IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://archchicago.us7.list-manage.com/track/click?u=32277848bb5b49b8121a67d14&id=54644935c5&e=e7e099342b#Florence.Narine@agf.com
URL
initial url
malicious
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\^%25#&#YTJTERTREJHJHEG#^&%25&#^(#^(#&(#^&#^#%25O(#&)(&##&([1].htm
HTML document, ASCII text, with very long lines, with CRLF line terminators
downloaded
malicious
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{42C4481A-6123-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{42C4481C-6123-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{4A79DAA2-6123-11EB-90E5-ECF4BB2D2496}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\wlm7n14\imagestore.dat
data
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\aad.login.min_c38fti7z7e0m2csp02b-sa2[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\http_403[1]
HTML document, UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\info_48[1]
PNG image data, 47 x 48, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\microsoft_logo[1].png
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\microsoft_logo_ee5c8d9fb6248c938fd0dc19370e90bd[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\suspendedpage[1].htm
HTML document, ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3Y2ADQKS\waiting[1].gif
GIF image data, version 89a, 256 x 256
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\0-small_138bcee624fa04ef9b75e86211a9fe0d[1].jpg
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 50x28, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\all[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410[1].svg
SVG Scalable Vector Graphics image
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\background_gradient[1]
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 1x800, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\converged.v2.login.min_rayhgcterrtxpnvapp3erg2[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\httpErrorPagesScripts[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\jquery.1.11.min_tu0oeunbyls-a4imj8e0xq2[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\jquery.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9QTQHWWN\logout[1].htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\0_a5dbd4393ff6a725c7e62b61df7e72f0[1].jpg
JPEG image data, baseline, precision 8, 1920x1080, frames 3
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\ErrorPageTemplate[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\bootstrap.min[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\bullet[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\favicon_a_eupayfgghqiai7k9sol6lg2[1].ico
MS Windows icon resource - 6 icons, 128x128, 16 colors, 72x72, 16 colors
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\personal_account_0f72b5950600f24e7f9a604b186f3945[1].png
PNG image data, 51 x 51, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\G62TDH9B\work_account_1963c6b1926b773986f53f844ce4c32e[1].png
PNG image data, 51 x 51, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\bootstrap.bundle.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\bootstrap.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\bootstrap.min[2].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\down[1]
PNG image data, 15 x 15, 8-bit colormap, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\errorPageStrings[1]
UTF-8 Unicode (with BOM) text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\jquery.min[1].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OTUW0Q90\jquery.min[2].js
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DFBB373337C695D0BC.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFBE004E96809C3348.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFFC78C53105AF8248.TMP
data
dropped
clean
There are 29 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:4872 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.js
unknown
clean
https://fra1.digitaloceanspaces.com/newonenow/
clean
https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/jquery.1.11.min_tu0oeunbyls-a4imj8e0xq2.js
unknown
clean
https://fra1.digitaloc
unknown
clean
https://aadcdn.msauth.net/ests/2.1/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
unknown
clean
http://fwdssp.com/?dn=referer_detect&pid=5POL4F2O4
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.css
unknown
clean
https://aadcdn.msauth.net/ests/2.1/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico~(
unknown
clean
https://aadcdn.msftauth.net/shared/1.0/content/images/personal_account_0f72b5950600f24e7f9a604b186f3
unknown
clean
https://aadcdn.msftauth.net/shared/1.0/content/images/work_account_1963c6b1926b773986f53f844ce4c32e.
unknown
clean
https://aadcdn.msftauth.net/ests/2.1/content/images/microsoft_logo.png
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
unknown
clean
https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/aad.login.min_c38fti7z7e0m2csp02b-sa2.js
unknown
clean
https://fra1.digitaloceanspaces.com/newonenow/%5E%25%23%26%23YTJTERTREJHJHEG%23%5E%26%25%26%23%5E%28
unknown
clean
https://fra1.digitaloceanspaces.com/newonenow/E%25%23%26%23YTJTERTREJHJHEG%23%5E%26%25%26%23%5E%28%2
unknown
clean
https://github.com/douglascrockford/JSON-js
unknown
clean
https://getbootstrap.com/)
unknown
clean
https://dancevida.com/css/app.css
unknown
clean
https://fontawesome.com/license/free
unknown
clean
http://gsgd.co.uk/sandbox/jquery/easing/
unknown
clean
https://sms.baptemedelair.fr/vendor/todayzoo.php
unknown
clean
https://sustainableinfrastructure.org/wp-content/themes/isi-child/images/waiting.gif
unknown
clean
https://fontawesome.com
unknown
clean
https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/0-small_138bcee624fa04ef9b75e86211
unknown
clean
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
clean
https://aadcdn.msauth.net/ests/2.1/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico~
unknown
clean
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.bundle.min.js
unknown
clean
https://aadcdn.msauth.net/ests/2.1/content/images/arrow_left_a9cc2824ef3517b6c4160dcf8ff7d410.svg
unknown
clean
https://logincdn.msauth.net/16.000.28543.10/content/images/microsoft_logo_ee5c8d9fb6248c938fd0dc1937
unknown
clean
https://use.fontawesome.com/releases/v5.6.1/css/all.css
unknown
clean
https://logincdn.msauth.net/16.000.28543.10/content/images/backgrounds/0_a5dbd4393ff6a725c7e62b61df7
unknown
clean
https://fra1.digitaloceanspaces.com/newonenow/%5E%25%23%26%23YTJTERTREJHJHEG%23%5E%26%25%26%23%5E%28%23%5E%28%23%26%28%23%5E%26%23%5E%23%25O%28%23%26%29%28%26%23%23%26%28.html#Florence.Narine@agf.com
clean
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
clean
https://login.microsoftonline.com/logout.srf?ct=1548343592&rver=64.4.6456.0&lc=1033&id=501392
unknown
clean
https://fra1.digitaloceanspaces.com/newonenow/%5E%25%23%26%23YTJTERTREJHJHEG%23%5E%26%25%26%23%5E%28%23%5E%28%23%26%28%23%5E%26%23%5E%23%25O%28%23%26%29%28%26%23%23%26%28.html#
clean
https://aadcdn.msftauth.net
unknown
clean
https://aadcdn.msftauth.net/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
unknown
clean
https://aadcdn.msftauth.net/shared/1.0/content/images/backgrounds/0_a5dbd4393ff6a725c7e62b61df7e72f0
unknown
clean
https://www.orka.mk/consdidews32ewdsering/pdansdidewsd32waedsrish?ct=t(Parish_Food_Pantry_1_26_2021_
unknown
clean
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.3.1/jquery.min.js
unknown
clean
https://fra1.digitalocnsdidews32ewdsering/pdansdidewsd32waedsrish?ct=t(Parish_Food_Pantry_1_26_2021_
unknown
clean
There are 31 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
dancevida.com
50.87.150.0
clean
cs1100.wpc.omegacdn.net
152.199.23.37
clean
fra1.digitaloceanspaces.com
5.101.109.44
clean
sustainableinfrastructure.org
3.218.111.133
clean
cdnjs.cloudflare.com
104.16.19.94
clean
fontawesome-cdn.fonticons.netdna-cdn.com
23.111.9.35
clean
cs1227.wpc.alphacdn.net
192.229.221.185
clean
orka.mk
23.227.133.50
clean
stackpath.bootstrapcdn.com
unknown
clean
logincdn.msauth.net
unknown
clean
aadcdn.msftauth.net
unknown
clean
aadcdn.msauth.net
unknown
clean
use.fontawesome.com
unknown
clean
www.orka.mk
unknown
clean
archchicago.us7.list-manage.com
unknown
clean
login.microsoftonline.com
unknown
clean
cdn.onenote.net
unknown
clean
There are 7 hidden domains, click here to show them.

IPs

IP
Domain
Country
Active
Malicious
3.218.111.133
unknown
United States
unknown
clean
23.111.9.35
unknown
United States
unknown
clean
192.168.2.1
unknown
unknown
unknown
clean
23.227.133.50
unknown
United States
unknown
clean
192.229.221.185
unknown
United States
unknown
clean
152.199.23.37
unknown
United States
unknown
clean
5.101.109.44
unknown
Netherlands
unknown
clean
50.87.150.0
unknown
United States
unknown
clean
104.16.19.94
unknown
United States
unknown
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{42C4481A-6123-11EB-90E5-ECF4BB2D2496}
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-912
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-904
clean
There are 15 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
7FF5C6146000
unkown
page readonly
clean
1D252F48000
heap default
page read and write
clean
1D252D80000
unkown
page readonly
clean
1D254BF0000
heap private
page read and write
clean
27BF77E000
unkown
page read and write
clean
7FF5C6907000
unkown
page readonly
clean
7FF5C6516000
unkown
page readonly
clean
7FF5C68A7000
unkown
page readonly
clean
7FF5C6917000
unkown
page readonly
clean
1D2548B0000
unkown
page readonly
clean
7FF5C692A000
unkown
page readonly
clean
1D254CEF000
heap private
page read and write
clean
1D2533D0000
unkown
page readonly
clean
7FF5C6957000
unkown
page readonly
clean
1D2548C0000
unkown
page readonly
clean
7FF5C6957000
unkown
page readonly
clean
1D252F20000
heap private
page read and write
clean
1D2549F0000
heap private
page read and write
clean
7FF5C6896000
unkown
page readonly
clean
7FF5C67F7000
unkown
page readonly
clean
7FF5C68AE000
unkown
page readonly
clean
1D252F40000
heap default
page read and write
clean
7FF5C6657000
unkown
page readonly
clean
7FF5C6914000
unkown
page readonly
clean
7FF5C68B4000
unkown
page readonly
clean
27BF57E000
unkown
page read and write
clean
27BF67C000
unkown
page read and write
clean
7FF5C6901000
unkown
page readonly
clean
7FF5C67FB000
unkown
page readonly
clean
7FF5C684F000
unkown
page readonly
clean
27BF5FD000
unkown
page read and write
clean
1D252F7D000
heap default
page read and write
clean
1D2547E0000
unkown
page readonly
clean
1D253040000
unkown
page readonly
clean
7FF5C65C6000
unkown
page readonly
clean
27BF6FE000
unkown
page read and write
clean
1D252EF0000
unkown
page readonly
clean
7FF5C689D000
unkown
page readonly
clean
7FF5C6535000
unkown
page readonly
clean
7FF5C6876000
unkown
page readonly
clean
7FF5C68A9000
unkown
page readonly
clean
7FF5C6946000
unkown
page readonly
clean
7FF5C653E000
unkown
page readonly
clean
1D252ED0000
unkown
page read and write
clean
7FF5C691B000
unkown
page readonly
clean
7FF5C6851000
unkown
page readonly
clean
7FF5C6943000
unkown
page readonly
clean
1D252F82000
heap default
page read and write
clean
7FF5C6904000
unkown
page readonly
clean
7FF5C687A000
unkown
page readonly
clean
7FF5C6882000
unkown
page readonly
clean
1D252DE0000
unkown
page readonly
clean
7FF5C690D000
unkown
page readonly
clean
7FF5C6952000
unkown
page readonly
clean
1D2548D0000
unkown
page readonly
clean
1D252EB0000
unkown
page read and write
clean
1D254910000
heap private
page read and write
clean
1D252F00000
unkown
page readonly
clean
7FF5C6801000
unkown
page readonly
clean
27BF4FE000
unkown
page read and write
clean
7FF5C6863000
unkown
page readonly
clean
1D252F25000
heap private
page read and write
clean
27BF47C000
unkown
page read and write
clean
1D254EC0000
heap private
page read and write
clean
There are 54 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://fra1.digitaloceanspaces.com/newonenow/%5E%25%23%26%23YTJTERTREJHJHEG%23%5E%26%25%26%23%5E%28%23%5E%28%23%26%28%23%5E%26%23%5E%23%25O%28%23%26%29%28%26%23%23%26%28.html#
malicious
https://fra1.digitaloceanspaces.com/newonenow/%5E%25%23%26%23YTJTERTREJHJHEG%23%5E%26%25%26%23%5E%28%23%5E%28%23%26%28%23%5E%26%23%5E%23%25O%28%23%26%29%28%26%23%23%26%28.html#Florence.Narine@agf.com
malicious
https://fra1.digitaloceanspaces.com/newonenow/
clean