IOC Report
https://form.jotform.co/91400704915855

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 59
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 60
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 61
Web Open Font Format (Version 2), TrueType, length 65976, version 2.8978
downloaded
Chrome Cache Entry: 62
ASCII text, with very long lines (2753)
downloaded
Chrome Cache Entry: 63
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 64
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=14, height=2981, bps=182, PhotometricIntepretation=RGB, manufacturer=NIKON CORPORATION, model=NIKON D3100, orientation=upper-left, width=4472], baseline, precision 8, 2048x1365, components 3
downloaded
Chrome Cache Entry: 65
HTML document, Unicode text, UTF-8 text, with very long lines (41331)
downloaded
Chrome Cache Entry: 66
JSON data
downloaded
Chrome Cache Entry: 67
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 68
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 827x749, components 3
dropped
Chrome Cache Entry: 69
Web Open Font Format (Version 2), TrueType, length 66592, version 2.8978
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (32766)
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (2199)
downloaded
Chrome Cache Entry: 72
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=14, height=2981, bps=182, PhotometricIntepretation=RGB, manufacturer=NIKON CORPORATION, model=NIKON D3100, orientation=upper-left, width=4472], baseline, precision 8, 2048x1365, components 3
dropped
Chrome Cache Entry: 73
Web Open Font Format (Version 2), TrueType, length 66388, version 2.8978
downloaded
Chrome Cache Entry: 74
Web Open Font Format (Version 2), TrueType, length 67028, version 2.8978
downloaded
Chrome Cache Entry: 75
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=14, height=2981, bps=182, PhotometricIntepretation=RGB, manufacturer=NIKON CORPORATION, model=NIKON D3100, orientation=upper-left, width=4472], progressive, precision 8, 4472x2981, components 3
downloaded
Chrome Cache Entry: 76
ASCII text, with very long lines (56138)
downloaded
Chrome Cache Entry: 77
ASCII text
downloaded
Chrome Cache Entry: 78
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 79
Unicode text, UTF-8 text, with very long lines (6048)
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 81
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 82
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 827x749, components 3
downloaded
Chrome Cache Entry: 83
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=14, height=2981, bps=182, PhotometricIntepretation=RGB, manufacturer=NIKON CORPORATION, model=NIKON D3100, orientation=upper-left, width=4472], progressive, precision 8, 4472x2981, components 3
dropped
There are 16 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2316 --field-trial-handle=2204,i,2313981544644397911,16468999574719493747,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://form.jotform.co/91400704915855"

URLs

Name
IP
Malicious
https://form.jotform.co/91400704915855
https://cdn.jotfor.ms/resources/assets/icon/jotform-icon-dark-400x400.png?v=1
unknown
https://www.jotform.com/oembed/?format=json&url=http://www.jotform.com/form/91400704915855
unknown
https://www.jotform.com/ownerView.php?id=91400704915855
104.19.129.105
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-BlackItalic.woff2)
unknown
https://screenshots.jotform.com/wishbox-server.php?callback=?
unknown
http://jquery.org/license
unknown
https://cdn.jotfor.ms
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Thin.woff)
unknown
https://www.jotform.com/uploads/hakardesign/form_files/Roundup.5ce5d6152c6430.17556224.jpg
104.19.129.105
http://tt.epicplay.com
unknown
https://www.jotform.com/uploads/hakardesign/form_files/pexels-photo-134878.5ce62ba0b5bfd0.35611671.j
unknown
http://sizzlejs.com/
unknown
https://www.jotform.com/oembed/?format=xml&url=http://www.jotform.com/form/'91400704915855
unknown
https://cdn.jotfor.ms/stylebuilder/91400704915855/style.css?themeID=5a55c5f1cf3bfe30640fbfe1&v=1441a7909c087dbbe7ce59881b9df8b9
172.67.7.107
http://jqueryui.com
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-MediumItalic.woff2)
unknown
https://hipaa-api.jotform.com
unknown
https://www.jotform.com/server.php
unknown
https://cdn01.jotfor.ms/static/prototype.forms.js?v=3.3.53134
104.22.73.81
https://cdn.jotfor.ms/assets/img/uncategorized/hipaa-badge-compliance.png
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-LightItalic.woff)
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-ThinItalic.woff)
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-LightItalic.woff2)
unknown
https://cdn.jotfor.ms/stylebuilder/91400704915855/style.css?themeID=5a55c5f1cf3bfe30640fbfe1&v=1
unknown
https://hipaa.jotform.com/
unknown
https://cdn02.jotfor.ms/static/jotform.forms.js?v=3.3.53134
172.67.7.107
https://cdn.jotfor.ms/assets/img/favicons/favicon-2021.svg
172.67.7.107
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Regular.woff)
unknown
http://loading.retry.widdit.com/
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Light.woff2)
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Italic.woff)
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Medium.woff)
unknown
https://www.jotform.com
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-ThinItalic.woff2)
unknown
https://form.jotform.co/91400704915855
http://jsfromhell.com/classes/math-processor
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Italic.woff2)
unknown
https://cdn.jotfor.ms/stylebuilder/static/cardforms-default.css?46d0360
172.67.7.107
https://www.jotform.com/?utm_source=powered_by_jotform&utm_medium=banner&utm_term=
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Regular.woff2)
unknown
https://github.com/getsentry/sentry-javascript
unknown
https://cdn01.jotfor.ms/s/umd/eb862aaabdf/for-formuser.js
104.22.73.81
https://www.jotform.com/encrypted-forms
unknown
https://www.jotform.com/uploads/hakardesign/form_files/pexels-photo-134878.5ce62ba0b5bfd0.35611671.jpeg
104.19.129.105
http://www.jotform.com/form/91400704915855
unknown
http://jedwatson.github.io/classnames
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Medium.woff2)
unknown
https://widgets.jotform.io/mobileResponsive/mobile.responsive.min.css
unknown
https://cdn.jotfor.ms/assets/img/uncategorized/encrypted-form-badge.png
unknown
https://form.jotform.com/91400704915855
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Bold.woff2)
unknown
https://browser.sentry-cdn.com/5.19.0/bundle.min.js
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-BoldItalic.woff2)
unknown
https://screenshots.jotform.com/wishbox-server.php
unknown
https://www.jotform.com/hipaa
unknown
http://api.jqueryui.com/category/ui-core/
unknown
https://api.jotform.com/formuser/91400704915855/combinedinfo?master=1
104.19.128.105
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Medium.woff2
172.67.7.107
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-MediumItalic.woff)
unknown
https://api.jotform.com
unknown
https://screenshots.jotform.com/queue/
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Regular.woff2
172.67.7.107
https://cdn01.jotfor.ms/s/umd/eb862aaabdf/for-cardform-js.js?4.5
104.22.73.81
https://events.jotform.com/form/91400704915855/?ref=&res=1280x1024&eventID=1713492267426_91400704915855_OgCiYPB&loc=https%253A%252F%252Fform.jotform.co%252F91400704915855
104.19.128.105
https://cdn.jotfor.ms/assets/img/uncategorized/access-image.png
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Light.woff2
172.67.7.107
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Bold.woff2
172.67.7.107
https://cdn.jotfor.ms/fonts/?family=Roboto&display=swap
172.67.7.107
https://screenshots.jotform.com/opt/templates/screen_editor.html?shot=
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Black.woff2)
unknown
https://eu-api.jotform.com
unknown
https://js.stripe.com/
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Light.woff)
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Thin.woff2)
unknown
https://www.jotform.com/accessible-forms/?utm_source=formfooter&utm_medium=banner&utm_term=
unknown
https://cdn01.jotfor.ms/js/vendor/math-processor.js?v=3.3.53134
104.22.73.81
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Black.woff)
unknown
https://events.jotform.com/
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-BoldItalic.woff)
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-Bold.woff)
unknown
https://cdn03.jotfor.ms/js/punycode-1.4.1.min.js?v=3.3.53134
104.22.72.81
https://browser.sentry-cdn.com/5.12.1/bundle.min.js
151.101.194.217
https://cdn.jotfor.ms/
unknown
https://cdn.jotfor.ms/fonts/Roboto/fonts/Roboto-BlackItalic.woff)
unknown
https://www.jotform.com/uploads/hakardesign/form_files/pexels-photo-134878.5ce62ba0b5bfd0.35611671.jpeg?width=2048
104.19.129.105
There are 75 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cdn01.jotfor.ms
104.22.73.81
browser.sentry-cdn.com
151.101.194.217
cdn.jotfor.ms
172.67.7.107
www.jotform.com
104.19.129.105
fp2e7a.wpc.phicdn.net
192.229.211.108
go.files.jotform.com
35.190.41.132
bg.microsoft.map.fastly.net
199.232.214.172
go.lb.jotform.com
35.201.118.58
edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.50.37
cdn03.jotfor.ms
104.22.72.81
www.google.com
142.250.9.103
api.jotform.com
104.19.128.105
cdn02.jotfor.ms
172.67.7.107
events.jotform.com
104.19.128.105
form.jotform.co
unknown
files.jotform.com
unknown
There are 6 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.19.129.105
www.jotform.com
United States
35.201.118.58
go.lb.jotform.com
United States
172.67.7.107
cdn.jotfor.ms
United States
192.168.2.6
unknown
unknown
104.19.128.105
api.jotform.com
United States
35.190.41.132
go.files.jotform.com
United States
239.255.255.250
unknown
Reserved
151.101.194.217
browser.sentry-cdn.com
United States
142.250.9.103
www.google.com
United States
104.22.73.81
cdn01.jotfor.ms
United States
104.22.72.81
cdn03.jotfor.ms
United States
There are 1 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://form.jotform.co/91400704915855
https://form.jotform.co/91400704915855
https://form.jotform.co/91400704915855
https://form.jotform.co/91400704915855