IOC Report
Electronic_Receipt_ATT0001.virus.html

loading gif

Files

File Path
Type
Category
Malicious
Electronic_Receipt_ATT0001.virus.html
HTML document, ASCII text, with very long lines (1012), with CRLF line terminators
initial sample
malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 20:07:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 20:07:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 20:07:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 20:07:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 20:07:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (48316), with no line terminators
dropped
Chrome Cache Entry: 268
RIFF (little-endian) data, Web/P image, VP8 encoding, 340x270, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 269
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
dropped
Chrome Cache Entry: 270
ASCII text, with very long lines (487)
dropped
Chrome Cache Entry: 271
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 272
ASCII text, with very long lines (2108)
downloaded
Chrome Cache Entry: 273
ASCII text, with very long lines (4103), with no line terminators
downloaded
Chrome Cache Entry: 274
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 340x270, components 3
dropped
Chrome Cache Entry: 275
ASCII text, with very long lines (1317), with CRLF line terminators
dropped
Chrome Cache Entry: 276
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 277
ASCII text, with very long lines (632)
downloaded
Chrome Cache Entry: 278
ASCII text, with very long lines (44394)
downloaded
Chrome Cache Entry: 279
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (47671)
dropped
Chrome Cache Entry: 281
ASCII text, with very long lines (65391)
dropped
Chrome Cache Entry: 282
ASCII text, with very long lines (4779), with no line terminators
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (533), with no line terminators
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (4103), with no line terminators
dropped
Chrome Cache Entry: 285
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 286
HTML document, ASCII text, with very long lines (580)
downloaded
Chrome Cache Entry: 287
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 288
Web Open Font Format (Version 2), TrueType, length 28984, version 1.0
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (632)
dropped
Chrome Cache Entry: 290
ASCII text, with very long lines (3139)
downloaded
Chrome Cache Entry: 291
ASCII text, with very long lines (65391)
downloaded
Chrome Cache Entry: 292
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 293
PNG image data, 5 x 44, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 294
ASCII text, with very long lines (5319), with no line terminators
downloaded
Chrome Cache Entry: 295
RIFF (little-endian) data, Web/P image, VP8 encoding, 680x540, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 296
ASCII text, with very long lines (65431)
dropped
Chrome Cache Entry: 297
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
downloaded
Chrome Cache Entry: 298
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 299
ASCII text, with very long lines (723)
downloaded
Chrome Cache Entry: 300
JSON data
downloaded
Chrome Cache Entry: 301
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 302
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 340x270, components 3
dropped
Chrome Cache Entry: 303
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 304
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 305
HTML document, ASCII text, with very long lines (6421), with CRLF line terminators
downloaded
Chrome Cache Entry: 306
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 500x250, components 3
dropped
Chrome Cache Entry: 307
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 308
RIFF (little-endian) data, Web/P image, VP8 encoding, 680x540, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 309
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 310
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 311
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 680x540, components 3
dropped
Chrome Cache Entry: 312
ASCII text, with very long lines (47671)
downloaded
Chrome Cache Entry: 313
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 340x270, components 3
dropped
Chrome Cache Entry: 314
C source, ASCII text, with very long lines (47001), with no line terminators
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (5674)
dropped
Chrome Cache Entry: 316
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 317
ASCII text, with very long lines (3139)
dropped
Chrome Cache Entry: 318
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 319
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 320
PNG image data, 5 x 44, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 321
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 322
ASCII text, with very long lines (3969)
dropped
Chrome Cache Entry: 323
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
dropped
Chrome Cache Entry: 324
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 325
HTML document, ASCII text, with very long lines (716), with no line terminators
downloaded
Chrome Cache Entry: 326
HTML document, ASCII text, with very long lines (540)
downloaded
Chrome Cache Entry: 327
ASCII text
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (5251), with no line terminators
dropped
Chrome Cache Entry: 329
RIFF (little-endian) data, Web/P image, VP8 encoding, 680x540, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 330
ASCII text, with very long lines (3969)
dropped
Chrome Cache Entry: 331
ASCII text, with very long lines (1321), with CRLF line terminators
downloaded
Chrome Cache Entry: 332
ASCII text, with very long lines (3969)
downloaded
Chrome Cache Entry: 333
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 334
ASCII text, with very long lines (47992), with no line terminators
dropped
Chrome Cache Entry: 335
ASCII text, with very long lines (65401)
dropped
Chrome Cache Entry: 336
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 337
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 680x540, components 3
dropped
Chrome Cache Entry: 338
Web Open Font Format (Version 2), TrueType, length 32432, version 1.0
downloaded
Chrome Cache Entry: 339
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 340
ASCII text, with very long lines (57559)
downloaded
Chrome Cache Entry: 341
RIFF (little-endian) data, Web/P image, VP8 encoding, 680x540, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 342
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (487)
downloaded
Chrome Cache Entry: 344
ASCII text, with very long lines (47992), with no line terminators
downloaded
Chrome Cache Entry: 345
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 500x250, components 3
dropped
Chrome Cache Entry: 346
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 340x270, components 3
dropped
Chrome Cache Entry: 347
very short file (no magic)
dropped
Chrome Cache Entry: 348
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 680x540, components 3
dropped
Chrome Cache Entry: 349
ASCII text, with very long lines (5674)
downloaded
Chrome Cache Entry: 350
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
dropped
Chrome Cache Entry: 351
JSON data
downloaded
Chrome Cache Entry: 352
ASCII text, with very long lines (65390)
downloaded
Chrome Cache Entry: 353
ASCII text, with very long lines (4779), with no line terminators
dropped
Chrome Cache Entry: 354
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
dropped
Chrome Cache Entry: 355
ASCII text
dropped
Chrome Cache Entry: 356
RIFF (little-endian) data, Web/P image, VP8 encoding, 680x540, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (2108)
dropped
Chrome Cache Entry: 358
ASCII text, with very long lines (22096), with no line terminators
downloaded
Chrome Cache Entry: 359
RIFF (little-endian) data, Web/P image, VP8 encoding, 340x270, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 360
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
dropped
Chrome Cache Entry: 361
HTML document, ASCII text, with very long lines (1056), with no line terminators
downloaded
Chrome Cache Entry: 362
RIFF (little-endian) data, Web/P image, VP8 encoding, 680x540, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 363
gzip compressed data, was "main.97c41ef3.js", last modified: Fri Aug 23 15:57:59 2024, from Unix, original size modulo 2^32 83598
dropped
Chrome Cache Entry: 364
HTML document, ASCII text, with very long lines (11686), with no line terminators
downloaded
Chrome Cache Entry: 365
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
dropped
Chrome Cache Entry: 366
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 367
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 368
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 369
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 370
ASCII text, with very long lines (48316), with no line terminators
downloaded
Chrome Cache Entry: 371
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 372
C source, ASCII text, with very long lines (10929)
dropped
Chrome Cache Entry: 373
very short file (no magic)
downloaded
Chrome Cache Entry: 374
C source, ASCII text, with very long lines (47001), with no line terminators
dropped
Chrome Cache Entry: 375
HTML document, ASCII text, with very long lines (565), with no line terminators
downloaded
Chrome Cache Entry: 376
RIFF (little-endian) data, Web/P image, VP8 encoding, 340x270, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 377
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 378
ASCII text, with very long lines (1615)
downloaded
Chrome Cache Entry: 379
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 380
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 381
ASCII text, with very long lines (5089), with no line terminators
downloaded
Chrome Cache Entry: 382
ASCII text, with very long lines (3969)
downloaded
Chrome Cache Entry: 383
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 384
ASCII text, with very long lines (1913), with no line terminators
dropped
Chrome Cache Entry: 385
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 386
ASCII text, with very long lines (57559)
dropped
Chrome Cache Entry: 387
ASCII text, with very long lines (15336)
dropped
Chrome Cache Entry: 388
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 680x540, components 3
dropped
Chrome Cache Entry: 389
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 390
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 391
ASCII text, with very long lines (52360)
downloaded
Chrome Cache Entry: 392
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 393
HTML document, ASCII text, with very long lines (14407), with no line terminators
downloaded
Chrome Cache Entry: 394
ASCII text, with very long lines (1913), with no line terminators
downloaded
Chrome Cache Entry: 395
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 680x540, components 3
dropped
Chrome Cache Entry: 396
ASCII text, with very long lines (52360)
dropped
Chrome Cache Entry: 397
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 680x540, components 3
dropped
Chrome Cache Entry: 398
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 399
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 400
ASCII text, with very long lines (15336)
downloaded
Chrome Cache Entry: 401
RIFF (little-endian) data, Web/P image, VP8 encoding, 500x250, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 402
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 340x270, components 3
dropped
Chrome Cache Entry: 403
HTML document, ASCII text, with very long lines (815)
downloaded
Chrome Cache Entry: 404
ASCII text, with very long lines (5089), with no line terminators
dropped
Chrome Cache Entry: 405
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 406
RIFF (little-endian) data, Web/P image, VP8 encoding, 340x270, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 407
ASCII text, with very long lines (65401)
downloaded
Chrome Cache Entry: 408
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
dropped
Chrome Cache Entry: 409
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 410
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 411
RIFF (little-endian) data, Web/P image, VP8 encoding, 340x270, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 412
ASCII text, with very long lines (1615)
dropped
Chrome Cache Entry: 413
ASCII text, with very long lines (44394)
dropped
Chrome Cache Entry: 414
C source, ASCII text, with very long lines (10929)
downloaded
Chrome Cache Entry: 415
RIFF (little-endian) data, Web/P image, VP8 encoding, 300x300, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 416
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 417
ASCII text, with very long lines (65390)
dropped
Chrome Cache Entry: 418
Web Open Font Format (Version 2), TrueType, length 28272, version 1.0
downloaded
Chrome Cache Entry: 419
RIFF (little-endian) data, Web/P image, VP8 encoding, 500x250, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 420
gzip compressed data, was "main.97c41ef3.js", last modified: Fri Aug 23 15:57:59 2024, from Unix, original size modulo 2^32 83598
downloaded
Chrome Cache Entry: 421
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 422
ASCII text, with very long lines (22096), with no line terminators
dropped
There are 153 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument C:\Users\user\Desktop\Electronic_Receipt_ATT0001.virus.html
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2244 --field-trial-handle=2032,i,17116003664022829940,1759603633118170970,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3328 --field-trial-handle=2032,i,17116003664022829940,1759603633118170970,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4060 --field-trial-handle=2032,i,17116003664022829940,1759603633118170970,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://6u.ithbetoxi.com/wtqllHS/
188.114.96.3
malicious
file:///C:/Users/user/Desktop/Electronic_Receipt_ATT0001.virus.html
malicious
https://6u.ithbetoxi.com/wtqllHS/#D#a2lya2JhbmVAaWNjdXNhLm5ldA==
malicious
https://insight.adsrvr.org/track/conv/?adv=r09jr34&ct=0:ezyvggn&fmt=3
3.33.220.150
https://code.jquery.com/jquery-3.6.0.min.js
151.101.2.137
https://i.etsystatic.com/36383707/r/il/3236b3/5824549940/il_340x270.5824549940_rbtz.jpg
151.101.1.224
https://www.etsy.com/include/tags.js
151.101.193.224
https://www.etsy.com/dac/site-chrome/components/components.fc26458b142737,site-chrome/header/header.ed900abd1aa2cc,__modules__MiniCart__src__/Overlay/OverlayView.74cb1c37c4995e,__modules__CategoryNav__src__/Views/ButtonMenu/Menu.8d961c48ba074a,__modules__CategoryNav__src__/Views/DropdownMenu/Menu.74cb1c37c4995e,site-chrome/footer/footer.74cb1c37c4995e,gdpr/settings-overlay.74cb1c37c4995e.css?variant=sasquatch
151.101.193.224
https://s.pinimg.com/ct/lib/main.97c41ef3.js
151.101.0.84
https://www.etsy.com/api/v3/ajax/bespoke/public/neu/specs/submenu?log_performance_metrics=false&specs%5Bsubmenu%5D%5B%5D=Etsy%5CModules%5CCategoryNav%5CSpecs%5CDropdownCatNav%5CDropdownSubmenu&runtime_analysis=false
151.101.193.224
https://i.etsystatic.com/50393449/c/1769/1405/109/787/il/219720/5911373326/il_680x540.5911373326_1peg.jpg
151.101.1.224
https://match.adsrvr.org/track/cmf/appnexus?ttd=1&anid=6619341948418111617&ttd_tdid=12662c3a-27d4-41e8-910c-8dae1cf68c72
3.33.220.150
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8d9de4d4ae616c2b/1730149632941/deaaa1f76103519aa1ab55f63e1e1ab0104f565a95d38168e03470c8911d8b19/2MEX90SqA0jvs1F
104.18.95.41
https://www.etsy.com/paula/v3/polyfill.min.js?etsy-v=v5&flags=gated&features=AbortController%2CDOMTokenList.prototype.@@iterator%2CDOMTokenList.prototype.forEach%2CIntersectionObserver%2CIntersectionObserverEntry%2CNodeList.prototype.@@iterator%2CNodeList.prototype.forEach%2CObject.preventExtensions%2CString.prototype.anchor%2CString.raw%2Cdefault%2Ces2015%2Ces2016%2Ces2017%2Ces2018%2Ces2019%2Ces2020%2Ces2021%2Ces2022%2Cfetch%2CgetComputedStyle%2CmatchMedia%2Cperformance.now
151.101.193.224
https://match.adsrvr.org/track/cmf/google?g_uuid=&gdpr=0&gdpr_consent=&ttd_tdid=12662c3a-27d4-41e8-910c-8dae1cf68c72&google_gid=CAESEFWQnOr6W1GNAK--KJXaLng&google_cver=1
3.33.220.150
https://developers.google.com/identity/gsi/web/guides/fedcm-migration?s=dc#skipped_moment
unknown
https://dsum-sec.casalemedia.com/rum?cm_dsp_id=39&external_user_id=12662c3a-27d4-41e8-910c-8dae1cf68
unknown
https://www.google.com
unknown
https://i.etsystatic.com/34269816/r/il/443d0d/6289105270/il_340x270.6289105270_3g86.jpg
151.101.1.224
https://datadome.co
unknown
https://i.etsystatic.com/26553019/r/il/3c2962/4627977771/il_680x540.4627977771_8r7e.jpg
151.101.1.224
https://teacurl.com/res444.php?2-68747470733a2f2f36552e6974686265746f78692e636f6d2f7774716c6c48532f-caracal
69.49.245.172
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8d9de4d4ae616c2b&lang=auto
104.18.95.41
https://www.etsy.com/ac/evergreenVendor/js/en-US/etsy_libs.6f2bc648a336d3e52761.js
151.101.193.224
https://web.btncdn.com/v1/button.js
99.86.4.106
https://js.adsrvr.org/up_loader.1.1.0.js
18.172.103.101
https://www.etsy.com/sourcemaps/evergreenVendor/en-US/vendor_bundle.051a2557fd322e046abd.js.map
unknown
https://www.etsy.com/assets/type/Graphik-Medium-Web.woff2
151.101.193.224
https://api.usebutton.com
unknown
https://cm.g.doubleclick.net/pixel?google_nid=TheTradeDesk&google_cm&google_sc&google_hm=MTI2NjJjM2EtMjdkNC00MWU4LTkxMGMtOGRhZTFjZjY4Yzcy&gdpr=0&gdpr_consent=&ttd_tdid=12662c3a-27d4-41e8-910c-8dae1cf68c72
216.58.206.34
https://i.etsystatic.com/53025087/c/2307/2307/92/376/il/51fecf/6153472233/il_300x300.6153472233_81o8.jpg
151.101.1.224
https://www.facebook.com/tr?uuid=1730149645&id=297472060462208&ev=PageView&ud[em]=%27%27%22&fbp=undefined&fbc=undefined
157.240.251.35
https://www.etsy.com/assets/type/Guardian-EgypTT-Light.woff2
151.101.193.224
https://www.etsy.com/ac/evergreenVendor/js/en-US/async/common-entrypoints/auto/@etsy-modules/CategoryNav/NavHandlers/CategoryNavigationLoader.12cd58e93e791b36f37b.js
151.101.193.224
https://insight.adsrvr.org/track/up?adv=r09jr34&ref=https%3A%2F%2Fwww.etsy.com%2F&upid=c6e9qnb&upv=1.1.0&paapi=1
3.33.220.150
https://lantern.roeye.com/track.php?
unknown
https://i.etsystatic.com/21536520/c/1951/1951/216/733/il/e6844e/3655473308/il_300x300.3655473308_tto5.jpg
151.101.1.224
https://match.adsrvr.org/track/cmf/rubicon?gdpr=0
3.33.220.150
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
104.17.24.14
https://i.etsystatic.com/5967687/c/1000/1000/0/218/il/39e11f/5316027134/il_300x300.5316027134_jctk.jpg
151.101.1.224
https://i.etsystatic.com/38199531/r/il/75e1bf/5898655978/il_300x300.5898655978_btj0.jpg
151.101.1.224
https://lantern.roeye.com/track.php?fingerprint=13d2393d-a482-4cf6-b4d7-c3b7dc910764&referrer=https%3A%2F%2F6u.ithbetoxi.com%2F&landingpage=https%3A%2F%2Fwww.etsy.com%2F&useragent=Mozilla%2F5.0%20(Windows%20NT%2010.0%3B%20Win64%3B%20x64)%20AppleWebKit%2F537.36%20(KHTML%2C%20like%20Gecko)%20Chrome%2F117.0.0.0%20Safari%2F537.36&site=6220
54.77.216.88
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/375677601:1730147206:oeSDq7mh5VkmWziSWJoPWgXOWXteJTfRPBFKiPow65M/8d9de4d4ae616c2b/41GOc5NQAwLE_gsQgYNHkI.7SNQnLSD1KK40k_lXmoE-1730149630-1.1.1.1-2MD1tMgV4ckJ75KK89c3HaEqCclLXyLbvw1tGVYnaNO90tEhIRlfBxBmDV0U8D60
104.18.95.41
https://i.etsystatic.com/ij/b8dd71/6404562281/ij_fullxfull.6404562281_t0f0lh31.jpg?version=0
151.101.1.224
https://ct.pinterest.com/stats/
unknown
https://tags.w55c.net/rs?id=590f83e499a54109bd553d1e2ebaf867&t=marketing
52.59.123.117
https://cct.google/taggy/agent.js
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8d9de4d4ae616c2b/1730149632944/1yyMpTkB8tQgcnf
104.18.95.41
https://ct.pinterest.com/user/?tid=2612477536450&pd=%7B%22np%22%3A%22gtm%22%7D&cb=1730149654295&dep=2%2CPAGE_LOAD
151.101.0.84
https://resources.xg4ken.com/js/v2/ktag.js?tid=KT-N3B63-3EB
34.252.33.46
https://www.etsy.com/dac/vesta_homepage/vesta_homepage.00d19f16e05ad5,vesta_homepage/consistent_spacing.74cb1c37c4995e,homepage/_modules/spacing.74cb1c37c4995e,__modules__OnsitePromos__src__/Flights/threeSlimTiles.74cb1c37c4995e,__modules__OnsitePromos__src__/Banners/hero.bda2a84cc20d45,__modules__OnsitePromos__src__/Regions/Contentful/CTA.89948954da3262,__modules__OnsitePromos__src__/Banners/secondary.fe5529e7bc4624,vesta_homepage/view/etsy-everyday.706dbffffca1c9,vesta_homepage/view/collage/card-group.74cb1c37c4995e,homepage/_modules/popular-right-now.74cb1c37c4995e,homepage/_modules/common/simple-header.74cb1c37c4995e,neu/modules/favorite_button_defaults.74cb1c37c4995e,listings/listing-card-video.74cb1c37c4995e,common/listing_card_text_badge.b1c6bd381ce780,common/stars-colors.74cb1c37c4995e,homepage/_modules/editors-picks.1a7eb298cb425f,neu/modules/listing_card.00d19f16e05ad5,web-toolkit-v2/modules/video/video_previews.74cb1c37c4995e,home_living/shop-the-look.74cb1c37c4995e,vesta_homepage/view/what-is-etsy.74cb1c37c4995e,impact/homepage/what-is-etsy/community-impact.74cb1c37c4995e,pages/join_neu/social/google_one_tap_modal.2ec02d4eb6d23b.css?variant=sasquatch
151.101.193.224
https://i.etsystatic.com/14466987/c/2884/2884/0/0/il/f0fd7f/6402591037/il_340x270.6402591037_kz4x.jpg
151.101.1.224
https://cm.g.doubleclick.net/pixel?google_nid=TheTradeDesk&google_cm&google_sc&google_hm=MTI2NjJjM2E
unknown
https://www.etsy.com/sourcemaps/evergreenVendor/en-US/vesta_homepage/bootstrap.fe520d7668e1b7d4fa14.
unknown
https://www.etsy.com/sourcemaps/evergreenVendor/en-US/vesta_homepage/search_bubbles.a18c2a5238135251
unknown
https://www.google.com/.well-known/web-identity
142.250.186.68
https://lantern.roeyecdn.com/lantern_global_6220.min.js
13.224.189.42
https://trkn.us/pixel/conv/ppt=8398;g=homepage;gid=34719;ord=1730149645?gtmcb=1658023618
95.101.111.153
https://i.etsystatic.com/6780165/c/1156/918/405/489/il/3abe7e/5335539978/il_680x540.5335539978_bnl0.jpg
151.101.1.224
https://ct.pinterest.com/v3/?tid=2612477536450&pd=%7B%22np%22%3A%22gtm%22%7D&event=init&ad=%7B%22loc%22%3A%22https%3A%2F%2Fwww.etsy.com%2F%22%2C%22ref%22%3A%22https%3A%2F%2F6u.ithbetoxi.com%2F%22%2C%22if%22%3Afalse%2C%22sh%22%3A1024%2C%22sw%22%3A1280%2C%22mh%22%3A%2297c41ef3%22%2C%22is_eu%22%3Atrue%2C%22architecture%22%3A%22x86%22%2C%22bitness%22%3A%2264%22%2C%22brands%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%2C%22uaFullVersion%22%3A%22117.0.5938.132%22%2C%22ecm_enabled%22%3Atrue%7D&cb=1730149654300
151.101.0.84
https://i.etsystatic.com/8505634/c/1538/1222/0/769/il/5b99c1/4275912553/il_680x540.4275912553_se3v.jpg
151.101.1.224
https://www.etsy.com/ac/evergreenVendor/js/en-US/async/common-entrypoints/auto/@etsy-modules/CategoryNav/Views/DropdownMenu/Menu.5c7ec203235cc6232225.js
151.101.193.224
https://js.adsrvr.org/universal_pixel.1.1.0.js
18.172.103.101
https://www.etsy.com/ac/evergreenVendor/js/en-US/vendor_bundle.051a2557fd322e046abd.js
151.101.193.224
https://trkn.us/pixel/conv/ppt=8398;g=homepage;gid=34719;ord=1730149645?gtmcb=1658023618;ip=155.94.241.188;cuidchk=1
95.101.111.153
https://www.dwin1.com/6220.js
143.204.215.129
https://6u.ithbetoxi.com/favicon.ico
188.114.96.3
https://www.etsy.com/ac/evergreenVendor/js/en-US/app-shell/globals/index.4ca09e8dfd06bd351eee.js.LIC
unknown
https://www.etsy.com/ac/evergreenVendor/js/en-US/vesta_homepage/search_bubbles.a18c2a52381352511211.js
151.101.193.224
https://4x7z97r4bjg56lmabax9710ob52c9wfwkb51eqn9dkmybdmla1.ticurson.com/csqzhjjkfjspcjzzvxshsllGyWlliRICOGMNJIWRTLNOOTLLQJIAQICZMMBVUGTEDBJHGSBASJVBHXTTPZYSJ
104.21.32.205
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1
104.18.95.41
https://i.etsystatic.com/5492298/c/2616/2079/0/201/il/ed2a9a/3145324589/il_680x540.3145324589_3wgr.jpg
151.101.1.224
https://s.pinimg.com/ct/core.js
151.101.0.84
https://developers.google.com/identity/gsi/web/guides/fedcm-migration
unknown
https://www.etsy.com/sourcemaps/evergreenVendor/en-US/app-shell/globals/index.4ca09e8dfd06bd351eee.j
unknown
https://meet.google.com
unknown
https://pixel.streetmetrics.io/pixel/62f2e71d-3885-4822-ba89-6e017b2f1a1e
172.67.143.206
https://cdn.usebutton.com/web-widgets/SmsCollectionV1.html
unknown
https://insight.adsrvr.org/track/up
unknown
https://www.etsy.com/bcn/beacon
151.101.193.224
https://www.etsy.com/site.webmanifest
151.101.193.224
https://ib.adnxs.com/getuid?https%3a%2f%2fmatch.adsrvr.org%2ftrack%2fcmf%2fappnexus%3fttd%3d1%26anid%3d%24UID&ttd_tdid=12662c3a-27d4-41e8-910c-8dae1cf68c72
185.89.211.116
https://www.etsy.com/ac/evergreenVendor/js/en-US/app-shell/globals/index.4ca09e8dfd06bd351eee.js
151.101.193.224
https://pixel.rubiconproject.com/tap.php?v=8981&nid=2307&put=12662c3a-27d4-41e8-910c-8dae1cf68c72&gd
unknown
https://www.etsy.com/
https://www.facebook.com/tr?uuid=1730149645&id=114623403312281&ev=PageView&ud[em]=%27%27%22&cd[page_path]=null&cd[detected_region]=US&fbp=undefined&fbc=undefined
157.240.251.35
https://www.etsy.com/ac/evergreenVendor/js/en-US/etsy_libs.6f2bc648a336d3e52761.js.LICENSE
unknown
https://challenges.cloudflare.com/turnstile/v0/b/e1a56f38220d/api.js
104.18.94.41
https://cdn.pdst.fm/ping.min.js
35.244.142.80
https://www.etsy.com/ac/evergreenVendor/js/en-US/vesta_homepage/bootstrap.fe520d7668e1b7d4fa14.js.LI
unknown
https://i.etsystatic.com/5533102/r/il/fa2faa/6104284395/il_300x300.6104284395_rbmu.jpg
151.101.1.224
https://www.etsy.com/ac/evergreenVendor/js/en-US/vesta_homepage/bootstrap.fe520d7668e1b7d4fa14.js
151.101.193.224
https://pixels.spotify.com/v1/ingest
35.186.224.24
https://ct.pinterest.com/ct.html
151.101.128.84
https://www.pinterest.com
unknown
https://i.etsystatic.com/41680084/r/il/f09928/5191407963/il_340x270.5191407963_rurr.jpg
151.101.1.224
https://developers.google.com/identity/gsi/web/guides/fedcm-migration?s=dc#cross_origin)
unknown
https://web.usebutton.com
unknown
https://googleads.g.doubleclick.net
unknown
https://www.etsy.com/assets/type/Graphik-Regular-Web.woff2
151.101.193.224
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
6u.ithbetoxi.com
188.114.96.3
malicious
dart.l.doubleclick.net
142.250.185.166
lantern.roeyecdn.com
13.224.189.42
alb-ireland-ext-ingress-group-474278744.eu-west-1.elb.amazonaws.com
34.252.33.46
4x7z97r4bjg56lmabax9710ob52c9wfwkb51eqn9dkmybdmla1.ticurson.com
104.21.32.205
eip-ntt.api.pinterest.com.akahost.net
2.18.48.37
adservice.google.com
142.250.185.226
dg2iu7dxxehbo.cloudfront.net
18.172.103.101
cdn.w55c.net
52.59.123.117
insight.adsrvr.org
3.33.220.150
code.jquery.com
151.101.2.137
cdnjs.cloudflare.com
104.17.25.14
cm.g.doubleclick.net
216.58.206.34
cdn.pdst.fm
35.244.142.80
www.google.com
142.250.185.228
edge-web.dual-gslb.spotify.com
35.186.224.24
d2pbcviywxotf2.cloudfront.net
143.204.215.129
match.adsrvr.org
3.33.220.150
star-mini.c10r.facebook.com
157.240.251.35
a.nel.cloudflare.com
35.190.80.1
google.com
142.250.186.174
ad.doubleclick.net
142.250.186.70
web.btncdn.com
99.86.4.106
teacurl.com
69.49.245.172
ax-0001.ax-msedge.net
150.171.28.10
pixel.streetmetrics.io
172.67.143.206
prod.pinterest.global.map.fastly.net
151.101.0.84
googleads.g.doubleclick.net
142.250.186.98
lantern.roeye.com
54.77.216.88
dsum-sec.casalemedia.com
172.64.151.101
dualstack.pinterest.map.fastly.net
151.101.0.84
challenges.cloudflare.com
104.18.94.41
etsy.map.fastly.net
151.101.193.224
td.doubleclick.net
142.250.186.66
trkn.us
95.101.111.153
ib.anycast.adnxs.com
185.89.211.116
9910951.fls.doubleclick.net
unknown
ct.pinterest.com
unknown
pt.ispot.tv
unknown
i.etsystatic.com
unknown
pixels.spotify.com
unknown
tags.w55c.net
unknown
www.facebook.com
unknown
js.adsrvr.org
unknown
www.dwin1.com
unknown
www.etsy.com
unknown
pixel.rubiconproject.com
unknown
resources.xg4ken.com
unknown
8666735.fls.doubleclick.net
unknown
s.pinimg.com
unknown
analytics.tiktok.com
unknown
ib.adnxs.com
unknown
There are 42 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
188.114.96.3
6u.ithbetoxi.com
European Union
malicious
142.250.186.68
unknown
United States
142.250.185.228
www.google.com
United States
151.101.0.84
prod.pinterest.global.map.fastly.net
United States
151.101.193.224
etsy.map.fastly.net
United States
142.250.185.226
adservice.google.com
United States
99.86.4.106
web.btncdn.com
United States
151.101.128.84
unknown
United States
185.89.211.116
ib.anycast.adnxs.com
Germany
172.67.187.119
unknown
United States
142.250.186.70
ad.doubleclick.net
United States
35.190.80.1
a.nel.cloudflare.com
United States
95.101.111.153
trkn.us
European Union
52.59.123.117
cdn.w55c.net
United States
13.224.189.100
unknown
United States
143.204.215.129
d2pbcviywxotf2.cloudfront.net
United States
3.33.220.150
insight.adsrvr.org
United States
142.250.184.198
unknown
United States
63.32.25.3
unknown
United States
142.250.184.194
unknown
United States
69.49.245.172
teacurl.com
United States
157.240.0.35
unknown
United States
104.18.95.41
unknown
United States
13.224.189.42
lantern.roeyecdn.com
United States
239.255.255.250
unknown
Reserved
104.17.25.14
cdnjs.cloudflare.com
United States
151.101.129.224
unknown
United States
104.21.32.205
4x7z97r4bjg56lmabax9710ob52c9wfwkb51eqn9dkmybdmla1.ticurson.com
United States
18.239.94.73
unknown
United States
34.252.33.46
alb-ireland-ext-ingress-group-474278744.eu-west-1.elb.amazonaws.com
United States
18.172.103.101
dg2iu7dxxehbo.cloudfront.net
United States
142.250.186.174
google.com
United States
104.18.94.41
challenges.cloudflare.com
United States
216.58.206.34
cm.g.doubleclick.net
United States
192.168.2.16
unknown
unknown
54.77.216.88
lantern.roeye.com
United States
172.64.151.101
dsum-sec.casalemedia.com
United States
142.250.185.166
dart.l.doubleclick.net
United States
54.228.148.251
unknown
United States
172.67.143.206
pixel.streetmetrics.io
United States
2.18.48.37
eip-ntt.api.pinterest.com.akahost.net
European Union
150.171.28.10
ax-0001.ax-msedge.net
United States
143.204.215.109
unknown
United States
142.250.186.98
googleads.g.doubleclick.net
United States
104.17.24.14
unknown
United States
151.101.1.224
unknown
United States
142.250.185.134
unknown
United States
142.250.185.132
unknown
United States
52.28.172.100
unknown
United States
35.186.224.24
edge-web.dual-gslb.spotify.com
United States
151.101.2.137
code.jquery.com
United States
150.171.27.10
unknown
United States
35.244.142.80
cdn.pdst.fm
United States
157.240.251.35
star-mini.c10r.facebook.com
United States
There are 44 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
file:///C:/Users/user/Desktop/Electronic_Receipt_ATT0001.virus.html
https://6u.ithbetoxi.com/wtqllHS/#D#a2lya2JhbmVAaWNjdXNhLm5ldA==
https://6u.ithbetoxi.com/wtqllHS/#D#a2lya2JhbmVAaWNjdXNhLm5ldA==
https://6u.ithbetoxi.com/wtqllHS/#D#a2lya2JhbmVAaWNjdXNhLm5ldA==
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
https://www.etsy.com/
There are 9 hidden doms, click here to show them.