IOC Report
https://doc-42.jimdosite.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
HTML document, ASCII text, with very long lines (1388), with no line terminators
downloaded
Chrome Cache Entry: 101
JSON data
downloaded
Chrome Cache Entry: 102
JSON data
downloaded
Chrome Cache Entry: 103
JSON data
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 105
JSON data
dropped
Chrome Cache Entry: 106
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 107
HTML document, ASCII text, with very long lines (7545)
downloaded
Chrome Cache Entry: 108
JSON data
dropped
Chrome Cache Entry: 109
Web Open Font Format (Version 2), TrueType, length 15860, version 1.0
downloaded
Chrome Cache Entry: 110
Web Open Font Format (Version 2), TrueType, length 7816, version 1.0
downloaded
Chrome Cache Entry: 111
HTML document, Unicode text, UTF-8 text, with very long lines (6523)
downloaded
Chrome Cache Entry: 112
Web Open Font Format (Version 2), TrueType, length 20388, version 3.66
downloaded
Chrome Cache Entry: 113
Web Open Font Format (Version 2), TrueType, length 20256, version 3.66
downloaded
Chrome Cache Entry: 114
Web Open Font Format (Version 2), TrueType, length 20420, version 3.66
downloaded
Chrome Cache Entry: 115
ASCII text, with very long lines (58893)
downloaded
Chrome Cache Entry: 116
Web Open Font Format (Version 2), TrueType, length 8000, version 1.0
downloaded
Chrome Cache Entry: 117
JSON data
dropped
Chrome Cache Entry: 118
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 119
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 120
JSON data
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (44439)
downloaded
Chrome Cache Entry: 122
JSON data
dropped
Chrome Cache Entry: 123
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 124
gzip compressed data, was "tmpCfWGAE", last modified: Fri May 8 09:06:08 2020, max compression, original size modulo 2^32 489
dropped
Chrome Cache Entry: 125
HTML document, ASCII text, with very long lines (690), with no line terminators
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (24674)
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (10459)
downloaded
Chrome Cache Entry: 128
JSON data
downloaded
Chrome Cache Entry: 129
RIFF (little-endian) data, Web/P image, VP8 encoding, 610x320, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (461), with no line terminators
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 132
JSON data
downloaded
Chrome Cache Entry: 133
ASCII text
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (65417)
downloaded
Chrome Cache Entry: 135
JSON data
downloaded
Chrome Cache Entry: 136
RIFF (little-endian) data, Web/P image, VP8 encoding, 612x320, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (35231)
downloaded
Chrome Cache Entry: 138
Unicode text, UTF-8 text, with very long lines (12416)
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (7821), with no line terminators
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (5180), with no line terminators
downloaded
Chrome Cache Entry: 141
JSON data
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 143
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 145
HTML document, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (32819)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (42414)
downloaded
Chrome Cache Entry: 148
RIFF (little-endian) data, Web/P image, VP8 encoding, 610x320, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 149
Unicode text, UTF-8 text, with very long lines (65441)
downloaded
Chrome Cache Entry: 150
PNG image data, 320 x 320, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 151
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 152
ASCII text
downloaded
Chrome Cache Entry: 153
JSON data
dropped
Chrome Cache Entry: 154
HTML document, Unicode text, UTF-8 text, with very long lines (7699)
downloaded
Chrome Cache Entry: 155
Web Open Font Format (Version 2), TrueType, length 15744, version 1.0
downloaded
Chrome Cache Entry: 156
JSON data
dropped
Chrome Cache Entry: 157
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 158
JSON data
dropped
Chrome Cache Entry: 159
RIFF (little-endian) data, Web/P image, VP8 encoding, 612x320, Scaling: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 160
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 87
ASCII text, with very long lines (36480)
downloaded
Chrome Cache Entry: 88
RIFF (little-endian) data, Web/P image, VP8 encoding, 610x320, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 89
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 90
ASCII text, with very long lines (65454)
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (65453)
downloaded
Chrome Cache Entry: 92
gzip compressed data, was "tmpCfWGAE", last modified: Fri May 8 09:06:08 2020, max compression, original size modulo 2^32 489
downloaded
Chrome Cache Entry: 93
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 94
Unicode text, UTF-8 text, with very long lines (65253)
downloaded
Chrome Cache Entry: 95
ASCII text, with very long lines (31034), with no line terminators
downloaded
Chrome Cache Entry: 96
ASCII text, with very long lines (65458)
downloaded
Chrome Cache Entry: 97
ASCII text, with very long lines (34414)
downloaded
Chrome Cache Entry: 98
PNG image data, 144 x 144, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 99
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
There are 64 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2152 --field-trial-handle=2028,i,12123064958446262542,16323001551945797636,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://doc-42.jimdosite.com/"

URLs

Name
IP
Malicious
https://doc-42.jimdosite.com/
malicious
https://tools.google.com/dlpage/gaoptout)
unknown
https://www.tiktok.com/legal/cookie-policy?lang=en
unknown
https://pub-915ec07e23184287868b4bc8f1cb3f00.r2.dev/favicon.ico
104.18.3.35
https://www.jimdo.com/fr/addon/legal-text-generator/)
unknown
https://policy.pinterest.com/en/privacy-policy
unknown
https://fonts.jimstatic.com/s/roboto/v30/KFOlCnqEu92Fr1MmWUlfBxc4EsA.woff2)
unknown
https://www.paypal.com/ie/webapps/mpp/ua/privacy-full
unknown
https://www.spotify.com/jp/legal/privacy-policy/
unknown
https://www.spotify.com/de/legal/privacy-policy/
unknown
https://fonts.jimstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu7GxKOzY.woff2)
unknown
about:blank
https://stripe.com/cookies-policy/legal
unknown
https://jimdo-community-events.jimdosite.com/events/
unknown
https://px.ads.linkedin.com/collect?
unknown
https://www.jimdo.com/it/addon/legal-text-generator/)
unknown
https://www.google.com
unknown
https://policies.google.com/privacy?hl=it
unknown
https://fonts.jimstatic.com/s/roboto/v30/KFOlCnqEu92Fr1MmWUlfChc4EsA.woff2)
unknown
https://doc-42.jimdosite.com/cookie-settings/
https://fonts.jimstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu7WxKOzY.woff2)
unknown
https://www.kddi-webcommunications.co.jp/privacy)
unknown
https://connect.facebook.net/en_US/fbevents.js
unknown
https://www.cloudflare.com/cookie-policy/
unknown
https://fonts.jimstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu4mxK.woff2)
unknown
https://presse.jimdo.com/
unknown
https://admin.typeform.com/to/dwk6gt/?typeform-source=www.typeform.com
unknown
https://developers.cloudflare.com/r2/data-access/public-buckets/
unknown
https://at.prod.jimdo.systems/anon
54.217.4.226
https://fonts.jimstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu7mxKOzY.woff2)
unknown
https://account.e.jimdo.com/login
unknown
https://fonts.jimstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu5mxKOzY.woff2)
unknown
https://logo.e.jimdo.com/?lng=en
unknown
https://bandcamp.com/privacy_shield
unknown
https://www.google.com/analytics/terms)
unknown
https://www.jimdo.com/fr/
unknown
https://a.jimdo.com/app/price/index/country
54.72.164.245
https://fonts.jimstatic.com/s/roboto/v30/KFOlCnqEu92Fr1MmWUlfBBc4.woff2)
unknown
https://jimdo-storage.freetls.fastly.net/
unknown
https://www.jimdo.com
unknown
https://www.jimdo.com/?utm_source=dol-doc-42%20en-US&utm_medium=footer%20ad&utm_campaign=ownads%20webview
https://www.jimdo.com/de/
unknown
http://tools.google.com/dlpage/gaoptout
unknown
https://fonts.jimstatic.com/s/poppins/v21/pxiByp8kv8JHgFVrLCz7Z1JlFc-K.woff2)
unknown
https://account.e.jimdo.com/openid/authorize?client_id=lc-website&redirect_uri=https://www.jimdo.com/oidc-silent-callback/&response_type=id_token&scope=openid%20email%20profile&state=256b7a98da7746ca9ff5752a1b68e60e&nonce=7640dc06b94045b186e893193bb13880&prompt=none
18.200.162.103
https://v1.api.service.cmp.usercentrics.eu/latest/1/cmp/en/GDPR/k1JwB2Dk_/265.83.373/265.83.373?isOutsideEu=true
34.102.170.124
https://fonts.jimstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu72xKOzY.woff2)
unknown
https://policies.google.com/)
unknown
https://adservice.google.com/pagead/regclk
unknown
https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback
104.17.3.184
https://cct.google/taggy/agent.js
unknown
https://static.ads-twitter.com/uwt.js
unknown
https://policies.google.com/privacy?hl=ja
unknown
https://jimdo-dolphin-static-assets-prod.freetls.fastly.net/renderer/static/default-website-favicon.1a874ea70dbf3a4b0e0e..png
151.101.2.79
https://jimdo-storage.freetls.fastly.net/image/455980452/9041bab6-4a58-4ffc-8c72-5cb97b13d08f.png?quality=80,90&auto=webp&disable=upscale&width=320&height=320
151.101.2.79
https://www.tumblr.com/privacy
unknown
https://www.jimdo.com/
unknown
https://www.jimdo.com/nl/addon/legal-text-generator/)
unknown
https://www.spotify.com/legal/privacy-policy/
unknown
https://at.prod.jimdo.systems/cf
54.217.4.226
https://www.jimdo.com/info/privacy/)
unknown
https://web.cmp.usercentrics.eu/ui/loader.js
34.149.254.14
https://www.spotify.com/legal/cookies-policy/
unknown
https://fonts.jimstatic.com/s/roboto/v30/KFOlCnqEu92Fr1MmWUlfCRc4EsA.woff2)
unknown
https://jimdo-dolphin-static-assets-prod.freetls.fastly.net/renderer/static/default-website-favicon.
unknown
https://www.jimdo.com/website/portfolio/
unknown
https://www.youtube.com/user/jimdo
unknown
https://help.business.jimdo.com/hc/de
unknown
https://www.jimdo.com/jp/
unknown
https://v1.api.service.cmp.usercentrics.eu/latest/core/k1JwB2Dk_
34.102.170.124
https://www.google.com/.well-known/web-identity
142.250.189.132
https://www.jimdo-status.com/).
unknown
https://www.jimdo.com/oidc-silent-callback/#error=login_required&error_description=The%20Authorization%20Server%20requires%20End-User%20authentication&state=256b7a98da7746ca9ff5752a1b68e60e
https://www.pinterest.de/JimdoEN/
unknown
https://web.cmp.usercentrics.eu/ui/v/3.12.2/BrowserSdk.lib.842d58da.js
34.149.254.14
https://web.cmp.usercentrics.eu/ui/v/3.12.2/cmp.a3828959.js
34.149.254.14
https://stripe.com/privacy
unknown
https://www.cloudflare.com/privacypolicy/
unknown
https://fonts.jimstatic.com/s/poppins/v21/pxiByp8kv8JHgFVrLEj6Z1JlFc-K.woff2)
unknown
https://www.cloudflare.com/ja-jp/privacypolicy/
unknown
https://web.cmp.usercentrics.eu/ui/v/3.12.2/UcGdprCmpView.5874706c.js
34.149.254.14
https://challenges.cloudflare.com/turnstile/v0/b/471dc2adc340/api.js?onload=onloadTurnstileCallback
104.17.3.184
https://help.instagram.com/1896641480634370?ref=ig
unknown
https://deploy.mopinion.com/js/pastease.js
unknown
https://www.tiktok.com/legal/privacy-policy-eea?lang=de
unknown
https://www.twitch.tv/p/de-de/legal/cookie-notice/
unknown
https://web.cmp.usercentrics.eu/ui/v/3.12.2/GdprCmpController.3f26e812.js
34.149.254.14
https://policies.google.com/privacy?hl=de
unknown
https://feature-flags-proxy.prod.jimdo.systems/feature-flags?shd=d5f4b0dd-411c-4c16-9ae7-a6ad92d3df1f&custom=%7B%22language%22%3A%22en%22%2C%22isMobileLayout%22%3Afalse%2C%22jimdoApp%22%3A%22lp%22%2C%22isAffiliate%22%3Afalse%7D
18.200.162.103
https://policies.google.com/privacy?hl=es
unknown
https://s.pinimg.com/ct/core.js
unknown
https://forschungswerkstatt.jimdo.com/
unknown
https://account.e.jimdo.com/signup/facebook
unknown
https://careers.jimdo.com/
unknown
https://www.jimdo.com/de/addon/legal-text-generator)
unknown
https://fonts.jimstatic.com/s/roboto/v30/KFOmCnqEu92Fr1Mu4WxKOzY.woff2)
unknown
https://vimeo.com/api/oembed.json?url=
unknown
https://www.jimdo.com/jp/news/)
unknown
https://policies.google.com/privacy?hl=en
unknown
https://twitter.com/en/privacy
unknown
https://www.jimdo.com/es/addon/legal-text-generator/)
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
app.usercentrics.eu
35.190.14.188
google.com
142.250.217.238
at.prod.jimdo.systems
54.217.4.226
web.cmp.usercentrics.eu
34.149.254.14
feature-flags-proxy.prod.jimdo.systems
18.200.162.103
pub-915ec07e23184287868b4bc8f1cb3f00.r2.dev
104.18.3.35
account.prod.jimdo.systems
18.200.162.103
fp2e7a.wpc.phicdn.net
192.229.211.108
jimdo-dolphin-static-assets-prod.freetls.fastly.net
151.101.2.79
bg.microsoft.map.fastly.net
199.232.210.172
consent-api.service.consent.usercentrics.eu
35.201.111.240
jimdo-storage.freetls.fastly.net
151.101.2.79
challenges.cloudflare.com
104.17.3.184
www.google.com
192.178.50.36
grupoej.com
192.185.144.111
a.prod.jimdo.systems
54.72.164.245
v1.api.service.cmp.usercentrics.eu
34.102.170.124
doc-42.jimdosite.com
unknown
account.e.jimdo.com
unknown
country.jimdo.com
unknown
a.jimdo.com
unknown
fonts.jimstatic.com
unknown
www.jimdo.com
unknown
There are 13 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.178.50.36
www.google.com
United States
54.72.164.245
a.prod.jimdo.systems
United States
104.18.3.35
pub-915ec07e23184287868b4bc8f1cb3f00.r2.dev
United States
192.168.2.4
unknown
unknown
104.17.3.184
challenges.cloudflare.com
United States
34.149.254.14
web.cmp.usercentrics.eu
United States
54.217.4.226
at.prod.jimdo.systems
United States
18.200.162.103
feature-flags-proxy.prod.jimdo.systems
United States
192.185.144.111
grupoej.com
United States
151.101.2.79
jimdo-dolphin-static-assets-prod.freetls.fastly.net
United States
35.190.14.188
app.usercentrics.eu
United States
239.255.255.250
unknown
Reserved
34.102.170.124
v1.api.service.cmp.usercentrics.eu
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://doc-42.jimdosite.com/
malicious
https://doc-42.jimdosite.com/
malicious
about:blank
https://doc-42.jimdosite.com/imprint/
https://pub-915ec07e23184287868b4bc8f1cb3f00.r2.dev/index.html
https://doc-42.jimdosite.com/cookie-settings/
https://www.jimdo.com/?utm_source=dol-doc-42%20en-US&utm_medium=footer%20ad&utm_campaign=ownads%20webview
https://www.jimdo.com/?utm_source=dol-doc-42%20en-US&utm_medium=footer%20ad&utm_campaign=ownads%20webview
https://www.jimdo.com/?utm_source=dol-doc-42%20en-US&utm_medium=footer%20ad&utm_campaign=ownads%20webview
https://www.jimdo.com/oidc-silent-callback/#error=login_required&error_description=The%20Authorization%20Server%20requires%20End-User%20authentication&state=256b7a98da7746ca9ff5752a1b68e60e
https://web.cmp.usercentrics.eu/cdcs/v/1.0.0/index.html
There are 1 hidden doms, click here to show them.