IOC Report
https://sothebys.us.com/4RAoTxB4GI1Anz01wI1Achm3T2APW4Q3E4RAha4RA4DCm3TB4G4RAaunz01coTxq01

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 101
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 102
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 103
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
PNG image data, 17 x 25, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 105
PNG image data, 338 x 72, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 106
gzip compressed data, original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 107
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (8019), with no line terminators
downloaded
Chrome Cache Entry: 109
gzip compressed data, from Unix, original size modulo 2^32 57443
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (8002), with no line terminators
dropped
Chrome Cache Entry: 111
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 112
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 113
gzip compressed data, from Unix, original size modulo 2^32 26676
downloaded
Chrome Cache Entry: 114
MS Windows icon resource - 5 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 115
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 116
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 117
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 118
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 119
PNG image data, 16 x 25, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 120
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 121
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 122
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 123
gzip compressed data, original size modulo 2^32 513
downloaded
Chrome Cache Entry: 124
PNG image data, 16 x 25, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 125
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1080, components 3
dropped
Chrome Cache Entry: 126
gzip compressed data, from Unix, original size modulo 2^32 26954
dropped
Chrome Cache Entry: 127
HTML document, Unicode text, UTF-8 text, with very long lines (941), with CRLF line terminators
dropped
Chrome Cache Entry: 128
PNG image data, 60 x 60, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 129
gzip compressed data, from Unix, original size modulo 2^32 89501
downloaded
Chrome Cache Entry: 130
PNG image data, 338 x 72, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 131
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 132
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 133
gzip compressed data, from Unix, original size modulo 2^32 89501
dropped
Chrome Cache Entry: 134
gzip compressed data, from Unix, original size modulo 2^32 3500
downloaded
Chrome Cache Entry: 135
gzip compressed data, from Unix, original size modulo 2^32 102818
dropped
Chrome Cache Entry: 136
gzip compressed data, from Unix, original size modulo 2^32 141804
dropped
Chrome Cache Entry: 137
gzip compressed data, from Unix, original size modulo 2^32 102818
downloaded
Chrome Cache Entry: 138
gzip compressed data, from Unix, original size modulo 2^32 407064
dropped
Chrome Cache Entry: 139
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 140
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 141
PNG image data, 17 x 25, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 142
gzip compressed data, from Unix, original size modulo 2^32 57443
dropped
Chrome Cache Entry: 143
gzip compressed data, from Unix, original size modulo 2^32 15763
dropped
Chrome Cache Entry: 144
gzip compressed data, original size modulo 2^32 1864
dropped
Chrome Cache Entry: 145
GIF image data, version 89a, 22 x 22
dropped
Chrome Cache Entry: 146
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 147
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 148
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 149
gzip compressed data, original size modulo 2^32 513
dropped
Chrome Cache Entry: 150
PNG image data, 89 x 18, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 77
GIF image data, version 89a, 22 x 22
downloaded
Chrome Cache Entry: 78
gzip compressed data, from Unix, original size modulo 2^32 40329
dropped
Chrome Cache Entry: 79
gzip compressed data, from Unix, original size modulo 2^32 113401
downloaded
Chrome Cache Entry: 80
gzip compressed data, from Unix, original size modulo 2^32 449646
downloaded
Chrome Cache Entry: 81
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 82
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 83
gzip compressed data, original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 84
gzip compressed data, from Unix, original size modulo 2^32 141804
downloaded
Chrome Cache Entry: 85
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 86
gzip compressed data, from Unix, original size modulo 2^32 407064
downloaded
Chrome Cache Entry: 87
MS Windows icon resource - 5 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 88
GIF image data, version 89a, 24 x 24
downloaded
Chrome Cache Entry: 89
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1080, components 3
downloaded
Chrome Cache Entry: 90
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 91
gzip compressed data, original size modulo 2^32 3651
dropped
Chrome Cache Entry: 92
gzip compressed data, from Unix, original size modulo 2^32 26676
dropped
Chrome Cache Entry: 93
PNG image data, 280 x 60, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 94
gzip compressed data, from Unix, original size modulo 2^32 15763
downloaded
Chrome Cache Entry: 95
HTML document, Unicode text, UTF-8 text, with very long lines (941), with CRLF line terminators
downloaded
Chrome Cache Entry: 96
gzip compressed data, from Unix, original size modulo 2^32 449646
dropped
Chrome Cache Entry: 97
gzip compressed data, from Unix, original size modulo 2^32 40329
downloaded
Chrome Cache Entry: 98
gzip compressed data, from Unix, original size modulo 2^32 26954
downloaded
Chrome Cache Entry: 99
PNG image data, 280 x 60, 8-bit/color RGBA, non-interlaced
downloaded
There are 65 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2220 --field-trial-handle=1944,i,14226714261646449891,17094810511241142371,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sothebys.us.com/4RAoTxB4GI1Anz01wI1Achm3T2APW4Q3E4RAha4RA4DCm3TB4G4RAaunz01coTxq01"

URLs

Name
IP
Malicious
https://sothebys.us.com/4RAoTxB4GI1Anz01wI1Achm3T2APW4Q3E4RAha4RA4DCm3TB4G4RAaunz01coTxq01
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/ScriptResource.axd?d=QLrP6mIJ7ueSGHO76v9yfTImQUOtYCoOjHacorzH5TLKOrh9q9RxJn4yT2gwt-5hCto2xKcJLNcreE4qet4Lh8rEpzV0U1CdXTgP1HQS6sdYdfc3vDJz_AHQWhudWnHugQouXXFhySP7eLg7L_3MN7WQWeyz2NjjwVkoZ_qPHIuVWaKEoOm3CQ7ncbyZM4_YTXDCK8GCLjftpLcukJlboowfkGtZtJ8Ej00GYvDVARg1&t=7a0cc936
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/css/ltrStyle.css?v=1342177280
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/images/footer_logo_grey_bg.png
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
143.110.153.1
malicious
https://adobesign.dcateam.com/common/instrumentation/reportbssotelemetry?hpgid=6&hpgact=2101&client-request-id=ff6956b6-29fa-401b-8d05-526c61a9442d&hpgrequestid=987796c6-9c4e-44a5-905b-584683aa0b00
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/js/ConvergedLogin_PCore_ELtAAt2Ya8ISGuc0PJcBKA2.js
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/images/header_microsoft.png
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/favicon.ico?v=1342177280
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/js/BssoInterrupt_Core_JQnUxWSvwsd9FrpspQmznw2.js
143.110.153.1
malicious
https://4b8136b0-4e5d42df.dcateam.com/Prefetch/Prefetch.aspx
143.110.153.1
malicious
https://ca0bbba6-4e5d42df.dcateam.com/ajax/jQuery/jquery-3.6.0.min.js
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/images/hip_reload.png
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_117b650bccea354984d8.js
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/Default.aspx/GetCaptchaChallenge
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/css/Style.css?v=1342177280
143.110.153.1
malicious
https://7a4e0ce6-4e5d42df.dcateam.com/c1c6b6c8-mon5obab8f9fj-3gyrormlqfhpfpsikkzhrzv9m-1f0/logintenantbranding/0/illustration?ts=637944331833970061
143.110.153.1
malicious
https://adobesign.dcateam.com/favicon.ico
143.110.153.1
malicious
https://28e58987-4e5d42df.dcateam.com/Images/hipaudioplay.png?vv=100
143.110.153.1
malicious
https://l1ve.dcateam.com/Me.htm?v=3
143.110.153.1
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true#/=
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/?ru=https%3a%2f%2fadobesign.dcateam.com%2fcommon%2freprocess%3fctx%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAQCjnptMZib6bQhIWSaYlJP2CpGZcJG6F9gZHzByDiJSbYoPykzT688MzmjxCE9tSgjsSilJKkosTQPpOwWk6B_UbpnSnixW2pKalFiSWZ-3iNm_HousAi8YuExYLbi4OASYJBgUGD4wcK4iBXo0uaJ--MYuA1cNx6RO6G_k4fhFKu-r4WJY2CRT1F2ZFm-l3NkvneaY7lJbnBZUlW5aaVJRG65e1KUs2ekX0hIua2RleEENqEJbEyn2Bg-sDF2sDPMYmc4wMl4gJfhB9-xN4e6197Y_s7jFb9OWXmwm1FySkGkoVdghktEkrG3gVFFmqNbRJGzd0llsl9Ufpi5Z4STWWZIse0GAYYHAgwA0&mkt=en-US&hosted=0&device_platform=Windows+10
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_1yb3e7oii5t28dgo4xrtow2.js
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/images/hip_text.gif
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/ScriptResource.axd?d=VOVMn-1ji7ptewpNKKe04Ptic_v4sQOkJoNbFSKTCgnJsUDWSYIRw2xt1tvPsTxUYZhIRTaUX9U_dbj8uphXZ0fSg0RHKflqXhImoGV7W_at39wE7F7NNSnjODDdnBpjRydn5povagbPAE8o6JMPhrtPc-X0tGWW1sDlhdiAl_QNQ2pOijcJ10WZjkyvuUaxYB0v6dTbanr2kY0nL-clTw2&t=ffffffffedc3492c
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/images/hip_speaker.png
143.110.153.1
malicious
https://7a4e0ce6-4e5d42df.dcateam.com/c1c6b6c8-mon5obab8f9fj-3gyrormlqfhpfpsikkzhrzv9m-1f0/logintenantbranding/0/bannerlogo?ts=637944331842360917
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/ScriptResource.axd?d=T0dtiwsjKq8gW-fIsAHJyvGnpZPh0iXezm0u3NfytbZ6-6TsiMM-tLKg1veJyjBNY_R3eWGKT7hbAEM4dL48sjZhOiEgfu5nu9KBaaEColWX9lEPD8FaiJMJS9w3E0b_PCJJB-U0Q-uXF00jBspnQFP7Izh7xg73UEYI_OsFKGUjtvZWehapPNjhxxovc4Gqlv_ui3xC40LE2RSikyfhYXQGc5YVZsDGR9yE_8mcw2o1&t=7a0cc936
143.110.153.1
malicious
https://adobesign.dcateam.com/4e5d42dfbe6c47edb237a2ec04853e46/
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/images/header_Microsoft.png
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/images/arrow_left_43280e0ba671a1d8b5e34f1931c4fe4b.svg
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/js/Button.js?v=1342177280
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/js/Webtrends.js
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg
143.110.153.1
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/WebResource.axd?d=YNhUFlNXinz8LgHwbL24RQH-ZbXxyvcr7OOnguhxng8ZuiFTPNJ9QXh8dtoptfX3BeFWG9A9Hk63eLbtbIxk0HvJhkP2FoYJavizwe94hutTawufYPfHJsHAawGlkTxEe6yX2kZBiYdQxI60gLHN2g2&t=638611486905325876
143.110.153.1
malicious
https://adobesign.dcateam.com/common/instrumentation/dssostatus
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/js/asyncchunk/convergedlogin_ppassword_89db715e3340a2e8ecd8.js
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/WebResource.axd?d=PZp-UguzV3eiIgC9jthUzRVid1Zp7Yrh6GnWr6UFT7HZeGKMaINHyYeiOoYl901XG1SgokATq5Nqn3NEpiSXniqMwkj7V_kjzBmM_w8PfSJW9srpOcEZZbp1FPwrN8XzdR0AFY0bHhANU64v3ZJk5Q2&t=638611486905325876
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/js/asyncchunk/convergedlogin_pfetchsessionsprogress_d0a803279e7397bef834.js
143.110.153.1
malicious
https://2c1fa62b-4e5d42df.dcateam.com/api/report?catId=GW+estsfd+dub2
143.110.153.1
malicious
https://03fe54c2-4e5d42df.dcateam.com/gerhardtbraun.com/winauth/ssoprobe?client-request-id=b44ac550-9d30-4269-b060-549621628c56&_=1727420763655
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/js/Common.js
143.110.153.1
malicious
https://df977804-4e5d42df.dcateam.com/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg
143.110.153.1
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/images/wait_animation.gif
143.110.153.1
malicious
https://a.nel.cloudflare.com/report/v4?s=iVNyW8%2FELp7FPA7yxgQAw8gpudMqbhihaB8ishQjNgbiNvsySEz739%2FXh9yyNwdXBSsYJgrZZqyg%2FBHjWITBrWAdLIb81vFVh6goXVlEmLdNzu4uNfpMvYQ1BqEnHSoyTok%3D
35.190.80.1
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=#/
https://account.dcateam.com/resetpassword.aspx
unknown
https://sothebys.us.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
104.21.67.142
https://wwwms.dcateam.com/en-US/servicesagreement/
unknown
https://sothebys.us.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/ec4b873d446c/main.js?
104.21.67.142
https://a.nel.cloudflare.com/report/v4?s=Aj1r5VfGyJBo2zvewhZDvdya1W8WZ99XgrF4YfcxfID3iN0IkUdv4abfIW756iVwrsjRPTckwUUmfGkIaiO6bWltXHE9uBA7FKZX7c9cKLJb9%2FX%2By6HKFueDzW7MlA5OGFY%3D
35.190.80.1
https://sothebys.us.com/4RAoTxB4GI1Anz01wI1Achm3T2APW4Q3E4RAha4RA4DCm3TB4G4RAaunz01coTxq01
https://28e58987-4e5d42df.dcateam.com:443/Images/hipaudioplay.png?vv=100
unknown
https://46d74361-4e5d42df.dcateam.com/en-US/privacystatement
unknown
There are 47 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
179eef38-4e5d42df.dcateam.com
143.110.153.1
malicious
7a4e0ce6-4e5d42df.dcateam.com
143.110.153.1
malicious
28e58987-4e5d42df.dcateam.com
143.110.153.1
malicious
ca0bbba6-4e5d42df.dcateam.com
143.110.153.1
malicious
03fe54c2-4e5d42df.dcateam.com
143.110.153.1
malicious
adobesign.dcateam.com
143.110.153.1
malicious
2c1fa62b-4e5d42df.dcateam.com
143.110.153.1
malicious
1f0e1fe2-4e5d42df.dcateam.com
143.110.153.1
malicious
df977804-4e5d42df.dcateam.com
143.110.153.1
malicious
l1ve.dcateam.com
143.110.153.1
malicious
4b8136b0-4e5d42df.dcateam.com
143.110.153.1
malicious
a.nel.cloudflare.com
35.190.80.1
fp2e7a.wpc.phicdn.net
192.229.221.95
sothebys.us.com
104.21.67.142
www.google.com
142.250.184.196
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
143.110.153.1
179eef38-4e5d42df.dcateam.com
United States
malicious
192.168.2.4
unknown
unknown
malicious
142.250.184.196
www.google.com
United States
239.255.255.250
unknown
Reserved
104.21.67.142
sothebys.us.com
United States
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=#/
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true#/=
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true#/=
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true#/=
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true#/=
malicious
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true#/=
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/?ru=https%3a%2f%2fadobesign.dcateam.com%2fcommon%2freprocess%3fctx%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAQCjnptMZib6bQhIWSaYlJP2CpGZcJG6F9gZHzByDiJSbYoPykzT688MzmjxCE9tSgjsSilJKkosTQPpOwWk6B_UbpnSnixW2pKalFiSWZ-3iNm_HousAi8YuExYLbi4OASYJBgUGD4wcK4iBXo0uaJ--MYuA1cNx6RO6G_k4fhFKu-r4WJY2CRT1F2ZFm-l3NkvneaY7lJbnBZUlW5aaVJRG65e1KUs2ekX0hIua2RleEENqEJbEyn2Bg-sDF2sDPMYmc4wMl4gJfhB9-xN4e6197Y_s7jFb9OWXmwm1FySkGkoVdghktEkrG3gVFFmqNbRJGzd0llsl9Ufpi5Z4STWWZIse0GAYYHAgwA0&mkt=en-US&hosted=0&device_platform=Windows+10
malicious
https://1f0e1fe2-4e5d42df.dcateam.com/?ru=https%3a%2f%2fadobesign.dcateam.com%2fcommon%2freprocess%3fctx%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuAQCjnptMZib6bQhIWSaYlJP2CpGZcJG6F9gZHzByDiJSbYoPykzT688MzmjxCE9tSgjsSilJKkosTQPpOwWk6B_UbpnSnixW2pKalFiSWZ-3iNm_HousAi8YuExYLbi4OASYJBgUGD4wcK4iBXo0uaJ--MYuA1cNx6RO6G_k4fhFKu-r4WJY2CRT1F2ZFm-l3NkvneaY7lJbnBZUlW5aaVJRG65e1KUs2ekX0hIua2RleEENqEJbEyn2Bg-sDF2sDPMYmc4wMl4gJfhB9-xN4e6197Y_s7jFb9OWXmwm1FySkGkoVdghktEkrG3gVFFmqNbRJGzd0llsl9Ufpi5Z4STWWZIse0GAYYHAgwA0&mkt=en-US&hosted=0&device_platform=Windows+10
malicious
https://sothebys.us.com/4RAoTxB4GI1Anz01wI1Achm3T2APW4Q3E4RAha4RA4DCm3TB4G4RAaunz01coTxq01
https://sothebys.us.com/4RAoTxB4GI1Anz01wI1Achm3T2APW4Q3E4RAha4RA4DCm3TB4G4RAaunz01coTxq01
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=#/
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=#/
https://adobesign.dcateam.com/?amp=cm9iaW4ud2ljaHRAZ2VyaGFyZHRicmF1bi5jb20=&sso_reload=true#/=
There are 3 hidden doms, click here to show them.