IOC Report
https://delivery.attempt.failure.ebbs.co.za/public/MY096OineFzTCVJ56qDw3aMDByE0CDQ1

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 56
HTML document, ASCII text
downloaded
Chrome Cache Entry: 57
HTML document, ASCII text, with very long lines (5395)
downloaded
Chrome Cache Entry: 58
Web Open Font Format (Version 2), TrueType, length 156388, version 773.1280
downloaded
Chrome Cache Entry: 59
HTML document, Unicode text, UTF-8 text, with very long lines (39884)
downloaded
Chrome Cache Entry: 60
ASCII text
downloaded
Chrome Cache Entry: 61
Web Open Font Format (Version 2), TrueType, length 117856, version 773.1280
downloaded
Chrome Cache Entry: 62
ASCII text, with very long lines (65321)
dropped
Chrome Cache Entry: 63
HTML document, ASCII text, with very long lines (5395)
downloaded
Chrome Cache Entry: 64
ASCII text, with very long lines (27377)
dropped
Chrome Cache Entry: 65
ASCII text, with very long lines (44992)
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (30837)
downloaded
Chrome Cache Entry: 67
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 68
Web Open Font Format (Version 2), TrueType, length 77160, version 4.459
downloaded
Chrome Cache Entry: 69
ASCII text, with very long lines (27377)
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (65450)
downloaded
Chrome Cache Entry: 71
HTML document, ASCII text, with very long lines (5395)
downloaded
Chrome Cache Entry: 72
ASCII text, with very long lines (1560)
dropped
Chrome Cache Entry: 73
HTML document, ASCII text, with very long lines (5395)
downloaded
Chrome Cache Entry: 74
ASCII text, with very long lines (608)
dropped
Chrome Cache Entry: 75
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 76
ASCII text, with very long lines (1560)
downloaded
Chrome Cache Entry: 77
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 78
ASCII text, with very long lines (7840)
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (65321)
downloaded
Chrome Cache Entry: 81
HTML document, ASCII text, with very long lines (5395)
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (11461)
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (608)
downloaded
There are 19 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2012,i,7095061208222682804,7365120454262363207,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://delivery.attempt.failure.ebbs.co.za/public/MY096OineFzTCVJ56qDw3aMDByE0CDQ1"

URLs

Name
IP
Malicious
https://delivery.attempt.failure.ebbs.co.za/public/MY096OineFzTCVJ56qDw3aMDByE0CDQ1
malicious
https://delivery.attempt.failure.ebbs.co.za/public/js/session-recorder.js
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/fonts/vendor/@fortawesome/fontawesome-free/webfa-solid-900.woff?eeccf4f66002c6f2ba24d3d22f2434c2
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/fonts/vendor/@fontsource/roboto/files/roboto-all-400-normal.woff?376ea5d93f71583052f65de4e0c6a92c
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/public/js/app.js
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/fonts/vendor/@fontsource/roboto/files/roboto-latin-400-normal.woff2?4673b4537a84c7f7a130799aa6af329b
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/favicon.ico
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/images/foo.png
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/public
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/public/MY096OineFzTCVJ56qDw3aMDByE0CDQ1
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/fonts/vendor/@fortawesome/fontawesome-free/webfa-brands-400.ttf?527940b104eb2ea366c8630f3f038603
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/images/all.png
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/fonts/vendor/@fortawesome/fontawesome-free/webfa-solid-900.ttf?be9ee23c0c6390141475d519c2c5fb8f
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/Krg18BVSvoTOJUgjqNiHEYHkU9uE9XJb/
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/images/logo.png
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/public/
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/public/css/app.css
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/fonts/vendor/@fortawesome/fontawesome-free/webfa-solid-900.woff2?1551f4f60c37af51121f106501f69b80
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/fonts/vendor/@fortawesome/fontawesome-free/webfa-brands-400.woff?2285773e6b4b172f07d9b777c81b0775
41.185.8.221
malicious
https://delivery.attempt.failure.ebbs.co.za/public/css/fonts/webfa-brands-400.woff2?d878b0a6a1144760244ff0665888404c
41.185.8.221
malicious
http://fontawesome.io
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/fonts/fontawesome-webfont.woff2?v=4.7.0
104.17.25.14
https://ka-f.fontawesome.com
unknown
https://testibb.co
unknown
https://yandex.com
unknown
https://cdn.lr-in.com/logger-1.min.js
104.21.234.145
http://js.pusher.com
unknown
https://kit.fontawesome.com/f7165dd215.js
unknown
about:blank
https://fontawesome.com/license/free
unknown
https://fontawesome.com
unknown
https://script.hotjar.com/modules.e4b2dc39f985f11fb1e4.js
13.227.219.3
https://github.com/pusher/pusher-js/tree/cc491015371a4bde5743d1c87a0fbac0feb53195#encrypted-channel-
unknown
https://ws-mt1.pusher.com/app/bc5ba70500b3342fb1aa?protocol=7&client=js&version=7.0.3&flash=false
54.209.125.179
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/4.7.0/css/font-awesome.min.css
104.17.25.14
https://delivery.attempt.failure.ebbs.co.za/public/Krg18BVSvoTOJUgjqNiHEYHkU9uE9XJb
https://static.hotjar.com/c/hotjar-
unknown
https://static.hotjar.com/c/hotjar-2895475.js?sv=6
18.239.94.35
https://getbootstrap.com/)
unknown
https://r.lr-in.com/i?a=mnnzup%2Fdus&r=5-45c7a511-fc29-489f-80e9-a613844dcd39&t=b399cfee-7e1f-4829-8180-557e2bb6b386&s=0&rs=0%2Cu&u=b3c3f9bd-46b1-4c50-bc98-ee911a1a0acd&is=1
104.198.23.205
http://fontawesome.io/license
unknown
https://kit.fontawesome.com
unknown
https://sockjs-mt1.pusher.com/pusher/app/bc5ba70500b3342fb1aa/443/ir465fcn/xhr_streaming?protocol=7&client=js&version=7.0.3&t=1720133101492&n=1
34.201.239.212
https://files.killbot.org/.cdn-cgi/killbot-security.js
unknown
https://pusher.com
unknown
https://github.com/js-cookie/js-cookie
unknown
https://popper.js.org)
unknown
https://github.com/es-shims/es5-shim
unknown
https://js.pusher.com
unknown
There are 39 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
delivery.attempt.failure.ebbs.co.za
41.185.8.221
malicious
bg.microsoft.map.fastly.net
199.232.210.172
prod-default.lb.logrocket.network
104.198.23.205
script.hotjar.com
13.227.219.3
cdnjs.cloudflare.com
104.17.25.14
socket-mt1-ingress-1987402783.us-east-1.elb.amazonaws.com
54.209.125.179
www.google.com
142.250.186.164
cdn.lr-in.com
104.21.234.145
fp2e7a.wpc.phicdn.net
192.229.221.95
ingress-sticky-haproxy-mt1-912d8b7308f82d6c.elb.us-east-1.amazonaws.com
34.201.239.212
static-cdn.hotjar.com
18.239.94.35
ka-f.fontawesome.com
unknown
static.hotjar.com
unknown
kit.fontawesome.com
unknown
r.lr-in.com
unknown
sockjs-mt1.pusher.com
unknown
files.killbot.org
unknown
ws-mt1.pusher.com
unknown
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
malicious
41.185.8.221
delivery.attempt.failure.ebbs.co.za
South Africa
malicious
18.239.94.35
static-cdn.hotjar.com
United States
104.21.234.145
cdn.lr-in.com
United States
54.209.125.179
socket-mt1-ingress-1987402783.us-east-1.elb.amazonaws.com
United States
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
13.227.219.3
script.hotjar.com
United States
104.198.23.205
prod-default.lb.logrocket.network
United States
142.250.186.164
www.google.com
United States
34.201.239.212
ingress-sticky-haproxy-mt1-912d8b7308f82d6c.elb.us-east-1.amazonaws.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States
There are 2 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
about:blank
https://delivery.attempt.failure.ebbs.co.za/public/Krg18BVSvoTOJUgjqNiHEYHkU9uE9XJb