IOC Report
http://votedrterrycronin.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 26 12:13:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 26 12:13:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 26 12:13:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 26 12:13:04 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Dec 26 12:13:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 101
Java source, ASCII text
downloaded
Chrome Cache Entry: 102
Java source, ASCII text
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 104
Java source, ASCII text, with very long lines (670)
dropped
Chrome Cache Entry: 105
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (1128)
downloaded
Chrome Cache Entry: 107
Java source, ASCII text, with very long lines (6236)
downloaded
Chrome Cache Entry: 108
Java source, ASCII text, with very long lines (497)
dropped
Chrome Cache Entry: 109
Java source, ASCII text, with very long lines (6236)
dropped
Chrome Cache Entry: 110
Unicode text, UTF-8 text, with very long lines (52101)
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (2702)
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (47691)
downloaded
Chrome Cache Entry: 113
Unicode text, UTF-8 text, with very long lines (21155)
downloaded
Chrome Cache Entry: 114
JSON data
dropped
Chrome Cache Entry: 115
Unicode text, UTF-8 text, with very long lines (45437)
dropped
Chrome Cache Entry: 116
PNG image data, 6 x 53, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 117
Java source, ASCII text, with very long lines (2254)
dropped
Chrome Cache Entry: 118
PNG image data, 128 x 128, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 119
Java source, ASCII text, with very long lines (6405)
downloaded
Chrome Cache Entry: 120
Java source, ASCII text, with very long lines (7960)
downloaded
Chrome Cache Entry: 121
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 122
HTML document, ASCII text, with very long lines (1883)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 124
ASCII text, with very long lines (23814)
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (65188)
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (13480)
dropped
Chrome Cache Entry: 127
Java source, ASCII text, with very long lines (1811)
dropped
Chrome Cache Entry: 128
Java source, ASCII text, with very long lines (6405)
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (870)
dropped
Chrome Cache Entry: 130
ASCII text, with very long lines (10924)
dropped
Chrome Cache Entry: 131
Java source, ASCII text, with very long lines (497)
downloaded
Chrome Cache Entry: 132
JSON data
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (4538)
downloaded
Chrome Cache Entry: 134
Web Open Font Format (Version 2), TrueType, length 12000, version 1.0
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (2702)
dropped
Chrome Cache Entry: 136
Unicode text, UTF-8 text, with very long lines (52101)
downloaded
Chrome Cache Entry: 137
PNG image data, 6 x 53, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (13090)
downloaded
Chrome Cache Entry: 139
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (62890)
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (13090)
dropped
Chrome Cache Entry: 142
Unicode text, UTF-8 text, with very long lines (21155)
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (11465)
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (21837)
dropped
Chrome Cache Entry: 145
JSON data
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (9262)
downloaded
Chrome Cache Entry: 147
Java source, ASCII text, with very long lines (5751)
downloaded
Chrome Cache Entry: 148
Java source, ASCII text, with very long lines (977)
downloaded
Chrome Cache Entry: 149
Java source, ASCII text, with very long lines (1149)
dropped
Chrome Cache Entry: 150
Java source, ASCII text, with very long lines (5368)
dropped
Chrome Cache Entry: 151
Java source, ASCII text, with very long lines (418)
dropped
Chrome Cache Entry: 152
Java source, ASCII text, with very long lines (1771)
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 154
Java source, ASCII text, with very long lines (670)
downloaded
Chrome Cache Entry: 155
Java source, ASCII text, with very long lines (5368)
downloaded
Chrome Cache Entry: 156
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (21837)
downloaded
Chrome Cache Entry: 158
Java source, ASCII text, with very long lines (1149)
downloaded
Chrome Cache Entry: 159
Java source, ASCII text, with very long lines (1811)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (8143)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (9262)
dropped
Chrome Cache Entry: 162
JSON data
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (47691)
dropped
Chrome Cache Entry: 164
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 165
ASCII text
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (62890)
downloaded
Chrome Cache Entry: 167
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 168
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 170
Web Open Font Format (Version 2), TrueType, length 12624, version 1.0
downloaded
Chrome Cache Entry: 171
Unicode text, UTF-8 text, with very long lines (45437)
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (11465)
downloaded
Chrome Cache Entry: 173
Java source, ASCII text, with very long lines (977)
dropped
Chrome Cache Entry: 174
Java source, ASCII text, with very long lines (895)
dropped
Chrome Cache Entry: 175
Java source, ASCII text, with very long lines (895)
downloaded
Chrome Cache Entry: 176
Java source, ASCII text, with very long lines (2254)
downloaded
Chrome Cache Entry: 177
Java source, ASCII text, with very long lines (1771)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (4538)
dropped
Chrome Cache Entry: 179
JSON data
dropped
Chrome Cache Entry: 180
ASCII text, with very long lines (10924)
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (65188)
dropped
Chrome Cache Entry: 182
Java source, ASCII text, with very long lines (7960)
dropped
Chrome Cache Entry: 183
Web Open Font Format (Version 2), TrueType, length 12752, version 1.0
downloaded
Chrome Cache Entry: 184
JSON data
downloaded
Chrome Cache Entry: 185
Java source, ASCII text, with very long lines (418)
downloaded
Chrome Cache Entry: 186
Java source, ASCII text, with very long lines (5751)
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (23814)
dropped
Chrome Cache Entry: 188
ASCII text, with very long lines (870)
downloaded
Chrome Cache Entry: 189
Unicode text, UTF-8 text, with very long lines (43679)
downloaded
Chrome Cache Entry: 190
JSON data
downloaded
Chrome Cache Entry: 191
JSON data
dropped
Chrome Cache Entry: 192
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (13480)
downloaded
There are 90 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1968,i,16486396866440312576,15105104726956286203,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://votedrterrycronin.com"

URLs

Name
IP
Malicious
http://votedrterrycronin.com
https://anedot.com/public/v3/action_pages/donate-today?account_slug=terry-cronin-jr-campaign
104.18.237.197
http://corner.squareup.com/2012/07/smoother-signatures.html
unknown
https://github.com/szimek/signature_pad
unknown
https://secure.anedot.com/uiv2/assets/Storefront-BzsNK9c0.css
104.18.241.197
https://secure.anedot.com/uiv2/assets/ISPTerminal-DKmBjWa1.js
104.18.241.197
https://anedot.com/user/v3/donor_profile
104.18.237.197
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=8f8154660d6d4337&lang=auto
104.18.95.41
https://anedot.com/api/features/proxy?accountId=a8b9f8fd0600605f4203a&appName=anedot-frontend
104.18.237.197
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/1562186968:1735215054:Z4Fmob2a2xhcC8uT4-nX3mN85A-4VALCIxu0525-0UI/8f8154660d6d4337/EV1qglZO7VTRgpqKzfQvcIuO3KNLQsfcdLMWyBHM0P4-1735218822-1.1.1.1-SVlidWaV0mkWEqE25owKCQ6hUl_a7XssJXs0xIJ.TiALQ8yYTZnNm8KvB4pH60Ud
104.18.95.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/8f8154660d6d4337/1735218826507/q9isRGLNeTb24Zi
104.18.95.41
https://secure.anedot.com/uiv2/assets/PageTitle-BvINv2C7.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/formControls-8Val9ZSN.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/useGetPaymentMethods-DW9jukbT.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/PhoneInputControl-CUOpwV8X.js
104.18.241.197
https://kjur.github.io/jsrsasign/license/
unknown
https://www.apache.org/licenses/LICENSE-2.0
unknown
https://anedot.com/user/v3/me
104.18.237.197
https://reactjs.org/link/react-polyfills
unknown
https://github.com/mholt/PapaParse
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1
104.18.95.41
https://secure.anedot.com/uiv2/assets/ActionPageContainerChakra-F2X7lKEh.js
104.18.241.197
https://challenges.cloudflare.com/turnstile/v0/b/787bc399e22f/api.js
104.18.95.41
https://github.com/focus-trap/tabbable/blob/master/LICENSE
unknown
https://secure.anedot.com/uiv2/assets/AddressField-DQUtMX1b.js
104.18.241.197
http://www.lemoda.net/maths/bezier-length/index.html
unknown
http://votedrterrycronin.com/
15.197.225.128
https://anedot.com
unknown
https://anedot.com/auth/login/secure/pre?account=a8b9f8fd0600605f4203a
unknown
https://secure.anedot.com/uiv2/assets/ActionPageBody-CtZKhyP8.js
104.18.241.197
http://benknowscode.wordpress.com/2012/09/14/path-interpolation-using-cubic-bezier-and-control-point
unknown
http://scurker.github.io/currency.js
unknown
https://secure.anedot.com/uiv2/assets/RollbarWrapper-BJfxK62X.css
104.18.241.197
https://secure.anedot.com/uiv2/assets/common-VHrs7aWP.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/ActionPageBodyChakra-ChnwPoPc.js
104.18.241.197
http://jedwatson.github.io/classnames
unknown
https://secure.anedot.com/uiv2/assets/outfit-latin-700-normal-DweUiK0g.woff2
104.18.241.197
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://secure.anedot.com/uiv2/assets/ActionPageContentBlocksChakra-9A5MPnoZ.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/CrimsonTerminal-DvQq7VK9.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/useGetPublicSubmission--bVz8j0w.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/PageTitle-C76QikAn.css
104.18.241.197
https://secure.anedot.com/uiv2/assets/donors-CYDmHt3t.js
104.18.241.197
https://anedot.com/public/v3/logins/focus?account_slug=terry-cronin-jr-campaign&next=https%253A%252F%252Fsecure.anedot.com%252Fterry-cronin-jr-campaign%252Fdonate-today
104.18.237.197
https://secure.anedot.com/uiv2/assets/ActionPageInfoChakra-fGbtaowK.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/ap-CddBFHSj.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/clsx-B2M_iVD8.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/FormPhoneInputControl-DzqgCgvV.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/outfit-latin-500-normal-Cf2hOGom.woff2
104.18.241.197
https://secure.anedot.com/uiv2/favicon.png
104.18.241.197
https://secure.anedot.com/uiv2/images/anedot_typemark_light.svg
104.18.241.197
https://secure.anedot.com/uiv2/assets/UpgradeContainer-IsLd0I-X.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/vendor-D-2c5weT.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/index-DDyj6qEb.css
104.18.241.197
https://anedot.com/api/features/proxy?appName=anedot-frontend
104.18.237.197
https://static.ads-twitter.com/uwt.js
unknown
https://secure.anedot.com/uiv2/assets/actionPagesBuilder-CC0mW9S9.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/customFields-DxJxm0eF.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/outfit-latin-400-normal-N3wp9mSd.woff2
104.18.241.197
https://secure.anedot.com/uiv2/assets/PaymentFields-CP07TtDf.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/Storefront-CV56y2r2.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/finance-BLFa9s5H.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/ActionPageSEO-BPCsOMWB.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/ActionPageLayoutChakra-DObUJ2GD.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/actionPages-BFXiQxVH.js
104.18.241.197
https://quilljs.com/
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/8f8154660d6d4337/1735218826511/1c21c26cefc4383d5494c4ce827a06a6312b67a27afb0f0a9bf5e5df93bd29ac/5CAJXor8BJDK9bh
104.18.95.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv/206j3/0x4AAAAAAAQSohTdkZ_Cb1mH/light/fbE/normal/auto/
104.18.95.41
https://secure.anedot.com/uiv2/assets/ActionPageView-BCwnu07n.css
104.18.241.197
https://secure.anedot.com/uiv2/assets/PublicActionPage-DXM2PigF.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/ActionPageView-CWjKF3hA.js
104.18.241.197
https://secure.anedot.com/terry-cronin-jr-campaign/donate-today
https://secure.anedot.com/uiv2/assets/RollbarWrapper-Dv278xoT.js
104.18.241.197
https://secure.anedot.com/uiv2/assets/index-CvHUEvin.js
104.18.241.197
http://developer.yahoo.com/yui/license.html
unknown
There are 64 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
anedot.com
104.18.237.197
secure.anedot.com
104.18.237.197
challenges.cloudflare.com
104.18.95.41
www.google.com
142.250.181.68
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.58.101
votedrterrycronin.com
15.197.225.128

IPs

IP
Domain
Country
Malicious
15.197.225.128
votedrterrycronin.com
United States
104.18.237.197
anedot.com
United States
104.18.94.41
unknown
United States
192.168.2.8
unknown
unknown
192.168.2.16
unknown
unknown
104.18.241.197
unknown
United States
104.18.95.41
challenges.cloudflare.com
United States
239.255.255.250
unknown
Reserved
142.250.181.68
www.google.com
United States

DOM / HTML

URL
Malicious
https://secure.anedot.com/terry-cronin-jr-campaign/donate-today
https://secure.anedot.com/terry-cronin-jr-campaign/donate-today
https://secure.anedot.com/terry-cronin-jr-campaign/donate-today
https://secure.anedot.com/terry-cronin-jr-campaign/donate-today