IOC Report
https://largeconfusion.com/bE3_VG0HP.2IlJj-PLXMBNzOJ_mQ9R0SPTU-NVnWSXkYR_RaUbkcldH-Yflgch5ia_WkFlXmenG-xpJqZr1sY_wuWvlwdx4-MzWANB5Cb_2EdFNGRHE-ZJqKWLTMJ_GObPVQlRt-STTUVVZWV_0YkZzaTbm-1dNeefkg1_EiZj3khla-Vn0oZpsqT_0sdtNuMv0-1xHyVzmAh_OCaDlEUF1-THUIRJnKd_2M1N0OUP0-tR1SUTVUk_0WaXWYJZJ-QbicZdyec_mglhkiP

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text
downloaded
Chrome Cache Entry: 101
PNG image data, 359 x 135, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 102
ASCII text
dropped
Chrome Cache Entry: 60
HTML document, ASCII text, with very long lines (327)
downloaded
Chrome Cache Entry: 61
PNG image data, 489 x 445, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 62
ASCII text
downloaded
Chrome Cache Entry: 63
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1200x1200, components 3
downloaded
Chrome Cache Entry: 64
PNG image data, 17 x 22, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 65
ASCII text
downloaded
Chrome Cache Entry: 66
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 300x300, components 3
dropped
Chrome Cache Entry: 67
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 68
Web Open Font Format (Version 2), TrueType, length 18028, version 1.589
downloaded
Chrome Cache Entry: 69
ASCII text
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (4653), with no line terminators
dropped
Chrome Cache Entry: 71
PNG image data, 68 x 68, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 72
ASCII text, with very long lines (4653), with no line terminators
downloaded
Chrome Cache Entry: 73
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 74
PNG image data, 400 x 400, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 75
PNG image data, 438 x 334, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 76
PNG image data, 438 x 334, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 77
PNG image data, 400 x 400, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 78
PNG image data, 489 x 445, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 79
ASCII text, with very long lines (65371)
downloaded
Chrome Cache Entry: 80
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 81
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 82
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 83
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 1200x1200, components 3
dropped
Chrome Cache Entry: 84
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 85
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 300x300, components 3
downloaded
Chrome Cache Entry: 86
PNG image data, 17 x 22, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 87
HTML document, ASCII text
downloaded
Chrome Cache Entry: 88
Web Open Font Format (Version 2), TrueType, length 29752, version 1.0
downloaded
Chrome Cache Entry: 89
ASCII text
dropped
Chrome Cache Entry: 90
ASCII text, with very long lines (8034), with no line terminators
downloaded
Chrome Cache Entry: 91
PNG image data, 400 x 400, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 92
PNG image data, 400 x 400, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 93
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 94
ASCII text
downloaded
Chrome Cache Entry: 95
PNG image data, 236 x 243, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 96
PNG image data, 68 x 68, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 97
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 28x28, segment length 16, baseline, precision 8, 1200x1200, components 3
downloaded
Chrome Cache Entry: 98
PNG image data, 236 x 243, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 99
PNG image data, 359 x 135, 8-bit/color RGBA, non-interlaced
downloaded
There are 34 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2428 --field-trial-handle=2368,i,4088455556186748259,1276231144463020914,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://largeconfusion.com/bE3_VG0HP.2IlJj-PLXMBNzOJ_mQ9R0SPTU-NVnWSXkYR_RaUbkcldH-Yflgch5ia_WkFlXmenG-xpJqZr1sY_wuWvlwdx4-MzWANB5Cb_2EdFNGRHE-ZJqKWLTMJ_GObPVQlRt-STTUVVZWV_0YkZzaTbm-1dNeefkg1_EiZj3khla-Vn0oZpsqT_0sdtNuMv0-1xHyVzmAh_OCaDlEUF1-THUIRJnKd_2M1N0OUP0-tR1SUTVUk_0WaXWYJZJ-QbicZdyec_mglhkiPjT-NllmNnWoF_hqZrTsAt4-OvGwQx1yZ_DAAB4CMDG-NFiGNHDIF_kKOLDMVNj-MPzQFRjSN_GUIVzWOXD-QZ5aJbncZ_0ePfTgEh3-MjzkAlzmM_joUpwqMrT-gttuYvzwN_myNzTAEBy-YDjEAFzGY_WIRJjKZLj-NNlOYPzQQ_5SYTmUQVx-ZXDYZZiaM_zcIdxeNfW-Ih2iYjWkI_mmenmo9pu-ZrWsltkuP_TwQx4yMzD-MB3CMDDEM_tGNHDIgJw-MLzMcNwON_AQ"

URLs

Name
IP
Malicious
https://largeconfusion.com/bE3_VG0HP.2IlJj-PLXMBNzOJ_mQ9R0SPTU-NVnWSXkYR_RaUbkcldH-Yflgch5ia_WkFlXmenG-xpJqZr1sY_wuWvlwdx4-MzWANB5Cb_2EdFNGRHE-ZJqKWLTMJ_GObPVQlRt-STTUVVZWV_0YkZzaTbm-1dNeefkg1_EiZj3khla-Vn0oZpsqT_0sdtNuMv0-1xHyVzmAh_OCaDlEUF1-THUIRJnKd_2M1N0OUP0-tR1SUTVUk_0WaXWYJZJ-QbicZdyec_mglhkiPjT-NllmNnWoF_hqZrTsAt4-OvGwQx1yZ_DAAB4CMDG-NFiGNHDIF_kKOLDMVNj-MPzQFRjSN_GUIVzWOXD-QZ5aJbncZ_0ePfTgEh3-MjzkAlzmM_joUpwqMrT-gttuYvzwN_myNzTAEBy-YDjEAFzGY_WIRJjKZLj-NNlOYPzQQ_5SYTmUQVx-ZXDYZZiaM_zcIdxeNfW-Ih2iYjWkI_mmenmo9pu-ZrWsltkuP_TwQx4yMzD-MB3CMDDEM_tGNHDIgJw-MLzMcNwON_AQ
https://eatcells.com/assets/img/game-tap.jpg
94.130.177.84
https://eatcells.com/land/images/background@2x.png
94.130.177.84
https://eatcells.com/assets/img/game-2048.jpg
94.130.177.84
https://eatcells.com/
unknown
https://eatcells.com/assets/img/split.png?4
94.130.177.84
https://eatcells.com/land/images/monster-02.png
94.130.177.84
https://eatcells.com/assets/img/game-floppy.jpg
94.130.177.84
https://eatcells.com/?from_land=1
https://eatcells.com/assets/js/new_main_out4.js?3512341123
94.130.177.84
https://ogar.eatcells.com/
unknown
https://eatcells.com/assets/img/eject.png?4
94.130.177.84
https://eatcells.com/skinList.txt
94.130.177.84
https://eatcells.com/api/
94.130.177.84
https://load.ocule.co.uk/script.js?key=74641aea-f924-4e70-9a40-c98d0de2a989
unknown
https://eatcells.com/land/images/monster-01.png
94.130.177.84
https://eatcells.com/assets/css/new_gallery.css
94.130.177.84
https://eatcells.com/assets/img/share
unknown
https://eatcells.com/land/images/fire.png
94.130.177.84
https://www.icone-png.com/png/22/22430.png
194.150.236.240
https://eatcells.com/assets/css/new_index.css
94.130.177.84
https://largeconfusion.com/ciG.Fjzkclz-9nkoapXqQ_9sMtTucvz-MxDyMz4AO_DCgDzENFD-IH5IMJjKc_wMNNzOkPx-ORSSZTkUd_GWtXuYPZU-FbScYd2ed_VgNhkiIjx-TlXmBnqoM_lqZrjsdtV-RvPwexUyF_WAbBUCVDH-ZFzGFHzIT_mKJLHMcNV-VP2QJRmSl_jUPVXWBXz-JZnaBb0cb_je1fDgZh0-pjWkVlXmh_JoSplqlru-StnuZvZwV_1yJzpAWBV-cD1EaF0Gt_pIQJXKlLN-aNkOlP4QT_USdTOUaVE-5X6YTZmal_acadkeZfo-WhmipjKkb_Fmln6oSpm-xrZsVt0u5_swTxnypzS-aBEC9DUEW_mGxHaIVJE-0LxMTNmOp_EQaRXShTv-NVjWVXCYa_malbGcbdF-FfOgQhTik_1kalWmxnB-ap2qdrGsJ_nuJvywZxX-FzoAPBTCV_kEZFTGQH5-OJTKgLyMO_DOAP1QNRD-VThUNVGWQ_xYZZmaUb1-ZdTeRfkgY_TicjxkNlW-Un2oNpjqM_4sJtnuJvy-axWyQz9AM_2CUD1EYFW-FHlIMJDKg_4MZNDOVPk-MRDSgTwUY_2WIX0YMZW-Qb4cNdWeM_zgMhWiMj0-YljmMn4oN_Dqkrmsctn-NvywYxzy1_vAdBXCQDm-eFmG9HuIZ_WKlLkMPNT-QP4QMRDSM_3UMVDWMX
88.85.68.219
http://getbootstrap.com)
unknown
https://eatcells.com/land/favicon.ico
94.130.177.84
https://maxcdn.bootstrapcdn.com/bootstrap/3.3.4/css/bootstrap.min.css
104.18.11.207
https://eatcells.com/landing/
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://eatcells.com/land/?token=3e5aae088d5d080cb41d85c31c4b3849
https://eatcells.com/land/css/styles.min.css?2444
94.130.177.84
https://eatcells.com/assets/img/favicon.ico?4
94.130.177.84
https://maxcdn.bootstrapcdn.com/bootstrap/3.3.4/fonts/glyphicons-halflings-regular.woff2
104.18.11.207
https://eatcells.com/assets/js/new_quadtree.js
94.130.177.84
https://eatcells.com/land/images/logo.png
94.130.177.84
https://eatcells.com/land/images/monster-03.png
94.130.177.84
There are 23 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
largeconfusion.com
88.85.68.219
eatcells.com
94.130.177.84
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
maxcdn.bootstrapcdn.com
104.18.11.207
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.185.228
www.icone-png.com
194.150.236.240
s7.addthis.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.185.228
www.google.com
United States
192.168.2.16
unknown
unknown
88.85.68.219
largeconfusion.com
Netherlands
192.168.2.4
unknown
unknown
94.130.177.84
eatcells.com
Germany
194.150.236.240
www.icone-png.com
France
104.18.11.207
maxcdn.bootstrapcdn.com
United States
239.255.255.250
unknown
Reserved

DOM / HTML

URL
Malicious
https://eatcells.com/land/?token=3e5aae088d5d080cb41d85c31c4b3849
https://eatcells.com/land/?token=3e5aae088d5d080cb41d85c31c4b3849
https://eatcells.com/land/?token=3e5aae088d5d080cb41d85c31c4b3849
https://eatcells.com/land/?token=3e5aae088d5d080cb41d85c31c4b3849
https://eatcells.com/?from_land=1