IOC Report
http://www.klinch.ch//ABOUT

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 21:53:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 21:53:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 21:53:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 21:53:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 21:53:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 69
ASCII text, with very long lines (32017)
downloaded
Chrome Cache Entry: 70
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 71
Web Open Font Format, CFF, length 8968, version 0.0
downloaded
Chrome Cache Entry: 72
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 73
Unicode text, UTF-8 text, with very long lines (65511), with no line terminators
downloaded
Chrome Cache Entry: 74
Web Open Font Format, TrueType, length 33108, version 0.0
downloaded
Chrome Cache Entry: 75
HTML document, Unicode text, UTF-8 text, with very long lines (43720)
downloaded
Chrome Cache Entry: 76
ASCII text
downloaded
Chrome Cache Entry: 77
Unicode text, UTF-8 text, with very long lines (65511), with no line terminators
dropped
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1984,i,5477112163227648564,8146938967037866638,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.klinch.ch//ABOUT"

URLs

Name
IP
Malicious
http://www.klinch.ch//ABOUT
http://www.openjs.com/scripts/events/keyboard_shortcuts/
unknown
https://static.cargo.site/assets/social/IconFont-Regular-0.9.3.woff2);unicode-range:U
unknown
https://files.cargocollective.com/c297512/SimplonMono-Bold.woff
unknown
https://static.cargo.site/assets/builds/apipackage.min.js?c=3680624028&
52.84.174.48
http://eepurl.com/hwnwsn
unknown
https://www.instagram.com/knoppkniel
unknown
https://files.cargocollective.com/c912954/UntitledSans-Light.woff
18.66.122.110
https://freight.cargo.site/t/original/i/bbdbde43edff00cef394f526e4aa52a330d7d2404d1ae9bf46248f4d6dee1b05/Knopp-Kniel_Logo_03_SM-Profilbild.ico
18.66.102.33
https://freight.cargo.site/t/original/i/20055066bc22ae8c9ddf389f98e498b6f63866d335dfd1f1893f966e864a
unknown
http://my.opera.com/emoller/blog/2011/12/20/requestanimationframe-for-smart-er-animating
unknown
http://underscorejs.org
unknown
https://freight.cargo.site/t/original/i/da6d5b8d17511eb5d599194215322537b98452d39d76b47a1bbf061f0618
unknown
http://paulirish.com/2011/requestanimationframe-for-smart-animating/
unknown
https://freight.cargo.site/t/original/i/dd0cc6c2ab69383867d91227ea3acf0917d9c5d23da222b2135d008e7f33
unknown
https://knoppkniel.com/rss
unknown
https://freight.cargo.site/t/original/i/543d9a88f49b0d812bb9e138ced98e8cf8cefdf36abc1141f4799fdbe409
unknown
https://freight.cargo.site/t/original/i/bbdbde43edff00cef394f526e4aa52a330d7d2404d1ae9bf46248f4d6dee
unknown
https://gist.github.com/paulirish/1579671
unknown
https://files.cargocollective.com/c912954/EXIL71.woff
18.66.122.110
https://knoppkniel.com/stylesheet?c=3680624028&1667768525
3.234.189.133
https://static.cargo.site/libs/cargo.apicore.package.jquery213.min.js?c=3680624028&
52.84.174.48
http://www.klinch.ch//ABOUT
149.126.4.35
https://www.klinch.ch//ABOUT
149.126.4.35
http://knoppkniel.com/DSGVO
unknown
https://freight.cargo.site
unknown
https://www.knoppkniel.com/ABOUT
3.234.189.133
https://freight.cargo.site/t/original/i/6200ec69e5d278afef87f9cd3151e27eea958866b49a16a6bf6e6b163004
unknown
https://freight.cargo.site/t/original/i/354f5586b6146286523be887547da905de1c9695bdd15bf53478e6a582eb
unknown
http://www.opensource.org/licenses/mit-license.php
unknown
https://freight.cargo.site/t/original/i/5d31c6c075589c770604d17b545a86ee038d1b0d53299d00ab637398c445
unknown
http://github.com/guillaumebort/jquery-ndd
unknown
http://handlebarsjs.com/
unknown
https://cargo.site
unknown
https://static.cargo.site/assets/social/IconFont-Regular-0.9.3.woff2);font-weight:240;unicode-range:
unknown
http://www.appelsiini.net/projects/viewport
unknown
http://backbonejs.org
unknown
https://freight.cargo.site/t/original/i/73b81bada1f27d7bfbacbb3570b708d207137130021bd2317d07e5ab46dd
unknown
https://github.com/wycats/handlebars.js/
unknown
https://goo.gl/maps/tn6t9m7ELUXwTHFS9
unknown
https://freight.cargo.site/t/original/i/1a12e97cfa51c903b49c450db373377d44a10cf3cf0d97f694008b817309
unknown
https://freight.cargo.site/t/original/i/3e0f31d2c2d18c0ba9c7ebde308e9d83e5e170856ff2ab3e6ecf1bf3c1ec
unknown
https://static.cargo.site/assets/images/select-arrows.svg)
unknown
https://freight.cargo.site/i/0635f5f8950bff425ad77f5eb1cd23570ab5977db715608bf7fc03657c8beaee/Knopp-
unknown
https://static.cargo.site/assets/social/IconFont-Regular-0.9.3.woff2
unknown
https://knoppkniel.com/ABOUT
https://freight.cargo.site/t/original/i/c02b9d461c3a1d7756aed90c539ab62f77464bd5cfa0b52008dc9573fc15
unknown
https://static.cargo.site
unknown
There are 37 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
d3fqahajli23b9.cloudfront.net
52.84.174.48
knoppkniel.com
3.234.189.133
klinch.ch
149.126.4.35
www.knoppkniel.com
3.234.189.133
d13notcisdyxg7.cloudfront.net
18.66.122.110
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
216.58.206.68
s-part-0039.t-0009.t-msedge.net
13.107.246.67
d3q7swlkq70mfj.cloudfront.net
18.66.102.33
fp2e7a.wpc.phicdn.net
192.229.221.95
freight.cargo.site
unknown
206.23.85.13.in-addr.arpa
unknown
www.klinch.ch
unknown
static.cargo.site
unknown
files.cargocollective.com
unknown
There are 6 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
18.66.102.33
d3q7swlkq70mfj.cloudfront.net
United States
18.66.122.110
d13notcisdyxg7.cloudfront.net
United States
192.168.2.7
unknown
unknown
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
216.58.206.68
www.google.com
United States
52.84.174.48
d3fqahajli23b9.cloudfront.net
United States
108.138.26.115
unknown
United States
239.255.255.250
unknown
Reserved
3.234.189.133
knoppkniel.com
United States
149.126.4.35
klinch.ch
Switzerland
172.217.18.100
unknown
United States
There are 2 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://knoppkniel.com/ABOUT