IOC Report
https://usdtmen.com

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://usdtmen.com/
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2040 --field-trial-handle=1776,i,2961118636078509660,12337485403736736407,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://usdtmen.com
https://usdtmen.com/index/order/index.html
154.211.96.136
https://usdtmen.com/layer3.1/layer.js
154.211.96.136
https://usdtmen.com/index/index/index.html
https://usdtmen.com/index/news/about.html
https://usdtmen.com/image/nav1.png
154.211.96.136
https://usdtmen.com/image/fr.jpg
154.211.96.136
https://usdtmen.com/image/bg1.6c9f941a.png
154.211.96.136
https://usdtmen.com/image/records1.png
154.211.96.136
https://usdtmen.com/index/passport/logout.html
154.211.96.136
https://usdtmen.com/image/portrait.jpeg
154.211.96.136
https://usdtmen.com/image/weui.min.js
154.211.96.136
https://usdtmen.com/image/viplevel_icon.png
154.211.96.136
https://usdtmen.com/image/withdraw_icon.png
154.211.96.136
https://usdtmen.com/image/nav2.png
154.211.96.136
https://usdtmen.com/layer3.1/theme/default/layer.css?v=3.1.1
154.211.96.136
https://usdtmen.com/image/records2.png
154.211.96.136
https://usdtmen.com/index/passport/login.html
154.211.96.136
https://usdtmen.com/image/nav3.png
154.211.96.136
https://usdtmen.com/image/common.css
154.211.96.136
https://usdtmen.com/image/menu.png
154.211.96.136
https://beacons2.gvt2.com/domainreliability/upload-nel
216.239.38.117
https://usdtmen.com/index/passport/login.html
https://usdtmen.com/favicon.ico
154.211.96.136
https://usdtmen.com/image/zepto.min.js
154.211.96.136
https://usdtmen.com/image/nav4.png
154.211.96.136
https://usdtmen.com/image/weui.css
154.211.96.136
https://usdtmen.com/
154.211.96.136
https://usdtmen.com/image/iconfont.css
154.211.96.136
https://usdtmen.com/image/nav5.png
154.211.96.136
https://usdtmen.com/image/jquery.min.js
154.211.96.136
https://usdtmen.com/image/es-es.jpg
154.211.96.136
https://usdtmen.com/image/transfer_icon.png
154.211.96.136
https://usdtmen.com/image/password_icon.png
154.211.96.136
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
142.250.184.237
https://usdtmen.com/image/head.b8e5d31e.png
154.211.96.136
https://usdtmen.com/image/bootstrap.min.css
154.211.96.136
https://usdtmen.com/image/card.8c0955e2.png
154.211.96.136
https://usdtmen.com/image/deposit_icon.png
154.211.96.136
https://usdtmen.com/image/nav6.png
154.211.96.136
https://usdtmen.com/image/icons8-tether-48.png
154.211.96.136
https://usdtmen.com/image/common.js
154.211.96.136
https://usdtmen.com/image/ko.jpg
154.211.96.136
https://usdtmen.com/image/username_icon.png
154.211.96.136
https://usdtmen.com/index/index/index.html
154.211.96.136
https://usdtmen.com/image/bootstrap.min.css.map
154.211.96.136
https://usdtmen.com/index/news/about.html
154.211.96.136
https://accounts.google.com/domainreliability/upload
142.250.184.237
https://usdtmen.com/image/nav7.png
154.211.96.136
https://usdtmen.com/image/logo.cba20b1b.png
154.211.96.136
https://usdtmen.com/image/ar-ae.jpg
154.211.96.136
https://usdtmen.com/image/pt-pt.jpg
154.211.96.136
https://usdtmen.com/index/order/index.html
https://usdtmen.com/image/nav9.png
154.211.96.136
https://usdtmen.com/image/en-us.jpg
154.211.96.136
https://usdtmen.com/image/nav8.png
154.211.96.136
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.102&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
142.250.186.110
There are 46 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
accounts.google.com
142.250.184.237
usdtmen.com
154.211.96.136
www.google.com
142.250.185.132
beacons2.gvt2.com
216.239.38.117
clients.l.google.com
142.250.186.110
clients2.google.com
unknown

IPs

IP
Domain
Country
Malicious
154.211.96.136
usdtmen.com
Seychelles
142.250.185.100
unknown
United States
239.255.255.250
unknown
Reserved
142.250.184.237
accounts.google.com
United States
142.250.186.110
clients.l.google.com
United States
172.217.16.196
unknown
United States
127.0.0.1
unknown
unknown
216.239.38.117
beacons2.gvt2.com
United States

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-2660496737-530772487-1027249058-1001
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.cdm.origin_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blocklist_cache_md5_digest
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_USERSS-1-5-19\Software\Microsoft\Cryptography\TPM\Telemetry
TraceTimeLast
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-2660496737-530772487-1027249058-1001
There are 36 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
6F3337E000
stack
page read and write
264D5703000
heap
page read and write
264D5726000
heap
page read and write
264D56D2000
heap
page read and write
264D5FAE000
heap
page read and write
264D5905000
heap
page read and write
264D565E000
heap
page read and write
6F332FE000
stack
page read and write
264D5720000
heap
page read and write
264D5FAD000
heap
page read and write
264D5FB5000
heap
page read and write
264D5FA3000
heap
page read and write
2BB6FD13000
heap
page read and write
264D56E0000
heap
page read and write
E93757E000
stack
page read and write
2BB6FC6D000
heap
page read and write
264D573E000
heap
page read and write
6F334FB000
stack
page read and write
264D56DD000
heap
page read and write
264D5685000
heap
page read and write
264D5692000
heap
page read and write
264D56AB000
heap
page read and write
264D56A7000
heap
page read and write
264D56C4000
heap
page read and write
264D5716000
heap
page read and write
264D6307000
heap
page read and write
E937377000
stack
page read and write
264D5711000
heap
page read and write
264D5700000
heap
page read and write
264D573E000
heap
page read and write
264D5682000
heap
page read and write
264D56F1000
heap
page read and write
264D5682000
heap
page read and write
264D61BA000
heap
page read and write
264D56BB000
heap
page read and write
264D56C8000
heap
page read and write
264D630C000
heap
page read and write
2BB70415000
heap
page read and write
264D571C000
heap
page read and write
264D56BC000
heap
page read and write
264D56F1000
heap
page read and write
264D5740000
heap
page read and write
264D56E0000
heap
page read and write
2BB6FC55000
heap
page read and write
264D630E000
heap
page read and write
264D56D2000
heap
page read and write
264D56FA000
heap
page read and write
264D5712000
heap
page read and write
264D5640000
heap
page read and write
264D5FA9000
heap
page read and write
264D56D6000
heap
page read and write
264D630B000
heap
page read and write
6F333FC000
stack
page read and write
264D56C4000
heap
page read and write
6F335FE000
stack
page read and write
E93747B000
stack
page read and write
264D6309000
heap
page read and write
264D572B000
heap
page read and write
2BB6FD00000
heap
page read and write
264D573E000
heap
page read and write
264D61B2000
heap
page read and write
264D5673000
heap
page read and write
264D572B000
heap
page read and write
E936DCE000
stack
page read and write
264D61B0000
heap
page read and write
264D5900000
heap
page read and write
2BB6FC13000
heap
page read and write
264D56D2000
heap
page read and write
264D61B5000
heap
page read and write
264D56B9000
heap
page read and write
264D60C0000
heap
page read and write
264D5730000
heap
page read and write
E93767E000
stack
page read and write
264D5610000
heap
page read and write
264D5736000
heap
page read and write
264D54F0000
heap
page read and write
264D571E000
heap
page read and write
264D5733000
heap
page read and write
264D56AF000
heap
page read and write
264D6311000
heap
page read and write
264D56E3000
heap
page read and write
264D5705000
heap
page read and write
264D56C2000
heap
page read and write
264D56E3000
heap
page read and write
264D56E5000
heap
page read and write
264D61BB000
heap
page read and write
264D56F1000
heap
page read and write
264D56CA000
heap
page read and write
2BB6FC77000
heap
page read and write
264D56B8000
heap
page read and write
264D5FC2000
heap
page read and write
2BB6FC00000
heap
page read and write
264D566B000
heap
page read and write
264D568D000
heap
page read and write
6F3347E000
stack
page read and write
6F33277000
stack
page read and write
264D5730000
heap
page read and write
264D6314000
heap
page read and write
264D5733000
heap
page read and write
264D56D6000
heap
page read and write
264D569B000
heap
page read and write
264D5723000
heap
page read and write
2BB6FC84000
heap
page read and write
264D568E000
heap
page read and write
E936D4C000
stack
page read and write
264D61BE000
heap
page read and write
264D5FAD000
heap
page read and write
264D5FA4000
heap
page read and write
264D5FA0000
heap
page read and write
264D56AB000
heap
page read and write
264D56DD000
heap
page read and write
264D5699000
heap
page read and write
264D56F8000
heap
page read and write
2BB70402000
heap
page read and write
264D61B7000
heap
page read and write
264D5FB8000
heap
page read and write
264D61BA000
heap
page read and write
264D5729000
heap
page read and write
E937178000
stack
page read and write
264D572B000
heap
page read and write
264D570A000
heap
page read and write
264D56F8000
heap
page read and write
264D61B4000
heap
page read and write
264D5726000
heap
page read and write
264D5730000
heap
page read and write
264D5711000
heap
page read and write
264D56FB000
heap
page read and write
264D61B7000
heap
page read and write
264D5659000
heap
page read and write
2BB6FD02000
heap
page read and write
264D56FE000
heap
page read and write
E93707E000
stack
page read and write
2BB6FA80000
heap
page read and write
264D5738000
heap
page read and write
264D56EF000
heap
page read and write
2BB6FC44000
heap
page read and write
264D5648000
heap
page read and write
264D5709000
heap
page read and write
264D56CA000
heap
page read and write
264D5FA3000
heap
page read and write
264D569F000
heap
page read and write
264D56E0000
heap
page read and write
264D61B3000
heap
page read and write
2BB70400000
heap
page read and write
264D56C4000
heap
page read and write
264D6316000
heap
page read and write
264D5699000
heap
page read and write
264D5738000
heap
page read and write
264D568B000
heap
page read and write
264D56DD000
heap
page read and write
6F3357E000
stack
page read and write
264D5729000
heap
page read and write
264D56A7000
heap
page read and write
2BB6FA20000
heap
page read and write
264D5FB6000
heap
page read and write
264D568D000
heap
page read and write
2BB6FA10000
heap
page read and write
2BB6FB80000
trusted library allocation
page read and write
264D56A0000
heap
page read and write
264D5719000
heap
page read and write
264D5709000
heap
page read and write
E93727B000
stack
page read and write
264D56DC000
heap
page read and write
264D56B6000
heap
page read and write
264D61BA000
heap
page read and write
2BB6FC2A000
heap
page read and write
264D568B000
heap
page read and write
264D6300000
heap
page read and write
There are 158 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://usdtmen.com/index/passport/login.html
https://usdtmen.com/index/index/index.html
https://usdtmen.com/index/news/about.html
https://usdtmen.com/index/order/index.html