IOC Report
https://demnpl.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
HTML document, ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 101
data
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (11256), with no line terminators
downloaded
Chrome Cache Entry: 103
HTML document, ASCII text, with very long lines (1107), with no line terminators
downloaded
Chrome Cache Entry: 104
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1080x1080, components 3
downloaded
Chrome Cache Entry: 105
HTML document, ASCII text
dropped
Chrome Cache Entry: 106
ASCII text, with very long lines (2570), with no line terminators
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (684), with CRLF line terminators
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (65472)
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (1191), with no line terminators
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (11513), with no line terminators
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (561)
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (57765)
downloaded
Chrome Cache Entry: 113
HTML document, ASCII text
downloaded
Chrome Cache Entry: 114
Web Open Font Format, TrueType, length 48468, version 1.0
downloaded
Chrome Cache Entry: 115
HTML document, Unicode text, UTF-8 text, with very long lines (13135), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 116
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 820x307, components 3
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (60051)
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (501)
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (65472)
dropped
Chrome Cache Entry: 120
gzip compressed data, max compression, original size modulo 2^32 424649
dropped
Chrome Cache Entry: 121
PNG image data, 300 x 97, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (561)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (65266)
dropped
Chrome Cache Entry: 124
HTML document, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (11203)
downloaded
Chrome Cache Entry: 126
Unicode text, UTF-8 text, with very long lines (64820)
downloaded
Chrome Cache Entry: 127
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1276x720, components 3
downloaded
Chrome Cache Entry: 128
Web Open Font Format (Version 2), TrueType, length 39744, version 1.0
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 130
gzip compressed data, max compression, original size modulo 2^32 613721
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (65266)
downloaded
Chrome Cache Entry: 133
Unicode text, UTF-8 text, with very long lines (61201)
downloaded
Chrome Cache Entry: 134
gzip compressed data, max compression, original size modulo 2^32 424649
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (60051)
dropped
Chrome Cache Entry: 84
Unicode text, UTF-8 text, with very long lines (41292)
downloaded
Chrome Cache Entry: 85
gzip compressed data, max compression, original size modulo 2^32 93361
downloaded
Chrome Cache Entry: 86
ASCII text, with very long lines (3581)
downloaded
Chrome Cache Entry: 87
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1080x1080, components 3
downloaded
Chrome Cache Entry: 88
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1556x720, components 3
downloaded
Chrome Cache Entry: 89
ASCII text, with very long lines (501)
downloaded
Chrome Cache Entry: 90
Web Open Font Format (Version 2), TrueType, length 112440, version 1.0
downloaded
Chrome Cache Entry: 91
gzip compressed data, max compression, original size modulo 2^32 2154562
dropped
Chrome Cache Entry: 92
ASCII text, with very long lines (2369), with CRLF line terminators
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (37646)
downloaded
Chrome Cache Entry: 94
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 499x320, components 3
downloaded
Chrome Cache Entry: 95
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 96
gzip compressed data, max compression, original size modulo 2^32 2495811
dropped
Chrome Cache Entry: 97
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 98
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1080x1080, components 3
downloaded
Chrome Cache Entry: 99
HTML document, ASCII text, with very long lines (54962)
downloaded
There are 43 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2384 --field-trial-handle=2344,i,17116983721634579967,12043951783507488369,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://demnpl.com/"

URLs

Name
IP
Malicious
https://demnpl.com/
https://github.com/mjhasbach)
unknown
https://demnpl.com/wp-content/plugins/wp-job-manager/assets/dist/css/job-listings.css?ver=598383a28a
unknown
https://github.com/svgdotjs/svg.draggable.js
unknown
https://twitter.com/nddemnpl/status/1846694402892116038
unknown
https://demnpl.com/wp-content/uploads/2018/01/cropped-darkblueDemNPLsmall-32x32.png
unknown
https://swift-cpa.net/assets/logos/1.jpg
unknown
https://www.youtube.com/embed/
unknown
https://swift-cpa.net/assets/css/custom.css
216.239.32.21
https://swift-cpa.net/donate/submit
unknown
https://demnpl.com/wp-content/plugins/duracelltomi-google-tag-manager/dist/js/gtm4wp-form-move-track
unknown
https://twitter.com/intent/retweet?tweet_id=1846927359519170773&related=McFeely_Inforum
unknown
https://demnpl.com/wp-content/plugins/wp-job-manager/assets/dist/css/job-listings.css?ver=598383a28ac5f9f156e4
172.67.223.194
https://twitter.com/intent/like?tweet_id=1846694456918995293&related=KatrinaforND
unknown
https://www.youtube.com
unknown
http://www.opensource.org/licenses/mit-license.php
unknown
https://twitter.com/intent/retweet?tweet_id=1847356897654870343&related=zacista
unknown
https://demnpl.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.9.8
172.67.223.194
https://demnpl.com/wp-content/uploads/2018/01/cropped-darkblueDemNPLsmall-192x192.png
unknown
https://demnpl.com/our-party/district-officers/
unknown
https://twitter.com/intent/like?tweet_id=1847356923923853571&related=KatrinaforND
unknown
https://demnpl.com/event/d13-meeting-rep-karla-rose-hanson-and-free-drinks/
unknown
https://demnpl.com/wp-content/uploads/dynamic_avia/avia-footer-scripts-b9a521a4cb8d3272acac3f2f2252c
unknown
https://demnpl.com/wp-content/uploads/dynamic_avia/avia-head-scripts-7972c19c7c64abca74a00b9799d4540
unknown
https://pbs.twimg.com/ext_tw_video_thumb/1846764118327676929/pu/img/z-Yv6VFoRWfzW9Ha.jpg:large
199.232.188.159
http://www.datatables.net
unknown
https://demnpl.com/wp-admin/admin-ajax.php
unknown
https://demnpl.com/comments/feed/
unknown
https://swift-cpa.net/assets/plugins/custom/prismjs/prismjs.bundle.css
216.239.32.21
http://www.mediaelementjs.com/
unknown
https://demnpl.com/wp-content/plugins/custom-facebook-feed-pro/assets/js/cff-scripts.min.js?ver=4.5.3
172.67.223.194
https://fengyuanchen.github.io/cropperjs
unknown
https://demnpl.com/download/
unknown
https://demnpl.com/#website
unknown
https://swift-cpa.net/assets/plugins/custom/prismjs/prismjs.bundle.js
216.239.32.21
https://swift-cpa.net/assets/css/style.bundle.css
216.239.32.21
https://demnpl.com/our-party/contact-us/
unknown
https://demnpl.com/#organization
unknown
https://schema.org/VideoObject
unknown
https://demnpl.com/wp-content/plugins/download-monitor/assets/js/dlm-xhr.min.js?ver=5.0.12
172.67.223.194
https://demnpl.com/wp-content/plugins/easy-table-of-contents/vendor/sticky-kit/jquery.sticky-kit.min
unknown
https://schema.org
unknown
https://demnpl.com/wp-includes/js/mediaelement/wp-mediaelement.min.css?ver=6.6.2
172.67.223.194
https://demnpl.com/our-party/job-opportunities/
unknown
https://twitter.com/intent/retweet?tweet_id=1846694402892116038&related=nddemnpl
unknown
https://demnpl.com/wp-content/uploads/dynamic_avia/avia_posts_css/post-206.css?ver=ver-1728664424
172.67.223.194
https://demnpl.com/wp-content/uploads/2024/02/Dem-NPL.jpg
unknown
https://demnpl.com/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/assets/fonts/entypo-fontello.woff
172.67.223.194
https://demnpl.com/wp-includes/js/mediaelement/mediaelementplayer-legacy.min.css?ver=4.2.17
172.67.223.194
https://pbs.twimg.com/profile_images/1410698050889293831/kQKodwhs_normal.jpg
199.232.188.159
https://schema.org/WPHeader
unknown
https://swift-cpa.net/assets/plugins/custom/datatables/datatables.bundle.js
216.239.32.21
https://jquery.com/
unknown
https://demnpl.com/#/schema/logo/image/
unknown
https://quilljs.com/
unknown
https://demnpl.com/privacy-policy-2/
unknown
https://demnpl.com/wp-content/uploads/2024/01/demnpl_logo_reversed-e1705678476360-80x26.png
unknown
https://github.com/js-cookie/js-cookie
unknown
https://demnpl.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
172.67.223.194
https://twitter.com/intent/like?tweet_id=1847356877539025201&related=nddemnpl
unknown
https://lea.verou.me
unknown
https://sizzlejs.com/
unknown
https://store.demnpl.com/
unknown
https://demnpl.com/event/executive-committee-meeting-9/2024-12-18/
unknown
https://twitter.com/zacista
unknown
https://pbs.twimg.com/card_img/1846763867713544192/u79yh6IT?format=jpg&name=800x320_1
199.232.188.159
https://twitter.com/intent/like?tweet_id=1847356897654870343&related=zacista
unknown
https://yoast.com/wordpress/plugins/seo/
unknown
https://demnpl.com/wp-content/plugins/easy-table-of-contents/vendor/sticky-kit/jquery.sticky-kit.min.js?ver=1.9.2
172.67.223.194
https://www.youtube.com/s/player/e627e516/www-widgetapi.vflset/www-widgetapi.js
142.250.186.110
https://s1.bcbits.com/img/buttons/bandcamp_22x22_blue.png
unknown
https://opensource.org/licenses/MIT
unknown
https://pbs.twimg.com/profile_images/1714094764725858304/msVAOO9U_normal.jpg
199.232.188.159
https://swift-cpa.net/dashboard
unknown
https://pbs.twimg.com/media/GaDGBiqW8AAeXKs.jpg
unknown
https://demnpl.com/wp-content/themes/enfold/config-templatebuilder/avia-template-builder/assets/fonts/entypo-fontello.woff2
172.67.223.194
https://swift-cpa.net/assets/plugins/custom/cropper/cropper.bundle.css
216.239.32.21
https://demnpl.com/resources/party-platform-resolutions/
unknown
https://demnpl.com/our-party/elected-officials/
unknown
https://demnpl.com/wp-includes/js/dist/hooks.min.js?ver=2810c76e705dd1a53b18
172.67.223.194
https://demnpl.com/wp-content/plugins/custom-facebook-feed-pro/assets/js/cff-scripts.min.js?ver=4.5.
unknown
https://developers.google.com/youtube/iframe_api_reference#Events
unknown
https://swift-cpa.net/favicon.ico
216.239.32.21
http://datatables.net/license
unknown
https://secure.actblue.com/donate/ccjoin?refcode=demnplwebsite
unknown
https://swift-cpa.net/donate/NDDemNPLCenturyClub
unknown
https://swift-cpa.net/assets/js/tinymce/tinymce.min.js
216.239.32.21
https://github.com/paulmillr/es6-shim/blob/0.35.3/LICENSE
unknown
https://demnpl.com/wp-content/plugins/events-calendar-pro/src/resources/css/tribe-events-pro-mini-calendar-block.min.css?ver=7.2.0
172.67.223.194
http://paulmillr.com)
unknown
https://demnpl.com/
http://daneden.me/animate
unknown
https://demnpl.com/xmlrpc.php
unknown
https://demnpl.com/terms-of-service/
unknown
https://twitter.com/intent/like?tweet_id=1846927359519170773&related=McFeely_Inforum
unknown
https://pbs.twimg.com/media/GaDGBiqW8AAeXKs.jpg:large
199.232.188.159
https://demnpl.com/wp-content/plugins/easy-table-of-contents/assets/js/smooth_scroll.min.js?ver=2.0.69.1
172.67.223.194
https://demnpl.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
172.67.223.194
https://github.com/wout/svg.filter.js
unknown
https://demnpl.com/wp-content/plugins/easy-table-of-contents/assets/js/front.min.js?ver=2.0.69.1-172
unknown
https://twitter.com/intent/retweet?tweet_id=1845875308873855301&related=nddemnpl
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
stats.wp.com
192.0.76.3
secure.gravatar.com
192.0.73.2
a.nel.cloudflare.com
35.190.80.1
youtube-ui.l.google.com
142.250.186.110
demnpl.com
172.67.223.194
dualstack.twimg.twitter.map.fastly.net
199.232.188.159
swift-cpa.net
216.239.32.21
s-part-0017.t-0009.t-msedge.net
13.107.246.45
lb.wordpress.com
192.0.78.13
www.google.com
216.58.206.36
fp2e7a.wpc.phicdn.net
192.229.221.95
s.btstatic.com
unknown
pbs.twimg.com
unknown
www.youtube.com
unknown
v0.wordpress.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.168.2.4
unknown
unknown
216.58.206.36
www.google.com
United States
104.21.78.163
unknown
United States
142.250.185.142
unknown
United States
216.239.34.21
unknown
United States
142.250.186.110
youtube-ui.l.google.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
216.239.32.21
swift-cpa.net
United States
192.0.76.3
stats.wp.com
United States
239.255.255.250
unknown
Reserved
142.250.186.142
unknown
United States
199.232.188.159
dualstack.twimg.twitter.map.fastly.net
United States
172.67.223.194
demnpl.com
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://demnpl.com/
https://swift-cpa.net/donate/demnpl