IOC Report
https://docs-paymentreceipts.info

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 52
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 53
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 54
PNG image data, 95 x 14, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 55
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 56
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 57
ASCII text, with very long lines (7043), with no line terminators
downloaded
Chrome Cache Entry: 58
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 59
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 60
PNG image data, 95 x 14, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 61
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 62
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 63
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 64
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 65
HTML document, ASCII text, with very long lines (4020)
downloaded
Chrome Cache Entry: 66
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 67
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 68
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 69
ASCII text, with very long lines (42414)
downloaded
Chrome Cache Entry: 70
SVG Scalable Vector Graphics image
dropped
There are 10 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2552 --field-trial-handle=2492,i,11101307525743700790,15830578110555909480,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://docs-paymentreceipts.info"

URLs

Name
IP
Malicious
https://docs-paymentreceipts.info
malicious
https://docs-paymentreceipts.info/271af8f3d119ef179555782afdad51066627c98dc2b8bLOG271af8f3d119ef179555782afdad51066627c98dc2b8c
malicious
https://docs-paymentreceipts.info/271af8f3d119ef179555782afdad51066627c98dc2b8bLOG271af8f3d119ef179555782afdad51066627c98dc2b8c#
malicious
https://docs-paymentreceipts.info/1
172.67.154.166
https://docs-paymentreceipts.info/APP-594cc24d68bfdaae8c54d6c84185ffae6627c9900c59a/594cc24d68bfdaae8c54d6c84185ffae6627c9900c59b
172.67.154.166
https://docs-paymentreceipts.info/cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v1?ray=878ea2bc0b600c55
172.67.154.166
https://docs-paymentreceipts.info/favicon.ico
172.67.154.166
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=878ea2c9be8cb03f
104.17.2.184
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1164005402:1713881625:5lO8_jsoAV7x_zd7QenGyOA3YuII3nvX1FlUXbmZotQ/878ea2c9be8cb03f/1a16ccbe5a46b3b
104.17.2.184
https://a.nel.cloudflare.com/report/v4?s=uBQWuV1QiiutcQHzZl2HIaQvBEgmEIQs6wsGvCcJah4HLttn3DaohOyDkcqwHTcNQ7rNeILIQ76xaZwzCn0LdQXF32qeZq8kswBmR3ljsmcUpZ13CX0FgipypzUS%2BwScgXU4EZph%2FM2y%2F9%2B0
35.190.80.1
https://getbootstrap.com/)
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/878ea2c9be8cb03f/1713883515091/757f6444804dd2e9981180324c79d0960eaff7747515f3966bf5bfb3215800f6/LawkcuOzk6b4KSF
104.17.2.184
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://docs-paymentreceipts.info/cdn-cgi/challenge-platform/h/b/flow/ov1/478945564:1713881454:lnZvRWlpex41tDYh1XMPdMDd5jHf7QjnKLdwEbvu1J4/878ea2bc0b600c55/d4d5a3b29a31928
172.67.154.166
https://a.nel.cloudflare.com/report/v4?s=UC9MkdpeDSz1crXNHAf2UfvdyDZZwZ%2F2Eha%2BdXIcDL%2BbthBuIWu%2Fnv%2BP2GoAUCa2D7ciLDc7UwN%2Fh5BtDl36m8q9KLIpgdEIyxRZv3Mtz1RSGJBQROBMXy1KaZ0YmS6OUK5dd7Zp5fz99krV
35.190.80.1
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.2.184
https://docs-paymentreceipts.info/jq/594cc24d68bfdaae8c54d6c84185ffae6627c98e6fe14
172.67.154.166
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://docs-paymentreceipts.info/o/594cc24d68bfdaae8c54d6c84185ffae6627c9900c5bb
172.67.154.166
https://docs-paymentreceipts.info/js/594cc24d68bfdaae8c54d6c84185ffae6627c98e6fe1b
172.67.154.166
https://docs-paymentreceipts.info/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/tr8vl/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://docs-paymentreceipts.info/boot/594cc24d68bfdaae8c54d6c84185ffae6627c98e6fe1a
172.67.154.166
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/878ea2c9be8cb03f/1713883515092/2oD3MXWtH9i_VzC
104.17.2.184
https://docs-paymentreceipts.info/ASSETS/img/sig-op.svg
172.67.154.166
https://docs-paymentreceipts.info/ASSETS/img/m_.svg
172.67.154.166
https://docs-paymentreceipts.info/x/594cc24d68bfdaae8c54d6c84185ffae6627c9900c5a0
172.67.154.166
There are 16 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
docs-paymentreceipts.info
172.67.154.166
a.nel.cloudflare.com
35.190.80.1
challenges.cloudflare.com
104.17.2.184
www.google.com
108.177.122.103
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
104.21.5.142
unknown
United States
172.67.154.166
docs-paymentreceipts.info
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
192.168.2.13
unknown
unknown
192.168.2.15
unknown
unknown
192.168.2.14
unknown
unknown
35.190.80.1
a.nel.cloudflare.com
United States
104.17.2.184
challenges.cloudflare.com
United States
108.177.122.103
www.google.com
United States

DOM / HTML

URL
Malicious
https://docs-paymentreceipts.info/271af8f3d119ef179555782afdad51066627c98dc2b8bLOG271af8f3d119ef179555782afdad51066627c98dc2b8c
malicious
https://docs-paymentreceipts.info/271af8f3d119ef179555782afdad51066627c98dc2b8bLOG271af8f3d119ef179555782afdad51066627c98dc2b8c#
malicious
https://docs-paymentreceipts.info/
https://docs-paymentreceipts.info/
https://docs-paymentreceipts.info/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/tr8vl/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/tr8vl/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://docs-paymentreceipts.info/271af8f3d119ef179555782afdad51066627c98dc2b8bLOG271af8f3d119ef179555782afdad51066627c98dc2b8c