IOC Report
http://docs-wltconnect.gitbook.io/us-en

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:49:06 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:49:06 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:49:06 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:49:06 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Jan 15 23:49:06 2025, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (16368), with no line terminators
dropped
Chrome Cache Entry: 110
ASCII text, with very long lines (9795), with no line terminators
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (13929), with no line terminators
dropped
Chrome Cache Entry: 112
ASCII text, with very long lines (20725)
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (515), with no line terminators
dropped
Chrome Cache Entry: 114
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (13109), with no line terminators
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 117
ASCII text, with very long lines (8549), with no line terminators
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (15593)
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (15089), with no line terminators
downloaded
Chrome Cache Entry: 120
Unicode text, UTF-8 text, with very long lines (37755), with no line terminators
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (15089), with no line terminators
dropped
Chrome Cache Entry: 122
JSON data
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (13109), with no line terminators
dropped
Chrome Cache Entry: 124
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 125
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (13929), with no line terminators
downloaded
Chrome Cache Entry: 128
Unicode text, UTF-8 text, with very long lines (65531), with no line terminators
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 130
ASCII text, with very long lines (15593)
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (9162)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (20350)
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (40456), with no line terminators
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (9162)
dropped
Chrome Cache Entry: 135
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (20350)
downloaded
Chrome Cache Entry: 139
Unicode text, UTF-8 text, with very long lines (18312), with no line terminators
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (6588), with no line terminators
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (5170), with no line terminators
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (16368), with no line terminators
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (34901), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (515), with no line terminators
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (1473), with no line terminators
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (14351), with no line terminators
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (20292)
dropped
Chrome Cache Entry: 150
Web Open Font Format (Version 2), TrueType, length 48556, version 1.0
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (1473), with no line terminators
dropped
Chrome Cache Entry: 152
ASCII text, with very long lines (6588), with no line terminators
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (6028), with no line terminators
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 155
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 156
Unicode text, UTF-8 text, with very long lines (18312), with no line terminators
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (20292)
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (14351), with no line terminators
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (8549), with no line terminators
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (6028), with no line terminators
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (20725)
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (40456), with no line terminators
dropped
Chrome Cache Entry: 163
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 165
ISO Media, AVIF Image
dropped
Chrome Cache Entry: 166
JSON data
dropped
Chrome Cache Entry: 167
Unicode text, UTF-8 text, with very long lines (37755), with no line terminators
dropped
Chrome Cache Entry: 168
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 169
HTML document, Unicode text, UTF-8 text, with very long lines (27954)
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (1928), with no line terminators
downloaded
Chrome Cache Entry: 171
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 32x32, components 3
dropped
Chrome Cache Entry: 172
ASCII text, with very long lines (5170), with no line terminators
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (28629), with no line terminators
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (63243)
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (65536), with no line terminators
dropped
There are 64 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2376 --field-trial-handle=2232,i,8778734680026656708,5545421188915152602,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://docs-wltconnect.gitbook.io/us-en"

URLs

Name
IP
Malicious
http://docs-wltconnect.gitbook.io/us-en
malicious
https://docs-wltconnect.gitbook.io/us-en/~gitbook/icon?size=small&theme=light
104.18.40.47
malicious
https://docs-wltconnect.gitbook.io/us-en/~gitbook/icon?size=small
unknown
malicious
https://docs-wltconnect.gitbook.io/us-en/~gitbook/ogimage/wxxWjjWfmO55dBjsreJu
unknown
malicious
https://docs-wltconnect.gitbook.io/us-en/~gitbook/icon?size=small&theme=dark
unknown
malicious
https://docs-wltconnect.gitbook.io/us-en
malicious
https://docs-wltconnect.gitbook.io/us-en/~gitbook/icon?size=small&theme=light
unknown
malicious
https://ka-p.fontawesome.com/releases/v6.6.0/svgs/regular/chevron-down.svg?v=2&token=a463935e93)
unknown
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/(content)/layout-e6f4ef7988da3dc2.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/5579-d5bbcfe5159dd700.js
172.64.146.167
https://tailwindcss.com
unknown
https://docs-wltconnect.gitbook.io/~gitbook/image?url=https%3A%2F%2Fdocs-wltconnect.gitbook.io%2Fus-
unknown
https://docs-wltconnect.gitbook.io/~gitbook/image?url=https%3A%2F%2Fdocs-wltconnect.gitbook.io%2Fus-en%2F%7Egitbook%2Ficon%3Fsize%3Dmedium%26theme%3Dlight&width=32&dpr=1&quality=100&sign=8b9120cd&sv=2
104.18.40.47
https://static.gitbook.com/_next/static/chunks/985-b5382d422b631066.js
172.64.146.167
https://static.gitbook.com/_next/static/css/95b358fb5c9305a3.css
172.64.146.167
https://static.gitbook.com/_next/static/css/09a5087aafb66ce5.css
172.64.146.167
https://static.gitbook.com/_next/static/chunks/8146-f6230584f5872f71.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/6150-57a79db9099e4be8.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/5458-66e2d52dd3e63bda.js
172.64.146.167
https://ka-p.fontawesome.com/releases/v6.6.0/svgs/regular/hashtag.svg?v=2&token=a463935e93);mask
unknown
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/layout-94a14cf6cf8a949a.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/webpack-a98f722a22f193c8.js
172.64.146.167
https://o1000929.ingest.sentry.io/api/4506619977269248/envelope/?sentry_key=6c85ab3639c4352deebd6996c011428d&sentry_version=7&sentry_client=sentry.javascript.browser%2F8.35.0
34.120.195.249
https://app.gitbook.com/__session?proposed=57569763-f5ad-4992-a31f-2aea09f5f52fR
104.18.41.89
https://static.gitbook.com/_next/static/media/a34f9d1faa5f3315-s.woff2
172.64.146.167
https://static.gitbook.com/_next/static/chunks/8510-4f0e00669f717e7c.js
172.64.146.167
https://static.gitbook.com/_next/static/css/3c8be925ae209ad0.css
172.64.146.167
https://ka-p.fontawesome.com/releases/v6.6.0/svgs/regular/bars.svg?v=2&token=a463935e93);mask-re
unknown
https://static.gitbook.com/_next/static/chunks/8325-d6fa305dcbcc6289.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/app/global-error-fab162c712b230e2.js
172.64.146.167
https://static.gitbook.com/_next/static/css/c8716d6751d02050.css
172.64.146.167
https://ka-p.fontawesome.com/releases/v6.6.0/svgs/regular/block-quote.svg?v=2&token=a463935e93);
unknown
https://static.gitbook.com/_next/static/chunks/1dd3208c-89f4beb5fcc5eacd.js
172.64.146.167
https://static.gitbook.com/_next/static/css/2567c890e467e55b.css
172.64.146.167
https://static.gitbook.com/_next/static/chunks/5543-4437716da9af0924.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/7695-5c620a347955c734.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/1281-8b933b50fa4af5db.js
172.64.146.167
https://api.gitbook.com/v1/orgs/L9ACUolpgOFNHw9w3y8J/sites/site_FL4Vx/insights/events
104.18.41.89
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/error-1b08ba6bae9c0706.js
172.64.146.167
https://docs.gitbook.com/published-documentation/custom-domain/configure-dns#are-you-using-cloudflar
unknown
https://static.gitbook.com/_next/static/chunks/5860-881c4499362df9bc.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/polyfills-42372ed130431b0a.js
unknown
https://static.gitbook.com/_next/static/chunks/95-368c0a9d707cd4e9.js
172.64.146.167
https://static.gitbook.com/_next/static/css/c10c8d24c1bdf135.css
172.64.146.167
https://ka-p.fontawesome.com/releases/v6.6.0/svgs/regular/magnifying-glass.svg?v=2&token=a463935
unknown
https://static.gitbook.com/_next/static/css/4af9aafd612346fe.css
172.64.146.167
https://static.gitbook.com/_next/static/css/3e9ba8594a4a680c.css
172.64.146.167
https://static.gitbook.com/_next/static/chunks/559-e30b0dfedc67c8e5.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/9028-799f06fb8d158937.js
172.64.146.167
https://1215575405-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1JuCxRvvgw5fhnUuOreu%2Fuploads%2FM7901qO5jNVJ0s2S4NYu%2Fconnect%20wallet%20git.avif?alt=media&token=63d602c1-3806-4ae5-83f0-3b1ab1f7ad82
172.64.147.209
https://static.gitbook.com/_next/static/chunks/main-app-4efbcc5bbe6ce3d8.js
172.64.146.167
https://static.gitbook.com/_next/static/chunks/4850-1d8521c88b91421c.js
172.64.146.167
https://static.gitbook.com/_next/static/css/7c5e34302cacdff9.css
172.64.146.167
https://static.gitbook.com/_next/static/css/e138f6ef6b7a7bbe.css
172.64.146.167
https://static.gitbook.com/_next/static/chunks/app/middleware/(site)/(content)/%5B%5B...pathname%5D%5D/page-064189368c515e1f.js
172.64.146.167
https://reown.com/
unknown
https://www.gitbook.com/?utm_source=content&utm_medium=trademark&utm_campaign=1JuCxRvvgw5fhn
unknown
https://static.gitbook.com/~gitbook/static/icons/svgs/custom-icons/gitbook.svg?v=2);mask-repeat:no-r
unknown
There are 47 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
docs-wltconnect.gitbook.io
104.18.40.47
malicious
www.google.com
142.250.186.100
1215575405-files.gitbook.io
172.64.147.209
app.gitbook.com
104.18.41.89
static.gitbook.com
172.64.146.167
api.gitbook.com
104.18.41.89
o1000929.ingest.sentry.io
34.120.195.249

IPs

IP
Domain
Country
Malicious
104.18.40.47
docs-wltconnect.gitbook.io
United States
malicious
104.18.41.89
app.gitbook.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
172.64.146.167
static.gitbook.com
United States
239.255.255.250
unknown
Reserved
142.250.186.100
www.google.com
United States
172.64.147.209
1215575405-files.gitbook.io
United States
34.120.195.249
o1000929.ingest.sentry.io
United States

DOM / HTML

URL
Malicious
https://docs-wltconnect.gitbook.io/us-en
malicious
https://docs-wltconnect.gitbook.io/us-en
malicious
https://docs-wltconnect.gitbook.io/us-en
malicious