IOC Report
https://tampoesdeferrofundido.com.br/redirect.php?v=2455b0ad034ad02

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 08:22:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 08:22:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 62
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 63
PNG image data, 974 x 436, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 64
HTML document, ASCII text
downloaded
Chrome Cache Entry: 65
gzip compressed data, from Unix, original size modulo 2^32 895
downloaded
Chrome Cache Entry: 66
gzip compressed data, from Unix, original size modulo 2^32 1140
downloaded
Chrome Cache Entry: 68
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped

URLs

Name
IP
Malicious
https://tampoesdeferrofundido.com.br/redirect.php?v=2455b0ad034ad02
malicious
https://platypustours.net.au/8G56zf/
malicious

Domains

Name
IP
Malicious
platypustours.net.au
192.185.12.190
malicious
tampoesdeferrofundido.com.br
194.163.179.79
www.google.com
142.250.185.196

IPs

IP
Domain
Country
Malicious
192.185.12.190
platypustours.net.au
United States
malicious
74.125.206.84
unknown
United States
142.250.186.78
unknown
United States
1.1.1.1
unknown
Australia
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
142.250.185.195
unknown
United States
216.58.206.67
unknown
United States
192.168.2.16
unknown
unknown
194.163.179.79
tampoesdeferrofundido.com.br
Germany
142.250.185.74
unknown
United States
216.58.206.46
unknown
United States
There are 2 hidden IPs, click here to show them.