IOC Report
https://springtail-lute-g4wp.squarespace.com/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 07:39:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 07:39:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 07:39:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 07:39:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 07:39:10 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 77
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 78
HTML document, ASCII text, with very long lines (1071)
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (25224), with no line terminators
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 82
HTML document, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 86
Unicode text, UTF-8 text, with very long lines (43878), with NEL line terminators
downloaded
Chrome Cache Entry: 87
Unicode text, UTF-8 text, with very long lines (7601)
downloaded
Chrome Cache Entry: 88
HTML document, ASCII text, with very long lines (1071)
downloaded
Chrome Cache Entry: 89
PNG image data, 300 x 109, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 90
PNG image data, 300 x 109, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (65202)
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (44343)
downloaded
There are 13 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2292 --field-trial-handle=2208,i,2800097577801916186,13105312776878611873,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://springtail-lute-g4wp.squarespace.com/"

URLs

Name
IP
Malicious
https://springtail-lute-g4wp.squarespace.com/
malicious
https://github.com/baryon
unknown
https://github.com/xsoh
unknown
https://github.com/noureddinem
unknown
https://github.com/TalAter
unknown
https://github.com/zloirock/core-js
unknown
https://springtail-lute-g4wp.squarespace.com/favicon.ico
198.185.159.177
https://github.com/ebraminio
unknown
https://github.com/jonashdown
unknown
https://github.com/ryanhart2
unknown
http://yuilibrary.com/license/
unknown
https://github.com/kalehv
unknown
https://github.com/crnjakovic
unknown
https://github.com/aliem
unknown
https://github.com/Manfre98
unknown
https://github.com/evoL
unknown
https://github.com/vnathalye
unknown
https://github.com/le0tan
unknown
https://github.com/narainsagar
unknown
https://assets.squarespace.com/universal/scripts-compressed/cldr-resource-pack-e94539391642d3b99900-min.en-US.js
151.101.0.237
https://github.com/ElFadiliY
unknown
https://github.com/ashwoolford
unknown
https://github.com/hagmandan
unknown
https://github.com/jbleduigou
unknown
https://github.com/muminoff
unknown
https://openjsf.org/
unknown
https://support.squarespace.com/hc/en-us/requests/new
unknown
https://assets.squarespace.com/@sqs/polyfiller/1.6/modern.js
151.101.0.237
https://github.com/jatinag22
unknown
https://springtail-lute-g4wp.squarespace.com/
https://github.com/hehachris
unknown
https://assets.squarespace.com/universal/scripts-compressed/common-vendors-stable-70736932c490ae0713e6-min.en-US.js
151.101.0.237
https://github.com/jarcoal
unknown
https://github.com/jcfranco
unknown
https://github.com/mayanksinghal
unknown
https://github.com/andela-batolagbe
unknown
https://github.com/forabi
unknown
https://github.com/bleadof
unknown
https://github.com/boyaq
unknown
https://github.com/passatgt
unknown
https://github.com/naderio
unknown
https://github.com/kaushikgandhi
unknown
https://github.com/B0k0
unknown
https://github.com/middagj
unknown
http://underscorejs.org/LICENSE
unknown
https://github.com/javkhaanj7
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/e7c36e4e52f3f35484a4d7e33
unknown
https://github.com/mweimerskirch
unknown
https://github.com/kruyvanna
unknown
https://github.com/suvash
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/ca345414d3962ef6cdaca8d28
unknown
https://github.com/andrewhood125
unknown
https://assets.squarespace.com/universal/scripts-compressed/system-page-cf938be2d5afeda1b3ba-min.en-US.js
151.101.0.237
https://github.com/ShahramMebashar
unknown
https://github.com/soniasimoes
unknown
https://github.com/BYK
unknown
https://github.com/skakri
unknown
https://github.com/jalex79
unknown
https://github.com/kraz
unknown
https://github.com/nusretparlak
unknown
https://github.com/sigurdga
unknown
https://github.com/nostalgiaz
unknown
https://github.com/sampathsris
unknown
https://github.com/ulmus
unknown
https://github.com/gurdiga
unknown
https://github.com/orif-jr
unknown
https://github.com/johnideal
unknown
https://github.com/bmarkovic
unknown
https://github.com/sedovsek
unknown
https://github.com/k2s
unknown
https://github.com/caio-ribeiro-pereira
unknown
https://github.com/jfroffice
unknown
https://github.com/hinrik
unknown
https://github.com/chrisgedrim
unknown
https://github.com/chienkira
unknown
https://github.com/colindean
unknown
https://github.com/Oire
unknown
https://github.com/chriscartlidge
unknown
https://github.com/mechuwind
unknown
https://assets.squarespace.com/universal/scripts-compressed/common-5c2b5c9b1687bfe753f6-min.en-US.js
151.101.0.237
https://github.com/miestasmia
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/f2c5d6fd265b78313ef5d39b4
unknown
https://github.com/MadMG
unknown
https://github.com/bkyceh
unknown
https://github.com/fadsel
unknown
https://github.com/Amine27
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/455470591ffbf5e53d164abb7
unknown
https://github.com/weldan
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/901edcd5f2eb8eeb56ba9b3c1
unknown
https://github.com/estellecomment
unknown
https://github.com/liabru/matter-wrap
unknown
https://github.com/avaly
unknown
https://github.com/lantip
unknown
https://github.com/amaranthrose
unknown
https://github.com/mergehez
unknown
https://github.com/cepem
unknown
https://assets.squarespace.com/universal/styles-compressed/dialog-081be79078914b908a1a-min.en-US.css
151.101.0.237
https://github.com/nicolaidavies
unknown
https://github.com/gholadr
unknown
https://github.com/mik01aj
unknown
https://github.com/topchiyev
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
static.squarespace.map.fastly.net
151.101.0.237
www.google.com
142.250.217.228
fp2e7a.wpc.phicdn.net
192.229.211.108
springtail-lute-g4wp.squarespace.com
198.185.159.177
assets.squarespace.com
unknown

IPs

IP
Domain
Country
Malicious
151.101.128.237
unknown
United States
198.185.159.177
springtail-lute-g4wp.squarespace.com
United States
239.255.255.250
unknown
Reserved
142.250.217.228
www.google.com
United States
151.101.0.237
static.squarespace.map.fastly.net
United States
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
https://springtail-lute-g4wp.squarespace.com/
https://springtail-lute-g4wp.squarespace.com/