IOC Report
https://url.usb.m.mimecastprotect.com/s/EYiPCJEkpZFx1AOtVfQFyLwg0?domain=saturne-ia.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 13:54:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 13:54:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 13:54:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 13:54:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 13:54:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 113
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 114
ASCII text, with very long lines (65490)
downloaded
Chrome Cache Entry: 115
Unicode text, UTF-8 text, with very long lines (65342)
downloaded
Chrome Cache Entry: 116
ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (65299)
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (57378)
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 122
Unicode text, UTF-8 text, with very long lines (64621)
downloaded
Chrome Cache Entry: 123
PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 124
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (340)
dropped
Chrome Cache Entry: 126
Web Open Font Format (Version 2), TrueType, length 50296, version 1.0
downloaded
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 130396, version 1.0
downloaded
Chrome Cache Entry: 128
ASCII text
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 130
ASCII text
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (8196)
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (10506)
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 134
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 135
C++ source, ASCII text
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (63702), with CRLF line terminators
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (65409)
dropped
Chrome Cache Entry: 138
ASCII text
downloaded
Chrome Cache Entry: 139
PNG image data, 250 x 250, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (65299)
dropped
Chrome Cache Entry: 141
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=8, description=Mosaic of multiethnic people portraits expressing positivity, smiling and looking at camera on different colorful studio backgr, orientation=upper-left, xresolution=286, yresolution=294, resolutionunit=2, software=GIMP 2.10.34, datetime=2024:09:26 19:07:02], comment: "Mosaic of multiethnic people portraits expressing positivity, smiling and looking at camera on different colorful studio backg", progressive, precision 8, 2048x910, components 3
dropped
Chrome Cache Entry: 142
C++ source, ASCII text
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (2345)
dropped
Chrome Cache Entry: 144
ASCII text
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (65409)
downloaded
Chrome Cache Entry: 146
Unicode text, UTF-8 text, with very long lines (64621)
dropped
Chrome Cache Entry: 147
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 148
ASCII text
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (2345)
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (65490)
dropped
Chrome Cache Entry: 151
Web Open Font Format (Version 2), TrueType, length 7748, version 1.0
downloaded
Chrome Cache Entry: 152
HTML document, Unicode text, UTF-8 text, with very long lines (674)
downloaded
Chrome Cache Entry: 153
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 154
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (63702), with CRLF line terminators
downloaded
Chrome Cache Entry: 156
Web Open Font Format (Version 2), TrueType, length 39124, version 1.0
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (8196)
dropped
Chrome Cache Entry: 158
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (340)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (57378)
downloaded
Chrome Cache Entry: 161
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=8, description=Mosaic of multiethnic people portraits expressing positivity, smiling and looking at camera on different colorful studio backgr, orientation=upper-left, xresolution=286, yresolution=294, resolutionunit=2, software=GIMP 2.10.34, datetime=2024:09:26 19:07:02], comment: "Mosaic of multiethnic people portraits expressing positivity, smiling and looking at camera on different colorful studio backg", progressive, precision 8, 2048x910, components 3
downloaded
Chrome Cache Entry: 162
ASCII text, with CRLF, LF line terminators
dropped
Chrome Cache Entry: 163
ASCII text, with very long lines (65443)
dropped
There are 48 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2500 --field-trial-handle=2256,i,16880286879759382739,2169740010670996207,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://url.usb.m.mimecastprotect.com/s/EYiPCJEkpZFx1AOtVfQFyLwg0?domain=saturne-ia.com"

URLs

Name
IP
Malicious
https://url.usb.m.mimecastprotect.com/s/EYiPCJEkpZFx1AOtVfQFyLwg0?domain=saturne-ia.com
https://github.com/mozilla/rhino/issues/346
unknown
https://github.com/svgdotjs/svg.draggable.js
unknown
https://tc39.es/ecma262/#sec-object.prototype.tostring
unknown
https://tc39.es/ecma262/#sec-toobject
unknown
https://stats.g.doubleclick.net/g/collect
unknown
https://github.com/firebase/firebase-js-sdk/issues/6838
unknown
https://tc39.es/ecma262/#sec-arrayspeciescreate
unknown
https://bugs.chromium.org/p/v8/issues/detail?id=3443
unknown
https://tc39.es/ecma262/#sec-array.isarray
unknown
https://tc39.es/ecma262/#sec-object.getownpropertydescriptor
unknown
https://github.com/rollup/rollup/issues/1691
unknown
https://github.com/zloirock/core-js
unknown
https://tc39.es/ecma262/#sec-object.prototype.propertyisenumerable
unknown
https://abs.twimg.com/a/1446542199/img/t1/web_heart_animation.png
unknown
https://saturne-ia.com/assets/vendor/bootstrap/css/bootstrap.min.css
217.160.0.90
https://tc39.es/ecma262/#sec-date.prototype-
unknown
https://tc39.es/ecma262/#sec-date.prototype.tostring
unknown
https://github.com/oven-sh/bun/issues/1633
unknown
https://tc39.es/ecma262/#sec-number-constructor
unknown
https://saturne-ia.com/assets/vendor/apexcharts/apexcharts.min.js
217.160.0.90
https://tc39.es/ecma262/#sec-array.prototype.includes
unknown
https://tc39.es/ecma262/#sec-object.setprototypeof
unknown
https://tc39.es/ecma262/#sec-string.prototype.trim
unknown
https://tc39.es/ecma262/#sec-symbol.keyfor
unknown
https://tc39.es/ecma262/#sec-hasownproperty
unknown
https://saturne-ia.com/assets/vendor/remixicon/remixicon.css
217.160.0.90
https://github.com/tc39/proposal-array-filtering
unknown
https://www.google.com
unknown
https://www.youtube.com/iframe_api
unknown
https://tc39.es/ecma262/#sec-symbol.prototype-
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://tc39.es/ecma262/#sec-%stringiteratorprototype%.next
unknown
https://tc39.es/ecma262/#sec-function.prototype.bind
unknown
https://tc39.es/ecma262/#sec-array.prototype.filter
unknown
https://tc39.es/ecma262/#sec-object.defineproperties
unknown
https://saturne-ia.com/assets/vendor/quill/quill.bubble.css
217.160.0.90
https://tc39.es/ecma262/#sec-tointegerorinfinity
unknown
http://ns.attribution.com/ads/1.0/
unknown
https://bugs.webkit.org/show_bug.cgi?id=109036)
unknown
https://tc39.es/ecma262/#sec-requireobjectcoercible
unknown
https://saturne-ia.com/assets/vendor/quill/quill.snow.css
217.160.0.90
https://url.usb.m.mimecastprotect.com/s/EYiPCJEkpZFx1AOtVfQFyLwg0?domain=saturne-ia.com
170.10.150.15
https://firebase.google.com/docs/web/setup#available-libraries
unknown
https://github.com/choojs/nanomorph/blob/master/lib/morph.jsL113
unknown
https://github.com/es-shims/es5-shim/issues/150
unknown
https://saturne-ia.com/assets/vendor/simple-datatables/simple-datatables.js
217.160.0.90
https://tc39.es/ecma262/#sec-object.getprototypeof
unknown
https://fengyuanchen.github.io/cropperjs
unknown
https://tc39.es/ecma262/#sec-array.prototype.values
unknown
https://saturne-ia.com/build/app.js
217.160.0.90
https://tc39.es/ecma262/#sec-getmethod
unknown
https://saturne-ia.com/build/runtime.js
217.160.0.90
https://tc39.es/ecma262/#sec-string.prototype-
unknown
https://html.spec.whatwg.org/multipage/timers-and-user-prompts.html#timers
unknown
https://github.com/microsoft/TypeScript-DOM-lib-generator/pull/1405
unknown
https://tc39.es/ecma262/#sec-symbol.iterator
unknown
https://tc39.es/ecma262/#sec-%iteratorprototype%-
unknown
https://tc39.es/ecma262/#sec-createiterresultobject
unknown
https://saturne-ia.com/reset-password/reset/V1RhGV6StLt8New4ev4asVwYc7kFaXaO3MXEjtt1
217.160.0.90
https://github.com/twbs/icons/blob/main/LICENSE)
unknown
https://saturne-ia.com/assets/vendor/boxicons/css/boxicons.min.css
217.160.0.90
https://snyk.io/vuln/SNYK-JS-LODASH-450202
unknown
https://cct.google/taggy/agent.js
unknown
https://www.skypack.dev/view/
unknown
https://tc39.es/ecma262/#sec-array.from
unknown
https://code.jquery.com/jquery-3.7.1.min.js
151.101.2.137
https://saturne-ia.com/assets/vendor/quill/quill.min.js
217.160.0.90
https://developer.mozilla.org/en-US/docs/Web/API/CanvasRenderingContext2D.drawImage
unknown
https://tc39.es/ecma262/#sec-array.prototype.findIndex
unknown
https://turbo.hotwired.dev/handbook/building#working-with-script-elements
unknown
https://saturne-ia.com/assets/css/style.css
217.160.0.90
https://github.com/fengyuanchen/cropper/issues/476
unknown
https://github.com/zloirock/core-js/issues/1130
unknown
https://tc39.es/ecma262/#sec-symbol.prototype.description
unknown
https://github.com/zloirock/core-js/blob/v3.38.1/LICENSE
unknown
https://tc39.es/ecma262/#sec-array.prototype.map
unknown
https://tc39.es/ecma262/#sec-array.prototype.indexof
unknown
https://quilljs.com/
unknown
https://tc39.es/ecma262/#sec-tolength
unknown
https://tc39.es/ecma262/#sec-array.prototype-
unknown
https://tc39.es/ecma262/#sec-object.getownpropertysymbols
unknown
https://ckeditor.com/docs/ckeditor4/latest/guide/dev_errors.html#
unknown
https://github.com/mathiasbynens/String.prototype.at
unknown
https://saturne-ia.com/build/vendors-node_modules_symfony_stimulus-bridge_dist_index_js-node_modules_chart_js_dist_chart_e-7c92e7.js
217.160.0.90
https://github.com/firebase/firebase-js-sdk/issues/2590
unknown
https://tc39.es/ecma262/#sec-IsHTMLDDA-internal-slot
unknown
https://tc39.es/ecma262/#sec-array.prototype.foreach
unknown
https://tc39.es/ecma262/#sec-string.prototype.trimstart
unknown
https://github.com/zloirock/core-js/issues/677
unknown
https://tc39.es/ecma262/#sec-symbol.for
unknown
https://tc39.es/ecma262/#sec-json.stringify
unknown
https://github.com/Microsoft/TypeScript-wiki/blob/master/Breaking-Changes.md#extending-built-ins-lik
unknown
https://github.com/WICG/indexed-db-observers)
unknown
https://tc39.es/ecma262/#sec-createunmappedargumentsobject
unknown
https://tc39.es/ecma262/#sec-lengthofarraylike
unknown
https://tc39.es/ecma262/#sec-IsHTMLDDA-internal-slot-aec
unknown
https://tc39.es/ecma262/#sec-iscallable
unknown
https://github.com/zloirock/core-js/issues/1128
unknown
https://tc39.es/ecma262/#sec-object.getownpropertydescriptors
unknown
https://code.google.com/p/v8/issues/detail?id=687
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
code.jquery.com
151.101.2.137
cdn.skypack.dev
104.26.13.82
url.usb.m.mimecastprotect.com
170.10.150.15
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
216.58.206.36
fp2e7a.wpc.phicdn.net
192.229.221.95
saturne-ia.com
217.160.0.90

IPs

IP
Domain
Country
Malicious
216.58.206.36
www.google.com
United States
192.168.2.5
unknown
unknown
170.10.150.15
url.usb.m.mimecastprotect.com
United States
151.101.2.137
code.jquery.com
United States
217.160.0.90
saturne-ia.com
Germany
239.255.255.250
unknown
Reserved
104.26.13.82
cdn.skypack.dev
United States
151.101.194.137
unknown
United States
104.26.12.82
unknown
United States

DOM / HTML

URL
Malicious
https://saturne-ia.com/reset-password/reset