IOC Report
http://asana.wf

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\Unconfirmed 106083.crdownload
Zip archive data, at least v4.5 to extract, compression method=deflate
dropped
C:\Users\user\Downloads\Unconfirmed 706069.crdownload
Zip archive data, at least v4.5 to extract, compression method=deflate
dropped
C:\Users\user\Downloads\a9efdc0f-0266-436e-9362-0ed770e01d09.tmp
Zip archive data, at least v4.5 to extract, compression method=deflate
dropped
Chrome Cache Entry: 100
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 101
HTML document, Unicode text, UTF-8 text, with very long lines (2508)
downloaded
Chrome Cache Entry: 102
MS Windows icon resource - 1 icon, 100x100, 32 bits/pixel
downloaded
Chrome Cache Entry: 103
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 104
HTML document, Unicode text, UTF-8 text, with very long lines (2508)
downloaded
Chrome Cache Entry: 105
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 106
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 107
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 108
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 109
Zip archive data, at least v4.5 to extract, compression method=deflate
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (512)
downloaded
Chrome Cache Entry: 111
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 112
MS Windows icon resource - 1 icon, 100x100, 32 bits/pixel
dropped
Chrome Cache Entry: 113
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 114
JSON data
dropped
Chrome Cache Entry: 115
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 116
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 117
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 118
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 119
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 120
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 121
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 68
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 69
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 70
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 71
JSON data
downloaded
Chrome Cache Entry: 72
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 73
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 74
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 75
HTML document, ASCII text
downloaded
Chrome Cache Entry: 76
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 77
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 78
HTML document, ASCII text
downloaded
Chrome Cache Entry: 79
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 80
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 81
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 82
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 83
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 84
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 85
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 86
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 87
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 88
Web Open Font Format, TrueType, length 56800, version 1.0
downloaded
Chrome Cache Entry: 89
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 90
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 91
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 92
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 93
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 94
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 95
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 96
RIFF (little-endian) data, Web/P image, VP8 encoding, 560x373, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 97
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 98
Web Open Font Format, TrueType, length 55956, version 1.0
downloaded
Chrome Cache Entry: 99
ASCII text, with CRLF line terminators
downloaded
There are 48 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2096 --field-trial-handle=1588,i,612205804712809674,15560752012359906843,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://asana.wf"

URLs

Name
IP
Malicious
http://asana.wf
https://asana.wf/fonts/gordita/gordita-regular.woff
94.131.101.65
https://asana.wf/img/logo-ratio-40pxheight-Dell.svg
94.131.101.65
https://cdn1124.net/9e4e27b7-bcfb-4298-bf8f-2cf4a6bdb3bf-9b6b40d6-3f8e-4755-9063-562658ebdb95
138.124.184.250
https://asana.wf/img/card-sony-music-asana-customer.webp
94.131.101.65
https://asana.wf/fonts/gordita/gordita-medium.woff
94.131.101.65
https://asana.wf/img/HOME24-web-hero-IDC-2x-en-US.webp
94.131.101.65
https://asana.wf/download.php
94.131.101.65
https://cdn1124.net/files/Asana.msix
138.124.184.250
https://asana.wf/img/home24-marketing-team-en-ui.webp
94.131.101.65
https://asana.wf/img/logo-ratio-40pxheight-Amazon.svg
94.131.101.65
https://asana.wf/img/home24-demo-thumbnail.webp
94.131.101.65
http://asana.wf/
94.131.101.65
https://api.ipify.org?format=json
unknown
https://asana.wf/css/reskin-0451c4949d.css
94.131.101.65
https://asana.wf/
https://asana.wf/img/logo-ratio-40pxheight-Johnson-Johnson.svg
94.131.101.65
http://asana.com/resources/anatomy-of-work
unknown
https://asana.wf/img/home24-ai-en.webp
94.131.101.65
https://asana.wf/img/card-overstock-asana-customer.webp
94.131.101.65
https://asana.wf/img/logo-ratio-40pxheight-McKesson.svg
94.131.101.65
https://asana.wf/img/logo-ratio-40pxheight-merck.webp
94.131.101.65
https://asana.wf/img/HOME24-web-hero-3x-en-US.webp
94.131.101.65
https://asana.wf/img/home24-resources-thumbnail.webp
94.131.101.65
https://asana.wf/img/card-figma-asana-customer.webp
94.131.101.65
https://asana.wf/img/home24-goals-ui.webp
94.131.101.65
https://api.ipify.org/?format=json
172.67.74.152
https://asana.wf/img/HOME24-web-hero-gartner-2x-en-US.webp
94.131.101.65
https://asana.wf/assets/img/brand/asana-logo-favicon.ico
94.131.101.65
https://asana.wf/index.html#i18n
https://asana.wf/img/home24-security.webp
94.131.101.65
https://asana.wf/img/card-zoom-1x.webp
94.131.101.65
https://asana.wf/css/style.css
94.131.101.65
https://asana.wf/img/HOME24-web-hero-forrester-2x-en-US.webp
94.131.101.65
https://asana.wf/pop-up.js
94.131.101.65
https://asana.wf/index.html
94.131.101.65
https://asana.wf/img/card-hubspot.webp
94.131.101.65
https://asana.wf/img/home24-templates-thumbnail.webp
94.131.101.65
https://asana.wf/assets/svg/icons.svg
94.131.101.65
There are 28 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
asana.wf
94.131.101.65
cdn1124.net
138.124.184.250
www.google.com
142.250.217.164
api.ipify.org
172.67.74.152

IPs

IP
Domain
Country
Malicious
94.131.101.65
asana.wf
Ukraine
142.250.217.164
www.google.com
United States
239.255.255.250
unknown
Reserved
138.124.184.250
cdn1124.net
Norway
192.168.2.4
unknown
unknown
172.67.74.152
api.ipify.org
United States

DOM / HTML

URL
Malicious
https://asana.wf/
https://asana.wf/index.html#i18n