IOC Report
https://cn4vl04.na1.hubspotlinks.com/Ctc/W1+113/cN4Vl04/VXgpzD5GgzF9W9ldFGR5PPVDWW3LfLlX5mzMv_N5XFYmH3m2ndW7lCdLW6lZ3nZW7ndT6k3g-0rkN3NMnGPksg33W8XlBqp2_dLJbW2pFZS53LKY8HW199Lcr8Pn9YLW4wSWXc2CD2vLW7m6Dnk7P_dMyW3ct7wn5z2HJtW93K1pd2sY21dW4xJBHc719W94W5Ll2J96vkgpYW2lfMJk97177mW1Ypm_Z70G8fMN3w4rW4xCZ4tW

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 63
ASCII text, with very long lines (62749)
downloaded
Chrome Cache Entry: 64
Unicode text, UTF-8 text, with very long lines (65327)
downloaded
Chrome Cache Entry: 65
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 67
ASCII text, with very long lines (539)
dropped
Chrome Cache Entry: 68
HTML document, ASCII text, with very long lines (1150)
dropped
Chrome Cache Entry: 69
Unicode text, UTF-8 text, with very long lines (57940)
downloaded
Chrome Cache Entry: 70
Web Open Font Format (Version 2), TrueType, length 33092, version 1.0
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 72
HTML document, Unicode text, UTF-8 text, with very long lines (1183)
downloaded
Chrome Cache Entry: 73
ASCII text
downloaded
Chrome Cache Entry: 74
HTML document, ASCII text, with very long lines (1150)
downloaded
Chrome Cache Entry: 75
ASCII text, with very long lines (539)
downloaded
Chrome Cache Entry: 76
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 77
ASCII text, with very long lines (6187)
dropped
Chrome Cache Entry: 78
JSON data
downloaded
Chrome Cache Entry: 79
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 80
JSON data
dropped
Chrome Cache Entry: 81
HTML document, ASCII text, with very long lines (1150)
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (62749)
dropped
Chrome Cache Entry: 83
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 84
ASCII text, with very long lines (6187)
downloaded
Chrome Cache Entry: 85
ASCII text, with very long lines (3067)
downloaded
Chrome Cache Entry: 86
ASCII text, with very long lines (3067)
dropped
Chrome Cache Entry: 87
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 88
Unicode text, UTF-8 text, with very long lines (65327)
dropped
Chrome Cache Entry: 89
Unicode text, UTF-8 text, with very long lines (57940)
dropped
Chrome Cache Entry: 90
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 92
ASCII text, with very long lines (65536), with no line terminators
dropped
There are 21 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2128 --field-trial-handle=1976,i,10266772572792055160,15789666534126017195,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://cn4vl04.na1.hubspotlinks.com/Ctc/W1+113/cN4Vl04/VXgpzD5GgzF9W9ldFGR5PPVDWW3LfLlX5mzMv_N5XFYmH3m2ndW7lCdLW6lZ3nZW7ndT6k3g-0rkN3NMnGPksg33W8XlBqp2_dLJbW2pFZS53LKY8HW199Lcr8Pn9YLW4wSWXc2CD2vLW7m6Dnk7P_dMyW3ct7wn5z2HJtW93K1pd2sY21dW4xJBHc719W94W5Ll2J96vkgpYW2lfMJk97177mW1Ypm_Z70G8fMN3w4rW4xCZ4tW1PkXj96WYZ54W26rxvm2h-1k4Vgjq371HFNDzW68PSvt58-p30W8v2Lsy3pf5v6W7XjnGX2RKKZ1VvmWfS64Q15TW6lVY3l4w5lcgW6ypPRG1YGbFtN8RhHblg1vsgf1VLhsx04"

URLs

Name
IP
Malicious
https://cn4vl04.na1.hubspotlinks.com/Ctc/W1+113/cN4Vl04/VXgpzD5GgzF9W9ldFGR5PPVDWW3LfLlX5mzMv_N5XFYmH3m2ndW7lCdLW6lZ3nZW7ndT6k3g-0rkN3NMnGPksg33W8XlBqp2_dLJbW2pFZS53LKY8HW199Lcr8Pn9YLW4wSWXc2CD2vLW7m6Dnk7P_dMyW3ct7wn5z2HJtW93K1pd2sY21dW4xJBHc719W94W5Ll2J96vkgpYW2lfMJk97177mW1Ypm_Z70G8fMN3w4rW4xCZ4tW1PkXj96WYZ54W26rxvm2h-1k4Vgjq371HFNDzW68PSvt58-p30W8v2Lsy3pf5v6W7XjnGX2RKKZ1VvmWfS64Q15TW6lVY3l4w5lcgW6ypPRG1YGbFtN8RhHblg1vsgf1VLhsx04
https://cn4vl04.na1.hubspotlinks.com/Ctc/W1+113/cN4Vl04/VXgpzD5GgzF9W9ldFGR5PPVDWW3LfLlX5mzMv_N5XFYmH3m2ndW7lCdLW6lZ3nZW7ndT6k3g-0rkN3NMnGPksg33W8XlBqp2_dLJbW2pFZS53LKY8HW199Lcr8Pn9YLW4wSWXc2CD2vLW7m6Dnk7P_dMyW3ct7wn5z2HJtW93K1pd2sY21dW4xJBHc719W94W5Ll2J96vkgpYW2lfMJk97177mW1Ypm_Z70G8fMN3w4rW4xCZ4tW1PkXj96WYZ54W26rxvm2h-1k4Vgjq371HFNDzW68PSvt58-p30W8v2Lsy3pf5v6W7XjnGX2RKKZ1VvmWfS64Q15TW6lVY3l4w5lcgW6ypPRG1YGbFtN8RhHblg1vsgf1VLhsx04
104.18.10.201
https://forms-na1.hubspot.com/submissions-validation/v1/validate/6470244/73aa6621-a6ba-433c-82be-8c3331164d6b
104.16.117.116
https://forms-na1.hsforms.com/embed/v3/counters.gif?key=forms-embed-v3-RENDER_SUCCESS&count=1
104.18.80.204
https://cn4vl04.na1.hubspotlinks.com/events/public/v1/encoded/track/tc/W1
unknown
http://www.hubspot.com
unknown
https://js-na1.hs-scripts.com/6470244.js
unknown
https://track.hubspot.com/__ptq.gif?k=18&fi=73aa6621-a6ba-433c-82be-8c3331164d6b&fci=b4be8cfc-1f89-4895-ac7c-705fe86239f5&ft=0&sd=1280x1024&cd=24-bit&cs=UTF-8&ln=en-us&bfp=471034161&v=1.1&a=6470244&ccu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0&pu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0%3Futm_medium%3Demail%26_hsenc%3Dp2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY%26_hsmi%3D98333125%26utm_content%3D98333125%26utm_source%3Dhs_automation&t=Form&cts=1729842776158&rv=1&vi=00606f1bca581039f3a401635d40f407&nc=true&ce=false&pt=1&cc=1
104.16.117.116
https://static.hsappstatic.net/forms-submission-pages/static-1.5071/bundles/share-legacy.js
104.17.172.91
https://js.hs-analytics.net/analytics/1729842600000/6470244.js
104.16.160.168
https://track.hubspot.com/__ptq.gif?k=15&fi=73aa6621-a6ba-433c-82be-8c3331164d6b&fci=b4be8cfc-1f89-4895-ac7c-705fe86239f5&ft=0&sd=1280x1024&cd=24-bit&cs=UTF-8&ln=en-us&bfp=471034161&v=1.1&a=6470244&ccu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0&pu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0%3Futm_medium%3Demail%26_hsenc%3Dp2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY%26_hsmi%3D98333125%26utm_content%3D98333125%26utm_source%3Dhs_automation&t=Form&cts=1729842749664&vi=b3c42d6dddf37c4abbebfab864b59b12&nc=true&ce=false&pt=1&cc=0
104.16.117.116
https://www.storage24.com/de-de/datenschutzerkl%C3%A4rung
unknown
https://js.usemessages.com/conversations-embed.js
104.16.75.142
https://js.hsadspixel.net/fb.js
104.17.223.152
https://js.hsleadflows.net/leadflows.js
104.18.140.17
https://track.hubspot.com/__ptq.gif?k=17&fi=73aa6621-a6ba-433c-82be-8c3331164d6b&fci=b4be8cfc-1f89-4895-ac7c-705fe86239f5&ft=0&sd=1280x1024&cd=24-bit&cs=UTF-8&ln=en-us&bfp=471034161&v=1.1&a=6470244&ccu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0&pu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0%3Futm_medium%3Demail%26_hsenc%3Dp2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY%26_hsmi%3D98333125%26utm_content%3D98333125%26utm_source%3Dhs_automation&t=Form&cts=1729842749665&vi=b3c42d6dddf37c4abbebfab864b59b12&nc=true&ce=false&pt=1&cc=0
104.16.117.116
https://share.hsforms.com/favicon.ico
104.19.175.188
https://forms.hsforms.com/embed/v3/counters.gif?key=collected-forms-embed-js-form-bind&count=1
104.19.175.188
https://js.hs-banner.com/cookie-banner-public/v1
unknown
https://js.hs-banner.com/cookie-banner-public/v1/activity/view
172.64.147.16
https://local.hsappstatic.net/forms-embed/static/bundles/project-v3.js
unknown
https://a.nel.cloudflare.com/report/v4?s=XMhKVx1wigjtDhHaS3HP2AN%2B0NmeWrD%2Fuu3SGd8GWS9rfPY%2BeeLbrSRwENJuz97OS%2FjHLZVP7PUACPJbCEV%2FDbpHi96q7FQNUqROCbQQ9HtPVPtEgnu6K%2FvaIx3z%2FdahxWiL3R%2Fdnw%3D%3D
35.190.80.1
https://js.hs-scripts.com/6470244.js
104.16.138.209
https://js.hsforms.net/forms/embed/v3.js
104.18.142.119
https://js.hscollectedforms.net/collectedforms.js
104.16.108.254
https://www.storage24.com/de-de/finde-deinen-standort
unknown
http://hubs.ly/H0702_H0
unknown
https://js.hubspot.com/web-interactives-embed.js
104.16.118.116
https://forms-na1.hsforms.com/embed/v3/counters.gif?key=forms-embed-v3-DEFINITION_SUCCESS&count=1
104.18.80.204
https://js.hsformsqa.net/success-green.svg);width:130px;height:201px;padding-top:28px;margin:0
unknown
https://share.hsforms.com/1c6pmIaa6QzyCvowzMRZNaw3uoh0?utm_medium=email&_hsenc=p2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY&_hsmi=98333125&utm_content=98333125&utm_source=hs_automation
https://js.hs-banner.com/6470244.js
172.64.147.16
https://forms.hsforms.com/embed/v3/form/6470244/73aa6621-a6ba-433c-82be-8c3331164d6b/json?hs_static_app=forms-embed&hs_static_app_version=1.6227&X-HubSpot-Static-App-Info=forms-embed-1.6227
104.19.175.188
https://track.hubspot.com/__ptq.gif?k=29&sd=1280x1024&cd=24-bit&cs=UTF-8&ln=en-us&bfp=471034161&v=1.1&a=6470244&ccu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0&pu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0%3Futm_medium%3Demail%26_hsenc%3Dp2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY%26_hsmi%3D98333125%26utm_content%3D98333125%26utm_source%3Dhs_automation&t=Form&cts=1729842762610&rv=1&vi=00606f1bca581039f3a401635d40f407&nc=true&ce=false&pt=1&cc=1
104.16.117.116
https://www.storage24.com/de-de/?redtn=true
unknown
https://track.hubspot.com/__ptq.gif?k=1&sd=1280x1024&cd=24-bit&cs=UTF-8&ln=en-us&bfp=471034161&v=1.1&a=6470244&ccu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0&pu=https%3A%2F%2Fshare.hsforms.com%2F1c6pmIaa6QzyCvowzMRZNaw3uoh0%3Futm_medium%3Demail%26_hsenc%3Dp2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY%26_hsmi%3D98333125%26utm_content%3D98333125%26utm_source%3Dhs_automation&t=Form&cts=1729842749658&vi=b3c42d6dddf37c4abbebfab864b59b12&nc=true&ce=false&pt=1&cc=0
104.16.117.116
https://a.nel.cloudflare.com/report/v4?s=hvX5RUWEDdQZHUXDm7gFsWZg2oSzegp%2FSGOsnxonPVl6BWwTA9K6oDBvqJe5O1RUrEtp7lxhQ3ulaONhGuXsr9wvH6DIJsHD0C00p75oSJkPQEXBOGaT%2FBuVZJxDbtuxoblmBmqrcQ%3D%3D
35.190.80.1
https://www.storage24.com/de-de/
unknown
https://js.hs-banner.com/cookie-banner-public/v1/activity/click
172.64.147.16
https://cn4vl04.na1.hubspotlinks.com/events/public/v1/encoded/track/tc/W1+113/cN4Vl04/VXgpzD5GgzF9W9ldFGR5PPVDWW3LfLlX5mzMv_N5XFYmH3m2ndW7lCdLW6lZ3nZW7ndT6k3g-0rkN3NMnGPksg33W8XlBqp2_dLJbW2pFZS53LKY8HW199Lcr8Pn9YLW4wSWXc2CD2vLW7m6Dnk7P_dMyW3ct7wn5z2HJtW93K1pd2sY21dW4xJBHc719W94W5Ll2J96vkgpYW2lfMJk97177mW1Ypm_Z70G8fMN3w4rW4xCZ4tW1PkXj96WYZ54W26rxvm2h-1k4Vgjq371HFNDzW68PSvt58-p30W8v2Lsy3pf5v6W7XjnGX2RKKZ1VvmWfS64Q15TW6lVY3l4w5lcgW6ypPRG1YGbFtN8RhHblg1vsgf1VLhsx04?_ud=38c51d23-cc08-444b-9d78-6ba90feffc26&_jss=1&_fl=8&_pl=5&_hc=4&_lg=en-US,en&_plt=Win32&_scr=1280,1024
104.18.10.201
https://forms.hscollectedforms.net/collected-forms/v1/config/json?portalId=6470244&utk=
104.16.111.254
There are 30 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
forms.hsforms.com
104.19.175.188
js.hs-banner.com
172.64.147.16
static.hsappstatic.net
104.17.172.91
a.nel.cloudflare.com
35.190.80.1
cn4vl04.na1.hubspotlinks.com
104.18.10.201
js.hubspot.com
104.16.118.116
s-part-0017.t-0009.t-msedge.net
13.107.246.45
js.hsadspixel.net
104.17.223.152
js.hs-analytics.net
104.16.160.168
s-part-0039.t-0009.t-msedge.net
13.107.246.67
fp2e7a.wpc.phicdn.net
192.229.221.95
js.hsleadflows.net
104.18.140.17
forms-na1.hubspot.com
104.16.117.116
track.hubspot.com
104.16.117.116
forms-na1.hsforms.com
104.18.80.204
js.hsforms.net
104.18.142.119
forms.hscollectedforms.net
104.16.111.254
js.hs-scripts.com
104.16.138.209
www.google.com
216.58.206.36
js.usemessages.com
104.16.75.142
share.hsforms.com
104.19.175.188
js.hscollectedforms.net
104.16.108.254
There are 12 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.18.139.17
unknown
United States
104.19.175.188
forms.hsforms.com
United States
104.18.10.201
cn4vl04.na1.hubspotlinks.com
United States
192.168.2.4
unknown
unknown
216.58.206.36
www.google.com
United States
104.16.118.116
js.hubspot.com
United States
104.16.75.142
js.usemessages.com
United States
192.168.2.23
unknown
unknown
172.64.147.16
js.hs-banner.com
United States
104.16.107.254
unknown
United States
104.17.172.91
static.hsappstatic.net
United States
104.16.160.168
js.hs-analytics.net
United States
104.16.111.254
forms.hscollectedforms.net
United States
104.16.138.209
js.hs-scripts.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
104.18.140.17
js.hsleadflows.net
United States
104.18.80.204
forms-na1.hsforms.com
United States
104.16.108.254
js.hscollectedforms.net
United States
104.18.141.119
unknown
United States
239.255.255.250
unknown
Reserved
192.168.2.13
unknown
unknown
104.17.173.91
unknown
United States
104.16.141.209
unknown
United States
104.17.223.152
js.hsadspixel.net
United States
104.16.117.116
forms-na1.hubspot.com
United States
104.18.142.119
js.hsforms.net
United States
There are 16 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://share.hsforms.com/1c6pmIaa6QzyCvowzMRZNaw3uoh0?utm_medium=email&_hsenc=p2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY&_hsmi=98333125&utm_content=98333125&utm_source=hs_automation
https://share.hsforms.com/1c6pmIaa6QzyCvowzMRZNaw3uoh0?utm_medium=email&_hsenc=p2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY&_hsmi=98333125&utm_content=98333125&utm_source=hs_automation
https://share.hsforms.com/1c6pmIaa6QzyCvowzMRZNaw3uoh0?utm_medium=email&_hsenc=p2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY&_hsmi=98333125&utm_content=98333125&utm_source=hs_automation
https://share.hsforms.com/1c6pmIaa6QzyCvowzMRZNaw3uoh0?utm_medium=email&_hsenc=p2ANqtz-8oVA7LWVCJUKcg00S1rSoJiM-NNhieg6MQuO8FziFHgqlG91cHlxTxA34F2MWyp_-we1fyevUXaNU4ADOXkKSuScBSbggrNJBw2qCD5zjIoKbgjJY&_hsmi=98333125&utm_content=98333125&utm_source=hs_automation