IOC Report
https://qhs-rx.com/index.php/lists/qf0856g1wm416/unsubscribe/oq197fczd8113/bt706mvd1j483

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 56
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 57
ASCII text
downloaded
Chrome Cache Entry: 58
ASCII text
downloaded
Chrome Cache Entry: 59
ASCII text, with very long lines (564)
downloaded
Chrome Cache Entry: 60
ASCII text, with very long lines (27303)
downloaded
Chrome Cache Entry: 61
ASCII text, with very long lines (65366)
downloaded
Chrome Cache Entry: 62
ASCII text, with very long lines (32086)
downloaded
Chrome Cache Entry: 63
MS Windows icon resource - 1 icon, 16x16, 2 colors
dropped
Chrome Cache Entry: 64
ASCII text
downloaded
Chrome Cache Entry: 65
MS Windows icon resource - 1 icon, 16x16, 2 colors
downloaded
Chrome Cache Entry: 66
Web Open Font Format (Version 2), TrueType, length 33092, version 1.0
downloaded
Chrome Cache Entry: 67
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 68
ASCII text
downloaded
Chrome Cache Entry: 69
Unicode text, UTF-8 text, with very long lines (50806)
downloaded
Chrome Cache Entry: 70
ASCII text
downloaded
Chrome Cache Entry: 71
ASCII text
downloaded
Chrome Cache Entry: 72
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 73
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 74
ASCII text, with very long lines (9373)
downloaded
Chrome Cache Entry: 75
ASCII text
downloaded
Chrome Cache Entry: 76
ASCII text
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (28941)
downloaded
Chrome Cache Entry: 78
ASCII text
downloaded
There are 14 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2212 --field-trial-handle=2020,i,2194234812516978810,3701196606030679472,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://qhs-rx.com/index.php/lists/qf0856g1wm416/unsubscribe/oq197fczd8113/bt706mvd1j483"

URLs

Name
IP
Malicious
https://qhs-rx.com/index.php/lists/qf0856g1wm416/unsubscribe/oq197fczd8113/bt706mvd1j483
https://qhs-rx.com/assets/js/knockout.min.js?av=9ec570bf
69.64.48.35
https://github.com/lipis/bootstrap-social
unknown
http://fontawesome.io
unknown
https://qhs-rx.com/index.php/lists/qf0856g1wm416/unsubscribe/oq197fczd8113/bt706mvd1j483
https://github.com/google/material-design-icons
unknown
https://www.mailwizz.com/
unknown
https://qhs-rx.com/assets/js/notify.js?av=9ec570bf
69.64.48.35
https://www.mailwizz.com/license/
unknown
https://qhs-rx.com/frontend/assets/cache/591dbfd1/jquery.min.js
69.64.48.35
https://twitter.com/benjsperry
unknown
https://www.mailwizz.com)
unknown
https://qhs-rx.com/assets/css/adminlte.css?av=9ec570bf
69.64.48.35
http://knockoutjs.com/
unknown
http://opensource.org/licenses/MIT
unknown
http://ionicons.com/
unknown
https://qhs-rx.com/assets/css/skin-blue.css?av=9ec570bf
69.64.48.35
https://qhs-rx.com/assets/js/cookie.js?av=9ec570bf
69.64.48.35
http://www.json.org/json2.js
unknown
https://github.com/driftyco/ionicons
unknown
https://twitter.com/ionicframework
unknown
http://fontawesome.io/license
unknown
https://qhs-rx.com/frontend/assets/css/style.css?av=9ec570bf
69.64.48.35
http://www.opensource.org/licenses/mit-license.php)
unknown
https://qhs-rx.com/assets/js/app.js?av=9ec570bf
69.64.48.35
https://qhs-rx.com/assets/js/bootstrap.min.js?av=9ec570bf
69.64.48.35
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.5.0/css/font-awesome.min.css?av=9ec570bf
104.17.25.14
https://qhs-rx.com/assets/js/adminlte.js?av=9ec570bf
69.64.48.35
http://getbootstrap.com)
unknown
http://www.almsaeedstudio.com
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://qhs-rx.com/frontend/assets/js/app.js?av=9ec570bf
69.64.48.35
https://github.com/js-cookie/js-cookie
unknown
https://qhs-rx.com/assets/css/bootstrap.min.css?av=9ec570bf
69.64.48.35
https://cdnjs.cloudflare.com/ajax/libs/ionicons/2.0.1/css/ionicons.min.css?av=9ec570bf
104.17.25.14
https://qhs-rx.com/favicon.ico
69.64.48.35
http://creativecommons.org/licenses/by/4.0/
unknown
http://almsaeedstudio.com
unknown
There are 27 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cdnjs.cloudflare.com
104.17.25.14
www.google.com
172.217.15.196
qhs-rx.com
69.64.48.35
fp2e7a.wpc.phicdn.net
192.229.211.108

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
172.217.15.196
www.google.com
United States
239.255.255.250
unknown
Reserved
69.64.48.35
qhs-rx.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://qhs-rx.com/index.php/lists/qf0856g1wm416/unsubscribe/oq197fczd8113/bt706mvd1j483