IOC Report
https://yungbucksbbq.com/portbiz/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 65
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 66
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 67
Web Open Font Format (Version 2), TrueType, length 11072, version 1.0
downloaded
Chrome Cache Entry: 68
ASCII text, with very long lines (32012)
dropped
Chrome Cache Entry: 69
ASCII text, with very long lines (8738), with no line terminators
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (32065)
dropped
Chrome Cache Entry: 72
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 73
ASCII text, with very long lines (50758)
dropped
Chrome Cache Entry: 74
ASCII text, with very long lines (32012)
downloaded
Chrome Cache Entry: 75
ASCII text, with very long lines (59825)
downloaded
Chrome Cache Entry: 76
ASCII text
downloaded
Chrome Cache Entry: 77
Web Open Font Format (Version 2), TrueType, length 11028, version 1.0
downloaded
Chrome Cache Entry: 78
HTML document, ASCII text
downloaded
Chrome Cache Entry: 79
HTML document, ASCII text, with very long lines (2783)
downloaded
Chrome Cache Entry: 80
Web Open Font Format (Version 2), TrueType, length 11040, version 1.0
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (8738), with no line terminators
dropped
Chrome Cache Entry: 82
ASCII text, with very long lines (48664)
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (19015)
downloaded
Chrome Cache Entry: 85
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 86
ASCII text, with very long lines (19015)
dropped
Chrome Cache Entry: 87
HTML document, ASCII text
downloaded
Chrome Cache Entry: 88
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 89
ASCII text, with very long lines (48664)
dropped
Chrome Cache Entry: 90
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 91
SVG Scalable Vector Graphics image
downloaded
There are 18 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2276 --field-trial-handle=2204,i,10793580977582758868,3268384068697070233,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://yungbucksbbq.com/portbiz/"

URLs

Name
IP
Malicious
https://yungbucksbbq.com/portbiz/
malicious
https://yungbucksbbq.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/787bc399e22f/main.js?
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/
malicious
https://yungbucksbbq.com/portbiz/icons/icon-blugov-info.svg
104.21.112.1
malicious
https://yungbucksbbq.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/icons/blugov-left-chevron-dark.svg
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/css/mgv2-application.css
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/css/blugov.css
104.21.112.1
malicious
https://yungbucksbbq.com/cdn-cgi/challenge-platform/h/b/jsd/r/8f7506295d20727b
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/images/myGov-cobranded-logo-white.svg
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/css/css.css
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/#
malicious
https://yungbucksbbq.com/favicon.ico
104.21.112.1
malicious
https://yungbucksbbq.com/portbiz/images/myGov-cobranded-logo-black.svg
104.21.112.1
malicious
https://code.jquery.com/jquery-3.2.1.slim.min.js
151.101.2.137
https://a.nel.cloudflare.com/report/v4?s=UrpOxnvS90nT4enVqEQEa9fWbxEoMzjHyMP4jnvrTheqVC9Rlo%2FJhuImUrKhqrBVOA1DXbV1BCZaisdhID1zf9pgRg5O4tThEqOGzFHC5E5xtQB8pc%2Ffb1SSGQDx4spLgoYz
35.190.80.1
https://a.nel.cloudflare.com/report/v4?s=WALG0QTwIft9Y7wjm%2BpyerU6Bn6BVJUZUGRwOsSWeseAJ4lLHXtu928LTLvuAoBWWW01WODeESIR9OO9IZRIlEW5Zu2DRRywhG4pkFEK9qd%2Fk2iHC4W2cqmw1JSZ1YMwj9nq
35.190.80.1
https://stackpath.bootstrapcdn.com/bootstrap/4.1.3/js/bootstrap.min.js
104.18.11.207
https://github.com/harvesthq/chosen
unknown
https://getbootstrap.com/)
unknown
https://a.nel.cloudflare.com/report/v4?s=gSae%2FPvDViVNzZ1Dz67TD%2F4i4o4bjcMfByOZ6JG%2FMx3u22xJ2W34gXBlDyHEOpUHMxsHmDxCDUmyDM1w%2FjPGhaii2uHNIBPLGGoowpgEIBVBTCh8TY%2FCkxZ3s4P0MRNCQcoB
35.190.80.1
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
104.17.25.14
https://github.com/harvesthq/chosen/blob/master/LICENSE.md
unknown
https://getbootstrap.com)
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
104.18.11.207
http://opensource.org/licenses/MIT).
unknown
http://getharvest.com
unknown
There are 18 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
yungbucksbbq.com
104.21.112.1
malicious
stackpath.bootstrapcdn.com
104.18.11.207
a.nel.cloudflare.com
35.190.80.1
code.jquery.com
151.101.2.137
cdnjs.cloudflare.com
104.17.25.14
maxcdn.bootstrapcdn.com
104.18.11.207
www.google.com
172.217.19.228

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
malicious
104.21.112.1
yungbucksbbq.com
United States
malicious
172.217.19.228
www.google.com
United States
104.17.24.14
unknown
United States
104.18.10.207
unknown
United States
104.18.11.207
stackpath.bootstrapcdn.com
United States
151.101.2.137
code.jquery.com
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States
104.17.25.14
cdnjs.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://yungbucksbbq.com/portbiz/
malicious
https://yungbucksbbq.com/portbiz/#
malicious
https://yungbucksbbq.com/portbiz/
https://yungbucksbbq.com/portbiz/
https://yungbucksbbq.com/portbiz/
https://yungbucksbbq.com/portbiz/#