IOC Report
http://v1.bcit.pro/2131005010/Instagram.com.html

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Aug 3 21:49:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Aug 3 21:49:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Aug 3 21:49:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Aug 3 21:49:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Sat Aug 3 21:49:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (543)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (3391)
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (3391)
downloaded
Chrome Cache Entry: 103
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 636x1280, components 3
downloaded
Chrome Cache Entry: 104
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (534)
dropped
Chrome Cache Entry: 106
ASCII text, with very long lines (543)
dropped
Chrome Cache Entry: 107
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 108
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 636x1280, components 3
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 110
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 111
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 112
PNG image data, 1200 x 1200, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 113
ASCII text
dropped
Chrome Cache Entry: 114
ASCII text
downloaded
Chrome Cache Entry: 115
ASCII text
dropped
Chrome Cache Entry: 116
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 117
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 118
ASCII text
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (3537)
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (1143)
dropped
Chrome Cache Entry: 121
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 122
ASCII text
downloaded
Chrome Cache Entry: 123
ASCII text
downloaded
Chrome Cache Entry: 89
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 90
ASCII text, with very long lines (809)
dropped
Chrome Cache Entry: 91
ASCII text, with very long lines (3537)
dropped
Chrome Cache Entry: 92
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 93
ASCII text
dropped
Chrome Cache Entry: 94
ASCII text, with very long lines (534)
downloaded
Chrome Cache Entry: 95
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 96
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 97
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 98
ASCII text, with very long lines (1143)
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (809)
downloaded
There are 32 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2760 --field-trial-handle=2608,i,17192106613044617387,2455478797431729721,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://v1.bcit.pro/2131005010/Instagram.com.html"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=3224 --field-trial-handle=2608,i,17192106613044617387,2455478797431729721,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5844 --field-trial-handle=2608,i,17192106613044617387,2455478797431729721,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
http://v1.bcit.pro/2131005010/Instagram.com.html
malicious
http://v1.bcit.pro/2131005010/Instagram.com.html
66.29.146.75
malicious
https://redux.js.org/tutorials/fundamentals/part-4-store#creating-a-store-with-enhancers
unknown
http://jquery.org/license
unknown
http://perfectionkills.com/detecting-event-support-without-browser-sniffing/
unknown
http://sizzlejs.com/
unknown
https://www.youtube.com/s/player/d2e656ee/player_ias.vflset/en_US/remote.js
172.217.16.206
https://support.google.com/youtube/?p=report_playback
unknown
https://v1.bcit.pro/2131005010/location.js
66.29.146.75
https://www.youtube.com/s/player/d2e656ee/www-player.css
172.217.16.206
http://youtube.com/streaming/otf/durations/112015
unknown
https://www.youtube.com/s/player/d2e656ee/player_ias.vflset/en_US/base.js
172.217.16.206
http://fluidproject.org/blog/2008/01/09/getting-setting-and-removing-tabindex-values-with-javascript
unknown
https://bugs.webkit.org/show_bug.cgi?id=29084
unknown
https://v1.bcit.pro/2131005010/Instagram.com.html
http://youtube.com/streaming/metadata/segment/102015
unknown
https://youtu.be/
unknown
http://blindsignals.com/index.php/2009/07/jquery-delay/
unknown
http://bugs.jquery.com/ticket/12282#comment:15
unknown
http://dev.w3.org/csswg/cssom/#resolved-values
unknown
http://api.jquery.com/jQuery.browser
unknown
https://admin.youtube.com
unknown
https://v1.bcit.pro/2131005010/client.min.js
66.29.146.75
https://www.youtube.com/youtubei/v1/log_event?alt=json&key=AIzaSyAO_FJ2SlqU8Q4STEHLGCilw_Y9_11qcW8
172.217.16.206
https://www.youtube.com/api/drm/fps?ek=
unknown
https://redux.js.org/tutorials/fundamentals/part-4-store#middleware
unknown