IOC Report
https://u17065553.ct.sendgrid.net/ls/click?upn=u001.Rw-2FXpvWBRDxNoiEvv-2B0VhMl349dE-2BIxYKCLpL5-2B-2FL8px39hmRTYxAZ-2BeMH1CR7jYvsg3f7mQR-2BtgzEdpv6rWDyoEa1Isq60WafIaat9IMqfozrbRuGiDhSD5zRfw1vSUnaPfHOkeKVWyjmgPghsIl-2FnSiz3vjd-2BgNdZNW1WWi7RlhTni8jQbV4O1UkQOa0-2F2VYGlXOPUclqMwRi50Vl1PR4j2jhVrjOnUdA6

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
Web Open Font Format, TrueType, length 35970, version 1.0
downloaded
Chrome Cache Entry: 101
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 102
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 103
Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (10017)
downloaded
Chrome Cache Entry: 105
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 106
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 107
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 108
PNG image data, 420 x 94, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 109
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 350x88, components 3
dropped
Chrome Cache Entry: 110
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 111
Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
downloaded
Chrome Cache Entry: 112
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 113
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 114
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 115
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 116
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 117
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 118
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 119
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 120
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 121
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 122
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1920x1080, components 3
downloaded
Chrome Cache Entry: 123
Unicode text, UTF-8 text, with very long lines (21720), with CRLF line terminators
downloaded
Chrome Cache Entry: 124
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 125
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 126
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 72
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 73
PNG image data, 420 x 94, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 74
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 75
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1920x1080, components 3
dropped
Chrome Cache Entry: 76
ASCII text, with very long lines (48238)
downloaded
Chrome Cache Entry: 77
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 78
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, baseline, precision 8, 350x88, components 3
downloaded
Chrome Cache Entry: 79
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 80
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 81
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 82
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 83
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (51734)
downloaded
Chrome Cache Entry: 85
very short file (no magic)
dropped
Chrome Cache Entry: 86
Web Open Font Format, TrueType, length 36696, version 1.0
downloaded
Chrome Cache Entry: 87
HTML document, ASCII text, with very long lines (52009), with CRLF line terminators
downloaded
Chrome Cache Entry: 88
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 89
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 90
ASCII text, with very long lines (48316), with no line terminators
downloaded
Chrome Cache Entry: 91
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 92
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (26765), with no line terminators
downloaded
Chrome Cache Entry: 94
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 95
very short file (no magic)
downloaded
Chrome Cache Entry: 96
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 97
HTML document, ASCII text, with very long lines (17925), with CRLF line terminators
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (10450)
downloaded
Chrome Cache Entry: 99
RIFF (little-endian) data, Web/P image
downloaded
There are 46 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2200,i,17724770803338348954,5673265326058284753,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2304 /prefetch:3
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u17065553.ct.sendgrid.net/ls/click?upn=u001.Rw-2FXpvWBRDxNoiEvv-2B0VhMl349dE-2BIxYKCLpL5-2B-2FL8px39hmRTYxAZ-2BeMH1CR7jYvsg3f7mQR-2BtgzEdpv6rWDyoEa1Isq60WafIaat9IMqfozrbRuGiDhSD5zRfw1vSUnaPfHOkeKVWyjmgPghsIl-2FnSiz3vjd-2BgNdZNW1WWi7RlhTni8jQbV4O1UkQOa0-2F2VYGlXOPUclqMwRi50Vl1PR4j2jhVrjOnUdA6E03jJF3YxTMCgxElFH-2Bjnu2oS6ZdGJGXf9TKr37Eh3pnVym0G5ilxnSN6bJyz-2FWbi47cL6vQDH-2FLX6HDdsxLQr4OiWNyplfwZIjGldJH3Oj3k-2B0Sr92pyHOs07I3QG9CN9BFC52s0blv8XoiBzACqb7MDZTgdhgx-2Fj3fdHjRUqn0E0aUxawEH-2F-2B7SQiAWk4bi4jHEXI-3DlKA5_AMa9RrBWZfrIG11ZEW0ArF1BRI9e8rcrPZr5T9DlZ7Ba2ZAvuJPwiS8cX4aFrXjFerUDwGcfFdNk6Ly7G30W-2FpJZ3vwwQM6aCBocvejnros7-2FYckwVQH02a6C13hCOZXCH6DxRozn9HOBenC-2BdqPCIwBV1vvkSKYyJjB4wo2MVyi5b4Ko6F9xhTiwowhGgTSo1JEnvhUu4BAFpCuBdmsFw-3D-3D"

URLs

Name
IP
Malicious
https://u17065553.ct.sendgrid.net/ls/click?upn=u001.Rw-2FXpvWBRDxNoiEvv-2B0VhMl349dE-2BIxYKCLpL5-2B-2FL8px39hmRTYxAZ-2BeMH1CR7jYvsg3f7mQR-2BtgzEdpv6rWDyoEa1Isq60WafIaat9IMqfozrbRuGiDhSD5zRfw1vSUnaPfHOkeKVWyjmgPghsIl-2FnSiz3vjd-2BgNdZNW1WWi7RlhTni8jQbV4O1UkQOa0-2F2VYGlXOPUclqMwRi50Vl1PR4j2jhVrjOnUdA6E03jJF3YxTMCgxElFH-2Bjnu2oS6ZdGJGXf9TKr37Eh3pnVym0G5ilxnSN6bJyz-2FWbi47cL6vQDH-2FLX6HDdsxLQr4OiWNyplfwZIjGldJH3Oj3k-2B0Sr92pyHOs07I3QG9CN9BFC52s0blv8XoiBzACqb7MDZTgdhgx-2Fj3fdHjRUqn0E0aUxawEH-2F-2B7SQiAWk4bi4jHEXI-3DlKA5_AMa9RrBWZfrIG11ZEW0ArF1BRI9e8rcrPZr5T9DlZ7Ba2ZAvuJPwiS8cX4aFrXjFerUDwGcfFdNk6Ly7G30W-2FpJZ3vwwQM6aCBocvejnros7-2FYckwVQH02a6C13hCOZXCH6DxRozn9HOBenC-2BdqPCIwBV1vvkSKYyJjB4wo2MVyi5b4Ko6F9xhTiwowhGgTSo1JEnvhUu4BAFpCuBdmsFw-3D-3D
malicious
https://rft.naturdon.com/xyyV1ZiqNXRC8zWXcIUDTUea88bP6rhTuulsSZCyRMCDOqwZZUjy
104.21.20.250
malicious
https://rft.naturdon.com/LFDIOVBACHUVLUMXWJMZZABIlktsueapchiibtoelfaoxbibelpkiiruq3hyt0s7ajwv4pmysqg1cwnj?LPJSZHQGFSSFRQTYJOJFCDJWWCYC
malicious
https://rft.naturdon.com/iVYo/
104.21.20.250
malicious
https://rft.naturdon.com/wxR15iAruHCp5MR53stdlsbAewGX1FsavzlKmlR34130
104.21.20.250
https://ok4static.oktacdn.com/fs/bcg/4/gfsh9pi7jcWKJKMAs1t7
13.33.187.96
https://aadcdn.msauthimages.net/dbd5a2dd-vmlo2cc2etebjdqhg-ytquz7jjmmuxj8qlopjyoab6y/logintenantbranding/0/illustration?ts=637920231785000429
92.123.12.181
https://code.jquery.com/jquery-3.6.0.min.js
151.101.2.137
https://rft.naturdon.com/GDSherpa-bold.woff
104.21.20.250
https://www.amazon.com
unknown
https://2aezx.szsnqp.ru/loray!m1hxo77
188.114.97.3
https://a.nel.cloudflare.com/report/v4?s=Qy3fa0ucgWYBvfzYV4smuYEaxjTnJOacrcbwajYJvX320ewuMZa4t0N29Q%2BF3OuW60kNEU5p63WcrlIcrVUtERXKZLESMDoDkq1mpEpFPA8f31BHPbIkA6sXR9UL
35.190.80.1
https://d2fykjvf206smvkvkvv0u6jhkusv7w0lybl1wipgnt1qufyffe.sorenxw.es/bChJbJByRMoiWVIzJsvbypYtqUVUTWUTXNFKJKJACAZSJESGCWVJJAOEENGZXBFSRWIWRBRMCVRFSKyzUgP6dnOJOXM56dsnqr50
104.21.96.1
https://rft.naturdon.com/xyR81473VsYaArsvHmgh24
104.21.20.250
https://registrosaraquari.com.br/g63f/614583/Pierceatwood/?nl=ZGNhYnJhbEBwaWVyY2VhdHdvb2QuY29t
186.209.113.142
https://app.salesforceiq.com/r?target=603feeba78af1c08f5743ad0&t=AFwhZf0amBvhYfM9RctKtaa9k2LfIrNDSUS7iRYke1td_G46ivu2nAbPY5ST0sm4YvyV9nje6hJ_AkhaGAB2Q-VekJszZwpRHWS5Qxj8Pkn-XA_5zkvZHw1vuXoxIMX7IYPI_hkyjtNB&url=https://registrosaraquari.com.br/g63f/614583/Pierceatwood/?nl=ZGNhYnJhbEBwaWVyY2VhdHdvb2QuY29t
44.226.80.26
https://ok4static.oktacdn.com/assets/loginpage/css/loginpage-theme.e0d37a504604ef874bad26435d62011f.css
13.33.187.96
https://registrosaraquari.com.br/favicon.ico
186.209.113.142
https://rft.naturdon.com/yp9BZPnLvX9qppjZ6vwVf7ZEopBEJOVpdL8dvd
104.21.20.250
https://github.com/fent)
unknown
https://registrosaraquari.com.br/0/index.xml?nl=ZGNhYnJhbEBwaWVyY2VhdHdvb2QuY29t
https://rft.naturdon.com/GDSherpa-bold.woff2
104.21.20.250
https://challenges.cloudflare.com/turnstile/v0/g/f3b948d8acb8/api.js
104.18.94.41
https://rft.naturdon.com/ijQ0IOXUR1aIdE2dIax8V9VT5mgSv8B3wxiSY8D4KNzfk5az6fKC4B8vvw56170
104.21.20.250
https://rft.naturdon.com/klZUXgOlh2u3Z2ys2P7suUE8OPsvE6D0NZcY24FlEVoyLh1rlCu0zJMqOpqgPM0t8xKY93rEWKezYEZUkbXH3MBDHfCQeW7aWFIDvpz4vU3PIiYP2CoSTMqCoZvmlMmOzASNryz660
104.21.20.250
https://registrosaraquari.com.br/0/index.xslt
186.209.113.142
https://rft.naturdon.com/rsj9FvgfYrm0DCkU7R3E0ZVRtwZjLNORj7eVq7ghG3bg6DT6IOZl4JRef193
104.21.20.250
https://rft.naturdon.com/dezNUCB7F1KEsi0FN0wryA8y4av4n6Oz1WzLtiMGksrOn987oMYSmcxxtWYou2jfcMbVvmkb60VdA3wr1dwZEXuZoYuejWksgw45j3q4VZxbXQF10CkWdNYZxh3MHx6WHC7lGtJJ6scfMTtvSsNFNJCw93uLSr83gx6zpijd2MxlyhgcWIfR6tYb2L6cd662
104.21.20.250
https://d2fykjvf206smvkvkvv0u6jhkusv7w0lybl1wipgnt1qufyffe.sorenxw.es/bChJbJByRMoiWVIzJsvbypYtqUVUTWUTXNFKJKJACAZSJESGCWVJJAOEENGZXBFSRWIWRBRMCVRFSK12AAuQJBSo78Umueop42
104.21.96.1
https://rft.naturdon.com/34ljcaLCdgnxyAWwV8920
104.21.20.250
https://rft.naturdon.com/uvJtmTGXX2g3FEEqQIMgBrLoxZ456mS64jlG3A6l7y7Lxkm6YTIoOlgS7jv42MEgh260
104.21.20.250
https://aadcdn.msauthimages.net/dbd5a2dd-vmlo2cc2etebjdqhg-ytquz7jjmmuxj8qlopjyoab6y/logintenantbranding/0/bannerlogo?ts=637919603932887433
92.123.12.181
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.1.1/crypto-js.min.js
104.17.25.14
https://ok4static.oktacdn.com/assets/js/sdk/okta-signin-widget/7.18.0/css/okta-sign-in.min.css
13.33.187.96
https://rft.naturdon.com/GDSherpa-regular.woff2
104.21.20.250
https://RFT.naturdon.com/iVYo/#D
unknown
https://challenges.cloudflare.com/turnstile/v0/api.js?onload=onloadTurnstileCallback
104.18.94.41
https://rft.naturdon.com/GDSherpa-vf2.woff2
104.21.20.250
https://rft.naturdon.com/rvBXzyX4Qq50i8TvtNXs8BpqNqxHqx6mzSSKcXalR4B6PLT8k9y
104.21.20.250
https://rft.naturdon.com/56ybTuSQ1jJ6y8kcSz0CgEs2AYKij17gyitf7LX4hemrK89103
104.21.20.250
https://rft.naturdon.com/favicon.ico
104.21.20.250
https://developers.cloudflare.com/favicon.png
104.16.2.189
https://rft.naturdon.com/GDSherpa-regular.woff
104.21.20.250
https://rft.naturdon.com/iVYo/#Ddcabral@pierceatwood.com
https://rft.naturdon.com/klVMx7KVI7aqSsO73T4YmMDJiwpgOXnjl0kvOhd3fZAopRdu3RNdl8MlVtw7oEWHHR2t8JGp85UDgXLK6yz230
104.21.20.250
https://rft.naturdon.com/optadu1ofPxrFCa4cOe9bGejoa2vR7hUGzGuvm86IppsV4y85FAZpZxeuef235
104.21.20.250
https://get.geojs.io/v1/ip/geo.json
172.67.70.233
https://rft.naturdon.com/efueBIf7KMBbXW0qQF2zeji3jy0JijcyRqJUUwcvNTCnOUKvkR78143
104.21.20.250
https://rft.naturdon.com/yzUMXXAK9cdiVG7unTSOjXlhW72wM8rZJ7uRvQrQmnp9mH4LntaZDifn490180
104.21.20.250
https://rft.naturdon.com/ijrlV3hi6dkeYhbR0U6WhmmiYz2MGccNsZegAMCklGrcaCM65n1iEmiCkEsATX4zN3WzSG5I12210
104.21.20.250
https://d2fykjvf206smvkvkvv0u6jhkusv7w0lybl1wipgnt1qufyffe.sorenxw.es/bChJbJByRMoiWVIzJsvbypYtqUVUTWUTXNFKJKJACAZSJESGCWVJJAOEENGZXBFSRWIWRBRMCVRFSKpqYiU5PkU4ch34fiS6guv40
104.21.96.1
https://rft.naturdon.com/qrhmLtoaKGMi81xl8TzghJ99XVgOdtJgIR4uW45140
104.21.20.250
https://rft.naturdon.com/GDSherpa-vf.woff2
104.21.20.250
There are 42 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
e329293.dscd.akamaiedge.net
92.123.12.181
developers.cloudflare.com
104.16.2.189
d2fykjvf206smvkvkvv0u6jhkusv7w0lybl1wipgnt1qufyffe.sorenxw.es
104.21.96.1
github.com
140.82.121.4
2aezx.szsnqp.ru
188.114.97.3
u17065553.ct.sendgrid.net
167.89.123.122
code.jquery.com
151.101.2.137
cdnjs.cloudflare.com
104.17.25.14
challenges.cloudflare.com
104.18.94.41
get.geojs.io
172.67.70.233
www.google.com
142.250.184.228
d19d360lklgih4.cloudfront.net
13.33.187.96
registrosaraquari.com.br
186.209.113.142
rft.naturdon.com
104.21.20.250
objects.githubusercontent.com
185.199.108.133
apiq-apiv1-06027f9a-pb-48692342.us-west-2.elb.amazonaws.com
44.226.80.26
app.salesforceiq.com
unknown
aadcdn.msauthimages.net
unknown
ok4static.oktacdn.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.18.94.41
challenges.cloudflare.com
United States
13.33.187.14
unknown
United States
192.168.2.16
unknown
unknown
172.67.195.46
unknown
United States
104.16.5.189
unknown
United States
192.168.2.4
unknown
unknown
104.21.80.1
unknown
United States
104.21.96.1
d2fykjvf206smvkvkvv0u6jhkusv7w0lybl1wipgnt1qufyffe.sorenxw.es
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.184.228
www.google.com
United States
44.226.80.26
apiq-apiv1-06027f9a-pb-48692342.us-west-2.elb.amazonaws.com
United States
104.16.2.189
developers.cloudflare.com
United States
104.21.20.250
rft.naturdon.com
United States
92.123.12.181
e329293.dscd.akamaiedge.net
European Union
167.89.123.122
u17065553.ct.sendgrid.net
United States
2.19.96.123
unknown
European Union
186.209.113.142
registrosaraquari.com.br
Brazil
140.82.121.4
github.com
United States
151.101.2.137
code.jquery.com
United States
188.114.97.3
2aezx.szsnqp.ru
European Union
13.33.187.96
d19d360lklgih4.cloudfront.net
United States
188.114.96.3
unknown
European Union
172.67.70.233
get.geojs.io
United States
185.199.108.133
objects.githubusercontent.com
Netherlands
104.17.25.14
cdnjs.cloudflare.com
United States
104.26.0.100
unknown
United States
There are 16 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://rft.naturdon.com/iVYo/#Ddcabral@pierceatwood.com
malicious
https://rft.naturdon.com/iVYo/#Ddcabral@pierceatwood.com
malicious
https://rft.naturdon.com/LFDIOVBACHUVLUMXWJMZZABIlktsueapchiibtoelfaoxbibelpkiiruq3hyt0s7ajwv4pmysqg1cwnj?LPJSZHQGFSSFRQTYJOJFCDJWWCYC
malicious
https://rft.naturdon.com/LFDIOVBACHUVLUMXWJMZZABIlktsueapchiibtoelfaoxbibelpkiiruq3hyt0s7ajwv4pmysqg1cwnj?LPJSZHQGFSSFRQTYJOJFCDJWWCYC
malicious
https://rft.naturdon.com/LFDIOVBACHUVLUMXWJMZZABIlktsueapchiibtoelfaoxbibelpkiiruq3hyt0s7ajwv4pmysqg1cwnj?LPJSZHQGFSSFRQTYJOJFCDJWWCYC
malicious
https://rft.naturdon.com/LFDIOVBACHUVLUMXWJMZZABIlktsueapchiibtoelfaoxbibelpkiiruq3hyt0s7ajwv4pmysqg1cwnj?LPJSZHQGFSSFRQTYJOJFCDJWWCYC
malicious
https://registrosaraquari.com.br/0/index.xml?nl=ZGNhYnJhbEBwaWVyY2VhdHdvb2QuY29t
https://rft.naturdon.com/iVYo/#Ddcabral@pierceatwood.com