IOC Report
http://weisscryptoalert.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 22:11:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 22:11:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 22:11:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 22:11:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 22:11:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 121
ASCII text, with very long lines (5605), with no line terminators
downloaded
Chrome Cache Entry: 122
PNG image data, 759 x 174, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 123
PNG image data, 560 x 392, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 126
Unicode text, UTF-8 (with BOM) text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 128
HTML document, ASCII text, with very long lines (3579)
downloaded
Chrome Cache Entry: 129
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 130
Unicode text, UTF-8 text, with very long lines (24256), with CRLF line terminators
downloaded
Chrome Cache Entry: 131
JSON data
downloaded
Chrome Cache Entry: 136
Unicode text, UTF-8 (with BOM) text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 140
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 141
PNG image data, 69 x 24, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 144
Unicode text, UTF-8 (with BOM) text, with very long lines (709), with no line terminators
downloaded
Chrome Cache Entry: 147
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (9111)
dropped
Chrome Cache Entry: 151
GIF image data, version 89a, 560 x 392
dropped
Chrome Cache Entry: 152
GIF image data, version 89a, 560 x 392
downloaded
Chrome Cache Entry: 153
HTML document, Unicode text, UTF-8 text, with very long lines (1152), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (3172)
dropped
Chrome Cache Entry: 155
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (47694)
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (33917), with no line terminators
downloaded
Chrome Cache Entry: 159
PNG image data, 560 x 392, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 160
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (5338), with no line terminators
dropped
Chrome Cache Entry: 163
ASCII text, with very long lines (2343)
dropped
Chrome Cache Entry: 164
JSON data
downloaded
Chrome Cache Entry: 166
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (19948), with no line terminators
downloaded
Chrome Cache Entry: 169
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 173
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (1490)
downloaded
Chrome Cache Entry: 175
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 176
Unicode text, UTF-8 (with BOM) text, with very long lines (518), with CRLF line terminators
downloaded
Chrome Cache Entry: 177
HTML document, ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 178
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (3172)
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 182
JSON data
dropped
Chrome Cache Entry: 184
Unicode text, UTF-8 (with BOM) text, with very long lines (14288), with no line terminators
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (52801), with CRLF line terminators
downloaded
Chrome Cache Entry: 187
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (9019), with no line terminators
dropped
Chrome Cache Entry: 190
ASCII text, with very long lines (9198)
dropped
Chrome Cache Entry: 193
ASCII text, with very long lines (9163)
downloaded
Chrome Cache Entry: 194
Unicode text, UTF-8 (with BOM) text, with very long lines (43380), with no line terminators
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (4223), with CRLF line terminators
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (38072)
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (65409)
dropped
Chrome Cache Entry: 207
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (65292), with CRLF line terminators
downloaded
There are 49 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://weisscryptoalert.com
https://weissratings.com/
http://weisscryptoalert.com/
13.107.246.43

Domains

Name
IP
Malicious
cdn.onesignal.com
104.16.160.145
cdn.weissratings.com
104.18.239.206
onesignal.com
104.17.111.223
static.cloudflareinsights.com
104.16.79.73
www-scripts.weissratings.com
104.18.240.162
challenges.cloudflare.com
104.18.94.41
www.google.com
142.250.181.100
weissratings.com
104.18.239.206
s-part-0035.t-0009.t-msedge.net
13.107.246.63
img.onesignal.com
104.16.160.145
weisscryptoalert.com
13.107.246.43
www.woopra.com
91.134.9.54
js.monitor.azure.com
unknown
static.woopra.com
unknown
dc.services.visualstudio.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.43
weisscryptoalert.com
United States
172.217.19.206
unknown
United States
172.217.19.238
unknown
United States
104.18.240.162
www-scripts.weissratings.com
United States
13.107.246.63
s-part-0035.t-0009.t-msedge.net
United States
1.1.1.1
unknown
Australia
172.217.17.67
unknown
United States
172.217.17.78
unknown
United States
104.17.111.223
onesignal.com
United States
151.101.1.91
unknown
United States
104.18.94.41
challenges.cloudflare.com
United States
104.16.160.145
cdn.onesignal.com
United States
192.168.2.16
unknown
unknown
20.50.88.245
unknown
United States
216.58.208.227
unknown
United States
104.18.95.41
unknown
United States
142.250.181.100
www.google.com
United States
74.125.205.84
unknown
United States
142.250.181.136
unknown
United States
104.18.239.206
cdn.weissratings.com
United States
239.255.255.250
unknown
Reserved
91.134.9.54
www.woopra.com
France
104.16.79.73
static.cloudflareinsights.com
United States
There are 13 hidden IPs, click here to show them.