IOC Report
https://go.fhmchc.org/e/1082453/2024-10-02/4jdfj1/2749392279/h/yT2pQ8kLopdjnY-DRaZwaJddOAgNE7yFzWjyxxKOC_E

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 3 12:07:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 3 12:07:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 3 12:07:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 3 12:07:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 3 12:07:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://go.fhmchc.org/e/1082453/2024-10-02/4jdfj1/2749392279/h/yT2pQ8kLopdjnY-DRaZwaJddOAgNE7yFzWjyxxKOC_E
https://mycw132.ecwcloud.com/portal18441/jsp/100mp/login_otp.jsp
https://www.fhm-chc.org/

Domains

Name
IP
Malicious
performance.squarespace.com
35.186.236.0
assets.codepen.io
104.18.111.164
nocrhf.org
104.21.69.4
fhm-chc.org
198.49.23.145
brightwaterbaywichita.com
198.71.60.173
static.squarespace.map.fastly.net
151.101.0.237
squarespace.map.fastly.net
151.101.0.238
mycw132.ecwcloud.com
20.84.201.93
code.jquery.com
151.101.194.137
www.google.com
216.58.206.36
fd.fhmchc.com
46.166.184.119
ext-cust.squarespace.com
198.185.159.144
prod.squarespace.map.fastly.net
151.101.0.238
pi-ue1-public-lb-f0209c6950285322.elb.us-east-1.amazonaws.com
18.208.125.13
images.squarespace-cdn.com
unknown
assets.squarespace.com
unknown
static1.squarespace.com
unknown
cdn.weglot.com
unknown
www.fhm-chc.org
unknown
go.fhmchc.org
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.69.4
nocrhf.org
United States
142.250.185.206
unknown
United States
104.18.111.164
assets.codepen.io
United States
151.101.64.237
unknown
United States
104.16.32.228
unknown
United States
192.168.2.17
unknown
unknown
192.168.2.16
unknown
unknown
198.49.23.145
fhm-chc.org
United States
151.101.0.237
static.squarespace.map.fastly.net
United States
172.64.149.114
unknown
United States
151.101.0.238
squarespace.map.fastly.net
United States
216.58.206.36
www.google.com
United States
20.84.201.93
mycw132.ecwcloud.com
United States
198.185.159.144
ext-cust.squarespace.com
United States
142.250.185.163
unknown
United States
142.250.186.110
unknown
United States
151.101.194.137
code.jquery.com
United States
142.250.186.74
unknown
United States
142.250.186.138
unknown
United States
142.250.184.195
unknown
United States
142.250.186.35
unknown
United States
142.250.110.84
unknown
United States
104.18.38.142
unknown
United States
1.1.1.1
unknown
Australia
151.101.192.238
unknown
United States
198.71.60.173
brightwaterbaywichita.com
United States
239.255.255.250
unknown
Reserved
46.166.184.119
fd.fhmchc.com
Netherlands
18.208.125.13
pi-ue1-public-lb-f0209c6950285322.elb.us-east-1.amazonaws.com
United States
35.186.236.0
performance.squarespace.com
United States
There are 20 hidden IPs, click here to show them.