IOC Report
http://enchantmc.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
JSON data
downloaded
Chrome Cache Entry: 101
gzip compressed data, from Unix, original size modulo 2^32 442
dropped
Chrome Cache Entry: 102
gzip compressed data, from Unix, original size modulo 2^32 243
downloaded
Chrome Cache Entry: 103
gzip compressed data, from Unix, original size modulo 2^32 2897
dropped
Chrome Cache Entry: 104
Java source, ASCII text
dropped
Chrome Cache Entry: 105
PNG image data, 62 x 1, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 106
PNG image data, 1280 x 222, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 107
gzip compressed data, from Unix, original size modulo 2^32 7501
downloaded
Chrome Cache Entry: 108
gzip compressed data, from Unix, original size modulo 2^32 3744
dropped
Chrome Cache Entry: 109
gzip compressed data, from Unix, original size modulo 2^32 2534
downloaded
Chrome Cache Entry: 110
gzip compressed data, from Unix, original size modulo 2^32 7860
dropped
Chrome Cache Entry: 111
gzip compressed data, from Unix, original size modulo 2^32 2534
dropped
Chrome Cache Entry: 112
gzip compressed data, from Unix, original size modulo 2^32 243
downloaded
Chrome Cache Entry: 113
gzip compressed data, from Unix, original size modulo 2^32 614
downloaded
Chrome Cache Entry: 114
PNG image data, 1280 x 222, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 115
PNG image data, 2560 x 1387, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 116
gzip compressed data, from Unix, original size modulo 2^32 23969
dropped
Chrome Cache Entry: 117
gzip compressed data, from Unix, original size modulo 2^32 139
dropped
Chrome Cache Entry: 118
gzip compressed data, from Unix, original size modulo 2^32 179
dropped
Chrome Cache Entry: 119
gzip compressed data, from Unix, original size modulo 2^32 180
dropped
Chrome Cache Entry: 120
gzip compressed data, from Unix, original size modulo 2^32 202720
downloaded
Chrome Cache Entry: 121
PNG image data, 1916 x 1077, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 122
data
downloaded
Chrome Cache Entry: 123
gzip compressed data, from Unix, original size modulo 2^32 3104
downloaded
Chrome Cache Entry: 124
gzip compressed data, from Unix, original size modulo 2^32 379
dropped
Chrome Cache Entry: 125
ASCII text, with very long lines (2203)
dropped
Chrome Cache Entry: 126
gzip compressed data, from Unix, original size modulo 2^32 4325
downloaded
Chrome Cache Entry: 127
gzip compressed data, from Unix, original size modulo 2^32 4559
dropped
Chrome Cache Entry: 128
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (22272)
dropped
Chrome Cache Entry: 130
gzip compressed data, from Unix, original size modulo 2^32 379
downloaded
Chrome Cache Entry: 131
gzip compressed data, from Unix, original size modulo 2^32 3744
downloaded
Chrome Cache Entry: 132
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 133
PNG image data, 1000 x 140, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 134
JSON data
dropped
Chrome Cache Entry: 135
JSON data
downloaded
Chrome Cache Entry: 136
gzip compressed data, from Unix, original size modulo 2^32 184
downloaded
Chrome Cache Entry: 137
PNG image data, 1000 x 140, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 138
gzip compressed data, from Unix, original size modulo 2^32 180
downloaded
Chrome Cache Entry: 139
gzip compressed data, from Unix, original size modulo 2^32 4559
downloaded
Chrome Cache Entry: 140
gzip compressed data, from Unix, original size modulo 2^32 184
dropped
Chrome Cache Entry: 141
Java source, ASCII text, with very long lines (8189)
dropped
Chrome Cache Entry: 142
gzip compressed data, from Unix, original size modulo 2^32 67
downloaded
Chrome Cache Entry: 143
gzip compressed data, from Unix, original size modulo 2^32 746
dropped
Chrome Cache Entry: 144
gzip compressed data, from Unix, original size modulo 2^32 29108
downloaded
Chrome Cache Entry: 145
PNG image data, 2560 x 1387, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 146
gzip compressed data, from Unix, original size modulo 2^32 139
downloaded
Chrome Cache Entry: 147
gzip compressed data, from Unix, original size modulo 2^32 139
dropped
Chrome Cache Entry: 148
Unicode text, UTF-8 text, with very long lines (29106)
dropped
Chrome Cache Entry: 149
gzip compressed data, from Unix, original size modulo 2^32 1241
dropped
Chrome Cache Entry: 150
gzip compressed data, from Unix, original size modulo 2^32 15086
downloaded
Chrome Cache Entry: 151
PNG image data, 1000 x 377, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 152
gzip compressed data, from Unix, original size modulo 2^32 8190
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (47671)
downloaded
Chrome Cache Entry: 154
gzip compressed data, from Unix, original size modulo 2^32 2204
downloaded
Chrome Cache Entry: 155
gzip compressed data, from Unix, original size modulo 2^32 8837
downloaded
Chrome Cache Entry: 156
gzip compressed data, from Unix, original size modulo 2^32 5059
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (47671)
dropped
Chrome Cache Entry: 158
gzip compressed data, from Unix, original size modulo 2^32 3028
downloaded
Chrome Cache Entry: 159
PNG image data, 1456 x 816, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 160
PNG image data, 1456 x 816, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 161
gzip compressed data, from Unix, original size modulo 2^32 746
downloaded
Chrome Cache Entry: 162
gzip compressed data, from Unix, original size modulo 2^32 5059
downloaded
Chrome Cache Entry: 163
PNG image data, 1000 x 377, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 78
gzip compressed data, from Unix, original size modulo 2^32 442
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (4728)
dropped
Chrome Cache Entry: 80
gzip compressed data, from Unix, original size modulo 2^32 101
downloaded
Chrome Cache Entry: 81
gzip compressed data, from Unix, original size modulo 2^32 2897
downloaded
Chrome Cache Entry: 82
Java source, ASCII text, with very long lines (7322)
dropped
Chrome Cache Entry: 83
JSON data
dropped
Chrome Cache Entry: 84
gzip compressed data, from Unix, original size modulo 2^32 23969
downloaded
Chrome Cache Entry: 85
gzip compressed data, from Unix, original size modulo 2^32 8398
downloaded
Chrome Cache Entry: 86
gzip compressed data, from Unix, original size modulo 2^32 436
dropped
Chrome Cache Entry: 87
PNG image data, 62 x 1, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 88
gzip compressed data, from Unix, original size modulo 2^32 436
downloaded
Chrome Cache Entry: 89
gzip compressed data, from Unix, original size modulo 2^32 22273
downloaded
Chrome Cache Entry: 90
Java source, ASCII text, with very long lines (4324)
dropped
Chrome Cache Entry: 91
gzip compressed data, from Unix, original size modulo 2^32 1241
downloaded
Chrome Cache Entry: 92
gzip compressed data, from Unix, original size modulo 2^32 15086
dropped
Chrome Cache Entry: 93
gzip compressed data, from Unix, original size modulo 2^32 2739
downloaded
Chrome Cache Entry: 94
gzip compressed data, from Unix, original size modulo 2^32 139
downloaded
Chrome Cache Entry: 95
gzip compressed data, from Unix, original size modulo 2^32 614
dropped
Chrome Cache Entry: 96
PNG image data, 1916 x 1077, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 97
gzip compressed data, from Unix, original size modulo 2^32 7860
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (50313)
dropped
Chrome Cache Entry: 99
gzip compressed data, from Unix, original size modulo 2^32 179
downloaded
There are 77 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2276,i,16750502585655619694,5052069107699107244,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://enchantmc.com/"

URLs

Name
IP
Malicious
http://enchantmc.com/
http://cv.iptc.org/newscodes/digitalsourcetype/trainedAlgorithmicMedia
unknown
https://enchantmc.com/_nuxt/DYXQyl31.js
172.67.177.159
https://store.enchantmc.com/favicon.ico
104.18.37.189
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8d85ca373990e827/1729896885436/VMMrUWN0_XVgavH
104.18.95.41
http://iptc.org/std/Iptc4xmpExt/2008-02-29/
unknown
https://enchantmc.com/
https://enchantmc.com/_nuxt/DvDH6DOc.js
172.67.177.159
https://store.enchantmc.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=8d85ca1e7cbb0c23
104.18.37.189
https://enchantmc.com/_nuxt/BFsARfXT.js
172.67.177.159
https://store.enchantmc.com/cdn-cgi/challenge-platform/h/b/flow/ov1/570441033:1729894448:lT1bfOeU_6YtX0cq5oLL9ffAzZkGhYk8LaxeR6KUHrQ/8d85ca1e7cbb0c23/YK5zfPGAW203zy6fB4opeFftcXwaTFIAnEWmrN1oZgg-1729896877-1.2.1.1-7d_rpIbY870dS0w.Pg7UUTRxNUAyjZxSKUIKuN6W11xBWZFKEe19n2z4hQ3F7v7E
104.18.37.189
https://enchantmc.com/blogs/introducing-survival-purple
http://enchantmc.com/
104.21.35.159
https://enchantmc.com/_nuxt/Dytb3AKv.js
172.67.177.159
https://enchantmc.com/_nuxt/DuHK2UAd.js
172.67.177.159
https://store.enchantmc.com/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1
104.18.95.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8d85ca373990e827&lang=auto
104.18.95.41
https://enchantmc.com/_nuxt/BS71KmvR.js
172.67.177.159
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8d85ca373990e827/1729896885437/02428cd6032968b13154f246552ad7a5478d1171e015df48c16a83dad5470f67/T54kqZ25Va0_QIn
104.18.95.41
https://enchantmc.com/_nuxt/BQkc-AXV.js
172.67.177.159
https://api.mcsrvstat.us/3/play.enchantmc.com
104.26.15.225
https://enchantmc.com/_nuxt/BN-IwMZ-.js
172.67.177.159
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1854591383:1729894565:zy-fy-Al7HA3eFlJ7MiFtmbN07iZ85zvGuu41mHW0cs/8d85ca373990e827/j46uBR9i2mvlgWpERV8LRWK3lOiRsev3LeATPuy.TaE-1729896881-1.1.1.1-4NaV8m_b545.STnF5.gzGqIQ0xCvfmci.jTSwbOvm9pjrcECVN7FUK_E8h42.Jbe
104.18.95.41
https://enchantmc.com/_nuxt/CciTduvY.js
172.67.177.159
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/snn17/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/normal/auto/
104.18.95.41
There are 15 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
a.nel.cloudflare.com
35.190.80.1
discord.gg
162.159.130.234
api.mcsrvstat.us
104.26.15.225
discord.com
162.159.135.232
4bbe3c67.webstore.tebex.io
104.18.37.189
challenges.cloudflare.com
104.18.95.41
www.google.com
142.250.186.68
enchantmc.com
104.21.35.159
store.enchantmc.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
162.159.136.232
unknown
United States
192.168.2.7
unknown
unknown
104.18.95.41
challenges.cloudflare.com
United States
162.159.135.232
discord.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
104.18.37.189
4bbe3c67.webstore.tebex.io
United States
162.159.130.234
discord.gg
United States
239.255.255.250
unknown
Reserved
104.21.35.159
enchantmc.com
United States
172.67.177.159
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
104.26.15.225
api.mcsrvstat.us
United States
There are 4 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://enchantmc.com/
https://enchantmc.com/
https://enchantmc.com/
https://enchantmc.com/blogs/introducing-survival-purple
https://store.enchantmc.com/
https://store.enchantmc.com/
https://store.enchantmc.com/