IOC Report
https://eshailor56718.wixsite.com/my-site

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 36
JSON data
downloaded
Chrome Cache Entry: 37
JSON data
dropped
Chrome Cache Entry: 38
JSON data
downloaded
Chrome Cache Entry: 39
JSON data
downloaded
Chrome Cache Entry: 40
JSON data
downloaded
Chrome Cache Entry: 41
Web Open Font Format (Version 2), TrueType, length 17176, version 1.0
downloaded
Chrome Cache Entry: 42
Web Open Font Format (Version 2), TrueType, length 36712, version 1.0
downloaded
Chrome Cache Entry: 43
Web Open Font Format, TrueType, length 41912, version 1.0
downloaded
Chrome Cache Entry: 44
JSON data
downloaded
Chrome Cache Entry: 45
Web Open Font Format (Version 2), TrueType, length 17216, version 1.0
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=2220,i,5598424088950673261,3096649071505494611,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eshailor56718.wixsite.com/my-site"

URLs

Name
IP
Malicious
https://eshailor56718.wixsite.com/my-site
malicious
https://eshailor56718.wixsite.com/my-site
34.144.206.118
malicious
https://eshailor56718.wixsite.com/my-site/_api/v1/access-tokens
34.144.206.118
malicious
https://panorama.wixapps.net/api/v1/bulklog
34.149.206.255
https://frog.wix.com/bolt-performance?src=72&evid=21&appName=thunderbolt&is_rollout=0&is_sav_rollout=0&is_dac_rollout=0&dc=42&microPop=42_g&is_cached=true&msid=fffd47dd-76a9-4b3c-a5af-a3b4d3f48470&session_id=b36a831e-f8a6-4ff9-81cc-be6583aad70d&ish=false&isb=false&vsi=ff76c2aa-430f-485d-9b4e-aab25dbd48e0&caching=hit,hit&pv=visible&pn=1&v=1.14640.0&url=https%3A%2F%2Feshailor56718.wixsite.com%2Fmy-site&st=2&ts=306&tsn=992&platformOnSite=true
3.212.27.91
https://static.parastorage.com/services/third-party/fonts/Helvetica/Fonts/60be5c39-863e-40cb-9434-6ebafb62ab2b.woff
34.49.229.81
https://static.parastorage.com/fonts/v2/2af1bf48-e783-4da8-9fa0-599dde29f2d5/v1/helvetica-w01-roman.woff2
34.49.229.81
https://static.parastorage.com/fonts/v2/af36905f-3c92-4ef9-b0c1-f91432f16ac1/v1/avenir-lt-w01_35-light1475496.woff2
34.49.229.81
https://static.parastorage.com/fonts/v2/74290729-59ae-4129-87d0-2eec3974dce1/v1/avenir-lt-w01_85-heavy1475544.woff2
34.49.229.81

Domains

Name
IP
Malicious
glb-editor.wix.com
34.149.206.255
username-ccm-206-118.wix.com
34.144.206.118
td-static-34-49-229-81.parastorage.com
34.49.229.81
d1cq301dpr7fww.cloudfront.net
99.86.4.125
www.google.com
142.250.185.132
bi-flogger-alb-ext-343643057.us-east-1.elb.amazonaws.com
3.212.27.91
fp2e7a.wpc.phicdn.net
192.229.221.95
static.wixstatic.com
unknown
siteassets.parastorage.com
unknown
frog.wix.com
unknown
eshailor56718.wixsite.com
unknown
panorama.wixapps.net
unknown
static.parastorage.com
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
3.212.27.91
bi-flogger-alb-ext-343643057.us-east-1.elb.amazonaws.com
United States
239.255.255.250
unknown
Reserved
34.49.229.81
td-static-34-49-229-81.parastorage.com
United States
142.250.185.132
www.google.com
United States
34.144.206.118
username-ccm-206-118.wix.com
United States
192.168.2.4
unknown
unknown
99.86.4.125
d1cq301dpr7fww.cloudfront.net
United States
34.149.206.255
glb-editor.wix.com
United States