IOC Report
https://octo9.com.ng/Greula/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 101
HTML document, ASCII text, with very long lines (2346), with CRLF line terminators
dropped
Chrome Cache Entry: 102
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (52420)
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (2167)
dropped
Chrome Cache Entry: 105
GIF image data, version 89a, 377 x 148
downloaded
Chrome Cache Entry: 106
GIF image data, version 89a, 377 x 148
dropped
Chrome Cache Entry: 107
ASCII text, with very long lines (2167)
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (39369)
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (39369)
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (52420)
downloaded
Chrome Cache Entry: 111
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 112
ASCII text
downloaded
Chrome Cache Entry: 113
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 114
HTML document, ASCII text, with very long lines (2346), with CRLF line terminators
downloaded
Chrome Cache Entry: 115
ASCII text
dropped
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2280 --field-trial-handle=2180,i,7874427550775345759,8041642482761675959,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://octo9.com.ng/Greula/"

URLs

Name
IP
Malicious
https://octo9.com.ng/Greula/
malicious
https://octo9.com.ng/Greula/files/user.js
208.91.199.242
malicious
https://octo9.com.ng/Greula/img/hero-security.gif
208.91.199.242
malicious
https://octo9.com.ng/Greula/gate.php
208.91.199.242
malicious
https://octo9.com.ng/Greula/favicon.ico
208.91.199.242
malicious
https://octo9.com.ng/Greula/img/logo.svg
208.91.199.242
malicious
https://octo9.com.ng/Greula/
malicious
https://tailwindcss.com/docs/installation
unknown
https://cdn.tailwindcss.com/
104.22.20.144
https://unpkg.com/@alpinejs/mask@3.14.1/dist/cdn.min.js
104.17.245.203
https://tse1.mm.bing.net/th?id=OADD2.10239395019081_1G8JFT41D9TYPNUJJ&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://cdn.tailwindcss.com/3.4.5
104.22.20.144
https://github.com/postcss/autoprefixer#readme
unknown
https://evilmartians.com/chronicles/postcss-8-plugin-migration
unknown
https://tse1.mm.bing.net/th?id=OADD2.10239370639702_1LY06F7YB2ZF9D3G5&pid=21.2&c=16&roil=0&roit=0&roir=1&roib=1&w=1920&h=1080&dynsize=1&qlt=90
150.171.28.10
https://unpkg.com/@alpinejs/mask@3.x.x/dist/cdn.min.js
104.17.245.203
https://unpkg.com/alpinejs@3.14.1/dist/cdn.min.js
104.17.245.203
https://mths.be/cssesc
unknown
https://unpkg.com/alpinejs@3.x.x/dist/cdn.min.js
104.17.245.203
https://github.com/browserslist/browserslist#readme
unknown
https://tse1.mm.bing.net/th?id=OADD2.10239397078654_1S1QUNL0C84S37ODT&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
https://twitter.com/browserslist
unknown
https://tse1.mm.bing.net/th?id=OADD2.10239395019080_17DEM3LK5H7QUOJTP&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
https://tse1.mm.bing.net/th?id=OADD2.10239370639703_1XZVEAKL3PD7EZGL4&pid=21.2&c=3&w=1080&h=1920&dynsize=1&qlt=90
150.171.28.10
There are 13 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
octo9.com.ng
208.91.199.242
cdn.tailwindcss.com
104.22.20.144
www.google.com
172.217.16.196
unpkg.com
104.17.245.203
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.34
ax-0001.ax-msedge.net
150.171.28.10
fp2e7a.wpc.phicdn.net
192.229.221.95
tse1.mm.bing.net
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
104.17.245.203
unpkg.com
United States
104.22.20.144
cdn.tailwindcss.com
United States
172.217.16.196
www.google.com
United States
208.91.199.242
octo9.com.ng
United States

DOM / HTML

URL
Malicious
https://octo9.com.ng/Greula/