IOC Report
https://ascot.auditboardapp.com/task-redirect/4113?source=email&CTA=taskTitleLink¬ificationId=044e55a3-481a-4a33-91c7-abbaf803b1d7&projectId=367&taskId=4113¬ificationType=WS-task-submitted

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 12:26:02 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 12:26:02 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:56:51 2023, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 12:26:02 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 12:26:02 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 12:26:02 2024, atime=Wed Sep 27 08:36:55 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (36023)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (10966), with no line terminators
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (4328), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (1045)
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (8366), with no line terminators
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (60624)
dropped
Chrome Cache Entry: 106
JSON data
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (4328), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (1053), with no line terminators
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (5004)
downloaded
Chrome Cache Entry: 110
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (63169)
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (316)
downloaded
Chrome Cache Entry: 113
JSON data
dropped
Chrome Cache Entry: 114
Unicode text, UTF-8 text, with very long lines (1749)
downloaded
Chrome Cache Entry: 115
ASCII text
downloaded
Chrome Cache Entry: 116
JSON data
dropped
Chrome Cache Entry: 117
ASCII text, with very long lines (60624)
downloaded
Chrome Cache Entry: 118
Unicode text, UTF-8 text, with very long lines (1749)
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (1045)
downloaded
Chrome Cache Entry: 120
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 121
ASCII text
dropped
Chrome Cache Entry: 122
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 123
JSON data
dropped
Chrome Cache Entry: 124
ASCII text, with very long lines (5004)
dropped
Chrome Cache Entry: 125
PNG image data, 389 x 50, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (316)
dropped
Chrome Cache Entry: 89
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 90
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 91
JSON data
downloaded
Chrome Cache Entry: 92
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
dropped
Chrome Cache Entry: 93
ASCII text, with very long lines (32129)
downloaded
Chrome Cache Entry: 94
JSON data
downloaded
Chrome Cache Entry: 95
ASCII text, with very long lines (10966), with no line terminators
dropped
Chrome Cache Entry: 96
ASCII text, with very long lines (38880)
downloaded
Chrome Cache Entry: 97
JSON data
downloaded
Chrome Cache Entry: 98
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 99
PNG image data, 389 x 50, 8-bit/color RGBA, non-interlaced
dropped
There are 35 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2124,i,8935729765929553251,3875744150044292695,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ascot.auditboardapp.com/task-redirect/4113?source=email&CTA=taskTitleLink&notificationId=044e55a3-481a-4a33-91c7-abbaf803b1d7&projectId=367&taskId=4113&notificationType=WS-task-submitted"

URLs

Name
IP
Malicious
https://ascot.auditboardapp.com/task-redirect/4113?source=email&CTA=taskTitleLink&notificationId=044e55a3-481a-4a33-91c7-abbaf803b1d7&projectId=367&taskId=4113&notificationType=WS-task-submitted
malicious
https://github.com/getsentry/sentry-javascript/issues/2286
unknown
https://github.com/jserz/js_piece/blob/master/DOM/ChildNode/remove()/remove().md
unknown
https://github.com/GoogleChrome/web-vitals/issues/383
unknown
http://wonko.com/post/html-escaping)
unknown
https://api.emberjs.com/ember/release/functions/rsvp/hashSettled).
unknown
https://codepen.io/snewcomer/pen/VwWMxwW
unknown
https://api.jqueryui.com/category/theming/
unknown
https://github.com/emberjs/data/blob/a4bf1426683073462ba351067b8f6a46141f6bbf/packages/schema-record
unknown
https://github.com/feross/buffer/pull/97
unknown
https://github.com/unicode-org/icu/blob/af7ed1f6d2298013dc303628438ec4abe1f16479/icu4c/source/common
unknown
https://github.com/getsentry/sentry-javascript/issues/6880
unknown
https://stackoverflow.com/questions/23191918/peformance-getentries-and-negative-duration-display
unknown
http://www.unicode.org/reports/tr35/tr35-31/tr35-dates.html#Date_Format_tokens
unknown
https://github.com/getsentry/sentry/blob/9f08305e09866c8bd6d0c24f5b0aabdd7dd6c59c/src/sentry/lang/ja
unknown
https://goo.gl/Qwc9u4
unknown
https://webidl.spec.whatwg.org/#es-DOMException-specialness
unknown
https://web.dev/articles/lcp#what_is_a_good_lcp_score
unknown
https://github.com/getsentry/sentry-javascript/issues/8935
unknown
https://twitter.com/alexandereardon/status/1732189803754713424
unknown
http://www.ecma-international.org/ecma-262/7.0/#sec-function.prototype.apply).
unknown
https://github.com/commonmark/cmark/issues/178#issuecomment-270417442
unknown
https://rbuckton.github.io/reflect-metadata/#ordinarymetadatakeys
unknown
https://auditboard.slack.com/archives/C05RAG6V5QE).
unknown
https://github.com/popperjs/popper-core/issues/837
unknown
https://github.com/GoogleChrome/web-vitals/issues/137
unknown
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Error/cause
unknown
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Promise/race).
unknown
https://unicode-org.github.io/icu/userguide/format_parse/numbers/skeletons.html#integer-width
unknown
https://github.com/microsoft/tabster/tree/master/tests
unknown
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Math/round#Decimal_
unknown
https://github.com/markdown-it/markdown-it/blob/master/lib/renderer.mjs).
unknown
https://mdn.io/clearTimeout).
unknown
https://openjsf.org/
unknown
https://apps.stag2.amplitude.com
unknown
https://ascot.auditboardapp.com/assets/vendor-032265e93a1013da935dc4761b02356c.js
76.223.78.180
https://github.com/getsentry/sentry-javascript/pull/8737#discussion_r1285719172
unknown
https://github.com/emberjs/data/)
unknown
http://momentjs.com/guides/#/warnings/zone/
unknown
https://github.com/microsoft/TypeScript/issues/28357
unknown
http://docs.closure-library.googlecode.com/git/closure_goog_date_date.js.source.html
unknown
https://bugs.chromium.org/p/v8/issues/detail?id=90
unknown
https://github.com/markdown-it/markdown-it/blob/master/lib/presets/commonmark.mjs)
unknown
http://cordova.apache.org))
unknown
http://powerbi.com/product/schema#identity
unknown
http://jsperf.com/diacritics/18
unknown
https://ember-concurrency.com/docs/v4-upgrade
unknown
https://github.com/date-fns/date-fns/blob/master/docs/upgradeGuide.md#string-arguments
unknown
https://sentry.io/for/session-replay/).
unknown
http://stackoverflow.com/questions/105034/how-to-create-a-guid-uuid-in-javascript/2117523#2117523
unknown
https://emberjs.com)
unknown
https://github.com/embroider-build/ember-auto-import/pull/512
unknown
https://html.spec.whatwg.org/multipage/dnd.html#drag-and-drop-processing-model
unknown
http://ecma-international.org/ecma-262/7.0/#sec-properties-of-the-map-prototype-object)
unknown
https://github.com/zertosh/invariant/blob/master/invariant.js#L46
unknown
https://github.com/mdn/content/issues/4713
unknown
https://github.com/unicode-org/icu/blob/master/docs/userguide/format_parse/numbers/skeletons.md#skel
unknown
https://web.dev/articles/fcp#what_is_a_good_fcp_score
unknown
https://github.com/markdown-it/markdown-it/blob/master/lib/rules_core/linkify.mjs)
unknown
https://tools.ietf.org/html/rfc3986#appendix-B
unknown
http://underscorejs.org/LICENSE
unknown
http://ecma-international.org/ecma-262/7.0/#sec-ecmascript-function-objects-call-thisargument-argume
unknown
https://web.dev/articles/fcp)
unknown
https://cdn.amplitude.com/libs/visual-tagging-selector-1.0.0-alpha.js.gz
unknown
https://web.dev/articles/ttfb#what_is_a_good_ttfb_score
unknown
https://github.com/emberjs/ember.js/blob/master/packages/%40ember/service/index.js#L66-L74
unknown
http://momentjs.com/timezone/docs/#/data-loading/.
unknown
https://api2.amplitude.com/2/httpapi
unknown
http://jsonapi.org/format/#document-links)
unknown
https://ascot.auditboardapp.com/assets/v2/auditboard-logo-a4eb1680b732ff0d34bda957c99b3a18.png
76.223.78.180
https://api.emberjs.com/ember/release/functions/rsvp/allSettled).
unknown
https://tc39.github.io/ecma262/#sec-ecmascript-language-types-null-type
unknown
https://github.com/getsentry/sentry-javascript/issues/5459
unknown
https://developer.mozilla.org/en-US/docs/Web/API/MediaDevices/getDisplayMedia
unknown
http://momentjs.com/guides/#/warnings/min-max/
unknown
https://develop.sentry.dev/sdk/metrics/#normalization
unknown
https://github.com/caridy/intl-datetimeformat-pattern/blob/master/index.js
unknown
https://npms.io/search?q=ponyfill.
unknown
https://jqueryui.com
unknown
http://danml.com/download.html
unknown
http://powerbi.com/product/schema#visualSelector
unknown
https://html.spec.whatwg.org/multipage/custom-elements.html#valid-custom-element-name
unknown
http://peter.michaux.ca/articles/lazy-function-definition-pattern)
unknown
https://github.com/microsoft/tabster/blob/ad23b8ca20d8b0c720aecd3bc439d630597962ad/src/State/Focused
unknown
http://commonmark.org/)
unknown
https://hertzen.com
unknown
https://github.com/wouter2203/fuzzy-search
unknown
https://github.com/GoogleChrome/web-vitals/issues/14
unknown
http://ecma-international.org/ecma-262/7.0/#sec-tolength).
unknown
https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/FinalizationRegistr
unknown
https://github.com/getsentry/sentry-javascript/issues/1168
unknown
https://github.com/getsentry/sentry-javascript/issues/3344
unknown
https://kb.acronis.com/content/39790
unknown
https://github.com/emberjs/data/tree/main/packages/adapter)
unknown
https://github.com/markdown-it/markdown-it/issues/1000
unknown
https://mdn.io/Number/isFinite).
unknown
http://www.jacklmoore.com/autosize
unknown
https://lodash.com/custom-builds).
unknown
https://github.com/getsentry/raven-js/issues/1233
unknown
https://ascot.auditboardapp.com/assets/chunk.339.3da07ca1179e7faaffbe.css
76.223.78.180
https://github.com/getsentry/sentry-javascript/issues/7813
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ascot.auditboardapp.com
76.223.78.180
malicious
clientstream-ga.launchdarkly.com
15.197.213.252
www.google.com
142.250.185.228
events.launchdarkly.com
44.196.125.45
fp2e7a.wpc.phicdn.net
192.229.221.95
o977643.ingest.sentry.io
34.120.195.249
clientstream.launchdarkly.com
unknown
app.launchdarkly.com
unknown

IPs

IP
Domain
Country
Malicious
76.223.78.180
ascot.auditboardapp.com
United States
malicious
142.250.185.228
www.google.com
United States
44.196.125.45
events.launchdarkly.com
United States
192.168.2.9
unknown
unknown
15.197.213.252
clientstream-ga.launchdarkly.com
United States
239.255.255.250
unknown
Reserved
75.2.90.152
unknown
United States
34.120.195.249
o977643.ingest.sentry.io
United States

DOM / HTML

URL
Malicious
https://ascot.auditboardapp.com/login
malicious
https://ascot.auditboardapp.com/task-redirect/4113?source=email&CTA=taskTitleLink&notificationId=044e55a3-481a-4a33-91c7-abbaf803b1d7&projectId=367&taskId=4113&notificationType=WS-task-submitted