IOC Report
mal attachment.html

loading gif

Files

File Path
Type
Category
Malicious
mal attachment.html
HTML document, ASCII text, with very long lines (65536), with no line terminators
initial sample
malicious
Chrome Cache Entry: 67
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 68
PNG image data, 1000 x 213, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 69
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 70
PNG image data, 1000 x 213, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 71
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
dropped
Chrome Cache Entry: 72
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 73
ASCII text, with very long lines (52592)
downloaded
Chrome Cache Entry: 74
ASCII text, with very long lines (65371)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\mal attachment.html"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2024,i,13121037808665432724,12509091682103536564,262144 /prefetch:8

URLs

Name
IP
Malicious
file:///C:/Users/user/Desktop/mal%20attachment.html
malicious
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/css/bootstrap.min.css
104.17.24.14
http://opensource.org/licenses/MIT
unknown
http://daneden.me/animate
unknown
https://upload.wikimedia.org/wikipedia/commons/thumb/9/96/Microsoft_logo_%282012%29.svg/1000px-Microsoft_logo_%282012%29.svg.png
208.80.154.240
https://cdnjs.cloudflare.com/ajax/libs/animate.css/3.5.2/animate.min.css
104.17.24.14
http://getbootstrap.com)
unknown

Domains

Name
IP
Malicious
part-0013.t-0009.t-msedge.net
13.107.213.41
cdnjs.cloudflare.com
104.17.24.14
www.google.com
74.125.136.103
upload.wikimedia.org
208.80.154.240
part-0012.t-0009.t-msedge.net
13.107.213.40

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
208.80.154.240
upload.wikimedia.org
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
192.168.2.13
unknown
unknown
13.107.213.41
part-0013.t-0009.t-msedge.net
United States
13.107.213.40
part-0012.t-0009.t-msedge.net
United States
192.168.2.14
unknown
unknown
74.125.136.103
www.google.com
United States

DOM / HTML

URL
Malicious
file:///C:/Users/user/Desktop/mal%20attachment.html
malicious