IOC Report
http://usmr.qtkymcl.xyz/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 138
ASCII text, with very long lines (2059), with no line terminators
dropped
Chrome Cache Entry: 139
Unicode text, UTF-8 (with BOM) text, with CRLF, CR, LF line terminators
downloaded
Chrome Cache Entry: 140
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 141
HTML document, ASCII text, with very long lines (5047), with CRLF line terminators
dropped
Chrome Cache Entry: 142
Unicode text, UTF-8 (with BOM) text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 143
Unicode text, UTF-8 (with BOM) text, with very long lines (3569), with no line terminators
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (1686), with no line terminators
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (1805), with no line terminators
dropped
Chrome Cache Entry: 146
Unicode text, UTF-8 (with BOM) text, with very long lines (4874), with no line terminators
dropped
Chrome Cache Entry: 147
Unicode text, UTF-8 (with BOM) text, with very long lines (4307), with no line terminators
dropped
Chrome Cache Entry: 148
ASCII text
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (52420)
dropped
Chrome Cache Entry: 150
Unicode text, UTF-8 (with BOM) text, with very long lines (3878), with no line terminators
dropped
Chrome Cache Entry: 151
Unicode text, UTF-8 (with BOM) text, with very long lines (3614), with no line terminators
downloaded
Chrome Cache Entry: 152
Unicode text, UTF-8 (with BOM) text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (2053), with no line terminators
dropped
Chrome Cache Entry: 154
ASCII text, with very long lines (2049), with no line terminators
downloaded
Chrome Cache Entry: 155
Web Open Font Format (Version 2), TrueType, length 78196, version 331.-31261
downloaded
Chrome Cache Entry: 156
Unicode text, UTF-8 (with BOM) text, with very long lines (3509), with no line terminators
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (2160), with no line terminators
dropped
Chrome Cache Entry: 158
PNG image data, 221 x 27, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (2131), with no line terminators
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (52420)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (1682), with no line terminators
downloaded
Chrome Cache Entry: 162
Unicode text, UTF-8 (with BOM) text, with no line terminators
dropped
Chrome Cache Entry: 163
Web Open Font Format (Version 2), TrueType, length 14824, version 1.0
downloaded
Chrome Cache Entry: 164
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 165
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 166
Web Open Font Format (Version 2), TrueType, length 18596, version 1.0
downloaded
Chrome Cache Entry: 167
Unicode text, UTF-8 (with BOM) text, with very long lines (4278), with no line terminators
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (2700), with no line terminators
downloaded
Chrome Cache Entry: 169
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (32034)
downloaded
Chrome Cache Entry: 171
PNG image data, 221 x 27, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 172
Unicode text, UTF-8 (with BOM) text, with very long lines (3737), with no line terminators
dropped
Chrome Cache Entry: 173
Unicode text, UTF-8 (with BOM) text, with very long lines (4917), with no line terminators
downloaded
Chrome Cache Entry: 174
Unicode text, UTF-8 (with BOM) text, with very long lines (3741), with no line terminators
downloaded
Chrome Cache Entry: 175
Unicode text, UTF-8 (with BOM) text, with very long lines (3359), with no line terminators
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (2012), with no line terminators
downloaded
Chrome Cache Entry: 177
Web Open Font Format (Version 2), TrueType, length 14892, version 1.0
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (2119), with no line terminators
downloaded
Chrome Cache Entry: 179
Unicode text, UTF-8 (with BOM) text, with very long lines (3611), with no line terminators
dropped
Chrome Cache Entry: 180
Unicode text, UTF-8 (with BOM) text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 181
Unicode text, UTF-8 (with BOM) text, with very long lines (3340), with no line terminators
dropped
Chrome Cache Entry: 182
Unicode text, UTF-8 (with BOM) text, with very long lines (3637), with no line terminators
downloaded
Chrome Cache Entry: 183
HTML document, ASCII text, with very long lines (5027), with CRLF line terminators
downloaded
Chrome Cache Entry: 184
Unicode text, UTF-8 (with BOM) text, with very long lines (2985), with no line terminators
downloaded
Chrome Cache Entry: 185
Unicode text, UTF-8 (with BOM) text, with very long lines (3168), with no line terminators
dropped
Chrome Cache Entry: 186
ASCII text, with very long lines (59158)
downloaded
Chrome Cache Entry: 187
Unicode text, UTF-8 (with BOM) text, with very long lines (3753), with no line terminators
downloaded
Chrome Cache Entry: 188
HTML document, ASCII text, with very long lines (682), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (1705), with no line terminators
dropped
Chrome Cache Entry: 190
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (2476), with no line terminators
dropped
Chrome Cache Entry: 192
ASCII text, with very long lines (2248), with no line terminators
downloaded
Chrome Cache Entry: 193
ASCII text
downloaded
Chrome Cache Entry: 194
Unicode text, UTF-8 (with BOM) text, with very long lines (3870), with no line terminators
downloaded
Chrome Cache Entry: 195
Unicode text, UTF-8 (with BOM) text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (32034)
dropped
There are 50 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2072 --field-trial-handle=2004,i,4011478996165279498,14020656425036628087,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://usmr.qtkymcl.xyz/"
malicious

URLs

Name
IP
Malicious
http://usmr.qtkymcl.xyz/
https://usmr.qtkymcl.xyz/c5214/bAp1LAAIEADy/suAJ??AJAD4AQxwHoYaAAH9HAAn6A/9EANjkgf6r2
188.114.96.3
https://cdn.tailwindcss.com
unknown
https://usmr.qtkymcl.xyz/c5214/z4Cu-8ZBmAAbA_AAIAR?T/qEAKhAVTIAXjN1pzm-EAsv1AINW-kA-UAxfAHSA5_U/f2siOtAmA.js
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/z4SC-HZcm8A7AFAAIAR?T/qEAo9Ai2IA1jJYptm-MAxv1AIa88aAixABfAHQA5h/Wf2siGtAmA.js
188.114.96.3
https://usmr.qtkymcl.xyz/StaticHtml/Error404Html/index.html?aspxerrorpath=/BeforeGetHtml
188.114.96.3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/webfonts/fa-solid-900.woff2
104.17.24.14
https://usmr.qtkymcl.xyz/c5214/x4Sc--ZkmwAAAPAAIAR?r/qEAfCAf3IAijILpXm-vA0v1AIzuwbAD3AAfAHUA51/9f2siEtAmA.css
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/6psMVFHGsAuzt8A7A7EOLSPU/BOwnm3pum70AjE5A2AEAXsA5qNEsT_4II_b8ECA3QhzA5EWRqLS84AvwwUM/AAj7AIQGZA?A_.png
188.114.96.3
https://github.com/postcss/autoprefixer#readme
unknown
https://usmr.qtkymcl.xyz/c5214/FrQg6EAdFLgARFtOgMEkVY0w_DYAySdA/AUjHA/ggTnBAt3Jy4JBres_BAETD84ACIelVG4ubSsPKxAGAbAuGYG2fjVgxGQEV_TnXvGG6ABAAq/jAhA4Awv
188.114.96.3
https://evilmartians.com/chronicles/postcss-8-plugin-migration
unknown
http://usmr.qtkymcl.xyz/
188.114.96.3
https://usmr.qtkymcl.xyz/
188.114.96.3
https://github.com/browserslist/browserslist#readme
unknown
https://usmr.qtkymcl.xyz/c5214/MXsMVFHCqAuztpAMAv-OLmCUBg/wGm3gb9LZAjE5AdA5ASSAL1rKIT_4DIL3qEvA6OrjA-ElRVKqZ4AvwrUNApv/oAIQGlA?A_.js
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/FhQg6Ef2RLgAlFgOF6EkVYcw_ncAySdA/AUYHA/uQTn9At3Jy4ZxGGs_FAEZgd4AHIBlcGDubJsPKaAaATApGYU2FmVj-GB4VQTnpXGG6AWAAp/qA6AXCwv
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/QksMYnHbpAGuGMAXALoEwTtg/nVli66G_JVbAGEYANAEA00A4ysSF2_yjglPOEQARTGzAE3MwN3tq4ASwd4UAn/EHAIVvRA?A_
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/94CsX_fyggrlAJAAIAm?y/wEACfA0ESAjqIzPRdbcAZNEA-2F7nP13AytAH6A/_phV7sdV3ApA
188.114.96.3
https://fontawesome.com/license/free
unknown
https://usmr.qtkymcl.xyz/c5214/z4Cf-HZMmMAnAkAAIAR?6/qEAqPAbmIA9j1upfm-3A_v1AINM61A24AQfAHW/A5Npf2siBtAmA.js
188.114.96.3
https://fontawesome.com
unknown
https://usmr.qtkymcl.xyz/c5214/FZQg6ErbRLgA9F1OKFEkVYUw_A2AySdA/AUeHA/UDTnKAt3Jy4QxfRs_RAEFLx4AzIIlIGxubosPGoAsACAaGYC2h5VsmGODVXTnlmGG6A1AAo/8ApAKTwv
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/FiQg6EZmfLgA9FuOHKEkVYuw_KfAySdA/AUvHALvTnIAt3Jy4Ox9Ts_hAEAyk4ADI8l7G-ubmsPjAAvAxA_GYk2Q4Vb6G-0VETnQUGG6AI/AArlAgAFNwv
188.114.96.3
https://tailwindcss.com/docs/installation
unknown
https://cdn.tailwindcss.com/
104.22.21.144
https://usmr.qtkymcl.xyz/c5214/x4y1-uZnmsAgAnAAIAR?i/qEAYTAFLIA2jpCpYm-cAev1AILOfyA69AQfAHXA52/Tf2sijtAmA.js
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/z4i3-pZjmYAGA1AAIAR?a/qEAV7A1oIA0j5lpVm-0Axv1AI-bfbAY2AAfAH3A5T-f/2siVtAmA.js
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/z4St-iZ_moAeA0AAIAR?c/qEAdYAa-IARj5Cplm-YAav1AISG-_AitAgfAHXA5/v3f2si8tAmA.css
188.114.96.3
https://cdn.tailwindcss.com/3.4.5
104.22.21.144
https://usmr.qtkymcl.xyz/c5214/BFsMVFH97AuztaAVAiLOLG5U/BfwkmmiUmxWAxE5AxAqA31APQ13CT_4DI78nE0A1AgzANEeRPffq4AvwGUs/Aq0CAIQGEA?A_.svg
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/qAGbA2ARHAA4/PG-V7tfEuQAAu-AFsAsw-A-I6CA4/AaGsAsut.ico
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/24SjEvSqgIW4AEAAIAJ?M/5EAhfAMuzAr5KDhGozzA3s6Atsms7LeEAylAHnAu/G7fpsnqtAmA
https://usmr.qtkymcl.xyz/c5214/jksMYnHbJAGuGeACAGoEwTHg/nVlo66GuJVBAGEYANAEAIoAQysNF2_yUgRPOEQAzTGDAE3rw4wto4ASwd4U/A0FzAIVvtA?A_
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/1AEEA2AyHAA4/MqTZyA-E-QAAfXALcAsQBACIZO/AcAvXBAsMt
188.114.96.3
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.css
104.17.24.14
https://usmr.qtkymcl.xyz/c5214/z4yO-cZmm8AhAYAAIAR?J/qEAvYAD3IAqjB_pzm-rAyv1AI31o_AS3AQfAHIA5/Yhf2si1tAmA.css
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/BksMYnHbSAGuGWA7AqxEwTFg/nVlI66GoJVQAGEYAfAcA59AYysYF2_yYgoPOEQAqTGDAE36wRUtr4ASwd4U/AQwCAIVvtA?A_
188.114.96.3
https://mths.be/cssesc
unknown
https://usmr.qtkymcl.xyz/c5214/x4y7-EZumkAcAFAAIAR?_q/EAiDAV5IACjkqpzm-tA5v1AIk_WNAVsAwfAHG/A5pZf2siHtAmA.css
188.114.96.3
https://code.jquery.com/jquery-3.0.0.min.js
151.101.130.137
https://usmr.qtkymcl.xyz/c5214/z4i--8ZJm0AEAcAAIAR?y/qEA5XAZdIA7jDbpIm-vAmv1AIOVJdAzwAgfAH8A5u/7f2sistAmA.js
188.114.96.3
https://usmr.qtkymcl.xyz/c5214/x4iW-nZbmYAUAJAAIAR?5/qEAHVA7FIAuj-vpRm-fALv1AIyttnAdvAQfAHWA5Cs/f2siMtAmA.js
188.114.96.3
https://twitter.com/browserslist
unknown
https://usmr.qtkymcl.xyz/c5214/x4Cz-bZgmQAzANAAIAR?A/qEA5zAxeIAfjytptm-aAHv1AIdtxbAsdAWfAH5A51/Kf2siCtAmA.js
188.114.96.3
There are 34 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
usmr.qtkymcl.xyz
188.114.96.3
malicious
code.jquery.com
151.101.130.137
cdnjs.cloudflare.com
104.17.24.14
cdn.tailwindcss.com
104.22.21.144
s-part-0017.t-0009.t-msedge.net
13.107.246.45
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
www.google.com
142.250.186.164
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
188.114.96.3
usmr.qtkymcl.xyz
European Union
malicious
104.17.24.14
cdnjs.cloudflare.com
United States
192.168.2.4
unknown
unknown
104.22.21.144
cdn.tailwindcss.com
United States
151.101.130.137
code.jquery.com
United States
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.186.164
www.google.com
United States
151.101.194.137
unknown
United States
142.250.74.196
unknown
United States

DOM / HTML

URL
Malicious
https://usmr.qtkymcl.xyz/c5214/24SjEvSqgIW4AEAAIAJ?M/5EAhfAMuzAr5KDhGozzA3s6Atsms7LeEAylAHnAu/G7fpsnqtAmA
https://usmr.qtkymcl.xyz/c5214/24SjEvSqgIW4AEAAIAJ?M/5EAhfAMuzAr5KDhGozzA3s6Atsms7LeEAylAHnAu/G7fpsnqtAmA
https://usmr.qtkymcl.xyz/c5214/24SjEvSqgIW4AEAAIAJ?M/5EAhfAMuzAr5KDhGozzA3s6Atsms7LeEAylAHnAu/G7fpsnqtAmA