IOC Report
https://indigentdefense.techsharetx.gov/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 101
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 102
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 103
data
downloaded
Chrome Cache Entry: 104
data
dropped
Chrome Cache Entry: 105
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 106
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 107
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 108
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 109
MS Windows icon resource - 4 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 110
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 111
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 112
ASCII text, with very long lines (12331), with CRLF line terminators
dropped
Chrome Cache Entry: 113
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 114
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 115
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 116
Unicode text, UTF-8 (with BOM) text, with very long lines (4859), with no line terminators
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (47352), with CRLF line terminators
downloaded
Chrome Cache Entry: 118
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 119
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 120
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 121
Unicode text, UTF-8 (with BOM) text, with very long lines (1842), with no line terminators
downloaded
Chrome Cache Entry: 122
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 123
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 124
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 125
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 126
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 127
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 128
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (33350), with CRLF line terminators
dropped
Chrome Cache Entry: 130
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (65195), with CRLF line terminators
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (12331), with CRLF line terminators
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (33350), with CRLF line terminators
downloaded
Chrome Cache Entry: 134
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 135
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 136
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 137
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 138
Web Open Font Format, TrueType, length 29536, version 1.0
downloaded
Chrome Cache Entry: 139
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 140
Web Open Font Format, TrueType, length 29100, version 1.0
downloaded
Chrome Cache Entry: 141
assembler source, ASCII text, with very long lines (318), with CRLF line terminators
downloaded
Chrome Cache Entry: 142
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 143
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 144
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 145
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 146
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 86
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 87
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 88
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 89
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 90
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 91
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 92
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (2432), with CRLF line terminators
downloaded
Chrome Cache Entry: 94
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 95
Web Open Font Format, TrueType, length 28880, version 1.0
downloaded
Chrome Cache Entry: 96
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 97
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 98
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 99
ASCII text, with CRLF line terminators
dropped
There are 52 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2056 --field-trial-handle=2008,i,16728800064589138983,9329921329852689906,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://indigentdefense.techsharetx.gov/"

URLs

Name
IP
Malicious
https://indigentdefense.techsharetx.gov/
https://github.com/jrburke/requirejs/issues/187
unknown
https://indigentdefense.techsharetx.gov/Content/js/form-submit.js?bust=24.0.0.706
52.238.117.243
http://requirejs.org/docs/errors.html#
unknown
http://blog.igorescobar.com
unknown
http://lodash.com/
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/lodash.js?bust=24.0.0.706
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/lib/jquery.scrollto.js?bust=24.0.0.706
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/lib/kendo/kendo.custom.min.js?bust=24.0.0.706
52.238.117.243
https://bugs.webkit.org/show_bug.cgi?id=29084
unknown
http://www.html5rocks.com/en/tutorials/developertools/sourcemaps/#toc-sourceurl
unknown
http://blindsignals.com/index.php/2009/07/jquery-delay/
unknown
http://bugs.jquery.com/ticket/12282#comment:15
unknown
http://dev.w3.org/csswg/cssom/#resolved-values
unknown
https://indigentdefense.techsharetx.gov/Account/Login?ReturnUrl=%2f
http://github.com/jrburke/requirejs
unknown
http://www.opensource.org/licenses/mit-license.php
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/shortcut.js?bust=24.0.0.706
52.238.117.243
http://people.mozilla.org/~jorendorff/es6-draft.html#sec-7.8.6
unknown
https://indigentdefense.techsharetx.gov/Content/js/config.js
52.238.117.243
http://www.gnu.org/licenses/gpl-2.0.html
unknown
https://github.com/julienw/jquery-trap-input/issues/3
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/domReady.js?bust=24.0.0.706
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/css/style.css
52.238.117.243
http://es5.github.com/#x8
unknown
http://www.quirksmode.org/css/box.html
unknown
https://github.com/jquery/jquery/pull/764
unknown
http://twbs.github.com/bootstrap/javascript.html#transitions
unknown
http://stackoverflow.com/questions/3665561/document-readystate-of-interactive-vs-ondomcontentloaded
unknown
http://bugs.jquery.com/ticket/12359
unknown
https://indigentdefense.techsharetx.gov/Content/css/lib/select2.css
52.238.117.243
http://staff.washington.edu/tft/tests/menus/simplyaccessible/index.html
unknown
https://github.com/nodeca/pako/blob/master/LICENSE
unknown
https://bugzilla.mozilla.org/show_bug.cgi?id=649285
unknown
http://www.modernizr.com/)
unknown
https://github.com/requirejs/domReady/issues/1
unknown
https://indigentdefense.techsharetx.gov/Content/js/modal.js?bust=24.0.0.706
52.238.117.243
http://twbs.github.com/bootstrap/javascript.html#modals
unknown
http://weblogs.java.net/blog/driscoll/archive/2009/09/08/eval-javascript-global-context
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/bootstrap.js?bust=24.0.0.706
52.238.117.243
https://developer.mozilla.org/en-US/docs/CSS/display
unknown
http://css-tricks.com/snippets/jquery/serialize-form-to-json/
unknown
http://github.com/requirejs/domReady
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://raw.github.com/Stuk/jszip/master/LICENSE.markdown.
unknown
https://indigentdefense.techsharetx.gov/Content/fonts/lato-reg-webfont.woff
52.238.117.243
https://developer.mozilla.org/en/Security/CSP)
unknown
https://indigentdefense.techsharetx.gov/favicon.ico
52.238.117.243
http://underscorejs.org/
unknown
http://code.google.com/p/v8/issues/detail?id=2291
unknown
http://dojofoundation.org/
unknown
http://twbs.github.com/bootstrap/javascript.html#carousel
unknown
https://github.com/jquery/sizzle/pull/225
unknown
https://bugzilla.mozilla.org/show_bug.cgi?id=491668
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/toastr.js?bust=24.0.0.706
52.238.117.243
http://www.telerik.com/kendo-ui)
unknown
http://twbs.github.com/bootstrap/javascript.html#affix
unknown
http://www.openjs.com/scripts/events/keyboard_shortcuts/
unknown
http://jquery.org/license
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/jquery-1.11.0.js
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/lib/jquery-1.11.0.js?bust=24.0.0.706
52.238.117.243
http://sizzlejs.com/
unknown
http://es5.github.com/#x13.2.2
unknown
http://stuartk.com/jszip
unknown
http://twbs.github.com/bootstrap/javascript.html#dropdowns
unknown
http://es5.github.com/#x15.3.4.5
unknown
http://jsperf.com/getall-vs-sizzle/2
unknown
http://fluidproject.org/blog/2008/01/09/getting-setting-and-removing-tabindex-values-with-javascript
unknown
http://www.telerik.com/purchase/license-agreement/kendo-ui-complete
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/kendo/jszip.min.js?bust=24.0.0.706
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/Default.js
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/form-inputs.js?bust=24.0.0.706
52.238.117.243
https://github.com/jquery/jquery/pull/557)
unknown
https://indigentdefense.techsharetx.gov/Content/css/lib/kendo.common.min.css
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/lib/jquery.placeholder.js?bust=24.0.0.706
52.238.117.243
http://code.google.com/p/v8/issues/detail?id=90
unknown
https://indigentdefense.techsharetx.gov/Content/css/lib/bootstrap.css
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/lib/require.js
52.238.117.243
http://twbs.github.com/bootstrap/javascript.html#scrollspy
unknown
http://lodash.com/license
unknown
http://blog.alexmaccaw.com/css-transitions
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/jquery.trap.js?bust=24.0.0.706
52.238.117.243
http://twbs.github.com/bootstrap/javascript.html#alerts
unknown
https://indigentdefense.techsharetx.gov/
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/fonts/lato-bla-webfont.woff
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/css/lib/normalize.min.css
52.238.117.243
https://indigentdefense.techsharetx.gov/Content/js/shake.js?bust=24.0.0.706
52.238.117.243
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://indigentdefense.techsharetx.gov/Content/js/lib/jquery.select2.js?bust=24.0.0.706
52.238.117.243
http://dev.w3.org/html5/spec/the-end.html#the-end
unknown
http://twbs.github.com/bootstrap/javascript.html#tabs
unknown
https://github.com/julienw/jquery-trap-input/blob/master/LICENSE
unknown
http://es5.github.com/#x15.1.2.4.
unknown
http://twbs.github.com/bootstrap/javascript.html#popovers
unknown
http://lodash.com/#custom-builds
unknown
http://youtu.be/XAqIpGU8ZZk#t=17m25s
unknown
http://twbs.github.com/bootstrap/javascript.html#buttons
unknown
https://indigentdefense.techsharetx.gov/Content/css/style-print.css
52.238.117.243
http://jsfiddle.net/kbpmy/3/
unknown
https://indigentdefense.techsharetx.gov/Content/css/lib/toastr.min.css
52.238.117.243
http://bugs.jquery.com/ticket/13378
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0017.t-0009.t-msedge.net
13.107.246.45
indigentdefense.techsharetx.gov
52.238.117.243
www.google.com
142.250.185.132
fp2e7a.wpc.phicdn.net
192.229.221.95
s-part-0032.t-0009.t-msedge.net
13.107.246.60

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
52.238.117.243
indigentdefense.techsharetx.gov
United States
192.168.2.16
unknown
unknown
142.250.185.132
www.google.com
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://indigentdefense.techsharetx.gov/Account/Login?ReturnUrl=%2f
https://indigentdefense.techsharetx.gov/Account/Login?ReturnUrl=%2f
https://indigentdefense.techsharetx.gov/Account/Login?ReturnUrl=%2f