IOC Report
http://www.riscository.com/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:12:20 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:12:20 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:00:51 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:12:20 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:12:20 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:12:20 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
PNG image data, 360 x 204, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 101
PNG image data, 322 x 52, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 102
PNG image data, 495 x 280, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (1443)
dropped
Chrome Cache Entry: 104
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 105
PNG image data, 132 x 163, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 106
PNG image data, 132 x 163, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 107
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 82", baseline, precision 8, 150x66, components 3
downloaded
Chrome Cache Entry: 108
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.30, datetime=2023:06:18 15:15:49], progressive, precision 8, 320x303, components 3
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 110
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 111
JPEG image data, JFIF standard 1.01, resolution (DPI), density 90x90, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.30, datetime=2022:12:03 12:45:31], progressive, precision 8, 120x119, components 3
downloaded
Chrome Cache Entry: 112
JPEG image data, JFIF standard 1.01, resolution (DPI), density 90x90, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.30, datetime=2022:12:03 12:45:31], progressive, precision 8, 120x119, components 3
dropped
Chrome Cache Entry: 113
ASCII text, with very long lines (15224)
downloaded
Chrome Cache Entry: 114
HTML document, ASCII text, with very long lines (2501), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 115
assembler source, ASCII text, with very long lines (1011), with CRLF line terminators
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 117
PNG image data, 120 x 162, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 118
ASCII text, with very long lines (2212), with no line terminators
downloaded
Chrome Cache Entry: 119
PNG image data, 120 x 188, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 120
PNG image data, 150 x 39, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (30837), with CRLF line terminators
downloaded
Chrome Cache Entry: 122
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 123
Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
downloaded
Chrome Cache Entry: 124
PNG image data, 120 x 180, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 125
PNG image data, 120 x 188, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (11126)
dropped
Chrome Cache Entry: 127
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 128
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (11126)
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (1443)
downloaded
Chrome Cache Entry: 131
PNG image data, 120 x 162, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 132
HTML document, ASCII text, with very long lines (2501), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 133
HTML document, ASCII text, with very long lines (5370), with CRLF line terminators
dropped
Chrome Cache Entry: 134
PNG image data, 120 x 180, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 135
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 136
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.28, datetime=2022:05:17 18:47:16], progressive, precision 8, 480x88, components 3
downloaded
Chrome Cache Entry: 137
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 82", baseline, precision 8, 150x66, components 3
dropped
Chrome Cache Entry: 138
PNG image data, 495 x 280, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 139
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.30, datetime=2023:06:18 15:15:49], progressive, precision 8, 320x303, components 3
downloaded
Chrome Cache Entry: 140
Web Open Font Format (Version 2), TrueType, length 18596, version 1.0
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 142
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 143
HTML document, Unicode text, UTF-8 text, with very long lines (2501), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 144
HTML document, ASCII text, with very long lines (5370), with CRLF line terminators
downloaded
Chrome Cache Entry: 145
PNG image data, 290 x 77, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 146
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 147
Web Open Font Format (Version 2), TrueType, length 18588, version 1.0
downloaded
Chrome Cache Entry: 148
PNG image data, 360 x 204, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 149
PNG image data, 150 x 39, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 150
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (15224)
dropped
Chrome Cache Entry: 152
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.10.28, datetime=2022:05:17 18:47:16], progressive, precision 8, 480x88, components 3
dropped
Chrome Cache Entry: 96
PNG image data, 322 x 52, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 97
Unicode text, UTF-8 text, with very long lines (33376)
downloaded
Chrome Cache Entry: 98
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 99
PNG image data, 290 x 77, 8-bit/color RGBA, non-interlaced
dropped
There are 54 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2076 --field-trial-handle=1972,i,1634422618731516257,16901956185502870521,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.riscository.com/"

URLs

Name
IP
Malicious
http://www.riscository.com/
https://www.riscository.com/2023/12/11/
unknown
http://fontawesome.io
unknown
https://www.blog2social.com
unknown
https://www.acmethemes.com/
unknown
https://www.riscository.com/2024/r-comp-oled-high-refresh-rate-monitors-london/
unknown
https://www.riscository.com/2024/08/01/
unknown
https://www.riscository.com/2024/preview-london-in-london-21st-october/
unknown
https://www.riscository.com/2024/riscosbits-at-the-london-show/
unknown
https://www.riscository.com/tag/credit-card/
unknown
https://www.riscository.com/category/user-groups/
unknown
https://www.mug.riscos.org/mega/
unknown
https://www.riscository.com/category/shows/
unknown
https://www.riscository.com/2024/risc-os-direct-5-31/
unknown
https://www.riscository.com/wp-content/uploads/2021/05/cropped-icon-192x192.png
unknown
https://www.riscository.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2
217.160.0.81
http://opensource.org/licenses/MIT)
unknown
https://www.riscository.com/tag/chris-hall/
unknown
https://www.riscository.com/tag/currency/
unknown
https://www.riscository.com/images/showbanners/generic/london.png
217.160.0.81
https://www.riscository.com/tag/api/
unknown
https://www.riscository.com/wp-content/themes/supermag/assets/library/html5shiv/html5shiv.min.js?ver
unknown
https://www.riscository.com/page/2/
unknown
https://www.riscository.com/tag/user-group/
unknown
https://www.riscository.com/wp-content/themes/supermag/assets/library/bxslider/css/jquery.bxslider.min.css?ver=4.2.5
217.160.0.81
https://www.riscository.com/wp-content/themes/supermag/assets/library/bxslider/js/jquery.bxslider.js
unknown
https://www.riscository.com/wp-content/uploads/2022/01/logo-rougol-150x66.jpg
217.160.0.81
https://www.riscository.com/2023/riscosbits-on-the-road-to-wrocc/
unknown
https://www.riscository.com/2024/dutch-added-macadd/
unknown
https://www.riscository.com/tag/networking/
unknown
https://twitter.com/RISCOSitory
unknown
http://www.gnu.org/licenses/gpl-2.0.html
unknown
https://www.riscository.com/wp-includes/css/dist/block-library/style.min.css?ver=5.8.10
217.160.0.81
https://www.riscository.com/wp-content/uploads/2022/03/featuredimage_currency-150x39.png
217.160.0.81
https://www.riscository.com/tag/advice/
unknown
https://www.riscository.com/tag/kevsoft/
unknown
https://www.riscository.com/wp-content/uploads/2021/05/cropped-icon-180x180.png
unknown
https://www.riscository.com/wp-content/themes/supermag/assets/library/bxslider/js/jquery.bxslider.js?ver=4.2.5.1.2
217.160.0.81
https://www.riscository.com/images/showbanners/generic/southwest.png
217.160.0.81
https://ko-fi.com/s/a24574d29d
unknown
https://www.riscoslondonshow.co.uk/
unknown
https://www.riscos-swshow.co.uk
unknown
https://www.riscository.com/wp-json/
unknown
https://www.riscository.com/wp-content/uploads/2021/05/cropped-icon-32x32.png
217.160.0.81
https://www.riscository.com/wp-content/themes/supermag/assets/library/bxslider/css/jquery.bxslider.m
unknown
https://www.riscository.com/tag/coding/
unknown
https://www.riscository.com/tag/london/
unknown
https://www.riscository.com/tutorials/
unknown
https://www.riscository.com/comments/feed/
unknown
https://www.riscository.com/tag/guidance/
unknown
https://www.riscository.com/wp-content/uploads/2022/03/featuredimage_currency.png
unknown
https://www.riscository.com/wp-content/uploads/2024/08/FeaturedImage_MACadd-495x280.png
217.160.0.81
https://www.riscository.com/search/feed/rss2/
unknown
https://www.riscository.com/tag/riscosbits/
unknown
https://www.riscository.com/wp-content/uploads/2021/05/cropped-icon-270x270.png
unknown
https://www.riscository.com/tag/debit-card/
unknown
https://www.riscository.com/wp-content/themes/supermag/assets/library/respond/respond.min.js?ver=1.1
unknown
http://gmpg.org/xfn/11
unknown
https://www.riscository.com/tag/london-show/
unknown
https://www.riscository.com/wp-content/themes/supermag/assets/library/Font-Awesome/css/font-awesome.
unknown
https://www.riscository.com/tag/tcp-ip-stack/
unknown
https://wordpress.org/
unknown
https://www.riscository.com/tag/iris/
unknown
https://www.riscository.com/wp-content/themes/supermag/assets/library/Font-Awesome/css/font-awesome.min.css?ver=4.7.0
217.160.0.81
https://www.riscository.com/wp-content/themes/supermag/assets/library/theia-sticky-sidebar/theia-sti
unknown
https://www.riscository.com/2024/risc-os-dev-tcp-ip-stack-portals/
https://www.riscository.com/2023/httpserv-0-12-available-again/
unknown
https://www.riscository.com/tag/programming/
unknown
https://www.riscository.com/wp-content/themes/supermag/style.css?ver=1.4.9
217.160.0.81
https://www.riscository.com/wp-content/uploads/2023/06/logo-wrocc.jpeg
217.160.0.81
https://www.bigbenclub.nl/bbc/rox/que_uk.html
unknown
https://www.riscository.com/tag/help/
unknown
https://www.riscository.com/author/vinceh/
unknown
https://www.riscository.com/wp-content/uploads/2022/01/logo-rougol.jpg
unknown
https://www.riscository.com/2024/new-release-kevsoft-cardinfo/
unknown
http://www.gimp.org/xmp/
unknown
https://www.riscository.com/2024/historical-data-extended-currency/
unknown
https://www.riscository.com/category/software/
unknown
https://www.riscository.com/2024/developers-fireside-chat-12th-october/
unknown
https://www.riscository.com/2024/fast-update-2024-2/
unknown
https://www.riscository.com/wp-content/uploads/2023/04/cropped-RISCOSitory-Main-2023-04-30.png
217.160.0.81
https://www.riscository.com/category/programming/
unknown
https://www.riscoslondonshow.co.uk
unknown
https://www.riscository.com/wp-content/uploads/2022/01/SRScollectionbanner-1.png
217.160.0.81
https://www.riscository.com/tag/risc-os-developments/
unknown
https://www.riscository.com/2018/prophet-visiting-london-17th-september/
unknown
https://www.riscository.com/tag/web-browser/
unknown
https://www.riscository.com/wp-includes/wlwmanifest.xml
unknown
https://www.riscository.com/wp-includes/js/wp-embed.min.js?ver=5.8.10
217.160.0.81
https://www.riscository.com/tag/monitors/
unknown
https://www.riscository.com/wp-content/themes/supermag/assets/library/Font-Awesome/fonts/fontawesome-webfont.woff2?v=4.7.0
217.160.0.81
https://www.riscository.com/tag/show/
unknown
https://www.riscository.com/mailing-lists/
unknown
https://www.riscository.com/calendar/
unknown
https://www.riscository.com/wp-content/themes/supermag/acmethemes/gutenberg/gutenberg-front.css?ver=1.0
217.160.0.81
https://www.riscository.com/wp-json/wp/v2/posts/10423
unknown
https://www.riscository.com/xmlrpc.php
unknown
https://www.riscository.com/tag/r-comp/
unknown
https://www.riscository.com/wp-content/themes/supermag/acmethemes/gutenberg/gutenberg-front.css?ver=
unknown
http://www.riscository.com/
unknown
https://www.riscository.com/category/announcements/
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
www.riscository.com
217.160.0.81
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
216.58.206.36
s.w.org
192.0.77.48
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
192.168.2.8
unknown
unknown
217.160.0.81
www.riscository.com
Germany
216.58.206.36
www.google.com
United States

DOM / HTML

URL
Malicious
https://www.riscository.com/
https://www.riscository.com/
https://www.riscository.com/2024/risc-os-dev-tcp-ip-stack-portals/
https://www.riscository.com/?s=
https://www.riscository.com/?s=