IOC Report
https://productlab.groupe-rocher.com/Advitium/login.asp

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 131
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 133
PNG image data, 7 x 7, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 134
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 135
PNG image data, 304 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 136
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 137
C source, ASCII text, with very long lines (65103)
downloaded
Chrome Cache Entry: 138
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 139
PNG image data, 7 x 7, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 140
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 141
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 142
GIF image data, version 89a, 44 x 44
downloaded
Chrome Cache Entry: 143
Unicode text, UTF-8 (with BOM) text, with very long lines (563), with CRLF line terminators
dropped
Chrome Cache Entry: 144
JSON data
downloaded
Chrome Cache Entry: 145
JSON data
downloaded
Chrome Cache Entry: 146
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 147
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 148
Unicode text, UTF-8 (with BOM) text, with very long lines (563), with CRLF line terminators
downloaded
Chrome Cache Entry: 149
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 150
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 151
PNG image data, 304 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 152
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1191x580, components 3
dropped
Chrome Cache Entry: 153
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 154
JSON data
dropped
Chrome Cache Entry: 155
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (500)
downloaded
Chrome Cache Entry: 157
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 158
GIF image data, version 89a, 44 x 44
dropped
Chrome Cache Entry: 159
HTML document, Unicode text, UTF-8 text, with very long lines (32769)
downloaded
Chrome Cache Entry: 160
JSON data
dropped
Chrome Cache Entry: 161
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 162
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 163
HTML document, Unicode text, UTF-8 text, with very long lines (32769)
dropped
Chrome Cache Entry: 164
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 165
Unicode text, UTF-8 (with BOM) text, with very long lines (347), with CRLF line terminators
downloaded
Chrome Cache Entry: 166
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 167
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 168
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 169
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 170
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 171
Unicode text, UTF-8 (with BOM) text, with very long lines (347), with CRLF line terminators
dropped
Chrome Cache Entry: 172
C source, ASCII text, with very long lines (65103)
dropped
Chrome Cache Entry: 173
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 174
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1191x580, components 3
downloaded
Chrome Cache Entry: 175
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 176
ASCII text, with CRLF line terminators
downloaded
There are 37 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2024,i,18257968916526087547,7377922921570812397,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://productlab.groupe-rocher.com/Advitium/login.asp"

URLs

Name
IP
Malicious
https://productlab.groupe-rocher.com/Advitium/login.asp
malicious
https://productlab.groupe-rocher.com/Advitium/login.asp
malicious
http://jqueryui.com/themeroller/
unknown
http://docs.jquery.com/UI/Progressbar#theming
unknown
http://docs.jquery.com/UI/Slider#theming
unknown
http://jquery.org/license
unknown
http://bugs.jqueryui.com/ticket/7233
unknown
http://docs.jquery.com/UI/Menu#theming
unknown
http://docs.jquery.com/UI/Tabs#theming
unknown
http://docs.jquery.com/UI
unknown
http://docs.jquery.com/UI/Dialog#theming
unknown
http://docs.jquery.com/UI/Theming/API
unknown
http://schemas.xmlsoap.org/soap/envelope/
unknown
http://jqueryui.com/about)
unknown
http://docs.jquery.com/UI/Accordion#theming
unknown
http://docs.jquery.com/UI/Button#theming
unknown
http://docs.jquery.com/UI/Autocomplete#theming
unknown
http://docs.jquery.com/UI/Datepicker#theming
unknown
http://docs.jquery.com/UI/Resizable#theming
unknown
http://docs.jquery.com/UI/Selectable#theming
unknown
There are 9 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
productlab.groupe-rocher.com
unknown
malicious
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
216.58.206.36
fp2e7a.wpc.phicdn.net
192.229.221.95
s.go-mpulse.net
unknown
baxhwiiccjae2zymyktq-f-8c5a7db05-clientnsv4-s.akamaihd.net
unknown
684dd311.akstat.io
unknown
c.go-mpulse.net
unknown
baxhwiiccjae2zymykra-f-88643dc9c-clientnsv4-s.akamaihd.net
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
216.58.206.36
www.google.com
United States
239.255.255.250
unknown
Reserved

DOM / HTML

URL
Malicious
https://productlab.groupe-rocher.com/Advitium/login.asp
malicious
https://productlab.groupe-rocher.com/Advitium/login.asp
https://productlab.groupe-rocher.com/Advitium/login.asp
https://productlab.groupe-rocher.com/Advitium/login.asp
https://productlab.groupe-rocher.com/Advitium/login.asp
https://productlab.groupe-rocher.com/Advitium/login.asp