IOC Report
http://qetf.de/XBxJ#

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (15752)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (31997), with CRLF line terminators
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (57765)
downloaded
Chrome Cache Entry: 103
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 105
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 106
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 107
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 108
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (31997), with CRLF line terminators
downloaded
Chrome Cache Entry: 110
ASCII text
dropped
Chrome Cache Entry: 111
HTML document, ASCII text, with very long lines (5370), with CRLF, CR line terminators
dropped
Chrome Cache Entry: 112
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 113
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 114
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 62
ASCII text, with very long lines (45722), with no line terminators
downloaded
Chrome Cache Entry: 63
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 64
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 65
ASCII text, with very long lines (941)
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (13479)
downloaded
Chrome Cache Entry: 67
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 68
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 69
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 70
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 71
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 72
HTML document, ASCII text, with very long lines (5370), with CRLF, CR line terminators
downloaded
Chrome Cache Entry: 73
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 74
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 75
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 76
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 78
ASCII text, with very long lines (32939), with no line terminators
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (54655)
downloaded
Chrome Cache Entry: 81
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (13479)
dropped
Chrome Cache Entry: 83
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 84
ASCII text
downloaded
Chrome Cache Entry: 85
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 86
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 87
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 88
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 89
ASCII text, with very long lines (3184), with CRLF line terminators
downloaded
Chrome Cache Entry: 90
Web Open Font Format (Version 2), TrueType, length 18596, version 1.0
downloaded
Chrome Cache Entry: 91
HTML document, Unicode text, UTF-8 text, with very long lines (9473)
downloaded
Chrome Cache Entry: 92
ASCII text
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 94
ASCII text, with very long lines (941)
dropped
Chrome Cache Entry: 95
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 96
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 97
RIFF (little-endian) data, Web/P image, VP8 encoding, 400x317, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 98
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (15752)
dropped
There are 44 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1680 --field-trial-handle=2028,i,10317001253910414027,1982138398670822239,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://qetf.de/XBxJ#"

URLs

Name
IP
Malicious
http://qetf.de/XBxJ#
https://stats.g.doubleclick.net/g/collect
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-2048x473.png
unknown
https://thereviewscasinos.com/bonus-category/free-spins/
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-768x177.png
unknown
https://thereviewscasinos.com/casino/sixdot-casino/
unknown
https://thereviewscasinos.com/?s=
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/4100cc3d0c00c26a-aces-style.css
188.114.96.3
https://thereviewscasinos.com/wp-content/uploads/2024/09/allspins-casino-logo-update-400x317.webp
188.114.96.3
https://www.google.com
unknown
https://www.youtube.com/iframe_api
unknown
https://thereviewscasinos.com/wp-json/wp/v2/pages/101
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/09/8xwins-casino-logo-400x317.webp
188.114.96.3
https://thereviewscasinos.com/casinos/#breadcrumb
unknown
https://thereviewscasinos.com/casinos/page/2/
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-173x40.png
188.114.96.3
https://thereviewscasinos.com/#website
unknown
https://thereviewscasinos.com/casinos/
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/6dea934c5ab3
unknown
https://thereviewscasinos.com/casino/belabet-casino/
unknown
https://jokoiu.cfd/p6FDjN?__pcd=9
188.114.96.3
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-347x80.png
unknown
https://thereviewscasinos.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fthereviewscasinos.com%2Fcas
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/09/immerion-casino-logo-1-400x317.webp
188.114.96.3
https://thereviewscasinos.com/bonus-category/no-deposit-bonus/
unknown
https://thereviewscasinos.com/bonus-category/deposit-bonus/
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/01/slots370-scaled.jpg
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/c5b24615265e8e28-animate.css
188.114.96.3
https://thereviewscasinos.com/casino/lucky-ones-casino/
unknown
https://speedycache.com
unknown
https://thereviewscasinos.com/casino-category/online-casinos/
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/09/luckyones-casino-logo-400x317.webp
188.114.96.3
https://schema.org
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/0025d45c917e05da-scripts.js
188.114.96.3
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-139x32.png
unknown
https://cct.google/taggy/agent.js
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/09/rakebit-casino-logo-400x317.webp
188.114.96.3
https://thereviewscasinos.com/casino/casiny-casino/
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/05/winwisper-1.png
unknown
https://thereviewscasinos.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
188.114.96.3
https://thereviewscasinos.com/wp-content/themes/mercury/js/owl.carousel.min.js?ver=2.3.4
188.114.96.3
https://thereviewscasinos.com/wp-content/themes/mercury/css/owl.carousel.min.css?ver=2.3.4
188.114.96.3
https://thereviewscasinos.com/wp-content/themes/mercury/fontawesome/css/all.min.css?ver=6.6.0
188.114.96.3
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/0025d45c917e
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/1e229ac6085c3d2e-style.css
188.114.96.3
https://thereviewscasinos.com/#/schema/logo/image/
unknown
https://thereviewscasinos.com/casino/8xwins-casino/
unknown
https://thereviewscasinos.com/casino/auf-casino/
unknown
https://thereviewscasinos.com/casino-category/newest-casinos/
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-585x135.png
unknown
https://thereviewscasinos.com/casino-category/mobile-casinos/
unknown
https://thereviewscasinos.com/casino-category/crypto-casino/
unknown
https://thereviewscasinos.com/bonus-category/reload-bonus/
unknown
https://thereviewscasinos.com/wp-includes/css/dist/block-library/style.min.css?ver=6.6.2
188.114.96.3
https://thereviewscasinos.com/casinos/#primaryimage
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-300x69.png
unknown
https://thereviewscasinos.com/bonus-category/cashback-bonus/
unknown
https://thereviewscasinos.com/wp-json/
unknown
https://thereviewscasinos.com/wp-content/themes/mercury/js/theia-sticky-sidebar.min.js?ver=1.7.0
188.114.96.3
https://thereviewscasinos.com/?p=101
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/beed5475599e22e7-public.js
188.114.96.3
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-303x70.png
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/09/auf-casino-logo-400x317.webp
188.114.96.3
https://thereviewscasinos.com/casino/romancasino/
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/5fb999c83785
unknown
http://daneden.me/animate
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/09/sixdot-casino-logo-400x317.webp
188.114.96.3
https://thereviewscasinos.com/casinos/page/6/
unknown
https://thereviewscasinos.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
188.114.96.3
https://thereviewscasinos.com/
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/01/cropped-favicon-270x270.webp
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/6dea934c5ab37fa7-media.css
188.114.96.3
https://thereviewscasinos.com/casino-category/certified-casinos/
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/a57eb246e26f
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/1e229ac6085c
unknown
https://thereviewscasinos.com/recommends/allspins/
unknown
https://thereviewscasinos.com/casino/immerion-casino/
unknown
https://thereviewscasinos.com/wp-includes/js/wp-emoji-release.min.js?ver=6.6.2
188.114.96.3
https://thereviewscasinos.com/wp-content/uploads/2024/09/romancasino-logo-400x317.webp
188.114.96.3
https://thereviewscasinos.com/casinos/page/7/
unknown
https://thereviewscasinos.com/xmlrpc.php?rsd
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/01/cropped-favicon-32x32.webp
188.114.96.3
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-1024x236.png
unknown
https://thereviewscasinos.com/#organization
unknown
https://thereviewscasinos.com/news/
unknown
https://api.w.org/
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/a57eb246e26fa7b5-enable-sticky-sidebar.js
188.114.96.3
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/4100cc3d0c00
unknown
https://a.nel.cloudflare.com/report/v4?s=3WhFP0mfNdybl0yUhxgLxtdb7Lfca%2BzVrlf%2BJ52JJkokOLJU9M%2BjD2AfwTq0oz8fyAl8hL7Qmf4t9DzlL3WkDFQcrqmMat5xN1wHxZaiRO54SOlTeypGLLIC7v6Li2f90WbyUGHUSnw%3D
35.190.80.1
https://thereviewscasinos.com/wp-content/uploads/2024/09/belabet-casino-logo-400x317.webp
188.114.96.3
https://thereviewscasinos.com/bonuses/
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/5fb999c837859fce-aces-media.css
188.114.96.3
https://thereviewscasinos.com/free-casino-games/
unknown
https://thereviewscasinos.com/wp-content/cache/speedycache/thereviewscasinos.com/assets/beed5475599e
unknown
https://td.doubleclick.net
unknown
https://thereviewscasinos.com/wp-content/uploads/2024/05/cropped-winwisper-1-1536x354.png
unknown
https://thereviewscasinos.com/casino/rakebit-casino/
unknown
https://www.merchant-center-analytics.goog
unknown
https://thereviewscasinos.com/casino/allspins-casino/
unknown
https://thereviewscasinos.com/casino-category/live-casino/
unknown
http://qetf.de/XBxJ
91.210.225.11
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
qetf.de
91.210.225.11
jokoiu.cfd
188.114.96.3
a.nel.cloudflare.com
35.190.80.1
gateway.clickshield.24metrics.com
35.233.96.203
thereviewscasinos.com
188.114.96.3
www.google.com
142.250.185.132
www.rvucw4trk.com
34.160.169.12
fp2e7a.wpc.phicdn.net
192.229.221.95
windowsupdatebg.s.llnwi.net
87.248.204.0
www.mks1q.com
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
34.160.169.12
www.rvucw4trk.com
United States
142.250.185.132
www.google.com
United States
35.233.96.203
gateway.clickshield.24metrics.com
United States
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
91.210.225.11
qetf.de
Germany
188.114.96.3
jokoiu.cfd
European Union
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://thereviewscasinos.com/casinos/