IOC Report
http://www.jdenviro.ca

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 15:20:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 15:20:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 15:20:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 15:20:55 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 15:20:54 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 139
JPEG image data, progressive, precision 8, 1500x1000, components 3
dropped
Chrome Cache Entry: 140
HTML document, Unicode text, UTF-8 text, with very long lines (17945)
downloaded
Chrome Cache Entry: 141
ASCII text
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (16813)
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (12695)
downloaded
Chrome Cache Entry: 144
JPEG image data, progressive, precision 8, 1500x1000, components 3
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 147
HTML document, Unicode text, UTF-8 text, with very long lines (17947)
downloaded
Chrome Cache Entry: 148
JPEG image data, progressive, precision 8, 500x332, components 3
dropped
Chrome Cache Entry: 149
JPEG image data, progressive, precision 8, 500x334, components 3
downloaded
Chrome Cache Entry: 150
JPEG image data, progressive, precision 8, 1500x1000, components 3
downloaded
Chrome Cache Entry: 151
JPEG image data, progressive, precision 8, 500x749, components 3
downloaded
Chrome Cache Entry: 152
JPEG image data, progressive, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (14665)
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (49795)
downloaded
Chrome Cache Entry: 155
JPEG image data, progressive, precision 8, 500x750, components 3
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (13535), with no line terminators
downloaded
Chrome Cache Entry: 157
JPEG image data, progressive, precision 8, 1500x827, components 3
dropped
Chrome Cache Entry: 158
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (65467)
downloaded
Chrome Cache Entry: 160
HTML document, ASCII text, with very long lines (17956)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (44349)
downloaded
Chrome Cache Entry: 162
HTML document, Unicode text, UTF-8 text, with very long lines (17960)
downloaded
Chrome Cache Entry: 163
Web Open Font Format (Version 2), TrueType, length 7748, version 1.0
downloaded
Chrome Cache Entry: 164
JPEG image data, progressive, precision 8, 500x334, components 3
dropped
Chrome Cache Entry: 165
ASCII text, with very long lines (44264)
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (44264)
downloaded
Chrome Cache Entry: 167
HTML document, Unicode text, UTF-8 text, with very long lines (18038)
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (43819)
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 170
JPEG image data, progressive, precision 8, 500x332, components 3
downloaded
Chrome Cache Entry: 171
JPEG image data, progressive, precision 8, 1500x1000, components 3
downloaded
Chrome Cache Entry: 172
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (1931)
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (64879)
downloaded
Chrome Cache Entry: 175
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 176
JPEG image data, progressive, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 177
JPEG image data, progressive, precision 8, 1500x1000, components 3
dropped
Chrome Cache Entry: 178
HTML document, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 179
JPEG image data, progressive, precision 8, 1500x1000, components 3
dropped
Chrome Cache Entry: 180
Unicode text, UTF-8 text, with very long lines (43878), with NEL line terminators
downloaded
Chrome Cache Entry: 181
JPEG image data, progressive, precision 8, 500x332, components 3
dropped
Chrome Cache Entry: 182
JPEG image data, progressive, precision 8, 1500x1125, components 3
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (41089)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (44262)
downloaded
Chrome Cache Entry: 186
JPEG image data, progressive, precision 8, 500x334, components 3
downloaded
Chrome Cache Entry: 187
JPEG image data, progressive, precision 8, 1200x902, components 3
dropped
Chrome Cache Entry: 188
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 189
HTML document, Unicode text, UTF-8 text, with very long lines (17990)
downloaded
Chrome Cache Entry: 190
Web Open Font Format (Version 2), TrueType, length 7816, version 1.0
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (451), with no line terminators
downloaded
Chrome Cache Entry: 192
Unicode text, UTF-8 text, with very long lines (33239), with no line terminators
downloaded
Chrome Cache Entry: 193
JPEG image data, progressive, precision 8, 500x750, components 3
dropped
Chrome Cache Entry: 194
JPEG image data, progressive, precision 8, 1500x1000, components 3
downloaded
Chrome Cache Entry: 195
Web Open Font Format (Version 2), TrueType, length 7840, version 1.0
downloaded
Chrome Cache Entry: 196
JPEG image data, progressive, precision 8, 1500x1000, components 3
downloaded
Chrome Cache Entry: 197
JPEG image data, progressive, precision 8, 500x334, components 3
dropped
Chrome Cache Entry: 198
JPEG image data, progressive, precision 8, 500x749, components 3
dropped
Chrome Cache Entry: 199
JPEG image data, progressive, precision 8, 500x332, components 3
downloaded
Chrome Cache Entry: 200
JPEG image data, progressive, precision 8, 1500x1125, components 3
dropped
Chrome Cache Entry: 201
JPEG image data, progressive, precision 8, 1500x1000, components 3
dropped
Chrome Cache Entry: 202
JPEG image data, progressive, precision 8, 1500x1000, components 3
downloaded
Chrome Cache Entry: 203
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (44264)
downloaded
Chrome Cache Entry: 205
JPEG image data, progressive, precision 8, 1500x827, components 3
downloaded
Chrome Cache Entry: 206
ASCII text, with very long lines (44343)
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (65202)
downloaded
Chrome Cache Entry: 208
JPEG image data, progressive, precision 8, 1200x902, components 3
downloaded
Chrome Cache Entry: 209
Unicode text, UTF-8 text, with very long lines (7601)
downloaded
Chrome Cache Entry: 210
ASCII text, with very long lines (44262)
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (44343)
downloaded
Chrome Cache Entry: 212
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 213
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 214
JPEG image data, progressive, precision 8, 1500x1000, components 3
downloaded
Chrome Cache Entry: 215
HTML document, Unicode text, UTF-8 text, with very long lines (17984)
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 218
JPEG image data, progressive, precision 8, 1500x1000, components 3
dropped
There are 77 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2328 --field-trial-handle=2264,i,13675748583419537801,14854919490164647966,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.jdenviro.ca"

URLs

Name
IP
Malicious
http://www.jdenviro.ca
malicious
https://github.com/baryon
unknown
https://www.jdenviro.ca/asbestos-mould
https://github.com/xsoh
unknown
https://github.com/noureddinem
unknown
https://github.com/TalAter
unknown
https://github.com/zloirock/core-js
unknown
https://github.com/ebraminio
unknown
https://github.com/jonashdown
unknown
https://assets.squarespace.com/universal/scripts-compressed/extract-css-runtime-3095a72d947f623b1e81-min.en-US.js
151.101.64.237
https://assets.squarespace.com/universal/scripts-compressed/32386-58416000149d1b131d52-min.en-US.js
151.101.64.237
https://github.com/ryanhart2
unknown
http://yuilibrary.com/license/
unknown
https://github.com/kalehv
unknown
https://github.com/crnjakovic
unknown
https://assets.squarespace.com/universal/scripts-compressed/async-visitor-forms-a833e6bf41e6f687d328-min.en-US.js
151.101.64.237
https://github.com/aliem
unknown
https://assets.squarespace.com/universal/scripts-compressed/common-836ac4156e3859bd3f2b-min.en-US.js
151.101.64.237
https://github.com/Manfre98
unknown
https://github.com/evoL
unknown
https://github.com/vnathalye
unknown
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/1646345356840-1300BM4S8RIJ8JJ
unknown
https://assets.squarespace.com/universal/styles-compressed/slide-normalize-f3e05d707a08546a77c65-min.en-US.css
151.101.64.237
https://github.com/le0tan
unknown
https://github.com/narainsagar
unknown
https://assets.squarespace.com/universal/scripts-compressed/cldr-resource-pack-e94539391642d3b99900-min.en-US.js
151.101.64.237
https://github.com/ElFadiliY
unknown
https://github.com/ashwoolford
unknown
https://github.com/hagmandan
unknown
https://github.com/jbleduigou
unknown
https://github.com/muminoff
unknown
https://openjsf.org/
unknown
https://assets.squarespace.com/@sqs/polyfiller/1.6/modern.js
151.101.64.237
https://www.jdenviro.ca/universal/svg/lock-screen.svg
198.185.159.144
https://github.com/jatinag22
unknown
https://github.com/hehachris
unknown
https://assets.squarespace.com/universal/scripts-compressed/common-vendors-stable-70736932c490ae0713e6-min.en-US.js
151.101.64.237
https://github.com/jarcoal
unknown
https://github.com/jcfranco
unknown
https://github.com/mayanksinghal
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/d921885d89b771bced38f351a
unknown
https://performance.squarespace.com/api/v1/records
35.186.236.0
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/1646689138855-IKI6UOGZU5CJ3M4
unknown
https://www.jdenviro.ca/api/census/RecordHit
198.185.159.144
https://github.com/andela-batolagbe
unknown
https://github.com/forabi
unknown
https://github.com/bleadof
unknown
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/1646345356840-1300BM4S8RIJ8JJVS2XU/kobu-agency-TWIRIAizZFU-unsplash.jpg?format=500w
151.101.128.238
https://github.com/boyaq
unknown
https://github.com/passatgt
unknown
https://github.com/naderio
unknown
https://github.com/kaushikgandhi
unknown
https://github.com/B0k0
unknown
https://github.com/middagj
unknown
http://underscorejs.org/LICENSE
unknown
https://github.com/javkhaanj7
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/e7c36e4e52f3f35484a4d7e33
unknown
https://github.com/mweimerskirch
unknown
https://github.com/kruyvanna
unknown
https://github.com/suvash
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/ca345414d3962ef6cdaca8d28
unknown
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/beb0f560-87ba-4992-8ec8-cdff160e4867/iStock-492889648.jpeg?format=1500w
151.101.128.238
https://github.com/andrewhood125
unknown
https://github.com/ShahramMebashar
unknown
https://github.com/soniasimoes
unknown
https://github.com/BYK
unknown
https://www.jdenviro.ca/
https://github.com/skakri
unknown
https://github.com/jalex79
unknown
https://github.com/kraz
unknown
https://github.com/nusretparlak
unknown
https://github.com/sigurdga
unknown
https://github.com/nostalgiaz
unknown
https://github.com/sampathsris
unknown
https://images.squarespace-cdn.com/content/v1/5ec321c2af33de48734cc929/1618497259178-6XJGK9GR6YAVBQL
unknown
https://github.com/ulmus
unknown
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/1646347310641-YH6ORY8ERXAT8TL8KBUZ/unsplash-image-E6KM98Q_d4o.jpg?format=1500w
151.101.128.238
https://github.com/gurdiga
unknown
https://github.com/orif-jr
unknown
https://github.com/johnideal
unknown
https://assets.squarespace.com/universal/scripts-compressed/extract-css-runtime-70516ca32e8783ce987a-min.en-US.js
151.101.64.237
https://static1.squarespace.com/static/vta/5c5a519771c10ba3470d8101/scripts/site-bundle.c60096393cff
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/1a95552bb6110607de79bb959
unknown
https://github.com/bmarkovic
unknown
https://assets.squarespace.com/universal/scripts-compressed/40660-4b4a3de7591f351c8626-min.en-US.js
151.101.64.237
https://github.com/sedovsek
unknown
https://github.com/k2s
unknown
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/1646348872384-3CFSZNN631X3M5P
unknown
https://www.jdenviro.ca/building-condition-reports
https://www.jdenviro.ca/api/census/button-render
198.185.159.144
https://github.com/caio-ribeiro-pereira
unknown
https://github.com/jfroffice
unknown
https://www.jdenviro.ca/demolition
https://github.com/hinrik
unknown
https://sourcemaps.squarespace.net/universal/scripts-compressed/sourcemaps/5df7e16aeca2dd8743f066c9a
unknown
https://github.com/chrisgedrim
unknown
https://github.com/chienkira
unknown
https://github.com/colindean
unknown
https://www.jdenviro.ca
unknown
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/1646345209723-H5CZ2KA1S35TKPZ
unknown
https://images.squarespace-cdn.com/content/v1/6221241e66aad7323ea8150a/1646345027361-F77V7MX7R3MABS7ORJC0/unsplash-image-MDteiLH1CZY.jpg?format=1500w
151.101.128.238
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
performance.squarespace.com
35.186.236.0
bg.microsoft.map.fastly.net
199.232.214.172
static.squarespace.map.fastly.net
151.101.64.237
www.google.com
172.217.215.103
ext-cust.squarespace.com
198.185.159.144
squarespace.map.fastly.net
151.101.128.238
prod.squarespace.map.fastly.net
151.101.192.238
fp2e7a.wpc.phicdn.net
192.229.211.108
www.jdenviro.ca
unknown
images.squarespace-cdn.com
unknown
assets.squarespace.com
unknown
static1.squarespace.com
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
151.101.64.237
static.squarespace.map.fastly.net
United States
172.217.215.103
www.google.com
United States
151.101.192.238
prod.squarespace.map.fastly.net
United States
151.101.0.238
unknown
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
151.101.128.238
squarespace.map.fastly.net
United States
198.185.159.144
ext-cust.squarespace.com
United States
239.255.255.250
unknown
Reserved
35.186.236.0
performance.squarespace.com
United States

DOM / HTML

URL
Malicious
https://www.jdenviro.ca/
https://www.jdenviro.ca/
https://www.jdenviro.ca/
https://www.jdenviro.ca/#page
https://www.jdenviro.ca/#page
https://www.jdenviro.ca/building-condition-reports
https://www.jdenviro.ca/building-condition-reports
https://www.jdenviro.ca/demolition
https://www.jdenviro.ca/demolition
https://www.jdenviro.ca/demolition
https://www.jdenviro.ca/air-soil-water
https://www.jdenviro.ca/air-soil-water
https://www.jdenviro.ca/client-access
https://www.jdenviro.ca/client-access
https://www.jdenviro.ca/client-access
https://www.jdenviro.ca/client-access
https://www.jdenviro.ca/environmental-site-assessment
https://www.jdenviro.ca/environmental-site-assessment
https://www.jdenviro.ca/asbestos-mould
https://www.jdenviro.ca/asbestos-mould
https://www.jdenviro.ca/contact
https://www.jdenviro.ca/employee-access
https://www.jdenviro.ca/employee-access
There are 13 hidden doms, click here to show them.