IOC Report
https://mail.oilreviewmiddleeast.com/link.php?M=532162&N=675&L=522&F=H

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:32:17 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:32:17 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:56:51 2023, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:32:17 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:32:17 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:32:17 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6820_224039311\LICENSE
ASCII text
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6820_224039311\_metadata\verified_contents.json
JSON data
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6820_224039311\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6820_224039311\manifest.json
JSON data
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6820_224039311\sets.json
JSON data
dropped
Chrome Cache Entry: 174
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 175
RIFF (little-endian) data, Web/P image, VP8 encoding, 480x200, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 176
GIF image data, version 89a, 728 x 90
dropped
Chrome Cache Entry: 177
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 178
gzip compressed data, from Unix, original size modulo 2^32 18838
dropped
Chrome Cache Entry: 179
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 180
PNG image data, 61 x 59, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 181
gzip compressed data, from Unix, original size modulo 2^32 26167
downloaded
Chrome Cache Entry: 182
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 183
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (1601)
downloaded
Chrome Cache Entry: 185
gzip compressed data, from Unix, original size modulo 2^32 149352
downloaded
Chrome Cache Entry: 186
gzip compressed data, from Unix, original size modulo 2^32 20635
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (1468), with no line terminators
dropped
Chrome Cache Entry: 188
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x90, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 189
RIFF (little-endian) data, Web/P image, VP8 encoding, 787x399, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 190
ASCII text, with very long lines (1108), with no line terminators
dropped
Chrome Cache Entry: 191
gzip compressed data, from Unix, original size modulo 2^32 4377
dropped
Chrome Cache Entry: 192
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 193
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 194
PNG image data, 57 x 59, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 195
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (7726)
dropped
Chrome Cache Entry: 197
RIFF (little-endian) data, Web/P image, VP8 encoding, 480x200, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 198
gzip compressed data, from Unix, original size modulo 2^32 31181
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (429), with no line terminators
downloaded
Chrome Cache Entry: 200
GIF image data, version 89a, 728 x 90
downloaded
Chrome Cache Entry: 201
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 202
PNG image data, 61 x 59, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 203
gzip compressed data, from Unix, original size modulo 2^32 4377
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (435), with no line terminators
dropped
Chrome Cache Entry: 205
gzip compressed data, from Unix, original size modulo 2^32 211964
downloaded
Chrome Cache Entry: 206
ASCII text, with very long lines (7726)
downloaded
Chrome Cache Entry: 207
PNG image data, 53 x 59, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 208
PNG image data, 310 x 120, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 209
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 210
gzip compressed data, max compression, truncated
downloaded
Chrome Cache Entry: 211
GIF image data, version 89a, 728 x 90
downloaded
Chrome Cache Entry: 212
ASCII text
downloaded
Chrome Cache Entry: 213
ASCII text, with very long lines (1468), with no line terminators
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (701)
dropped
Chrome Cache Entry: 215
gzip compressed data, from Unix, original size modulo 2^32 1355
downloaded
Chrome Cache Entry: 216
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x90, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 217
gzip compressed data, from Unix, original size modulo 2^32 7480
dropped
Chrome Cache Entry: 218
ASCII text
downloaded
Chrome Cache Entry: 219
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 220
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x120, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 221
Web Open Font Format (Version 2), TrueType, length 51404, version 1.0
downloaded
Chrome Cache Entry: 222
PNG image data, 62 x 59, 8-bit/color RGBA, interlaced
dropped
Chrome Cache Entry: 223
ASCII text, with very long lines (480)
downloaded
Chrome Cache Entry: 224
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 225
gzip compressed data, max compression, original size modulo 2^32 40
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (18272)
dropped
Chrome Cache Entry: 227
ASCII text, with very long lines (435), with no line terminators
downloaded
Chrome Cache Entry: 228
gzip compressed data, from Unix, original size modulo 2^32 81039
dropped
Chrome Cache Entry: 229
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 230
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 231
gzip compressed data, from Unix, original size modulo 2^32 81039
downloaded
Chrome Cache Entry: 232
Web Open Font Format (Version 2), TrueType, length 34328, version 1.0
downloaded
Chrome Cache Entry: 233
gzip compressed data, from Unix, original size modulo 2^32 1925
downloaded
Chrome Cache Entry: 234
GIF image data, version 89a, 728 x 90
dropped
Chrome Cache Entry: 235
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x600, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 236
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x600, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 237
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, progressive, precision 8, 300x600, components 3
downloaded
Chrome Cache Entry: 238
GIF image data, version 89a, 728 x 120
dropped
Chrome Cache Entry: 239
ASCII text, with very long lines (701)
downloaded
Chrome Cache Entry: 240
ASCII text
downloaded
Chrome Cache Entry: 241
gzip compressed data, from Unix, original size modulo 2^32 11314
dropped
Chrome Cache Entry: 242
ASCII text
downloaded
Chrome Cache Entry: 243
ASCII text, with very long lines (3152), with no line terminators
downloaded
Chrome Cache Entry: 244
GIF image data, version 89a, 728 x 120
downloaded
Chrome Cache Entry: 245
gzip compressed data, from Unix, original size modulo 2^32 20635
downloaded
Chrome Cache Entry: 246
gzip compressed data, from Unix, original size modulo 2^32 71417
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (18272)
downloaded
Chrome Cache Entry: 248
PNG image data, 61 x 59, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 249
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x120, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 250
gzip compressed data, from Unix, original size modulo 2^32 87533
dropped
Chrome Cache Entry: 251
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x90, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 252
gzip compressed data, from Unix, original size modulo 2^32 87533
downloaded
Chrome Cache Entry: 253
gzip compressed data, from Unix, original size modulo 2^32 18838
downloaded
Chrome Cache Entry: 254
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 255
PNG image data, 53 x 59, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 256
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, progressive, precision 8, 300x600, components 3
dropped
Chrome Cache Entry: 257
HTML document, ASCII text, with very long lines (624)
downloaded
Chrome Cache Entry: 258
PNG image data, 62 x 59, 8-bit/color RGBA, interlaced
downloaded
Chrome Cache Entry: 259
gzip compressed data, from Unix, original size modulo 2^32 26167
dropped
Chrome Cache Entry: 260
ASCII text, with very long lines (701)
downloaded
Chrome Cache Entry: 261
gzip compressed data, from Unix, original size modulo 2^32 11314
downloaded
Chrome Cache Entry: 262
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x90, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 263
data
dropped
Chrome Cache Entry: 264
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x120, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 265
PNG image data, 61 x 59, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 266
RIFF (little-endian) data, Web/P image, VP8 encoding, 728x120, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 267
PNG image data, 57 x 59, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 268
gzip compressed data, from Unix, original size modulo 2^32 77160
downloaded
Chrome Cache Entry: 269
gzip compressed data, from Unix, original size modulo 2^32 1355
dropped
Chrome Cache Entry: 270
RIFF (little-endian) data, Web/P image, VP8 encoding, 787x399, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 271
ASCII text, with very long lines (1108), with no line terminators
downloaded
Chrome Cache Entry: 272
PNG image data, 310 x 120, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 273
gzip compressed data, from Unix, original size modulo 2^32 7480
downloaded
There are 102 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1908,i,16621473218498686646,16063989223168888059,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://mail.oilreviewmiddleeast.com/link.php?M=532162&N=675&L=522&F=H"

URLs

Name
IP
Malicious
https://mail.oilreviewmiddleeast.com/link.php?M=532162&N=675&L=522&F=H
https://stats.g.doubleclick.net/g/collect
unknown
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://wieistmeineip.de
unknown
https://mercadoshops.com.co
unknown
https://oilreviewmiddleeast.com/media/vendor/bootstrap/js/popper.min.js?5.3.0
52.222.236.123
https://gliadomain.com
unknown
https://poalim.xyz
unknown
https://mercadolivre.com
unknown
https://oilreviewmiddleeast.com/media/vendor/bootstrap/js/dom.min.js?5.3.0
52.222.236.123
https://reshim.org
unknown
https://ampcid.google.com/v1/publisher:getClientId
unknown
https://nourishingpursuits.com
unknown
https://medonet.pl
unknown
https://unotv.com
unknown
https://mercadoshops.com.br
unknown
https://joyreactor.cc
unknown
https://zdrowietvn.pl
unknown
https://johndeere.com
unknown
https://songstats.com
unknown
https://baomoi.com
unknown
https://supereva.it
unknown
https://elfinancierocr.com
unknown
https://bolasport.com
unknown
https://rws1nvtvt.com
unknown
https://oilreviewmiddleeast.com/templates/ja_teline_v/fonts/font-awesome/fonts/fontawesome-webfont.woff2?v=4.7.0
52.222.236.123
https://desimartini.com
unknown
https://github.com/matomo-org/matomo/blob/master/js/piwik.js
unknown
https://hearty.app
unknown
https://support.google.com/recaptcha/#6175971
unknown
https://hearty.gift
unknown
https://mercadoshops.com
unknown
https://heartymail.com
unknown
https://nlc.hu
unknown
https://p106.net
unknown
https://pagesense-collect.zoho.eu/pslog.gif?type=2
185.230.212.19
https://stats.g.doubleclick.net/j/collect
unknown
https://radio2.be
unknown
https://finn.no
unknown
https://hc1.com
unknown
https://kompas.tv
unknown
https://mystudentdashboard.com
unknown
https://songshare.com
unknown
https://smaker.pl
unknown
https://support.google.com/recaptcha
unknown
https://mercadopago.com.mx
unknown
https://p24.hu
unknown
https://talkdeskqaid.com
unknown
https://oilreviewmiddleeast.com/media/com_finder/js/finder.min.js?a2c3894d062787a266d59d457ffba5481b639f64
52.222.236.123
https://24.hu
unknown
https://mercadopago.com.pe
unknown
https://cardsayings.net
unknown
https://www.gstatic.c..?/recaptcha/releases/-ZG7BC9TxCVEbzIO2m429usb/recaptcha__.
unknown
https://oilreviewmiddleeast.com/banners/_images/ORME_HB_Oman_010724_310724.gif
52.222.236.123
https://text.com
unknown
https://oilreviewmiddleeast.com/images/ochri/de23667cea1252d10fde50fa0ecbdff3-728px.webp
52.222.236.123
https://mightytext.net
unknown
https://mail.oilreviewmiddleeast.com/link.php?M=532162&N=675&L=522&F=H
149.106.168.53
https://pudelek.pl
unknown
https://hazipatika.com
unknown
https://joyreactor.com
unknown
https://cookreactor.com
unknown
https://wildixin.com
unknown
https://eworkbookcloud.com
unknown
https://cognitiveai.ru
unknown
https://nacion.com
unknown
https://chennien.com
unknown
https://drimer.travel
unknown
https://deccoria.pl
unknown
https://oilreviewmiddleeast.com/t3-assets/css/css-eceeb-78747.css
52.222.236.123
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://mercadopago.cl
unknown
https://talkdeskstgid.com
unknown
https://naukri.com
unknown
https://interia.pl
unknown
https://bonvivir.com
unknown
https://carcostadvisor.be
unknown
https://salemovetravel.com
unknown
https://sapo.io
unknown
https://wpext.pl
unknown
https://welt.de
unknown
https://www.zoho.com/sites/cookie-policy/
unknown
https://poalim.site
unknown
https://drimer.io
unknown
https://infoedgeindia.com
unknown
https://blackrockadvisorelite.it
unknown
https://cognitive-ai.ru
unknown
https://oilreviewmiddleeast.com/templates/ja_teline_v/favicon.ico
52.222.236.123
https://cafemedia.com
unknown
https://graziadaily.co.uk
unknown
https://thirdspace.org.au
unknown
https://mercadoshops.com.ar
unknown
https://smpn106jkt.sch.id
unknown
https://oilreviewmiddleeast.com/banners/_images/twit_icon.png
52.222.236.123
https://elpais.uy
unknown
https://landyrev.com
unknown
https://www.google.com/js/bg/Cyqba_K0pUDdT5_AhrcTxS5-b1C3jUsFpG6edXmCObU.js
142.250.184.196
https://oilreviewmiddleeast.com/media/vendor/bootstrap/js/popover.min.js?5.3.2
52.222.236.123
https://the42.ie
unknown
https://static.addtoany.com/menu/modules/core.m4v434v2.js
104.22.71.197
https://ws.alaincharles.com/matomo.js
34.251.236.241
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
oilreviewmiddleeast.com
52.222.236.123
d1da88slxvkrhp.cloudfront.net
18.66.102.19
static.addtoany.com
104.22.71.197
mail.oilreviewmiddleeast.com
149.106.168.53
www.google.com
142.250.185.132
h2-stratus.zohocdn.com
89.36.170.147
ws.alaincharles.com
34.251.236.241
l7-26-c2.zoho.eu
185.230.212.19
fp2e7a.wpc.phicdn.net
192.229.221.95
cdn-eu.pagesense.io
unknown
static.zohocdn.com
unknown
pagesense-collect.zoho.eu
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
52.222.236.129
unknown
United States
18.66.102.19
d1da88slxvkrhp.cloudfront.net
United States
192.168.2.9
unknown
unknown
185.230.212.19
l7-26-c2.zoho.eu
Netherlands
172.67.39.148
unknown
United States
104.22.71.197
static.addtoany.com
United States
142.250.184.228
unknown
United States
52.222.236.123
oilreviewmiddleeast.com
United States
34.251.236.241
ws.alaincharles.com
United States
149.106.168.53
mail.oilreviewmiddleeast.com
United States
18.66.102.65
unknown
United States
142.250.184.196
unknown
United States
142.250.185.132
www.google.com
United States
89.36.170.147
h2-stratus.zohocdn.com
Switzerland
239.255.255.250
unknown
Reserved
142.250.186.100
unknown
United States
104.22.70.197
unknown
United States
There are 7 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics
https://oilreviewmiddleeast.com/events/event-news/free-webinar-enhancing-oil-and-gas-operations-with-advanced-video-analytics