2Bx6RDHIfQyffXLDMtJeXsj3djldwCqw85eVKA%2Ff9%2FN9F8wZlAEi8sM5FU0Xd9U2tK%2FWmgiysM7TgT%2BhIwG6wzQrYmkC4h
35.190.80.1
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/4lv48/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/normal/auto/
104.18.95.41
https://sitespecfics.net/goodlawyer/img/3.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/stellar.js
172.67.145.77
https://sitespecfics.net/goodlawyer/images/p3.jpg
172.67.145.77
https://w3layouts.com/
unknown
https://sitespecfics.net/goodlawyer/images/f1.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/font-awesome/css/font-awesome.min.css
172.67.145.77
https://sitespecfics.net/goodlawyer/js/classie.js
172.67.145.77
https://sitespecfics.net/goodlawyer/color/default.css
172.67.145.77
http://bootstraptaste.com
unknown
https://sitespecfics.net/goodlawyer/js/jquery.easing.min.js
172.67.145.77
https://sitespecfics.net/public/assets/images/auth/bkTlwuDJCVcWnhs.png
172.67.145.77
https://sitespecfics.net/goodlawyer/js/nivo-lightbox.min.js
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.min.js
172.67.145.77
https://sitespecfics.net/goodlawyer/js/bootstrap.min.js
172.67.145.77
https://sitespecfics.net/goodlawyer/images/p1.jpg
172.67.145.77
https://sitespecfics.net/cdn-cgi/challenge-platform/h/g/jsd/r/8cc5d26fd9466a5f
172.67.145.77
https://sitespecfics.net/goodlawyer/css/style2.css
172.67.145.77
https://sitespecfics.net/goodlawyer/js/move-top.js
172.67.145.77
https://sitespecfics.net/goodlawyer/img/works/8.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/css/nivo-lightbox-theme/default/default.css
172.67.145.77
https://sitespecfics.net/goodlawyer/img/1.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/owl.carousel.min.js
172.67.145.77
https://sitespecfics.net/goodlawyer/images/f3.jpg
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.flexslider-min.js
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.cslider.js
172.67.145.77
https://sitespecfics.net/goodlawyer/css/style.css
172.67.145.77
https://sitespecfics.net/goodlawyer/js/jquery.mmenu.js
172.67.145.77
https://sitespecfics.net/goodlawyer/img/works/1.jpg
172.67.145.77
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
a.nel.cloudflare.com
35.190.80.1
code.jquery.com
151.101.2.137
sitespecfics.net
172.67.145.77
challenges.cloudflare.com
104.18.95.41
www.google.com
142.250.186.164

IPs

IP
Domain
Country
Malicious
104.18.95.41
challenges.cloudflare.com
United States
151.101.2.137
code.jquery.com
United States
192.168.2.10
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.186.164
www.google.com
United States
151.101.66.137
unknown
United States
172.67.145.77
sitespecfics.net
United States
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==?__cf_chl_tk=kzaak0pUaPMAo9PoYNMhO39tPnRhJ2FModzsiIpeWzo-1727883917-0.0.1.1-5438
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==#contact
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==#contact
https://sitespecfics.net/goodlawyer/ZWFybC5tYXJ0aW5Ac3RlcHRvZS1qb2huc29uLmNvbQ==#service