IOC Report
http://whatsapp-32w.pages.dev/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 111
Unicode text, UTF-8 text, with very long lines (492), with CRLF line terminators
downloaded
Chrome Cache Entry: 112
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 736x1308, components 3
dropped
Chrome Cache Entry: 113
PNG image data, 223 x 145, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 114
Web Open Font Format (Version 2), TrueType, length 14780, version 1.0
downloaded
Chrome Cache Entry: 115
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 116
PNG image data, 498 x 501, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 117
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 2048x1536, components 3
dropped
Chrome Cache Entry: 118
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 2048x1536, components 3
downloaded
Chrome Cache Entry: 119
ASCII text
downloaded
Chrome Cache Entry: 120
HTML document, ASCII text, with very long lines (352), with CRLF line terminators
downloaded
Chrome Cache Entry: 121
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 736x1308, components 3
downloaded
Chrome Cache Entry: 122
PNG image data, 498 x 501, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 123
HTML document, ASCII text, with very long lines (352), with CRLF line terminators
downloaded
Chrome Cache Entry: 124
HTML document, ASCII text, with very long lines (352), with CRLF line terminators
dropped
Chrome Cache Entry: 125
PNG image data, 223 x 145, 8-bit/color RGBA, non-interlaced
downloaded
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2032,i,7004676408669070218,2015690869022979061,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://whatsapp-32w.pages.dev/"

URLs

Name
IP
Malicious
http://whatsapp-32w.pages.dev/
https://whatsapp-32w.pages.dev/style.css
172.66.47.180
malicious
https://whatsapp-32w.pages.dev/images/whatsapp.png
172.66.47.180
malicious
https://whatsapp-32w.pages.dev/images/xxx.jpg
172.66.47.180
malicious
https://whatsapp-32w.pages.dev/backoffer.js
172.66.47.180
malicious
https://whatsapp-32w.pages.dev/main-style.css
172.66.47.180
malicious
https://whatsapp-32w.pages.dev/images/gaber.jpg
172.66.47.180
malicious
https://whatsapp-32w.pages.dev/
malicious
https://whatsapp-32w.pages.dev/images/wa.png
172.66.47.180
malicious
https://vozkn.unfamlliiardates.net/c/da57dc555e50572d?s1=74105&s2=1211737&s3=TEMUROSE_2&click_id=TEM
unknown

Domains

Name
IP
Malicious
whatsapp-32w.pages.dev
172.66.47.180
www.google.com
216.58.206.36

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
172.66.47.180
whatsapp-32w.pages.dev
United States
192.168.2.7
unknown
unknown
216.58.206.36
www.google.com
United States

DOM / HTML

URL
Malicious
https://whatsapp-32w.pages.dev/
malicious