IOC Report
https://evicertia.com/Delivery/019247e7-307b-4d79-bf99-a300cd1f6d97

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 48
Unicode text, UTF-8 text, with very long lines (47335)
downloaded
Chrome Cache Entry: 49
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 50
Web Open Font Format (Version 2), TrueType, length 18664, version 1.0
downloaded
Chrome Cache Entry: 51
Web Open Font Format (Version 2), TrueType, length 18628, version 1.0
downloaded
Chrome Cache Entry: 52
PNG image data, 300 x 100, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 53
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 54
HTML document, Unicode text, UTF-8 text, with very long lines (747)
downloaded
Chrome Cache Entry: 55
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 56
ASCII text, with very long lines (45176)
dropped
Chrome Cache Entry: 57
Web Open Font Format (Version 2), TrueType, length 18740, version 1.0
downloaded
Chrome Cache Entry: 58
PNG image data, 300 x 100, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 59
ASCII text, with very long lines (45176)
downloaded
There are 3 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2024,i,15333744745124969845,5568448262312495137,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://evicertia.com/Delivery/019247e7-307b-4d79-bf99-a300cd1f6d97"

URLs

Name
IP
Malicious
https://evicertia.com/Delivery/019247e7-307b-4d79-bf99-a300cd1f6d97
https://github.com/bigskysoftware/htmx/pull/2159
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://evicertia.com/Delivery/019247e7-307b-4d79-bf99-a300cd1f6d97
94.103.116.70
https://evicertia.com/Content/Fonts/open-sans-latin-500-normal.woff2
94.103.116.70
https://evicertia.com/Content/Images/favicon.ico?v=24259.16716.14.14
94.103.116.70
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://evicertia.com/Public/EviNotice/Custody/01926b27-fda1-4931-8cb6-ddb420cd95f9/Access
https://evicertia.com/Public/EviNotice/Custody?uniqueId=019247e7-307b-446a-ad9c-9727c03931e7
94.103.116.70
https://evicertia.com/Master/Logo
94.103.116.70
https://evicertia.com/Content/Fonts/open-sans-latin-600-normal.woff2
94.103.116.70
https://evicertia.com/Content/Fonts/open-sans-latin-400-normal.woff2
94.103.116.70
https://getbootstrap.com/)
unknown
https://evicertia.com/Public/EviNotice/Delivery/Start?deliveryId=019247e7-307b-4d79-bf99-a300cd1f6d97
94.103.116.70
https://evicertia.com/bundles/scripts?v=x4d2qT5CnQZ_0DFzoxe_OYPzAkbBM9iDu4jhJfBbepk1
94.103.116.70
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
216.58.206.68
evicertia.com
94.103.116.70
fp2e7a.wpc.phicdn.net
192.229.221.95
206.23.85.13.in-addr.arpa
unknown

IPs

IP
Domain
Country
Malicious
142.250.185.132
unknown
United States
192.168.2.4
unknown
unknown
216.58.206.68
www.google.com
United States
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
192.168.2.15
unknown
unknown
94.103.116.70
evicertia.com
Spain

DOM / HTML

URL
Malicious
https://evicertia.com/Public/EviNotice/Custody/01926b27-fda1-4931-8cb6-ddb420cd95f9/Access