IOC Report
http://url960.aceeduconsult.com/ls/click?upn=u001.LUpianUM71xe7PV7wDA6i1kcuy38W249FfPzE-2Fn4iGArrL0MQBCUZHFEzmfBrwW7hf5h8aNQUml0OSIHqpXf0LMpnaTL-2BzYU1WV-2BSTu4-2FYE-3DnWBx_C2kZwAnfGwUSqF5D87NbxLVpuF-2FUu77KiRgkAhE5NE4LxNdD8Vk-2BBXjUuKxXLIa0fIDZmJqQTdTMUWaKg74qY7H1042trEdUOL1Ty-2B4ikz6aamPgX0YPKifSg

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 54
gzip compressed data, was "main.css", last modified: Tue Oct 22 17:17:46 2024, from Unix, original size modulo 2^32 15106
downloaded
Chrome Cache Entry: 55
PNG image data, 65 x 76, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 56
ASCII text, with very long lines (44597)
downloaded
Chrome Cache Entry: 57
PNG image data, 65 x 76, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 58
HTML document, ASCII text
downloaded
Chrome Cache Entry: 59
HTML document, ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 60
HTML document, ASCII text, with very long lines (1308), with CRLF line terminators
downloaded
Chrome Cache Entry: 61
PNG image data, 225 x 225, 4-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 62
ASCII text, with very long lines (44597)
dropped
Chrome Cache Entry: 63
ASCII text, with very long lines (47531)
dropped
Chrome Cache Entry: 64
gzip compressed data, was "main.bundle.js", last modified: Tue Oct 22 17:17:46 2024, from Unix, original size modulo 2^32 141304
dropped
Chrome Cache Entry: 65
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (47531)
downloaded
Chrome Cache Entry: 67
HTML document, ASCII text, with very long lines (1871)
downloaded
Chrome Cache Entry: 68
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 69
gzip compressed data, was "main.bundle.js", last modified: Tue Oct 22 17:17:46 2024, from Unix, original size modulo 2^32 141304
downloaded
Chrome Cache Entry: 70
JPEG image data, baseline, precision 8, 756x427, components 3
dropped
Chrome Cache Entry: 71
PNG image data, 225 x 225, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 72
JPEG image data, baseline, precision 8, 756x427, components 3
downloaded
Chrome Cache Entry: 73
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 74
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 75
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
There are 13 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2552 --field-trial-handle=2516,i,10547701594380448541,10932106283826123114,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://url960.aceeduconsult.com/ls/click?upn=u001.LUpianUM71xe7PV7wDA6i1kcuy38W249FfPzE-2Fn4iGArrL0MQBCUZHFEzmfBrwW7hf5h8aNQUml0OSIHqpXf0LMpnaTL-2BzYU1WV-2BSTu4-2FYE-3DnWBx_C2kZwAnfGwUSqF5D87NbxLVpuF-2FUu77KiRgkAhE5NE4LxNdD8Vk-2BBXjUuKxXLIa0fIDZmJqQTdTMUWaKg74qY7H1042trEdUOL1Ty-2B4ikz6aamPgX0YPKifSgbmdnoJ9QNdI7-2Fj5HU9YtlUVfM2hhaIRlcN5LDyRrfABDYCmE6HCezIFJke-2Bw8MgqKR8oZe3x0bNQ5ip4gqKVt9OZvtTXtI2W19VoVZDzbdeDK4WD-2F3HaEv25gNxrltbLRhf8V-2BO7eWR3mjaJT30K-2BcVCwIlJZO7lziFom1TeAFneOePh2rvH67eyoHyRuDs7uhJ58UvSbL-2F5WGOZFqHf1Uoqm5u1BuusL-2F4yIoUS3Zge-2Bhwb2SPTTZrQp-2B3YQW62QJEBscu8XAGBtmCTNO-2FGrj9S-2BwtsmLluvkoUx0cXtIZxgyjwWcDifMxEpsoupBhIu0vHgSwbA5Jlj-2FdPy-2B0yhvKMBxhOgsBuXNzAVSfF8HuZvD5iWXinRKWqhNg1QpvfMK5Why8PnI5FwIsgrY7RxMkEbcDdf0VL1a7dM3RDh9LkpekDjtHu-2F4c-2FsI73UIfVUG4-2BbcH5VEOHzkCenTbIl-2BeYnL2jw9k-2Bt-2BAEZMQZavCq5q7Io2kchrzK3tu9Vj43TTv0K790k8tA4okR0vSuH0WvhSIZBs2e3uKgx9FK2SAr5JJzheB6cW2OXdbGgfDGPwGYkvJqNCBixLi9dWacb8fBed5RjA3p1JUsS79RbxF-2FaSjDqEr3OTeFx3WgBthSzcSYPpiE9ha00gB-2FAVdpFU8eOGGhrdGc6OgU4OZhDsRkN5FNMpRj3pgHOHQ6dkJW4RJx1-2B1Om8bljV3ruWQytV5mwg68-2FvnkkpkZM63omm27kalKxw-3D"

URLs

Name
IP
Malicious
http://url960.aceeduconsult.com/ls/click?upn=u001.LUpianUM71xe7PV7wDA6i1kcuy38W249FfPzE-2Fn4iGArrL0MQBCUZHFEzmfBrwW7hf5h8aNQUml0OSIHqpXf0LMpnaTL-2BzYU1WV-2BSTu4-2FYE-3DnWBx_C2kZwAnfGwUSqF5D87NbxLVpuF-2FUu77KiRgkAhE5NE4LxNdD8Vk-2BBXjUuKxXLIa0fIDZmJqQTdTMUWaKg74qY7H1042trEdUOL1Ty-2B4ikz6aamPgX0YPKifSgbmdnoJ9QNdI7-2Fj5HU9YtlUVfM2hhaIRlcN5LDyRrfABDYCmE6HCezIFJke-2Bw8MgqKR8oZe3x0bNQ5ip4gqKVt9OZvtTXtI2W19VoVZDzbdeDK4WD-2F3HaEv25gNxrltbLRhf8V-2BO7eWR3mjaJT30K-2BcVCwIlJZO7lziFom1TeAFneOePh2rvH67eyoHyRuDs7uhJ58UvSbL-2F5WGOZFqHf1Uoqm5u1BuusL-2F4yIoUS3Zge-2Bhwb2SPTTZrQp-2B3YQW62QJEBscu8XAGBtmCTNO-2FGrj9S-2BwtsmLluvkoUx0cXtIZxgyjwWcDifMxEpsoupBhIu0vHgSwbA5Jlj-2FdPy-2B0yhvKMBxhOgsBuXNzAVSfF8HuZvD5iWXinRKWqhNg1QpvfMK5Why8PnI5FwIsgrY7RxMkEbcDdf0VL1a7dM3RDh9LkpekDjtHu-2F4c-2FsI73UIfVUG4-2BbcH5VEOHzkCenTbIl-2BeYnL2jw9k-2Bt-2BAEZMQZavCq5q7Io2kchrzK3tu9Vj43TTv0K790k8tA4okR0vSuH0WvhSIZBs2e3uKgx9FK2SAr5JJzheB6cW2OXdbGgfDGPwGYkvJqNCBixLi9dWacb8fBed5RjA3p1JUsS79RbxF-2FaSjDqEr3OTeFx3WgBthSzcSYPpiE9ha00gB-2FAVdpFU8eOGGhrdGc6OgU4OZhDsRkN5FNMpRj3pgHOHQ6dkJW4RJx1-2B1Om8bljV3ruWQytV5mwg68-2FvnkkpkZM63omm27kalKxw-3D
malicious
https://teamspdf.ubpages.com/microsoft-apps-adobe-pdf-viewer/
malicious
https://baignoireaporue.com/nsvrD/#L
malicious
https://teamspdf.ubpages.com/microsoft-apps-adobe-pdf-viewer/clkn/https/pms.usmmycity.com/local/arull.php?7096797967704b536932307464505373784d7a3876504c45704e4c4d67764b6b335653383750316338724c69747930516341
172.64.146.119
malicious
http://url960.aceeduconsult.com/ls/click?upn=u001.LUpianUM71xe7PV7wDA6i1kcuy38W249FfPzE-2Fn4iGArrL0MQBCUZHFEzmfBrwW7hf5h8aNQUml0OSIHqpXf0LMpnaTL-2BzYU1WV-2BSTu4-2FYE-3DnWBx_C2kZwAnfGwUSqF5D87NbxLVpuF-2FUu77KiRgkAhE5NE4LxNdD8Vk-2BBXjUuKxXLIa0fIDZmJqQTdTMUWaKg74qY7H1042trEdUOL1Ty-2B4ikz6aamPgX0YPKifSgbmdnoJ9QNdI7-2Fj5HU9YtlUVfM2hhaIRlcN5LDyRrfABDYCmE6HCezIFJke-2Bw8MgqKR8oZe3x0bNQ5ip4gqKVt9OZvtTXtI2W19VoVZDzbdeDK4WD-2F3HaEv25gNxrltbLRhf8V-2BO7eWR3mjaJT30K-2BcVCwIlJZO7lziFom1TeAFneOePh2rvH67eyoHyRuDs7uhJ58UvSbL-2F5WGOZFqHf1Uoqm5u1BuusL-2F4yIoUS3Zge-2Bhwb2SPTTZrQp-2B3YQW62QJEBscu8XAGBtmCTNO-2FGrj9S-2BwtsmLluvkoUx0cXtIZxgyjwWcDifMxEpsoupBhIu0vHgSwbA5Jlj-2FdPy-2B0yhvKMBxhOgsBuXNzAVSfF8HuZvD5iWXinRKWqhNg1QpvfMK5Why8PnI5FwIsgrY7RxMkEbcDdf0VL1a7dM3RDh9LkpekDjtHu-2F4c-2FsI73UIfVUG4-2BbcH5VEOHzkCenTbIl-2BeYnL2jw9k-2Bt-2BAEZMQZavCq5q7Io2kchrzK3tu9Vj43TTv0K790k8tA4okR0vSuH0WvhSIZBs2e3uKgx9FK2SAr5JJzheB6cW2OXdbGgfDGPwGYkvJqNCBixLi9dWacb8fBed5RjA3p1JUsS79RbxF-2FaSjDqEr3OTeFx3WgBthSzcSYPpiE9ha00gB-2FAVdpFU8eOGGhrdGc6OgU4OZhDsRkN5FNMpRj3pgHOHQ6dkJW4RJx1-2B1Om8bljV3ruWQytV5mwg68-2FvnkkpkZM63omm27kalKxw-3D
167.89.118.109
malicious
https://baignoireaporue.com/nsvrD/
188.114.97.3
https://pms.usmmycity.com/assets/img/logo.png
unknown
https://a.nel.cloudflare.com/report/v4?s=hnv2MsuKMZIp%2F6ysTtZUfXcCNEJtFlbRUZoJFnBoCQHhZbtYhSwUHFNGcxW6dLwEKGY8W%2Fp1r8Qxs8dM6PYwCxat1lcC5IFj%2F544g6CvFjV%2BKrsK37A3iU7ES1us9Zy7DAeQ6PZt
35.190.80.1
https://d9hhrg4mnvzow.cloudfront.net/teamspdf.ubpages.com/microsoft-apps-adobe-pdf-viewer/8ae81d81-image-1_10l00bv00000000000001o.jpg
3.160.156.17
https://pms.usmmycity.com/local/arull.php
https://pms.usmmycity.com/assets/js/bootstrap-datepicker.js
unknown
https://d9hhrg4mnvzow.cloudfront.net/teamspdf.ubpages.com/microsoft-apps-adobe-pdf-viewer/f48aeb78-images-2024-10-23t142851-783.png
3.160.156.17
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/2100437455:1729702684:jEfIATDHwP2kwc6-KPYz3tHBFlnd7GkPDmTjblGu_QU/8d7ad739dae42cc4/RpIImtt.zt8mDkyrwuXx.SiCSlRbl0FJ0PAYVZSb1BY-1729782071-1.1.1.1-DYEudbRhaDTfKHDH8amAQK.bn8Ph8_OSnkX6gSeYzCwQjEgHE54u_NvAzxRLIVhr
104.18.95.41
https://pms.usmmycity.com/assets/js/jquery-1.11.2.min.js
unknown
https://pms.usmmycity.com/assets/js/jcfilter.min.js
unknown
https://pms.usmmycity.com/notifications/get-accepted-collections
unknown
https://pms.usmmycity.com/assets/css/app.css
unknown
https://pms.usmmycity.com/assets/js/jquery-scrolltofixed-min.js
unknown
https://pms.usmmycity.com/assets/js/alertify.js
unknown
https://pms.usmmycity.com/assets/js/jPushMenu.js
unknown
https://teamspdf.ubpages.com/_ub/i
172.64.146.119
https://pms.usmmycity.com/assets/js/app.js
unknown
https://teamspdf.ubpages.com/_ub/static/ts/e6c35f50fd3355ae56cc4292c3ae66e2e57ced28.js
172.64.146.119
https://pms.usmmycity.com/assets/js/jquery-ui-auto.min.js
unknown
https://pms.usmmycity.com/assets/css/bootstrap-datetimepicker.css
unknown
https://builder-assets.unbounce.com/published-css/main-ebbfc5e.z.css
13.224.189.63
https://pms.usmmycity.com/notifications/get-notifications
unknown
https://pms.usmmycity.com/assets/js/classie.js
unknown
https://pms.usmmycity.com/assets/css/fileinput.css
unknown
https://pms.usmmycity.com/assets/css/bootstrap.min.css
unknown
https://challenges.cloudflare.com/turnstile/v0/g/f2bbd6738e15/api.js
104.18.95.41
https://pms.usmmycity.com/local/arull.php?7096797967704b536932307464505373784d7a3876504c45704e4c4d67764b6b335653383750316338724c69747930516341
137.59.201.126
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8d7ad739dae42cc4/1729782073781/9ac878c88372b978e23a5f8719fffa5c577d6c375cced02a4de962e23483c658/bRi4pwrTS2IMNF1
104.18.95.41
https://builder-assets.unbounce.com/published-js/main.bundle-ef43f79.z.js
13.224.189.63
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/mb7rr/0x4AAAAAAAxr63lst9lJdLB9/auto/fbE/normal/auto/
104.18.95.41
https://pms.usmmycity.com/assets/js/tableFixed.js
unknown
https://pms.usmmycity.com/save-as-homepage
unknown
https://pms.usmmycity.com/assets/js/bootstrap-multiselect.js
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8d7ad739dae42cc4/1729782073786/pukFTA2ACm6Cdwj
104.18.95.41
https://pms.usmmycity.com/login
unknown
https://pms.usmmycity.com
unknown
https://challenges.cloudflare.com/turnstile/v0/api.js
104.18.95.41
https://pms.usmmycity.com/assets/css/bootstrap-select.min.css
unknown
https://pms.usmmycity.com/assets/favicon.png
unknown
https://pms.usmmycity.com/assets/js/footable.sort.min.js
unknown
https://pms.usmmycity.com/assets/css/alertify.core.css
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=8d7ad739dae42cc4&lang=auto
104.18.95.41
https://pms.usmmycity.com/notifications/get-booked-plot-notifications
unknown
https://pms.usmmycity.com/assets/js/fileinput.js
unknown
https://app.unbounce.com/2bd667c0-ab77-4009-9687-867b825916e7
unknown
https://pms.usmmycity.com/assets/js/bootstrap.min.js
unknown
https://app.unbounce.com/8d67f185-8dec-407a-84fb-efe9dc8724a0
unknown
https://pms.usmmycity.com/assets/js/bootstrap-select.min.js
unknown
https://pms.usmmycity.com/favicon.ico
137.59.201.126
https://pms.usmmycity.com/assets/css/bootstrap-multiselect.css
unknown
https://pms.usmmycity.com/assets/css/bootstrap-datepicker.css
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1
104.18.95.41
https://baignoireaporue.com/favicon.ico
188.114.97.3
https://pms.usmmycity.com/assets/css/jquery-ui-auto.css
unknown
https://teamspdf.ubpages.com/assets/f41565e4-1959-4496-9e0d-451567d1305c/image-1.original.jpg?1729715604
172.64.146.119
http://teamspdf.ubpages.com/microsoft-apps-adobe-pdf-viewer/
unknown
https://cdnjs.cloudflare.com/ajax/libs/crypto-js/4.0.0/crypto-js.min.js
104.17.25.14
https://pms.usmmycity.com/assets/js/footable.js
unknown
There are 52 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
teamspdf.ubpages.com
172.64.146.119
d9hhrg4mnvzow.cloudfront.net
3.160.156.17
sendgrid.net
167.89.118.109
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
fp2e7a.wpc.phicdn.net
192.229.221.95
proteiqueur.ru
172.67.211.140
baignoireaporue.com
188.114.97.3
builder-assets.unbounce.com
13.224.189.63
cdnjs.cloudflare.com
104.17.25.14
challenges.cloudflare.com
104.18.95.41
www.google.com
216.58.206.68
pms.usmmycity.com
137.59.201.126
url960.aceeduconsult.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
167.89.118.109
sendgrid.net
United States
13.224.189.28
unknown
United States
137.59.201.126
pms.usmmycity.com
India
172.64.146.119
teamspdf.ubpages.com
United States
104.18.95.41
challenges.cloudflare.com
United States
192.168.2.4
unknown
unknown
216.58.206.68
www.google.com
United States
13.224.189.63
builder-assets.unbounce.com
United States
3.160.156.17
d9hhrg4mnvzow.cloudfront.net
United States
239.255.255.250
unknown
Reserved
188.114.97.3
baignoireaporue.com
European Union
35.190.80.1
a.nel.cloudflare.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://teamspdf.ubpages.com/microsoft-apps-adobe-pdf-viewer/
malicious
https://baignoireaporue.com/nsvrD/#L
malicious
https://pms.usmmycity.com/local/arull.php
https://baignoireaporue.com/nsvrD/#L
https://baignoireaporue.com/nsvrD/#L