IOC Report
http://logincrypto-crypto.gitbook.io/us

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:42:58 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:42:58 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:42:58 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:42:58 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:42:58 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (16368), with no line terminators
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (9795), with no line terminators
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (13929), with no line terminators
dropped
Chrome Cache Entry: 105
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (20725)
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (515), with no line terminators
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (13109), with no line terminators
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (8549), with no line terminators
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (15593)
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (15089), with no line terminators
downloaded
Chrome Cache Entry: 112
Unicode text, UTF-8 text, with very long lines (37755), with no line terminators
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (15089), with no line terminators
dropped
Chrome Cache Entry: 114
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (13109), with no line terminators
dropped
Chrome Cache Entry: 116
ISO Media, AVIF Image
dropped
Chrome Cache Entry: 117
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (13929), with no line terminators
downloaded
Chrome Cache Entry: 119
Unicode text, UTF-8 text, with very long lines (65531), with no line terminators
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 121
ASCII text, with very long lines (15593)
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (9162)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (20350)
dropped
Chrome Cache Entry: 124
ASCII text, with very long lines (40456), with no line terminators
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (9162)
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 127
HTML document, Unicode text, UTF-8 text, with very long lines (23453)
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (20350)
downloaded
Chrome Cache Entry: 130
Unicode text, UTF-8 text, with very long lines (18312), with no line terminators
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (6588), with no line terminators
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (5170), with no line terminators
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (16368), with no line terminators
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (34901), with no line terminators
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (515), with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (1473), with no line terminators
downloaded
Chrome Cache Entry: 139
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (14351), with no line terminators
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (20292)
dropped
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 48556, version 1.0
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (1473), with no line terminators
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (6588), with no line terminators
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (6028), with no line terminators
downloaded
Chrome Cache Entry: 146
Unicode text, UTF-8 text, with very long lines (18312), with no line terminators
dropped
Chrome Cache Entry: 147
ASCII text, with very long lines (20292)
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (14351), with no line terminators
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (8549), with no line terminators
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (6028), with no line terminators
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (20725)
dropped
Chrome Cache Entry: 152
ASCII text, with very long lines (40456), with no line terminators
dropped
Chrome Cache Entry: 153
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 155
PNG image data, 32 x 32, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 156
Unicode text, UTF-8 text, with very long lines (37755), with no line terminators
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (1928), with no line terminators
downloaded
Chrome Cache Entry: 158
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (5170), with no line terminators
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (28629), with no line terminators
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (63243)
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (65536), with no line terminators
dropped
There are 58 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1980 --field-trial-handle=1992,i,10123655658756750285,11558820566922631875,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://logincrypto-crypto.gitbook.io/us"

URLs

Name
IP
Malicious
http://logincrypto-crypto.gitbook.io/us
malicious
https://logincrypto-crypto.gitbook.io/us
malicious
https://static.gitbook.com/_next/static/chunks/7695-5c620a347955c734.js
104.18.41.89
https://logincrypto-crypto.gitbook.io/~gitbook/image?url=https%3A%2F%2F4257142164-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FZfnPqNJC14j6GpRQcy3S%252Fuploads%252FxLPPFJHkSfFwSfHtthXc%252Fcrypto%2520Exchange.JPG%3Falt%3Dmedia%26token%3Dc816124a-0cae-43a8-bba0-9d82bac3190e&width=768&dpr=1&quality=100&sign=29ed9cfc&sv=2
104.18.40.47
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/(content)/layout-e6f4ef7988da3dc2.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/5579-d5bbcfe5159dd700.js
104.18.41.89
https://tailwindcss.com
unknown
https://a.nel.cloudflare.com/report/v4?s=uyPVAnLO18%2FJWdjVYLrqCqjkVVUf%2FdlLYkDyrRX%2BzRKnx8dpYqyE34DwHKxGRwkejzpbln4NgkHegrb4jwpBa1lLB87hdRGYbQzPp7vqiFP5E5PnSYDZO%2B4N3WZzbVXsF5Ky
35.190.80.1
https://static.gitbook.com/_next/static/chunks/985-b5382d422b631066.js
104.18.41.89
https://4257142164-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZfnPqNJC14j6GpRQcy3S%2Ficon%2Fk2YaF5SCsYAaFqmJBLrn%2FCRYPTO%20LOGO.png?alt=media&token=198f9d0a-f1a6-43d4-86c6-feade3f80142
172.64.147.209
https://static.gitbook.com/_next/static/chunks/1281-8b933b50fa4af5db.js
104.18.41.89
https://static.gitbook.com/_next/static/css/95b358fb5c9305a3.css
104.18.41.89
https://static.gitbook.com/_next/static/css/09a5087aafb66ce5.css
104.18.41.89
https://static.gitbook.com/_next/static/chunks/8146-f6230584f5872f71.js
104.18.41.89
https://a.nel.cloudflare.com/report/v4?s=iXWKwl3HNIcawIlikd7aUcihlvnXK8rMFqjzTgTaHsDm8hBuJADUio2UMchQKoLNTYlMo4s0%2B9usfyp9trqFt%2FffXcLCyfKVLdE8vmHaAAtnPuZl%2FLYyOXDfbwxFizUoyjN%2F
35.190.80.1
https://static.gitbook.com/_next/static/chunks/6150-57a79db9099e4be8.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/error-1b08ba6bae9c0706.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/5458-66e2d52dd3e63bda.js
104.18.41.89
https://docs.gitbook.com/published-documentation/custom-domain/configure-dns#are-you-using-cloudflar
unknown
https://static.gitbook.com/_next/static/chunks/5860-881c4499362df9bc.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/95-368c0a9d707cd4e9.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/layout-94a14cf6cf8a949a.js
104.18.41.89
https://static.gitbook.com/_next/static/css/c10c8d24c1bdf135.css
104.18.41.89
https://static.gitbook.com/_next/static/chunks/webpack-a98f722a22f193c8.js
104.18.41.89
https://static.gitbook.com/_next/static/media/a34f9d1faa5f3315-s.woff2
104.18.41.89
https://static.gitbook.com/_next/static/chunks/8510-4f0e00669f717e7c.js
104.18.41.89
https://static.gitbook.com/_next/static/css/3c8be925ae209ad0.css
104.18.41.89
https://www.gitbook.com/?utm_source=content&utm_medium=trademark&utm_campaign=ZfnPqNJC14j6Gp
unknown
https://static.gitbook.com/_next/static/css/4af9aafd612346fe.css
104.18.41.89
https://static.gitbook.com/_next/static/css/3e9ba8594a4a680c.css
104.18.41.89
https://static.gitbook.com/_next/static/chunks/559-e30b0dfedc67c8e5.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/8325-d6fa305dcbcc6289.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/app/global-error-fab162c712b230e2.js
104.18.41.89
https://static.gitbook.com/_next/static/css/c8716d6751d02050.css
104.18.41.89
https://static.gitbook.com/_next/static/chunks/9028-799f06fb8d158937.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/1dd3208c-89f4beb5fcc5eacd.js
104.18.41.89
https://static.gitbook.com/_next/static/css/2567c890e467e55b.css
104.18.41.89
https://static.gitbook.com/_next/static/chunks/main-app-4efbcc5bbe6ce3d8.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/4850-1d8521c88b91421c.js
104.18.41.89
https://static.gitbook.com/_next/static/css/7c5e34302cacdff9.css
104.18.41.89
https://4257142164-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZfnPqNJC14j6G
unknown
https://logincrypto-crypto.gitbook.io/~gitbook/image?url=https%3A%2F%2F4257142164-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FZfnPqNJC14j6GpRQcy3S%252Ficon%252Fk2YaF5SCsYAaFqmJBLrn%252FCRYPTO%2520LOGO.png%3Falt%3Dmedia%26token%3D198f9d0a-f1a6-43d4-86c6-feade3f80142&width=32&dpr=1&quality=100&sign=cda7febe&sv=2
104.18.40.47
https://static.gitbook.com/_next/static/css/e138f6ef6b7a7bbe.css
104.18.41.89
https://static.gitbook.com/_next/static/chunks/5543-4437716da9af0924.js
104.18.41.89
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/(content)/%5B%5B...pathname%5D%5D/page-064189368c515e1f.js
104.18.41.89
https://static.gitbook.com/~gitbook/static/icons/svgs/custom-icons/gitbook.svg?v=2);mask-repeat:no-r
unknown
There are 35 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
logincrypto-crypto.gitbook.io
104.18.40.47
malicious
a.nel.cloudflare.com
35.190.80.1
4257142164-files.gitbook.io
172.64.147.209
www.google.com
142.250.185.68
static.gitbook.com
104.18.41.89
api.gitbook.com
104.18.41.89

IPs

IP
Domain
Country
Malicious
104.18.40.47
logincrypto-crypto.gitbook.io
United States
malicious
142.250.185.68
www.google.com
United States
104.18.41.89
static.gitbook.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
172.64.146.167
unknown
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States
172.64.147.209
4257142164-files.gitbook.io
United States

DOM / HTML

URL
Malicious
https://logincrypto-crypto.gitbook.io/us
malicious