IOC Report
https://tarah.com.sa/reee

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 43
ASCII text, with very long lines (8066), with no line terminators
downloaded
Chrome Cache Entry: 44
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 45
ASCII text, with very long lines (8097), with no line terminators
dropped
Chrome Cache Entry: 46
HTML document, ASCII text, with very long lines (1195), with no line terminators
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=2000,i,3163096309959427379,10217832694736686010,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://tarah.com.sa/reee"

URLs

Name
IP
Malicious
https://tarah.com.sa/reee
malicious
https://tarah.com.sa/reee
23.235.208.180
malicious
https://tarah.com.sa/reee/
23.235.208.180
malicious
https://supportcustomers.info/favicon.ico
188.114.97.3
https://supportcustomers.info/cdn-cgi/challenge-platform/h/g/scripts/jsd/f2bbd6738e15/main.js?
188.114.97.3
https://supportcustomers.info/cdn-cgi/challenge-platform/h/g/jsd/r/8d7895700cec6c4a
188.114.97.3
https://a.nel.cloudflare.com/report/v4?s=kD%2Fxx9JAtQPsxy5s%2Ftd5ZUqmUmhqZQB2wNEsQXB6JQ1IQ92yekDeEJvANIBUuFqub2B0U0aPfJSkMvF%2FLqGuRSTPHckTyTT2v6cGkDWKNRXCDa4WJmHi5LP3Krw4LR%2FjfkJk4vqaY64%3D
35.190.80.1
https://a.nel.cloudflare.com/report/v4?s=iqgPPrGG%2FAOQoJuaxKoVtrMGZ5OkC5x4VDm1vQRPIZ8GX5ReDl9a7u0QK4lSQSSWgWig0k7f9UdUFf6YT3ABMTbbNuL1DgjHwvLYnp3eDVwq%2FvneF%2BgcQj1oTZMD%2FW9vTWA%2BBAlLdI0%3D
35.190.80.1
https://supportcustomers.info/DHL/
https://supportcustomers.info/cdn-cgi/challenge-platform/scripts/jsd/main.js
188.114.97.3
https://a.nel.cloudflare.com/report/v4?s=mItf1%2BVzKnb487NAyPwmA3vivN%2F9tb38LOHhexystavbwO3S%2B29qrcPTFs6IOJkb7Xj%2FgwIpYZoYTNhKbzqRQ%2BFfdSRNvqwHaeDVkxvXh4zOPlNNEAsCmqj0C3lCuTNqw3ccOju8pI0%3D
35.190.80.1

Domains

Name
IP
Malicious
supportcustomers.info
188.114.97.3
a.nel.cloudflare.com
35.190.80.1
s-part-0017.t-0009.t-msedge.net
13.107.246.45
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
www.google.com
216.58.212.132
tarah.com.sa
23.235.208.180
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
23.235.208.180
tarah.com.sa
United States
216.58.212.132
www.google.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
188.114.97.3
supportcustomers.info
European Union
192.168.2.13
unknown
unknown
188.114.96.3
unknown
European Union
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://supportcustomers.info/DHL/
https://supportcustomers.info/DHL/