IOC Report
https://pub-fb608504b57048a1b1ca54c74dbf132d.r2.dev/ront.html?ccsend

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 149
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 150
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (27809)
downloaded
Chrome Cache Entry: 152
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 153
HTML document, ASCII text, with very long lines (65390)
downloaded
Chrome Cache Entry: 154
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 155
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 156
Web Open Font Format (Version 2), TrueType, length 22904, version 0.0
downloaded
Chrome Cache Entry: 157
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 159
exported SGML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 160
Unicode text, UTF-8 (with BOM) text, with very long lines (480), with CRLF line terminators
downloaded
Chrome Cache Entry: 161
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 162
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (32047)
downloaded
Chrome Cache Entry: 164
Unicode text, UTF-8 (with BOM) text, with very long lines (7625), with CRLF line terminators
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (378), with CRLF line terminators
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (1245), with no line terminators
downloaded
Chrome Cache Entry: 167
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 168
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (385), with CRLF line terminators
downloaded
Chrome Cache Entry: 170
HTML document, ASCII text, with very long lines (322), with CRLF line terminators
downloaded
Chrome Cache Entry: 171
Unicode text, UTF-8 (with BOM) text, with very long lines (512), with CRLF line terminators
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (415), with CRLF line terminators
downloaded
Chrome Cache Entry: 173
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 174
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 175
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 176
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 177
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (27809)
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (31463), with no line terminators
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (356), with CRLF line terminators
downloaded
Chrome Cache Entry: 181
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 182
Web Open Font Format, TrueType, length 41280, version 0.0
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (878), with CRLF line terminators
downloaded
Chrome Cache Entry: 184
Unicode text, UTF-8 text, with very long lines (65514), with no line terminators
downloaded
Chrome Cache Entry: 185
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 186
Unicode text, UTF-8 (with BOM) text, with very long lines (1072), with CRLF line terminators
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (314), with CRLF line terminators
downloaded
Chrome Cache Entry: 188
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 189
JSON data
dropped
Chrome Cache Entry: 190
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 191
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 192
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 193
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 194
JSON data
downloaded
Chrome Cache Entry: 195
Unicode text, UTF-8 (with BOM) text, with very long lines (503), with CRLF line terminators
downloaded
Chrome Cache Entry: 196
Unicode text, UTF-8 (with BOM) text, with very long lines (16609), with CRLF line terminators
downloaded
Chrome Cache Entry: 197
Unicode text, UTF-8 text, with very long lines (37565)
downloaded
Chrome Cache Entry: 198
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 199
GIF image data, version 89a, 1181 x 1181
dropped
Chrome Cache Entry: 200
JSON data
downloaded
Chrome Cache Entry: 201
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 202
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 203
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 204
ASCII text, with very long lines (312), with CRLF line terminators
downloaded
Chrome Cache Entry: 205
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 206
Unicode text, UTF-8 text, with very long lines (65520), with no line terminators
downloaded
Chrome Cache Entry: 207
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (327), with CRLF line terminators
downloaded
Chrome Cache Entry: 209
Unicode text, UTF-8 text, with very long lines (64241)
downloaded
Chrome Cache Entry: 210
Unicode text, UTF-8 (with BOM) text, with very long lines (497), with CRLF line terminators
dropped
Chrome Cache Entry: 211
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 212
Unicode text, UTF-8 text, with very long lines (64174)
downloaded
Chrome Cache Entry: 213
Unicode text, UTF-8 (with BOM) text, with very long lines (480), with CRLF line terminators
dropped
Chrome Cache Entry: 214
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 215
JSON data
downloaded
Chrome Cache Entry: 216
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 217
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 218
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 219
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 220
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 221
Web Open Font Format, TrueType, length 33556, version 0.0
downloaded
Chrome Cache Entry: 222
Web Open Font Format, TrueType, length 35900, version 0.0
downloaded
Chrome Cache Entry: 223
Unicode text, UTF-8 (with BOM) text, with very long lines (512), with CRLF line terminators
dropped
Chrome Cache Entry: 224
Unicode text, UTF-8 (with BOM) text, with very long lines (529), with CRLF line terminators
downloaded
Chrome Cache Entry: 225
ASCII text, with very long lines (4050), with no line terminators
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (42133)
downloaded
Chrome Cache Entry: 227
Unicode text, UTF-8 text, with very long lines (557), with CRLF line terminators
downloaded
Chrome Cache Entry: 228
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 229
Web Open Font Format, TrueType, length 2576, version 1.0
downloaded
Chrome Cache Entry: 230
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 231
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 232
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 233
JSON data
dropped
Chrome Cache Entry: 234
ASCII text, with very long lines (816), with CRLF line terminators
downloaded
Chrome Cache Entry: 235
Unicode text, UTF-8 text, with very long lines (37565)
dropped
Chrome Cache Entry: 236
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 237
Unicode text, UTF-8 (with BOM) text, with very long lines (36076), with CRLF line terminators
downloaded
Chrome Cache Entry: 238
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 239
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 240
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 241
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 242
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 243
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 244
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 245
GIF image data, version 89a, 1181 x 1181
downloaded
Chrome Cache Entry: 246
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 247
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 248
JSON data
downloaded
Chrome Cache Entry: 249
ASCII text, with very long lines (395), with CRLF line terminators
downloaded
Chrome Cache Entry: 250
Unicode text, UTF-8 (with BOM) text, with very long lines (503), with CRLF line terminators
dropped
Chrome Cache Entry: 251
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 252
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 253
ASCII text, with very long lines (32089)
downloaded
Chrome Cache Entry: 254
JSON data
dropped
Chrome Cache Entry: 255
Unicode text, UTF-8 (with BOM) text, with very long lines (529), with CRLF line terminators
dropped
Chrome Cache Entry: 256
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 257
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (65397)
downloaded
Chrome Cache Entry: 259
JSON data
dropped
Chrome Cache Entry: 260
ASCII text, with very long lines (318), with CRLF line terminators
downloaded
Chrome Cache Entry: 261
ASCII text, with very long lines (301), with CRLF line terminators
downloaded
Chrome Cache Entry: 262
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 263
Unicode text, UTF-8 (with BOM) text, with very long lines (34199), with CRLF line terminators, with escape sequences
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (421), with CRLF line terminators
downloaded
Chrome Cache Entry: 265
Unicode text, UTF-8 (with BOM) text, with very long lines (497), with CRLF line terminators
downloaded
Chrome Cache Entry: 266
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 267
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 268
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 269
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 270
ASCII text, with very long lines (42133)
downloaded
Chrome Cache Entry: 271
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 272
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 273
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 274
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 275
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 276
exported SGML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 277
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 278
Unicode text, UTF-8 (with BOM) text, with very long lines (653), with CRLF line terminators
downloaded
Chrome Cache Entry: 279
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (316), with CRLF line terminators
downloaded
Chrome Cache Entry: 281
JSON data
dropped
Chrome Cache Entry: 282
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 283
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 284
Unicode text, UTF-8 text, with very long lines (64241)
downloaded
Chrome Cache Entry: 285
PNG image data, 2560 x 546, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 286
ASCII text, with very long lines (402)
downloaded
Chrome Cache Entry: 287
Unicode text, UTF-8 (with BOM) text, with very long lines (434), with CRLF line terminators
downloaded
Chrome Cache Entry: 288
Unicode text, UTF-8 (with BOM) text, with very long lines (434), with CRLF line terminators
dropped
Chrome Cache Entry: 289
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 290
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 291
ASCII text, with very long lines (65450), with CRLF line terminators
downloaded
Chrome Cache Entry: 292
HTML document, ASCII text, with very long lines (322), with CRLF line terminators
dropped
There are 135 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2504 --field-trial-handle=2200,i,15190939568180799863,15624682917963673456,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pub-fb608504b57048a1b1ca54c74dbf132d.r2.dev/ront.html?ccsend"

URLs

Name
IP
Malicious
https://pub-fb608504b57048a1b1ca54c74dbf132d.r2.dev/ront.html?ccsend
malicious
https://pub-fb608504b57048a1b1ca54c74dbf132d.r2.dev/ront.html?ccsend
malicious
https://aka.ms/youngpeopleprivacy
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://icon-library.com/images/loading-icon-animated-gif/loading-icon-animated-gif-7.jpg
104.26.10.155
http://live.xbox.com/MyXbox/Profile
unknown
https://upload.wikimedia.org/wikipedia/commons/thumb/9/96/Microsoft_logo_%282012%29.svg/2560px-Micro
unknown
https://mattcooperfamilylaw.sharepoint.com/:b:/g/EQHRsiZsHXdDisO3M3swRP0BfVMXsv1uIFWH41KS1v0d_g?e=4%
unknown
http://knockoutjs.com/
unknown
https://github.com/chemerisuk/better-dom
unknown
about:blank
http://www.json.org/json2.js
unknown
https://aka.ms/dpa
unknown
https://upload.wikimedia.org/wikipedia/commons/thumb/9/96/Microsoft_logo_%282012%29.svg/2560px-Microsoft_logo_%282012%29.svg.png
185.15.59.240
http://NSwag.org)
unknown
https://www.w3.org/TR/wai-aria-practices/examples/dialog-modal/css/datepicker.css
104.18.23.19
https://onedrive.live.com/
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://minecraft.net
unknown
https://aka.ms/privacy
23.3.110.134
https://outlook.live.com/mail/inbox
unknown
https://www.w3.org/WAI/ARIA/apg/
104.18.23.19
http://goo.gl/MqrFmX
unknown
https://api.telegram.org/bot$
unknown
https://logo.clearbit.com/
18.239.36.8
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
unknown
https://js.monitor.azure.com/scripts/c/ms.analytics-web-3.gbl.min.js
13.107.246.67
http://github.com/requirejs/almond/LICENSE
unknown
https://github.com/chemerisuk/better-dateinput-polyfill
unknown
https://i.imgur.com/aqOTSn0.png
199.232.192.193
There are 19 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
waws-prod-am2-46f973ed.sip.p.azurewebsites.windows.net
20.76.252.24
d26p066pn2w0s0.cloudfront.net
18.239.36.8
bg.microsoft.map.fastly.net
199.232.214.172
pub-fb608504b57048a1b1ca54c74dbf132d.r2.dev
104.18.3.35
www.google.com
172.217.18.4
upload.wikimedia.org
185.15.59.240
www.w3.org
104.18.23.19
aka.ms
23.3.110.134
s-part-0039.t-0009.t-msedge.net
13.107.246.67
icon-library.com
104.26.10.155
fp2e7a.wpc.phicdn.net
192.229.221.95
ipv4.imgur.map.fastly.net
199.232.192.193
js.monitor.azure.com
unknown
assets.onestore.ms
unknown
i.s-microsoft.com
unknown
ajax.aspnetcdn.com
unknown
c.s-microsoft.com
unknown
i.imgur.com
unknown
logo.clearbit.com
unknown
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.18.3.35
pub-fb608504b57048a1b1ca54c74dbf132d.r2.dev
United States
13.107.246.67
s-part-0039.t-0009.t-msedge.net
United States
199.232.196.193
unknown
United States
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
185.15.59.240
upload.wikimedia.org
Netherlands
104.18.23.19
www.w3.org
United States
199.232.192.193
ipv4.imgur.map.fastly.net
United States
172.217.18.4
www.google.com
United States
20.76.252.24
waws-prod-am2-46f973ed.sip.p.azurewebsites.windows.net
United States
104.26.10.155
icon-library.com
United States
239.255.255.250
unknown
Reserved
18.239.36.8
d26p066pn2w0s0.cloudfront.net
United States
23.3.110.134
aka.ms
United States
There are 4 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://pub-fb608504b57048a1b1ca54c74dbf132d.r2.dev/ront.html?ccsend
malicious
https://privacy.microsoft.com/en-us/privacystatement
https://privacy.microsoft.com/en-US/updates
https://privacy.microsoft.com/en-us/privacystatement#maincookiessimilartechnologiesmodule
https://privacy.microsoft.com/en-us/privacystatement#maincookiessimilartechnologiesmodule
https://privacy.microsoft.com/en-us/privacystatement#mainwherewestoreandprocessdatamodule
https://www.microsoft.com/en-us/concern/privacy
https://www.microsoft.com/en-us/concern/privacy
https://www.microsoft.com/en-us/concern/privacy
https://www.microsoft.com/en-us/concern/privacy
about:blank
https://www.microsoft.com/store/buy/cartcount
https://privacy.microsoft.com/en-US/privacystatement#mainhowtocontactusmodule
https://privacy.microsoft.com/en-US/privacystatement#mainhowtocontactusmodule
https://privacy.microsoft.com/en-us/privacystatement#mainenterprisedeveloperproductsmodule
https://privacy.microsoft.com/en-us/privacystatement#mainenterprisedeveloperproductsmodule
https://privacy.microsoft.com/en-us/privacystatement#mainnoticetoendusersmodule
https://privacy.microsoft.com/en-us/privacystatement#mainnoticetoendusersmodule
https://privacy.microsoft.com/en-us/privacystatement#mainmicrosoftaccountmodule
There are 9 hidden doms, click here to show them.