IOC Report
Housecallpro Chase Bank ACH.htm

loading gif

Files

File Path
Type
Category
Malicious
Housecallpro Chase Bank ACH.htm
HTML document, ASCII text, with very long lines (1693), with no line terminators
initial sample
malicious
Chrome Cache Entry: 73
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 74
JSON data
dropped
Chrome Cache Entry: 75
ASCII text
downloaded
Chrome Cache Entry: 76
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 78
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "C:\Users\user\Desktop\Housecallpro Chase Bank ACH.htm"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2156 --field-trial-handle=2036,i,10491020609356299719,17026791416098519770,262144 /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://%3cfnc1%3e(79)/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2164 --field-trial-handle=1940,i,14694226768755553256,8904102379768142272,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
file:///C:/Users/user/Desktop/Housecallpro%20Chase%20Bank%20ACH.htm
malicious
https://bc1q2a22gd79umarrlvhudct2v5.com/lnk/cloud.js
185.216.70.216
https://aadcdn.msftauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
152.199.4.44
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.6.0/jquery.min.js
104.17.24.14
https://bc1qusz5l7h87pd2v6sv45nz82s.com/api/v3/auth
185.216.70.6

Domains

Name
IP
Malicious
bc1q2a22gd79umarrlvhudct2v5.com
185.216.70.216
google.com
192.178.50.46
bc1qusz5l7h87pd2v6sv45nz82s.com
185.216.70.6
cs1100.wpc.omegacdn.net
152.199.4.44
cdnjs.cloudflare.com
104.17.24.14
www.google.com
142.250.217.196
aadcdn.msftauth.net
unknown

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
185.216.70.6
bc1qusz5l7h87pd2v6sv45nz82s.com
Germany
152.199.4.44
cs1100.wpc.omegacdn.net
United States
192.168.2.17
unknown
unknown
192.168.2.4
unknown
unknown
142.250.217.196
www.google.com
United States
142.250.64.196
unknown
United States
239.255.255.250
unknown
Reserved
185.216.70.216
bc1q2a22gd79umarrlvhudct2v5.com
Germany

DOM / HTML

URL
Malicious
file:///C:/Users/user/Desktop/Housecallpro%20Chase%20Bank%20ACH.htm
file:///C:/Users/user/Desktop/Housecallpro%20Chase%20Bank%20ACH.htm
file:///C:/Users/user/Desktop/Housecallpro%20Chase%20Bank%20ACH.htm