IOC Report
https://srmcorp.tecuidoc.com/?PSZlk=ViP

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
gzip compressed data, original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 62
gzip compressed data, from Unix, original size modulo 2^32 444173
downloaded
Chrome Cache Entry: 63
gzip compressed data, original size modulo 2^32 1864
dropped
Chrome Cache Entry: 64
gzip compressed data, from Unix, original size modulo 2^32 80160
downloaded
Chrome Cache Entry: 65
gzip compressed data, original size modulo 2^32 3651
dropped
Chrome Cache Entry: 66
gzip compressed data, original size modulo 2^32 1592
downloaded
Chrome Cache Entry: 67
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 68
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 69
gzip compressed data, from Unix, original size modulo 2^32 273262
downloaded
Chrome Cache Entry: 70
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 71
gzip compressed data, original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 72
gzip compressed data, original size modulo 2^32 1592
dropped
Chrome Cache Entry: 73
gzip compressed data, from Unix, original size modulo 2^32 4739
downloaded
Chrome Cache Entry: 74
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 75
gzip compressed data, original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 76
gzip compressed data, from Unix, original size modulo 2^32 29024
downloaded
Chrome Cache Entry: 77
gzip compressed data, from Unix, original size modulo 2^32 96745
downloaded
Chrome Cache Entry: 78
gzip compressed data, from Unix, original size modulo 2^32 113689
downloaded
Chrome Cache Entry: 79
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 80
gzip compressed data, from Unix, original size modulo 2^32 8111
downloaded
Chrome Cache Entry: 81
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 82
gzip compressed data, original size modulo 2^32 3651
dropped
Chrome Cache Entry: 83
gzip compressed data, from Unix, original size modulo 2^32 55071
downloaded
Chrome Cache Entry: 84
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 85
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 86
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 87
gzip compressed data, from Unix, original size modulo 2^32 2405
downloaded
Chrome Cache Entry: 89
gzip compressed data, from Unix, original size modulo 2^32 209667
downloaded
Chrome Cache Entry: 90
gzip compressed data, original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 91
gzip compressed data, from Unix, original size modulo 2^32 113084
downloaded
Chrome Cache Entry: 92
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 93
gzip compressed data, from Unix, original size modulo 2^32 95910
downloaded
Chrome Cache Entry: 94
gzip compressed data, from Unix, original size modulo 2^32 141279
downloaded
Chrome Cache Entry: 95
gzip compressed data, from Unix, original size modulo 2^32 22961
downloaded
Chrome Cache Entry: 96
gzip compressed data, from Unix, original size modulo 2^32 223826
downloaded
Chrome Cache Entry: 97
gzip compressed data, from Unix, original size modulo 2^32 10141
downloaded
Chrome Cache Entry: 98
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 99
gzip compressed data, original size modulo 2^32 1864
downloaded
There are 29 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2264 --field-trial-handle=2212,i,6787345325031674847,628112371274147507,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://srmcorp.tecuidoc.com/?PSZlk=ViP"

URLs

Name
IP
Malicious
https://srmcorp.tecuidoc.com/?PSZlk=ViP
malicious
https://srmcorp.tecuidoc.com/?PSZlk=ViP&sso_reload=true
malicious
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
198.58.99.33
https://signup.tecuidoc.com/handlers/Watson
198.58.99.33
https://srmcorp.tecuidoc.com/favicon.ico
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/lwsignupstringscountrybirthdate_en-us_gdxUIqa3ijrOefuBnwhTKg2.js?v=1
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg
198.58.99.33
https://0a413710-7d4f53f3.tecuidoc.com/Prefetch/Prefetch.aspx
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/watson_DOaS_v-h3FCKtNPQv8zSLw2.js?v=1
198.58.99.33
https://l1ve.tecuidoc.com/oauth20_authorize.srf?scope=openid+profile+email+offline_access&response_type=code&client_id=51483342-085c-4d86-bf88-cf50c7252078&response_mode=form_post&redirect_uri=https%3a%2f%2fsrmcorp.tecuidoc.com%2fcommon%2ffederation%2foauth2msa&state=rQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAS-2C5ti-584NIeJumk-uG95ixGzviczDKwylWMyoSN07_AyPiCkfEWk6B_UbpnSnixW2pKalFiSWZ-3gUWgVcsPAbMVhwcXAIMEgwKDD9YGBexAm3VWO3s1Lcnw31_0fR5LYUijKdY9bMyUtxSLVJcS1Mz3V1TAnP1i1MrUqPcIgPTi6tSMyIqDSL0XXzdQzySfIptDa0MJ7AJTWBjOsXG8IGNsYOdYRY7wwFOxg08jAd4GX7wtW_9OXXigZnvPF7x6wSUhie6VVRFuYdblhXkm-Z5umtHOZunBQWVuZhUpOlHhUQ5O3qmOGa7p-XbbhBgAAA1&estsfed=1&uaid=86a53df4895b44e08756194225f0ef29&signup=1&lw=1&fl=easi2&fci=https%3a%2f%2f0a413710-7d4f53f3.tecuidoc.com.orgid.com
198.58.99.33
https://7457d826-7d4f53f3.tecuidoc.com/api/report?catId=GW+estsfd+ams2
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/converged_ux_v2_nBE5FSqn9KpH44ZlTc3VqQ2.css?v=1
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/images/signin-options_3e3f6b73c3f310c31d2c4d131a8ab8c6.svg
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/ests/2.1/content/cdnbundles/converged.v2.login.min_1ito3russhq-9gioj-zd4w2.css
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_7f0a8c2a247460fad87f.js
198.58.99.33
https://signup.tecuidoc.com/Resources/images/2_vD0yppaJX3jBnfbHF1hqXQ2.svg
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/images/2_vD0yppaJX3jBnfbHF1hqXQ2.svg
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/datarequestpackage_h-_7C7UzwdefXJT9njDBTQ2.js
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/oneds_MC5gQfpbTUjLu60sQCwU1w2.js?v=1
198.58.99.33
https://srmcorp.tecuidoc.com/?PSZlk=ViP
https://l1ve.tecuidoc.com/login.srf?wa=wsignin1.0&rpsnv=150&checkda=1&ct=1714143430&rver=7.5.2156.0&wp=MBI_SSL&wreply=https%3A%2F%2Fsignup.tecuidoc.com%2Fsignup%3Fsru%3Dhttps%253a%252f%252fl1ve.tecuidoc.com%252foauth20_authorize.srf%253flc%253d1033%2526client_id%253d51483342-085c-4d86-bf88-cf50c7252078%2526mkt%253dEN-US%2526opid%253dB6E95959DB8DBA86%2526opidt%253d1714143427%2526uaid%253d86a53df4895b44e08756194225f0ef29%2526contextid%253d5ABD0222F1D086D5%2526opignore%253d1%26mkt%3DEN-US%26uiflavor%3Dweb%26lw%3D1%26fl%3Deasi2%26client_id%3D51483342-085c-4d86-bf88-cf50c7252078%26uaid%3D86a53df4895b44e08756194225f0ef29%26suc%3Dhttps%253a%252f%252f0a413710-7d4f53f3.tecuidoc.com.orgid.com%26lic%3D1&lc=1033&id=68692&mkt=en-US&uaid=86a53df4895b44e08756194225f0ef29
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/lightweightsignuppackage_9itStK--DdHYjkMJSN7X3A2.js?v=1
198.58.99.33
https://l1ve.tecuidoc.com/Me.htm?v=3
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/js/asyncchunk/convergedlogin_pstringcustomizationhelper_eb638da25d4055fbbb57.js
198.58.99.33
https://signup.tecuidoc.com/signup?sru=https://l1ve.tecuidoc.com/oauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3dB6E95959DB8DBA86%26opidt%3d1714143427%26uaid%3d86a53df4895b44e08756194225f0ef29%26contextid%3d5ABD0222F1D086D5%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=86a53df4895b44e08756194225f0ef29&suc=https://2a9e5726-7d4f53f3.tecuidoc.com
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/jqueryshim_hlu0tTfjWJFWYNt1WZrVqg2.js?v=1
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/knockout_3.3.0_X1BYS2jZMbi7hfUj8VuqFA2.js?v=1
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/jquerypackage_1.10_5V7LAuc3bNAQx2QQfr1RPw2.js?v=1
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/images/favicon.ico?v=2
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif
198.58.99.33
https://srmcorp.tecuidoc.com/7d4f53f33e0f490ca63a57a3f299e2af/
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/js/asyncchunk/convergedlogin_presetpasswordsplitter_3c78f555810791db83a9.js
198.58.99.33
https://signup.tecuidoc.com/Resources/images/favicon.ico
198.58.99.33
https://eccd3fea-7d4f53f3.tecuidoc.com/shared/1.0/content/js/BssoInterrupt_Core_ChpboAn7HyXj89A22M8mzg2.js
198.58.99.33
https://7e55e394-7d4f53f3.tecuidoc.com/shared/1.0/content/js/ConvergedLogin_PCore_jHSrlUosdD1xxbmcR_lMNA2.js
198.58.99.33
https://bd6a002d-7d4f53f3.tecuidoc.com/datarequestpackage_h-_7C7UzwdefXJT9njDBTQ2.js?v=1
198.58.99.33
https://signup.tecuidoc.com/Resources/images/microsoft_logo_7lyNn7YkjJOP0NwZNw6QvQ2.svg
198.58.99.33
https://signup.tecuidoc.com/signup?sru=https%3a%2f%2fl1ve.tecuidoc.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3dB6E95959DB8DBA86%26opidt%3d1714143427%26uaid%3d86a53df4895b44e08756194225f0ef29%26contextid%3d5ABD0222F1D086D5%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=86a53df4895b44e08756194225f0ef29&suc=https%3a%2f%2f2a9e5726-7d4f53f3.tecuidoc.com&lic=1
There are 30 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
7457d826-7d4f53f3.tecuidoc.com
198.58.99.33
bd6a002d-7d4f53f3.tecuidoc.com
198.58.99.33
fp2e7a.wpc.phicdn.net
192.229.211.108
bg.microsoft.map.fastly.net
199.232.210.172
0a413710-7d4f53f3.tecuidoc.com
198.58.99.33
30e9fbb5-7d4f53f3.tecuidoc.com
198.58.99.33
a0d99ec0-7d4f53f3.tecuidoc.com
198.58.99.33
srmcorp.tecuidoc.com
198.58.99.33
l1ve.tecuidoc.com
198.58.99.33
www.google.com
142.250.217.196
eccd3fea-7d4f53f3.tecuidoc.com
198.58.99.33
a4a4d19d-7d4f53f3.tecuidoc.com
198.58.99.33
7e55e394-7d4f53f3.tecuidoc.com
198.58.99.33
signup.tecuidoc.com
198.58.99.33
There are 4 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
198.58.99.33
7457d826-7d4f53f3.tecuidoc.com
United States
142.250.217.196
www.google.com
United States
239.255.255.250
unknown
Reserved
192.168.2.6
unknown
unknown

DOM / HTML

URL
Malicious
https://srmcorp.tecuidoc.com/?PSZlk=ViP
malicious
https://srmcorp.tecuidoc.com/?PSZlk=ViP&sso_reload=true
malicious
https://srmcorp.tecuidoc.com/?PSZlk=ViP&sso_reload=true
malicious
https://srmcorp.tecuidoc.com/?PSZlk=ViP&sso_reload=true
malicious
https://srmcorp.tecuidoc.com/?PSZlk=ViP
https://srmcorp.tecuidoc.com/?PSZlk=ViP
https://0a413710-7d4f53f3.tecuidoc.com/Prefetch/Prefetch.aspx
https://signup.tecuidoc.com/signup?sru=https%3a%2f%2fl1ve.tecuidoc.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3dB6E95959DB8DBA86%26opidt%3d1714143427%26uaid%3d86a53df4895b44e08756194225f0ef29%26contextid%3d5ABD0222F1D086D5%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=86a53df4895b44e08756194225f0ef29&suc=https%3a%2f%2f2a9e5726-7d4f53f3.tecuidoc.com&lic=1
https://signup.tecuidoc.com/signup?sru=https%3a%2f%2fl1ve.tecuidoc.com%2foauth20_authorize.srf%3flc%3d1033%26client_id%3d51483342-085c-4d86-bf88-cf50c7252078%26mkt%3dEN-US%26opid%3dB6E95959DB8DBA86%26opidt%3d1714143427%26uaid%3d86a53df4895b44e08756194225f0ef29%26contextid%3d5ABD0222F1D086D5%26opignore%3d1&mkt=EN-US&uiflavor=web&lw=1&fl=easi2&client_id=51483342-085c-4d86-bf88-cf50c7252078&uaid=86a53df4895b44e08756194225f0ef29&suc=https%3a%2f%2f2a9e5726-7d4f53f3.tecuidoc.com&lic=1