IOC Report
https://admin.hotcoinbase.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 42
gzip compressed data, from Unix, original size modulo 2^32 1618
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2524 --field-trial-handle=2420,i,322086348749757300,7989299051341829707,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://admin.hotcoinbase.com/"
malicious

URLs

Name
IP
Malicious
https://admin.hotcoinbase.com/
malicious
https://admin.hotcoinbase.com/
107.148.71.103
malicious
https://admin.hotcoinbase.com/h5
107.148.71.103
malicious
https://z15sbq.xyz/

Domains

Name
IP
Malicious
z15sbq.xyz
154.215.233.195
malicious
bg.microsoft.map.fastly.net
199.232.210.172
admin.hotcoinbase.com
107.148.71.103
www.google.com
142.250.185.132
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
154.215.233.195
z15sbq.xyz
Seychelles
malicious
107.148.71.103
admin.hotcoinbase.com
United States
239.255.255.250
unknown
Reserved
142.250.185.132
www.google.com
United States
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown

DOM / HTML

URL
Malicious
https://z15sbq.xyz/