IOC Report
http://tmllegislativeseries.org

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:43:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:43:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:43:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:43:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:43:15 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 139
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, comment: "ID:150564203", Exif Standard: [TIFF image data, big-endian, direntries=6, description=American and Texas state flags flying on the dome of the Texas State Capitol building in Austin, xresolution=182, yresolution=190, resolutionunit=2, copyright=Bigstock], baseline, precision 8, 768x432, components 3
dropped
Chrome Cache Entry: 140
ASCII text
downloaded
Chrome Cache Entry: 141
PNG image data, 8334 x 2500, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 143
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 144
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (3781), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (2964), with no line terminators
downloaded
Chrome Cache Entry: 147
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, comment: "ID:150564203", Exif Standard: [TIFF image data, big-endian, direntries=6, description=American and Texas state flags flying on the dome of the Texas State Capitol building in Austin, xresolution=182, yresolution=190, resolutionunit=2, copyright=Bigstock], baseline, precision 8, 768x432, components 3
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (30804)
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (6975), with no line terminators
downloaded
Chrome Cache Entry: 150
HTML document, Unicode text, UTF-8 text, with very long lines (10038), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 151
PNG image data, 8334 x 2500, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 152
ASCII text, with very long lines (6975), with no line terminators
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (21966), with no line terminators
downloaded
Chrome Cache Entry: 154
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (15718)
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (15718)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (48325)
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (12551), with no line terminators
downloaded
There are 17 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=2008,i,4673199221344751582,14115566352950747719,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://tmllegislativeseries.org"

URLs

Name
IP
Malicious
http://tmllegislativeseries.org
https://tmllegislativeseries.org/wp-content/uploads/2014/12/bigstock-150564203-768x432.jpg
208.109.21.251
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/components/font-icons.mi
unknown
https://schema.org/WebPage
unknown
https://tmllegislativeseries.org/wp-json/wp/v2/pages/8
unknown
https://tmllegislativeseries.org/feed/
unknown
https://schema.org/WPFooter
unknown
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/components/font-awesome.min.css?ver=4.7
208.109.21.251
https://tmllegislativeseries.org/webinars/
unknown
http://www.tml.org/
unknown
https://api.w.org/
unknown
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/unsemantic-grid.min.css?
unknown
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/components/font-awesome.
unknown
https://tmllegislativeseries.org/wp-content/uploads/2024/04/2025_TML-Legislative-Series_300x1000.png
208.109.21.251
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/mobile.min.css?ver=3.3.0
208.109.21.251
https://tmllegislativeseries.org/favicon.ico
208.109.21.251
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/style.min.css?ver=3.3.0
208.109.21.251
https://tmllegislativeseries.org/wp-content/uploads/2014/12/bigstock-150564203-1024x576.jpg
unknown
https://tmllegislativeseries.org/wp-includes/js/wp-emoji-release.min.js?ver=6.2.6
208.109.21.251
https://tmllegislativeseries.org/wp-includes/css/classic-themes.min.css?ver=6.2.6
208.109.21.251
https://schema.org/SiteNavigationElement
unknown
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/js/classList.min.js?ver=3.3.
unknown
http://tmllegislativeseries.org/
208.109.21.251
https://schema.org/CreativeWork
unknown
https://tmllegislativeseries.org/wp-json/oembed/1.0/embed?url=https%3A%2F%2Ftmllegislativeseries.org
unknown
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/js/menu.min.js?ver=3.3.0
208.109.21.251
https://tmllegislativeseries.org/xmlrpc.php?rsd
unknown
https://tmllegislativeseries.org/
https://tmllegislativeseries.org/workshop/
unknown
https://tmllegislativeseries.org/wp-includes/css/dist/block-library/style.min.css?ver=6.2.6
208.109.21.251
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/components/font-icons.min.css?ver=3.3.0
208.109.21.251
https://tmllegislativeseries.org/wp-content/themes/generatepress/assets/css/unsemantic-grid.min.css?ver=3.3.0
208.109.21.251
https://tmllegislativeseries.org/comments/feed/
unknown
https://livedashboardkit.info/track-67214820.js
104.21.83.15
https://tmllegislativeseries.org/wp-content/uploads/2014/12/bigstock-150564203.jpg
unknown
https://generatepress.com
unknown
https://tmllegislativeseries.org/registration/
unknown
https://tmllegislativeseries.org/wp-json/
unknown
https://tmllegislativeseries.org/wp-includes/images/w-logo-blue-white-bg.png
208.109.21.251
https://tmllegislativeseries.org/wp-content/uploads/2014/12/bigstock-150564203-300x169.jpg
unknown
https://tmllegislativeseries.org/wp-includes/wlwmanifest.xml
unknown
There are 30 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
tmllegislativeseries.org
208.109.21.251
livedashboardkit.info
104.21.83.15
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.186.68
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
192.168.2.5
unknown
unknown
104.21.83.15
livedashboardkit.info
United States
208.109.21.251
tmllegislativeseries.org
United States
239.255.255.250
unknown
Reserved

DOM / HTML

URL
Malicious
https://tmllegislativeseries.org/
https://tmllegislativeseries.org/