IOC Report
https://equipstudy.net/iwxaj

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 50
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], progressive, precision 8, 1920x50, components 3
downloaded
Chrome Cache Entry: 51
ASCII text, with very long lines (65367), with CRLF line terminators
downloaded
Chrome Cache Entry: 52
HTML document, ASCII text
downloaded
Chrome Cache Entry: 53
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 54
ASCII text, with very long lines (32035), with CRLF line terminators
downloaded
Chrome Cache Entry: 55
Web Open Font Format (Version 2), CFF, length 25444, version 1.0
downloaded
Chrome Cache Entry: 56
Unicode text, UTF-8 (with BOM) text, with very long lines (416), with CRLF line terminators
downloaded
Chrome Cache Entry: 57
HTML document, Unicode text, UTF-8 text, with very long lines (349), with CRLF line terminators
downloaded
Chrome Cache Entry: 58
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 59
Web Open Font Format (Version 2), TrueType, length 20860, version 1.0
downloaded
Chrome Cache Entry: 60
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 61
troff or preprocessor input, ASCII text, with very long lines (305), with CRLF line terminators
downloaded
Chrome Cache Entry: 62
ASCII text, with very long lines (32087), with CRLF line terminators
downloaded
Chrome Cache Entry: 63
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 64
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], progressive, precision 8, 1920x50, components 3
dropped
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2368 --field-trial-handle=2280,i,7619782800502618050,10566268962405110305,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://equipstudy.net/iwxaj"

URLs

Name
IP
Malicious
https://equipstudy.net/iwxaj
https://surveys.equip-surveys.com/fieldlinknavi/bootstrap/font-awesome-4.2.0/css/font-awesome.css
212.6.184.245
http://fontawesome.io
unknown
http://formvalidation.io)
unknown
http://bugs.jquery.com/ticket/12359
unknown
https://surveys.equip-surveys.com/favicon.ico
212.6.184.245
http://jquery.org/license
unknown
https://equipstudy.net/iwxaj
212.6.184.245
http://json.org/json2.js
unknown
https://twitter.com/formvalidation
unknown
https://surveys.equip-surveys.com/fieldlinknavi/assets/header_bgr.jpg
212.6.184.245
https://bugzilla.mozilla.org/show_bug.cgi?id=649285
unknown
http://sizzlejs.com/
unknown
http://html5shim.googlecode.com/svn/trunk/html5.js
unknown
http://jqueryui.com
unknown
https://surveys.equip-surveys.com/fieldlinknavi/navigations/navigation_de.php?slink=aHR0cHM6Ly9zdXJ2ZXlzLmVxdWlwLXN1cnZleXMuY29tLzgwMTFlZDQ2N2ZjODhiYWY4ZTA4Y2YyOWMyMGNjOWE5
https://surveys.equip-surveys.com/fieldlinknavi/css/global.css
212.6.184.245
http://weblogs.java.net/blog/driscoll/archive/2009/09/08/eval-javascript-global-context
unknown
https://surveys.equip-surveys.com/fieldlinknavi/js/formvalidation/formValidation.css
212.6.184.245
http://jsperf.com/getall-vs-sizzle/2
unknown
http://fluidproject.org/blog/2008/01/09/getting-setting-and-removing-tabindex-values-with-javascript
unknown
https://bugs.webkit.org/show_bug.cgi?id=29084
unknown
https://surveys.equip-surveys.com/fieldlinknavi/bootstrap/js/bootstrap.min.js
212.6.184.245
http://formvalidation.io/license/
unknown
http://fontawesome.io/license
unknown
https://surveys.equip-surveys.com/fieldlinknavi/bootstrap/css/bootstrap.min.css
212.6.184.245
http://blindsignals.com/index.php/2009/07/jquery-delay/
unknown
http://bugs.jquery.com/ticket/12282#comment:15
unknown
https://developer.mozilla.org/en-US/docs/CSS/display
unknown
http://dev.w3.org/csswg/cssom/#resolved-values
unknown
https://surveys.equip-surveys.com/fieldlinknavi/assets/fonts/museo-slab-500italic.woff2
212.6.184.245
https://developer.mozilla.org/en/Security/CSP)
unknown
https://surveys.equip-surveys.com/fieldlinknavi/js/jquery/jquery-1.9.1.js
212.6.184.245
http://getbootstrap.com)
unknown
https://surveys.equip-surveys.com/8011ed467fc88baf8e08cf29c20cc9a9
unknown
https://surveys.equip-surveys.com/fieldlinknavi/assets/fonts/museosans-300-webfont.woff2
212.6.184.245
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://surveys.equip-surveys.com/fieldlinknavi/css/textobj.css
212.6.184.245
http://erik.eae.net/archives/2007/07/27/18.54.15/#comment-102291
unknown
http://helpful.knobs-dials.com/index.php/Component_returned_failure_code:_0x80040111_(NS_ERROR_NOT_A
unknown
https://github.com/jquery/jquery/pull/764
unknown
https://bugzilla.mozilla.org/show_bug.cgi?id=491668
unknown
http://javascript.nwbox.com/IEContentLoaded/
unknown
http://jquery.com/
unknown
https://surveys.equip-surveys.com/fieldlinknavi/js/jquery/jquery-ui-1.11.4.min.js
212.6.184.245
There are 34 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
surveys.equip-surveys.com
212.6.184.245
equipstudy.net
212.6.184.245
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
172.217.215.104
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
212.6.184.245
surveys.equip-surveys.com
Germany
239.255.255.250
unknown
Reserved
172.217.215.104
www.google.com
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
https://surveys.equip-surveys.com/fieldlinknavi/navigations/navigation_de.php?slink=aHR0cHM6Ly9zdXJ2ZXlzLmVxdWlwLXN1cnZleXMuY29tLzgwMTFlZDQ2N2ZjODhiYWY4ZTA4Y2YyOWMyMGNjOWE5