IOC Report
http://portal.causely.app

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
JSON data
dropped
Chrome Cache Entry: 101
HTML document, ASCII text
downloaded
Chrome Cache Entry: 102
JSON data
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (18501)
downloaded
Chrome Cache Entry: 104
PNG image data, 2134 x 666, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 105
JSON data
downloaded
Chrome Cache Entry: 106
JSON data
dropped
Chrome Cache Entry: 107
ASCII text, with very long lines (65465)
dropped
Chrome Cache Entry: 108
HTML document, ASCII text
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (37546)
dropped
Chrome Cache Entry: 110
JSON data
downloaded
Chrome Cache Entry: 111
JSON data
dropped
Chrome Cache Entry: 112
gzip compressed data, from Unix, original size modulo 2^32 1171143
downloaded
Chrome Cache Entry: 113
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 114
gzip compressed data, from Unix, original size modulo 2^32 105218
dropped
Chrome Cache Entry: 115
gzip compressed data, from Unix, original size modulo 2^32 3758
downloaded
Chrome Cache Entry: 116
JSON data
downloaded
Chrome Cache Entry: 117
ASCII text
dropped
Chrome Cache Entry: 118
JSON data
dropped
Chrome Cache Entry: 119
JSON data
downloaded
Chrome Cache Entry: 120
gzip compressed data, from Unix, original size modulo 2^32 105218
downloaded
Chrome Cache Entry: 121
HTML document, ASCII text, with very long lines (1216), with no line terminators
downloaded
Chrome Cache Entry: 122
JSON data
downloaded
Chrome Cache Entry: 123
ASCII text
downloaded
Chrome Cache Entry: 124
JSON data
dropped
Chrome Cache Entry: 125
JSON data
downloaded
Chrome Cache Entry: 126
gzip compressed data, from Unix, original size modulo 2^32 495
downloaded
Chrome Cache Entry: 127
Java source, ASCII text, with very long lines (1115)
dropped
Chrome Cache Entry: 128
gzip compressed data, from Unix, original size modulo 2^32 1025429
downloaded
Chrome Cache Entry: 129
gzip compressed data, from Unix, original size modulo 2^32 1175047
downloaded
Chrome Cache Entry: 130
JSON data
dropped
Chrome Cache Entry: 131
HTML document, ASCII text, with very long lines (1216), with no line terminators
dropped
Chrome Cache Entry: 132
PNG image data, 2134 x 666, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (47789)
downloaded
Chrome Cache Entry: 134
JSON data
downloaded
Chrome Cache Entry: 135
gzip compressed data, from Unix, original size modulo 2^32 494
downloaded
Chrome Cache Entry: 136
Java source, ASCII text, with very long lines (1843)
downloaded
Chrome Cache Entry: 137
JSON data
downloaded
Chrome Cache Entry: 138
JSON data
downloaded
Chrome Cache Entry: 139
JSON data
downloaded
Chrome Cache Entry: 140
JSON data
dropped
Chrome Cache Entry: 141
Java source, ASCII text, with very long lines (1843)
dropped
Chrome Cache Entry: 142
gzip compressed data, from Unix, original size modulo 2^32 1025429
dropped
Chrome Cache Entry: 143
JSON data
dropped
Chrome Cache Entry: 144
gzip compressed data, from Unix, original size modulo 2^32 494
dropped
Chrome Cache Entry: 145
ASCII text
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (65465)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (7820), with no line terminators
downloaded
Chrome Cache Entry: 148
gzip compressed data, from Unix, original size modulo 2^32 3784
dropped
Chrome Cache Entry: 149
gzip compressed data, from Unix, original size modulo 2^32 1171143
dropped
Chrome Cache Entry: 150
gzip compressed data, from Unix, original size modulo 2^32 105306
downloaded
Chrome Cache Entry: 151
JSON data
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (18501)
dropped
Chrome Cache Entry: 153
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 154
Java source, ASCII text, with very long lines (1115)
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (47789)
dropped
Chrome Cache Entry: 156
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 157
gzip compressed data, from Unix, original size modulo 2^32 1175047
dropped
Chrome Cache Entry: 158
Web Open Font Format (Version 2), TrueType, length 19156, version 1.0
downloaded
Chrome Cache Entry: 159
Web Open Font Format (Version 2), TrueType, length 19440, version 1.0
downloaded
Chrome Cache Entry: 160
JSON data
dropped
Chrome Cache Entry: 161
ASCII text
downloaded
Chrome Cache Entry: 162
gzip compressed data, from Unix, original size modulo 2^32 105306
dropped
Chrome Cache Entry: 163
gzip compressed data, from Unix, original size modulo 2^32 3758
dropped
Chrome Cache Entry: 164
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 165
JSON data
downloaded
Chrome Cache Entry: 84
Java source, ASCII text, with very long lines (1645)
downloaded
Chrome Cache Entry: 85
JSON data
dropped
Chrome Cache Entry: 86
ASCII text
downloaded
Chrome Cache Entry: 87
Java source, ASCII text, with very long lines (1645)
dropped
Chrome Cache Entry: 88
PNG image data, 665 x 666, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 89
JSON data
dropped
Chrome Cache Entry: 90
HTML document, ASCII text, with very long lines (1216), with no line terminators
downloaded
Chrome Cache Entry: 91
ASCII text
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (7820), with no line terminators
dropped
Chrome Cache Entry: 93
JSON data
dropped
Chrome Cache Entry: 94
gzip compressed data, from Unix, original size modulo 2^32 495
dropped
Chrome Cache Entry: 95
ASCII text, with very long lines (37546)
downloaded
Chrome Cache Entry: 96
Web Open Font Format (Version 2), TrueType, length 16748, version 1.1
downloaded
Chrome Cache Entry: 97
gzip compressed data, from Unix, original size modulo 2^32 3784
downloaded
Chrome Cache Entry: 98
PNG image data, 665 x 666, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 99
JSON data
downloaded
There are 73 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2444 --field-trial-handle=2336,i,15122138701160821970,4658482889216879052,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://portal.causely.app"

URLs

Name
IP
Malicious
http://portal.causely.app
https://auth.causely.app/oauth/account/login
malicious
https://assets.frontegg.com/admin-box/7.13.0/login-box/720.index.js
13.107.253.45
https://assets.frontegg.com/admin-box/6.173.0/login-box/index.js
13.107.253.45
https://portal.causely.app/
https://auth.causely.app/frontegg/identity/resources/auth/v1/user/token/refresh
13.35.58.51
https://github.com/facebook/react.git
unknown
https://portal.causely.app/locales/en/translation.json?_v=9e891389-c6e1-71db-c669-784c476a3d2d
34.160.121.254
http://portal.causely.app/
34.160.121.254
https://cdn.frontegg.com/content/hosted-login/74c8ae4/assets/AppWrapper-63ce078a.js
18.245.60.33
https://portal.causely.app/locales/en-US/translation.json?_v=9e891389-c6e1-71db-c669-784c476a3d2d
34.160.121.254
https://auth.causely.app/frontegg/identity/resources/configurations/v1/public
13.35.58.51
https://reactjs.org/
unknown
https://portal.causely.app/manifest.json
34.160.121.254
https://assets.frontegg.com/admin-box/6.173.0/login-box/610.index.js
13.107.253.45
https://portal.causely.app/static/js/main.11205b58.js
34.160.121.254
https://github.com/jonschlinkert/is-primitive
unknown
https://assets.frontegg.com/admin-box/7.13.0/login-box/index.js
13.107.253.45
https://auth.causely.app/frontegg/identity/resources/configurations/v1/auth/strategies/public
13.35.58.51
https://app-u79khqcmarmf.frontegg.com/auth/saml/callback
unknown
https://cdn.frontegg.com/content/hosted-login/74c8ae4/assets/index-35557702.js
18.245.60.33
https://portal.causely.app/static/css/main.6632c569.css
34.160.121.254
https://api.causely.app
unknown
https://cdn.frontegg.com/content/hosted-login/74c8ae4/assets/utils-cf5b8066.js
18.245.60.33
https://auth.causely.app/oauth/account/social/success
unknown
https://portal.causely.app/favicon.ico
34.160.121.254
https://cdn.frontegg.com/content/hosted-login/74c8ae4/$
unknown
https://github.com/facebook/react/issues
unknown
https://auth.causely.app/favicon.ico
13.35.58.51
https://auth.causely.app/frontegg/metadata?entityName=saml
13.35.58.51
https://assets.frontegg.com/admin-box/6.173.0/admin-portal/index.js
13.107.253.45
https://cdn.frontegg.com/content/hosted-login/74c8ae4/assets/index-ced87b53.js
18.245.60.33
https://auth.causely.app/frontegg/metadata?entityName=adminBox
13.35.58.51
https://portal.causely.app/env.js
34.160.121.254
https://github.com/jonschlinkert/set-value
unknown
https://assets.frontegg.com/admin-box/6.173.0/login-box/289.index.js
13.107.253.45
https://assets.frontegg.com/admin-box/7.13.0/login-box/586.index.js
13.107.253.45
https://auth.causely.app/vendors/public
13.35.58.51
https://cdn.frontegg.com/content/hosted-login/74c8ae4/assets/HostedLoginWrapper-e2d84b0d.js
18.245.60.33
https://auth.causely.app
unknown
https://portal.causely.app/styles.css
34.160.121.254
https://cdn.frontegg.com/content/hosted-login/74c8ae4/assets/PreLoginPage-c3b1a93c.js
18.245.60.33
https://auth.causely.app/frontegg/identity/resources/sso/v2
13.35.58.51
https://auth.causely.app/frontegg/identity/resources/configurations/v1/captcha-policy/public
13.35.58.51
https://auth.causely.app/frontegg/flags
13.35.58.51
https://portal.causely.app/static/media/IBMPlexSans-Regular-Latin1.cf8cdfc9a1ead9d332f5.woff2
34.160.121.254
https://auth.causely.app/frontegg/oauth/authorize?response_type=code&client_id=750050b5-3c87-4d0c-b108-f9e9b4573690&scope=openid+email+profile&redirect_uri=https%3A%2F%2Fportal.causely.app%2Foauth%2Fcallback&code_challenge=ngtfOGz1pMqQjjiVmsrBk9xKW9nYFhFQ4lxuLS5eo9I&code_challenge_method=S256&nonce=2qt6dNnPn9esBc2n
13.35.58.51
https://assets.frontegg.com/admin-box/7.13.0/login-box/128.index.js
13.107.253.45
https://auth.causely.app/frontegg/identity/resources/sso/custom/v1
13.35.58.51
https://assets.frontegg.com/admin-box/6.173.0/login-box/54.index.js
13.107.253.45
https://auth.causely.app/frontegg/team/resources/sso/v2/configurations/public
13.35.58.51
https://github.com/jonschlinkert/is-plain-object
unknown
https://auth.causely.app/oauth/prelogin?client_id=750050b5-3c87-4d0c-b108-f9e9b4573690&state=41d51d76-ac3d-4501-86db-400dbbe026c3&redirect_uri=https%253A%252F%252Fportal.causely.app%252Foauth%252Fcallback
https://github.com/jonschlinkert/get-value
unknown
https://github.com/jonschlinkert).
unknown
https://auth.causely.app/flags
13.35.58.51
https://auth.causely.app/frontegg/oauth/authorize/silent
13.35.58.51
https://github.com/emn178/js-sha256
unknown
https://auth.causely.app/frontegg/vendors/public
13.35.58.51
https://github.com/jonschlinkert/isobject
unknown
There are 49 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.185.68
di53opyd1sdu2.cloudfront.net
13.35.58.51
portal.causely.app
34.160.121.254
d1mr5ezov3l6ny.cloudfront.net
18.245.60.33
fp2e7a.wpc.phicdn.net
192.229.221.95
s-part-0032.t-0009.t-msedge.net
13.107.246.60
auth.causely.app
unknown
assets.frontegg.com
unknown
cdn.frontegg.com
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.68
www.google.com
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
13.107.253.45
s-part-0017.t-0009.fb-t-msedge.net
United States
192.168.2.4
unknown
unknown
34.160.121.254
portal.causely.app
United States
239.255.255.250
unknown
Reserved
142.250.186.132
unknown
United States
13.35.58.51
di53opyd1sdu2.cloudfront.net
United States
18.245.60.78
unknown
United States
18.245.60.33
d1mr5ezov3l6ny.cloudfront.net
United States

DOM / HTML

URL
Malicious
https://portal.causely.app/
https://portal.causely.app/
https://auth.causely.app/oauth/prelogin?client_id=750050b5-3c87-4d0c-b108-f9e9b4573690&state=41d51d76-ac3d-4501-86db-400dbbe026c3&redirect_uri=https%253A%252F%252Fportal.causely.app%252Foauth%252Fcallback
https://auth.causely.app/oauth/prelogin?client_id=750050b5-3c87-4d0c-b108-f9e9b4573690&state=41d51d76-ac3d-4501-86db-400dbbe026c3&redirect_uri=https%253A%252F%252Fportal.causely.app%252Foauth%252Fcallback
https://auth.causely.app/oauth/prelogin?client_id=750050b5-3c87-4d0c-b108-f9e9b4573690&state=41d51d76-ac3d-4501-86db-400dbbe026c3&redirect_uri=https%253A%252F%252Fportal.causely.app%252Foauth%252Fcallback
https://auth.causely.app/oauth/account/login
https://auth.causely.app/oauth/account/login
https://auth.causely.app/oauth/account/login