IOC Report
https://u17065553.ct.sendgrid.net/ls/click?upn=u001.Rw-2FXpvWBRDxNoiEvv-2B0VhGNZUddqwhjRz7Y3aH-2F1iEXujVcSjMM7CY7q30axNIjPtSPwVANtpwkARse71YbTG6hv5YyKcZ3EG9czO3tuqWXIHvFV-2FdtzTRYY9DFBEvbC0MnWDkjPffSjdhbZvMXBG-2Fbl-2F1JQalpy10ZBTpuDmJw8qtDG1RR-2FO-2Bzqy6Ryg-2BIXW6P-2FRmEE7JdIRaCncCouVLTVsWciZPEjkoHD

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 101
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 102
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (10017)
downloaded
Chrome Cache Entry: 105
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 106
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 107
PNG image data, 420 x 94, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 108
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 109
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 110
Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
downloaded
Chrome Cache Entry: 111
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 112
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 113
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 115
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 116
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 119
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 72
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 73
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 75
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 76
ASCII text, with very long lines (48238)
downloaded
Chrome Cache Entry: 78
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 79
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (26765), with no line terminators
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (51734)
downloaded
Chrome Cache Entry: 83
Web Open Font Format, TrueType, length 36696, version 1.0
downloaded
Chrome Cache Entry: 84
Unicode text, UTF-8 text, with very long lines (21720), with CRLF line terminators
downloaded
Chrome Cache Entry: 87
ASCII text, with very long lines (48316), with no line terminators
downloaded
Chrome Cache Entry: 88
HTML document, ASCII text, with very long lines (52007), with CRLF line terminators
downloaded
Chrome Cache Entry: 89
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 90
very short file (no magic)
dropped
Chrome Cache Entry: 91
HTML document, ASCII text, with very long lines (11997), with CRLF line terminators
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (10450)
downloaded
Chrome Cache Entry: 93
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 95
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 96
Web Open Font Format, TrueType, length 35970, version 1.0
downloaded
Chrome Cache Entry: 99
Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
downloaded
There are 27 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://u17065553.ct.sendgrid.net/ls/click?upn=u001.Rw-2FXpvWBRDxNoiEvv-2B0VhGNZUddqwhjRz7Y3aH-2F1iEXujVcSjMM7CY7q30axNIjPtSPwVANtpwkARse71YbTG6hv5YyKcZ3EG9czO3tuqWXIHvFV-2FdtzTRYY9DFBEvbC0MnWDkjPffSjdhbZvMXBG-2Fbl-2F1JQalpy10ZBTpuDmJw8qtDG1RR-2FO-2Bzqy6Ryg-2BIXW6P-2FRmEE7JdIRaCncCouVLTVsWciZPEjkoHD7BDf7qzUctKE-2Fuov9RtCNiCQmJmwXCDa5dDgefQoLRKRDmR4vQ-3D-3DKnfO_4-2BCeSnTfNElQaOz0iIYXcY63TczAP34ghOtoTraLSwoOLAyQYuLOf75Ty99J50dacfCtsIK1GZvxQM45z1qBFZ9wseL0KuFhELugADtC7G-2Bvzzdi1qvZkAsCG7tQfhZagkro3woJV3MTqoQy1rs8sT0Ut5uYpsrniDcVKn6MJEnCWRsblRYyJRkv-2BYtQV-2BKUm1WYOzDqDkYxny3kQFWCbISNT8xpoE2o-2BIn1-2FK5Ue8M-3D
malicious
https://rft.naturdon.com/bcq9PU8gOPhcXwMY3MInh6fvEUmeuYy6piCOF8yFeQiPDLM9K1gBC8tqCxo1E3M7mo5dhDusdL8AxbH85jh54EklZYN7HwkIQvYMfgnz2npRrtDzVuxT18G34BaLy44aLJOl45wa5Pcd670
104.21.20.250
malicious
https://rft.naturdon.com/iVYo/
104.21.20.250
malicious
https://rft.naturdon.com/wx1lfn8lc0EFfs4mS49GKwWjftrdGRsTZrs301Ar5RcEFM7ud9hEuB5NWcqnRab176
104.21.20.250
malicious
https://rft.naturdon.com/klfKSUW4h4SIph0P6yrnQG1Nt2rzThqQo2ba6oKozc4I6AiIoptSSBRYnqI0B77dZSxazhbtWBRab221
104.21.20.250
malicious
https://rft.naturdon.com/uvCrkdS4sVQLblK9iUyXZWTOZI5Dc45gWlMwUwXcVQ5HVhV0E2h4h3gJx71q60gh260
104.21.20.250
malicious
https://rft.naturdon.com/GDSherpa-bold.woff
104.21.20.250
malicious
https://rft.naturdon.com/xymUqoRpqdeAef30
104.21.20.250
malicious
https://rft.naturdon.com/kknyelgqveozzmeznlopjkctpua1vrjcrxr90achqpa38ptbqfm1h?XQTXXGFVVHRYHWWRHYESWOWMAID
malicious
https://rft.naturdon.com/xyosxLBk4yon8qRTsmel9wgW7a2Lt2JU1ZXRfw
104.21.20.250
malicious
https://rft.naturdon.com/GDSherpa-regular.woff2
104.21.20.250
malicious
https://rft.naturdon.com/opkmv1QBWy5HuyxZJI5Cg5CDMC4Bj2jXZcl7dzghirqCw8Vp0H6SYkfkWBBVpcX2ef196
104.21.20.250
malicious
https://rft.naturdon.com/5689EGsgt7WhYocxyMxT56718
104.21.20.250
malicious
https://rft.naturdon.com/GDSherpa-vf2.woff2
104.21.20.250
malicious
https://rft.naturdon.com/taKIYA02gqszDpuhNW5gHAUNgMqo
104.21.20.250
malicious
https://rft.naturdon.com/favicon.ico
104.21.20.250
malicious
https://rft.naturdon.com/opVP3rfXGJ5bZgUzKMghOMzgDiUi9yP8TMZ0NrYAZL67140
104.21.20.250
malicious
https://rft.naturdon.com/ghSXEQ1jgBW3V9P7wMkvy4klITPIyt6UpoJRIqdxbMFS12207
104.21.20.250
malicious
https://rft.naturdon.com/klw0MWVCCCfjzbu3qhSfOHiFVdyzK5NKZ1JyeafAXi3Uv56163
104.21.20.250
malicious
https://rft.naturdon.com/GDSherpa-bold.woff2
104.21.20.250
malicious
https://rft.naturdon.com/GDSherpa-regular.woff
104.21.20.250
malicious
https://rft.naturdon.com/ijHRyxlFrBBK9WsNrsle305J2IEt3f5AIzhQ0XYDQgR9ASa0bhpUWTy1Qpq6NE0TfiRkANAoHaO0ImUi9ROZv0PuACwKjFkEZ7S1UiHoFoVwNvx0ho34zw6o9H8YMwGDT3a8V9Tyz660
104.21.20.250
malicious
https://rft.naturdon.com/wxos0x516c9i2j2vcqm7bsDy0fwzHbSopUF4ljm9RfToW7LRFjix12130
104.21.20.250
malicious
https://rft.naturdon.com/mnNnvbueihu6r9rho0oBMMCuvwTXQG8kyViZolZYXb7n90148
104.21.20.250
malicious
https://rft.naturdon.com/iVYo/#Dbrian.gurbach@texanacenter.com
malicious
https://rft.naturdon.com/op75mQqx1n2Dk3yrHQCNx1pqg7GvFntHLN6ll12AfFPJ5mvcT8IqHATcRSjK27Gmk5jeRX4bkoQvcd237
104.21.20.250
malicious
https://rft.naturdon.com/GDSherpa-vf.woff2
104.21.20.250
malicious
https://cp.edison.tech/api/mailer/m/url?code=c06e5a047f4b46d286ff484bc2602c46&to=https://registrosaraquari.com.br/g63d/686989/Texanacenter/?nl=YnJpYW4uZ3VyYmFjaEB0ZXhhbmFjZW50ZXIuY29t
54.88.141.1
https://ok4static.oktacdn.com/fs/bcg/4/gfsh9pi7jcWKJKMAs1t7
13.33.187.14
https://code.jquery.com/jquery-3.6.0.min.js
151.101.194.137
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
104.17.24.14
https://ok4static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.18.0/css/okta-sign-in.min.css
13.33.187.14
https://9d0wc.jnfemo.ru/pani!a5uhbp
104.21.70.67
https://rodwiy1jurevg6zwutcukkmwcadr7cqmxxcychioypf3tx55yuqbvspm9h.amayaxw.es/527545368042699394148kDaAOIILBdLBNLIALVQSOCFKHCELKKWYWRIGSZEXNNrsz2CiQJLi34FjzXQJpuv40
104.21.49.96
https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback
104.18.95.41
https://a.nel.cloudflare.com/report/v4?s=C70JJCw1mT2aURmz5zQniHTAQ36mtfRx%2Bt%2BWc8vknMxBfXCBR9jvWcPnbO3nz6soPaYvcx6OCNouYx7mOjvpALBibEXSk%2FC0ZrOfH%2FNwDawxi7Czrj%2FLxuOC0ueP
35.190.80.1
https://ok4static.oktacdn.com/assets/loginpage/css/loginpage-theme.e0d37a504604ef874bad26435d62011f.css
13.33.187.14
https://registrosaraquari.com.br/favicon.ico
186.209.113.142
https://registrosaraquari.com.br/0/index.xml?nl=YnJpYW4uZ3VyYmFjaEB0ZXhhbmFjZW50ZXIuY29t
https://a.nel.cloudflare.com/report/v4?s=zlJWWlAJxfgQRzsXrhIAXMacsQvkqtF5Ns3DnawCh21t1wOmr2x%2FK0H82EMB2zKoBH51RZonfT%2BnEW9AdjiniB8qMGM6Kr0SpUiu6Q5LEQ42Qu%2F2EvoupvqkJHDC
35.190.80.1
https://developers.cloudflare.com/favicon.png
104.16.3.189
https://a.nel.cloudflare.com/report/v4?s=7f4OGbVRU%2BKweoJpV8V2zXlRrSkyR95zB8xwYeGc3ToMzftQfpnE31WE6h%2BCpJgfpy1mmCK42WgTIlkJtIyXDv4sdwuGAupwLTYWdlNuH8vJg4IEJA2D9Yez%2FR4%2F
35.190.80.1
https://challenges.cloudflare.com/turnstile/v0/g/f3b948d8acb8/api.js
104.18.95.41
https://registrosaraquari.com.br/g63d/686989/Texanacenter/?nl=YnJpYW4uZ3VyYmFjaEB0ZXhhbmFjZW50ZXIuY29t
186.209.113.142
https://registrosaraquari.com.br/0/index.xslt
186.209.113.142
https://get.geojs.io/v1/ip/geo.json
172.67.70.233
There are 35 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
rft.naturdon.com
104.21.20.250
malicious
a.nel.cloudflare.com
35.190.80.1
developers.cloudflare.com
104.16.3.189
github.com
140.82.121.3
u17065553.ct.sendgrid.net
167.89.123.53
9d0wc.jnfemo.ru
104.21.70.67
rodwiy1jurevg6zwutcukkmwcadr7cqmxxcychioypf3tx55yuqbvspm9h.amayaxw.es
104.21.49.96
code.jquery.com
151.101.194.137
cp.edison.tech
54.88.141.1
cdnjs.cloudflare.com
104.17.24.14
challenges.cloudflare.com
104.18.95.41
get.geojs.io
172.67.70.233
www.google.com
172.217.18.4
d19d360lklgih4.cloudfront.net
13.33.187.14
registrosaraquari.com.br
186.209.113.142
objects.githubusercontent.com
185.199.108.133
ok4static.oktacdn.com
unknown
There are 7 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.20.250
rft.naturdon.com
United States
malicious
172.217.18.14
unknown
United States
13.33.187.14
d19d360lklgih4.cloudfront.net
United States
216.58.206.78
unknown
United States
192.168.2.16
unknown
unknown
54.88.141.1
cp.edison.tech
United States
104.21.49.96
rodwiy1jurevg6zwutcukkmwcadr7cqmxxcychioypf3tx55yuqbvspm9h.amayaxw.es
United States
172.67.220.176
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
151.101.194.137
code.jquery.com
United States
172.217.18.10
unknown
United States
104.16.2.189
unknown
United States
104.17.24.14
cdnjs.cloudflare.com
United States
142.250.186.78
unknown
United States
142.250.110.84
unknown
United States
104.16.3.189
developers.cloudflare.com
United States
104.21.70.67
9d0wc.jnfemo.ru
United States
1.1.1.1
unknown
Australia
142.250.186.163
unknown
United States
172.217.18.4
www.google.com
United States
186.209.113.142
registrosaraquari.com.br
Brazil
140.82.121.3
github.com
United States
104.18.95.41
challenges.cloudflare.com
United States
13.33.187.96
unknown
United States
172.67.70.233
get.geojs.io
United States
185.199.108.133
objects.githubusercontent.com
Netherlands
142.250.72.99
unknown
United States
167.89.123.53
u17065553.ct.sendgrid.net
United States
216.58.212.163
unknown
United States
104.26.0.100
unknown
United States
There are 20 hidden IPs, click here to show them.