IOC Report
http://whatsapp.accounts.help/?p=905075711936b356

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 48
gzip compressed data, from Unix, original size modulo 2^32 193
downloaded
Chrome Cache Entry: 49
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 50
HTML document, ASCII text
downloaded
Chrome Cache Entry: 51
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 52
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 53
Unicode text, UTF-8 text, with very long lines (65023)
downloaded
Chrome Cache Entry: 54
HTML document, ASCII text
downloaded
Chrome Cache Entry: 55
ASCII text, with very long lines (65465)
dropped
Chrome Cache Entry: 56
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 57
ASCII text, with very long lines (65465)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2264,i,5448973385861853987,8131865266549427277,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://whatsapp.accounts.help/?p=905075711936b356"

URLs

Name
IP
Malicious
http://whatsapp.accounts.help/?p=905075711936b356
malicious
http://whatsapp.accounts.help/?p=905075711936b356
malicious
http://whataspp.accounts.help/v/static/media/logo.84b41bb05bb756ed0b40e595f2f555a9.svg
84.247.131.30
http://whatsapp.accounts.help/favicon.ico
185.61.154.30
https://getbootstrap.com/)
unknown
http://whataspp.accounts.help/v/static/css/main.48b9f51d.css
84.247.131.30
http://whataspp.accounts.help/v/favicon.ico
84.247.131.30
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
http://whataspp.accounts.help/favicon.ico
84.247.131.30
http://whataspp.accounts.help/v/static/js/main.4b1babab.js
84.247.131.30
http://whataspp.accounts.help/v/?p=905075711936b356

Domains

Name
IP
Malicious
whatsapp.accounts.help
185.61.154.30
malicious
whataspp.accounts.help
84.247.131.30
www.google.com
142.250.185.68

IPs

IP
Domain
Country
Malicious
185.61.154.30
whatsapp.accounts.help
United Kingdom
malicious
142.250.185.68
www.google.com
United States
239.255.255.250
unknown
Reserved
192.168.2.7
unknown
unknown
84.247.131.30
whataspp.accounts.help
Norway

DOM / HTML

URL
Malicious
http://whatsapp.accounts.help/?p=905075711936b356
http://whataspp.accounts.help/v/?p=905075711936b356