IOC Report
https://identity.eu.my-clay.com/Account/CompleteRegistration?code=CfDJ8KgkDTOKMMpOuP36p3Dozxt8PELhFtKv7XhGiLvUJb65B4gsgrZAJNeoWOl3%2bJqjFC0z2PgNNrBPIYyDQpCLYYktywk8FL8riSS1Gw9JoQjzsJeXeEGLQPLN93pvJbRNrEaprcXkfbiWItEC6wUTL8%2bUI3JeJ18XbphkqGM9o3eFYb5fspQpTOcpN9%2fgGTMKuaFzVmBdnIyLH8B%2fLvMz8bqGONRUa%

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 18:41:32 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 18:41:32 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 18:41:32 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 18:41:32 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 18:41:32 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (6983), with no line terminators
dropped
Chrome Cache Entry: 121
ASCII text, with very long lines (11742)
dropped
Chrome Cache Entry: 122
ASCII text
dropped
Chrome Cache Entry: 123
PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 124
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 125
PNG image data, 41 x 41, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (61816)
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (65457)
dropped
Chrome Cache Entry: 129
PNG image data, 41 x 41, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (12505)
dropped
Chrome Cache Entry: 131
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 132
Web Open Font Format (Version 2), TrueType, length 129484, version 1.0
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (65468)
downloaded
Chrome Cache Entry: 134
JSON data
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 136
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 137
Unicode text, UTF-8 text, with very long lines (43805)
downloaded
Chrome Cache Entry: 138
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 139
PNG image data, 41 x 41, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (65453)
downloaded
Chrome Cache Entry: 141
HTML document, ASCII text, with very long lines (30706)
dropped
Chrome Cache Entry: 142
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 143
Unicode text, UTF-8 text, with very long lines (47124), with NEL line terminators
dropped
Chrome Cache Entry: 144
Unicode text, UTF-8 text, with very long lines (47124), with NEL line terminators
downloaded
Chrome Cache Entry: 145
Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (1621)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65468)
dropped
Chrome Cache Entry: 148
Web Open Font Format (Version 2), TrueType, length 234260, version 1.0
downloaded
Chrome Cache Entry: 149
Unicode text, UTF-8 text, with very long lines (64979), with no line terminators
downloaded
Chrome Cache Entry: 150
ASCII text
downloaded
Chrome Cache Entry: 151
Web Open Font Format (Version 2), TrueType, length 220536, version 1.0
downloaded
Chrome Cache Entry: 152
ASCII text
downloaded
Chrome Cache Entry: 153
Unicode text, UTF-8 text, with very long lines (64791)
downloaded
Chrome Cache Entry: 154
PNG image data, 55 x 44, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 155
Unicode text, UTF-8 text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 156
PNG image data, 41 x 41, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 157
ASCII text
dropped
Chrome Cache Entry: 158
HTML document, Unicode text, UTF-8 text, with very long lines (11857)
downloaded
Chrome Cache Entry: 159
Web Open Font Format (Version 2), TrueType, length 14140, version 1.0
downloaded
Chrome Cache Entry: 160
Unicode text, UTF-8 text, with very long lines (64142), with no line terminators
downloaded
Chrome Cache Entry: 161
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 162
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 163
JSON data
dropped
Chrome Cache Entry: 164
ASCII text, with very long lines (6983), with no line terminators
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (432)
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (61816)
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (11742)
downloaded
Chrome Cache Entry: 169
Unicode text, UTF-8 text, with very long lines (64992), with no line terminators
downloaded
Chrome Cache Entry: 170
PNG image data, 5652 x 15, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (60050)
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (60050)
dropped
Chrome Cache Entry: 173
ASCII text, with very long lines (61395)
downloaded
Chrome Cache Entry: 174
PNG image data, 41 x 41, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 175
ASCII text, with very long lines (49996)
downloaded
Chrome Cache Entry: 176
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 177
Unicode text, UTF-8 text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 178
TrueType Font data, 15 tables, 1st "FFTM", 14 names, Macintosh, Copyright (c) 2018, Gurpreet Kaur Balgir1shared-iconsiconsFontForge 2.0 : shared-icons : 23-7-20
downloaded
Chrome Cache Entry: 179
ASCII text
downloaded
Chrome Cache Entry: 180
ASCII text
dropped
Chrome Cache Entry: 181
ASCII text, with very long lines (61395)
dropped
Chrome Cache Entry: 182
PNG image data, 55 x 44, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 183
JSON data
dropped
Chrome Cache Entry: 184
TrueType Font data, 18 tables, 1st "GDEF", 26 names, Macintosh, Copyright 2011 Google Inc. All Rights Reserved.RobotoRegularVersion 2.137; 2017Roboto-RegularRob
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (65453)
dropped
Chrome Cache Entry: 186
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 187
PNG image data, 435 x 151, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 188
HTML document, Unicode text, UTF-8 text, with very long lines (11857)
dropped
Chrome Cache Entry: 189
ASCII text, with very long lines (432)
dropped
Chrome Cache Entry: 190
Web Open Font Format, TrueType, length 9552, version 1.0
downloaded
Chrome Cache Entry: 191
MS Windows icon resource - 3 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 192
JSON data
downloaded
Chrome Cache Entry: 193
Unicode text, UTF-8 text, with very long lines (64791)
dropped
Chrome Cache Entry: 194
Unicode text, UTF-8 text, with very long lines (64945), with no line terminators
downloaded
Chrome Cache Entry: 195
PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 196
ASCII text, with very long lines (12505)
downloaded
Chrome Cache Entry: 197
Unicode text, UTF-8 text, with very long lines (45262)
downloaded
Chrome Cache Entry: 198
PNG image data, 5652 x 15, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 199
ASCII text, with very long lines (49996)
dropped
Chrome Cache Entry: 200
PNG image data, 41 x 41, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 201
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 202
TrueType Font data, 18 tables, 1st "GDEF", 26 names, Macintosh, Copyright 2011 Google Inc. All Rights Reserved.RobotoBoldRoboto BoldVersion 2.137; 2017Roboto-Bo
downloaded
Chrome Cache Entry: 203
PNG image data, 435 x 151, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (1621)
dropped
There are 82 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2304 --field-trial-handle=2236,i,14419739948207854976,17419969883120276566,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://identity.eu.my-clay.com/Account/CompleteRegistration?code=CfDJ8KgkDTOKMMpOuP36p3Dozxt8PELhFtKv7XhGiLvUJb65B4gsgrZAJNeoWOl3%2bJqjFC0z2PgNNrBPIYyDQpCLYYktywk8FL8riSS1Gw9JoQjzsJeXeEGLQPLN93pvJbRNrEaprcXkfbiWItEC6wUTL8%2bUI3JeJ18XbphkqGM9o3eFYb5fspQpTOcpN9%2fgGTMKuaFzVmBdnIyLH8B%2fLvMz8bqGONRUa%2b4n5ZxQZjpAMETBM05PT8wJDX5x%2fItYEfQcxQ%3d%3d&clientId=cbe74aaf-5932-4749-b07e-9d26c8bb0d6b&productId=a5fda6d4-6817-40f1-8635-4131db3054cb"

URLs

Name
IP
Malicious
https://identity.eu.my-clay.com/Account/CompleteRegistration?code=CfDJ8KgkDTOKMMpOuP36p3Dozxt8PELhFtKv7XhGiLvUJb65B4gsgrZAJNeoWOl3%2bJqjFC0z2PgNNrBPIYyDQpCLYYktywk8FL8riSS1Gw9JoQjzsJeXeEGLQPLN93pvJbRNrEaprcXkfbiWItEC6wUTL8%2bUI3JeJ18XbphkqGM9o3eFYb5fspQpTOcpN9%2fgGTMKuaFzVmBdnIyLH8B%2fLvMz8bqGONRUa%2b4n5ZxQZjpAMETBM05PT8wJDX5x%2fItYEfQcxQ%3d%3d&clientId=cbe74aaf-5932-4749-b07e-9d26c8bb0d6b&productId=a5fda6d4-6817-40f1-8635-4131db3054cb
https://ipinfo.io/missingauth
unknown
http://fontawesome.io
unknown
http://baris.aydinoglu.info)
unknown
https://web.archive.org/web/20180602074607/https://daneden.me/2011/12/14/putting-up-with-androids-bu
unknown
https://github.com/zloirock/core-js
unknown
https://paulirish.com/demo/inline-svg
unknown
https://developer.mozilla.org/en-US/docs/Web/CSS/filter
unknown
https://stackoverflow.com/questions/3952009/defer-attribute-chrome#answer-3982619
unknown
http://www.wikidata.org/entity/Q312
unknown
https://ipinfo.io/?callback=jQuery37105484807738369033_1736970097837&_=1736970097838
34.117.59.81
https://developer.mozilla.org/en/docs/HTML/Using_the_application_cache
unknown
https://www.youtube.com/user/Apple
unknown
http://github.com/Modernizr/Modernizr/issues/1182
unknown
http://www.apache.org/licenses/LICENSE-2.0Copyright
unknown
https://fontawesome.com/license/free
unknown
https://fontawesome.com
unknown
http://canjs.com/
unknown
http://schema.org
unknown
http://srufaculty.sru.edu/david.dailey/svg/newstuff/clipPath4.svg
unknown
https://bugs.chromium.org/p/chromium/issues/detail?id=129004
unknown
https://www.linkedin.com/company/apple
unknown
https://css-tricks.com/almanac/properties/a/appearance/
unknown
https://developer.mozilla.org/en-US/docs/Web/CSS/-moz-appearance
unknown
https://github.com/Modernizr/Modernizr/issues/648
unknown
http://purl.eligrey.com/github/classList.js/blob/master/classList.js
unknown
https://html.spec.whatwg.org/multipage/interaction.html#contenteditable
unknown
https://openjsf.org/
unknown
https://developer.mozilla.org/en-US/docs/Web/API/Clipboard_API
unknown
https://www.twitter.com/Apple
unknown
http://yepnopejs.com.
unknown
https://developer.mozilla.org/en-US/docs/Web/API/Clipboard
unknown
http://jedwatson.github.io/classnames
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://github.com/zloirock/core-js/blob/v3.39.0/LICENSE
unknown
https://lodash.com/
unknown
http://barisaydinoglu.github.com/Detectizr/
unknown
https://developer.mozilla.org/en-US/docs/Web/API/Window/scrollTo
unknown
https://codepen.io/eltonmesquita/full/GgXbvo/
unknown
https://getbootstrap.com/)
unknown
http://fontawesome.io/license
unknown
https://dev.w3.org/csswg/css3-conditional/#the-csssupportsrule-interface
unknown
http://underscorejs.org/LICENSE
unknown
https://jquery.org/license
unknown
https://developers.whatwg.org/links.html#downloading-resources
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://feross.org/opensource
unknown
https://html.spec.whatwg.org/multipage/semantics.html#attr-style-scoped
unknown
https://jquery.com/
unknown
http://schema.org/
unknown
https://developer.mozilla.org/en-US/docs/Web/API/HTMLCanvasElement.toDataURL
unknown
https://identity.eu.my-clay.com/Account/CompleteRegistration?code=CfDJ8KgkDTOKMMpOuP36p3Dozxt8PELhFtKv7XhGiLvUJb65B4gsgrZAJNeoWOl3%2bJqjFC0z2PgNNrBPIYyDQpCLYYktywk8FL8riSS1Gw9JoQjzsJeXeEGLQPLN93pvJbRNrEaprcXkfbiWItEC6wUTL8%2bUI3JeJ18XbphkqGM9o3eFYb5fspQpTOcpN9%2fgGTMKuaFzVmBdnIyLH8B%2fLvMz8bqGONRUa%2b4n5ZxQZjpAMETBM05PT8wJDX5x%2fItYEfQcxQ%3d%3d&clientId=cbe74aaf-5932-4749-b07e-9d26c8bb0d6b&productId=a5fda6d4-6817-40f1-8635-4131db3054cb
https://w3c.github.io/FileAPI/#constructorBlob
unknown
http://github.com/RobinHerbots/jquery.inputmask
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://lodash.com/license
unknown
https://drafts.fxtf.org/compositing-1/
unknown
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
unknown
https://preactjs.com
unknown
http://feross.org
unknown
https://dev.w3.org/csswg/css3-conditional/#at-supports
unknown
There are 50 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ipinfo.io
34.117.59.81
www.google.com
142.250.184.228
is1-ssl.mzstatic.com
unknown
identity.eu.my-clay.com
unknown

IPs

IP
Domain
Country
Malicious
34.117.59.81
ipinfo.io
United States
239.255.255.250
unknown
Reserved
142.250.184.228
www.google.com
United States

DOM / HTML

URL
Malicious
https://identity.eu.my-clay.com/Account/CompleteRegistration?code=CfDJ8KgkDTOKMMpOuP36p3Dozxt8PELhFtKv7XhGiLvUJb65B4gsgrZAJNeoWOl3%2bJqjFC0z2PgNNrBPIYyDQpCLYYktywk8FL8riSS1Gw9JoQjzsJeXeEGLQPLN93pvJbRNrEaprcXkfbiWItEC6wUTL8%2bUI3JeJ18XbphkqGM9o3eFYb5fspQpTOcpN9%2fgGTMKuaFzVmBdnIyLH8B%2fLvMz8bqGONRUa%2b4n5ZxQZjpAMETBM05PT8wJDX5x%2fItYEfQcxQ%3d%3d&clientId=cbe74aaf-5932-4749-b07e-9d26c8bb0d6b&productId=a5fda6d4-6817-40f1-8635-4131db3054cb
https://appleid.apple.com/auth/authorize?client_id=com.saltoks&redirect_uri=https%3A%2F%2Fidentity.eu.my-clay.com%2Ffederation%2Fapple%2Fsignin&response_type=code%20id_token&scope=openid%20name%20email&response_mode=form_post&nonce=638725669239955805.NWViZTZiMWQtYzA5Yi00ZDk3LTk3NDMtYWNiODk2NDhkMmIwMzg1NDA4NDMtNTcxYS00MjE3LWIwYmItNWE0ZjY3MDIwNWIz&state=CfDJ8KgkDTOKMMpOuP36p3DozxsFursk5PSsorWoh4tyne5_El5GnOJMHRff52ZWRNh7ApdIOwqJ1v7hCfPbbsNdVy5N0U12cFwLOTqqPeN_JvcUuIgRyZ_6k76ImUXlkyh_ii-r8bzpKxl9CyUE9RLIvmPtySOjY9jIx7F8NhmyClqaWPTyZN5bHJdK9AvO1NzqODYj4m4HYY2ApOyf3Z8tiauKcZdcLpDAY7D_LHvdenTu95LofVh-yaU1Qp6O-WPNy0isWN_yakoqSJfSBbvRndBVOPRiNweDU9tzlpbPB8barcLK_4ld4fDrciRP1pmoz9lBw4jd9LanCNkFhHi0BW6slnSCSyUmj22Z7wKRCU0NcKy9oDz5XmDFoLiASRBLcpK5fHFlXurU5OiipIhzHTXrHVmtyaQNI88grRWHNvi95RC_HL-8fBtd4Iql1FYVez7o-3qstxutuT5Ug6J4tEk63JVn-2mwnn3dZa8tonUxG2OSSkcjFmIvN2O54b__Iw
https://appleid.apple.com/auth/authorize?client_id=com.saltoks&redirect_uri=https%3A%2F%2Fidentity.eu.my-clay.com%2Ffederation%2Fapple%2Fsignin&response_type=code%20id_token&scope=openid%20name%20email&response_mode=form_post&nonce=638725669239955805.NWViZTZiMWQtYzA5Yi00ZDk3LTk3NDMtYWNiODk2NDhkMmIwMzg1NDA4NDMtNTcxYS00MjE3LWIwYmItNWE0ZjY3MDIwNWIz&state=CfDJ8KgkDTOKMMpOuP36p3DozxsFursk5PSsorWoh4tyne5_El5GnOJMHRff52ZWRNh7ApdIOwqJ1v7hCfPbbsNdVy5N0U12cFwLOTqqPeN_JvcUuIgRyZ_6k76ImUXlkyh_ii-r8bzpKxl9CyUE9RLIvmPtySOjY9jIx7F8NhmyClqaWPTyZN5bHJdK9AvO1NzqODYj4m4HYY2ApOyf3Z8tiauKcZdcLpDAY7D_LHvdenTu95LofVh-yaU1Qp6O-WPNy0isWN_yakoqSJfSBbvRndBVOPRiNweDU9tzlpbPB8barcLK_4ld4fDrciRP1pmoz9lBw4jd9LanCNkFhHi0BW6slnSCSyUmj22Z7wKRCU0NcKy9oDz5XmDFoLiASRBLcpK5fHFlXurU5OiipIhzHTXrHVmtyaQNI88grRWHNvi95RC_HL-8fBtd4Iql1FYVez7o-3qstxutuT5Ug6J4tEk63JVn-2mwnn3dZa8tonUxG2OSSkcjFmIvN2O54b__Iw
https://iforgot.apple.com/password/verify/appleid
https://iforgot.apple.com/password/verify/appleid
https://iforgot.apple.com/password/verify/appleid