IOC Report
http://www.cataxe.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 52
ASCII text, with very long lines (1222), with no line terminators
downloaded
Chrome Cache Entry: 53
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 54
ASCII text, with very long lines (65465)
downloaded
Chrome Cache Entry: 55
C source, ASCII text, with very long lines (56156)
downloaded
Chrome Cache Entry: 56
HTML document, ASCII text
downloaded
Chrome Cache Entry: 57
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 58
JSON data
downloaded
Chrome Cache Entry: 59
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 60
ASCII text, with very long lines (2247)
downloaded
Chrome Cache Entry: 61
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 62
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 63
ASCII text, with very long lines (374), with no line terminators
downloaded
Chrome Cache Entry: 64
ASCII text, with very long lines (2736)
downloaded
Chrome Cache Entry: 65
MS Windows icon resource - 2 icons, 16x16, 16 colors, 32x32, 16 colors
downloaded
Chrome Cache Entry: 66
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 67
ASCII text, with very long lines (17696)
downloaded
Chrome Cache Entry: 68
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 69
ASCII text, with very long lines (554)
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (56398), with no line terminators
downloaded
Chrome Cache Entry: 71
HTML document, ASCII text, with very long lines (619)
downloaded
Chrome Cache Entry: 72
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 73
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 74
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 75
JSON data
dropped
Chrome Cache Entry: 76
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 77
MS Windows icon resource - 2 icons, 16x16, 16 colors, 32x32, 16 colors
dropped
There are 17 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=1884,i,9792551897781359410,12110252184249234793,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.cataxe.com/"

URLs

Name
IP
Malicious
http://www.cataxe.com/
https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b
https://btloader.com/tag?o=5097926782615552&upapi=true
172.67.41.60
https://img1.wsimg.com/parking-lander/static/css/main.8a1d19af.css
unknown
https://api.aws.parking.godaddy.com/v1/parking/landers/www.cataxe.com?trafficTarget=gd&abp=1&gdabp=true
54.91.44.216
https://img1.wsimg.com/parking-lander/static/js/main.93aa74bd.js
unknown
https://www.google.com/js/bg/rIjZlM8ZNfOeVQTojtt5OPuY9YnE0CAT82tG0V-YUX0.js
172.253.124.99
https://api.btloader.com/mw/state?bt_env=prod
130.211.23.194
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://syndicatedsearch.goog
unknown
https://www.godaddy.com/domainfind/v1/redirect?key=parkweb
unknown
https://support.google.com/recaptcha#6262736
unknown
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://recaptcha.net
unknown
about:blank
https://www.gstatic.c..?/recaptcha/releases/rz4DvU-cY2JYCwHSTck0_qm-/recaptcha__.
unknown
https://support.google.com/recaptcha/?hl=en#6223828
unknown
http://www.cataxe.com/
3.33.130.190
https://cloud.google.com/contact
unknown
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://ad.doubleclick.net/favicon.ico?ad=300x250&ad_box_=1&adnet=1&showad=1&size=250x250
172.253.124.149
https://play.google.com/log?format=json&hasfast=true
unknown
https://ad-delivery.net/px.gif?ch=2
104.26.3.70
http://www.cataxe.com/lander
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://www.google.com/recaptcha/api.js
172.253.124.99
https://support.google.com/recaptcha/#6175971
unknown
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=normal&s=c95XiB53U-_Y0eoaiQPBpjZcEJ5coSlEXmXGK28Fy47VPPdXzs8hgw8WmP47ZhEUaYEzj57k3TtdziMcdozqSF_u_QV9zekXnnb1XnaOPKZEolOF8KVtdsGIC3cxc2HIS8kAf8BdEvoohZhd79Nbd-K1PODqowlQhNOar9kxBqXrAs5j_Y66Vdwq7bZve-DBXXhTZqRMEz750OB_aVFPEsk0v0wn7jjx1meAe3UP6VIYNcWUWbDb9-RAMoOHUJ5SRwHh39pS9I9lCH27auNtjq6qy0K7JUk&cb=xs9wuenu2hfm
https://www.godaddy.com/domainfind/v1/redirect?key=parkweb&utm_source=godaddy&utm_medium=parkedpages&utm_campaign=x_dom-broker_parkedpages_x_x_invest_001&tmskey=dpp_dbs&domainToCheck=cataxe.com&isc=GPPTCOM&itc=parkedpage_landers
https://www.google.com/recaptcha/api2/
unknown
https://support.google.com/recaptcha
unknown
https://ad-delivery.net/px.gif?ch=1&e=0.6532143484236457
104.26.3.70
https://www.google.com/adsense/domains/caf.js?abp=1&gdabp=true
64.233.176.99
https://www.google.com/recaptcha/api2/webworker.js?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-
172.253.124.99
There are 23 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
gddomainparking.com
54.91.44.216
www3.l.google.com
74.125.138.101
api.btloader.com
130.211.23.194
ad.doubleclick.net
172.253.124.149
www.google.com
142.251.15.104
btloader.com
172.67.41.60
fp2e7a.wpc.phicdn.net
192.229.211.108
cataxe.com
3.33.130.190
ad-delivery.net
104.26.3.70
img1.wsimg.com
unknown
www.cataxe.com
unknown
api.aws.parking.godaddy.com
unknown
www.godaddy.com
unknown
www.adsensecustomsearchads.com
unknown
There are 4 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.26.3.70
ad-delivery.net
United States
142.250.9.149
unknown
United States
64.233.176.99
unknown
United States
172.253.124.149
ad.doubleclick.net
United States
192.168.2.6
unknown
unknown
130.211.23.194
api.btloader.com
United States
142.251.15.104
www.google.com
United States
54.91.44.216
gddomainparking.com
United States
104.26.2.70
unknown
United States
172.253.124.99
unknown
United States
172.67.41.60
btloader.com
United States
239.255.255.250
unknown
Reserved
3.33.130.190
cataxe.com
United States
74.125.138.101
www3.l.google.com
United States
There are 4 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
http://www.cataxe.com/lander
http://www.cataxe.com/lander
https://www.google.com/sorry/index?continue=https://www.adsensecustomsearchads.com/afs/ads%3Fadsafe%3Dlow%26adtest%3Doff%26psid%3D7949183650%26pcsa%3Dfalse%26channel%3Dnon-expiry%26domain_name%3Dcataxe.com%26client%3Ddp-godaddy1_xml%26r%3Dm%26rpbu%3Dhttp%253A%252F%252Fwww.cataxe.com%252Flander%26type%3D3%26uiopt%3Dtrue%26swp%3Das-drid-oo-1885714186540894%26oe%3DUTF-8%26ie%3DUTF-8%26fexp%3D21404%252C17300002%252C17301431%252C17301433%252C17301436%26client_gdprApplies%3D0%26format%3Dr3%26nocache%3D2921713563519117%26num%3D0%26output%3Dafd_ads%26v%3D3%26bsl%3D8%26pac%3D2%26u_his%3D1%26u_tz%3D120%26dt%3D1713563519120%26u_w%3D1280%26u_h%3D1024%26biw%3D1280%26bih%3D907%26psw%3D1280%26psh%3D907%26frm%3D0%26uio%3D-%26cont%3DrelatedLinks%26drt%3D0%26jsid%3Dcaf%26nfp%3D1%26jsv%3D625314022%26rurl%3Dhttp%253A%252F%252Fwww.cataxe.com%252Flander%26referer%3Dhttp%253A%252F%252Fwww.cataxe.com%252F&q=EgRRtTk0GIDPi7EGIjDGc8CFvNIij74Yy2rbRuaWJhB-lAdPFA_J-39lfbjJTLzG5M6E_U9fSHqzMk9glxcyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
https://www.google.com/sorry/index?continue=https://www.adsensecustomsearchads.com/afs/ads%3Fadsafe%3Dlow%26adtest%3Doff%26psid%3D7949183650%26pcsa%3Dfalse%26channel%3Dnon-expiry%26domain_name%3Dcataxe.com%26client%3Ddp-godaddy1_xml%26r%3Dm%26rpbu%3Dhttp%253A%252F%252Fwww.cataxe.com%252Flander%26type%3D3%26uiopt%3Dtrue%26swp%3Das-drid-oo-1885714186540894%26oe%3DUTF-8%26ie%3DUTF-8%26fexp%3D21404%252C17300002%252C17301431%252C17301433%252C17301436%26client_gdprApplies%3D0%26format%3Dr3%26nocache%3D2921713563519117%26num%3D0%26output%3Dafd_ads%26v%3D3%26bsl%3D8%26pac%3D2%26u_his%3D1%26u_tz%3D120%26dt%3D1713563519120%26u_w%3D1280%26u_h%3D1024%26biw%3D1280%26bih%3D907%26psw%3D1280%26psh%3D907%26frm%3D0%26uio%3D-%26cont%3DrelatedLinks%26drt%3D0%26jsid%3Dcaf%26nfp%3D1%26jsv%3D625314022%26rurl%3Dhttp%253A%252F%252Fwww.cataxe.com%252Flander%26referer%3Dhttp%253A%252F%252Fwww.cataxe.com%252F&q=EgRRtTk0GIDPi7EGIjDGc8CFvNIij74Yy2rbRuaWJhB-lAdPFA_J-39lfbjJTLzG5M6E_U9fSHqzMk9glxcyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
about:blank
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=normal&s=c95XiB53U-_Y0eoaiQPBpjZcEJ5coSlEXmXGK28Fy47VPPdXzs8hgw8WmP47ZhEUaYEzj57k3TtdziMcdozqSF_u_QV9zekXnnb1XnaOPKZEolOF8KVtdsGIC3cxc2HIS8kAf8BdEvoohZhd79Nbd-K1PODqowlQhNOar9kxBqXrAs5j_Y66Vdwq7bZve-DBXXhTZqRMEz750OB_aVFPEsk0v0wn7jjx1meAe3UP6VIYNcWUWbDb9-RAMoOHUJ5SRwHh39pS9I9lCH27auNtjq6qy0K7JUk&cb=xs9wuenu2hfm
https://www.google.com/recaptcha/api2/bframe?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b
https://www.godaddy.com/domainfind/v1/redirect?key=parkweb&utm_source=godaddy&utm_medium=parkedpages&utm_campaign=x_dom-broker_parkedpages_x_x_invest_001&tmskey=dpp_dbs&domainToCheck=cataxe.com&isc=GPPTCOM&itc=parkedpage_landers