IOC Report
http://lcattertonpe.com

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1960 --field-trial-handle=1736,i,823529605349688411,4145770639965686966,131072 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "http://lcattertonpe.com

URLs

Name
IP
Malicious
http://lcattertonpe.com
https://stats.g.doubleclick.net/j/collect?t=dc&aip=1&_r=3&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&gjid=1286070036&_gid=1283538996.1675822043&_u=YEBAAUAAAAAAACAAI~&z=612317697
142.251.31.155
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/webfonts/fa-brands-400.woff2
104.17.24.14
http://lcattertonpe.com/
2.57.90.16
https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/css/bootstrap.min.css
104.18.10.207
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/webfonts/fa-solid-900.woff2
104.17.24.14
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
216.58.209.45
https://www.google.com/ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&_u=YEBAAUAAAAAAACAAI~&z=481455849
142.250.184.100
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=104.0.5112.81&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1
142.250.180.174
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.15.3/css/all.min.css
104.17.24.14
https://www.google.co.uk/ads/ga-audiences?t=sr&aip=1&_r=4&slf_rd=1&v=1&_v=j99&tid=UA-26575989-44&cid=315444834.1675822043&jid=1751296008&_u=YEBAAUAAAAAAACAAI~&z=481455849
142.251.209.3
http://lcattertonpe.com/
https://maxcdn.bootstrapcdn.com/bootstrap/3.3.7/js/bootstrap.min.js
104.18.10.207
http://lcattertonpe.com/favicon.ico
2.57.90.16
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
accounts.google.com
216.58.209.45
lcattertonpe.com
2.57.90.16
cdnjs.cloudflare.com
104.17.24.14
www.google.co.uk
142.251.209.3
maxcdn.bootstrapcdn.com
104.18.10.207
www.google.com
142.250.184.100
clients.l.google.com
142.250.180.174
stats.g.doubleclick.net
142.251.31.155
cpanel.hostinger.com
unknown
clients2.google.com
unknown
cdn.hostinger.com
unknown
support.hostinger.com
unknown
www.hostinger.com
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
192.168.2.1
unknown
unknown
104.18.10.207
maxcdn.bootstrapcdn.com
United States
142.251.31.155
stats.g.doubleclick.net
United States
142.251.209.3
www.google.co.uk
United States
216.58.209.45
accounts.google.com
United States
239.255.255.250
unknown
Reserved
142.250.184.100
www.google.com
United States
142.250.180.174
clients.l.google.com
United States
2.57.90.16
lcattertonpe.com
Lithuania
127.0.0.1
unknown
unknown
There are 1 hidden IPs, click here to show them.

Registry

Path
Value
Malicious
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gdaefkejpgkiemlaofpalmlakkmbjdnl
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.cdm.origin_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.reporting
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
media.storage_id_salt
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.account_id
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
module_blocklist_cache_md5_digest
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_seed
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
default_search_provider_data.template_url_data
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
safebrowsing.incidents_sent
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
pinned_tabs
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
browser.show_home_button
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
search_provider_overrides
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.last_triggered_for_default_search
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
prefs.preference_reset_time
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
software_reporter.prompt_version
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
google.services.last_username
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.startup_urls
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
session.restore_on_startup
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
settings_reset_prompt.prompt_wave
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default
homepage_is_newtabpage
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
HKEY_USERSS-1-5-19\Software\Microsoft\Cryptography\TPM\Telemetry
TraceTimeLast
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\LastWasDefault
S-1-5-21-3853321935-2125563209-4053062332-1002
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
There are 42 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
276DBFF000
stack
page read and write
2652C890000
trusted library allocation
page read and write
20B93A87000
heap
page read and write
20B93A3E000
heap
page read and write
1D37A79000
stack
page read and write
222F5864000
heap
page read and write
20BEDE41000
heap
page read and write
222F5842000
heap
page read and write
20B93A6E000
heap
page read and write
20B93A66000
heap
page read and write
222F585A000
heap
page read and write
1C11DE91000
heap
page read and write
222F5884000
heap
page read and write
1C11DE2A000
heap
page read and write
2508AE50000
heap
page read and write
2508B03B000
heap
page read and write
A52857D000
stack
page read and write
276D9FE000
stack
page read and write
2508ADF0000
heap
page read and write
B0E4B7D000
stack
page read and write
1C11E722000
heap
page read and write
1C11DE43000
heap
page read and write
1C11DC70000
heap
page read and write
222F57B0000
heap
page read and write
2652C05C000
heap
page read and write
1C11E78E000
heap
page read and write
222F5860000
heap
page read and write
1D3777B000
stack
page read and write
B0E47FE000
stack
page read and write
1C11E722000
heap
page read and write
1C11DF13000
heap
page read and write
1C11DE2F000
heap
page read and write
1C11DE8F000
heap
page read and write
1C11E813000
heap
page read and write
9CDE57E000
stack
page read and write
A5289FE000
stack
page read and write
2652C03D000
heap
page read and write
9CDE3FB000
stack
page read and write
20B94402000
heap
page read and write
20BEDCF0000
heap
page read and write
B0E4CFF000
stack
page read and write
1C11DDD0000
trusted library allocation
page read and write
1C11DE13000
heap
page read and write
222F5800000
heap
page read and write
1C11DE00000
heap
page read and write
222F5857000
heap
page read and write
A5285FB000
stack
page read and write
2652BF90000
heap
page read and write
2508B02F000
heap
page read and write
1C11E743000
heap
page read and write
9CDEA7F000
stack
page read and write
2508B029000
heap
page read and write
1C11E700000
heap
page read and write
20B93920000
heap
page read and write
20BEDE00000
heap
page read and write
1C11E5A0000
trusted library allocation
page read and write
20BEE802000
trusted library allocation
page read and write
2652C063000
heap
page read and write
20B9453A000
heap
page read and write
A5286FC000
stack
page read and write
2652C002000
heap
page read and write
1C11E7AE000
heap
page read and write
20B93930000
heap
page read and write
D3E7979000
stack
page read and write
A52807F000
stack
page read and write
1D379FB000
stack
page read and write
276D6FE000
stack
page read and write
1C11DE6C000
heap
page read and write
1D37E7E000
stack
page read and write
9CDE87D000
stack
page read and write
A5280FC000
stack
page read and write
1C11DE86000
heap
page read and write
20BEDE02000
heap
page read and write
222F5902000
heap
page read and write
2508B054000
heap
page read and write
2508B102000
heap
page read and write
222F6202000
trusted library allocation
page read and write
20BEDE29000
heap
page read and write
1C11E823000
heap
page read and write
A52837C000
stack
page read and write
20B94500000
heap
page read and write
20B93B13000
heap
page read and write
1D37D7E000
stack
page read and write
B0E428C000
stack
page read and write
20BEDD60000
heap
page read and write
B0E477F000
stack
page read and write
2652C8C0000
remote allocation
page read and write
2652C055000
heap
page read and write
222F5869000
heap
page read and write
2652BFF0000
heap
page read and write
B0E4A7E000
stack
page read and write
222F5740000
heap
page read and write
D3E7B7E000
stack
page read and write
20BEDF13000
heap
page read and write
20B93ABC000
heap
page read and write
276DAFE000
stack
page read and write
276D77E000
stack
page read and write
2652C013000
heap
page read and write
20BEDE13000
heap
page read and write
2508AF50000
trusted library allocation
page read and write
2508AE00000
heap
page read and write
2508B802000
trusted library allocation
page read and write
9CDEC7E000
stack
page read and write
222F583C000
heap
page read and write
222F5831000
heap
page read and write
2652C102000
heap
page read and write
222F5840000
heap
page read and write
222F5877000
heap
page read and write
20B93990000
heap
page read and write
9CDED7E000
stack
page read and write
222F5841000
heap
page read and write
1D37B7A000
stack
page read and write
D3E7C7C000
stack
page read and write
1C11E828000
heap
page read and write
1D37EFF000
stack
page read and write
222F587E000
heap
page read and write
2652C029000
heap
page read and write
20B93AE1000
heap
page read and write
B0E49FD000
stack
page read and write
222F583A000
heap
page read and write
20BEDE68000
heap
page read and write
20BEDF02000
heap
page read and write
1C11E702000
heap
page read and write
20B93A29000
heap
page read and write
D3E767B000
stack
page read and write
20B93A13000
heap
page read and write
2652BF80000
heap
page read and write
A52847E000
stack
page read and write
2652C026000
heap
page read and write
9CDDF8B000
stack
page read and write
D3E7A7E000
stack
page read and write
1C11E7C5000
heap
page read and write
20B939C0000
trusted library allocation
page read and write
222F5829000
heap
page read and write
276D67B000
stack
page read and write
1C11DE59000
heap
page read and write
222F5856000
heap
page read and write
222F586D000
heap
page read and write
1C11DE6E000
heap
page read and write
2652C8C0000
remote allocation
page read and write
20BEDD00000
heap
page read and write
222F5813000
heap
page read and write
2652CA02000
trusted library allocation
page read and write
2508B04E000
heap
page read and write
9CDE77F000
stack
page read and write
1C11E802000
heap
page read and write
2508B046000
heap
page read and write
222F587A000
heap
page read and write
20B93B02000
heap
page read and write
222F5847000
heap
page read and write
222F584E000
heap
page read and write
222F586B000
heap
page read and write
1C11DC60000
heap
page read and write
2652C8C0000
remote allocation
page read and write
2508B000000
heap
page read and write
1D37F7E000
stack
page read and write
2508B013000
heap
page read and write
222F57E0000
trusted library allocation
page read and write
20B93AE7000
heap
page read and write
1C11E7BF000
heap
page read and write
1C11DFE6000
heap
page read and write
A5288FD000
stack
page read and write
9CDEB7E000
stack
page read and write
1C11E76F000
heap
page read and write
1C11E602000
heap
page read and write
1D3733C000
stack
page read and write
222F5750000
heap
page read and write
20B93ACD000
heap
page read and write
1D37C7E000
stack
page read and write
20B93AC5000
heap
page read and write
1C11DF8F000
heap
page read and write
B0E48FE000
stack
page read and write
222F5858000
heap
page read and write
A5287FE000
stack
page read and write
1C11DFBA000
heap
page read and write
B0E4C7D000
stack
page read and write
2652C024000
heap
page read and write
222F5862000
heap
page read and write
222F585C000
heap
page read and write
1C11E754000
heap
page read and write
2508B002000
heap
page read and write
20B94512000
heap
page read and write
20BEDE5B000
heap
page read and write
1C11DE91000
heap
page read and write
222F585F000
heap
page read and write
222F587B000
heap
page read and write
1C11DCD0000
heap
page read and write
1C11E831000
heap
page read and write
1D378FF000
stack
page read and write
2652C057000
heap
page read and write
2508B03E000
heap
page read and write
222F5866000
heap
page read and write
9CDE67D000
stack
page read and write
20B93A00000
heap
page read and write
276D8FE000
stack
page read and write
A527D5B000
stack
page read and write
20BEDD90000
trusted library allocation
page read and write
1C11DE65000
heap
page read and write
9CDE97E000
stack
page read and write
2652C000000
heap
page read and write
222F585E000
heap
page read and write
222F5855000
heap
page read and write
1C11E800000
heap
page read and write
222F5859000
heap
page read and write
1C11DE3D000
heap
page read and write
20BEDE75000
heap
page read and write
There are 196 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
http://lcattertonpe.com/