IOC Report
https://sites.google.com/view/busch-vacuum/home

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 101
PNG image data, 192 x 192, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 102
Web Open Font Format (Version 2), TrueType, length 47048, version 1.0
downloaded
Chrome Cache Entry: 103
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (580)
downloaded
Chrome Cache Entry: 105
PNG image data, 93 x 72, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 106
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=10, description=Mockup image of male hands using a laptop computer and holing a smart phone both with blank white screens. Focus on the index f, manufacturer=Canon, model=Canon EOS 6D, orientation=upper-left, xresolution=141, yresolution=149, resolutionunit=2, software=Adobe Photoshop CC 2018 (Windows), datetime=2018:07:25 12:37:24], baseline, precision 8, 5472x3648, components 3
downloaded
Chrome Cache Entry: 107
ASCII text
downloaded
Chrome Cache Entry: 108
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 109
Web Open Font Format (Version 2), TrueType, length 34108, version 1.0
downloaded
Chrome Cache Entry: 110
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 111
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 112
ASCII text, with very long lines (1505)
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (2265)
downloaded
Chrome Cache Entry: 114
ASCII text, with very long lines (2056)
downloaded
Chrome Cache Entry: 115
Web Open Font Format (Version 2), TrueType, length 15744, version 1.0
downloaded
Chrome Cache Entry: 116
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 117
Web Open Font Format (Version 2), TrueType, length 20028, version 1.0
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (383)
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (1283)
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (1851)
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 74
PNG image data, 192 x 192, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 75
Web Open Font Format (Version 2), TrueType, length 45300, version 1.0
downloaded
Chrome Cache Entry: 76
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 77
PNG image data, 93 x 72, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 78
ASCII text, with very long lines (38991)
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (1163)
downloaded
Chrome Cache Entry: 81
HTML document, ASCII text
downloaded
Chrome Cache Entry: 82
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 83
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 84
HTML document, ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 85
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 86
ASCII text
downloaded
Chrome Cache Entry: 87
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=10, description=Mockup image of male hands using a laptop computer and holing a smart phone both with blank white screens. Focus on the index f, manufacturer=Canon, model=Canon EOS 6D, orientation=upper-left, xresolution=141, yresolution=149, resolutionunit=2, software=Adobe Photoshop CC 2018 (Windows), datetime=2018:07:25 12:37:24], baseline, precision 8, 5472x3648, components 3
dropped
Chrome Cache Entry: 88
PNG image data, 72 x 39, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 89
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 90
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 91
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 93
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 94
ASCII text, with very long lines (546)
downloaded
Chrome Cache Entry: 95
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 96
PNG image data, 72 x 39, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 97
HTML document, ASCII text, with very long lines (4020)
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (7043), with no line terminators
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (65536), with no line terminators
downloaded
There are 39 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2204 --field-trial-handle=1984,i,8483475906506789809,10319773719344864098,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sites.google.com/view/busch-vacuum/home

URLs

Name
IP
Malicious
https://sites.google.com/view/busch-vacuum/home
malicious
https://allmysonscom.top/21663221c08095a4839b4833d7029a6265ca72cb02785LOG21663221c08095a4839b4833d7029a6265ca72cb02786#
malicious
https://allmysonscom.top/21663221c08095a4839b4833d7029a6265ca72cb02785LOG21663221c08095a4839b4833d7029a6265ca72cb02786
malicious
https://allmysonscom.top/
malicious
https://scriptz.corp.google.com/
unknown
https://apis.google.com/js/client.js
unknown
https://allmysonscom.top/1
104.21.51.145
https://allmysonscom.top/jq/8845edfee9737b347c9bba0188b1b8f065ca72cbd90c1
104.21.51.145
https://nowlifestyle.com/redir.php?k
unknown
https://accounts.google.com/o/oauth2/iframe
unknown
https://www.google.com/log?format=json&hasfast=true
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=85474485de6744e2
104.17.3.184
https://console.developers.google.com/
unknown
https://accounts.google.com/o/oauth2/postmessageRelay
unknown
https://dataconnector.corp.google.com/:session_prefix:ui/widgetview?usegapi=1
unknown
https://nowlifestyle.com/redir.php?k=9a4e080456dabe5eebc8863cde7b1b48&url=https://allmysonscom.top
199.116.250.99
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/854744532923b0b1/1707766445864/145450f9f29a437153a4db87001c50914e532129640eb0e34670b650d28dc54a/9uVA9OYt25Qd1Gt
104.17.3.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=854744532923b0b1
104.17.3.184
https://allmysonscom.top/ASSETS/img/m_.svg
104.21.51.145
https://workspace.google.com/:session_prefix:marketplace/appfinder?usegapi=1
unknown
https://a.nel.cloudflare.com/report/v3?s=%2B0ieNGnK2w2m5tpN3e2ajxjqYTrHozX88GQL4I0FVab7sya4tNbTH1fbUAF0iBFI6WzejWyq4WOm5vTeD1o923%2BIIivGDNI8%2Fpf%2BBEEZoRPJDhUpiTDn%2F5ybzSCtCDmCZX80
35.190.80.1
https://nowlifestyle.com/redir.php?k=9a4e080456dabe5eebc8863cde7b1b48&url=https://allmysonscom.t
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/9ye9b/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://www.google.com/shopping/customerreviews/badge?usegapi=1
unknown
https://sites.google.com/view/busch-vacuum/home
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://allmysonscom.top/boot/8845edfee9737b347c9bba0188b1b8f065ca72cbd90c6
104.21.51.145
https://csp.withgoogle.com/csp/lcreport/
unknown
https://pay.google.com/gp/v/widget/save
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/85474485de6744e2/1707766453720/5819046ea238e2a8ddd561ca4d8dfc754e0e7c697e8fddbb8fc7df8ef3a52cf6/wfnc6rc2Hky3rQj
104.17.3.184
https://drive.google.com/savetodrivebutton?usegapi=1
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.3.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/85474485de6744e2/1707766453724/5MPlSsszeImzAsF
104.17.3.184
https://accounts.google.com/o/oauth2/auth
unknown
https://www.google.com/shopping/customerreviews/optin?usegapi=1
unknown
https://developers.google.com/api-client-library/javascript/reference/referencedocs
unknown
https://apis.google.com
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1536897702:1707765084:WklD56mw33U7CPv27fqqC0pnnqAIy10G1Wxmdbh_jt0/854744532923b0b1/5c8cf7413cc3963
104.17.3.184
https://a.nel.cloudflare.com/report/v3?s=kp1ImpmtQqJ%2Bje%2FJjcUwtyXyLL7Oi%2FeHWaJDd0q9S%2BfgJ18k6LAG0RbqPLdNVRh6OWrpfCm98Ff81NI8oaWjxtL1JtdInwYsrQDWBPBzxBa7Jc29tb8HO0aAV13yfbWVAuwR
35.190.80.1
https://developers.google.com/
unknown
https://domains.google.com/suggest/flow
unknown
https://support.google.com/cloudsearch/answer/6172299
unknown
https://developers.google.com/identity/gsi/web/guides/gis-migration)
unknown
https://www.google.com/url?q=https%3A%2F%2Fnowlifestyle.com%2Fredir.php%3Fk%3D9a4e080456dabe5eebc8863cde7b1b48%26url%3Dhttps%3A%2F%2Fallmysonscom.top&sa=D&sntz=1&usg=AOvVaw1wKraueWhnGr5VlpbWx2MD
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.y0xCMa4KeeI.O/m=client/rt=j/sv=1/d=1/ed=1/rs=AHpOoo8-3MGCaatZB3kdS5TpZdd-gOSBHg/cb=gapi.loaded_0?le=scs
172.253.124.100
https://sites.google.com/_/view/logImpressions?authuser=0
142.250.105.139
https://allmysonscom.top/cdn-cgi/challenge-platform/h/b/flow/ov1/262488950:1707764966:vaAlIai909zKvAhWSk_psiX7v9StSENbiBvKUScxVng/85474443ad6c4503/8c2b9e0eb6a0042
104.21.51.145
https://allmysonscom.top/o/8845edfee9737b347c9bba0188b1b8f065ca72ce4265c
104.21.51.145
https://classroom.google.com/sharewidget?usegapi=1
unknown
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
64.233.185.84
https://allmysonscom.top/cdn-cgi/challenge-platform/h/b/flow/ov1/318354221:1707764905:dMGQ1qf0ojXCyT3GkA92YDzydM_ywRIzHUqJOdKJBCE/854744798c5612da/bb407e331054714
104.21.51.145
https://allmysonscom.top/js/8845edfee9737b347c9bba0188b1b8f065ca72cbd90ca
104.21.51.145
https://developers.googleblog.com/2018/03/discontinuing-support-for-json-rpc-and.html
unknown
https://workspace.google.com/products/sites/
unknown
https://www.youtube.com/subscribe_embed?usegapi=1
unknown
https://allmysonscom.top/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=85474443ad6c4503
104.21.51.145
https://play.google.com/log?format=json&hasfast=true&authuser=0
64.233.176.139
https://allmysonscom.top/ASSETS/img/sig-op.svg
104.21.51.145
https://getbootstrap.com/)
unknown
https://allmysonscom.top/favicon.ico
104.21.51.145
https://plus.google.com
unknown
https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
unknown
https://clients3.google.com/cast/chromecast/home/widget/backdrop?usegapi=1
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1852742952:1707764992:pN_rDYEjXF1KZ4h6K2VLQ9UjW2aqmKZRx1oZcVFaw4o/85474485de6744e2/b8bef5262dabc89
104.17.3.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/854744532923b0b1/1707766445862/TL2Z-SAoYDbR0-B
104.17.3.184
https://allmysonscom.top/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=854744798c5612da
104.21.51.145
https://lh6.googleusercontent.com/fSqYar0jheoUPBYKca6aF_NSRtDkQuF_3zYDeKWst7rfzPohazcN9UFL3nOv9fXNuHhAU8TgyRRs-R1SWXu5b_Q=w16383
74.125.138.132
https://allmysonscom.top/APP-8845edfee9737b347c9bba0188b1b8f065ca72ce4261b/8845edfee9737b347c9bba0188b1b8f065ca72ce4261c
104.21.51.145
https://lh3.googleusercontent.com/uNIla_7jRBSSF3AYmFIAe6z2LT9wgy8chO3jGUsCmMSzR9r_PaqAbY4eE5z2pvW0gcPhVNOfFaVI0EEfJ0EY6-0=w16383
172.217.215.132
https://allmysonscom.top/x/8845edfee9737b347c9bba0188b1b8f065ca72ce4262d
104.21.51.145
https://allmysonscom.top
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://talkgadget.google.com/:session_prefix:talkgadget/_/widget
unknown
https://play.google.com/work/embedded/search?usegapi=1&usegapi=1
unknown
https://rapid.corp.google.com/
unknown
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1
142.250.9.138
https://families.google.com/webcreation?usegapi=1&usegapi=1
unknown
https://fonts.google.com/license/googlerestricted
unknown
https://apis.google.com/js/client.js?onload=gapiLoaded
172.253.124.100
https://clients6.google.com
unknown
There are 70 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
accounts.google.com
64.233.185.84
plus.l.google.com
172.253.124.100
sites.google.com
142.250.105.139
allmysonscom.top
104.21.51.145
fp2e7a.wpc.phicdn.net
192.229.211.108
play.google.com
64.233.176.139
challenges.cloudflare.com
104.17.2.184
www.google.com
74.125.136.103
clients.l.google.com
142.250.9.138
nowlifestyle.com
199.116.250.99
googlehosted.l.googleusercontent.com
74.125.138.132
windowsupdatebg.s.llnwi.net
69.164.42.0
clients2.google.com
unknown
lh6.googleusercontent.com
unknown
lh3.googleusercontent.com
unknown
apis.google.com
unknown
There are 7 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.253.124.100
plus.l.google.com
United States
142.250.105.132
unknown
United States
142.250.105.139
sites.google.com
United States
192.168.2.4
unknown
unknown
104.17.3.184
unknown
United States
64.233.185.84
accounts.google.com
United States
74.125.136.103
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
74.125.138.132
googlehosted.l.googleusercontent.com
United States
64.233.176.139
play.google.com
United States
172.217.215.132
unknown
United States
172.253.124.132
unknown
United States
142.250.9.138
clients.l.google.com
United States
199.116.250.99
nowlifestyle.com
United States
104.21.51.145
allmysonscom.top
United States
239.255.255.250
unknown
Reserved
173.194.219.139
unknown
United States
104.17.2.184
challenges.cloudflare.com
United States
There are 8 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://sites.google.com/view/busch-vacuum/home
malicious
https://sites.google.com/view/busch-vacuum/home
malicious
https://allmysonscom.top/21663221c08095a4839b4833d7029a6265ca72cb02785LOG21663221c08095a4839b4833d7029a6265ca72cb02786
malicious
https://allmysonscom.top/21663221c08095a4839b4833d7029a6265ca72cb02785LOG21663221c08095a4839b4833d7029a6265ca72cb02786#
malicious
https://www.google.com/url?q=https%3A%2F%2Fnowlifestyle.com%2Fredir.php%3Fk%3D9a4e080456dabe5eebc8863cde7b1b48%26url%3Dhttps%3A%2F%2Fallmysonscom.top&sa=D&sntz=1&usg=AOvVaw1wKraueWhnGr5VlpbWx2MD
https://allmysonscom.top/
https://allmysonscom.top/
https://allmysonscom.top/
https://allmysonscom.top/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/9ye9b/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/9ye9b/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/9ye9b/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/82xpu/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/82xpu/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://allmysonscom.top/21663221c08095a4839b4833d7029a6265ca72cb02785LOG21663221c08095a4839b4833d7029a6265ca72cb02786
There are 5 hidden doms, click here to show them.