IOC Report
https://www.google.be/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp%2F%E2%80%8Bdd%C2%AD7%C2%ADk%C2%ADyv6%C2%ADcs%C2%ADjaa8%E2%80%8B.c%C2%ADlou%C2%ADdf%C2%ADro%C2%ADnt%E2%80%8B.n%C2%ADe%C2%AD

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 62
ASCII text, with very long lines (48316), with no line terminators
dropped
Chrome Cache Entry: 63
ASCII text, with very long lines (47459)
downloaded
Chrome Cache Entry: 64
PNG image data, 48 x 39, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 65
XML 1.0 document, ASCII text
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 67
gzip compressed data, from Unix, original size modulo 2^32 4889
downloaded
Chrome Cache Entry: 68
Unicode text, UTF-8 text, with very long lines (65306)
downloaded
Chrome Cache Entry: 69
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (47459)
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (47459)
dropped
Chrome Cache Entry: 72
ASCII text, with very long lines (1158)
dropped
Chrome Cache Entry: 73
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 74
PNG image data, 17 x 48, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 75
HTML document, ASCII text
downloaded
Chrome Cache Entry: 76
JSON data
dropped
Chrome Cache Entry: 77
very short file (no magic)
dropped
Chrome Cache Entry: 78
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 79
very short file (no magic)
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 83
HTML document, ASCII text, with very long lines (6577), with CRLF line terminators
downloaded
Chrome Cache Entry: 84
PNG image data, 17 x 48, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (48316), with no line terminators
downloaded
Chrome Cache Entry: 86
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 87
PNG image data, 48 x 39, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 88
XML 1.0 document, ASCII text
downloaded
Chrome Cache Entry: 89
ASCII text, with very long lines (1158)
downloaded
There are 19 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2424 --field-trial-handle=2384,i,16173492334426608781,2710274369230945367,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.google.be/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp%2F%E2%80%8Bdd%C2%AD7%C2%ADk%C2%ADyv6%C2%ADcs%C2%ADjaa8%E2%80%8B.c%C2%ADlou%C2%ADdf%C2%ADro%C2%ADnt%E2%80%8B.n%C2%ADe%C2%ADt%23pV~IYmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU="

URLs

Name
IP
Malicious
https://www.google.be/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp%2F%E2%80%8Bdd%C2%AD7%C2%ADk%C2%ADyv6%C2%ADcs%C2%ADjaa8%E2%80%8B.c%C2%ADlou%C2%ADdf%C2%ADro%C2%ADnt%E2%80%8B.n%C2%ADe%C2%ADt%23pV~IYmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
https://chick-fil-a-menu.s3.eu-north-1.amazonaws.com/chicken+%26+burgers/waffle-potato-fries/Come-Visit-Chick-fil-A-yMLuZ0P9QALho3Tp4TlTEtf6UevLtheNAtvi35UgSyjdxyOpznAy6FlkHuFWea1xVExctKENx8fTmsTmTLce47GQJlitK8YJ00vIxM439sfzEOtCWtyR5qW6I4CFqb/index.html#YmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/gidp1/0x4AAAAAAAiSTUDZPPc8TA8S/auto/fbE/normal/auto/
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8d0a06f41de842d8&lang=auto
104.18.94.41
https://www.overstock.com/
23.227.38.74
http://dd7kyv6csjaa8.cloudfront.net/favicon.ico
18.239.47.144
http://dd7kyv6csjaa8.cloudfront.net/
18.239.47.144
https://code.jquery.com/jquery-3.6.0.min.js
151.101.130.137
https://sci.suareptitious.com/CcOtNJFaDyNmAfXRmhw/
172.67.197.162
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
104.17.24.14
https://a.nel.cloudflare.com/report/v4?s=qYoKbIoZijtbkjnzvWJBJDyexrx8%2FnC4h2VrAP2%2BON5mAFWgIBN2gsFbv0X7uK3q%2FA1rcDWOhS%2BSBycBOgGk2BjcWABT%2FXlb0HmnZrBUxF%2BflgblYaVHjj9wvxIlLY8WFx2Z
35.190.80.1
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://chick-fil-a-menu.s3.eu-north-1.amazonaws.com/favicon.ico
3.5.217.70
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8d0a0757fc2b558f/1728599153372/c0bbcf47d18dec00ecfcd22b94c4c8b41e9cf461c06159d5c0485906d7bf5ff4/1z20DJUp3RkjoKO
104.18.95.41
https://challenges.cloudflare.com/turnstile/v0/b/62ec4f065604/api.js
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/15njv/0x4AAAAAAAi0IXhVvC1FMAdv/auto/fbE/normal/auto/
104.18.95.41
https://getbootstrap.com/)
unknown
https://href.li/?https://sci.suareptitious.com/CcOtNJFaDyNmAfXRmhw/
192.0.78.27
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8d0a0757fc2b558f/1728599153371/IL9rVXl2WXtspwt
104.18.95.41
https://f0vdflmxqd4gb2sbj2clkhyjidu39mnbnueve7aksn5fnfkmmwyjcgj1iov.transenil.ru/freudesjynielbhsccdzrkvazxRimKxLBFAYJOPVUMOQVBRHEBMBWIXQCJHSFCPIJOAPKPSWFDM
188.114.97.3
https://ohayo.psone-1.com/cloud.php
103.3.1.16
https://chick-fil-a-menu.s3.eu-north-1.amazonaws.com/chicken+%26+burgers/waffle-potato-fries/Come-Visit-Chick-fil-A-yMLuZ0P9QALho3Tp4TlTEtf6UevLtheNAtvi35UgSyjdxyOpznAy6FlkHuFWea1xVExctKENx8fTmsTmTLce47GQJlitK8YJ00vIxM439sfzEOtCWtyR5qW6I4CFqb/index.html
3.5.217.70
http://medialize.github.io/URI.js/
unknown
https://cdnjs.cloudflare.com/ajax/libs/URI.js/1.19.11/URI.min.js
104.17.24.14
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8d0a0757fc2b558f&lang=auto
104.18.95.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8d0a06f41de842d8/1728599137271/Q5qFOECnTdOpQ2T
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1328431043:1728594682:7FJwN7qGM-qyE3QXQIz615NmF3jpXkck3-bkhO6MFT0/8d0a0757fc2b558f/9d41e3ccdeec428
104.18.95.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1919844282:1728594527:KR9qSwzh7NZty1nu-VEyPk7wdK6hf--q6K5unyBTFJo/8d0a06f41de842d8/7172f037d902f99
104.18.94.41
http://dd7kyv6csjaa8.cloudfront.net/#pV~IYmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
There are 19 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s3-r-w.eu-north-1.amazonaws.com
3.5.217.70
a.nel.cloudflare.com
35.190.80.1
s-part-0017.t-0009.t-msedge.net
13.107.246.45
f0vdflmxqd4gb2sbj2clkhyjidu39mnbnueve7aksn5fnfkmmwyjcgj1iov.transenil.ru
188.114.97.3
shops.myshopify.com
23.227.38.74
fp2e7a.wpc.phicdn.net
192.229.221.95
href.li
192.0.78.27
sci.suareptitious.com
172.67.197.162
ohayo.psone-1.com
103.3.1.16
code.jquery.com
151.101.130.137
cdnjs.cloudflare.com
104.17.24.14
challenges.cloudflare.com
104.18.94.41
www.google.com
142.250.81.228
dd7kyv6csjaa8.cloudfront.net
18.239.47.144
www.google.be
142.250.185.163
cdn.jsdelivr.net
unknown
chick-fil-a-menu.s3.eu-north-1.amazonaws.com
unknown
www.overstock.com
unknown
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
104.18.94.41
challenges.cloudflare.com
United States
23.227.38.74
shops.myshopify.com
Canada
192.168.2.7
unknown
unknown
3.5.217.70
s3-r-w.eu-north-1.amazonaws.com
United States
104.18.95.41
unknown
United States
192.168.2.4
unknown
unknown
142.250.81.228
www.google.com
United States
192.168.2.6
unknown
unknown
192.0.78.27
href.li
United States
151.101.130.137
code.jquery.com
United States
103.3.1.16
ohayo.psone-1.com
Japan
239.255.255.250
unknown
Reserved
188.114.97.3
f0vdflmxqd4gb2sbj2clkhyjidu39mnbnueve7aksn5fnfkmmwyjcgj1iov.transenil.ru
European Union
35.190.80.1
a.nel.cloudflare.com
United States
172.67.197.162
sci.suareptitious.com
United States
18.239.47.144
dd7kyv6csjaa8.cloudfront.net
United States
There are 7 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
http://dd7kyv6csjaa8.cloudfront.net/#pV~IYmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
http://dd7kyv6csjaa8.cloudfront.net/#pV~IYmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
http://dd7kyv6csjaa8.cloudfront.net/#pV~IYmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
https://chick-fil-a-menu.s3.eu-north-1.amazonaws.com/chicken+%26+burgers/waffle-potato-fries/Come-Visit-Chick-fil-A-yMLuZ0P9QALho3Tp4TlTEtf6UevLtheNAtvi35UgSyjdxyOpznAy6FlkHuFWea1xVExctKENx8fTmsTmTLce47GQJlitK8YJ00vIxM439sfzEOtCWtyR5qW6I4CFqb/index.html#YmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
https://chick-fil-a-menu.s3.eu-north-1.amazonaws.com/chicken+%26+burgers/waffle-potato-fries/Come-Visit-Chick-fil-A-yMLuZ0P9QALho3Tp4TlTEtf6UevLtheNAtvi35UgSyjdxyOpznAy6FlkHuFWea1xVExctKENx8fTmsTmTLce47GQJlitK8YJ00vIxM439sfzEOtCWtyR5qW6I4CFqb/index.html#YmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=
https://chick-fil-a-menu.s3.eu-north-1.amazonaws.com/chicken+%26+burgers/waffle-potato-fries/Come-Visit-Chick-fil-A-yMLuZ0P9QALho3Tp4TlTEtf6UevLtheNAtvi35UgSyjdxyOpznAy6FlkHuFWea1xVExctKENx8fTmsTmTLce47GQJlitK8YJ00vIxM439sfzEOtCWtyR5qW6I4CFqb/index.html#YmVuLmZhcnJ1Z2lhQG9uc2l0ZS5jb20uYXU=