IOC Report
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=2bdd817baf4e46e28f740a82bff8e850881b2c9159d1f9f1d332e339e76eea813a3f5893897cb7539a84e2eac2026594b5d62df0bbf5820b252c5afd2b02c9cd

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 61
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
dropped
Chrome Cache Entry: 62
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 63
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 64
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 65
HTML document, ASCII text, with very long lines (3445), with CRLF line terminators
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (48238)
downloaded
Chrome Cache Entry: 67
PNG image data, 9 x 40, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 68
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 69
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
dropped
Chrome Cache Entry: 70
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 71
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 72
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 73
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
downloaded
Chrome Cache Entry: 74
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 75
JSON data
dropped
Chrome Cache Entry: 76
ASCII text
downloaded
Chrome Cache Entry: 77
PNG image data, 9 x 40, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 78
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 79
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 80
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 81
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 82
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113424
downloaded
Chrome Cache Entry: 83
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
dropped
There are 14 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=3340,i,1354710186197194451,1516178957246450856,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=3440 /prefetch:3
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=2bdd817baf4e46e28f740a82bff8e850881b2c9159d1f9f1d332e339e76eea813a3f5893897cb7539a84e2eac2026594b5d62df0bbf5820b252c5afd2b02c9cd"

URLs

Name
IP
Malicious
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=2bdd817baf4e46e28f740a82bff8e850881b2c9159d1f9f1d332e339e76eea813a3f5893897cb7539a84e2eac2026594b5d62df0bbf5820b252c5afd2b02c9cd
malicious
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=2bdd817baf4e46e28f740a82bff8e850881b2c9159d1f9f1d332e339e76eea813a3f5893897cb7539a84e2eac2026594b5d62df0bbf5820b252c5afd2b02c9cd
23.95.206.231
https://hapiinenstys.criadordeconexoes.com.br/favicon.ico
23.95.206.231
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/d/921df19f1aa9330c/1742229751867/S9e8vOBS_eqZ502
104.18.94.41
https://login.microsoftonline.com
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://hapiinenstys.criadordeconexoes.com.br/?dataXX0=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1cmwiOiJodHRwczovL2hhcGlpbmVuc3R5cy5jcmlhZG9yZGVjb25leG9lcy5jb20uYnIvIiwiZG9tYWluIjoiaGFwaWluZW5zdHlzLmNyaWFkb3JkZWNvbmV4b2VzLmNvbS5iciIsImtleSI6InFWUDg3RWFGR0NRbiIsInFyYyI6bnVsbCwiaWF0IjoxNzQyMjI5NzYyLCJleHAiOjE3NDIyMjk4ODJ9.bpFU2t6kMODAzyr1sHzSD1xCGWuz2a7omLxO3ziToVg
23.95.206.231
https://hapiinenstys.criadordeconexoes.com.br/common/GetCredentialType?mkt=en-US
23.95.206.231
https://challenges.cloudflare.com/turnstile/v0/g/f3b948d8acb8/api.js
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1
104.18.94.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=921df19f1aa9330c&lang=auto
104.18.94.41
http://knockoutjs.com/
unknown
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=cebc15b3c86fa69be7285330a66657219c1287ff53c1f7059daa44d10ef1952d669e891ae8484a544c8d16f0be8cc4af98aec84015acb9fd06d2a3ccc941854c
https://hapiinenstys.criadordeconexoes.com.br/
23.95.206.231
https://login.windows-ppe.net
unknown
https://js.monitor.azure.com/scripts/c/ms.analytics-web-2.min.js
unknown
https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback
104.18.94.41
https://h89s9dhj.ccbequipamentos.com.br/favicon.ico
23.95.206.231
https://hapiinenstys.criadordeconexoes.com.br/?piwg10otu=aHR0cHM6Ly93d3cub2ZmaWNlLmNvbS9sb2dpbiM=
23.95.206.231
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv/va3bb/0x4AAAAAABAbx3VGqcPC-OGo/auto/fbE/new/normal/auto/
104.18.94.41
http://www.json.org/json2.js
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/921df19f1aa9330c/1742229751868/0df0701f524323cd1dd6ed6b0a6c711cea6cb7d910bb71d6d33d24befe49df70/2Si4XeZsCj928_7
104.18.94.41
There are 11 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
hapiinenstys.criadordeconexoes.com.br
23.95.206.231
malicious
e329293.dscd.akamaiedge.net
92.123.12.139
challenges.cloudflare.com
104.18.94.41
www.google.com
142.250.185.132
h89s9dhj.ccbequipamentos.com.br
23.95.206.231
s-part-0032.t-0009.t-msedge.net
13.107.246.60
aadcdn.msftauth.net
unknown

IPs

IP
Domain
Country
Malicious
23.95.206.231
hapiinenstys.criadordeconexoes.com.br
United States
malicious
104.18.94.41
challenges.cloudflare.com
United States
142.250.185.132
www.google.com
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://hapiinenstys.criadordeconexoes.com.br/?piwg10otu=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU/Y2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4Nzc4MjY1NjUxMDA2ODgwLk5HWXdZakJoTkdFdE1qbGpZUzAwTW1VekxUaG1NRE10TVdFelpHUTNaR1prTlRNNFpqVTBOMkkxTjJFdE16Y3pNQzAwTURaaExXRXdaRGd0WWpWbFptRXlNbVUyWVdNeCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD0zOTE5ZDJiOC1lZjIwLTQ0MDctOTI4Ni1jYjNlOWMxYWJhNzEmc3RhdGU9WHY5MFNmNENmWlFJcFE3WFFDQmFMUHYwMTRWcVd4dEk2d3dpbDBfZXdPRVNEc1BfQS1mOGEtN29CcTlQejdKZDhQcF9qcHJLQm1lR3ZodDdvU3RwR1ZUR1NlYkpacUdvNE1oN3h6eWdOZlh5V3ljQzFxSktEZ1ZLcV8xX3U1T0w4VFd5OFJnbWpBN3lzLS1RZDFhTjktSUFHc2F4aDVnWHpEYWZsZmp1NzBLZkc4eWMtamRHM2t2MzZWclY2THVXMGEwTkpaOTN4aHdnUXhkVG51S3NraDBaZnhYMGp
malicious
https://hapiinenstys.criadordeconexoes.com.br/?piwg10otu=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU/Y2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4Nzc4MjY1NjUxMDA2ODgwLk5HWXdZakJoTkdFdE1qbGpZUzAwTW1VekxUaG1NRE10TVdFelpHUTNaR1prTlRNNFpqVTBOMkkxTjJFdE16Y3pNQzAwTURaaExXRXdaRGd0WWpWbFptRXlNbVUyWVdNeCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD0zOTE5ZDJiOC1lZjIwLTQ0MDctOTI4Ni1jYjNlOWMxYWJhNzEmc3RhdGU9WHY5MFNmNENmWlFJcFE3WFFDQmFMUHYwMTRWcVd4dEk2d3dpbDBfZXdPRVNEc1BfQS1mOGEtN29CcTlQejdKZDhQcF9qcHJLQm1lR3ZodDdvU3RwR1ZUR1NlYkpacUdvNE1oN3h6eWdOZlh5V3ljQzFxSktEZ1ZLcV8xX3U1T0w4VFd5OFJnbWpBN3lzLS1RZDFhTjktSUFHc2F4aDVnWHpEYWZsZmp1NzBLZkc4eWMtamRHM2t2MzZWclY2THVXMGEwTkpaOTN4aHdnUXhkVG51S3NraDBaZnhYMGp
malicious
https://hapiinenstys.criadordeconexoes.com.br/?piwg10otu=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU/Y2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4Nzc4MjY1NjUxMDA2ODgwLk5HWXdZakJoTkdFdE1qbGpZUzAwTW1VekxUaG1NRE10TVdFelpHUTNaR1prTlRNNFpqVTBOMkkxTjJFdE16Y3pNQzAwTURaaExXRXdaRGd0WWpWbFptRXlNbVUyWVdNeCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD0zOTE5ZDJiOC1lZjIwLTQ0MDctOTI4Ni1jYjNlOWMxYWJhNzEmc3RhdGU9WHY5MFNmNENmWlFJcFE3WFFDQmFMUHYwMTRWcVd4dEk2d3dpbDBfZXdPRVNEc1BfQS1mOGEtN29CcTlQejdKZDhQcF9qcHJLQm1lR3ZodDdvU3RwR1ZUR1NlYkpacUdvNE1oN3h6eWdOZlh5V3ljQzFxSktEZ1ZLcV8xX3U1T0w4VFd5OFJnbWpBN3lzLS1RZDFhTjktSUFHc2F4aDVnWHpEYWZsZmp1NzBLZkc4eWMtamRHM2t2MzZWclY2THVXMGEwTkpaOTN4aHdnUXhkVG51S3NraDBaZnhYMGp
malicious
https://hapiinenstys.criadordeconexoes.com.br/?piwg10otu=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU/Y2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4Nzc4MjY1NjUxMDA2ODgwLk5HWXdZakJoTkdFdE1qbGpZUzAwTW1VekxUaG1NRE10TVdFelpHUTNaR1prTlRNNFpqVTBOMkkxTjJFdE16Y3pNQzAwTURaaExXRXdaRGd0WWpWbFptRXlNbVUyWVdNeCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD0zOTE5ZDJiOC1lZjIwLTQ0MDctOTI4Ni1jYjNlOWMxYWJhNzEmc3RhdGU9WHY5MFNmNENmWlFJcFE3WFFDQmFMUHYwMTRWcVd4dEk2d3dpbDBfZXdPRVNEc1BfQS1mOGEtN29CcTlQejdKZDhQcF9qcHJLQm1lR3ZodDdvU3RwR1ZUR1NlYkpacUdvNE1oN3h6eWdOZlh5V3ljQzFxSktEZ1ZLcV8xX3U1T0w4VFd5OFJnbWpBN3lzLS1RZDFhTjktSUFHc2F4aDVnWHpEYWZsZmp1NzBLZkc4eWMtamRHM2t2MzZWclY2THVXMGEwTkpaOTN4aHdnUXhkVG51S3NraDBaZnhYMGp
malicious
https://hapiinenstys.criadordeconexoes.com.br/?piwg10otu=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU/Y2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4Nzc4MjY1NjUxMDA2ODgwLk5HWXdZakJoTkdFdE1qbGpZUzAwTW1VekxUaG1NRE10TVdFelpHUTNaR1prTlRNNFpqVTBOMkkxTjJFdE16Y3pNQzAwTURaaExXRXdaRGd0WWpWbFptRXlNbVUyWVdNeCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD0zOTE5ZDJiOC1lZjIwLTQ0MDctOTI4Ni1jYjNlOWMxYWJhNzEmc3RhdGU9WHY5MFNmNENmWlFJcFE3WFFDQmFMUHYwMTRWcVd4dEk2d3dpbDBfZXdPRVNEc1BfQS1mOGEtN29CcTlQejdKZDhQcF9qcHJLQm1lR3ZodDdvU3RwR1ZUR1NlYkpacUdvNE1oN3h6eWdOZlh5V3ljQzFxSktEZ1ZLcV8xX3U1T0w4VFd5OFJnbWpBN3lzLS1RZDFhTjktSUFHc2F4aDVnWHpEYWZsZmp1NzBLZkc4eWMtamRHM2t2MzZWclY2THVXMGEwTkpaOTN4aHdnUXhkVG51S3NraDBaZnhYMGp
malicious
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=cebc15b3c86fa69be7285330a66657219c1287ff53c1f7059daa44d10ef1952d669e891ae8484a544c8d16f0be8cc4af98aec84015acb9fd06d2a3ccc941854c
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=cebc15b3c86fa69be7285330a66657219c1287ff53c1f7059daa44d10ef1952d669e891ae8484a544c8d16f0be8cc4af98aec84015acb9fd06d2a3ccc941854c
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=cebc15b3c86fa69be7285330a66657219c1287ff53c1f7059daa44d10ef1952d669e891ae8484a544c8d16f0be8cc4af98aec84015acb9fd06d2a3ccc941854c
https://h89s9dhj.ccbequipamentos.com.br/?noiajvga=cebc15b3c86fa69be7285330a66657219c1287ff53c1f7059daa44d10ef1952d669e891ae8484a544c8d16f0be8cc4af98aec84015acb9fd06d2a3ccc941854c
https://hapiinenstys.criadordeconexoes.com.br/?piwg10otu=aHR0cHM6Ly9sb2dpbi5taWNyb3NvZnRvbmxpbmUuY29tL2NvbW1vbi9vYXV0aDIvdjIuMC9hdXRob3JpemU/Y2xpZW50X2lkPTQ3NjU0NDViLTMyYzYtNDliMC04M2U2LTFkOTM3NjUyNzZjYSZyZWRpcmVjdF91cmk9aHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRmxhbmRpbmd2MiZyZXNwb25zZV90eXBlPWNvZGUlMjBpZF90b2tlbiZzY29wZT1vcGVuaWQlMjBwcm9maWxlJTIwaHR0cHMlM0ElMkYlMkZ3d3cub2ZmaWNlLmNvbSUyRnYyJTJGT2ZmaWNlSG9tZS5BbGwmcmVzcG9uc2VfbW9kZT1mb3JtX3Bvc3Qmbm9uY2U9NjM4Nzc4MjY1NjUxMDA2ODgwLk5HWXdZakJoTkdFdE1qbGpZUzAwTW1VekxUaG1NRE10TVdFelpHUTNaR1prTlRNNFpqVTBOMkkxTjJFdE16Y3pNQzAwTURaaExXRXdaRGd0WWpWbFptRXlNbVUyWVdNeCZ1aV9sb2NhbGVzPWVuLVVTJm1rdD1lbi1VUyZjbGllbnQtcmVxdWVzdC1pZD0zOTE5ZDJiOC1lZjIwLTQ0MDctOTI4Ni1jYjNlOWMxYWJhNzEmc3RhdGU9WHY5MFNmNENmWlFJcFE3WFFDQmFMUHYwMTRWcVd4dEk2d3dpbDBfZXdPRVNEc1BfQS1mOGEtN29CcTlQejdKZDhQcF9qcHJLQm1lR3ZodDdvU3RwR1ZUR1NlYkpacUdvNE1oN3h6eWdOZlh5V3ljQzFxSktEZ1ZLcV8xX3U1T0w4VFd5OFJnbWpBN3lzLS1RZDFhTjktSUFHc2F4aDVnWHpEYWZsZmp1NzBLZkc4eWMtamRHM2t2MzZWclY2THVXMGEwTkpaOTN4aHdnUXhkVG51S3NraDBaZnhYMGp