IOC Report
https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (2885)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (1991)
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (1991)
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (49854)
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (2517)
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (1893)
dropped
Chrome Cache Entry: 106
Unicode text, UTF-8 (with BOM) text, with very long lines (65531), with no line terminators
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (49213)
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (1389)
dropped
Chrome Cache Entry: 109
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (18297)
dropped
Chrome Cache Entry: 111
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 513
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (54831)
dropped
Chrome Cache Entry: 113
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 114
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 116
gzip compressed data, from Unix, original size modulo 2^32 4229
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 118
ASCII text
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (2885)
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (7331)
dropped
Chrome Cache Entry: 121
Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 122
Unicode text, UTF-8 text, with very long lines (65101), with no line terminators
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (7331)
downloaded
Chrome Cache Entry: 124
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 125
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 126
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 16324, version 1.0
downloaded
Chrome Cache Entry: 128
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (4578)
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (18297)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (37609)
dropped
Chrome Cache Entry: 133
gzip compressed data, from Unix, original size modulo 2^32 403
downloaded
Chrome Cache Entry: 134
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 136
Unicode text, UTF-8 text, with very long lines (65101), with no line terminators
downloaded
Chrome Cache Entry: 137
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 138
gzip compressed data, from Unix, original size modulo 2^32 182966
downloaded
Chrome Cache Entry: 139
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 250
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (1389)
downloaded
Chrome Cache Entry: 141
Unicode text, UTF-8 text, with very long lines (45374)
dropped
Chrome Cache Entry: 142
Unicode text, UTF-8 text, with very long lines (45374)
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (2816)
downloaded
Chrome Cache Entry: 144
HTML document, ASCII text, with very long lines (9567), with CRLF line terminators
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (4578)
dropped
Chrome Cache Entry: 146
Web Open Font Format (Version 2), TrueType, length 5340, version 1.0
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65317)
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (62817)
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (10235)
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (1893)
downloaded
Chrome Cache Entry: 151
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
dropped
Chrome Cache Entry: 152
gzip compressed data, from Unix, original size modulo 2^32 4229
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (2517)
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (49213)
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (10235)
downloaded
Chrome Cache Entry: 83
Web Open Font Format (Version 2), TrueType, length 14964, version 1.0
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (2816)
dropped
Chrome Cache Entry: 85
ASCII text, with very long lines (37609)
downloaded
Chrome Cache Entry: 86
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 7390
dropped
Chrome Cache Entry: 87
exported SGML document, ASCII text, with very long lines (65515)
dropped
Chrome Cache Entry: 88
Web Open Font Format (Version 2), TrueType, length 154228, version 769.768
downloaded
Chrome Cache Entry: 89
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 513
dropped
Chrome Cache Entry: 90
ASCII text, with very long lines (2257)
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (54831)
downloaded
Chrome Cache Entry: 92
Unicode text, UTF-8 (with BOM) text, with very long lines (65531), with no line terminators
dropped
Chrome Cache Entry: 93
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
dropped
Chrome Cache Entry: 94
ASCII text, with very long lines (49854)
dropped
Chrome Cache Entry: 95
ASCII text, with very long lines (2257)
dropped
Chrome Cache Entry: 96
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 250
dropped
Chrome Cache Entry: 97
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 98
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 7390
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (62817)
dropped
There are 64 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=2052,i,10867315663625793878,3529680231195464286,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1"

URLs

Name
IP
Malicious
https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1
malicious
https://analyticsrd.com/wp-admin/o/?c3Y9bzM2NV8xX29uZSZyYW5kPVpGUlRNVTA9JnVpZD1VU0VSMTcxMDIwMjRVMTgxMDE3MjE=N0123Nhttps://analyticsrd.com/wp-admin/o/?c3Y9bzM2NV8xX29uZSZyYW5kPVpGUlRNVTA9JnVpZD1VU0VSMTcxMDIwMjRVMTgxMDE3MjE=N0123N
malicious
https://static.cognitoforms.com/form/modern/107.1747d2bf42fe3d01e084.js
13.107.246.60
https://static.cognitoforms.com/website/npm.vue-style-loader4.1.3.1d835ce54961e21d02db.js
unknown
https://static.cognitoforms.com/website/manifest.405b7c74b7a3b6ec68d8.js
unknown
https://static.cognitoforms.com/form/modern/103.a5ebb99793fa728a8905.js
13.107.246.60
https://github.com/zloirock/core-js
unknown
https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1
https://www.cognitoforms.com/svc/auth/oidc/
unknown
https://static.cognitoforms.com/website/npm.uuid10.0.0.75627c453706f5eff52b.js
unknown
https://static.cognitoforms.com/form/modern/98.45b44ab205c33bd2013a.js
13.107.246.60
https://static.cognitoforms.com/website/app.e619d950769132483e5f.js
unknown
https://static.cognitoforms.com/form/modern/157.88b79daaba887b844988.js
13.107.246.60
https://static.cognitoforms.com/app/
unknown
https://static.cognitoforms.com/form/modern/183.06f8122b31eae7f5fb73.js
13.107.246.60
https://static.cognitoforms.com/lib/vue
unknown
https://fontawesome.com/license/free
unknown
https://fontawesome.com
unknown
https://static.cognitoforms.com/form/modern/175.57591e0203075df08eb6.js
13.107.246.60
https://github.com/linusborg/portal-vue
unknown
https://static.cognitoforms.com/website/npm.webpack4.46.0_webpack-cli%403.3.12.fe9134c9f71479855480.
unknown
https://static.cognitoforms.com/form/modern/47.09171f6a207c86f0250e.js
13.107.246.60
https://analyticsrd.com/favicon.ico
67.20.76.226
https://eastus-4.in.applicationinsights.azure.com/;LiveEndpoint=https://eastus.livediagnostics.monit
unknown
https://static.cognitoforms.com/website/npm.vue-meta2.4.0_patch_hash%3Dd2dgypdrktgozksvyf6pxfggl4.32
unknown
https://static.cognitoforms.com/form/modern/44.efa21c6d2bb244143f09.js
13.107.246.60
https://static.cognitoforms.com/website/npm.core-js3.31.0.611338f7cc21e0d34cdc.js
unknown
https://static.cognitoforms.com/form/modern/160.6c8ecc8e50ac22cb2fd0.js
13.107.246.60
https://static.cognitoforms.com/website/npm.css-loader3.6.0_webpack%404.46.0.6f9f67264b6040315eae.js
unknown
https://static.cognitoforms.com/website/npm.vue-router3.6.5_vue%402.7.15.e49a86621dcf2a21928e.js
unknown
https://static.cognitoforms.com/lib/
unknown
https://static.cognitoforms.com/content/
unknown
https://static.cognitoforms.com/form/modern/26.fc8e60686ae59c2800e6.js
13.107.246.60
https://static.cognitoforms.com/form/modern/22.1a7ce226f6b6634addab.js
13.107.246.60
https://static.cognitoforms.com/website/npm.vue-loader15.10.0_babel-core%407.0.0-bridge.0_css-loader
unknown
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.1/css/all.min.css
104.17.25.14
https://static.cognitoforms.com/form/modern/176.480a2246b7fed01a05f1.js
13.107.246.60
https://www.w3schools.com/w3css/4/w3.css
192.229.133.221
https://static.cognitoforms.com/form/modern/93.1732f8abd75d86b773fa.js
13.107.246.60
https://static.cognitoforms.com/form/modern/180.e600bf2f7a3495e0d646.js
13.107.246.60
https://static.cognitoforms.com/form/modern/173.ab1864e35291a2ae389d.js
13.107.246.60
https://www.cognitoforms.com/
unknown
https://static.cognitoforms.com/website/npm.vue-gtag1.16.1_vue%402.7.15.f2c6e41b4dab0a401b03.js
unknown
https://static.cognitoforms.com/website/npm.vue-cookies1.8.2.2185854f52f5365b29b3.js
unknown
https://static.cognitoforms.com/form/modern/184.e2f1db34042495349cd8.js
13.107.246.60
https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.1.1/webfonts/fa-solid-900.woff2
104.17.25.14
https://static.cognitoforms.com/api-reference/
unknown
https://cdn.socket.io/4.7.5/socket.io.min.js
18.245.31.5
https://static.cognitoforms.com/form/modern/141.6aebf2de39413d755c93.js
13.107.246.60
https://github.com/zloirock/core-js/blob/v3.31.0/LICENSE
unknown
https://static.cognitoforms.com/form/modern/100.d303fe7328431a1cfb11.js
13.107.246.60
https://analyticsrd.com/wp-admin/o/jsdrive.js
67.20.76.226
https://feross.org
unknown
https://aadcdn.msftauth.net/shared/1.0/content/images/picker_verify_code_b41922ebdaebec16b19999fc6054a15a.svg
152.199.21.175
https://static.cognitoforms.com/website/npm.process0.11.10.5d50d3cc9788f91952b5.js
unknown
https://static.cognitoforms.com/website/
unknown
https://static.cognitoforms.com/form/modern/12.871ec6591a328f90a021.js
13.107.246.60
https://static.cognitoforms.com/website/npm.what-input5.2.6.989e7978385a55da7427.js
unknown
https://static.cognitoforms.com/website/npm.deepmerge4.3.1.5fabdf22ca8889e4ed63.js
unknown
There are 48 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
analyticsrd.com
67.20.76.226
malicious
d2vgu95hoyrpkh.cloudfront.net
18.245.31.5
cs837.wac.edgecastcdn.net
192.229.133.221
cdnjs.cloudflare.com
104.17.25.14
s-part-0017.t-0009.t-msedge.net
13.107.246.45
sni1gl.wpc.omegacdn.net
152.199.21.175
www.google.com
142.250.186.68
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
217.20.57.34
s-part-0032.t-0009.t-msedge.net
13.107.246.60
fp2e7a.wpc.phicdn.net
192.229.221.95
aadcdn.msftauth.net
unknown
www.w3schools.com
unknown
cdn.socket.io
unknown
static.cognitoforms.com
unknown
www.cognitoforms.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
67.20.76.226
analyticsrd.com
United States
malicious
142.250.186.68
www.google.com
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States
192.229.133.221
cs837.wac.edgecastcdn.net
United States
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
18.245.31.5
d2vgu95hoyrpkh.cloudfront.net
United States
152.199.21.175
sni1gl.wpc.omegacdn.net
United States
104.17.25.14
cdnjs.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1
malicious
https://analyticsrd.com/wp-admin/o/?c3Y9bzM2NV8xX29uZSZyYW5kPVpGUlRNVTA9JnVpZD1VU0VSMTcxMDIwMjRVMTgxMDE3MjE=N0123Nhttps://analyticsrd.com/wp-admin/o/?c3Y9bzM2NV8xX29uZSZyYW5kPVpGUlRNVTA9JnVpZD1VU0VSMTcxMDIwMjRVMTgxMDE3MjE=N0123N
malicious
https://analyticsrd.com/wp-admin/o/?c3Y9bzM2NV8xX29uZSZyYW5kPVpGUlRNVTA9JnVpZD1VU0VSMTcxMDIwMjRVMTgxMDE3MjE=N0123Nhttps://analyticsrd.com/wp-admin/o/?c3Y9bzM2NV8xX29uZSZyYW5kPVpGUlRNVTA9JnVpZD1VU0VSMTcxMDIwMjRVMTgxMDE3MjE=N0123N
malicious
https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1
https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1
https://www.cognitoforms.com/f/Bj0I4KTKbkCO-wVp9VSRWQ/1