IOC Report
https://zxptech.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\2a3f141a-28cc-4d26-bae1-301f24f6468e.tmp
ASCII text, with very long lines (4997)
dropped
C:\Users\user\Downloads\551d2d85-eb49-4812-8dd1-b6431c10b1ba.tmp
ASCII text, with very long lines (4997)
dropped
C:\Users\user\Downloads\Unconfirmed 368662.crdownload (copy)
ASCII text, with very long lines (4997)
dropped
C:\Users\user\Downloads\Unconfirmed 950610.crdownload (copy)
ASCII text, with very long lines (4997)
dropped
Chrome Cache Entry: 136
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 137
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 138
ASCII text, with very long lines (5658)
downloaded
Chrome Cache Entry: 139
data
downloaded
Chrome Cache Entry: 140
HTML document, ASCII text, with very long lines (13452), with no line terminators
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (5933)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (664)
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (1801), with no line terminators
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (18993), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (44087)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (60535)
downloaded
Chrome Cache Entry: 149
PNG image data, 1024 x 451, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (10747), with no line terminators
downloaded
Chrome Cache Entry: 151
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 152
Unicode text, UTF-8 text, with very long lines (26748)
downloaded
Chrome Cache Entry: 153
Unicode text, UTF-8 text, with very long lines (8189)
dropped
Chrome Cache Entry: 154
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 155
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 156
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 157
JSON data
dropped
Chrome Cache Entry: 158
ISO Media, Apple QuickTime movie, Apple QuickTime (.MOV/QT)
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (974), with no line terminators
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (545)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (5212)
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (5902)
downloaded
Chrome Cache Entry: 163
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=1, orientation=upper-left], progressive, precision 8, 2560x1439, components 3
dropped
Chrome Cache Entry: 164
PNG image data, 1024 x 451, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 165
Web Open Font Format (Version 2), TrueType, length 50296, version 1.0
downloaded
Chrome Cache Entry: 166
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 167
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 168
Unicode text, UTF-8 text, with very long lines (54783)
dropped
Chrome Cache Entry: 169
ASCII text
downloaded
Chrome Cache Entry: 170
JPEG image data, JFIF standard 1.01, resolution (DPI), density 240x240, segment length 16, progressive, precision 8, 2560x1707, components 3
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (5501), with no line terminators
downloaded
Chrome Cache Entry: 172
PNG image data, 300 x 233, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 173
data
downloaded
Chrome Cache Entry: 174
data
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 176
ASCII text, with very long lines (10054)
downloaded
Chrome Cache Entry: 177
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 2560x1708, components 3
downloaded
Chrome Cache Entry: 178
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, progressive, precision 8, 500x500, components 3
dropped
Chrome Cache Entry: 179
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 180
ASCII text, with very long lines (6219)
downloaded
Chrome Cache Entry: 181
Unicode text, UTF-8 text, with very long lines (7210), with no line terminators
downloaded
Chrome Cache Entry: 182
ASCII text, with very long lines (4272)
downloaded
Chrome Cache Entry: 183
Web Open Font Format (Version 2), TrueType, length 98472, version 1.0
downloaded
Chrome Cache Entry: 184
JSON data
downloaded
Chrome Cache Entry: 185
JPEG image data, JFIF standard 1.01, resolution (DPI), density 240x240, segment length 16, progressive, precision 8, 1024x683, components 3
downloaded
Chrome Cache Entry: 186
ASCII text, with very long lines (483)
downloaded
Chrome Cache Entry: 187
GIF image data, version 87a, 1 x 1
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (1320)
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (19975)
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (27162), with no line terminators
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (872)
downloaded
Chrome Cache Entry: 192
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (934), with no line terminators
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (1801), with no line terminators
dropped
Chrome Cache Entry: 196
ASCII text, with very long lines (934), with no line terminators
dropped
Chrome Cache Entry: 197
ASCII text, with very long lines (3264)
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (3720)
dropped
Chrome Cache Entry: 199
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 200
ASCII text, with very long lines (5933)
downloaded
Chrome Cache Entry: 201
ASCII text, with very long lines (7256), with no line terminators
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (4181)
downloaded
Chrome Cache Entry: 203
ASCII text, with very long lines (42864)
downloaded
Chrome Cache Entry: 204
data
downloaded
Chrome Cache Entry: 205
ASCII text, with very long lines (5212)
dropped
Chrome Cache Entry: 206
data
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (24870)
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (318), with no line terminators
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (42864)
dropped
Chrome Cache Entry: 210
JPEG image data, JFIF standard 1.01, aspect ratio, density 72x72, segment length 16, progressive, precision 8, 1024x451, components 3
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (24021)
dropped
Chrome Cache Entry: 212
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 213
ASCII text, with very long lines (1468), with no line terminators
dropped
Chrome Cache Entry: 214
ASCII text, with very long lines (5658)
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (6219)
dropped
Chrome Cache Entry: 216
data
downloaded
Chrome Cache Entry: 217
JPEG image data, JFIF standard 1.01, aspect ratio, density 72x72, segment length 16, progressive, precision 8, 1024x451, components 3
dropped
Chrome Cache Entry: 218
HTML document, Unicode text, UTF-8 text, with very long lines (8856)
downloaded
Chrome Cache Entry: 219
data
downloaded
Chrome Cache Entry: 220
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 221
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 222
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 223
C++ source, ASCII text
dropped
Chrome Cache Entry: 224
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (15752)
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (24021)
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (645), with no line terminators
downloaded
Chrome Cache Entry: 228
ASCII text, with very long lines (3720)
downloaded
Chrome Cache Entry: 229
ASCII text, with very long lines (545)
dropped
Chrome Cache Entry: 230
Unicode text, UTF-8 text, with very long lines (8189)
downloaded
Chrome Cache Entry: 231
ASCII text, with very long lines (5658)
downloaded
Chrome Cache Entry: 232
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, progressive, precision 8, 500x500, components 3
downloaded
Chrome Cache Entry: 233
ASCII text, with very long lines (21556)
dropped
Chrome Cache Entry: 234
ASCII text, with very long lines (545)
downloaded
Chrome Cache Entry: 235
ASCII text, with very long lines (18291)
dropped
Chrome Cache Entry: 236
data
downloaded
Chrome Cache Entry: 237
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (9889)
downloaded
Chrome Cache Entry: 239
Web Open Font Format (Version 2), TrueType, length 39608, version 1.0
downloaded
Chrome Cache Entry: 240
JPEG image data, JFIF standard 1.01, resolution (DPI), density 240x240, segment length 16, progressive, precision 8, 1024x683, components 3
dropped
Chrome Cache Entry: 241
ASCII text, with very long lines (15752)
dropped
Chrome Cache Entry: 242
ASCII text, with very long lines (1468), with no line terminators
downloaded
Chrome Cache Entry: 243
ASCII text, with very long lines (13479)
downloaded
Chrome Cache Entry: 244
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 2560x1708, components 3
dropped
Chrome Cache Entry: 245
ASCII text, with very long lines (15310)
downloaded
Chrome Cache Entry: 246
HTML document, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 247
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 248
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, progressive, precision 8, 500x500, components 3
dropped
Chrome Cache Entry: 249
ASCII text, with very long lines (24870)
dropped
Chrome Cache Entry: 250
ASCII text, with very long lines (13479)
dropped
Chrome Cache Entry: 251
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 252
ASCII text, with very long lines (4272)
dropped
Chrome Cache Entry: 253
ASCII text, with very long lines (872)
dropped
Chrome Cache Entry: 254
Web Open Font Format (Version 2), TrueType, length 37828, version 1.0
downloaded
Chrome Cache Entry: 255
PNG image data, 910 x 1024, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 256
data
downloaded
Chrome Cache Entry: 257
ASCII text
downloaded
Chrome Cache Entry: 258
ASCII text, with CRLF, CR line terminators
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (16214)
downloaded
Chrome Cache Entry: 260
Unicode text, UTF-8 text, with very long lines (5142), with no line terminators
downloaded
Chrome Cache Entry: 261
ASCII text, with very long lines (7305), with no line terminators
dropped
Chrome Cache Entry: 262
Web Open Font Format (Version 2), TrueType, length 78196, version 331.-31261
downloaded
Chrome Cache Entry: 263
data
dropped
Chrome Cache Entry: 264
Unicode text, UTF-8 text, with very long lines (38582), with no line terminators
dropped
Chrome Cache Entry: 265
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=1, orientation=upper-left], progressive, precision 8, 2560x1439, components 3
downloaded
Chrome Cache Entry: 266
ASCII text, with very long lines (10260), with no line terminators
downloaded
Chrome Cache Entry: 267
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 268
GIF image data, version 87a, 1 x 1
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (5293)
dropped
Chrome Cache Entry: 270
ASCII text, with very long lines (1320)
dropped
Chrome Cache Entry: 271
ASCII text, with very long lines (753)
downloaded
Chrome Cache Entry: 272
C++ source, ASCII text
downloaded
Chrome Cache Entry: 273
GIF image data, version 87a, 1 x 1
downloaded
Chrome Cache Entry: 274
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, progressive, precision 8, 500x500, components 3
downloaded
Chrome Cache Entry: 275
data
downloaded
Chrome Cache Entry: 276
ASCII text, with very long lines (11480), with no line terminators
downloaded
Chrome Cache Entry: 277
ASCII text, with very long lines (12512), with no line terminators
dropped
Chrome Cache Entry: 278
PNG image data, 1024 x 356, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 279
ASCII text, with very long lines (12512), with no line terminators
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (44087)
dropped
Chrome Cache Entry: 281
JPEG image data, JFIF standard 1.01, resolution (DPI), density 240x240, segment length 16, progressive, precision 8, 2560x1707, components 3
dropped
Chrome Cache Entry: 282
ASCII text, with very long lines (21556)
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (4256)
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (15310)
dropped
Chrome Cache Entry: 285
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 286
data
downloaded
Chrome Cache Entry: 287
ASCII text, with very long lines (29559), with no line terminators
downloaded
Chrome Cache Entry: 288
data
downloaded
Chrome Cache Entry: 289
PNG image data, 1024 x 356, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 290
ASCII text, with very long lines (560)
downloaded
Chrome Cache Entry: 291
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 292
ASCII text
downloaded
Chrome Cache Entry: 293
ASCII text, with very long lines (18291)
downloaded
Chrome Cache Entry: 294
ASCII text, with very long lines (57884)
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 296
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 297
ASCII text, with very long lines (5293)
downloaded
Chrome Cache Entry: 298
Unicode text, UTF-8 text, with very long lines (38582), with no line terminators
downloaded
Chrome Cache Entry: 299
Unicode text, UTF-8 text, with very long lines (54783)
downloaded
Chrome Cache Entry: 300
ASCII text, with very long lines (11480), with no line terminators
dropped
Chrome Cache Entry: 301
HTML document, ASCII text, with very long lines (13452), with no line terminators
downloaded
Chrome Cache Entry: 302
PNG image data, 300 x 233, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 303
PNG image data, 910 x 1024, 8-bit/color RGB, non-interlaced
downloaded
There are 163 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2308 --field-trial-handle=2264,i,10744145677410267763,17831737128887353639,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://zxptech.com"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5088 --field-trial-handle=2264,i,10744145677410267763,17831737128887353639,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://zxptech.com
malicious
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LeTnvIpAAAAACHvLYKw71swo_8NUdyrA_zUv9Hu&co=aHR0cHM6Ly96eHB0ZWNoLmNvbTo0NDM.&hl=en&v=pPK749sccDmVW_9DSeTMVvh2&size=invisible&cb=h0mvgv56onjl
142.250.181.100
https://jqueryui.com
unknown
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://pluralism.themancav.com/7vTdvZXWvtSK1ueP1sTxn52duZ/UxeyF2MbtjsLWr5/U1rPVjYK51YSDuMWIn7HbzIk=
62.60.154.114
https://api.jqueryui.com/position/
unknown
https://recruitingbypaycor.com/career/CareerHome.action?clientId=8a7883d088796678018896ea69d212f6
unknown
https://yoast.com/wordpress/plugins/seo/
unknown
https://www.google.com/recaptcha/api.js?render=6LeTnvIpAAAAACHvLYKw71swo_8NUdyrA_zUv9Hu&ver=3.0
unknown
https://ahs.8a1.myftpupload.com/#organization
unknown
https://github.com/zloirock/core-js
unknown
https://support.google.com/recaptcha#6262736
unknown
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://api.w.org/
unknown
https://pluralism.themancav.com/Z/RrshzWCNsD1lGAX8RHkBSADsJFzkneBpoP2wmTNNQOmA6QS9YZkF3WG9NFiQ==
62.60.154.114
https://ahs.8a1.myftpupload.com/#website
unknown
https://www.google.com/js/bg/W8CPGdzYmlcjn--3_xeFmudIk8Wv0vupGU9Bdr5QE-g.js
142.250.181.100
http://www.smartmenus.org/
unknown
https://pluralism.themancav.com/thCm080yxbrSMpzhjiCK8cVkw6OUKoS/137Cuth3+aDCcdKglDyEoMIynOKaMtTxjDLQstV50rnUZ87xyw==
62.60.154.114
https://gmpg.org/xfn/11
unknown
https://schema.org
unknown
https://img1.wsimg.com/signals/js/clients/scc-c2/scc-c2.min.js
unknown
https://www.google.com/recaptcha/api2/webworker.js?hl=en&v=pPK749sccDmVW_9DSeTMVvh2
142.250.181.100
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://swiperjs.com
unknown
https://callnowbutton.com)
unknown
https://cloud.google.com/contact
unknown
https://fontawesome.com/license/free
unknown
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://fontawesome.com
unknown
https://jquery.org/license
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://pluralism.themancav.com/jwCAr/Qi48brIrqdtzCsjfx05d+tOqLD7m7kxuFn39z7YfTcrSyi3Psiup2jIvKNtSLzwONz48n7cfGN8g==
62.60.154.114
https://img1.wsimg.com/traffic-assets/js/tccl-tti.min.js
unknown
https://www.google.com/recaptcha/api.js?render=6LeTnvIpAAAAACHvLYKw71swo_8NUdyrA_zUv9Hu&ver=3.0
142.250.181.100
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://goo.gl/maps/kAtRJABtdu9AgdaF6
unknown
https://pluralism.themancav.com/1XCTXq5S8DexUqls7UC/fKYE9i73SrEytB73N7sXzC2hEect91yxLaFSqW35UuF871LrOr4C8jeiBfU6vBPrMaAJ9DWwB7Ej
62.60.154.114
https://ahs.8a1.myftpupload.com/?s=
unknown
https://support.google.com/recaptcha/#6175971
unknown
http://www.videolan.org/x264.html
unknown
https://ahs.8a1.myftpupload.com/#/schema/logo/image/
unknown
https://ahs.8a1.myftpupload.com/
unknown
https://www.google.com/recaptcha/api2/
unknown
https://www.gstatic.c..?/recaptcha/releases/pPK749sccDmVW_9DSeTMVvh2/recaptcha__.
unknown
https://support.google.com/recaptcha
unknown
https://pluralism.themancav.com/R17MaTx8rwAjfPZbf27gSzQqqRllZO4IKT+gED07kw83fOBLNXz2SzUwvRsrJ7YNJTLuFA==
62.60.154.114
https://github.com/zloirock/core-js/blob/v3.32.0/LICENSE
unknown
There are 37 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ahs.8a1.myftpupload.com
132.148.52.3
zxptech.com
160.153.0.33
www.google.com
142.250.181.100
pluralism.themancav.com
62.60.154.114
img1.wsimg.com
unknown
csp.secureserver.net
unknown
events.api.secureserver.net
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
malicious
142.250.181.100
www.google.com
United States
239.255.255.250
unknown
Reserved
160.153.0.33
zxptech.com
United States
132.148.52.3
ahs.8a1.myftpupload.com
United States
62.60.154.114
pluralism.themancav.com
Iran (ISLAMIC Republic Of)

DOM / HTML

URL
Malicious
https://zxptech.com/
https://zxptech.com/
https://zxptech.com/
https://zxptech.com/
https://zxptech.com/#
https://zxptech.com/#