IOC Report
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1644,34356383147248551,10702149225259720885,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2000 /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=ppapi --field-trial-handle=1644,34356383147248551,10702149225259720885,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --lang=en-US --device-scale-factor=1 --ppapi-antialiased-text-enabled=1 --ppapi-subpixel-rendering-setting=1 --mojo-platform-channel-handle=3928 /prefetch:3

URLs

Name
IP
Malicious
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va
https://drive.filen.io/static/js/418.b5bed9d9.chunk.js
146.0.41.208
https://drive.filen.io/static/js/758.8a2278ed.chunk.js
146.0.41.208
https://analytics.filen.io/js/plausible.js
146.0.41.206
https://gateway.filen-2.net/v3/file/link/info
146.0.41.208
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f
146.0.41.208
https://cdn.filen.io/ht/HackTimer.js
146.0.41.207
https://drive.filen.io/static/js/main.8419430e.js
146.0.41.208
https://drive.filen.io/static/js/208.ecfb968a.chunk.js
146.0.41.208
https://drive.filen.io/static/js/32.1f5639c6.chunk.js
146.0.41.208
https://gateway.filen.io/v3/file/link/password
146.0.41.207
https://socket.filen.io/socket.io/?EIO=3&transport=websocket
146.0.41.207
https://drive.filen.io/static/media/inter-v12-latin-500.c72c72b70c82b1f4bacf.woff2
146.0.41.208
https://drive.filen.io/favicon.ico
146.0.41.208
https://drive.filen.io/webstreams.js
146.0.41.208
https://cdn.filen.io/cfg.json?noCache=1713473073206
146.0.41.207
https://cdn.filen.io/cfg.json?noCache=1713473133215
146.0.41.206
https://drive.filen.io/static/css/main.eeb9c19c.css
146.0.41.208
https://drive.filen.io/static/js/528.6d3a337a.chunk.js
146.0.41.208
https://drive.filen.io/static/js/454.d38d97fe.chunk.js
146.0.41.208
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va
https://drive.filen.io/static/js/153.93ada2fc.chunk.js
146.0.41.208
https://drive.filen.io/static/js/885.04acd75a.chunk.js
146.0.41.208
https://drive.filen.io/static/js/731.c9335a78.chunk.js
146.0.41.208
https://drive.filen.io/static/media/logo_animated.5b2a93fbda359a792c23.gif
146.0.41.208
https://drive.filen.io/static/js/273.97b75179.chunk.js
146.0.41.208
https://drive.filen.io/static/js/107.29c4b0a4.chunk.js
146.0.41.208
https://drive.filen.io/static/js/109.14cb8a71.chunk.js
146.0.41.208
https://drive.filen.io/static/js/592.ab1857e1.chunk.js
146.0.41.208
https://drive.filen.io/static/media/dark_logo.41ab3ed5c0117abdb8e47d6bac43d9ae.svg
146.0.41.208
https://analytics.filen.io/api/event
146.0.41.206
https://drive.filen.io/site.webmanifest
146.0.41.208
https://drive.filen.io/static/js/520.81de291f.chunk.js
146.0.41.208
https://drive.filen.io/swfs.js
146.0.41.208
https://drive.filen.io/static/js/827.d99a6ec2.chunk.js
146.0.41.208
https://egest.filen-4.net/de-1/filen-1013/c326ef2d-8daa-48dd-a726-0a5725d3d183/0
146.0.41.207
There are 25 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gateway.filen-2.net
146.0.41.208
analytics.filen.io
146.0.41.206
cdn.filen.io
146.0.41.207
socket.filen.io
146.0.41.207
www.google.com
142.250.176.4
drive.filen.io
146.0.41.208
gateway.filen.io
146.0.41.207
egest.filen-4.net
146.0.41.207

IPs

IP
Domain
Country
Malicious
192.168.11.20
unknown
unknown
239.255.255.250
unknown
Reserved
146.0.41.207
cdn.filen.io
Germany
146.0.41.206
analytics.filen.io
Germany
146.0.41.208
gateway.filen-2.net
Germany
142.250.176.4
www.google.com
United States

DOM / HTML

URL
Malicious
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va
https://drive.filen.io/d/86d87964-c23f-4257-ab67-1d3a6a53307f#p6azJi5gS13nDkjcLoSnKfqLeQFJ51Va