IOC Report
http://spreadengineering.w3spaces.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 45
HTML document, Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 46
Web Open Font Format (Version 2), TrueType, length 14892, version 1.0
downloaded
Chrome Cache Entry: 47
Web Open Font Format (Version 2), TrueType, length 125064, version 768.67
downloaded
Chrome Cache Entry: 48
Web Open Font Format (Version 2), TrueType, length 18596, version 1.0
downloaded
Chrome Cache Entry: 49
ASCII text, with very long lines (65311)
downloaded
Chrome Cache Entry: 50
HTML document, ASCII text, with very long lines (1835)
downloaded
Chrome Cache Entry: 51
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 52
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 53
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 54
ASCII text
downloaded
Chrome Cache Entry: 55
Web Open Font Format (Version 2), TrueType, length 14712, version 1.0
downloaded
Chrome Cache Entry: 56
ASCII text
downloaded
Chrome Cache Entry: 57
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
There are 4 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2512 --field-trial-handle=2024,i,2154893502831723345,15109222188338521242,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://spreadengineering.w3spaces.com/"

URLs

Name
IP
Malicious
http://spreadengineering.w3spaces.com/
https://fontawesome.com
unknown
https://raw.githubusercontent.com/Purplegaze/osu-stuff/main/diffs/mania/
unknown
https://raw.githubusercontent.com/Purplegaze/osu-stuff/main/diffs/taiko/
unknown
https://raw.githubusercontent.com/Purplegaze/osu-stuff/main/diffs/std/
unknown
https://www.w3schools.com/spaces/
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/webfonts/fa-solid-900.woff2
104.17.24.14
http://spreadengineering.w3spaces.com/
143.204.98.75
https://raw.githubusercontent.com/Purplegaze/osu-stuff/main/diffs/catch/
unknown
https://a.nel.cloudflare.com/report/v4?s=Ax7oxiO%2FdVpya7CciZqT9ZvpTelpE2i3s82wvusrm5kHMS5oMr3x%2BjugrauggM44KM%2FPv7SccLwvaUMB5ZUrCJlx4ivmUnTTdBaA71jhuqwtevnUSp87l0aB
35.190.80.1
https://support.w3schools.com/
unknown
https://www.w3schools.com/howto/howto_website_create_free.asp
unknown
https://d3js.org/d3.v7.min.js
172.67.73.126
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.0.0-beta3/css/all.min.css
104.17.24.14
https://www.w3schools.com
unknown
https://spreadengineering.w3spaces.com/
https://www.w3schools.com/favicon.ico
192.229.133.221
https://spreadengineering.w3spaces.com/favicon.ico
143.204.98.34
https://fontawesome.com/license/free
unknown
There are 8 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
spreadengineering.w3spaces.com
143.204.98.75
cs837.wac.edgecastcdn.net
192.229.133.221
cdnjs.cloudflare.com
104.17.24.14
www.google.com
142.250.81.228
d3js.org
172.67.73.126
www.w3schools.com
unknown

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
172.67.73.126
d3js.org
United States
192.168.2.7
unknown
unknown
192.168.2.4
unknown
unknown
192.229.133.221
cs837.wac.edgecastcdn.net
United States
142.250.81.228
www.google.com
United States
239.255.255.250
unknown
Reserved
143.204.98.75
spreadengineering.w3spaces.com
United States
143.204.98.34
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://spreadengineering.w3spaces.com/
https://spreadengineering.w3spaces.com/