IOC Report
https://web.leitz-cloud.com/shares/folder/k11NnLCmDNb/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 68
ASCII text, with very long lines (9090)
downloaded
Chrome Cache Entry: 69
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 70
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 71
Unicode text, UTF-8 text, with very long lines (685)
downloaded
Chrome Cache Entry: 72
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 73
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 74
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 75
ASCII text, with very long lines (524)
downloaded
Chrome Cache Entry: 76
Web Open Font Format (Version 2), TrueType, length 89668, version 3.393
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (7786)
downloaded
Chrome Cache Entry: 78
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 79
Web Open Font Format (Version 2), TrueType, length 89676, version 3.393
downloaded
Chrome Cache Entry: 80
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 81
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 82
PNG image data, 100 x 100, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 83
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 85
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 86
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 87
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 88
PNG image data, 100 x 100, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 89
HTML document, Unicode text, UTF-8 text, with very long lines (4716), with no line terminators
downloaded
Chrome Cache Entry: 90
ASCII text, with very long lines (1601)
downloaded
Chrome Cache Entry: 91
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (12770), with no line terminators
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 94
TrueType Font data, 11 tables, 1st "OS/2", 14 names, Macintosh, type 1 string, axcient-iconfont
downloaded
Chrome Cache Entry: 95
Web Open Font Format (Version 2), TrueType, length 88732, version 3.393
downloaded
Chrome Cache Entry: 96
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 97
Unicode text, UTF-8 text, with very long lines (37649)
downloaded
There are 21 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2032 --field-trial-handle=1988,i,5874812371822322334,2225953221869786979,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://web.leitz-cloud.com/shares/folder/k11NnLCmDNb/"

URLs

Name
IP
Malicious
https://web.leitz-cloud.com/shares/folder/k11NnLCmDNb/
https://web.leitz-cloud.com/auth/login/?domain=abtax-Steuerberatung&next=%2Fshares%2Ffolder%2Fk11NnLCmDNb%2F%3F
https://gravatar.com/avatar/
unknown
https://web.leitz-cloud.com/api/2/person
2.58.164.9
https://web.leitz-cloud.com/static/themes/default/images/svg/sidebar.js
2.58.164.9
https://web.leitz-cloud.com/auth/login/
https://piwik.org/free-software/bsd/
unknown
https://web.leitz-cloud.com/static/gen/main.ed99ea6b.min.css
2.58.164.9
https://analytics.vboxx.eu/matomo.js
2.58.165.70
https://analytics.vboxx.eu/plugins/HeatmapSessionRecording/configs.php?idsite=33&trackerid=0eVsvC&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Fforgot%2F
2.58.165.70
https://web.leitz-cloud.com/static/bootstrap/dist/fonts/sourcesanspro-light.woff2
2.58.164.9
https://github.com/select2/select2/blob/master/LICENSE.md
unknown
https://web.leitz-cloud.com/sites/1/branding/logo
2.58.164.9
https://www.youtube.com/iframe_api
unknown
https://analytics.vboxx.eu/matomo.php?action_name=Passwort%20vergessen&idsite=33&rec=1&r=724701&h=8&m=23&s=58&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Fforgot%2F&_id=1d7f1cb1d782f35f&_idn=0&send_image=0&_refts=0&pv_id=9zYqZ8&fa_pv=1&fa_fp[0][fa_vid]=McZrQa&fa_fp[0][fa_id]=valid&fa_fp[0][fa_fv]=1&pf_net=525&pf_srv=463&pf_tfr=2&pf_dm1=544&uadata=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1280x1024
2.58.165.70
http://jqueryui.com)
unknown
https://developer.matomo.org/guides/tracking-javascript-guide#multiple-piwik-trackers
unknown
https://analytics.vboxx.eu/matomo.php?action_name=Einloggen&idsite=33&rec=1&r=204970&h=8&m=23&s=34&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2F&_id=1d7f1cb1d782f35f&_idn=0&send_image=0&_refts=0&pv_id=TCHRDo&fa_pv=1&fa_fp[0][fa_vid]=e65TJF&fa_fp[0][fa_id]=valid&fa_fp[0][fa_fv]=1&pf_net=0&pf_srv=249&pf_tfr=36&pf_dm1=541&uadata=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1280x1024
2.58.165.70
https://github.com/matomo-org/matomo/blob/master/js/piwik.js
unknown
https://web.leitz-cloud.com/sites/1/branding/icon/
2.58.164.9
https://analytics.vboxx.eu/plugins/HeatmapSessionRecording/configs.php?idsite=33&trackerid=WgIqI3&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2F
2.58.165.70
https://analytics.vboxx.eu/plugins/HeatmapSessionRecording/configs.php?idsite=33&trackerid=TvJd9S&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Fforgot%2F
2.58.165.70
https://analytics.vboxx.eu/matomo.php?action_name=Einloggen&idsite=33&rec=1&r=448950&h=8&m=23&s=3&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2F%3Fdomain%3Dabtax-Steuerberatung%26next%3D%2Fshares%2Ffolder%2Fk11NnLCmDNb%2F%3F&_id=1d7f1cb1d782f35f&_idn=1&send_image=0&_refts=0&pv_id=s2EsOK&fa_pv=1&fa_fp[0][fa_vid]=pv5G4q&fa_fp[0][fa_id]=valid&fa_fp[0][fa_fv]=1&pf_net=0&pf_srv=328&pf_tfr=2&pf_dm1=4480&uadata=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1280x1024
2.58.165.70
https://analytics.vboxx.eu/matomo.php?action_name=Kontowiederherstellung&idsite=33&rec=1&r=310271&h=8&m=23&s=46&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2Frecovery%2F&_id=1d7f1cb1d782f35f&_idn=0&send_image=0&_refts=0&pv_id=LGr2Y2&fa_pv=1&fa_fp[0][fa_vid]=fTrLsE&fa_fp[0][fa_id]=valid&fa_fp[0][fa_fv]=1&pf_net=539&pf_srv=453&pf_tfr=1&pf_dm1=745&uadata=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1280x1024
2.58.165.70
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://w.soundcloud.com/player/api.js
unknown
https://web.leitz-cloud.com/static/bootstrap/dist/fonts/sourcesanspro-regular.woff2
2.58.164.9
https://web.leitz-cloud.com/static/gen/main.52b56941.min.js
2.58.164.9
https://developer.matomo.org/api-reference/tracking-javascript
unknown
https://web.leitz-cloud.com/static/bootstrap/dist/fonts/sourcesanspro-semibold.woff2
2.58.164.9
https://analytics.vboxx.eu/plugins/HeatmapSessionRecording/configs.php?idsite=33&trackerid=RUPzzJ&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2Frecovery%2F
2.58.165.70
https://analytics.vboxx.eu/plugins/HeatmapSessionRecording/configs.php?idsite=33&trackerid=SwQQnj&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2F
2.58.165.70
https://www.innocraft.com/license
unknown
https://web.leitz-cloud.com/auth/login/recovery/
https://web.leitz-cloud.com/static/vendor/select2-4.0.3/dist/js/i18n/de.js?v=3.6.0.117
2.58.164.9
https://web.leitz-cloud.com/auth/forgot/
https://analytics.vboxx.eu/matomo.php?action_name=Passwort%20vergessen&idsite=33&rec=1&r=562126&h=8&m=23&s=30&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Fforgot%2F&_id=1d7f1cb1d782f35f&_idn=0&send_image=0&_refts=0&pv_id=21iyUu&fa_pv=1&fa_fp[0][fa_vid]=yu2AXf&fa_fp[0][fa_id]=valid&fa_fp[0][fa_fv]=1&pf_net=529&pf_srv=482&pf_tfr=3&pf_dm1=477&uadata=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1280x1024
2.58.165.70
https://piwik.org
unknown
https://www.innocraft.com/
unknown
https://web.leitz-cloud.com/custom/styles.css?v=3.6.0.117
2.58.164.9
https://analytics.vboxx.eu/matomo.php?action_name=Passwort%20vergessen&idsite=33&rec=1&r=771846&h=8&m=23&s=14&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Fforgot%2F&_id=1d7f1cb1d782f35f&_idn=0&send_image=0&_refts=0&pv_id=MzNZPV&fa_pv=1&fa_fp[0][fa_vid]=0bnpR5&fa_fp[0][fa_id]=valid&fa_fp[0][fa_fv]=1&pf_net=522&pf_srv=497&pf_tfr=2&pf_dm1=251&uadata=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1280x1024
2.58.165.70
https://web.leitz-cloud.com/shares/folder/k11NnLCmDNb/
2.58.164.9
https://web.leitz-cloud.com/static/bootstrap/dist/fonts/axcient-iconfont.ttf?avds6c
2.58.164.9
https://analytics.vboxx.eu/plugins/HeatmapSessionRecording/configs.php?idsite=33&trackerid=ToyWF0&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2F%3Fdomain%3Dabtax-Steuerberatung%26next%3D%2Fshares%2Ffolder%2Fk11NnLCmDNb%2F%3F
2.58.165.70
https://web.leitz-cloud.com/static/themes/default/images/svg/lottie.js
2.58.164.9
https://web.leitz-cloud.com/static/themes/default/images/svg/custom_script.js
2.58.164.9
https://web.leitz-cloud.com/static/gen/main_header.cf07ee37.min.js
2.58.164.9
https://analytics.vboxx.eu/matomo.php
2.58.165.70
https://analytics.vboxx.eu/plugins/HeatmapSessionRecording/configs.php?idsite=33&trackerid=z99seb&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Fforgot%2F
2.58.165.70
https://analytics.vboxx.eu/matomo.php?action_name=Einloggen&idsite=33&rec=1&r=032852&h=8&m=23&s=18&url=https%3A%2F%2Fweb.leitz-cloud.com%2Fauth%2Flogin%2F&_id=1d7f1cb1d782f35f&_idn=0&send_image=0&_refts=0&pv_id=FK8JTu&fa_pv=1&fa_fp[0][fa_vid]=bf6zEM&fa_fp[0][fa_id]=valid&fa_fp[0][fa_fv]=1&pf_net=0&pf_srv=294&pf_tfr=2&pf_dm1=301&uadata=%7B%22fullVersionList%22%3A%5B%7B%22brand%22%3A%22Google%20Chrome%22%2C%22version%22%3A%22117.0.5938.132%22%7D%2C%7B%22brand%22%3A%22Not%3BA%3DBrand%22%2C%22version%22%3A%228.0.0.0%22%7D%2C%7B%22brand%22%3A%22Chromium%22%2C%22version%22%3A%22117.0.5938.132%22%7D%5D%2C%22mobile%22%3Afalse%2C%22model%22%3A%22%22%2C%22platform%22%3A%22Windows%22%2C%22platformVersion%22%3A%2210.0.0%22%7D&pdf=1&qt=0&realp=0&wma=0&fla=0&java=0&ag=0&cookie=1&res=1280x1024
2.58.165.70
https://web.leitz-cloud.com/auth/login/?clear_cookie=1
2.58.164.9
https://web.leitz-cloud.com/static/js/translations/de.js?v=3.6.0.117
2.58.164.9
https://web.leitz-cloud.com/static/themes/default/images/svg/right-arrow.png
2.58.164.9
There are 42 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.google.com
142.250.105.103
web.leitz-cloud.com
2.58.164.9
analytics.vboxx.eu
2.58.165.70
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
2.58.164.9
web.leitz-cloud.com
Netherlands
2.58.165.70
analytics.vboxx.eu
Netherlands
239.255.255.250
unknown
Reserved
192.168.2.16
unknown
unknown
192.168.2.4
unknown
unknown
142.250.105.103
www.google.com
United States

DOM / HTML

URL
Malicious
https://web.leitz-cloud.com/auth/login/?domain=abtax-Steuerberatung&next=%2Fshares%2Ffolder%2Fk11NnLCmDNb%2F%3F
https://web.leitz-cloud.com/auth/login/?domain=abtax-Steuerberatung&next=%2Fshares%2Ffolder%2Fk11NnLCmDNb%2F%3F
https://web.leitz-cloud.com/auth/forgot/
https://web.leitz-cloud.com/auth/forgot/
https://web.leitz-cloud.com/auth/forgot/
https://web.leitz-cloud.com/auth/login/
https://web.leitz-cloud.com/auth/login/
https://web.leitz-cloud.com/auth/login/recovery/