IOC Report
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index.html

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text
downloaded
Chrome Cache Entry: 101
PNG image data, 187 x 188, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (10469)
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (60169)
downloaded
Chrome Cache Entry: 104
PNG image data, 225 x 225, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (32030)
dropped
Chrome Cache Entry: 106
ASCII text, with very long lines (32012)
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (48664)
downloaded
Chrome Cache Entry: 108
PNG image data, 187 x 188, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 109
PNG image data, 253 x 218, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 110
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=6], baseline, precision 8, 946x481, components 3
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 71
PNG image data, 190 x 187, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 72
PNG image data, 460 x 360, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 73
PNG image data, 26 x 26, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 74
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=6], baseline, precision 8, 946x481, components 3
downloaded
Chrome Cache Entry: 75
ASCII text, with very long lines (32030)
downloaded
Chrome Cache Entry: 76
ASCII text, with very long lines (32012)
dropped
Chrome Cache Entry: 77
ASCII text, with very long lines (19015)
downloaded
Chrome Cache Entry: 78
HTML document, ASCII text, with very long lines (37551), with CRLF line terminators
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (26519)
dropped
Chrome Cache Entry: 80
PNG image data, 151 x 151, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 81
PNG image data, 26 x 26, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 82
PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 83
PNG image data, 190 x 187, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (26519)
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (60169)
dropped
Chrome Cache Entry: 86
ASCII text, with very long lines (10469)
dropped
Chrome Cache Entry: 87
ASCII text, with very long lines (32065)
dropped
Chrome Cache Entry: 88
PNG image data, 225 x 225, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 89
PNG image data, 151 x 151, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 90
ASCII text, with very long lines (48664)
dropped
Chrome Cache Entry: 91
ASCII text, with very long lines (65325)
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (19015)
dropped
Chrome Cache Entry: 93
PNG image data, 1280 x 1280, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 94
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=3, software=Google], baseline, precision 8, 670x335, components 3
downloaded
Chrome Cache Entry: 95
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=3, software=Google], baseline, precision 8, 670x335, components 3
dropped
Chrome Cache Entry: 96
PNG image data, 253 x 218, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 97
PNG image data, 460 x 360, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 98
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 99
ASCII text
downloaded
There are 32 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1948,i,14027463791644869405,591485059889879011,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index.html"

URLs

Name
IP
Malicious
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index.html
malicious
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index.html
malicious
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/hover.css
172.66.0.235
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/other1.png
172.66.0.235
http://ianlunn.github.io/Hover/)
unknown
https://1.bp.blogspot.com/-zndug-qdlts/YAoGcDiqSaI/AAAAAAAABsc/-5XaCJ_GBZM4-ChlihkuE3uATfPRx6NkQCLcBGAsYHQ/s1600/onedriveside.jpg
172.217.16.193
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/office3651.png
172.66.0.235
https://1.bp.blogspot.com/-kmByNX6oGz0/YAoK1C_CE6I/AAAAAAAABtg/tgOfU7JjXoEeVFNCJl0Qi1STBo0v2DldgCLcB
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/jquery-3.js
172.66.0.235
https://1.bp.blogspot.com/-DyFOm03SivQ/YFSrU_W607I/AAAAAAAAB2c/wqA0ubeOldExnnOxvIvyjKylznQK7D6iACLcB
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/jquery.js
172.66.0.235
https://ka-f.fontawesome.com
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/outlook1.png
172.66.0.235
https://1.bp.blogspot.com/-L2YD11QImHw/YAoKbqqeBnI/AAAAAAAABtM/q_dxMeucmZ4r1aV5x5iOajbhWu1WghKmwCLcB
unknown
https://1.bp.blogspot.com/-3zAqfSS7OCU/YAoKtVY811I/AAAAAAAABtY/r-7YbJZWJMINW8Jhcj1-_jOEYomopVtfwCLcB
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/popper.js
172.66.0.235
https://processsolutions.net/run/indigo.php
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/585b051251.js
172.66.0.235
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/gmail.png
172.66.0.235
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/bootstrap.js
172.66.0.235
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/onedrive.png
172.66.0.235
https://1.bp.blogspot.com/-wNI7T63umgw/YAoKM0qDvfI/AAAAAAAABtI/Vm3XOteB6BMnfLeuPPn8unLiAj7MoGtmwCLcB
unknown
https://code.jquery.com/jquery-3.3.1.js
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/yahoo1.png
172.66.0.235
https://fontawesome.com/license/free
unknown
https://fontawesome.com
unknown
https://1.bp.blogspot.com/-bb3Yq66sQg8/YAoKigrMVLI/AAAAAAAABtQ/b4UwsA3oU3k2lgrN7W8xa_5-GXs_2-lWwCLcB
unknown
https://kit.fontawesome.com
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/bootstrap.css
172.66.0.235
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/infoondrive.jpg
172.66.0.235
https://getbootstrap.com)
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/jquery-3_002.js
172.66.0.235
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/aol1.png
172.66.0.235
http://ianlunn.co.uk/
unknown
https://1.bp.blogspot.com/-oYJVgO9SptU/YAoJysgR4tI/AAAAAAAABs4/cArQ36GfeeY7YxsPcOUFCE__hIoIdUNagCLcB
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://1.bp.blogspot.com/-zndug-qdlts/YAoGcDiqSaI/AAAAAAAABsc/-5XaCJ_GBZM4-ChlihkuE3uATfPRx6NkQCLcB
unknown
https://github.com/IanLunn/Hover
unknown
https://1.bp.blogspot.com/-DyFOm03SivQ/YFSrU_W607I/AAAAAAAAB2c/wqA0ubeOldExnnOxvIvyjKylznQK7D6iACLcBGAsYHQ/s1600/download.png
172.217.16.193
http://opensource.org/licenses/MIT).
unknown
https://1drv.ms/b/s
unknown
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index_files/css.css
172.66.0.235
There are 32 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
pub-6e60812ea6034887a73a58b17a92a80f.r2.dev
172.66.0.235
malicious
bg.microsoft.map.fastly.net
199.232.210.172
photos-ugc.l.googleusercontent.com
172.217.16.193
www.google.com
142.250.181.228
fp2e7a.wpc.phicdn.net
192.229.221.95
ka-f.fontawesome.com
unknown
1.bp.blogspot.com
unknown

IPs

IP
Domain
Country
Malicious
172.66.0.235
pub-6e60812ea6034887a73a58b17a92a80f.r2.dev
United States
malicious
162.159.140.237
unknown
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.181.228
www.google.com
United States
172.217.16.193
photos-ugc.l.googleusercontent.com
United States
142.250.186.65
unknown
United States

DOM / HTML

URL
Malicious
https://pub-6e60812ea6034887a73a58b17a92a80f.r2.dev/index.html
malicious