IOC Report
http://metaextn.gitbook.io/us/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 102
JSON data
downloaded
Chrome Cache Entry: 103
JSON data
dropped
Chrome Cache Entry: 104
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 105
JSON data
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (8396)
downloaded
Chrome Cache Entry: 107
Web Open Font Format (Version 2), TrueType, length 48556, version 1.0
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (65472)
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (3907)
dropped
Chrome Cache Entry: 110
ASCII text, with very long lines (28198)
downloaded
Chrome Cache Entry: 111
Unicode text, UTF-8 text, with very long lines (29907)
dropped
Chrome Cache Entry: 112
JSON data
downloaded
Chrome Cache Entry: 113
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 114
ASCII text, with very long lines (14941)
downloaded
Chrome Cache Entry: 115
ASCII text, with very long lines (3596)
dropped
Chrome Cache Entry: 116
ASCII text, with very long lines (63937)
dropped
Chrome Cache Entry: 117
ASCII text, with very long lines (311)
downloaded
Chrome Cache Entry: 118
JSON data
downloaded
Chrome Cache Entry: 119
Unicode text, UTF-8 text, with very long lines (28477)
downloaded
Chrome Cache Entry: 120
JSON data
downloaded
Chrome Cache Entry: 121
JSON data
dropped
Chrome Cache Entry: 122
JSON data
dropped
Chrome Cache Entry: 123
JSON data
downloaded
Chrome Cache Entry: 124
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 125
JSON data
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 127
Unicode text, UTF-8 text, with very long lines (59073)
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (8827)
dropped
Chrome Cache Entry: 129
JSON data
dropped
Chrome Cache Entry: 130
ASCII text, with very long lines (12105)
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (40811)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (40811)
dropped
Chrome Cache Entry: 133
JSON data
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (34267)
dropped
Chrome Cache Entry: 135
JSON data
dropped
Chrome Cache Entry: 136
JSON data
downloaded
Chrome Cache Entry: 137
JSON data
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (6926)
dropped
Chrome Cache Entry: 139
JSON data
dropped
Chrome Cache Entry: 140
JSON data
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (6247)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (6247)
downloaded
Chrome Cache Entry: 143
JSON data
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (18153)
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (25336)
dropped
Chrome Cache Entry: 146
Unicode text, UTF-8 text, with very long lines (59073)
downloaded
Chrome Cache Entry: 147
JSON data
dropped
Chrome Cache Entry: 148
ASCII text, with very long lines (11638)
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (34267)
downloaded
Chrome Cache Entry: 150
JSON data
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (63937)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (1146)
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (11638)
dropped
Chrome Cache Entry: 154
JSON data
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (3907)
downloaded
Chrome Cache Entry: 156
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 157
ASCII text
downloaded
Chrome Cache Entry: 158
JSON data
downloaded
Chrome Cache Entry: 159
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 160
JSON data
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (56462)
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (3596)
downloaded
Chrome Cache Entry: 164
JSON data
dropped
Chrome Cache Entry: 165
ASCII text, with very long lines (14941)
dropped
Chrome Cache Entry: 166
ASCII text
downloaded
Chrome Cache Entry: 167
JSON data
downloaded
Chrome Cache Entry: 168
ASCII text
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (6926)
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (18153)
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (1146)
downloaded
Chrome Cache Entry: 172
Unicode text, UTF-8 text, with very long lines (28477)
dropped
Chrome Cache Entry: 173
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 174
JSON data
dropped
Chrome Cache Entry: 175
ASCII text, with very long lines (3227)
downloaded
Chrome Cache Entry: 176
JSON data
dropped
Chrome Cache Entry: 177
ASCII text, with very long lines (12105)
downloaded
Chrome Cache Entry: 178
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 179
HTML document, Unicode text, UTF-8 text, with very long lines (30065)
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (25336)
downloaded
Chrome Cache Entry: 181
JSON data
downloaded
Chrome Cache Entry: 182
Unicode text, UTF-8 text, with very long lines (29907)
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (60328)
downloaded
Chrome Cache Entry: 184
JSON data
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (8827)
downloaded
Chrome Cache Entry: 186
JSON data
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (56462)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (28774)
downloaded
There are 78 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2584 --field-trial-handle=2212,i,18144309429322111329,1805828728470401882,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://metaextn.gitbook.io/us/"

URLs

Name
IP
Malicious
http://metaextn.gitbook.io/us/
malicious
https://tailwindcss.com
unknown
https://metaextn.gitbook.io/_next/static/css/bf7df5d7c6de54ec.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/css/026444ec630b65a2.css
104.18.40.47
https://app.gitbook.com/__session?proposed=621bdff0-594f-4c94-b5c1-829c0bc12195R
172.64.146.167
https://metaextn.gitbook.io/us#id-4.-transaction-fees
https://metaextn.gitbook.io/_next/static/chunks/webpack-ed8f5a60dc0318fb.js
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/8731-301749ee030e10bf.js
104.18.40.47
https://metaextn.gitbook.io/us/
104.18.40.47
https://metaextn.gitbook.io/us#id-2.-security-concerns
https://app.gitbook.com/__session?proposed=547a9c69-9834-4c66-8950-6b1844ac2252R
172.64.146.167
https://metaextn.gitbook.io/us#disadvantages-of-metamask
https://metaextn.gitbook.io/_next/static/css/e11f1c6a6568d9ab.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/2632-58a8169263096f76.js
104.18.40.47
https://metaextn.gitbook.io/_next/static/media/a34f9d1faa5f3315-s.woff2
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/app/(space)/layout-7ef296a0cca4ea87.js
104.18.40.47
https://metaextn.gitbook.io/_next/static/css/ebf7d0073b0092ea.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/css/c311d6484335995a.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/app/global-error-ae0a7781226b5f7c.js
104.18.40.47
https://metaextn.gitbook.io/us#metamask-extension-bridging-the-gap-to-blockchain
https://metaextn.gitbook.io/_next/static/css/19ad1175bf75e201.css
104.18.40.47
https://app.gitbook.com/__session?proposed=16d4f936-b1e8-4aba-a03e-56e8a395031cR
172.64.146.167
https://metaextn.gitbook.io/us#id-2.-secure-wallet-management
https://metaextn.gitbook.io/us
https://app.gitbook.com/__session?proposed=cbb16d32-04ca-48f1-9587-565a948f20e1R
172.64.146.167
https://metaextn.gitbook.io/_next/static/css/55c273d39abae12a.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/4037-4d151b686812ceb4.js
104.18.40.47
https://app.gitbook.com/__session?proposed=343c7c0c-7267-491b-9f1e-6e13d9548e5bR
172.64.146.167
https://unpkg.com/
unknown
https://metaextn.gitbook.io/_next/static/chunks/app/(space)/error-e13e0b765fd3fff7.js
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/3546-983d8e659994cb93.js
104.18.40.47
http://jedwatson.github.io/classnames
unknown
https://metaextn.gitbook.io/us#id-1.-dependency-on-browser
https://metaextn.gitbook.io/us#id-5.-interoperability
https://metaextn.gitbook.io/_next/static/css/594af977d5a2878d.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/css/829150f9e3c1e921.css
104.18.40.47
https://metaextn.gitbook.io/us#id-3.-diverse-dapp-ecosystem
https://3347957231-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fxf1VmUta2ggCeLV2Z1Dw%2Ficon%2Fothp9F96GAv1qklvr9W0%2FMetaMask_%20fabb%20(1).png?alt=media&token=7d63203c-379f-4b0b-9230-ff49382cdadc
104.18.40.47
https://metaextn.gitbook.io/us#id-4.-customization-and-integration
https://app.gitbook.com/__session?proposed=5fab2876-c3f8-48e1-8cd2-3a3d2aaa599fR
172.64.146.167
https://metaextn.gitbook.io/_next/static/chunks/app/(space)/(content)/layout-e6c9e9cb143d3791.js
104.18.40.47
https://app.gitbook.com/__session?proposed=01f8fed2-613f-4246-b50d-033231ddf0b1R
172.64.146.167
https://metaextn.gitbook.io/us#advantages-of-metamask
https://docs.gitbook.com/published-documentation/custom-domain/configure-dns#are-you-using-cloudflar
unknown
https://metaextn.gitbook.io/us#overview-of-metamask
https://metaextn.gitbook.io/_next/static/chunks/4377-f33ce08f4cf11496.js
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/app/(space)/(content)/%5B%5B...pathname%5D%5D/page-80dffb20e3f68740.js
104.18.40.47
https://metaextn.gitbook.io/us#id-3.-learning-curve-for-beginners
https://metaextn.gitbook.io/_next/static/chunks/6985-24d17eba2c4006cb.js
104.18.40.47
https://metaextn.gitbook.io/us#id-1.-user-friendly-interface
https://metaextn.gitbook.io/~gitbook/image?url=https%3A%2F%2F3347957231-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252Fxf1VmUta2ggCeLV2Z1Dw%252Ficon%252Fothp9F96GAv1qklvr9W0%252FMetaMask_%2520fabb%2520%281%29.png%3Falt%3Dmedia%26token%3D7d63203c-379f-4b0b-9230-ff49382cdadc&width=32&dpr=1&quality=100&sign=a604c4d1&sv=1
104.18.40.47
https://app.gitbook.com/__session?proposed=f560ea32-4038-4b1e-8e8f-9c4bb2733c0bR
172.64.146.167
https://app.gitbook.com/__session?proposed=99426138-3b4e-47e3-bc29-ce5573cdb35fR
172.64.146.167
https://app.gitbook.com/__session?proposed=61def9e4-ea87-4f48-bc68-c3032c37febcR
172.64.146.167
https://feross.org
unknown
https://metaextn.gitbook.io/_next/static/css/84671c0b86c5eace.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/8381-2f754da8e779eeab.js
104.18.40.47
https://3347957231-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fxf1VmUta2ggCeLV2Z1Dw%2Fuploads%2FzAVoWPBg9iXMa9D5Ckyv%2Ffile.excalidraw.svg?alt=media&token=9e5526e4-019f-4d6b-982a-90e812a11444
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/1698-e89c19bbf0c8e05d.js
104.18.40.47
https://api.gitbook.com/v1/orgs/aRuvaNy7EOQQ9X7Nrhcn/sites/site_w0BEB/insights/track_view
104.18.41.89
https://metaextn.gitbook.io/_next/static/chunks/b5d5b83b-79880c6c180a831f.js
104.18.40.47
https://app.gitbook.com/__session?proposed=95ddf36b-f421-4636-af97-6896c015a4f4R
172.64.146.167
https://metaextn.gitbook.io/_next/static/chunks/6445-f44ccdfb3d68c36a.js
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/main-app-edf9fc05fff9a094.js
104.18.40.47
https://app.gitbook.com/__session?proposed=46e7c377-2cb6-4baf-b007-5916293fdeaaR
172.64.146.167
https://metaextn.gitbook.io/_next/static/css/0f891de5863d7182.css
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/1dd3208c-65f236513d05994f.js
104.18.40.47
https://metaextn.gitbook.io/_next/static/chunks/6718-c9b90b1ba43809dd.js
104.18.40.47
https://app.gitbook.com/__session?proposed=1ca90bb5-d526-414e-b660-2dc7187c3d9eR
172.64.146.167
https://app.gitbook.com/__session?proposed=0a65abde-339b-4220-aace-f8595584977bR
172.64.146.167
https://app.gitbook.com/__session?proposed=c6f1d058-33c3-4f70-af35-eb3c7e7b9e97R
172.64.146.167
There are 60 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
a.nel.cloudflare.com
35.190.80.1
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.185.196
app.gitbook.com
172.64.146.167
3347957231-files.gitbook.io
104.18.40.47
metaextn.gitbook.io
104.18.40.47
fp2e7a.wpc.phicdn.net
192.229.221.95
api.gitbook.com
104.18.41.89

IPs

IP
Domain
Country
Malicious
104.18.40.47
3347957231-files.gitbook.io
United States
104.18.41.89
api.gitbook.com
United States
192.168.2.4
unknown
unknown
172.64.146.167
app.gitbook.com
United States
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
172.64.147.209
unknown
United States

DOM / HTML

URL
Malicious
https://metaextn.gitbook.io/us
malicious
https://metaextn.gitbook.io/us#metamask-extension-bridging-the-gap-to-blockchain
malicious
https://metaextn.gitbook.io/us#overview-of-metamask
malicious
https://metaextn.gitbook.io/us#advantages-of-metamask
malicious
https://metaextn.gitbook.io/us#id-1.-user-friendly-interface
malicious
https://metaextn.gitbook.io/us#id-2.-secure-wallet-management
malicious
https://metaextn.gitbook.io/us#id-3.-diverse-dapp-ecosystem
malicious
https://metaextn.gitbook.io/us#id-4.-customization-and-integration
malicious
https://metaextn.gitbook.io/us#id-5.-interoperability
malicious
https://metaextn.gitbook.io/us#disadvantages-of-metamask
malicious
https://metaextn.gitbook.io/us#id-1.-dependency-on-browser
malicious
https://metaextn.gitbook.io/us#id-2.-security-concerns
malicious
https://metaextn.gitbook.io/us#id-3.-learning-curve-for-beginners
malicious
https://metaextn.gitbook.io/us#id-4.-transaction-fees
malicious
https://metaextn.gitbook.io/us#id-5.-limited-mobile-experience
malicious
There are 5 hidden doms, click here to show them.