IOC Report
https://web.lehighvalleychamber.org/cwt/external/wcpages/referral.aspx?ReferralType=W&ProfileID=5337&ListingID=4065&CategoryID=74&SubCategoryID=0&url=//sanemedia.ca/owaow/yjyo8q/bWFyaWEud29qY2llY2hvd3NraUBjby5tb25tb3V0aC5uai51cw==

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 101
Web Open Font Format, TrueType, length 36696, version 1.0
downloaded
Chrome Cache Entry: 102
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (42414)
downloaded
Chrome Cache Entry: 104
HTML document, ASCII text
downloaded
Chrome Cache Entry: 105
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 106
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 107
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 108
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 109
HTML document, ASCII text, with very long lines (59469), with CRLF line terminators
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (631)
downloaded
Chrome Cache Entry: 67
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 68
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 69
ASCII text, with very long lines (45667)
downloaded
Chrome Cache Entry: 70
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 71
PNG image data, 4096 x 4096, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 72
ASCII text, with very long lines (1437), with CRLF line terminators
downloaded
Chrome Cache Entry: 73
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 74
PNG image data, 1 x 40, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 75
PNG image data, 1115 x 700, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 76
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 77
ASCII text, with very long lines (23398), with no line terminators
downloaded
Chrome Cache Entry: 78
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 79
ASCII text, with very long lines (1222), with no line terminators
downloaded
Chrome Cache Entry: 80
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 81
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 82
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 83
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 84
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 85
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 86
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 87
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 88
Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
downloaded
Chrome Cache Entry: 89
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 90
PNG image data, 1 x 40, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 91
Web Open Font Format, TrueType, length 35970, version 1.0
downloaded
Chrome Cache Entry: 92
HTML document, ASCII text, with very long lines (1445), with CRLF line terminators
downloaded
Chrome Cache Entry: 93
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 94
PNG image data, 1115 x 700, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 95
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 96
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 97
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 98
PNG image data, 4096 x 4096, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 99
Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
downloaded
There are 35 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2280 --field-trial-handle=2208,i,4448026011857965918,2290539440561733020,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://web.lehighvalleychamber.org/cwt/external/wcpages/referral.aspx?ReferralType=W&ProfileID=5337&ListingID=4065&CategoryID=74&SubCategoryID=0&url=//sanemedia.ca/owaow/yjyo8q/bWFyaWEud29qY2llY2hvd3NraUBjby5tb25tb3V0aC5uai51cw=="

URLs

Name
IP
Malicious
https://web.lehighvalleychamber.org/cwt/external/wcpages/referral.aspx?ReferralType=W&ProfileID=5337&ListingID=4065&CategoryID=74&SubCategoryID=0&url=//sanemedia.ca/owaow/yjyo8q/bWFyaWEud29qY2llY2hvd3NraUBjby5tb25tb3V0aC5uai51cw==
malicious
https://efe.q39r.com/efe/#Xmaria.wojciechowski@co.monmouth.nj.us
malicious
https://efe.q39r.com/efe/?fXmaria.wojciechowski@co.monmouth.nj.us
172.67.218.12
https://efe.q39r.com/web8socket/socket.io/?type=User&appnum=1&EIO=4&transport=websocket
172.67.218.12
https://efe.q39r.com/opowUdIRVvkQBTpz9zU3kvicjS7Vd758jghSE2WOx04K5tpqvy3hO3cd194
172.67.218.12
https://efe.q39r.com/opqrVzJ7QK65jRHLycjIYeEmn3nYSEsxUcPMwlK45140
172.67.218.12
https://efe.q39r.com/klInHvOHos9aWrFFUZMeefGPqwxhIrivj5FxETTv56170
172.67.218.12
https://code.jquery.com/jquery-3.6.0.min.js
151.101.66.137
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://efe.q39r.com/efIkwX88PctuuCqm8UQNdlk78EKul19lCmn100
172.67.218.12
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/876680488:1714051748:QmiDdes-9Nz6iXnBJZCLK0I7EQT-6gDXt8XExuUwPvw/879f1dd91a63b08b/2bc5d6b33762ac4
104.17.2.184
https://support.google.com/recaptcha#6262736
unknown
https://efe.q39r.com/yzsbPpRgtDS56O6DQfqr50
172.67.218.12
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/879f1dd91a63b08b/1714056325985/utgLeOjvjpAz4Rs
104.17.2.184
https://efe.q39r.com/favicon.ico
172.67.218.12
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://cloud.google.com/contact
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/879f1dd91a63b08b/1714056325990/1f93f76bb1b23b48ccddb7874975acb1314a2bc3e9f714b1688119b710b2df13/W8f6NEtdUi5mTUV
104.17.2.184
https://efe.q39r.com/qrLAnsLIQYwNSdAtFLDZAVDTqAL5avHc3AjdCSMdpstcHKxHSNTwj5RyHAtXh530miRlbef231
172.67.218.12
https://efe.q39r.com/3260159782465770049704iFFVMYwfZXHNULWNRTYRTUBJRAOWNOUFUOKLGSUKRBDLEVYTKDSOIHHK?384399381880252904888uIpvhsLIBURLKKWOATGJNBCEFIHVGVBRUIPDOOAHZYFXEBBOMXYRQWILAFIDEAPRQ
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/alyrn/0x4AAAAAAAYIhGTHgfwrnf2u/auto/normal
https://www.google.com/recaptcha/api.js
172.217.215.147
https://support.google.com/recaptcha/#6175971
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.2.184
https://www.gstatic.c..?/recaptcha/releases/V6_85qpc2Xf2sbe3xTnRte7m/recaptcha__.
unknown
https://a.nel.cloudflare.com/report/v4?s=4ozS%2FD%2BlhebByb9jaBaCRWoAEncGPbHpc01bkEyWlR9QzWHR%2FB9s%2F%2F50q%2BwlKuLB0VLH2U6N5aT1m2TFYtnVn1eP3Skjt1q0M%2BCesyWR3U00ru6Y6S3N5kKqF3Fs%2FQ%3D%3D
35.190.80.1
https://www.google.com/recaptcha/api2/
unknown
https://sanemedia.ca/favicon.ico
162.241.120.242
https://efe.q39r.com/mxd88J5SFObXj8HgS9r5Oqo
172.67.218.12
https://efe.q39r.com/3260159782465770049704iFFVMYwfZXHNULWNRTYRTUBJRAOWNOUFUOKLGSUKRBDLEVYTKDSOIHHK?384399381880252904888uIpvhsLIBURLKKWOATGJNBCEFIHVGVBRUIPDOOAHZYFXEBBOMXYRQWILAFIDEAPRQ#
https://support.google.com/recaptcha
unknown
https://a.nel.cloudflare.com/report/v4?s=a6GvRdjU7wxUPS6xvKrNLItf1hxVWchbnphYEKfU9CkfSz1LBm%2FLNH8SepAyB%2BEQ8sPkYxIjgzhfbeAKcr%2B1JhUob0dzo1yRdxmY7HV61OAgf6DbmmoXDXodTf0cjw%3D%3D
35.190.80.1
https://efe.q39r.com/78YLTTRnUphmEbu9qO67SLVo5st60
172.67.218.12
https://sanemedia.ca/owaow/yjyo8q/bWFyaWEud29qY2llY2hvd3NraUBjby5tb25tb3V0aC5uai51cw==
https://efe.q39r.com/89gLF9wAyZQBttvEu1214qTO8Jk0zab80
172.67.218.12
https://efe.q39r.com/baYfqODAqON352foJK6CCE9kK3PljnLlksxN1ximawy4Kzj8eLKti
172.67.218.12
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://recaptcha.net
unknown
https://efe.q39r.com/efe/
172.67.218.12
https://www.apache.org/licenses/
unknown
https://efe.q39r.com/uvY5pc9R3aOMn5iktLy2aF80JVOqgOgAQmDmXJRh16V8fRqisgR96zZWNLppBr6uPqAnZgGMrstoDND7PTYaJrxoxbwvdXm6lbBR6k1MmdSRx33m9e4MOGfx7f0zwZleHhh4RkMIcd426
172.67.218.12
https://efe.q39r.com/efVNIXESSrQw6BIj3MhA1KKgkluoFJllnuG6p4XxyrMQmt6p78145
172.67.218.12
https://efe.q39r.com/yzLzEv86HZWOuTs43gD6XgopoPEM7xE25vteTrcz90175
172.67.218.12
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=879f1dd91a63b08b
104.17.2.184
https://play.google.com/log?format=json&hasfast=true
unknown
https://efe.q39r.com/uvNTmYhBjmYRofOqCut3dZa4UstUasUJN1P0bM12122
172.67.218.12
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://web.lehighvalleychamber.org/cwt/external/wcpages/referral.aspx?ReferralType=W&ProfileID=5337&ListingID=4065&CategoryID=74&SubCategoryID=0&url=//sanemedia.ca/owaow/yjyo8q/bWFyaWEud29qY2llY2hvd3NraUBjby5tb25tb3V0aC5uai51cw==
104.18.248.141
https://efe.q39r.com/pqbZD8J7FTYmSxlvQoeRprDFjztNLRFVGfLqei0S3C5OKYFYXooWduvPQauK5eZhaN1ALtm8rATfqbv2GlgZzZXRCuPcYNYW3t1lvQlHMEBuEV79yz414
172.67.218.12
https://cdn.socket.io/4.6.0/socket.io.min.js
99.84.108.59
https://efe.q39r.com/xyVJM3U7MOm9vvpqo9Yqgh30
172.67.218.12
https://efe.q39r.com/12deHT1xywXm8915
172.67.218.12
https://efe.q39r.com/ghNptpEXYJR7LTcZ65tUkEWP4OmnFHYdEppOMq56CTaQuzPVKMBnXiF5yqRi12209
172.67.218.12
https://efe.q39r.com/234cS6u1hDGFEEM8d4zs89TYj5mkaHvw70
172.67.218.12
https://efe.q39r.com/rscAVjDySGVa9dH78yzE7duv38
172.67.218.12
There are 45 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
a.nel.cloudflare.com
35.190.80.1
code.jquery.com
151.101.66.137
d2vgu95hoyrpkh.cloudfront.net
99.84.108.59
lehighvalleypacoc.weblinkconnect.com
104.18.248.141
efe.q39r.com
172.67.218.12
challenges.cloudflare.com
104.17.3.184
www.google.com
64.233.177.99
sanemedia.ca
162.241.120.242
fp2e7a.wpc.phicdn.net
192.229.211.108
web.lehighvalleychamber.org
unknown
cdn.socket.io
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
99.84.108.59
d2vgu95hoyrpkh.cloudfront.net
United States
104.18.248.141
lehighvalleypacoc.weblinkconnect.com
United States
172.217.215.147
unknown
United States
172.67.218.12
efe.q39r.com
United States
192.168.2.4
unknown
unknown
64.233.177.99
www.google.com
United States
104.17.3.184
challenges.cloudflare.com
United States
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
151.101.66.137
code.jquery.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
162.241.120.242
sanemedia.ca
United States
104.17.2.184
unknown
United States
104.21.17.5
unknown
United States
There are 4 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://efe.q39r.com/3260159782465770049704iFFVMYwfZXHNULWNRTYRTUBJRAOWNOUFUOKLGSUKRBDLEVYTKDSOIHHK?384399381880252904888uIpvhsLIBURLKKWOATGJNBCEFIHVGVBRUIPDOOAHZYFXEBBOMXYRQWILAFIDEAPRQ
malicious
https://efe.q39r.com/3260159782465770049704iFFVMYwfZXHNULWNRTYRTUBJRAOWNOUFUOKLGSUKRBDLEVYTKDSOIHHK?384399381880252904888uIpvhsLIBURLKKWOATGJNBCEFIHVGVBRUIPDOOAHZYFXEBBOMXYRQWILAFIDEAPRQ#
malicious
https://efe.q39r.com/3260159782465770049704iFFVMYwfZXHNULWNRTYRTUBJRAOWNOUFUOKLGSUKRBDLEVYTKDSOIHHK?384399381880252904888uIpvhsLIBURLKKWOATGJNBCEFIHVGVBRUIPDOOAHZYFXEBBOMXYRQWILAFIDEAPRQ#
malicious
https://sanemedia.ca/owaow/yjyo8q/bWFyaWEud29qY2llY2hvd3NraUBjby5tb25tb3V0aC5uai51cw==
https://efe.q39r.com/efe/#Xmaria.wojciechowski@co.monmouth.nj.us
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/alyrn/0x4AAAAAAAYIhGTHgfwrnf2u/auto/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/alyrn/0x4AAAAAAAYIhGTHgfwrnf2u/auto/normal