IOC Report
https://megafansland.com/download.php?id=R6gN0a

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (16600), with no line terminators
dropped
Chrome Cache Entry: 101
PNG image data, 160 x 160, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 102
ASCII text
downloaded
Chrome Cache Entry: 103
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 104
HTML document, ASCII text, with very long lines (345), with no line terminators
downloaded
Chrome Cache Entry: 105
gzip compressed data, original size modulo 2^32 2323
downloaded
Chrome Cache Entry: 106
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 107
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 108
ASCII text
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (16600), with no line terminators
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (12331)
dropped
Chrome Cache Entry: 111
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 112
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 113
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 114
HTML document, ASCII text
downloaded
Chrome Cache Entry: 115
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 116
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 117
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (63965), with no line terminators
dropped
Chrome Cache Entry: 119
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 120
PNG image data, 160 x 160, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 121
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 122
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 123
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 124
HTML document, ASCII text, with very long lines (574)
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (2077)
downloaded
Chrome Cache Entry: 126
JSON data
downloaded
Chrome Cache Entry: 127
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 128
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 129
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 130
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 131
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 132
ASCII text
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (595), with no line terminators
downloaded
Chrome Cache Entry: 134
HTML document, ASCII text, with very long lines (7623), with CRLF line terminators
downloaded
Chrome Cache Entry: 135
gzip compressed data, original size modulo 2^32 26516
dropped
Chrome Cache Entry: 136
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 137
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 138
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 139
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 140
gzip compressed data, original size modulo 2^32 2320
downloaded
Chrome Cache Entry: 141
gzip compressed data, original size modulo 2^32 2323
dropped
Chrome Cache Entry: 142
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 143
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 144
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 145
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 146
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 147
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 148
ASCII text, with very long lines (43601), with no line terminators
downloaded
Chrome Cache Entry: 149
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 150
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 151
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 152
HTML document, ASCII text, with very long lines (3008)
downloaded
Chrome Cache Entry: 153
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 154
ASCII text
dropped
Chrome Cache Entry: 155
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 156
ASCII text
dropped
Chrome Cache Entry: 157
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 158
HTML document, ASCII text, with very long lines (11440), with no line terminators
downloaded
Chrome Cache Entry: 159
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 160
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (43601), with no line terminators
dropped
Chrome Cache Entry: 162
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 163
JSON data
dropped
Chrome Cache Entry: 164
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 165
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 166
HTML document, Unicode text, UTF-8 text, with very long lines (32769)
dropped
Chrome Cache Entry: 167
ASCII text, with very long lines (640), with no line terminators
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (32126)
dropped
Chrome Cache Entry: 169
gzip compressed data, original size modulo 2^32 24732
downloaded
Chrome Cache Entry: 170
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 171
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 172
ASCII text, with very long lines (63965), with no line terminators
downloaded
Chrome Cache Entry: 173
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 174
HTML document, ASCII text
downloaded
Chrome Cache Entry: 175
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 176
gzip compressed data, original size modulo 2^32 26516
downloaded
Chrome Cache Entry: 177
HTML document, ASCII text, with very long lines (345), with no line terminators
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (32126)
downloaded
Chrome Cache Entry: 179
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 180
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 181
gzip compressed data, original size modulo 2^32 2097
downloaded
Chrome Cache Entry: 182
gzip compressed data, original size modulo 2^32 2320
dropped
Chrome Cache Entry: 183
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 184
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 185
gzip compressed data, original size modulo 2^32 2320
downloaded
Chrome Cache Entry: 186
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (12331)
downloaded
Chrome Cache Entry: 188
gzip compressed data, original size modulo 2^32 2097
downloaded
Chrome Cache Entry: 189
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 190
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 191
HTML document, ASCII text, with very long lines (2302), with no line terminators
downloaded
Chrome Cache Entry: 192
ASCII text
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (65371)
downloaded
Chrome Cache Entry: 194
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 195
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 196
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 197
ASCII text, with very long lines (2077)
dropped
Chrome Cache Entry: 198
ASCII text
downloaded
Chrome Cache Entry: 199
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 200
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 201
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 202
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 203
ASCII text
downloaded
Chrome Cache Entry: 82
gzip compressed data, original size modulo 2^32 24732
dropped
Chrome Cache Entry: 83
PNG image data, 1 x 1, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 84
HTML document, Unicode text, UTF-8 text, with very long lines (32769)
downloaded
Chrome Cache Entry: 85
HTML document, ASCII text, with very long lines (11440), with no line terminators
dropped
Chrome Cache Entry: 86
PNG image data, 622 x 948, 2-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 87
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 88
gzip compressed data, original size modulo 2^32 2320
dropped
Chrome Cache Entry: 89
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 90
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 91
PNG image data, 622 x 948, 2-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 92
HTML document, ASCII text, with very long lines (574)
dropped
Chrome Cache Entry: 93
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 94
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 95
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 96
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 97
ASCII text
dropped
Chrome Cache Entry: 98
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 99
PNG image data, 300 x 150, 8-bit/color RGBA, non-interlaced
downloaded
There are 113 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2092 --field-trial-handle=1836,i,17429994843348634434,15223416854209038650,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://megafansland.com/download.php?id=R6gN0a"

URLs

Name
IP
Malicious
https://megafansland.com/download.php?id=R6gN0a
https://live.rezync.com/pixel?c=bd8618c307ae9885a12561b7191e2cea&cid=5141210832561980116&referrer={encSite}&forward=https%3A%2F%2Fi.liadm.com%2Fs%2F56409%3Fbidder_id%3D200442%26bidder_uuid%3Db2d1e47d-bc18-48f1-b567-3072489c5f66%253A1728339233.2729042%26pid%3D500040%26it%3D1%26iv%3Db2d1e47d-bc18-48f1-b567-3072489c5f66%253A1728339233.2729042%26_%3D1728339233.2746704
18.66.218.84
https://pixel-sync.sitescout.com/connectors/eyeota/usersync?gdpr=0&gdpr_consent=&redir=https%3A%2F%2Fps.eyeota.net%2Fmatch%3Fbid%3Dm51mhg1%26uid%3D%7BuserId%7D
34.36.216.150
https://pixel-sync.sitescout.com/connectors/throtle/usersync?redir=https%3A%2F%2Fthrtle.com%2Fsync%3Fvxii_pid%3D5026%26vxii_pdid%3D%7BuserId%7D%26vxii_ts%3D1%26_t%3D1728339203%26_reach%3D1
34.36.216.150
https://thrtle.com/sync?vxii_pid=5026&vxii_pdid=8e9703c8-81c9-4c9c-9098-d0a09dd9a8fe-67045cfd-5553&vxii_ts=1&_t=1728339203&_reach=1
18.233.177.237
https://s.tribalfusion.com/z/i.match?p=b31&redirect=https%3A%2F%2Fthrtle.com%2Fsync%3Fvxii_pid%3D5042%26vxii_pdid%3D%24TF_USER_ID_ENC%24%26vxii_ts%3D2%26_t%3D1728339205%26_reach%3D1&u=721562d4-f092-41b4-9be2-3faaeb5f2215
172.64.150.63
https://megafansland.com/img/virus/bitdefender.png
185.66.143.46
https://pippio.com/api/sync?pid=5324&it=1&iv=8c520684282f123018400cc7e7ba73beff1334214004191bf4f485d18253df88791426b5417dce21&_=2
107.178.254.65
https://ups.analytics.yahoo.com/ups/58736/cms?partner_id=LOTME&gdpr=0
3.75.62.37
https://match.prod.bidr.io/cookie-sync/throtle?_bee_ppp=1
34.252.67.98
https://pixel.onaudience.com/?partner=137085098&mapped=104017283391850008058ADFAE0A6398
54.38.113.8
https://loadm.exelator.com/load/?p=204&g=1133&j=0
34.254.143.3
https://a.tribalfusion.com/i.match?p=b31&redirect=https%3A%2F%2Fthrtle.com%2Fsync%3Fvxii_pid%3D5042%26vxii_pdid%3D%24TF_USER_ID_ENC%24%26vxii_ts%3D2%26_t%3D1728339205%26_reach%3D1&u=721562d4-f092-41b4-9be2-3faaeb5f2215
172.64.150.63
https://megafansland.com/js/rocket-loader.min.js
185.66.143.46
https://sync.crwdcntrl.net/map/c=1389/tp=STSC/tpid=8e9703c8-81c9-4c9c-9098-d0a09dd9a8fe-67045cfd-5553/gdpr=0
54.74.215.235
https://t.dtscout.com/idg/?su=104017283391850008058ADFAE0A6398
141.101.120.11
https://sync.crwdcntrl.net/map/c=281/tp=ANXS/tpid=6513737755939604745/gdpr=0/rand=46473235
54.74.215.235
http://getbootstrap.com)
unknown
https://megafansland.com/img/virus/eset.png
185.66.143.46
https://match.adsrvr.org/track/cmf/generic?ttd_pid=lotame&ttd_tpi=1&gdpr=0
15.197.193.217
https://i.liadm.com/s/76929?bidder_id=204553&bidder_uuid=JdXVAQZHubo3YiDqSeG1j2vc&rnd=1728339240534
107.21.124.174
https://i.w55c.net/ping_match.gif?st=EYEOTA&rurl=https%3A%2F%2Fps.eyeota.net%2Fmatch%3Fbid%3D9sn4omv%26uid%3D_wfivefivec_%26newuser%3D1%26dc_rc%3D4%26dc_mr%3D5%26dc_orig%3D51mdg9u%26
3.67.209.183
https://global.ib-ibi.com/image.sbxx?go=262106&pid=420&xid=440ea49f4d537d0a764cd47bf20a1a2c
54.94.182.41
https://cm.g.doubleclick.net/pixel?google_nid=eye&google_cm&google_sc&google_hm=Mno3czdaRXBiWTZPTzlSVFpMaGFuY2pJZFpkNFZLVkFhSzlvM2piNkR6Tms&gdpr=0&gdpr_consent=&uid=1&bid=gdo9o51&newuser=1&dc_rc=1&dc_mr=5&dc_orig=51mdg9u&
172.217.23.98
https://sync.smartadserver.com/getuid?gdpr=0&url=https://bcp.crwdcntrl.net/qmap?c=16236&tp=SMAD&tpid=[sas_uid]&gdpr=0&cklb=1
89.149.193.104
https://t.dtscdn.com/widget/?d=104017283391850008058ADFAE0A6398&nid=300&p=2114454483&t=240&s=1280x1024x24&u=https%3A%2F%2Fmegafansland.com%2Fdownload.php%3Fid%3DR6gN0a&r=
104.26.13.60
https://cm.g.doubleclick.net/pixel?google_nid=lotameddp&google_hm=NDQwZWE0OWY0ZDUzN2QwYTc2NGNkNDdiZjIwYTFhMmM&gdpr=0
172.217.23.98
https://ps.eyeota.net/match?bid=51mdg9u&uid=440ea49f4d537d0a764cd47bf20a1a2c&gdpr=0
3.125.70.222
https://pd.sharethis.com/pd/dtscout
3.74.183.50
https://id5-sync.com/k/264.gif?puid=27c896d0-3d35-4d91-9d6d-d80dc54e6067&ttl=%%TTL%%
162.19.138.82
https://sync.srv.stackadapt.com/sync?nid=50&gdpr=&gdpr_consent=&gdpr_pd=&ssp=liveintent
54.157.243.69
https://sync.crwdcntrl.net/map/c=10832/tp=TRUP/tpid=74290837f250263fdcc8dd59276000ba
54.74.215.235
https://ps.eyeota.net/match?uid=ZwRdAwAHsA99mgAF&bid=0rijhbu&dc_rc=3&dc_mr=5&dc_orig=51mdg9u&&_test=ZwRdAwAHsA99mgAF
3.125.70.222
https://id5-sync.com/s/19/9.gif?puid=440ea49f4d537d0a764cd47bf20a1a2c&gdpr=0
162.19.138.82
https://thrtle.com/sync?vxii_pid=5017&vxii_pdid=1D196BD42F8D41FFCE7BD545F7120A89
18.233.177.237
https://pd.sharethis.com/pd/dtscout?_t_=px&url=
unknown
https://ic.tynt.com/b/p?id=wu!&lm=0&ts=1728339185806&dn=AFWU&iso=0&pu=https%3A%2F%2Fmegafansland.com%2Fdownload.php%3Fid%3DR6gN0a&t=sierra%20cabot%20Download%20-%20Mediafire&chpv=10.0.0&chuav=Google%20Chrome%3Bv%3D117.0.5938.134%2C%20Not%3BA%3DBrand%3Bv%3D8.0.0.0%2C%20Chromium%3Bv%3D117.0.5938.134&chp=Windows&chmob=0&chua=Google%20Chrome%3Bv%3D117%2C%20Not%3BA%3DBrand%3Bv%3D8%2C%20Chromium%3Bv%3D117
67.202.105.34
https://sync.smartadserver.com/getuid?gdpr=0&url=https%3A%2F%2Fbcp.crwdcntrl.net%2Fqmap%3Fc%3D16236%26tp%3DSMAD%26tpid%3D[sas_uid]%26gdpr%3D0
89.149.193.104
https://thrtle.com/sync?vxii_pid=7002&vxii_pdid=na
18.233.177.237
https://sync.crwdcntrl.net/qmap?c=5437&tp=DTAX&tpidqp=tpidqa&tpidqa=y-rpWNOlNE2pyDZC8Ayue3.mxO7fsDiOTwzsA-~A&gdpr=0
54.74.215.235
https://sync.ipredictive.com/d/sync/cookie/generic?partner=lotame&cspid=20&cb=${ADELPHIC_CACHE_BUSTER}&redirect=https%3A%2F%2Fsync.crwdcntrl.net%2Fqmap%3Fc%3D16622%26tp%3DALDX%26tpid%3D%24{ADELPHIC_CUID}%26gdpr%3D0
54.159.226.24
https://secure.adnxs.com/getuid?https%3A%2F%2Fsync.crwdcntrl.net%2Fmap%2Fc%3D281%2Ftp%3DANXS%2Ftpid%3D%24UID%2Fgdpr%3D0%2Frand=46473235
37.252.171.21
https://match.adsrvr.org/track/cmf/generic?ttd_pid=tapad&ttd_tpi=1&ttd_puid=2572367b-1bb4-4393-990a-0380506a7f29%252Chttps%25253A%25252F%25252Fsync.crwdcntrl.net%25252Fmap%25252Fc%25253D10158%25252Ftp%25253DTPAD%25252Ftpid%25253D2572367b-1bb4-4393-990a-0380506a7f29%252C%25257B%252522fullVersionList%252522%25253A%25255B%25257B%252522brand%252522%25253A%252522Google%252520Chrome%252522%25252C%252522version%252522%25253A%252522117.0.5938.134%252522%25257D%25252C%25257B%252522brand%252522%25253A%252522Not%25253BA%25255Cu003dBrand%252522%25252C%252522version%252522%25253A%2525228.0.0.0%252522%25257D%25252C%25257B%252522brand%252522%25253A%252522Chromium%252522%25252C%252522version%252522%25253A%252522117.0.5938.134%252522%25257D%25255D%25252C%252522mobile%252522%25253Afalse%25252C%252522model%252522%25253A%252522%252522%25252C%252522platform%252522%25253A%252522Windows%252522%25252C%252522platformVersion%252522%25253A%25252210.0.0%252522%25257D&gdpr=0&gdpr_consent=
15.197.193.217
https://sync.sharethis.com/id5?uid=ID5-ae980dJ9dv4ot750n8CaHddFajoaxcTojYTf40a_bg&gdpr=0&gdpr_consent=&rurl=https%3A%2F%2Fid5-sync.com%2Fa%2F19%2F121%2F4%2F6%2Fgif%2F0%2F0%2F0%2F0%2F
35.156.126.175
https://secure.adnxs.com/bounce?%2Fgetuid%3Fhttps%253A%252F%252Fsync.crwdcntrl.net%252Fmap%252Fc%253D281%252Ftp%253DANXS%252Ftpid%253D%2524UID%252Fgdpr%253D0%252Frand%3D46473235
37.252.171.21
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://x.bidswitch.net/sync?dsp_id=188&user_id=RO9hsv43VjtJegiqx3XZlggueyE&user_group=1&ssp=liveintent
35.214.136.108
https://d.turn.com/r/dd/id/L2NzaWQvMS9jaWQvMzQ4ODM4MC90LzI/dpuid/440ea49f4d537d0a764cd47bf20a1a2c/url/https://sync.crwdcntrl.net/map/c=10915/tp=TRNN/tpid=$!%7BTURN_UUID%7D/gdpr=0
46.228.164.13
https://megafansland.com/background/bR2vbfO.png
185.66.143.46
https://thrtle.com/sync?_reach=1&vxii_pdid=efbe099a-57c6-4d75-bd95-cfa970f48a53&vxii_pid=12&vxii_pid1=7006&vxii_rcid=721562d4-f092-41b4-9be2-3faaeb5f2215&vxii_rmax=3
18.233.177.237
https://secure.adnxs.com/getuid?https%3A%2F%2Fsync.crwdcntrl.net%2Fmap%2Fc%3D281%2Ftp%3DANXS%2Ftpid%
unknown
https://pixel.tapad.com/idsync/ex/receive/check?partner_id=LOTAME&partner_device_id=440ea49f4d537d0a764cd47bf20a1a2c&gdpr=0&partner_url=https%3A%2F%2Fsync.crwdcntrl.net%2Fmap%2Fc%3D10158%2Ftp%3DTPAD%2Ftpid%3D%24%7BTA_DEVICE_ID%7D&ch=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.134%22%7D%2C%7B%22brand%22%3A%22Not%3BA%5Cu003dBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.134%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D
34.111.113.62
https://sync.srv.stackadapt.com/sync?nid=lotame&gdpr=0
54.157.243.69
https://id5-sync.com/c/19/2/7/3.gif?puid=8747211381281681394&gdpr=0&gdpr_consent=
162.19.138.82
https://x.bidswitch.net/sync?ssp=liveintent&user_id=efbe099a-57c6-4d75-bd95-cfa970f48a53
35.214.136.108
https://i.simpli.fi/dpx?cid=11411&us_privacy=&33random=1728339231856.2&ref=
35.234.162.151
https://cm.g.doubleclick.net/pixel?google_nid=lotameddp&google_hm=NDQwZWE0OWY0ZDUzN2QwYTc2NGNkNDdiZjIwYTFhMmM&gdpr=0&google_tc=
172.217.23.98
https://sync.sharethis.com/ttd?uid=27c896d0-3d35-4d91-9d6d-d80dc54e6067&gdpr=0&gdpr_consent=
35.156.126.175
https://bcp.crwdcntrl.net/pixels?src=LTJS&s=41%2C92%2C78%2C136%2C135%2C148%2C49%2C7%2C33%2C31%2C122%2C22%2C116%2C61%2C154%2C106%2C104%2C8%2C54%2C100%2C145%2C3%2C2&c=3825&ch=%7B%22brands%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117%22%7D%5D%2C%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.134%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.134%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D
54.229.139.118
https://image6.pubmatic.com/AdServer/UCookieSetPug?gdpr=0&rd=https%3A%2F%2Fsync.crwdcntrl.net%2Fqmap%3Fc%3D240%26tp%3DPUBM%26tpid%3D%23PM_USER_ID%26gdpr%3D0&rdf=1
185.64.190.78
https://sync.crwdcntrl.net/qmap?c=16622&tp=ALDX&tpid=21720924-c7f7-4b6c-8ff5-a43fd45a7aeb&gdpr=0
54.74.215.235
https://pixel.tapad.com/idsync/ex/receive?partner_id=LOTAME&partner_device_id=440ea49f4d537d0a764cd4
unknown
https://pixel-sync.sitescout.com/connectors/lotame/usersync?cookieQ=1&gdpr=0&redir=https%3A%2F%2Fsync.crwdcntrl.net%2Fmap%2Fc%3D1389%2Ftp%3DSTSC%2Ftpid%3D%24UUID%2Fgdpr%3D0
34.36.216.150
https://tags.crwdcntrl.net/lt/shared/2/lt.iframe.html?c=3825
18.155.129.34
https://loadm.exelator.com/load/?p=204&g=1133&j=0&xl8blockcheck=1
34.254.143.3
https://pixel.tapad.com/idsync/ex/receive?partner_id=1830&partner_device_id=27c896d0-3d35-4d91-9d6d-d80dc54e6067&ttd_puid=2572367b-1bb4-4393-990a-0380506a7f29%2Chttps%253A%252F%252Fsync.crwdcntrl.net%252Fmap%252Fc%253D10158%252Ftp%253DTPAD%252Ftpid%253D2572367b-1bb4-4393-990a-0380506a7f29%2C%257B%2522fullVersionList%2522%253A%255B%257B%2522brand%2522%253A%2522Google%2520Chrome%2522%252C%2522version%2522%253A%2522117.0.5938.134%2522%257D%252C%257B%2522brand%2522%253A%2522Not%253BA%255Cu003dBrand%2522%252C%2522version%2522%253A%25228.0.0.0%2522%257D%252C%257B%2522brand%2522%253A%2522Chromium%2522%252C%2522version%2522%253A%2522117.0.5938.134%2522%257D%255D%252C%2522mobile%2522%253Afalse%252C%2522model%2522%253A%2522%2522%252C%2522platform%2522%253A%2522Windows%2522%252C%2522platformVersion%2522%253A%252210.0.0%2522%257D
34.111.113.62
https://track2.securedvisit.com/sync/1540_03681?id=na
107.23.180.140
https://nlsn.thrtle.com/sync?vxii_pid=5036&vxii_ts=4&_reach=1&puid=618e3ed0-84f9-11ef-bdb9-41cef0821a9d
54.82.142.25
https://ps.eyeota.net/pixel?pid=51md42u&t=ajs&e_pc=3&e_mr=0
3.125.70.222
https://thrtle.com/sync?vxii_pid=7006&vxii_pdid=efbe099a-57c6-4d75-bd95-cfa970f48a53&us_privacy=1YN-
18.233.177.237
https://e.dtscout.com/e/?v=1a&pid=5200&site=1&l=https%3A%2F%2Fmegafansland.com%2Fdownload.php%3Fid%3DR6gN0a&j=
141.101.120.10
https://live.rezync.com/pixel?c=bd8618c307ae9885a12561b7191e2cea&cid=5131077724524015663&referrer={encSite}&forward=https%3A%2F%2Fi.liadm.com%2Fs%2F56409%3Fbidder_id%3D200442%26bidder_uuid%3D1fb05311-e2e1-44be-a567-14c8d5b2ca5a%253A1728339233.2723432%26pid%3D500040%26it%3D1%26iv%3D1fb05311-e2e1-44be-a567-14c8d5b2ca5a%253A1728339233.2723432%26_%3D1728339233.2749367
18.66.218.84
https://sync.crwdcntrl.net/map/c=6466/tp=ADFM/tpid=7420645320403319419/gdpr=/gdpr_consent=
54.74.215.235
https://sync.intentiq.com/profiles_engine/ProfilesEngineServlet?at=20&mi=10&secure=1&dpi=182772995&iiqidtype=2&iiqpcid=f9a56d85-f0b1-8f98-d5d5-8c8646f7f15c&iiqpciddate=1728339203743&tsrnd=763_1728339203891&vrref=https%3A%2F%2Fpxdrop.lijit.com%2F&jsver=5.088&dw=1280&dh=1024&dpr=1&lan=en-US&uh=%7B%220%22%3A%22%5C%22Google%20Chrome%5C%22%3Bv%3D%5C%22117%5C%22%2C%20%5C%22Not%3BA%3DBrand%5C%22%3Bv%3D%5C%228%5C%22%2C%20%5C%22Chromium%5C%22%3Bv%3D%5C%22117%5C%22%22%2C%221%22%3A%22%3F0%22%2C%222%22%3A%22%5C%22Windows%5C%22%22%2C%223%22%3A%22%5C%22x86%5C%22%22%2C%224%22%3A%22%5C%2264%5C%22%22%2C%226%22%3A%22%5C%2210.0.0%5C%22%22%2C%227%22%3A%22%3F0%22%2C%228%22%3A%22%5C%22Google%20Chrome%5C%22%3Bv%3D%5C%22117.0.5938.134%5C%22%2C%20%5C%22Not%3BA%3DBrand%5C%22%3Bv%3D%5C%228.0.0.0%5C%22%2C%20%5C%22Chromium%5C%22%3Bv%3D%5C%22117.0.5938.134%5C%22%22%7D&gdpr=&ckls=true&ci=tXtixt8AfO&nc=false&trid=-496015370
18.66.196.124
https://token.rubiconproject.com/token?pid=7&puid=440ea49f4d537d0a764cd47bf20a1a2c&gdpr=0
unknown
https://x.bidswitch.net/ul_cb/sync?ssp=liveintent&user_id=efbe099a-57c6-4d75-bd95-cfa970f48a53
35.214.136.108
https://idsync.rlcdn.com/395886.gif?partner_uid=3647547360606158907
35.244.174.68
https://i6.liadm.com/s/41715?bidder_id=127211&bidder_uuid=440ea49f4d537d0a764cd47bf20a1a2c
44.194.236.225
https://t.sharethis.com/1/k/t.dhj?cid=c010&cls=C&rnd=
unknown
https://tags.crwdcntrl.net/lt/c/3825/optimus_rules.json
65.9.66.122
https://d.turn.com/r/dd/id/L2NzaWQvMS9jaWQvMTc0ODM4ODY2Ni90LzI/dpuid/ID5-ae980dJ9dv4ot750n8CaHddFajoaxcTojYTf40a_bg/url/https%3A%2F%2Fid5-sync.com%2Fc%2F19%2F224%2F6%2F4.gif%3Fpuid%3D%24%21%7BTURN_UUID%7D%26gdpr%3D0%26gdpr_consent%3D&gdpr=0&gdpr_consent=
46.228.164.13
https://de.tynt.com/deb/v2?id=wu!&dn=AFWU&cc=2&chp=Windows&chmob=0&chua=Google%20Chrome%3Bv%3D117%2C%20Not%3BA%3DBrand%3Bv%3D8%2C%20Chromium%3Bv%3D117&r=&pu=https%3A%2F%2Fmegafansland.com%2Fdownload.php%3Fid%3DR6gN0a
67.202.105.32
http://fontawesome.io/license
unknown
https://dmp.truoptik.com/f2d2e39fc16bc9cc/sync.gif?cbp=tpid&cbk=https%3A%2F%2Fsync.crwdcntrl.net%2Fm
unknown
https://a.dtssrv.com/a?i=
unknown
https://pixel.onaudience.com/?partner=137085098&mapped=
unknown
https://ps.eyeota.net/match?bid=1mpjpn0&turn_id=2367057880248159784&newuser=1&dc_rc=2&dc_mr=5&dc_orig=51mdg9u&
3.125.70.222
https://pixel.onaudience.com/?partner=109&icm&cver&gdpr=0&smartmap=1&redirect=tags.bluekai.com%2Fsite%2F33141%3F%26id%3D%25m
54.38.113.8
https://thrtle.com/sync?vxii_pid=7002&vxii_pdid=JdXVAQZHubo3YiDqSeG1j2vc
18.233.177.237
https://id5-sync.com/c/19/136/5/5.gif?puid=ZwRdAwAHsA99mgAF&gdpr=0&gdpr_consent=
162.19.138.82
https://sync.crwdcntrl.net/map/c=10620/tp=TRAD/tpid=27c896d0-3d35-4d91-9d6d-d80dc54e6067/gdpr=0/gdpr_consent=
54.74.215.235
https://i.liadm.com/s/41715?bidder_id=127211&bidder_uuid=440ea49f4d537d0a764cd47bf20a1a2c
107.21.124.174
https://c1.adform.net/serving/cookie/match?party=1040
unknown
https://megafansland.com/js/bower.js
185.66.143.46
https://megafansland.com/css/bower.css
185.66.143.46
https://megafansland.com/img/icon.jpg
185.66.143.46
http://fontawesome.io
unknown
https://ps.eyeota.net/match?bid=m51mhg1&uid=8e9703c8-81c9-4c9c-9098-d0a09dd9a8fe-67045cfd-5553
3.122.214.165
https://i.liadm.com/s/52164?bidder_id=5298&licd=&bidder_uuid=c92ba6ca-c503-4234-8529-0cdd853ebfe5
107.21.124.174
https://rtb.adentifi.com/CookieSyncThrotle?
52.200.121.93
https://i.simpli.fi/dpx?cid=11411&us_privacy=&33random=1728339187666.3&ref=
35.234.162.151
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
um.simpli.fi
34.91.62.186
id5-sync.com
162.19.138.82
d-ams1.turn.com
46.228.164.13
live.rezync.com
18.66.218.84
cdn.w55c.net
3.67.209.183
httplogserver-lb.global.unified-prod.sharethis.net
35.156.126.175
ats-eks.eu-central-1.dcs-online-targeting-prd.aws.oath.cloud
3.75.62.37
rtb-csync-euw1.smartadserver.com
89.149.193.104
sync.crwdcntrl.net
54.74.215.235
api.intentiq.com
13.226.175.112
s4.histats.com
149.56.240.129
cm.g.doubleclick.net
172.217.23.98
idaas-ext.cph.liveintent.com
107.21.124.174
www.google.com
172.217.16.196
sync.intentiq.com
18.66.196.124
idaas6.cph.liveintent.com
44.194.236.225
bcp.crwdcntrl.net
54.229.139.118
match.adsrvr.org
15.197.193.217
match.prod.bidr.io
34.252.67.98
pugm-lhrc.pubmnet.com
185.64.190.78
t.dtscout.com
141.101.120.11
pixel.onaudience.com
54.38.113.8
pixel-sync.sitescout.com
34.36.216.150
bg.microsoft.map.fastly.net
199.232.210.172
ActivationEdge-activation-212358690.eu-west-1.elb.amazonaws.com
52.49.76.6
a.tribalfusion.com
172.64.150.63
ml314.com
34.117.77.79
a.dtssrv.com
104.21.34.180
s.tribalfusion.com
172.64.150.63
simple-redirect-eu-west-1-kaas-blue.sre.nielsen.com
52.208.21.139
de.tynt.com
67.202.105.32
user-data-eu.bidswitch.net
35.214.136.108
ps.eyeota.net
3.125.70.222
idsync.rlcdn.com
35.244.174.68
dmp.truoptik.com
104.17.208.58
i.simpli.fi
35.234.162.151
rtb.adentifi.com
52.200.121.93
sync.srv.stackadapt.com
54.157.243.69
thrtle.com
18.233.177.237
pixel.tapad.com
34.111.113.62
raptor-prd-ew1-alb-2127381300.eu-west-1.elb.amazonaws.com
52.17.21.147
rtb-csync-euw2.smartadserver.com
164.132.25.185
megafansland.com
185.66.143.46
pippio.com
107.178.254.65
sync.ipredictive.com
54.159.226.24
track2.securedvisit.com
107.23.180.140
global.ib-ibi.com
54.94.182.41
tags.crwdcntrl.net
65.9.66.122
thirdparty-logserver-lb.global.unified-prod.sharethis.net
3.74.183.50
t.dtscdn.com
104.26.13.60
nlsn.thrtle.com
54.82.142.25
e.dtscout.com
141.101.120.10
ic.tynt.com
67.202.105.34
load-euw1.exelator.com
54.78.254.47
ib.anycast.adnxs.com
185.89.210.46
pm.w55c.net
unknown
idpix.media6degrees.com
unknown
secure.adnxs.com
unknown
token.rubiconproject.com
unknown
sync.smartadserver.com
unknown
i6.liadm.com
unknown
c1.adform.net
unknown
ce.lijit.com
unknown
px.ads.linkedin.com
unknown
d.turn.com
unknown
stags.bluekai.com
unknown
thrtl.redinuid.imrworldwide.com
unknown
c.cintnetworks.com
unknown
i.w55c.net
unknown
sync-tm.everesttech.net
unknown
p.rfihub.com
unknown
sync.sharethis.com
unknown
t.sharethis.com
unknown
image6.pubmatic.com
unknown
ups.analytics.yahoo.com
unknown
time.windows.com
unknown
cdn-tc.33across.com
unknown
loadus.exelator.com
unknown
aqfer.lijit.com
unknown
cdn.tynt.com
unknown
agent.intentiq.com
unknown
idsync.reson8.com
unknown
s10.histats.com
unknown
aa.agkn.com
unknown
rtd-tm.everesttech.net
unknown
x.bidswitch.net
unknown
i.liadm.com
unknown
tags.bluekai.com
unknown
pxdrop.lijit.com
unknown
ib.adnxs.com
unknown
pd.sharethis.com
unknown
loadm.exelator.com
unknown
There are 82 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
54.39.156.32
unknown
Canada
65.9.66.97
unknown
United States
107.21.124.174
idaas-ext.cph.liveintent.com
United States
52.208.21.139
simple-redirect-eu-west-1-kaas-blue.sre.nielsen.com
United States
34.254.143.3
unknown
United States
35.156.126.175
httplogserver-lb.global.unified-prod.sharethis.net
United States
18.233.177.237
thrtle.com
United States
107.178.254.65
pippio.com
United States
239.255.255.250
unknown
Reserved
35.244.174.68
idsync.rlcdn.com
United States
44.193.146.248
unknown
United States
54.229.139.118
bcp.crwdcntrl.net
United States
54.78.254.47
load-euw1.exelator.com
United States
18.155.129.34
unknown
United States
3.74.183.50
thirdparty-logserver-lb.global.unified-prod.sharethis.net
United States
34.252.67.98
match.prod.bidr.io
United States
46.228.164.13
d-ams1.turn.com
United Kingdom
54.82.142.25
nlsn.thrtle.com
United States
54.159.226.24
sync.ipredictive.com
United States
104.26.13.60
t.dtscdn.com
United States
185.89.210.46
ib.anycast.adnxs.com
Germany
3.122.214.165
unknown
United States
164.132.25.185
rtb-csync-euw2.smartadserver.com
France
34.36.216.150
pixel-sync.sitescout.com
United States
52.200.121.93
rtb.adentifi.com
United States
185.64.190.78
pugm-lhrc.pubmnet.com
United Kingdom
52.49.236.173
unknown
United States
104.21.34.180
a.dtssrv.com
United States
52.17.21.147
raptor-prd-ew1-alb-2127381300.eu-west-1.elb.amazonaws.com
United States
44.194.236.225
idaas6.cph.liveintent.com
United States
142.250.181.226
unknown
United States
37.252.171.21
unknown
European Union
54.157.243.69
sync.srv.stackadapt.com
United States
192.168.2.7
unknown
unknown
3.75.152.14
unknown
United States
3.125.70.222
ps.eyeota.net
United States
3.160.150.74
unknown
United States
192.168.2.5
unknown
unknown
35.234.162.151
i.simpli.fi
United States
54.94.182.41
global.ib-ibi.com
United States
104.17.208.58
dmp.truoptik.com
United States
89.149.193.104
rtb-csync-euw1.smartadserver.com
Netherlands
18.184.216.10
unknown
United States
3.67.209.183
cdn.w55c.net
United States
162.19.138.82
id5-sync.com
United States
18.66.196.124
sync.intentiq.com
United States
149.56.240.129
s4.histats.com
Canada
54.74.215.235
sync.crwdcntrl.net
United States
34.117.77.79
ml314.com
United States
3.75.62.37
ats-eks.eu-central-1.dcs-online-targeting-prd.aws.oath.cloud
United States
44.194.57.235
unknown
United States
172.64.150.63
a.tribalfusion.com
United States
52.30.186.133
unknown
United States
104.26.12.60
unknown
United States
172.217.16.196
www.google.com
United States
34.91.62.186
um.simpli.fi
United States
18.66.218.84
live.rezync.com
United States
141.101.120.11
t.dtscout.com
European Union
35.214.136.108
user-data-eu.bidswitch.net
United States
141.101.120.10
e.dtscout.com
European Union
15.197.193.217
match.adsrvr.org
United States
54.78.53.108
unknown
United States
54.38.113.8
pixel.onaudience.com
France
65.9.66.122
tags.crwdcntrl.net
United States
18.205.228.210
unknown
United States
172.217.23.98
cm.g.doubleclick.net
United States
54.76.113.237
unknown
United States
67.202.105.32
de.tynt.com
United States
67.202.105.31
unknown
United States
13.226.175.112
api.intentiq.com
United States
107.23.180.140
track2.securedvisit.com
United States
67.202.105.34
ic.tynt.com
United States
52.49.76.6
ActivationEdge-activation-212358690.eu-west-1.elb.amazonaws.com
United States
34.111.113.62
pixel.tapad.com
United States
34.194.53.2
unknown
United States
185.66.143.46
megafansland.com
Netherlands
There are 66 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
https://megafansland.com/download.php?id=R6gN0a
There are 16 hidden doms, click here to show them.