IOC Report
https://fernwork.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 45
MS Windows icon resource - 3 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 46
ASCII text, with very long lines (325), with CRLF line terminators
downloaded
Chrome Cache Entry: 47
MS Windows icon resource - 3 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1880 --field-trial-handle=1988,i,4519568244183972402,11343462911106918720,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fernwork.com/"

URLs

Name
IP
Malicious
https://fernwork.com/
https://fernwork.com/vendor/vendor.23238u92u82.js
208.87.207.65
https://fernwork.com/favicon.ico
208.87.207.65
https://fernwork.com/index.php?t=09f68bd3966d16ba337bfd3cfc2604ced6cee37053212aebed2ea0335e4cd14b
https://fernwork.com/

Domains

Name
IP
Malicious
www.google.com
142.250.101.106
fp2e7a.wpc.phicdn.net
192.229.211.108
fernwork.com
208.87.207.65

IPs

IP
Domain
Country
Malicious
142.250.101.106
www.google.com
United States
239.255.255.250
unknown
Reserved
208.87.207.65
fernwork.com
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://fernwork.com/
https://fernwork.com/index.php?t=09f68bd3966d16ba337bfd3cfc2604ced6cee37053212aebed2ea0335e4cd14b