IOC Report
http://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/home.html

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jul 2 21:50:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jul 2 21:50:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jul 2 21:50:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jul 2 21:50:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Jul 2 21:50:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 135
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 136
GIF image data, version 89a, 22 x 16
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (4776), with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (24729), with no line terminators
downloaded
Chrome Cache Entry: 140
PNG image data, 10 x 10, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 141
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 142
gzip compressed data, max speed, from Unix, original size modulo 2^32 25004
downloaded
Chrome Cache Entry: 143
ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 144
PNG image data, 82 x 112, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (65450)
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (1822)
downloaded
Chrome Cache Entry: 147
GIF image data, version 89a, 22 x 16
downloaded
Chrome Cache Entry: 148
HTML document, Unicode text, UTF-8 text, with very long lines (1024), with CRLF line terminators
downloaded
Chrome Cache Entry: 149
PNG image data, 208 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 150
gzip compressed data, max speed, from Unix, original size modulo 2^32 394
downloaded
Chrome Cache Entry: 151
gzip compressed data, max speed, from Unix, original size modulo 2^32 4492
downloaded
Chrome Cache Entry: 152
GIF image data, version 89a, 16 x 16
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (32014)
downloaded
Chrome Cache Entry: 154
PNG image data, 1000 x 115, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 155
Web Open Font Format, TrueType, length 28340, version 1.0
downloaded
Chrome Cache Entry: 156
OpenType font data
downloaded
Chrome Cache Entry: 157
GIF image data, version 89a, 45 x 20
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (5215)
downloaded
Chrome Cache Entry: 160
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (65472)
downloaded
Chrome Cache Entry: 162
GIF image data, version 89a, 22 x 16
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (906), with no line terminators
downloaded
Chrome Cache Entry: 164
gzip compressed data, max speed, from Unix, original size modulo 2^32 849
downloaded
Chrome Cache Entry: 165
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 166
GIF image data, version 89a, 22 x 16
dropped
Chrome Cache Entry: 167
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 168
PNG image data, 1000 x 115, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 169
Web Open Font Format, TrueType, length 27944, version 1.0
downloaded
Chrome Cache Entry: 170
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (42158), with no line terminators
downloaded
Chrome Cache Entry: 172
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 173
GIF image data, version 89a, 22 x 16
downloaded
Chrome Cache Entry: 174
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 175
gzip compressed data, max speed, from Unix, original size modulo 2^32 954
downloaded
Chrome Cache Entry: 176
PNG image data, 10 x 10, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 177
ASCII text, with very long lines (7840)
downloaded
Chrome Cache Entry: 178
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 179
OpenType font data
downloaded
Chrome Cache Entry: 180
GIF image data, version 89a, 45 x 20
downloaded
Chrome Cache Entry: 181
Unicode text, UTF-8 text, with very long lines (65464)
downloaded
Chrome Cache Entry: 182
PNG image data, 277 x 134, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 183
PNG image data, 192 x 192, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 184
GIF image data, version 89a, 45 x 20
dropped
Chrome Cache Entry: 185
gzip compressed data, max speed, from Unix, original size modulo 2^32 848
downloaded
Chrome Cache Entry: 186
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 187
gzip compressed data, max speed, from Unix, original size modulo 2^32 93586
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (10466), with no line terminators
downloaded
Chrome Cache Entry: 189
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (65454)
downloaded
Chrome Cache Entry: 191
HTML document, ASCII text, with very long lines (4204), with CRLF line terminators
downloaded
Chrome Cache Entry: 192
gzip compressed data, max speed, from Unix, original size modulo 2^32 842
downloaded
Chrome Cache Entry: 193
gzip compressed data, max speed, from Unix, original size modulo 2^32 18796
downloaded
Chrome Cache Entry: 194
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (65324)
downloaded
Chrome Cache Entry: 196
gzip compressed data, max speed, from Unix, original size modulo 2^32 214382
downloaded
Chrome Cache Entry: 197
GIF image data, version 89a, 359 x 13
downloaded
Chrome Cache Entry: 198
HTML document, ASCII text, with very long lines (26405), with CRLF line terminators
downloaded
Chrome Cache Entry: 199
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 200
GIF image data, version 89a, 16 x 16
dropped
Chrome Cache Entry: 201
PNG image data, 82 x 112, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (2306), with no line terminators
downloaded
Chrome Cache Entry: 203
GIF image data, version 89a, 22 x 16
dropped
Chrome Cache Entry: 204
ASCII text, with very long lines (57791)
downloaded
Chrome Cache Entry: 205
GIF image data, version 89a, 22 x 16
dropped
Chrome Cache Entry: 206
JSON data
downloaded
Chrome Cache Entry: 207
OpenType font data
downloaded
Chrome Cache Entry: 208
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 209
GIF image data, version 89a, 22 x 16
dropped
Chrome Cache Entry: 210
HTML document, Unicode text, UTF-8 text, with very long lines (1024), with CRLF line terminators
downloaded
Chrome Cache Entry: 211
GIF image data, version 89a, 16 x 16
downloaded
Chrome Cache Entry: 212
GIF image data, version 89a, 22 x 16
dropped
Chrome Cache Entry: 213
GIF image data, version 89a, 359 x 13
dropped
Chrome Cache Entry: 214
ASCII text, with very long lines (535), with no line terminators
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (18219), with no line terminators
downloaded
Chrome Cache Entry: 216
Unicode text, UTF-8 text, with very long lines (65458)
downloaded
Chrome Cache Entry: 217
PNG image data, 208 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 218
GIF image data, version 89a, 22 x 16
downloaded
Chrome Cache Entry: 219
gzip compressed data, max speed, from Unix, original size modulo 2^32 3450
downloaded
Chrome Cache Entry: 220
gzip compressed data, max speed, from Unix, original size modulo 2^32 15815
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (6454), with CR line terminators
downloaded
Chrome Cache Entry: 222
gzip compressed data, max speed, from Unix, original size modulo 2^32 404
downloaded
Chrome Cache Entry: 223
PNG image data, 277 x 134, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 224
ASCII text, with very long lines (19795), with no line terminators
downloaded
Chrome Cache Entry: 225
GIF image data, version 89a, 45 x 20
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (430), with CRLF line terminators
downloaded
Chrome Cache Entry: 227
HTML document, ASCII text, with very long lines (611)
downloaded
Chrome Cache Entry: 228
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 229
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 230
ASCII text, with very long lines (65464)
downloaded
Chrome Cache Entry: 231
HTML document, ASCII text
downloaded
Chrome Cache Entry: 232
JSON data
dropped
Chrome Cache Entry: 233
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 234
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 235
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 236
gzip compressed data, max speed, from Unix, original size modulo 2^32 390
downloaded
Chrome Cache Entry: 237
gzip compressed data, max speed, from Unix, original size modulo 2^32 740
downloaded
Chrome Cache Entry: 238
gzip compressed data, max speed, from Unix, original size modulo 2^32 13584
downloaded
Chrome Cache Entry: 239
gzip compressed data, max speed, from Unix, original size modulo 2^32 3082
downloaded
Chrome Cache Entry: 240
ASCII text, with very long lines (1822)
downloaded
Chrome Cache Entry: 241
PNG image data, 192 x 192, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 242
JSON data
dropped
Chrome Cache Entry: 243
GIF image data, version 89a, 16 x 16
downloaded
Chrome Cache Entry: 244
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 245
HTML document, Unicode text, UTF-8 text, with very long lines (1024), with CRLF line terminators
downloaded
There are 108 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=2092,i,16260208065849529715,7431551040430799622,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/home.html"

URLs

Name
IP
Malicious
http://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/home.html
malicious
http://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/home.html
104.18.3.35
malicious
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/js/bootstrap.min.js
104.18.10.207
https://www.ram.co.za/careers.html
https://www.ram.co.za/js/toastr.min.js
41.21.176.100
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-app.js
unknown
http://portal.ram.co.za/#DefaultBreadCrumb_SkipLink
https://www.ram.co.za/images/footer_icons.png
41.21.176.100
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-chunk-f163fcd0.js
unknown
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-iterator-polyfill.js
unknown
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-vendor.js
188.114.97.3
https://twitter.com/OfficialRAMsa
unknown
https://www.ram.co.za/Send/Confirm
unknown
https://www.ram.co.za/fonts/Gotham/gothambook.otf
41.21.176.100
https://static.userguiding.com/media/sdk-061677463ID.json
172.67.70.147
https://github.com/zloirock/core-js
unknown
https://static.hotjar.com/c/hotjar-1900525.js?sv=6
18.239.94.85
https://ajax.aspnetcdn.com/ajax/jquery/jquery-3.3.1.min.js
unknown
https://www.ram.co.za/lib/modernizr/modernizr-2.8.3.js
41.21.176.100
http://jqueryui.com
unknown
http://portal.ram.co.za/Scripts/clock_aus.js?v=20220802020558
41.21.176.110
http://jqueryui.com/themeroller/?ffDefault=Arial%2Csans-serif&fwDefault=bold&fsDefault=1.1em&cornerR
unknown
http://www.ram.co.za/information-act.html
41.21.176.100
about:blank
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-arr-find-polyfill.js
unknown
http://www.ram.co.za/careers.html
41.21.176.100
https://vsa7.tawk.to/s/?k=6684846e5625d7d34e352368&cver=0&pop=false&asver=64916&tkn=eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InZpc2l0b3ItYXBwbGljYXRpb24tc2VydmVyLTIwMjEwMjIifQ.eyJwaWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQiLCJ2aWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQtME5Ga0ZlMmI2UURtaFJhaGtzc01RIiwic2lkIjoiNjY4NDg0NmU1NjI1ZDdkMzRlMzUyMzY4IiwiaWF0IjoxNzE5OTYwNjg2LCJleHAiOjE3MTk5NjI0ODYsImp0aSI6Im50ZnlxSEhXV0hUU25oRnpLTlZYaSJ9.NdIu-6FHB3ddjHxQjIrto0piQ8kKwQyvjmPl_a2621P0TjkonqpuGXbEVHFnKFf5NfSyWwBnXuTvEiOfvXtTPg&EIO=3&transport=websocket&__t=P1rfMzW
188.114.96.3
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-chunk-7c2f6ba4.js
188.114.97.3
http://portal.ram.co.za/images/btn_login_black.gif
41.21.176.110
http://portal.ram.co.za/WebResource.axd?d=_x4i-K-eKgZKn-t1GQ4NsiDaFk_o10oDybcLFdkizY6q8SEUdFunnUaOiCx4G1smiUGP74RNfgnLOzYWBIFtAktcp-riGmOrFDtESaR7TL81&t=638393498760000000
41.21.176.110
https://www.google.com
unknown
https://script.hotjar.com/modules.e4b2dc39f985f11fb1e4.js
13.227.219.28
https://www.ram.co.za/fonts/Rambla/rambla-bold-webfont.woff
41.21.176.100
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
http://www.typography.comGothamLightH&FJ:
unknown
http://portal.ram.co.za/Scripts/clock_za.js?v=20220802020558
41.21.176.110
https://github.com/kriskowal/es5-shim/blob/master/es5-shim.js
unknown
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(4).html
https://vsa111.tawk.to/s/?k=6684846e5625d7d34e352368&cver=0&pop=false&asver=64916&tkn=eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InZpc2l0b3ItYXBwbGljYXRpb24tc2VydmVyLTIwMjEwMjIifQ.eyJwaWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQiLCJ2aWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQtME5Ga0ZlMmI2UURtaFJhaGtzc01RIiwic2lkIjoiNjY4NDg0NmU1NjI1ZDdkMzRlMzUyMzY4IiwiaWF0IjoxNzE5OTYwNjg2LCJleHAiOjE3MTk5NjI0ODYsImp0aSI6Im50ZnlxSEhXV0hUU25oRnpLTlZYaSJ9.NdIu-6FHB3ddjHxQjIrto0piQ8kKwQyvjmPl_a2621P0TjkonqpuGXbEVHFnKFf5NfSyWwBnXuTvEiOfvXtTPg&EIO=3&transport=websocket&__t=P1rfMM-
188.114.96.3
https://portal.ram.co.za/
unknown
https://embed.tawk.to/_s/v4/app/66790c3897f/css/min-widget.css
188.114.97.3
http://portal.ram.co.za/Images/customer-care.gif
41.21.176.110
https://sacoronavirus.co.za/
unknown
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
unknown
https://www.ram.co.za/information-act.html
http://portal.ram.co.za/App_Themes/RAM/RAM.css?v=20220802020542
41.21.176.110
https://developers.cloudflare.com/r2/data-access/public-buckets/
unknown
https://github.com/zloirock/core-js/blob/v3.37.1/LICENSE
unknown
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-chunk-4fe9d5dd.js
unknown
https://www.ram.co.za/js/respond.min.js
41.21.176.100
https://www.linkedin.com/company/ram-hand-to-hand-couriers/
unknown
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-chunk-24d8db78.js
188.114.97.3
https://www.ram.co.za/css/moving-vehicles.css
41.21.176.100
http://www.typography.comGotham
unknown
https://embed.tawk.to/59fb16f9198bd56b8c039004/default
188.114.97.3
https://github.com/scottjehl/Respond/blob/master/LICENSE-MIT
unknown
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/css
104.18.3.35
https://www.ram.co.za/images/nice-highres.png
41.21.176.100
https://vsa77.tawk.to/s/?k=6684846e5625d7d34e352368&cver=0&pop=false&asver=64916&tkn=eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InZpc2l0b3ItYXBwbGljYXRpb24tc2VydmVyLTIwMjEwMjIifQ.eyJwaWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQiLCJ2aWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQtME5Ga0ZlMmI2UURtaFJhaGtzc01RIiwic2lkIjoiNjY4NDg0NmU1NjI1ZDdkMzRlMzUyMzY4IiwiaWF0IjoxNzE5OTYwNjg2LCJleHAiOjE3MTk5NjI0ODYsImp0aSI6Im50ZnlxSEhXV0hUU25oRnpLTlZYaSJ9.NdIu-6FHB3ddjHxQjIrto0piQ8kKwQyvjmPl_a2621P0TjkonqpuGXbEVHFnKFf5NfSyWwBnXuTvEiOfvXtTPg&EIO=3&transport=websocket&__t=P1rfNPY
188.114.96.3
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-chunk-vendors.js
unknown
http://portal.ram.co.za/images/icons/error.gif
41.21.176.110
https://www.ram.co.za/images/ram_header_logo.png
41.21.176.100
https://cct.google/taggy/agent.js
unknown
https://vsa89.tawk.to/s/?k=6684846e5625d7d34e352368&cver=0&pop=false&asver=64916&tkn=eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InZpc2l0b3ItYXBwbGljYXRpb24tc2VydmVyLTIwMjEwMjIifQ.eyJwaWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQiLCJ2aWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQtME5Ga0ZlMmI2UURtaFJhaGtzc01RIiwic2lkIjoiNjY4NDg0NmU1NjI1ZDdkMzRlMzUyMzY4IiwiaWF0IjoxNzE5OTYwNjg2LCJleHAiOjE3MTk5NjI0ODYsImp0aSI6Im50ZnlxSEhXV0hUU25oRnpLTlZYaSJ9.NdIu-6FHB3ddjHxQjIrto0piQ8kKwQyvjmPl_a2621P0TjkonqpuGXbEVHFnKFf5NfSyWwBnXuTvEiOfvXtTPg&EIO=3&transport=websocket&__t=P1rfLiI
188.114.96.3
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-chunk-32507910.js
unknown
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(1).html
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-promise-polyfill.js
unknown
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-chunk-48f3b594.js
188.114.97.3
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-vendor.js
unknown
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-chunk-71978bb6.js
188.114.97.3
https://a.nel.cloudflare.com/report/v4?s=3%2FrrgRizJowihWq2M%2Fb%2F2EYq17%2BtW3k3QKyynEKNDUpysNsTGZWIoO6RFlN8xATiPJSXxI8ryb%2F09SzvOx3fJYts6%2FIpO%2BSBvO98hP7k%2F8QwNMBRTpPk0f88Q3nJPjrkqygH4O295jk%3D
35.190.80.1
https://www.ram.co.za/css/toastr.min.css
41.21.176.100
https://www.ram.co.za/fonts/Gotham/gothambold.otf
41.21.176.100
https://www.ram.co.za/fonts/Rambla/rambla-regular-webfont.woff
41.21.176.100
http://portal.ram.co.za/Scripts/json2.js?v=20220802020558
41.21.176.110
http://portal.ram.co.za/images/exclamation.gif
41.21.176.110
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(2).html
https://www.ram.co.za/images/black_close.png
41.21.176.100
http://portal.ram.co.za/Scripts/Shared.js?v=20230814040740
41.21.176.110
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-chunk-48f46bef.js
unknown
http://www.ram.co.za/contact-us.html
41.21.176.100
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-chunk-common.js
188.114.97.3
https://deep-tech-summit.goodwood.com/default/auth/parcel.php#
unknown
http://portal.ram.co.za/App_Themes/RAM/MenuStyle.css?v=20220802020542
41.21.176.110
https://vsa30.tawk.to/s/?k=6684846e5625d7d34e352368&cver=0&pop=false&asver=64916&tkn=eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InZpc2l0b3ItYXBwbGljYXRpb24tc2VydmVyLTIwMjEwMjIifQ.eyJwaWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQiLCJ2aWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQtME5Ga0ZlMmI2UURtaFJhaGtzc01RIiwic2lkIjoiNjY4NDg0NmU1NjI1ZDdkMzRlMzUyMzY4IiwiaWF0IjoxNzE5OTYwNjg2LCJleHAiOjE3MTk5NjI0ODYsImp0aSI6Im50ZnlxSEhXV0hUU25oRnpLTlZYaSJ9.NdIu-6FHB3ddjHxQjIrto0piQ8kKwQyvjmPl_a2621P0TjkonqpuGXbEVHFnKFf5NfSyWwBnXuTvEiOfvXtTPg&EIO=3&transport=websocket&__t=P1rfMc3
188.114.97.3
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-main.js
unknown
https://embed.tawk.to/_s/v4/app/62d9e8f6147/js/twk-chunk-696bc286.js
unknown
https://stackpath.bootstrapcdn.com/bootstrap/4.3.1/css/bootstrap.min.css
104.18.10.207
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-object-values-polyfill.js
unknown
https://www.ram.co.za/css/site_v2.min.css?v=2
41.21.176.100
http://www.typography.com/support/eula.html.http://www.typography.com/support/eula.htmlGothamLight
unknown
http://portal.ram.co.za/Images/flag_japan.gif
41.21.176.110
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(3).html
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-chunk-bf24a88e.js
188.114.97.3
https://embed.tawk.to/_s/v4/app/66790c3897f/js/twk-chunk-vendors.js
188.114.97.3
https://www.ram.co.za/contact-us.html
http://portal.ram.co.za/Images/flag_aus.gif
41.21.176.110
https://embed.tawk.to/_s/v4/app/66790c3897f/css/message-preview.css
188.114.97.3
https://vsa120.tawk.to/s/?k=6684846e5625d7d34e352368&cver=0&pop=false&asver=64916&tkn=eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6InZpc2l0b3ItYXBwbGljYXRpb24tc2VydmVyLTIwMjEwMjIifQ.eyJwaWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQiLCJ2aWQiOiI1OWZiMTZmOTE5OGJkNTZiOGMwMzkwMDQtME5Ga0ZlMmI2UURtaFJhaGtzc01RIiwic2lkIjoiNjY4NDg0NmU1NjI1ZDdkMzRlMzUyMzY4IiwiaWF0IjoxNzE5OTYwNjg2LCJleHAiOjE3MTk5NjI0ODYsImp0aSI6Im50ZnlxSEhXV0hUU25oRnpLTlZYaSJ9.NdIu-6FHB3ddjHxQjIrto0piQ8kKwQyvjmPl_a2621P0TjkonqpuGXbEVHFnKFf5NfSyWwBnXuTvEiOfvXtTPg&EIO=3&transport=websocket&__t=P1rfMA_
188.114.97.3
https://embed.tawk.to/_s/v4/app/66790c3897f/
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
stackpath.bootstrapcdn.com
104.18.10.207
jsdelivr.map.fastly.net
151.101.129.229
google.com
216.58.206.78
a.nel.cloudflare.com
35.190.80.1
vsa120.tawk.to
188.114.97.3
vsa44.tawk.to
188.114.97.3
vsa111.tawk.to
188.114.96.3
vsa30.tawk.to
188.114.97.3
vsa89.tawk.to
188.114.96.3
fp2e7a.wpc.phicdn.net
192.229.221.95
ram.co.za
41.21.176.100
vsa88.tawk.to
188.114.97.3
embed.tawk.to
188.114.97.3
va.tawk.to
188.114.97.3
bg.microsoft.map.fastly.net
199.232.210.172
vsa35.tawk.to
188.114.96.3
pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev
104.18.3.35
script.hotjar.com
13.227.219.28
www.google.com
142.250.185.132
portal.ram.co.za
41.21.176.110
vsa77.tawk.to
188.114.96.3
static.userguiding.com
172.67.70.147
vsa7.tawk.to
188.114.96.3
static-cdn.hotjar.com
18.239.94.85
cdn.jsdelivr.net
unknown
ajax.aspnetcdn.com
unknown
static.hotjar.com
unknown
www.ram.co.za
unknown
deep-tech-summit.goodwood.com
unknown
There are 19 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.18.3.35
pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev
United States
41.21.176.110
portal.ram.co.za
South Africa
104.18.10.207
stackpath.bootstrapcdn.com
United States
151.101.129.229
jsdelivr.map.fastly.net
United States
192.168.2.7
unknown
unknown
192.168.2.5
unknown
unknown
172.67.70.147
static.userguiding.com
United States
13.227.219.28
script.hotjar.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
41.21.176.100
ram.co.za
South Africa
18.239.94.85
static-cdn.hotjar.com
United States
142.250.185.132
www.google.com
United States
239.255.255.250
unknown
Reserved
188.114.97.3
vsa120.tawk.to
European Union
188.114.96.3
vsa111.tawk.to
European Union
There are 5 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(3).html
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource.html
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/home.html
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(4).html
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(2).html
https://pub-2e7429ed1f544f43a4684eeceb978dbb.r2.dev/pag1_files/saved_resource(1).html
http://portal.ram.co.za/
http://portal.ram.co.za/#DefaultBreadCrumb_SkipLink
https://www.ram.co.za/careers.html
https://www.ram.co.za/careers.html
about:blank
about:blank
about:blank
about:blank
about:blank
about:blank
https://www.ram.co.za/contact-us.html
https://www.ram.co.za/contact-us.html
https://www.ram.co.za/contact-us.html
https://www.ram.co.za/information-act.html
https://www.ram.co.za/information-act.html
There are 11 hidden doms, click here to show them.