IOC Report
https://r20.rs6.net/tn.jsp?f=001mdupJ4qBb-Nd2_ylzx8HBttlQ9opTAsCLDNaIzR_kjOMUNmpNcZJwTrf1-JKcQms1CJ9Uho976bwGC08_tX5C5noMjVDoDyLOXoK3aopxxStOM8t6wvTBKWgVo18etJYQ_eeHjJ4R2lwkep1pKOUg8VLdGfphtuo&c=&ch=/Er8BdK9PMSuOgr2lskWkeZAKVKx339#?ZnJhbmtfZHJhcGVyQGFvLnVzY291cnRzLmdvdg==

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 101
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 102
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 59
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 60
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 61
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 62
ASCII text, with very long lines (42414)
downloaded
Chrome Cache Entry: 63
Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
downloaded
Chrome Cache Entry: 64
PNG image data, 26 x 45, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 65
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 66
PNG image data, 26 x 45, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 67
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 68
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 69
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 70
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 71
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 72
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 73
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 74
HTML document, ASCII text
downloaded
Chrome Cache Entry: 75
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 76
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 77
HTML document, ASCII text, with very long lines (1445), with CRLF line terminators
downloaded
Chrome Cache Entry: 78
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 79
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 80
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 81
ASCII text, with very long lines (631)
downloaded
Chrome Cache Entry: 82
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (1437), with CRLF line terminators
downloaded
Chrome Cache Entry: 84
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 86
Web Open Font Format, TrueType, length 35970, version 1.0
downloaded
Chrome Cache Entry: 87
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 88
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 89
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 90
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 91
ASCII text, with very long lines (23398), with no line terminators
downloaded
Chrome Cache Entry: 92
HTML document, ASCII text, with very long lines (59301), with CRLF line terminators
downloaded
Chrome Cache Entry: 93
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 94
Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
downloaded
Chrome Cache Entry: 95
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 96
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 97
ASCII text, with very long lines (45667)
downloaded
Chrome Cache Entry: 98
Web Open Font Format, TrueType, length 36696, version 1.0
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (1222), with no line terminators
downloaded
There are 35 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2488 --field-trial-handle=2464,i,8825247410331717604,3017276949073741127,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://r20.rs6.net/tn.jsp?f=001mdupJ4qBb-Nd2_ylzx8HBttlQ9opTAsCLDNaIzR_kjOMUNmpNcZJwTrf1-JKcQms1CJ9Uho976bwGC08_tX5C5noMjVDoDyLOXoK3aopxxStOM8t6wvTBKWgVo18etJYQ_eeHjJ4R2lwkep1pKOUg8VLdGfphtuo&c=&ch=/Er8BdK9PMSuOgr2lskWkeZAKVKx339#?ZnJhbmtfZHJhcGVyQGFvLnVzY291cnRzLmdvdg=="

URLs

Name
IP
Malicious
https://r20.rs6.net/tn.jsp?f=001mdupJ4qBb-Nd2_ylzx8HBttlQ9opTAsCLDNaIzR_kjOMUNmpNcZJwTrf1-JKcQms1CJ9Uho976bwGC08_tX5C5noMjVDoDyLOXoK3aopxxStOM8t6wvTBKWgVo18etJYQ_eeHjJ4R2lwkep1pKOUg8VLdGfphtuo&c=&ch=/Er8BdK9PMSuOgr2lskWkeZAKVKx339#?ZnJhbmtfZHJhcGVyQGFvLnVzY291cnRzLmdvdg==
malicious
https://iwc.ylanove.com/aKmKmNZtsTqvFkYafLZLLVswZYBVZSNSIATGQSWRCHBRZHPPAOJCZNEDRNIVGOJIWBTZEIDYROFUDJYRM?259761317902526776iylYsUHNRKWMZPCZIJMJVTVBVVBHFIPFVPJFVVAAJVNGGNGROIGOMMTNZLINEIP#
malicious
https://iwc.ylanove.com/aKmKmNZtsTqvFkYafLZLLVswZYBVZSNSIATGQSWRCHBRZHPPAOJCZNEDRNIVGOJIWBTZEIDYROFUDJYRM?259761317902526776iylYsUHNRKWMZPCZIJMJVTVBVVBHFIPFVPJFVVAAJVNGGNGROIGOMMTNZLINEIP
malicious
https://iwc.ylanove.com/NqZs/?aHfrank_draper@ao.uscourts.gov
104.21.7.226
https://code.jquery.com/jquery-3.6.0.min.js
151.101.130.137
https://iwc.ylanove.com/uv5UZ1KIVEUCh5yHNIHetL4ApA2noplU2fqwsQqYer934130
104.21.7.226
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://iwc.ylanove.com/yz7Mu1eFyB88op8565Kmop50
104.21.7.226
https://iwc.ylanove.com/wxeHjHqYecUpzThhXMaI1JDjHopY6j6TxKp1AhiffEAfFxS41zvgsW90180
104.21.7.226
https://baires2.com/public/folder/
167.250.5.48
https://support.google.com/recaptcha#6262736
unknown
https://iwc.ylanove.com/NqZs/
104.21.7.226
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=879ef3cf7a13136b
104.17.2.184
https://iwc.ylanove.com/rskswwaJvriBijPq3483bvnLwx34
104.21.7.226
https://iwc.ylanove.com/klp2moZcClbzc9b1hr8rgadqwJHQ0gpSvDqrFHZ4tCyKbi3qBOoz4LbtowE1RS5W8lHyz228
104.21.7.226
https://iwc.ylanove.com/23d5Uttl3mSaxKzHSo90MsdLTxy70
104.21.7.226
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://cloud.google.com/contact
unknown
https://iwc.ylanove.com/apjtmlhASdjx1zdhT8Is5t
104.21.7.226
https://r20.rs6.net/tn.jsp?f=001mdupJ4qBb-Nd2_ylzx8HBttlQ9opTAsCLDNaIzR_kjOMUNmpNcZJwTrf1-JKcQms1CJ9Uho976bwGC08_tX5C5noMjVDoDyLOXoK3aopxxStOM8t6wvTBKWgVo18etJYQ_eeHjJ4R2lwkep1pKOUg8VLdGfphtuo&c=&ch=/Er8BdK9PMSuOgr2lskWkeZAKVKx339
208.75.122.11
https://www.google.com/recaptcha/api.js
142.250.9.106
https://support.google.com/recaptcha/#6175971
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.2.184
https://iwc.ylanove.com/favicon.ico
104.21.7.226
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/879ef3cf7a13136b/1714054603760/129c8b6e5637fae9e552b8c06cfe2d9f72d3ad7f67b0fd06221f1725feab0540/xh6x6ogrpc1VhY0
104.17.2.184
https://iwc.ylanove.com/cdCDR8sekdekx562rY0fDL5hwkl93
104.21.7.226
https://www.gstatic.c..?/recaptcha/releases/V6_85qpc2Xf2sbe3xTnRte7m/recaptcha__.
unknown
https://iwc.ylanove.com/ijWdqnzbAJvwpS7A2WEQ7hn5cmnxE2V7THZqRYP4RObQe1pn12210
104.21.7.226
https://iwc.ylanove.com/mntk2WlxToS2W9Yt18UFSPRmNqx9FHNsxjkl0pcAHUrqTJwrSa6AkFrD5P78150
104.21.7.226
https://iwc.ylanove.com/ujYP0MVlSXJUCeR0qLFxB8lMVbBhyE1t3tj3pY0MHOWrjTDvPPE9tYy05
104.21.7.226
https://www.google.com/recaptcha/api2/
unknown
https://iwc.ylanove.com/78mMVBx0f2230HrZst60
104.21.7.226
https://support.google.com/recaptcha
unknown
https://iwc.ylanove.com/kl8UAmLHVhePLB4HuJeyyzx1hX5W1Xef0Q4W778169
104.21.7.226
https://iwc.ylanove.com/web8socket/socket.io/?type=User&appnum=1&EIO=4&transport=websocket
104.21.7.226
https://iwc.ylanove.com/opyiMPYKZKzNB28TPtQcCy09fuvTC62cdjuYaVHVaZilQSIfVkRscd200
104.21.7.226
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2unp2/0x4AAAAAAAWqZm37nVeQCu8P/auto/normal
https://iwc.ylanove.com/stugJJYFR8hTbkwtP6SbngLYGGrJTJ769dnaW679cpWS7fXCNNAsZV0khwEm0c8WTurFiDFmiggh258
104.21.7.226
https://iwc.ylanove.com/abKm4zSRhrsQXazgh26
104.21.7.226
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://recaptcha.net
unknown
https://iwc.ylanove.com/90uD4AhHC1FtvlY4w3ZK6zcdclI5nXtrVryz73
104.21.7.226
https://www.apache.org/licenses/
unknown
https://a.nel.cloudflare.com/report/v4?s=AT8ysDJLeuBmWUvB8sjPZKiwVTyqFYhcZK1ogdpHevnSLABJ5cUl7OsPQXqVi6LVQUFY9jW0NYogdsH0r4lyUjPcrZYQUhoTTD1ty7%2BVg1cxDVMXRGb%2Fy270EzahnA%3D%3D
35.190.80.1
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://iwc.ylanove.com/34fRE0Se58eWLCBC3ejWCEkYYDij6eHdpq3OuePIlz89110
104.21.7.226
https://iwc.ylanove.com/kl87nJ99LatzvO95WxCOR2mrFKiiaR4YmHLNTkl3vVhtfijeEPSfyT2eeBzLc7Vgztcemrkrw7sieIdSuv220
104.21.7.226
https://cdn.socket.io/4.6.0/socket.io.min.js
108.156.152.114
https://iwC.ylanove.com/NqZs/#H
unknown
https://iwc.ylanove.com/qr8v1vd1Y28jFT3wIXwXqY6Xv8F6yONfP06nz4L12r40ZJOYoyftOtCQnkiox2pcd240
104.21.7.226
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/879ef3cf7a13136b/1714054603763/Z3chV7lU4C30LnK
104.17.2.184
https://iwc.ylanove.com/qr9kueTswpS1TaKvcMP1ER62reuDiQ4jchefn0ulWVNoazKnFrg45138
104.21.7.226
https://iwc.ylanove.com/56R1BLa3GPZvmDxyEN08920
104.21.7.226
https://iwc.ylanove.com/NqZs/#Hfrank_draper@ao.uscourts.gov
https://baires2.com/public/folder
167.250.5.48
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/19004042:1714051579:SBPw9V4HU5m_KVTEHd7dILHsrP8X1Ng2eaJjx5cdx4o/879ef3cf7a13136b/ef2820e19d5a2af
104.17.2.184
There are 47 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
a.nel.cloudflare.com
35.190.80.1
code.jquery.com
151.101.130.137
d2vgu95hoyrpkh.cloudfront.net
108.156.152.114
rs6.net
208.75.122.11
challenges.cloudflare.com
104.17.3.184
www.google.com
142.250.105.104
baires2.com
167.250.5.48
fp2e7a.wpc.phicdn.net
192.229.211.108
iwc.ylanove.com
104.21.7.226
r20.rs6.net
unknown
cdn.socket.io
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
108.156.152.114
d2vgu95hoyrpkh.cloudfront.net
United States
142.250.9.106
unknown
United States
104.21.7.226
iwc.ylanove.com
United States
192.168.2.4
unknown
unknown
172.67.156.129
unknown
United States
142.250.105.104
www.google.com
United States
151.101.130.137
code.jquery.com
United States
104.17.3.184
challenges.cloudflare.com
United States
239.255.255.250
unknown
Reserved
167.250.5.48
baires2.com
Argentina
35.190.80.1
a.nel.cloudflare.com
United States
208.75.122.11
rs6.net
United States
104.17.2.184
unknown
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://iwc.ylanove.com/aKmKmNZtsTqvFkYafLZLLVswZYBVZSNSIATGQSWRCHBRZHPPAOJCZNEDRNIVGOJIWBTZEIDYROFUDJYRM?259761317902526776iylYsUHNRKWMZPCZIJMJVTVBVVBHFIPFVPJFVVAAJVNGGNGROIGOMMTNZLINEIP
malicious
https://iwc.ylanove.com/aKmKmNZtsTqvFkYafLZLLVswZYBVZSNSIATGQSWRCHBRZHPPAOJCZNEDRNIVGOJIWBTZEIDYROFUDJYRM?259761317902526776iylYsUHNRKWMZPCZIJMJVTVBVVBHFIPFVPJFVVAAJVNGGNGROIGOMMTNZLINEIP#
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2unp2/0x4AAAAAAAWqZm37nVeQCu8P/auto/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/2unp2/0x4AAAAAAAWqZm37nVeQCu8P/auto/normal
https://iwc.ylanove.com/NqZs/#Hfrank_draper@ao.uscourts.gov