IOCReport

loading gif

Files

File Path
Type
Category
Malicious
https://covid19.protected-forms.com/XWkZKNVRYQmFTVmxrVkRoek9VTkdXRzVHWjNBM2RtMDBRMlptZVRkdGNFUjFZekV6ZWxkblJEZzFiMlZCTWxoTlVXaG5aMHRoYW1kc09VSnlja2xZYkc5MlYwdzNOWFpsVERWNUsxWXZiVkJ5YURreFUzTk9kbGt4ZWtoSGRYa3dTM1ppY1hkT0x6Y3pSMFJXVjNsMWRXNVRiRnBCZURZMGJVWkNlRlJ0TVdGM1REZEhNRnA0ZW5keksyTmFZV2hPWVRGd1Z6Tm9iRFVyVlhnd1UwdHhOVkU0YTJsRGRXMDBjMlZOUFMwdGVsSnhlVlJOWkZKRlNIVjZZbEpUYkVscGJUQTJaejA5LS0yNjI0MmEyNmU5MTE4NzY5Nzk4YzQ5Nzk4MGQyMGYxNmNiYmE1MGQy?cid=874637403
URL
initial url
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\DOMStore\E5F0NRSV\secured-login[1].xml
ASCII text, with no line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0B1EB684-C85C-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0B1EB686-C85C-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{1283C016-C85C-11EB-90EB-ECF4BBEA1588}.dat
Microsoft Word Document
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-17529550060\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-18270793970\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-21706820\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-4759708130\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-6757900\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-8760897390\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20259167780\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin20332743330\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin8215062560\msapplication.xml
XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
dropped
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\IU9ESTP0.htm
HTML document, ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\KB4-logo[1].png
PNG image data, 200 x 75, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\application-90929fee9f5daac0eca637129a780171565a15cebe060e2d86c95ffac685fd7b[1].js
UTF-8 Unicode text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\landing-watermark-8487e36eef1bec74f06631f19fea0aa171c208e2976373cda5bd0a4b9e230903[1].css
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\modernizr-79e0181ec91aff04bb01d87cba546535ede843f75d19f5c60f66b8dd6546971f[1].js
HTML document, ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\2WF3MMUU\vendor-f9f57d7be17e331a1955[1].js
ASCII text, with very long lines, with no line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\css2[1].css
ASCII text
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\9026IKNJ\dd[1].css
UTF-8 Unicode text, with CRLF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\QRF01zv[1].png
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\CS6IXJW6\mem8YaGs126MiZpBA-U1UQ[1].woff
Web Open Font Format, TrueType, length 55324, version 1.1
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\6F17TJ3O.htm
HTML document, UTF-8 Unicode text, with very long lines, with CRLF, LF line terminators
downloaded
clean
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\OR0WKIO1\bootstrap.min[1].css
ASCII text, with very long lines
downloaded
clean
C:\Users\user\AppData\Local\Temp\~DF820E21105090C19F.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFB81FC44A4392FBBB.TMP
data
dropped
clean
C:\Users\user\AppData\Local\Temp\~DFD3A635E75702A4C0.TMP
data
dropped
clean
There are 19 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\internet explorer\iexplore.exe
'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5852 CREDAT:17410 /prefetch:2
clean

URLs

Name
IP
Malicious
https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/css/bootstrap.min.css
unknown
clean
http://api.jqueryui.com/slide-effect/
unknown
clean
https://github.com/moment/moment/issues/1423
unknown
clean
https://github.com/chartjs/Chart.js/pull/4507
unknown
clean
https://covid19.protected-forms.com/XWkZKNVRYQmFTVmxrVkRoek9VTkdXRzVHWjNBM2RtMDBRMlptZVRkdGNFUjFZekV
unknown
clean
http://stackoverflow.com/a/32954565/96342
unknown
clean
https://github.com/madrobby/zepto/blob/master/src/zepto.js
unknown
clean
https://stackoverflow.com/questions/30464750/chartjs-line-chart-set-background-color
unknown
clean
https://github.com/chartjs/Chart.js/issues/5597
unknown
clean
http://stackoverflow.com/a/26707753
unknown
clean
https://github.com/jquery/jquery-color
unknown
clean
https://github.com/select2/select2/blob/master/LICENSE.md
unknown
clean
http://api.jqueryui.com/jQuery.widget/
unknown
clean
http://blog.jquery.com/2012/08/09/jquery-1-8-released/
unknown
clean
http://codereview.stackexchange.com/q/13338
unknown
clean
https://cdn2.hubspot.net/hubfs/241394/html_file/files/img/KB4-logo.png
unknown
clean
https://bugzilla.mozilla.org/show_bug.cgi?id=561664
unknown
clean
http://dev.w3.org/csswg/cssom/#resolved-values
unknown
clean
https://caniuse.com/download
unknown
clean
https://github.com/chartjs/Chart.js/issues/2538
unknown
clean
http://dev.w3.org/csswg/css-color/#hwb-to-rgb
unknown
clean
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
unknown
clean
http://www.apache.org/licenses/LICENSE-2.0)
unknown
clean
https://github.com/kriskowal/es5-shim/blob/master/es5-shim.js
unknown
clean
http://api.jqueryui.com/button/
unknown
clean
http://getbootstrap.com)
unknown
clean
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
unknown
clean
https://blog.alexmaccaw.com/css-transitions
unknown
clean
https://github.com/bassjobsen/Bootstrap-3-Typeahead
unknown
clean
https://getbootstrap.com/docs/3.4/javascript/#transitions
unknown
clean
https://github.com/chartjs/Chart.js/issues/4152
unknown
clean
http://bugs.jquery.com/ticket/9917
unknown
clean
http://www.reddit.com/
unknown
clean
http://api.jqueryui.com/size-effect/
unknown
clean
https://github.com/Do/iso8601.js
unknown
clean
https://developer.mozilla.org/en-US/docs/Web/API/EventTarget/addEventListener#Safely_detecting_optio
unknown
clean
http://momentjs.com/guides/#/warnings/zone/
unknown
clean
http://bugs.jquery.com/ticket/12359
unknown
clean
https://developer.mozilla.org/en-US/docs/Web/API/EventTarget/removeEventListener
unknown
clean
https://w3c.github.io/IntersectionObserver/#intersection-observer-interface
unknown
clean
http://creativecommons.org/licenses/by/3.0/)
unknown
clean
http://docs.closure-library.googlecode.com/git/closure_goog_date_date.js.source.html
unknown
clean
https://www.nathanaeluser.com/blog/2013/reading-max-width-cross-browser
unknown
clean
https://bugzilla.mozilla.org/show_bug.cgi?id=649285
unknown
clean
https://getbootstrap.com/docs/3.4/javascript/#tooltip
unknown
clean
https://github.com/chartjs/Chart.js/issues/6104
unknown
clean
http://jsperf.com/diacritics/18
unknown
clean
http://api.jqueryui.com/category/ui-core/
unknown
clean
https://github.com/twbs/bootstrap/issues/20280
unknown
clean
https://github.com/chartjs/Chart.js/issues/4287
unknown
clean
https://getbootstrap.com/docs/3.4/javascript/#modals
unknown
clean
https://github.com/chartjs/Chart.js/issues/2435#issuecomment-216718158
unknown
clean
https://jsperf.com/object-keys-vs-for-in-with-closure/3
unknown
clean
https://stackoverflow.com/q/181348
unknown
clean
https://getbootstrap.com/docs/3.4/javascript/#collapse
unknown
clean
https://www.anujgakhar.com/2014/03/01/binary-search-in-javascript/
unknown
clean
https://github.com/chartjs/Chart.js/issues/4737
unknown
clean
https://github.com/kkapsner/CanvasBlocker
unknown
clean
http://www.robertpenner.com/easing/
unknown
clean
https://w3c.github.io/IntersectionObserver/#calculate-intersection-rect-algo
unknown
clean
https://github.com/chartjs/Chart.js/issues/3887
unknown
clean
https://getbootstrap.com/docs/3.4/javascript/#scrollspy
unknown
clean
https://github.com/w3c/IntersectionObserver/issues/211
unknown
clean
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
clean
http://flightschool.acylt.com/devnotes/caret-position-woes/
unknown
clean
http://api.jqueryui.com/transfer-effect/
unknown
clean
https://github.com/rails/jquery-ujs
unknown
clean
https://stackoverflow.com/questions/8506881/nice-label-algorithm-for-charts-with-minimum-ticks
unknown
clean
https://bugzilla.mozilla.org/show_bug.cgi?id=491668
unknown
clean
https://github.com/marcj/css-element-queries
unknown
clean
http://www.robertpenner.com/easing)
unknown
clean
http://momentjs.com/guides/#/warnings/min-max/
unknown
clean
https://github.com/chartjs/Chart.js/issues/4102
unknown
clean
https://stackoverflow.com/q/3922139
unknown
clean
http://api.jqueryui.com/drop-effect/
unknown
clean
http://www.amazon.com/
unknown
clean
http://www.twitter.com/
unknown
clean
http://jsperf.com/getall-vs-sizzle/2
unknown
clean
https://getbootstrap.com/docs/3.4/javascript/#buttons
unknown
clean
https://github.com/jquery/jquery/pull/557)
unknown
clean
https://www.html5canvastutorials.com/advanced/html5-canvas-mouse-coordinates/
unknown
clean
http://api.jqueryui.com/menu/
unknown
clean
https://getbootstrap.com/docs/3.4/javascript/#alerts
unknown
clean
https://github.com/chartjs/Chart.js/issues/5208
unknown
clean
http://api.jqueryui.com/category/effects-core/
unknown
clean
http://bugs.jquery.com/ticket/8235
unknown
clean
https://chartjs.gitbooks.io/proposals/content/Platform.html
unknown
clean
https://secured-login.ted-forms.com/XWkZKNVRYQmFTVmxrVkRoek9VTkdXRzVHWjNBM2RtMDBRMlptZVRkdGNFUjFZekV
unknown
clean
http://api.jqueryui.com/dialog/
unknown
clean
https://w3c.github.io/IntersectionObserver/#intersection-observer-entry
unknown
clean
https://secured-login.net/pages/c3955b1c48a/XWkZKNVRYQmFTVmxrVkRoek9VTkdXRzVHWjNBM2RtMDBRMlptZVRkdGNFUjFZekV6ZWxkblJEZzFiMlZCTWxoTlVXaG5aMHRoYW1kc09VSnlja2xZYkc5MlYwdzNOWFpsVERWNUsxWXZiVkJ5YURreFUzTk9kbGt4ZWtoSGRYa3dTM1ppY1hkT0x6Y3pSMFJXVjNsMWRXNVRiRnBCZURZMGJVWkNlRlJ0TVdGM1REZEhNRnA0ZW5keksyTmFZV2hPWVRGd1Z6Tm9iRFVyVlhnd1UwdHhOVkU0YTJsRGRXMDBjMlZOUFMwdGVsSnhlVlJOWkZKRlNIVjZZbEpUYkVscGJUQTJaejA5LS0yNjI0MmEyNmU5MTE4NzY5Nzk4YzQ5Nzk4MGQyMGYxNmNiYmE1MGQy
clean
http://api.jqueryui.com/shake-effect/
unknown
clean
http://www.nytimes.com/
unknown
clean
https://github.com/Microsoft/tslib/blob/v1.6.0/tslib.js
unknown
clean
https://stackoverflow.com/questions/10149963/adding-event-listener-cross-browser
unknown
clean
https://github.com/imulus/retinajs/issues/8
unknown
clean
http://jsperf.com/1-vs-infinity
unknown
clean
https://github.com/cujojs/when/issues/410
unknown
clean
https://getbootstrap.com/)
unknown
clean
https://github.com/ankane/chartkick.js
unknown
clean
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
cdn2.hubspot.net
104.17.243.204
clean
s3.amazonaws.com
52.217.196.184
clean
cdnjs.cloudflare.com
104.16.18.94
clean
secured-login.net
34.226.85.79
clean
landing.training.knowbe4.com
34.226.85.79
clean
ipv4.imgur.map.fastly.net
151.101.112.193
clean
covid19.protected-forms.com
unknown
clean
i.imgur.com
unknown
clean
favicon.ico
unknown
clean

IPs

IP
Domain
Country
Malicious
52.217.196.184
s3.amazonaws.com
United States
clean
104.17.243.204
cdn2.hubspot.net
United States
clean
151.101.112.193
ipv4.imgur.map.fastly.net
United States
clean
104.16.18.94
cdnjs.cloudflare.com
United States
clean
34.226.85.79
secured-login.net
United States
clean

Registry

Path
Value
Malicious
C:\Program Files\internet explorer\iexplore.exe
{0B1EB684-C85C-11EB-90EB-ECF4BBEA1588}
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Blocked
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
Count
clean
C:\Program Files\internet explorer\iexplore.exe
Time
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
LoadTimeArray
clean
C:\Program Files\internet explorer\iexplore.exe
CVListPingLastYMD
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files\internet explorer\iexplore.exe
DecayDateQueue
clean
C:\Program Files\internet explorer\iexplore.exe
LastProcessed
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NumberOfSubdomains
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-912
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
@C:\Windows\System32\ieframe.dll,-904
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
NULL
clean
C:\Program Files (x86)\Internet Explorer\iexplore.exe
Total
clean
There are 23 hidden registries, click here to show them.

DOM / HTML

URL
Malicious
https://secured-login.net/pages/c3955b1c48a/XWkZKNVRYQmFTVmxrVkRoek9VTkdXRzVHWjNBM2RtMDBRMlptZVRkdGNFUjFZekV6ZWxkblJEZzFiMlZCTWxoTlVXaG5aMHRoYW1kc09VSnlja2xZYkc5MlYwdzNOWFpsVERWNUsxWXZiVkJ5YURreFUzTk9kbGt4ZWtoSGRYa3dTM1ppY1hkT0x6Y3pSMFJXVjNsMWRXNVRiRnBCZURZMGJVWkNlRlJ0TVdGM1REZEhNRnA0ZW5keksyTmFZV2hPWVRGd1Z6Tm9iRFVyVlhnd1UwdHhOVkU0YTJsRGRXMDBjMlZOUFMwdGVsSnhlVlJOWkZKRlNIVjZZbEpUYkVscGJUQTJaejA5LS0yNjI0MmEyNmU5MTE4NzY5Nzk4YzQ5Nzk4MGQyMGYxNmNiYmE1MGQy
clean