IOC Report
https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2fQBQ8BMYNH7uIDGkesMgjv6eprHN%2bmcf7%2bFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2bVKkQOoZ%2f0h70fo%3d&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3d

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (8094), with no line terminators
dropped
Chrome Cache Entry: 101
MS Windows icon resource - 1 icon, 64x64, 32 bits/pixel
downloaded
Chrome Cache Entry: 102
Unicode text, UTF-8 text, with very long lines (20025)
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (3180)
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (2888), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 105
Unicode text, UTF-8 text, with very long lines (20025)
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (5890)
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (63875)
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (3062)
dropped
Chrome Cache Entry: 109
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 110
HTML document, ASCII text, with very long lines (1187)
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (27377)
dropped
Chrome Cache Entry: 112
TrueType Font data, 17 tables, 1st "GDEF", 13 names, Microsoft, language 0x409, Copyright 2016 The Nunito Project Authors (contact@sansoxygen.com)Nunito SansRegular2.001;UKWN;N
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (63450)
downloaded
Chrome Cache Entry: 114
ASCII text, with very long lines (63450)
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (2806)
downloaded
Chrome Cache Entry: 116
Unicode text, UTF-8 text, with very long lines (8070)
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (2417), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 118
TrueType Font data, 17 tables, 1st "GDEF", 15 names, Microsoft, language 0x409, Copyright 2016 The Nunito Project Authors (contact@sansoxygen.com)Nunito Sans ExtraBoldRegular2.
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (2806)
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (2888), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 121
JSON data
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (6216)
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (6216)
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (27377)
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (12736)
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (5890)
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (1560)
downloaded
Chrome Cache Entry: 128
PNG image data, 1061 x 661, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 129
ASCII text
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (12736)
dropped
Chrome Cache Entry: 131
MS Windows icon resource - 1 icon, 64x64, 32 bits/pixel
dropped
Chrome Cache Entry: 132
ASCII text, with very long lines (63364)
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (3180)
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (63875)
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (3272)
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (1488)
dropped
Chrome Cache Entry: 137
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (2417), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 139
JSON data
downloaded
Chrome Cache Entry: 140
TrueType Font data, 17 tables, 1st "GDEF", 13 names, Microsoft, language 0x409, Copyright 2016 The Nunito Project Authors (contact@sansoxygen.com)Nunito SansItalic2.001;UKWN;Nu
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (608)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (1488)
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (3272)
dropped
Chrome Cache Entry: 144
Unicode text, UTF-8 text, with very long lines (12075)
downloaded
Chrome Cache Entry: 145
JSON data
dropped
Chrome Cache Entry: 146
TrueType Font data, 17 tables, 1st "GDEF", 13 names, Microsoft, language 0x409, Copyright 2016 The Nunito Project Authors (contact@sansoxygen.com)Nunito SansBold2.001;UKWN;Nuni
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65321)
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (65321)
dropped
Chrome Cache Entry: 149
Unicode text, UTF-8 text, with very long lines (12075)
dropped
Chrome Cache Entry: 150
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 151
Unicode text, UTF-8 text, with very long lines (65305)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (5890)
dropped
Chrome Cache Entry: 153
Unicode text, UTF-8 text, with very long lines (8070)
dropped
Chrome Cache Entry: 154
ASCII text, with very long lines (3062)
downloaded
Chrome Cache Entry: 155
ASCII text
dropped
Chrome Cache Entry: 156
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (8195), with no line terminators
downloaded
Chrome Cache Entry: 158
PNG image data, 1061 x 661, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (65431)
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (63364)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (1560)
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (5890)
downloaded
Chrome Cache Entry: 163
ASCII text
downloaded
Chrome Cache Entry: 164
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (2851)
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (65431)
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (608)
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (2851)
downloaded
There are 60 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2104 --field-trial-handle=2028,i,14252126878679427959,8536158208477036774,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2fQBQ8BMYNH7uIDGkesMgjv6eprHN%2bmcf7%2bFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2bVKkQOoZ%2f0h70fo%3d&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3d"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5404 --field-trial-handle=2028,i,14252126878679427959,8536158208477036774,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5500 --field-trial-handle=2028,i,14252126878679427959,8536158208477036774,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2fQBQ8BMYNH7uIDGkesMgjv6eprHN%2bmcf7%2bFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2bVKkQOoZ%2f0h70fo%3d&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3d
https://siigonube.portaldeclientes.siigo.com/basedeconocimiento/nomina-electronica-contrato-periodo/
unknown
https://d2gh2oz6jtmsd4.cloudfront.net/
unknown
https://cdn.jsdelivr.net/npm/bootstrap
unknown
https://services.siigo.com/alliances/api/v2/public-document-view/
unknown
https://ka-f.fontawesome.com
unknown
https://documentview.siigo.com/cdn-cgi/challenge-platform/h/b/jsd/r/8d0b9bcb997b1835
104.18.13.13
https://github.com/stevermeister/ngx-cookie-service/issues/86#issuecomment-597720130
unknown
https://api-js.datadome.co/js/
18.196.205.95
https://documentview.siigo.com/5.9afb625a62009feeb46c.js
104.18.13.13
https://documentview.siigo.com/8.33e718cfd5a521170754.js
104.18.13.13
https://documentview.siigo.com/main.2802b9d27955792786d6.js
104.18.13.13
https://documentview.siigo.com/runtime.976b259069d51ab5327c.js
104.18.13.13
https://material.angular.io/guide/theming
unknown
https://www.siigo.com/blog/
unknown
http://www.sansoxygen.comThis
unknown
https://qastaging.siigo.com//empresaApiV1//Img//invoceERP_ribbon_Paid.png
unknown
https://documentview.siigo.com/polyfills.7a66aa4ed195ca952626.js
104.18.13.13
https://fontawesome.com/license/free
unknown
https://fontawesome.com
unknown
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFLNunito
unknown
https://datadome.co
unknown
https://documentview.siigo.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
104.18.13.13
https://g.co/ng/security#xss)
unknown
https://angular.io/errors
unknown
https://siigonube.portaldeclientes.siigo.com/basedeconocimiento/asociar-prefijos-facturacion-pagina-
unknown
https://g.co/ng/security#xss
unknown
https://js.datadome.co/tags.js
18.66.122.78
https://documentview.siigo.com/styles.e5b7f0249f33f8fa2d08.css
104.18.13.13
https://documentview.siigo.com/assets/i18n/es-ES.json
104.18.13.13
http://scripts.sil.org/OFLhttp://scripts.sil.org/OFL
unknown
https://documentview.siigo.com/cdn-cgi/apps/head/-Ig2g4YCHL7xzvsuaY8RQTzViE4.js
104.18.13.13
https://documentview.siigo.com/vendor.efb914a4f9d05d8a92f1.js
104.18.13.13
https://documentview.siigo.com/siigo-button-icon-atom_12-entry-js.78f7d2690b832b9161a9.js
104.18.13.13
https://cms.siigo.com/wp-content/uploads/2023/08/logo_slogan.png
104.18.13.13
https://siigonube.portaldeclientes.siigo.com/basedeconocimiento/solicitud-resolucion-factura-electro
unknown
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://documentview.siigo.com/siigo-button-dropdown-atom_8-entry-js.0376441ca965ee493497.js
104.18.13.13
https://documentview.siigo.com/0.d78638fa9941c5492c58.js
104.18.13.13
https://documentview.siigo.com/siigo-panel-atom_3-entry-js.f81f66f98228ba8ec634.js
104.18.13.13
https://documentview.siigo.com/1.c9d34d4013fafc317dc1.js
104.18.13.13
https://documentview.siigo.com/3.c725cd76cede0462e02e.js
104.18.13.13
https://documentview.siigo.com/siigo-input-atom_2-entry-js.83396e400145f59c3702.js
104.18.13.13
https://documentview.siigo.com/siigo-button-icon-atom-entry-js.e120f0d6242e9ba1f335.js
104.18.13.13
https://getbootstrap.com/)
unknown
https://siigonube.portaldeclientes.siigo.com/basedeconocimiento/clasificacion-inventario-servicio/
unknown
https://documentview.siigo.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/62ec4f065604/main.js?
104.18.13.13
https://monolithprod.siigo.com/DISTRIBUIDORAPUERTADEOROPLUSSAS/ERPBilling/ERPBilling.aspx?data=b4iKB
unknown
https://angular.io/api/forms/$
unknown
https://documentview.siigo.com/siigo-button-atom_3-entry-js.c0c73ce651c382cded45.js
104.18.13.13
https://feross.org
unknown
https://kit.fontawesome.com
unknown
https://goo.gl/X2J8zc.
unknown
https://feross.org/opensource
unknown
https://www.siigo.com/facturacion-electronica/?ppc=1&medio_virtual=ISIIgo%20Factura&utm_campaign=Lin
unknown
https://monolithprod.siigo.com//DISTRIBUIDORAPUERTADEOROPLUSSAS//Img//ElaboradoSiigoElectronicamente
unknown
https://angular.io/api/common/NgForOf#change-propagation
unknown
https://kit.fontawesome.com/da0df7ccf4.js
unknown
https://services.siigo.com/alliances/api/public-document-view/
unknown
https://documentview.siigo.com/6.2ece5cec372953bcf8ee.js
104.18.13.13
https://portaldeclientes.siigo.com/capacitaciones/
unknown
https://siigonube.portaldeclientes.siigo.com/basedeconocimiento/creacion-productos-facturacion-elect
unknown
https://documentview.siigo.com/favicon.ico
104.18.13.13
https://bit.ly/IWukam
unknown
https://documentview.siigo.com/7.51828c7cf34a9736cb21.js
104.18.13.13
https://goo.gl/wIDDiL
unknown
There are 55 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0023.t-0009.t-msedge.net
13.107.246.51
cms.siigo.com
104.18.13.13
monolithprod.siigo.com
52.232.216.12
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
172.217.18.4
js.datadome.co
18.66.122.78
documentview.siigo.com
104.18.13.13
fp2e7a.wpc.phicdn.net
192.229.221.95
s-part-0032.t-0009.t-msedge.net
13.107.246.60
api-alb-eu-central-1.datadome.co
18.196.205.95
ka-f.fontawesome.com
unknown
services.siigo.com
unknown
cdn.jsdelivr.net
unknown
kit.fontawesome.com
unknown
api-js.datadome.co
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.51
s-part-0023.t-0009.t-msedge.net
United States
3.79.145.87
unknown
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
172.217.18.4
www.google.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
104.18.13.13
cms.siigo.com
United States
18.66.122.78
js.datadome.co
United States
104.18.12.13
unknown
United States
52.232.216.12
monolithprod.siigo.com
United States
18.196.205.95
api-alb-eu-central-1.datadome.co
United States
There are 1 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2fQBQ8BMYNH7uIDGkesMgjv6eprHN%2bmcf7%2bFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2bVKkQOoZ%2f0h70fo%3d&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3d
https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2FQBQ8BMYNH7uIDGkesMgjv6eprHN%2Bmcf7%2BFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2BVKkQOoZ%2F0h70fo%3D&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3D
https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2FQBQ8BMYNH7uIDGkesMgjv6eprHN%2Bmcf7%2BFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2BVKkQOoZ%2F0h70fo%3D&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3D
https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2FQBQ8BMYNH7uIDGkesMgjv6eprHN%2Bmcf7%2BFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2BVKkQOoZ%2F0h70fo%3D&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3D
https://documentview.siigo.com/document?data=gg2ubUJzsv0Vywx1hv%2FQBQ8BMYNH7uIDGkesMgjv6eprHN%2Bmcf7%2BFvaSmMNUIeYof62fXsO9MMAWjFxpKcfdficgmbNo%2BVKkQOoZ%2F0h70fo%3D&extraFields=MjpESVNUUklCVUlET1JBUFVFUlRBREVPUk9QTFVTU0FTOjQzMTkzMzpGYWxzZTphNTNiNDE4ZC01ZGNjLTRlYTAtOWU3Zi1jMDRhN2I5YmExM2I6RmFsc2U%3D