IOC Report
https://t.email.currys.co.uk/r/?id=h7aa4a341,8b3374d,743904&p1=concretocasa.com.br%2Fhtml%2Fssl%2Ffyvqcw/anBlcmtpbnNAaGFycmlzd2lsbGlhbXMuY29t

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 144
ASCII text, with very long lines (31803)
downloaded
Chrome Cache Entry: 145
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (19175)
downloaded
Chrome Cache Entry: 147
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 148
PNG image data, 92 x 11, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (6149), with no line terminators
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 155
PNG image data, 280 x 60, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 158
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 163
HTML document, ASCII text, with very long lines (10899)
downloaded
Chrome Cache Entry: 165
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 166
PNG image data, 1920 x 1080, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 167
SVG Scalable Vector Graphics image
dropped
There are 8 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://t.email.currys.co.uk/r/?id=h7aa4a341,8b3374d,743904&p1=concretocasa.com.br%2Fhtml%2Fssl%2Ffyvqcw/anBlcmtpbnNAaGFycmlzd2lsbGlhbXMuY29t
malicious
https://mego6knkfy6446e58a59d14.ptalen.ru/e3b52af7f42b89943d3cf517518321e0647f4edf9d1ccPASe3b52af7f42b89943d3cf517518321e0647f4edf9d1ce
malicious
https://mego6knkfy6446e58a59d14.ptalen.ru/Mjperkins@harriswilliams.com
malicious
https://concretocasa.com.br/html/ssl/fyvqcw/anBlcmtpbnNAaGFycmlzd2lsbGlhbXMuY29t
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/dp0qq/0x4AAAAAAADnPIDROrmt1Wwj/light/normal

Domains

Name
IP
Malicious
mego6knkfy6446e58a59d14.ptalen.ru
172.67.173.146
a.nel.cloudflare.com
35.190.80.1
accounts.google.com
142.250.186.77
challenges.cloudflare.com
104.18.7.185
concretocasa.com.br
185.201.10.27
www.google.com
142.250.185.164
clients.l.google.com
142.250.185.174
dixonsretail-mkt-prod1-ssl1-2796-396715988.eu-west-1.elb.amazonaws.com
52.31.211.174
unpkg.com
104.16.126.175
cs1025.wpc.upsiloncdn.net
152.199.23.72
aadcdn.msauthimages.net
unknown
clients2.google.com
unknown
t.email.currys.co.uk
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.35
unknown
United States
192.168.2.2
unknown
unknown
104.18.7.185
challenges.cloudflare.com
United States
1.1.1.1
unknown
Australia
34.104.35.123
unknown
United States
192.168.2.1
unknown
unknown
152.199.23.72
cs1025.wpc.upsiloncdn.net
United States
172.217.18.4
unknown
United States
52.31.211.174
dixonsretail-mkt-prod1-ssl1-2796-396715988.eu-west-1.elb.amazonaws.com
United States
142.250.181.234
unknown
United States
185.201.10.27
concretocasa.com.br
Germany
239.255.255.250
unknown
Reserved
142.250.185.174
clients.l.google.com
United States
142.250.185.164
www.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.184.227
unknown
United States
172.67.173.146
mego6knkfy6446e58a59d14.ptalen.ru
United States
142.250.186.77
accounts.google.com
United States
104.16.126.175
unpkg.com
United States
There are 9 hidden IPs, click here to show them.