IOC Report
http://curbengh.github.io

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 112
HTML document, ASCII text, with very long lines (12171), with no line terminators
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (1231)
downloaded
Chrome Cache Entry: 114
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 115
ASCII text, with very long lines (26152)
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (960)
downloaded
Chrome Cache Entry: 117
JSON data
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (19742)
downloaded
Chrome Cache Entry: 119
JSON data
downloaded
Chrome Cache Entry: 120
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 121
Unicode text, UTF-8 text, with very long lines (19920)
downloaded
Chrome Cache Entry: 122
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 123
HTML document, Unicode text, UTF-8 text, with very long lines (13030)
downloaded
Chrome Cache Entry: 124
Unicode text, UTF-8 text, with very long lines (16255)
downloaded
Chrome Cache Entry: 125
HTML document, Unicode text, UTF-8 text, with very long lines (6314)
downloaded
Chrome Cache Entry: 126
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 127
HTML document, Unicode text, UTF-8 text, with very long lines (14529)
downloaded
Chrome Cache Entry: 128
HTML document, Unicode text, UTF-8 text, with very long lines (6291)
downloaded
Chrome Cache Entry: 129
Unicode text, UTF-8 text, with very long lines (28549)
downloaded
Chrome Cache Entry: 130
HTML document, Unicode text, UTF-8 text, with very long lines (6327)
downloaded
Chrome Cache Entry: 131
JSON data
dropped
Chrome Cache Entry: 132
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 133
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 134
JSON data
downloaded
Chrome Cache Entry: 135
Unicode text, UTF-8 text, with very long lines (19033)
downloaded
Chrome Cache Entry: 136
JSON data
downloaded
Chrome Cache Entry: 137
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 138
ASCII text, with very long lines (26198)
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (18428)
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (38350)
downloaded
Chrome Cache Entry: 141
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 142
JSON data
downloaded
Chrome Cache Entry: 143
JSON data
downloaded
Chrome Cache Entry: 144
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 146
Web Open Font Format (Version 2), TrueType, length 324504, version 4.0
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (28942)
downloaded
Chrome Cache Entry: 148
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (29080)
downloaded
Chrome Cache Entry: 150
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 151
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 152
JSON data
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (5055)
downloaded
Chrome Cache Entry: 154
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 155
Web Open Font Format (Version 2), TrueType, length 86832, version 2.19923
downloaded
Chrome Cache Entry: 156
JSON data
dropped
Chrome Cache Entry: 157
HTML document, Unicode text, UTF-8 text, with very long lines (10197)
downloaded
Chrome Cache Entry: 158
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 159
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 160
HTML document, ASCII text, with very long lines (6691), with no line terminators
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (1632), with no line terminators
downloaded
Chrome Cache Entry: 162
XML 1.0 document, Unicode text, UTF-8 text, with very long lines (16531)
downloaded
Chrome Cache Entry: 163
JSON data
dropped
Chrome Cache Entry: 164
HTML document, ASCII text, with very long lines (11651), with no line terminators
downloaded
Chrome Cache Entry: 165
Unicode text, UTF-8 text, with very long lines (10360)
downloaded
Chrome Cache Entry: 166
HTML document, ASCII text, with very long lines (6078), with no line terminators
downloaded
Chrome Cache Entry: 167
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (20298)
downloaded
Chrome Cache Entry: 169
JSON data
dropped
Chrome Cache Entry: 170
Unicode text, UTF-8 text, with very long lines (40477)
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (41028)
downloaded
Chrome Cache Entry: 172
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 173
HTML document, ASCII text, with very long lines (5345), with no line terminators
downloaded
Chrome Cache Entry: 174
HTML document, Unicode text, UTF-8 text, with very long lines (10781)
downloaded
Chrome Cache Entry: 175
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 176
ASCII text, with very long lines (14649)
downloaded
Chrome Cache Entry: 177
HTML document, ASCII text, with very long lines (5295), with no line terminators
downloaded
Chrome Cache Entry: 178
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 179
ASCII text, with very long lines (17853)
downloaded
Chrome Cache Entry: 180
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 181
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 182
HTML document, Unicode text, UTF-8 text, with very long lines (24483), with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (13270)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (28438)
downloaded
Chrome Cache Entry: 185
HTML document, Unicode text, UTF-8 text, with very long lines (13777)
downloaded
Chrome Cache Entry: 186
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 187
Web Open Font Format (Version 2), TrueType, length 78644, version 2.19923
downloaded
Chrome Cache Entry: 188
JSON data
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (11350)
downloaded
Chrome Cache Entry: 190
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 191
JSON data
dropped
Chrome Cache Entry: 192
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (514)
downloaded
Chrome Cache Entry: 194
HTML document, Unicode text, UTF-8 text, with very long lines (7659)
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (44813)
downloaded
Chrome Cache Entry: 196
HTML document, Unicode text, UTF-8 text, with very long lines (4991)
downloaded
Chrome Cache Entry: 197
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 198
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 199
JSON data
dropped
Chrome Cache Entry: 200
Web Open Font Format (Version 2), TrueType, length 360780, version 4.0
downloaded
Chrome Cache Entry: 201
JSON data
downloaded
Chrome Cache Entry: 202
Unicode text, UTF-8 text, with very long lines (65104)
downloaded
Chrome Cache Entry: 203
Unicode text, UTF-8 text, with very long lines (65344), with no line terminators
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (62335)
downloaded
Chrome Cache Entry: 205
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 206
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (14070)
downloaded
Chrome Cache Entry: 208
ASCII text
downloaded
Chrome Cache Entry: 209
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 210
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 211
Unicode text, UTF-8 text, with very long lines (12325), with no line terminators
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (3556)
downloaded
Chrome Cache Entry: 213
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 214
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (397), with no line terminators
downloaded
Chrome Cache Entry: 216
HTML document, Unicode text, UTF-8 text, with very long lines (6693)
downloaded
Chrome Cache Entry: 217
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 218
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 219
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 220
Unicode text, UTF-8 text, with very long lines (65513), with no line terminators
downloaded
Chrome Cache Entry: 221
HTML document, Unicode text, UTF-8 text, with very long lines (16126)
downloaded
Chrome Cache Entry: 222
PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 223
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 224
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 225
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 226
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 227
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 228
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 229
ASCII text, with very long lines (2523)
downloaded
Chrome Cache Entry: 230
ASCII text, with very long lines (12005)
downloaded
Chrome Cache Entry: 231
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 232
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 233
ASCII text, with very long lines (14551)
downloaded
Chrome Cache Entry: 234
HTML document, ASCII text, with very long lines (8679), with no line terminators
downloaded
There are 114 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1756,i,13357440529980894533,13399501441401331727,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://curbengh.github.io"

URLs

Name
IP
Malicious
http://curbengh.github.io
https://xw226dvxac7jzcpsf4xb64r4epr6o5hgn46dxlqk7gnjptakik6xnzqd.onion{uri}
unknown
malicious
https://duckduckgogg42xjoc72x3sjasowoarfbgcmvfimaftt6twagswzczad.onion/
unknown
malicious
https://kushaldas.in/posts/get-a-tls-certificate-for-your-onion-service.html
unknown
malicious
https://gitlab.com/curben/blog/-/blob/master/source/_posts/grub-luks2-argon2.md
unknown
https://developers.cloudflare.com/cloudflare-one/tutorials/ssh-cert-bastion/
unknown
https://collector.prd-278964.gl-product-analytics.com
unknown
https://mdleom.com/tags/nginx/
unknown
https://nixos.org/guides/nix-pills/callpackage-design-pattern.html
unknown
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Defaultmetaconf
unknown
https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/Useasubsearch
unknown
http://192.168.1.2:8080/api/path"
unknown
https://gitlab.com/assets/webpack/commons-pages.projects.blob.show-pages.projects.show-pages.projects.tree.show.67c0a05c.chunk.js
172.65.251.78
https://smallstep.com/blog/use-ssh-certificates/
unknown
https://gitlab.com/curben/blog/-/commit/a81e34a62e03ee2563ba8241f23f47493c0af1e4
unknown
https://gitlab.com/malware-filter/splunk-malware-filter
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://customers.gitlab.com/billing_accounts
unknown
https://gitlab.com/curben/splunk-scripts
unknown
https://stats.uptimerobot.com/1394zup2LQ
unknown
https://user-content.gitlab-static.net/907d6ee1a1a879097bc7de0f23a205830cc2f23d/68747470733a2f2f6170
unknown
https://mdleom.com/tags/gitlab/
unknown
https://about.gitlab.com/why-gitlab
unknown
https://gitlab.com/curben/splunk-scripts/-/tree/main/SA-ldapsearch?ref_type=heads
unknown
https://gitlab.com/assets/webpack/38.21890e17.chunk.js
172.65.251.78
https://gitlab.com/malware-filter/malware-filter
unknown
https://gitlab.com/assets/webpack/global_search_modal.adefb40e.chunk.js
172.65.251.78
https://teddit.net/r/linux/comments/osah05/ysk_do_not_use_sudo_vimnanoemacs_to_edit_a_file/
unknown
https://curbengh.github.io/blog/2024/02/24/splunk-app-acl/
https://leo3418.github.io/collections/gentoo-config-luks2-grub-systemd/auto-unlock.html
unknown
https://mdleom.com/atom.xml
unknown
https://user-content.gitlab-static.net/7dc22bdd9872d7a3b62e95f959117004d58058df/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6865786f2d6865786f6a732f6865786f2d627269676874677265656e2e737667
104.18.35.147
https://gitlab.com/assets/fonts-fae5d3f79948bd85f18b6513a025f863b19636e85b09a1492907eb4b1bb0557b.css
172.65.251.78
https://gitlab.com/assets/webpack/sentry.24e97836.chunk.js
172.65.251.78
https://mdleom.com/screenshot/blog/2024/02/24/splunk-app-acl/
unknown
https://curbengh.github.io/tags/android/
https://docs.splunk.com/Splexicon:Event
unknown
https://curbengh.github.io/blog/2022/08/09/remove-gitlab-artifacts/
https://github.com/curbengh/hexo-nofollow
unknown
https://github.com/caddyserver/ntlm-transport
unknown
https://mdleom.com/tags/caddy/
unknown
https://docs.aws.amazon.com/config/latest/developerguide/aggregate-data.html
unknown
https://github.com/caddyserver/caddy/releases/latest
unknown
https://splunkbase.splunk.com/app/1151
unknown
https://sizzlejs.com/
unknown
https://gitlab.com/malware-filter/urlhaus-filter
unknown
https://gitlab.com/curben/blog.git
unknown
https://www.masteringemacs.org/article/keyboard-shortcuts-every-command-line-hacker-should-know-abou
unknown
https://mdleom.com/tags/tor/
unknown
https://curbengh.github.io/svg/share.svg
185.199.111.153
https://mdleom.com/tags/zsh/
unknown
https://mdleom.com/tags/servicenow/
unknown
https://gitlab.com/malware-filter/vn-badsite-filter
unknown
https://gitlab.com/assets/webpack/pages.projects.show.a16e4485.chunk.js
172.65.251.78
https://gitlab.com/malware-filter/botnet-filter
unknown
https://curbengh.github.io/img/about/website-architecture.png?f=auto
185.199.111.153
https://blog.cloudflare.com/argo-tunnels-that-live-forever/
unknown
https://mdleom.com/blog/2021/09/17/aws-config/
unknown
https://developers.cloudflare.com/cloudflare-one/identity/users/short-lived-certificates/
unknown
https://docs.servicenow.com/en-US/bundle/vancouver-platform-security/page/integrate/single-sign-on/t
unknown
https://gitlab.com/curben/blog/-/refs/master/logs_tree/?format=json&offset=0&ref_type=heads
172.65.251.78
https://aur.archlinux.org/packages/grub-improved-luks2-git
unknown
https://www.recaptcha.net/recaptcha/api.js
unknown
https://github.com/caddyserver/caddy/blob/master/cmd/main.go
unknown
https://mdleom.com/tags/cloudflare/
unknown
https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Managesourcetypes
unknown
http://192.168.1.2:8080/api/path
unknown
https://mdleom.com/blog/2021/07/04/ecdsa-tls-tor-caddy/
unknown
https://www.huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java
unknown
https://docs.aws.amazon.com/cloudcontrolapi/latest/APIReference/API_ListResources.html
unknown
https://curbengh.github.io/js/chameleon.js
185.199.111.153
https://getbootstrap.com/)
unknown
https://gitlab.com/assets/twitter_card-570ddb06edf56a2312253c5872489847a0f385112ddbcd71ccfa1570febab
unknown
https://gitlab.com/curben/aws-scripts/-/blob/main/aws-config.py
unknown
https://nixos.org/
unknown
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Inputlookup
unknown
https://gitlab.com/curben/blog/tree/master/themes/chameleon
unknown
https://gitlab.com/assets/webpack/initInviteMembersTrigger.9a40ea1b.chunk.js
172.65.251.78
https://gitlab.com/curben/splunk-scripts/-/tree/main/TA-librenms-data-poller?ref_type=heads
unknown
https://mdleom.com/blog/2021/12/17/log4shell-log4j-unbound-dns/
unknown
https://hicss.hawaii.edu/
unknown
https://gitlab.com/assets/page_bundles/projects-97864a07bdb44dc7694b22d96267284ba18244aa259b388fb339eebb2e4d7d07.css
172.65.251.78
https://docs.aws.amazon.com/config/latest/developerguide/querying-AWS-resources.html
unknown
https://gitlab.com/assets/page_bundles/project-9264738885a02be386176dc85c96b550fae5ce8d174fba9508a843966d6c4213.css
172.65.251.78
https://docs.aws.amazon.com/cloudcontrolapi/latest/userguide/supported-resources.html
unknown
https://gitlab.com/assets/favicon-72a2cad5025aa931d6ea56c3201d1f18e68a8cd39788c7c80d5b2b82aa5143ef.png
172.65.251.78
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Wheretofindtheconfigurationfiles
unknown
https://docs.python.org/3/tutorial/datastructures.html#sets
unknown
https://dbushell.com/
unknown
https://www.aplura.com/assets/pdf/props_conf_order.pdf
unknown
https://gitlab.com/assets/webpack/analytics.01b6170a.chunk.js
172.65.251.78
https://curbengh.github.io/svg/favicon.svg
185.199.111.153
https://repo.harica.gr/rep_dyn.php
unknown
https://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileswithstructureddata#Fi
unknown
https://aws.amazon.com/systems-manager/
unknown
https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Aboutlookupsandfieldactions
unknown
https://curbengh.github.io/tags/aws-config/
https://github.com/mitchellkrogza/Phishing.Database
unknown
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Table
unknown
https://mdleom.com/tags/linux/
unknown
https://customers.gitlab.com/customers/sign_in?legacy=true
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
curbengh.github.io
185.199.111.153
bg.microsoft.map.fastly.net
199.232.210.172
a.nel.cloudflare.com
35.190.80.1
new-sentry.gitlab.net
172.64.147.68
gitlab.com
172.65.251.78
www.google.com
172.253.124.105
collector.prd-278964.gl-product-analytics.com
34.120.22.49
user-content.gitlab-static.net
104.18.35.147
snowplowalb-1011729428.us-east-1.elb.amazonaws.com
52.205.37.183
fp2e7a.wpc.phicdn.net
192.229.211.108
snowplow.trx.gitlab.net
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
34.120.22.49
collector.prd-278964.gl-product-analytics.com
United States
185.199.111.153
curbengh.github.io
Netherlands
192.168.2.4
unknown
unknown
172.253.124.105
www.google.com
United States
172.64.147.68
new-sentry.gitlab.net
United States
172.65.251.78
gitlab.com
United States
52.205.37.183
snowplowalb-1011729428.us-east-1.elb.amazonaws.com
United States
239.255.255.250
unknown
Reserved
104.18.40.188
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
172.64.152.109
unknown
United States
104.18.35.147
user-content.gitlab-static.net
United States
There are 2 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://curbengh.github.io/
https://curbengh.github.io/blog/
https://curbengh.github.io/about/
https://gitlab.com/curben/blog
https://gitlab.com/curben/blog
https://curbengh.github.io/blog/2024/02/24/splunk-app-acl/
https://curbengh.github.io/blog/2023/10/01/splunk-ldapsearch-useraccountcontrol/
https://curbengh.github.io/blog/2023/08/27/saml-scim/
https://curbengh.github.io/blog/2023/07/17/ctrl-h-backspace/
https://curbengh.github.io/blog/2023/06/17/json-splunk-uf/
https://curbengh.github.io/blog/2023/04/16/splunk-lookup-malware-filter/
https://curbengh.github.io/blog/2023/02/13/ssh-certificate-cloudflare-tunnel/
https://curbengh.github.io/blog/2022/11/27/grub-luks2-argon2/
https://curbengh.github.io/blog/2022/08/09/remove-gitlab-artifacts/
https://curbengh.github.io/blog/2021/12/27/caddy-plugins-nixos/
https://curbengh.github.io/tags/alpine/
https://curbengh.github.io/tags/android/
https://curbengh.github.io/tags/arch/
https://curbengh.github.io/tags/aws/
https://curbengh.github.io/blog/2021/06/27/aws-waf/
https://curbengh.github.io/tags/aws-config/
There are 11 hidden doms, click here to show them.