IOC Report
http://go.risetechnical.co.uk/lt/click/8E0472685EEC9137DA6ECC8A8B6E69F9040AA2D1D9E528813A40019BDE1AEC6C617931C6075D9BB63CBC5128A015DF0D049CE52D1ACF824C967630C9857E16AAEBB1F0DA2DD501F3C3C3BAF5C897E23CDF6F0E3BBC351AF0194F600E2B36809325DE3A70/757334BB271B240D00865685C53719F96A4A2D359B4921B5A62D6A5316CA

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 53
PNG image data, 400 x 75, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 54
Unicode text, UTF-8 text, with very long lines (51693), with NEL line terminators
downloaded
Chrome Cache Entry: 55
PNG image data, 400 x 75, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 56
Unicode text, UTF-8 text, with very long lines (51693), with NEL line terminators
dropped
Chrome Cache Entry: 57
ASCII text
downloaded
Chrome Cache Entry: 58
ASCII text, with very long lines (65324)
downloaded
Chrome Cache Entry: 60
ASCII text, with very long lines (2345)
dropped
Chrome Cache Entry: 61
PNG image data, 400 x 75, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 62
ASCII text
downloaded
Chrome Cache Entry: 63
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 64
ASCII text, with very long lines (24084)
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (2345)
downloaded
Chrome Cache Entry: 67
PNG image data, 400 x 75, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 68
ASCII text, with very long lines (7854)
downloaded
Chrome Cache Entry: 69
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 71
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 72
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 73
Web Open Font Format (Version 2), TrueType, length 80252, version 331.-31327
downloaded
Chrome Cache Entry: 75
PNG image data, 512 x 512, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 76
Web Open Font Format (Version 2), TrueType, length 78472, version 331.-31327
downloaded
Chrome Cache Entry: 77
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 78
HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (311), with CRLF line terminators
downloaded
There are 13 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=1608,i,5211168086697897842,2733312193166914627,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://go.risetechnical.co.uk/lt/click/8E0472685EEC9137DA6ECC8A8B6E69F9040AA2D1D9E528813A40019BDE1AEC6C617931C6075D9BB63CBC5128A015DF0D049CE52D1ACF824C967630C9857E16AAEBB1F0DA2DD501F3C3C3BAF5C897E23CDF6F0E3BBC351AF0194F600E2B36809325DE3A70/757334BB271B240D00865685C53719F96A4A2D359B4921B5A62D6A5316CA8BDE6F2A3944E3A995C1A175F30332FF696CBF9C55C2BDDDD2E944EAD615DAF5C640CFD001E854AA543931CBF723BA274062810B04D08E32E5D1AC275EBE8BE88C4D6573B5FE/D3EE35DB54A50C3407D64FC0A5DBB73FC84519CE36A2EEAB306AAEE7D3FA500BA73555436D0259A26EB05CDADF3FF83A99D29063A6672C2E7ED7946B21DACB68EED692B39D032FF7F6BE3F7F3233678568D9E3B54617E4BA9D40889B25276ECA557C9493/12E5C1F92A20D288F972E5FB20B766DE8C310DAF2D58479AF7F02578E82725CA1A2134E1D604B1EADAA57E2C3F2F3B6A71B44EFE2DF5DBD0009ADB241D4878538801DE2732AEF0"

URLs

Name
IP
Malicious
http://go.risetechnical.co.uk/lt/click/8E0472685EEC9137DA6ECC8A8B6E69F9040AA2D1D9E528813A40019BDE1AEC6C617931C6075D9BB63CBC5128A015DF0D049CE52D1ACF824C967630C9857E16AAEBB1F0DA2DD501F3C3C3BAF5C897E23CDF6F0E3BBC351AF0194F600E2B36809325DE3A70/757334BB271B240D00865685C53719F96A4A2D359B4921B5A62D6A5316CA8BDE6F2A3944E3A995C1A175F30332FF696CBF9C55C2BDDDD2E944EAD615DAF5C640CFD001E854AA543931CBF723BA274062810B04D08E32E5D1AC275EBE8BE88C4D6573B5FE/D3EE35DB54A50C3407D64FC0A5DBB73FC84519CE36A2EEAB306AAEE7D3FA500BA73555436D0259A26EB05CDADF3FF83A99D29063A6672C2E7ED7946B21DACB68EED692B39D032FF7F6BE3F7F3233678568D9E3B54617E4BA9D40889B25276ECA557C9493/12E5C1F92A20D288F972E5FB20B766DE8C310DAF2D58479AF7F02578E82725CA1A2134E1D604B1EADAA57E2C3F2F3B6A71B44EFE2DF5DBD0009ADB241D4878538801DE2732AEF0
http://sorgalla.com/lity/
unknown
http://fontawesome.io
unknown
https://stats.g.doubleclick.net/g/collect
unknown
https://qa-herefish-web.azurewebsites.net/
unknown
https://www.risetechnical.co.uk/db_assets/production/1143/application.js?t=1713343932
13.225.78.60
https://cdn-cookieyes.com/client_data/00fd91dc4539ec7d7a92c171/script.js
104.22.58.91
https://github.com/zloirock/core-js
unknown
https://www.risetechnical.co.uk/vault/images/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBM2F5NXc9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--7630d7947573fd486a5a59de857c500503d0c3fe?size=NDAweDIwMD4%3D%0A
13.225.78.60
https://www.risetechnical.co.uk/vault/images/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBM3V5NXc9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--8736789cb2495bdbaaeca2cd09cdda6fa01f849b?size=NDAweDIwMD4%3D%0A
13.225.78.60
https://www.risetechnical.co.uk/rails/active_storage/blobs/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBdzRqREE9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--1dc6796cf2600ece9d9f2cac596ac829b69cde1c/fa-brands-400.woff2
13.225.78.60
https://www.risetechnical.co.uk/api/v1/job_locations.json
13.225.78.60
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/52e031b901071eaef95d6a210853bc94?t=1713343953
52.222.214.47
https://github.com/zloirock/core-js/blob/v3.36.1/LICENSE
unknown
https://app.herefish.com/
unknown
https://px.ads.linkedin.com/collect?
unknown
https://www.risetechnical.co.uk/vault/images/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBMm15NXc9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--6a6c5a761b1614f20a967e2a2d8d90dd3594cf37?size=NDAweDIwMD4%3D%0A
13.225.78.60
https://fontawesome.com/license/free
unknown
https://www.risetechnical.co.uk/vault/images/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBMjJ5NXc9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--9b6da49b41ec52cb3e4ede9716b16613508dce67?size=NDAweDIwMD4%3D%0A
13.225.78.60
https://fontawesome.com
unknown
https://www.google.com
unknown
https://www.youtube.com/iframe_api
unknown
https://fonts.eu-2.volcanic.cloud/s/montserrat/v26/JTUSjIg1_i6t8kCHKm459Wlhyw.woff2
18.172.112.125
https://log.cookieyes.com/api/v1/log
63.32.127.100
https://www.risetechnical.co.uk/en/api/v1/job_locations.json
13.225.78.60
https://fontawesome.com/license
unknown
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/8531d2ab82331b75a8431dc5d551b8d7?t=1611721607
52.222.214.47
https://www.risetechnical.co.uk/vault/images/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBNjZ5NXc9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--bf6f5388c2d98713f113e7e48daceeb20af1a8ca?size=NDAweDIwMD4%3D%0A
13.225.78.60
https://www.risetechnical.co.uk/rails/active_storage/blobs/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBeThtRUE9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--1f8e5a04ed3010e4acb0c35508475f62e3b4df08/Google%20Review.png
13.225.78.60
https://dev-herefish-web.azurewebsites.net/
unknown
https://www.risetechnical.co.uk/api/v1/jobs/search.json?per_page=8&disciplines=
13.225.78.60
https://www.risetechnical.co.uk/rails/active_storage/blobs/eyJfcmFpbHMiOnsibWVzc2FnZSI6IkJBaHBBeGNqREE9PSIsImV4cCI6bnVsbCwicHVyIjoiYmxvYl9pZCJ9fQ==--1d73139d3c3df238aed10d08a360718b1b949c10/fa-solid-900.woff2
13.225.78.60
https://fonts.eu-2.volcanic.cloud/css2?family=Montserrat:wght@400;700&display=swap
18.172.112.125
https://test-herefish-web.azurewebsites.net/
unknown
https://www.risetechnical.co.uk/db_assets/production/1143/application_universal.css?t=1713343932
13.225.78.60
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/cae825613a185c0eae98029453ceedbb?t=1713343955
52.222.214.47
https://www.risetechnical.co.uk/db_assets/production/1143/application_universal.js?t=1713343932
13.225.78.60
https://googleads.g.doubleclick.net
unknown
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/9fa9707dc8d1f0daa601334f4a782bca?format=webp
52.222.214.47
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/bda4b5547cfc7fe27988e77c8ffd25e8?format=webp
52.222.214.47
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/03c9420336e7e749c615f08ae969dbc7?t=1612420799
52.222.214.47
https://getbootstrap.com/)
unknown
https://test-herefish-web2.azurewebsites.net/
unknown
https://cct.google/taggy/agent.js
unknown
http://creativecommons.org/licenses/by-nc/4.0/
unknown
https://www.risetechnical.co.uk/db_assets/production/1143/application_redirect.js?t=1713343932
13.225.78.60
http://fontawesome.io/license
unknown
https://snap.licdn.com/li.lms-analytics/insight.min.js
unknown
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/66d8c659479811f79ab0bb7d369aaaac?fallback=true&format=&size=2000x800%3E&version=4
52.222.214.47
https://td.doubleclick.net
unknown
https://image-assets.eu-2.volcanic.cloud/api/v1/assets/images/fe4381b3b9363ffa66a4422b521818eb?format=webp
52.222.214.47
https://www.merchant-center-analytics.goog
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://fonts.eu-2.volcanic.cloud/css?family=Montserrat:300,400,600
18.172.112.125
https://google.com
unknown
https://adservice.google.com/pagead/regclk?
unknown
There are 45 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
fonts.eu-2.volcanic.cloud
18.172.112.125
db56v6xprxns1.cloudfront.net
13.225.78.60
www.google.com
142.250.184.196
cdn-cookieyes.com
104.22.58.91
log.cookieyes.com
63.32.127.100
d2685wyn1i0hln.cloudfront.net
52.222.214.47
coview.com
130.211.16.248
fp2e7a.wpc.phicdn.net
192.229.221.95
go.risetechnical.co.uk
unknown
www.risetechnical.co.uk
unknown
image-assets.eu-2.volcanic.cloud
unknown
api.herefish.com
unknown
app.herefish.com
unknown
cdn.coview.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
18.172.112.125
fonts.eu-2.volcanic.cloud
United States
142.250.184.196
www.google.com
United States
104.22.58.91
cdn-cookieyes.com
United States
13.225.78.60
db56v6xprxns1.cloudfront.net
United States
192.168.2.16
unknown
unknown
192.168.2.6
unknown
unknown
63.32.127.100
log.cookieyes.com
United States
192.168.2.5
unknown
unknown
52.222.214.89
unknown
United States
239.255.255.250
unknown
Reserved
13.225.78.109
unknown
United States
52.222.214.47
d2685wyn1i0hln.cloudfront.net
United States
There are 2 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.risetechnical.co.uk/?survey=c3VydmV5SWQ9ODk4NyZhbnN3ZXJJZD0xNTUzOTImaGY9MTU2MTk3ODY3JnR5cGU9MCZlSWQ9MTU2MTk3ODY3JnYxPWI0OWM0OWNiOGZiMDkyNWZkYjI4MjdkMDY2YjRjNTgzNjdkOTQyZjc0NzRjY2YwM2FiNDJkYTRmMjQ5YzEwZWMmdHM9MTcyODA1MTUzOTk1NiZ1dG1fY2FtcGFpZ249d2Vic2l0ZSZ1dG1fc291cmNlPUhlcmVmaXNoJnV0bV9tZWRpdW09RW1haWw