IOC Report
https://rdv-msgs.online/83-hsiryir

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 52
ASCII text, with very long lines (59810)
downloaded
Chrome Cache Entry: 53
PNG image data, 676 x 676, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 54
PNG image data, 677 x 677, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 55
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 609x215, components 3
downloaded
Chrome Cache Entry: 56
PNG image data, 580 x 580, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 57
PNG image data, 677 x 677, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 58
PNG image data, 676 x 676, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 59
PNG image data, 672 x 672, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 60
ASCII text, with very long lines (59158)
downloaded
Chrome Cache Entry: 61
HTML document, Unicode text, UTF-8 text, with very long lines (2571)
downloaded
Chrome Cache Entry: 62
PNG image data, 672 x 672, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 63
Web Open Font Format (Version 2), TrueType, length 78196, version 331.-31261
downloaded
Chrome Cache Entry: 64
HTML document, ASCII text
downloaded
Chrome Cache Entry: 65
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 609x215, components 3
dropped
Chrome Cache Entry: 66
PNG image data, 580 x 580, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 67
ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 68
PNG image data, 676 x 676, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 69
Unicode text, UTF-8 text, with very long lines (65306)
downloaded
Chrome Cache Entry: 70
PNG image data, 676 x 676, 8-bit/color RGBA, non-interlaced
downloaded
There are 10 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2456 --field-trial-handle=2256,i,12859117087495175500,9687681321712161097,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://rdv-msgs.online/83-hsiryir"

URLs

Name
IP
Malicious
https://rdv-msgs.online/83-hsiryir
https://fontawesome.com
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://hot-line.tv/src/uploads/x4sq.png
104.21.43.167
https://hot-line.tv/src/img/HOT%20LINE%20Main%20Logo%20800x600%20%20222.jpg
104.21.43.167
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/webfonts/fa-solid-900.woff2
104.17.24.14
https://hot-line.tv/src/uploads/x3sq.png
104.21.43.167
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://hot-line.tv/src/js/bootstrap.min.js
104.21.43.167
https://hot-line.tv/
https://hot-line.tv/favicon.ico
104.21.43.167
https://hot-line.tv/src/uploads/x2sq.png
104.21.43.167
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.css
104.17.24.14
https://a.nel.cloudflare.com/report/v4?s=nxQ%2Fz7t2b5t9unlg%2FWk5fh35jTtRwhYl%2FM1%2Bfzt4%2BdSB5G%2B1n6VMde4dhYn7PZeWU2zc1uZh04SJC8txly%2BySY2J3k%2F8LKiZTnF%2FTwfBmeez6bmeGijBAXse8dNHJg%3D%3D
35.190.80.1
https://hot-line.tv/src/css/bootstrap.min.css
104.21.43.167
https://hot-line.tv/src/uploads/vava.png
104.21.43.167
https://getbootstrap.com/)
unknown
https://hot-line.tv/src/uploads/x1sq.png
104.21.43.167
https://hot-line.tv/src/css/ci/csspage.css
104.21.43.167
https://fontawesome.com/license/free
unknown
https://rdv-msgs.online/83-hsiryir
172.67.179.98
There are 10 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
a.nel.cloudflare.com
35.190.80.1
cdnjs.cloudflare.com
104.17.24.14
rdv-msgs.online
172.67.179.98
www.google.com
172.253.124.106
hot-line.tv
104.21.43.167
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
239.255.255.250
unknown
Reserved
104.21.43.167
hot-line.tv
United States
172.253.124.106
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
172.67.179.98
rdv-msgs.online
United States
192.168.2.4
unknown
unknown
172.67.181.191
unknown
United States

DOM / HTML

URL
Malicious
https://hot-line.tv/