IOC Report
http://www.anovis.com.br/

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1772,i,1740651327127756512,7249462608667158532,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.anovis.com.br/

URLs

Name
IP
Malicious
http://www.anovis.com.br/
http://www.anovis.com.br/images/icone-liquidos-orais.png
179.188.52.129
http://www.anovis.com.br/images/galeria-2.jpg
179.188.52.129
https://oss.maxcdn.com/html5shiv/3.7.2/html5shiv.min.js
23.111.8.154
http://www.anovis.com.br/ilightbox/src/js/jquery.requestAnimationFrame.js
179.188.52.129
http://www.anovis.com.br/bootstrap/css/bootstrap.min.css
179.188.52.129
http://www.anovis.com.br/images/unidade-embu.jpg
179.188.52.129
http://www.anovis.com.br/images/rodape-site-anovis.jpg
179.188.52.129
http://www.anovis.com.br/stellar.js
179.188.52.129
http://www.anovis.com.br/ilightbox/src/light-skin/skin.css
179.188.52.129
http://www.anovis.com.br/images/novo-logo-uniao5.png
179.188.52.129
http://www.anovis.com.br/bootstrap/js/bootstrap.min.js
179.188.52.129
http://www.anovis.com.br/images/rodape-site-anovis-mobile.jpg
179.188.52.129
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
142.251.143.141
http://www.anovis.com.br/index.php
179.188.52.129
http://www.anovis.com.br/images/band_en.gif
179.188.52.129
http://www.anovis.com.br/
http://www.anovis.com.br/
179.188.52.129
http://www.anovis.com.br/ilightbox/src/metro-black-skin/skin.css
179.188.52.129
http://www.anovis.com.br/images/seta-naveg-baixo-2.png
179.188.52.129
http://www.anovis.com.br/ilightbox/src/metro-white-skin/skin.css
179.188.52.129
http://www.anovis.com.br/ilightbox/src/mac-skin/skin.css
179.188.52.129
https://oss.maxcdn.com/respond/1.4.2/respond.min.js
23.111.8.154
http://www.anovis.com.br/ilightbox/src/js/ilightbox.packed.js
179.188.52.129
http://www.anovis.com.br/ilightbox/src/css/ilightbox.css
179.188.52.129
http://www.anovis.com.br/images/icone-solidos-orais.png
179.188.52.129
http://www.anovis.com.br/images/home1.jpg
179.188.52.129
http://www.anovis.com.br/images/slide-footer-2.jpg
179.188.52.129
http://www.anovis.com.br/ilightbox/src/smooth-skin/skin.css
179.188.52.129
http://www.anovis.com.br/ilightbox/src/dark-skin/skin.css
179.188.52.129
http://www.anovis.com.br/images/galeria-4.jpg
179.188.52.129
http://www.anovis.com.br/respond.src.js
179.188.52.129
http://www.anovis.com.br/images/band_br.gif
179.188.52.129
http://www.anovis.com.br/ilightbox/src/js/jquery.mousewheel.js
179.188.52.129
http://www.anovis.com.br/images/logo-anovis.png
179.188.52.129
http://www.anovis.com.br/images/unidade-brasilia-2.jpg
179.188.52.129
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
142.251.143.174
http://www.anovis.com.br/images/unidade-taboao.jpg
179.188.52.129
http://www.anovis.com.br/images/unidade-pouso.jpg
179.188.52.129
http://www.anovis.com.br/index.php
http://www.anovis.com.br/images/slide-footer-1.jpg
179.188.52.129
http://www.anovis.com.br/ilightbox/src/parade-skin/skin.css
179.188.52.129
http://www.anovis.com.br/favicon.ico
179.188.52.129
http://www.anovis.com.br/images/icone-semi-solidos.png
179.188.52.129
http://www.anovis.com.br/images/galeria-1.jpg
179.188.52.129
There are 34 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
anovis.websiteseguro.com
186.202.188.90
accounts.google.com
142.251.143.141
www.anovis.com.br
179.188.52.129
www.google.com
142.251.143.132
clients.l.google.com
142.251.143.174
osscdn.netdnasa9.netdna-cdn.com
23.111.8.154
clients2.google.com
unknown
oss.maxcdn.com
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.1
unknown
unknown
186.202.188.90
anovis.websiteseguro.com
Brazil
179.188.52.129
www.anovis.com.br
Brazil
23.111.8.154
osscdn.netdnasa9.netdna-cdn.com
United States
239.255.255.250
unknown
Reserved
142.251.143.132
www.google.com
United States
142.251.143.141
accounts.google.com
United States
142.251.143.174
clients.l.google.com
United States
127.0.0.1
unknown
unknown

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.cdm.origin_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blocklist_cache_md5_digest
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_USERSS-1-5-19\Software\Microsoft\Cryptography\TPM\Telemetry
TraceTimeLast
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
There are 41 hidden registries, click here to show them.

DOM / HTML

URL
Malicious
http://www.anovis.com.br/
http://www.anovis.com.br/index.php
http://www.anovis.com.br/