IOC Report
https://download-myproposal.xyz

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 13:51:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 13:51:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 13:51:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 13:51:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 19 13:51:46 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (3379)
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 103
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 104
JPEG image data, JFIF standard 1.01, resolution (DPI), density 141x141, segment length 16, baseline, precision 8, 1193x671, components 3
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 106
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 107
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 108
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 109
HTML document, ASCII text, with very long lines (4020)
downloaded
Chrome Cache Entry: 110
PNG image data, 48 x 99, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 112
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 113
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 114
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 115
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 116
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 117
JPEG image data, JFIF standard 1.01, resolution (DPI), density 141x141, segment length 16, baseline, precision 8, 1193x671, components 3
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (6357), with no line terminators
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 120
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 121
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 122
HTML document, ASCII text
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 124
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 125
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 127
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 81
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 82
ASCII text, with very long lines (41442)
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (7043), with no line terminators
downloaded
Chrome Cache Entry: 84
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 85
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 86
PNG image data, 48 x 99, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 87
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 88
HTML document, ASCII text, with very long lines (4020)
downloaded
Chrome Cache Entry: 89
ASCII text, with very long lines (42414)
downloaded
Chrome Cache Entry: 90
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 92
PNG image data, 280 x 60, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 93
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 94
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 95
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 96
PNG image data, 280 x 60, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 97
ASCII text, with very long lines (7043), with no line terminators
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 99
SVG Scalable Vector Graphics image
downloaded
There are 44 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://download-myproposal.xyz/
malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1984,i,6798421476443814385,7181011332723128876,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
malicious

URLs

Name
IP
Malicious
https://download-myproposal.xyz
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622852b244ddLOGd740c10c7b9cf800d441f265844201e16622852b244de
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622856c3120dLOGd740c10c7b9cf800d441f265844201e16622856c3120e
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622854c4a5f6PASd740c10c7b9cf800d441f265844201e16622854c4a5fc#
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622854c4a5f6PASd740c10c7b9cf800d441f265844201e16622854c4a5fc
malicious
https://a.nel.cloudflare.com/report/v4?s=v1etqe%2FeUqzKY9JTUw0DbtCMjExie90OZZ7aGO%2FwwCRxI%2FuZ9XNrgI%2FSKiOsizqphu6af7cDjF%2BsiZSYn7ZO9RdCm%2FJgWytFBJcCNfDIdUgGxf%2FxEoBpMELC75i6%2BRN8jTAkWwMY1fakww%3D%3D
35.190.80.1
https://download-myproposal.xyz/CAPY0ZDa2JWWTRZR3NnVThX
104.21.24.157
https://code.jquery.com/jquery-3.6.0.min.js
151.101.194.137
https://download-myproposal.xyz/o/da39f66b5a2e27a3d2620be272c1d0c06622854ed4976
104.21.24.157
https://download-myproposal.xyz/cdn-cgi/challenge-platform/h/b/rc/876db6fa6e48b0d9
104.21.24.157
https://download-myproposal.xyz/js/da39f66b5a2e27a3d2620be272c1d0c06622856c84513
104.21.24.157
https://download-myproposal.xyz/GT9a523b6384c01f89d0fdeb94066704dd6622852d32742/9a523b6384c01f89d0fdeb94066704dd6622852d32743FR9a523b6384c01f89d0fdeb94066704dd6622852d32744
104.21.24.157
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/d61b0/0x4AAAAAAAXnFLj2eYtTRdVo/auto/normal
https://download-myproposal.xyz/js/9594849f4c8cc410f167ed02945f21fe6622852b5df28
104.21.24.157
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://download-myproposal.xyz/e/da39f66b5a2e27a3d2620be272c1d0c06622854ed497d
104.21.24.157
https://a.nel.cloudflare.com/report/v4?s=7bGvqaGTQBQQaYl8qvWU0LJJ7AMYyMvOlTlOE%2B482MCgkzIQXCyG1F0%2B9KehKo7IZdbE%2B4ukHr93mg5UW8t987mbFSNm1j1HHxAKFuTkhXRPDX2wLE%2Bq76SMgpBC3DFTRbUR2gQTdnQeEA%3D%3D
35.190.80.1
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.2.184
https://download-myproposal.xyz/captcha/style.css
104.21.24.157
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/876db6fa6e48b0d9/1713538309713/IpjNlJyrfCrbFhH
104.17.2.184
https://unpkg.com/axios/dist/axios.min.js
104.17.249.203
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=876db6fa6e48b0d9
104.17.2.184
https://unpkg.com/axios@1.6.8/dist/axios.min.js
104.17.249.203
https://download-myproposal.xyz/
https://aadcdn.msauthimages.net/dbd5a2dd-n2kxueriy-dm8fhyf0anvulmvhi3kdbkkxqluuekyfc/logintenantbranding/0/bannerlogo?ts=636783560697171089
152.195.19.97
https://download-myproposal.xyz/APP-da39f66b5a2e27a3d2620be272c1d0c06622856e8261d/da39f66b5a2e27a3d2620be272c1d0c06622856e8261e
104.21.24.157
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1183773793:1713536091:FSHJzQkVJDFHD0RlA0zy6yxoebMNBS1E5kSyV2Zp_4E/876db6fa6e48b0d9/74cedd7e88826ed
104.17.2.184
https://download-myproposal.xyz/ASSETS/img/sig-op.svg
104.21.24.157
https://download-myproposal.xyz/captcha/logo.svg
104.21.24.157
https://download-myproposal.xyz/o/da39f66b5a2e27a3d2620be272c1d0c06622856e82656
104.21.24.157
https://download-myproposal.xyz/x/9594849f4c8cc410f167ed02945f21fe6622852d32723
104.21.24.157
https://download-myproposal.xyz/boot/da39f66b5a2e27a3d2620be272c1d0c06622854d0a52e
104.21.24.157
https://download-myproposal.xyz/GT656df62a1a0af0e4878b4670eecd98136622854ed496c/656df62a1a0af0e4878b4670eecd98136622854ed496dSC656df62a1a0af0e4878b4670eecd98136622854ed496e
104.21.24.157
https://getbootstrap.com/)
unknown
https://download-myproposal.xyz/jq/da39f66b5a2e27a3d2620be272c1d0c06622856c84503
104.21.24.157
https://download-myproposal.xyz/jq/9594849f4c8cc410f167ed02945f21fe6622852b5df24
104.21.24.157
https://download-myproposal.xyz/favicon.ico
104.21.24.157
https://download-myproposal.xyz/jm/da39f66b5a2e27a3d2620be272c1d0c06622854d0a530
104.21.24.157
https://aadcdn.msauthimages.net/dbd5a2dd-n2kxueriy-dm8fhyf0anvulmvhi3kdbkkxqluuekyfc/logintenantbranding/0/illustration?ts=638116536587632547
152.195.19.97
https://download-myproposal.xyz/API.php?data=mail&email=dsqdsq@joesandbox.com&_=1713538347333
104.21.24.157
https://download-myproposal.xyz/API.php?data=mail&email=dsqdsq@joesandbox.com&_=1713538347332
104.21.24.157
https://download-myproposal.xyz/boot/9594849f4c8cc410f167ed02945f21fe6622852b5df27
104.21.24.157
https://download-myproposal.xyz/ASSETS/img/m_.svg
104.21.24.157
https://download-myproposal.xyz/o/9594849f4c8cc410f167ed02945f21fe6622852d3274d
104.21.24.157
https://download-myproposal.xyz/jq/da39f66b5a2e27a3d2620be272c1d0c06622854d0a527
104.21.24.157
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/876db6fa6e48b0d9/1713538309702/84cdfddea392e79a6f9b445c25d85e274613c7650a8d5538f2b37dbb82748c60/H0DK3jJmlvX3Cnk
104.17.2.184
https://download-myproposal.xyz/APP-349RHT/da39f66b5a2e27a3d2620be272c1d0c06622854ed4936
104.21.24.157
https://download-myproposal.xyz/APP-9594849f4c8cc410f167ed02945f21fe6622852d3271d/9594849f4c8cc410f167ed02945f21fe6622852d3271e
104.21.24.157
https://download-myproposal.xyz/API.php?data=mail&email=dssd@aftral.education&_=1713538412477
104.21.24.157
https://download-myproposal.xyz/2
104.21.24.157
https://download-myproposal.xyz/1
104.21.24.157
https://download-myproposal.xyz/x/da39f66b5a2e27a3d2620be272c1d0c06622856e82623
104.21.24.157
https://download-myproposal.xyz/boot/da39f66b5a2e27a3d2620be272c1d0c06622856c84511
104.21.24.157
There are 43 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
download-myproposal.xyz
104.21.24.157
malicious
a.nel.cloudflare.com
35.190.80.1
code.jquery.com
151.101.194.137
sni1gl.wpc.upsiloncdn.net
152.195.19.97
challenges.cloudflare.com
104.17.3.184
www.google.com
142.251.15.99
unpkg.com
104.17.249.203
aadcdn.msauthimages.net
unknown

IPs

IP
Domain
Country
Malicious
104.21.24.157
download-myproposal.xyz
United States
malicious
152.195.19.97
sni1gl.wpc.upsiloncdn.net
United States
192.168.2.16
unknown
unknown
192.168.2.4
unknown
unknown
104.17.3.184
challenges.cloudflare.com
United States
239.255.255.250
unknown
Reserved
142.251.15.99
www.google.com
United States
104.17.249.203
unpkg.com
United States
151.101.194.137
code.jquery.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
104.17.2.184
unknown
United States
There are 1 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622852b244ddLOGd740c10c7b9cf800d441f265844201e16622852b244de
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622852b244ddLOGd740c10c7b9cf800d441f265844201e16622852b244de
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622854c4a5f6PASd740c10c7b9cf800d441f265844201e16622854c4a5fc
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622854c4a5f6PASd740c10c7b9cf800d441f265844201e16622854c4a5fc
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622854c4a5f6PASd740c10c7b9cf800d441f265844201e16622854c4a5fc#
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622856c3120dLOGd740c10c7b9cf800d441f265844201e16622856c3120e
malicious
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622856c3120dLOGd740c10c7b9cf800d441f265844201e16622856c3120e
malicious
https://download-myproposal.xyz/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/d61b0/0x4AAAAAAAXnFLj2eYtTRdVo/auto/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/d61b0/0x4AAAAAAAXnFLj2eYtTRdVo/auto/normal
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622852b244ddLOGd740c10c7b9cf800d441f265844201e16622852b244de
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622854c4a5f6PASd740c10c7b9cf800d441f265844201e16622854c4a5fc
https://download-myproposal.xyz/d740c10c7b9cf800d441f265844201e16622856c3120dLOGd740c10c7b9cf800d441f265844201e16622856c3120e
There are 3 hidden doms, click here to show them.