IOC Report
https://credit-bittrex.com/creditor

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 48
HTML document, ASCII text, with very long lines (2503)
downloaded
Chrome Cache Entry: 49
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 50
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 51
HTML document, ASCII text
downloaded
Chrome Cache Entry: 52
HTML document, ASCII text
dropped
Chrome Cache Entry: 53
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 54
HTML document, ASCII text
downloaded
Chrome Cache Entry: 55
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 56
HTML document, ASCII text, with very long lines (394)
dropped
Chrome Cache Entry: 57
HTML document, Unicode text, UTF-8 text, with very long lines (12845)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2188,i,8863006628045067295,9348882958572428432,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://credit-bittrex.com/creditor"

URLs

Name
IP
Malicious
https://credit-bittrex.com/creditor
malicious
https://credit-bittrex.com/creditor
172.67.150.105
malicious
https://us-bittrex.com/bankruptcy/withdrawal/chapter11/debtor/js/contracts.js
172.67.150.61
https://a.nel.cloudflare.com/report/v4?s=2jyDMb%2FV7iVu0z3YYb7JSUPuSVXTgCcrf0JTb8gEbJmRLmE%2F6NDg74LRBFFR6FJx6DMbvA%2FDXusEAywRqWc9N4ho658FerOWetbV%2BMGq3AJiJbeZibWrjLAI2dTpkLpv%2FkeLag%3D%3D
35.190.80.1
https://us-bittrex.com/favicon.ico
172.67.150.61
https://us-bittrex.com/withdrawal/
https://us-bittrex.com/bankruptcy/withdrawal/chapter11/debtor/js/main.js
172.67.150.61
https://zhu-ni-hao-yun.sh/api/authenticate
172.67.213.53
https://us-bittrex.com/withdrawal
172.67.150.61
https://us-bittrex.com/bankruptcy/withdrawal/chapter11/debtor/js/entry.js
172.67.150.61
https://credit-bittrex.com/creditor/
172.67.150.105
https://google.com
unknown
https://a.nel.cloudflare.com/report/v4?s=3KY6KE1%2BY0Knvx9Hl7WA9o0TtCt%2FG55EMz8oLXK%2Ff7B8fi0riI1WQJtRvZYdkfYhDNJns4kOGrsX0hLv2K%2FNjdCntY0%2BgRbEW3lIDKDAg7M6OTVyesoC544vnmsZ94yfZuSCVg%3D%3D
35.190.80.1
https://us-bittrex.com/bankruptcy/withdrawal/chapter11/debtor/
https://www.cloudflare.com/5xx-error-landing
unknown
There are 4 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
credit-bittrex.com
172.67.150.105
zhu-ni-hao-yun.sh
172.67.213.53
us-bittrex.com
172.67.150.61
www.google.com
172.253.63.147
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
172.67.150.105
credit-bittrex.com
United States
172.67.150.61
us-bittrex.com
United States
172.67.213.53
zhu-ni-hao-yun.sh
United States
192.168.2.17
unknown
unknown
192.168.2.16
unknown
unknown
192.168.2.4
unknown
unknown
172.253.63.147
www.google.com
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://us-bittrex.com/withdrawal/
https://us-bittrex.com/bankruptcy/withdrawal/chapter11/debtor/