IOC Report
http://bitopluluk.com.tr/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:34:32 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:34:32 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 09:52:18 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:34:32 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:34:32 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 21:34:32 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 125
ASCII text
downloaded
Chrome Cache Entry: 126
HTML document, Unicode text, UTF-8 text, with very long lines (1788)
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (550)
downloaded
Chrome Cache Entry: 128
HTML document, Unicode text, UTF-8 text, with very long lines (1780)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2332 --field-trial-handle=2236,i,17664272902337260405,6308631327659289975,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bitopluluk.com.tr/"

URLs

Name
IP
Malicious
http://bitopluluk.com.tr/
http://schema.org/Person
unknown
https://bitopluluk.com.tr/arama/search?keywords=
unknown
https://bitopluluk.com.tr
unknown
https://www.tumblr.com/widgets/share/tool?canonicalUrl=
unknown
https://schema.org/BreadcrumbList
unknown
https://reddit.com/submit?url=
unknown
https://bitopluluk.com.tr/js/vendor/vendor-compiled.js?_v=c431ca1c
188.114.97.3
https://pinterest.com/pin/create/bookmarklet/?url=
unknown
https://schema.org
unknown
https://a.nel.cloudflare.com/report/v4?s=PUtDCfzjU8Lki1p0u5qfaiRMAiz4e7CcdFO8VBvrRyjSh9Ftef9m2NloWG0YymxgHHO1ecVEFmv5XAjSVcDUKwG0y1ku3bwaLLnSfAaEVT4PeTSeVx3%2BO0cgKm0Q8bYVm02ZXw%3D%3D
35.190.80.1
https://bitopluluk.com.tr/data/local/icons/regular.svg?v=1725621669
188.114.97.3
https://schema.org/ListItem
unknown
https://bitopluluk.com.tr/styles/default/xenforo/bell.png
unknown
https://www.google.com/chrome/
unknown
https://bitopluluk.com.tr/data/local/icons/brands.svg?v=1725621669
188.114.97.3
https://bitopluluk.com.tr/
188.114.97.3
https://bitopluluk.com.tr/css.php?css=public%3ACMTV_Badges.less%2Cpublic%3Ashare_controls.less%2Cpublic%3Astructured_list.less%2Cpublic%3Atb_hizli_arama.less%2Cpublic%3Aextra.less&s=2&l=3&d=1725621669&k=7409d0a36a9d6f25e5c0de7b64772a6707bce829
188.114.97.3
https://bitopluluk.com.tr/js/xf/preamble.min.js?_v=c431ca1c
188.114.97.3
https://bitopluluk.com.tr/login/
188.114.97.3
https://bitopluluk.com.tr/css.php?css=public%3ACMTV_Badges.less%2Cpublic%3Anode_list.less%2Cpublic%3Ashare_controls.less%2Cpublic%3Astructured_list.less%2Cpublic%3Atb_hizli_arama.less%2Cpublic%3Axgt_forum_istatistik.less%2Cpublic%3Aextra.less&s=2&l=3&d=1725621669&k=235a687d201a9ff7b2ab4529dfbb5a60551f9c88
188.114.97.3
https://www.linkedin.com/sharing/share-offsite/?url=
unknown
https://twitter.com/intent/tweet?url=
unknown
https://api.whatsapp.com/send?text=
unknown
https://bitopluluk.com.tr/data/assets/logo/_67b851cb-3943-49da-9a54-0221b673569f.jpeg
unknown
https://bitopluluk.com.tr/data/local/icons/solid.svg?v=1725621669
188.114.97.3
https://bitopluluk.com.tr/data/local/icons/light.svg?v=1725621669
188.114.97.3
https://bitopluluk.com.tr/css.php?css=public%3Anormalize.css%2Cpublic%3Afa.css%2Cpublic%3Avariations.less%2Cpublic%3Acore.less%2Cpublic%3Aapp.less&s=2&l=3&d=1725621669&k=8a38a786ef7f9637d045426c8453ece34dc5a218
188.114.97.3
https://xenforo.com
unknown
https://siberup.com.tr
unknown
https://bitopluluk.com.tr/js/xf/core-compiled.js?_v=c431ca1c
188.114.97.3
There are 20 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
bitopluluk.com.tr
188.114.97.3
www.google.com
172.217.18.4
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
172.217.18.4
www.google.com
United States
192.168.2.11
unknown
unknown
239.255.255.250
unknown
Reserved
188.114.97.3
bitopluluk.com.tr
European Union
188.114.96.3
unknown
European Union
35.190.80.1
a.nel.cloudflare.com
United States