IOC Report
http://support-wlletconect.gitbook.io/us/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 06:33:37 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 06:33:36 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:56:51 2023, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 06:33:36 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 06:33:37 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 06:33:36 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (6247)
downloaded
Chrome Cache Entry: 167
PNG image data, 32 x 32, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (18153)
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (6926)
dropped
Chrome Cache Entry: 170
ASCII text, with very long lines (40811)
downloaded
Chrome Cache Entry: 171
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (28774)
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 174
Web Open Font Format (Version 2), TrueType, length 48556, version 1.0
downloaded
Chrome Cache Entry: 175
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (11638)
dropped
Chrome Cache Entry: 177
ASCII text, with very long lines (3596)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (60328)
downloaded
Chrome Cache Entry: 179
Unicode text, UTF-8 text, with very long lines (28477)
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (6926)
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (3907)
dropped
Chrome Cache Entry: 182
ASCII text, with very long lines (311)
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (65472)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (3227)
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (1146)
dropped
Chrome Cache Entry: 186
JSON data
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (56462)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 189
ASCII text, with very long lines (25336)
dropped
Chrome Cache Entry: 190
ASCII text, with very long lines (8827)
downloaded
Chrome Cache Entry: 191
ASCII text
downloaded
Chrome Cache Entry: 192
ASCII text, with very long lines (3596)
dropped
Chrome Cache Entry: 193
ASCII text, with very long lines (8396)
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (25336)
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (11638)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (63937)
downloaded
Chrome Cache Entry: 198
Unicode text, UTF-8 text, with very long lines (59073)
dropped
Chrome Cache Entry: 199
JSON data
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (12105)
downloaded
Chrome Cache Entry: 201
Unicode text, UTF-8 text, with very long lines (29907)
dropped
Chrome Cache Entry: 202
Unicode text, UTF-8 text, with very long lines (59073)
downloaded
Chrome Cache Entry: 203
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 204
JSON data
dropped
Chrome Cache Entry: 205
ASCII text, with very long lines (28198)
downloaded
Chrome Cache Entry: 206
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 207
HTML document, Unicode text, UTF-8 text, with very long lines (29350)
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (40811)
dropped
Chrome Cache Entry: 209
ASCII text, with very long lines (1146)
downloaded
Chrome Cache Entry: 210
ASCII text, with very long lines (18153)
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (12105)
dropped
Chrome Cache Entry: 212
JSON data
downloaded
Chrome Cache Entry: 213
ASCII text, with very long lines (63937)
dropped
Chrome Cache Entry: 214
ASCII text, with very long lines (34267)
dropped
Chrome Cache Entry: 215
ASCII text, with very long lines (3907)
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (56462)
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (34267)
downloaded
Chrome Cache Entry: 218
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (14941)
dropped
Chrome Cache Entry: 220
Unicode text, UTF-8 text, with very long lines (28477)
dropped
Chrome Cache Entry: 221
ASCII text, with very long lines (6247)
dropped
Chrome Cache Entry: 222
ASCII text
downloaded
Chrome Cache Entry: 223
ASCII text, with very long lines (8827)
dropped
Chrome Cache Entry: 224
ASCII text
downloaded
Chrome Cache Entry: 225
Unicode text, UTF-8 text, with very long lines (29907)
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (14941)
downloaded
There are 58 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2124 --field-trial-handle=1720,i,4433582537565805331,11987204677116290734,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://support-wlletconect.gitbook.io/us/"

URLs

Name
IP
Malicious
http://support-wlletconect.gitbook.io/us/
malicious
https://support-wlletconect.gitbook.io/_next/static/css/bf7df5d7c6de54ec.css
172.64.147.209
https://app.gitbook.com/__session?proposed=9eb91f30-0397-4ab2-8fb4-49000b7c4c18R
104.18.41.89
https://support-wlletconect.gitbook.io/_next/static/chunks/webpack-ed8f5a60dc0318fb.js
172.64.147.209
https://tailwindcss.com
unknown
https://support-wlletconect.gitbook.io/_next/static/css/829150f9e3c1e921.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/main-app-edf9fc05fff9a094.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/8731-301749ee030e10bf.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/6718-c9b90b1ba43809dd.js
172.64.147.209
https://support-wlletconect.gitbook.io/us
https://support-wlletconect.gitbook.io/us#connecting-wallet
https://support-wlletconect.gitbook.io/_next/static/media/a34f9d1faa5f3315-s.woff2
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/6445-f44ccdfb3d68c36a.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/app/(space)/(content)/layout-e6c9e9cb143d3791.js
172.64.147.209
https://a.nel.cloudflare.com/report/v4?s=oCLwa04w3g2WabZglEElRq5%2FdD9P8TQrFeISUlnmM3LVFWJrm5WCtmIiB8uICtB9s44uUmlWp3Kq4NRCU7EzZtRV2K61MR8L1Z8Awmriq8cGssmZDKkj1uFGPzGvbuzk4%2BDZAVWajFN%2F5GDt4erP
35.190.80.1
https://docs.gitbook.com/published-documentation/custom-domain/configure-dns#are-you-using-cloudflar
unknown
https://298150198-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8r253d1ccKf1VxYcKEDA%2Fuploads%2FhujvWvsjfTBRp0BL1yhH%2Ffile.excalidraw.svg?alt=media&token=293ea0e6-249c-4189-aec4-c9e5168f9c1e
104.18.40.47
https://support-wlletconect.gitbook.io/_next/static/css/c311d6484335995a.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/css/0f891de5863d7182.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/app/(space)/(content)/%5B%5B...pathname%5D%5D/page-80dffb20e3f68740.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/b5d5b83b-79880c6c180a831f.js
172.64.147.209
https://298150198-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8r253d1ccKf1VxYcKEDA%2Ficon%2FmhCLcEaoGFG4YNaD39pq%2Fwalletconect%2032.png?alt=media&token=21a1e110-9a1c-4980-a663-930ab524719a
104.18.40.47
https://support-wlletconect.gitbook.io/_next/static/chunks/3546-983d8e659994cb93.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/4037-4d151b686812ceb4.js
172.64.147.209
https://support-wlletconect.gitbook.io/us/
172.64.147.209
https://feross.org
unknown
https://support-wlletconect.gitbook.io/_next/static/chunks/app/(space)/layout-7ef296a0cca4ea87.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/app/global-error-ae0a7781226b5f7c.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/8381-2f754da8e779eeab.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/1698-e89c19bbf0c8e05d.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/css/19ad1175bf75e201.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/app/(space)/error-e13e0b765fd3fff7.js
172.64.147.209
https://api.gitbook.com/v1/orgs/b4THWM8Nse3PUAQ1Y8vO/sites/site_xUCpG/insights/track_view
172.64.146.167
https://support-wlletconect.gitbook.io/_next/static/css/55c273d39abae12a.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/css/84671c0b86c5eace.css
172.64.147.209
https://app.gitbook.com/__session?proposed=46a84666-1ee8-42fd-b61e-9666ab596e6fR
104.18.41.89
https://support-wlletconect.gitbook.io/_next/static/css/026444ec630b65a2.css
172.64.147.209
https://support-wlletconect.gitbook.io/~gitbook/image?url=https%3A%2F%2F298150198-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252F8r253d1ccKf1VxYcKEDA%252Ficon%252FmhCLcEaoGFG4YNaD39pq%252Fwalletconect%252032.png%3Falt%3Dmedia%26token%3D21a1e110-9a1c-4980-a663-930ab524719a&width=32&dpr=1&quality=100&sign=9d8088f2&sv=1
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/css/594af977d5a2878d.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/2632-58a8169263096f76.js
172.64.147.209
https://unpkg.com/
unknown
https://support-wlletconect.gitbook.io/_next/static/chunks/4377-f33ce08f4cf11496.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/css/ebf7d0073b0092ea.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/6985-24d17eba2c4006cb.js
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/css/e11f1c6a6568d9ab.css
172.64.147.209
https://support-wlletconect.gitbook.io/_next/static/chunks/1dd3208c-65f236513d05994f.js
172.64.147.209
http://jedwatson.github.io/classnames
unknown
There are 36 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
google.com
142.250.185.78
298150198-files.gitbook.io
104.18.40.47
support-wlletconect.gitbook.io
104.18.40.47
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
216.58.206.68
app.gitbook.com
104.18.41.89
fp2e7a.wpc.phicdn.net
192.229.221.95
api.gitbook.com
172.64.146.167
antressmirestos.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.184.196
unknown
United States
104.18.40.47
298150198-files.gitbook.io
United States
104.18.41.89
app.gitbook.com
United States
192.168.2.9
unknown
unknown
216.58.206.68
www.google.com
United States
172.64.146.167
api.gitbook.com
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States
172.64.147.209
unknown
United States

DOM / HTML

URL
Malicious
https://support-wlletconect.gitbook.io/us
https://support-wlletconect.gitbook.io/us
https://support-wlletconect.gitbook.io/us#connecting-wallet