IOC Report
http://www.reuters.com/markets/deals/dealmakers-wait-see-mode-expect-ma-pace-pick-up-later-2025-2025-03-06/<scriΡt type="application/javascriΡt" src="https:/pixel.adsafeprotected.com/rjss/st/2412881/86283336/skeleton.js?bidurl=%%PATTERN:url%%"></scriΡt> <NOscriΡt><IMG S

loading gifFilesProcessesURLsDomainsIPsDOM20102Label

Files

File Path
Type
Category
Malicious
Download
Chrome Cache Entry: 48
ASCII text
downloaded
Chrome Cache Entry: 49
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 280x155, components 3
downloaded
Chrome Cache Entry: 50
ASCII text
downloaded
Chrome Cache Entry: 51
PNG image data, 63 x 155, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 52
Web Open Font Format (Version 2), TrueType, length 15688, version 1.0
downloaded
Chrome Cache Entry: 53
HTML document, Unicode text, UTF-8 text, with very long lines (24975)
downloaded
Chrome Cache Entry: 54
HTML document, ASCII text, with very long lines (44394)
downloaded
Chrome Cache Entry: 55
HTML document, Unicode text, UTF-8 text, with very long lines (24975)
downloaded
Chrome Cache Entry: 56
PNG image data, 63 x 155, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 57
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 58
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 280x155, components 3
dropped
Chrome Cache Entry: 59
HTML document, Unicode text, UTF-8 text, with very long lines (24975)
downloaded
Chrome Cache Entry: 60
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 61
MS Windows icon resource - 1 icon, 32x33, 32 bits/pixel
downloaded
Chrome Cache Entry: 62
MS Windows icon resource - 1 icon, 32x33, 32 bits/pixel
dropped
Chrome Cache Entry: 63
ASCII text, with no line terminators
downloaded
There are 7 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2060,i,7466857020853385346,12186381282290386696,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=2160 /prefetch:3
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=printing.mojom.UnsandboxedPrintBackendHost --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=2060,i,7466857020853385346,12186381282290386696,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250306-183004.429000 --mojo-platform-channel-handle=5008 /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.reuters.com/markets/deals/dealmakers-wait-see-mode-expect-ma-pace-pick-up-later-2025-2025-03-06/%3Cscript%20type=%22application/javascript%22%20src=%22https:/pixel.adsafeprotected.com/rjss/st/2412881/86283336/skeleton.js?bidurl=%%PATTERN:url%%%22%3E%3C/SCRIPT%3E%20%3CNOSCRIPT%3E%3CIMG%20SRC=%22https://pixel.adsafeprotected.com/rfw/st/2412881/86283334/skeleton.gif?gdpr=$%7BGDPR%7D&gdpr_consent=$%7BGDPR_CONSENT_278%7D&gdpr_pd=$%7BGDPR_PD%7D&bidurl=%%PATTERN:url%%%22%20BORDER=0%20WIDTH=1%20HEIGHT=1%20ALT=%22%22%3E%3C/NOSCRIPT%3E"

URLs

Name
IP
Malicious
http://www.reuters.com/markets/deals/dealmakers-wait-see-mode-expect-ma-pace-pick-up-later-2025-2025-03-06/%3Cscript%20type=%22application/javascript%22%20src=%22https:/pixel.adsafeprotected.com/rjss/st/2412881/86283336/skeleton.js?bidurl=%%PATTERN:url%%%22%3E%3C/SCRIPT%3E%20%3CNOSCRIPT%3E%3CIMG%20SRC=%22https://pixel.adsafeprotected.com/rfw/st/2412881/86283334/skeleton.gif?gdpr=$%7BGDPR%7D&gdpr_consent=$%7BGDPR_CONSENT_278%7D&gdpr_pd=$%7BGDPR_PD%7D&bidurl=%%PATTERN:url%%%22%20BORDER=0%20WIDTH=1%20HEIGHT=1%20ALT=%22%22%3E%3C/NOSCRIPT%3E
https://www.reuters.com/tools/mobile/us
https://geo.captcha-delivery.com/captcha/?initialCid=AHrlqAAAAAMAMP6OWjEoonkAoU0NAg%3D%3D&hash=2013457ADA70C67D6A4123E0A76873&cid=Kb19fXtY9VqSW23aP2mbgsMCdENX~Zo_1NyjAuR4WMKvjwP8mnchBmuDg52RaW_R4nK~irQ3WqIh9D7GYIa5PF6BM30RBLoLrhdPJ03AMBQ4aPTa9WUGlqtGz63~QrT8&t=fe&referer=https%3A%2F%2Fwww.reuters.com%2Ftools%2Fmobile%2Fus&s=43909&e=74507901172fc7e720e30ad3c5cbe7c7dd4af9f4d59244f144036e2c08e7a2fa&dm=cd
44.216.146.82
https://www.twitter.com/Reuters
unknown
https://www.thomsonreuters.com/en/careers.html
unknown
https://www.reuters.com/fact-check/
unknown
https://static.captcha-delivery.com/captcha/assets/tpl/6dc485c0c428c35b53577b146dc6f9179f55ef9ad41b327a2a179998839364bf/index.css
108.139.29.28
http://c.pki.goog/r/r4.crl
142.250.80.35
https://ct.captcha-delivery.com/c.js
18.173.132.69
https://dd.prod.captcha-delivery.com/image/2025-04-10/9cde6138c368867e9ef49e9d99991d4c.frag.png
18.238.49.103
https://www.reutersagency.com/en/about/about-us/
unknown
https://caniuse.com/woff2
unknown
https://www.reuters.com/info-pages/disclaimer/
unknown
https://dd.prod.captcha-delivery.com/audio/2025-04-10/en/65b19a1501d2b2bb9faa5ede6edc6c36.wav
unknown
https://www.reuters.com/news/pictures
unknown
https://dd.prod.captcha-delivery.com/image/2025-04-10/9cde6138c368867e9ef49e9d99991d4c.jpg
18.238.49.103
https://static.captcha-delivery.com/common/fonts/roboto/font-face.css
108.139.29.28
https://www.reuters.com
unknown
https://datadome.co
unknown
https://static.captcha-delivery.com/common/fonts/roboto/roboto.woff2
108.139.29.28
https://newslink.reuters.com/join/subscribe
unknown
https://www.thomsonreuters.com/en/policies/copyright.html
unknown
https://www.reuters.com/DiversityReportApril2022
unknown
https://www.reuters.com/site-api/header/?_website=reuters&outputType=json
13.249.91.10
https://www.reutersagency.com/en/about/about-us/brand-attribution-guidelines/
unknown
https://www.reuters.com/favicon.ico
13.249.91.10
https://caniuse.com/woff
unknown
https://www.reutersagency.com/en/about/leadership-team/
unknown
https://www.reuters.com/site-api/footer/?_website=reuters&outputType=json
13.249.91.10
http://c.pki.goog/r/gsr1.crl
142.250.80.35
https://caniuse.com/ttf
unknown
https://www.reutersagency.com/en/?utm_source=website&utm_medium=reuters&utm_campaign=site-referral&u
unknown
https://www.reuters.com/video/
unknown
https://graphics.reuters.com/
unknown
https://www.reuters.com/
unknown
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
ct.captcha-delivery.com
18.173.132.69
www.reutersmedia.net
13.249.91.21
d2lhhyweudwf3e.cloudfront.net
108.139.29.28
www.google.com
142.250.65.228
api-us-east-1.captcha-delivery.com
44.216.146.82
dd.prod.captcha-delivery.com
18.238.49.103
www.reuters.com
unknown
static.captcha-delivery.com
unknown
geo.captcha-delivery.com
unknown

IPs

IP
Domain
Country
Malicious
18.173.132.69
ct.captcha-delivery.com
United States
13.249.91.10
unknown
United States
13.249.91.21
www.reutersmedia.net
United States
108.139.29.28
d2lhhyweudwf3e.cloudfront.net
United States
192.168.2.5
unknown
unknown
18.238.49.103
dd.prod.captcha-delivery.com
United States
142.250.65.228
www.google.com
United States
18.238.49.105
unknown
United States
44.216.146.82
api-us-east-1.captcha-delivery.com
United States

DOM / HTML

URL
Malicious
https://www.reuters.com/markets/deals/dealmakers-wait-see-mode-expect-ma-pace-pick-up-later-2025-2025-03-06/%3Cscript%20type=%22application/javascript%22%20src=%22https:/pixel.adsafeprotected.com/rjss/st/2412881/86283336/skeleton.js?bidurl=%%PATTERN:url%%%22%3E%3C/SCRIPT%3E%20%3CNOSCRIPT%3E%3CIMG%20SRC=%22https://pixel.adsafeprotected.com/rfw/st/2412881/86283334/skeleton.gif?gdpr=$%7BGDPR%7D&gdpr_consent=$%7BGDPR_CONSENT_278%7D&gdpr_pd=$%7BGDPR_PD%7D&bidurl=%%PATTERN:url%%%22%20BORDER=0%20WIDTH=1%20HEIGHT=1%20ALT=%22%22%3E%3C/NOSCRIPT%3E
https://www.reuters.com/tools/mobile/us
https://www.reuters.com/tools/mobile/us
https://www.reuters.com/tools/mobile/us