IOC Report
https://google.lt/amp/taerendil.online.fr/gpfv9cqYcuejGaVElbEvNcI6wCkeo

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (32012)
dropped
Chrome Cache Entry: 102
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (846)
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (65270)
dropped
Chrome Cache Entry: 105
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 106
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 107
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 108
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 109
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 110
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 111
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 112
Web Open Font Format (Version 2), TrueType, length 37808, version 1.0
downloaded
Chrome Cache Entry: 113
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 114
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 115
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 116
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 117
PNG image data, 1200 x 1200, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 118
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 119
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 120
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 121
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 122
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 123
Unicode text, UTF-8 text, with very long lines (15469)
downloaded
Chrome Cache Entry: 124
Web Open Font Format (Version 2), TrueType, length 39836, version 1.0
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (2606)
downloaded
Chrome Cache Entry: 126
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 127
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 128
Unicode text, UTF-8 text, with very long lines (15469)
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (65371)
downloaded
Chrome Cache Entry: 130
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 131
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 132
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 133
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 134
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 135
HTML document, Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 136
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (51679), with no line terminators
dropped
Chrome Cache Entry: 138
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 139
Web Open Font Format (Version 2), TrueType, length 38600, version 1.0
downloaded
Chrome Cache Entry: 140
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 141
PNG image data, 3200 x 1224, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (11460)
downloaded
Chrome Cache Entry: 143
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (32033)
downloaded
Chrome Cache Entry: 145
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 146
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 147
ASCII text, with very long lines (32033)
dropped
Chrome Cache Entry: 148
PNG image data, 1200 x 1200, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 149
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (32030)
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (32012)
downloaded
Chrome Cache Entry: 152
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 153
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 154
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 155
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 156
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (20087)
downloaded
Chrome Cache Entry: 158
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (32030)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (65270)
downloaded
Chrome Cache Entry: 161
Web Open Font Format (Version 2), TrueType, length 37320, version 1.0
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (20087)
dropped
Chrome Cache Entry: 76
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 77
PNG image data, 3200 x 1224, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 78
Web Open Font Format (Version 2), TrueType, length 37876, version 1.0
downloaded
Chrome Cache Entry: 79
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 80
PNG image data, 3200 x 1224, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 81
Web Open Font Format (Version 2), TrueType, length 37100, version 1.0
downloaded
Chrome Cache Entry: 82
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 83
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (19512)
downloaded
Chrome Cache Entry: 85
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 86
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 87
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 88
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 89
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 90
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (51679), with no line terminators
downloaded
Chrome Cache Entry: 92
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 93
PNG image data, 3200 x 1224, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 94
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 95
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 96
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 97
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 98
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (5254)
downloaded
There are 78 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2504 --field-trial-handle=2484,i,6327027691492919552,13260781465317734570,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://google.lt/amp/taerendil.online.fr/gpfv9cqYcuejGaVElbEvNcI6wCkeo"

URLs

Name
IP
Malicious
https://google.lt/amp/taerendil.online.fr/gpfv9cqYcuejGaVElbEvNcI6wCkeo
malicious
https://www.lhv.ee/noortepank-tesla-fg-et.svg
91.224.189.34
https://www.lhv.ee/resources/styles/bootstrap.min.css
91.224.189.34
https://www.lhv.ee/resources/scripts/bootstrap.min.js
91.224.189.34
https://investor.lhv.ee/et/
unknown
https://www.lhv.ee/assets/images/elements/app-store-et.svg
91.224.189.34
https://www.lhv.ee/resources/scripts/swiper.min.js
91.224.189.34
https://www.lhv.ee/et
https://www.lhv.ee/assets/images/headers/noortepank-tesla-fg-et.svg
91.224.189.34
https://www.lhv.ee/assets/fonts/500cb60b-8895-4dfc-aea6-47ee4c4da6ac.woff2
91.224.189.34
https://www.lhv.ee/resources/styles/owl.carousel.min.css
91.224.189.34
https://www.lhv.ee/assets/images/headers/ukraina-esileht-m.svg
91.224.189.34
https://sketch.com
unknown
https://caiotapereading.com.br/SIrSE4slm/NVGyiKtv.php
216.172.172.72
https://www.lhv.ee/assets/fonts/1a14dcac-7c9e-471c-8039-33c730f871f2.woff2
91.224.189.34
https://www.lhv.ee/assets/images/headers/esileht_pension_mees_fg_2024.11.svg
91.224.189.34
https://www.lhv.ee/assets/fonts/2192a26c-de1c-4c50-88d1-e5136033c15a.woff2
91.224.189.34
https://www.lhv.ee/resources/scripts/moment.min.js
91.224.189.34
https://www.lhv.ee/assets/images/elements/play-video.svg
91.224.189.34
https://www.lhv.ee/auth/ibank
91.224.189.34
https://www.lhv.ee/resources/scripts/jquery.magnific-popup.min.js
91.224.189.34
https://www.lhv.ee/index/index.cfm?l3=et&id=10661
91.224.189.34
https://www.lhv.ee/assets/images/headers/ml_bg.svg
91.224.189.34
https://www.lhv.ee/script.js?v=20112024
91.224.189.34
https://www.lhv.ee/assets/fonts/d9122e8d-bf26-4f1c-bab9-c06599397b59.woff2
91.224.189.34
https://www.lhv.ee/b/public/consent
91.224.189.34
https://github.com/OwlCarousel2/OwlCarousel2/blob/master/LICENSE)
unknown
https://www.lhv.ee/resources/styles/swiper.min.css
91.224.189.34
https://www.lhv.ee/assets/images/elements/mobile-arrow-down.svg
91.224.189.34
https://www.lhv.ee/assets/images/elements/arrow-bold-16.svg
91.224.189.34
http://getbootstrap.com)
unknown
https://www.google.lt/amp/taerendil.online.fr/gpfv9cqYcuejGaVElbEvNcI6wCkeo
172.217.19.163
https://www.lhv.ee/assets/images/icons/small/q.svg
91.224.189.34
https://www.lhv.ee/resources/scripts/jquery-3.1.1.min.js
91.224.189.34
https://soundcloud.com/lhvpodcast/18092024-nadal-turgudel-saksamaa-majandus-langeb-ja-hiina-pensioni
unknown
https://fast.fonts.net/t/1.css?apiType=css&projectid=5966243c-757c-4cf2-a5da-1ec17207d611
104.16.40.28
https://www.lhv.ee/assets/images/icons/small/search.svg
91.224.189.34
https://fp.lhv.ee/?locale=et
unknown
https://www.lhv.ee/assets/images/elements/blog.svg
91.224.189.34
https://soundcloud.com/lhvpodcast
unknown
https://www.lhv.ee/assets/images/icons/small/fb.svg
91.224.189.34
https://www.lhv.ee/assets/images/icons/small/insta.svg
91.224.189.34
https://www.lhv.ee/assets/images/headers/noortepank-tesla-bg.svg
91.224.189.34
https://www.lhv.ee/assets/images/headers/palkyle_bg_2024.svg
91.224.189.34
https://www.lhv.ee/assets/images/elements/checkbox.svg
91.224.189.34
https://caiotapereading.com.br/SIrSE4slm/fjnb1k9sjcn5xhyu/exit.php?client_id=lI8BrP1iGkrwnaG8h9SDdwSwpaq9sh7Lzr0fsLkqVCMoB3kwFJoaGmskW194eO00&action=exit
216.172.172.72
https://www.lhv.ee/style.css?v=21112024
91.224.189.34
https://www.lhv.ee/assets/images/icons/small/soundcloud.svg
91.224.189.34
https://www.lhv.ee/resources/styles/owl.theme.default.min.css
91.224.189.34
https://www.lhv.ee/assets/images/elements/mobile-close-black.svg
91.224.189.34
http://dimsemenov.com/plugins/magnific-popup/
unknown
http://www.bohemiancoding.com/sketch
unknown
http://www.idangero.us/swiper/
unknown
https://status.lhv.ee/
unknown
https://lhv.teamdash.com/p/job/jp2Ve0dp/tule-meile
unknown
https://www.lhv.ee/assets/images/headers/ml_fg.png
91.224.189.34
https://caiotapereading.com.br/SIrSE4slm/fjnb1k9sjcn5xhyu/index.php?fvXy5ob6I6kZ3SCD=wWWpZoY2Lpqojl4wuIiVvhMEfafI1k0d2vI7fnddR62IpFzHYAdGEWvw8LGxiwN4
216.172.172.72
https://www.lhv.ee/assets/images/lhv-logo.svg
91.224.189.34
https://www.lhv.ee/resources/styles/font.min.css
91.224.189.34
http://taerendil.online.fr/gpfv9cqYcuejGaVElbEvNcI6wCkeo
212.27.63.101
https://www.lhv.ee/assets/images/headers/palkyle_fg_et_2024.png
91.224.189.34
https://www.lhv.ee/assets/fonts/198fd78b-3655-4768-89c4-31caf65ea363.woff2
91.224.189.34
https://caiotapereading.com.br/jHO4glsleO38qrXCR2UJ
216.172.172.72
https://www.lhv.ee/resources/scripts/owl.carousel.min.js
91.224.189.34
https://www.lhv.ee/assets/images/elements/read.svg
91.224.189.34
https://www.lhv.ee/assets/images/icons/small/youtube.svg
91.224.189.34
https://www.lhv.ee/assets/images/elements/google-play-et.svg
91.224.189.34
https://www.instagram.com/lhvpank/
unknown
https://www.lhv.ee/assets/images/headers/esileht_pension_mees_bg_2024.11.svg
91.224.189.34
https://www.lhv.ee/assets/images/icons/illustrative/kypsis-circle.svg
91.224.189.34
https://www.lhv.ee/assets/images/elements/huawei-et.svg
91.224.189.34
https://www.lhv.ee/assets/images/favicon.png
91.224.189.34
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://investor.lhv.ee/et
unknown
https://soundcloud.com/lhvpodcast/25092024-nadal-turgudel-kas-balti-borsil-on-allahindlused
unknown
https://fp.lhv.ee/academy?locale=et
unknown
https://www.lhv.ee/assets/images/headers/eften_thumb.png
91.224.189.34
https://www.lhv.ee/assets/fonts/5393f1cf-e069-4466-bb37-f26f99fb4cf7.woff2
91.224.189.34
https://fp.lhv.ee/balticanalysis?locale=et
unknown
https://www.lhv.ee/resources/styles/magnific-popup.min.css
91.224.189.34
There are 69 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
perso101-g5.free.fr
212.27.63.101
static.zdassets.com
216.198.54.3
www.lhv.ee
91.224.189.34
fast.fonts.net
104.16.40.28
www.google.com
142.250.181.100
www.google.lt
172.217.19.163
caiotapereading.com.br
216.172.172.72
google.lt
172.217.17.35
taerendil.online.fr
unknown

IPs

IP
Domain
Country
Malicious
172.217.19.163
www.google.lt
United States
192.168.2.6
unknown
unknown
91.224.189.34
www.lhv.ee
Estonia
142.250.181.100
www.google.com
United States
212.27.63.101
perso101-g5.free.fr
France
239.255.255.250
unknown
Reserved
216.172.172.72
caiotapereading.com.br
United States
104.16.40.28
fast.fonts.net
United States

DOM / HTML

URL
Malicious
https://www.lhv.ee/et
https://www.lhv.ee/et
https://www.lhv.ee/et
https://www.lhv.ee/et
https://www.lhv.ee/et