Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Douglas County Government.pdf
|
PDF document, version 1.7, 1 pages
|
initial sample
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\8980f2a4-5068-4961-9e87-a8a3756bd2e6.tmp
|
JSON data
|
modified
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
|
data
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
|
ASCII text
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-241023224715Z-158.bmp
|
PC bitmap, Windows 3.x format, 164 x -115 x 32, cbSize 75494, bits offset 54
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
|
Certificate, Version=3
|
dropped
|
||
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt23.lst.4012
|
PostScript document text
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst (copy)
|
PostScript document text
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\Edit_InApp_Aug2020
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTING
|
data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json
|
JSON data
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents
|
SQLite 3.x database, last written using SQLite version 3040000, file counter 19, database pages 3, cookie 0x2, schema 4, UTF-8,
version-valid-for 19
|
dropped
|
||
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal
|
SQLite Rollback Journal
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\MSIb0744.LOG
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-10-23 18-47-13-990.log
|
ASCII text, with very long lines (393)
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
|
ASCII text, with very long lines (393), with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\21394f33-e000-4272-aa93-10b1d3146789.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 33081
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\5bd09822-b773-4e3f-ae3e-a5fd7f0dc620.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\724b51ca-0f96-4929-bca6-605504695f61.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\acrocef_low\8ee7eb4d-7751-408a-9c24-1e7520b4640c.tmp
|
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:47:39 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:47:39 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:47:39 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:47:39 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 21:47:39 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 242
|
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 243
|
ASCII text, with very long lines (10956), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 244
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 245
|
ASCII text, with very long lines (24745), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 246
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 247
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 248
|
ASCII text, with very long lines (65448)
|
downloaded
|
||
Chrome Cache Entry: 249
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 250
|
ASCII text, with very long lines (19948), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 251
|
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 252
|
ASCII text, with very long lines (1297), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 253
|
PNG image data, 128 x 128, 8-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 254
|
ASCII text, with very long lines (12331)
|
dropped
|
||
Chrome Cache Entry: 255
|
ASCII text, with very long lines (21229)
|
downloaded
|
||
Chrome Cache Entry: 256
|
PNG image data, 94 x 13, 8-bit/color RGB, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 257
|
ASCII text, with very long lines (47531)
|
downloaded
|
||
Chrome Cache Entry: 258
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 259
|
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 260
|
Unicode text, UTF-8 text, with very long lines (59934)
|
downloaded
|
||
Chrome Cache Entry: 261
|
ASCII text, with very long lines (1297), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 262
|
ASCII text, with very long lines (19948), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 263
|
ASCII text, with very long lines (47531)
|
dropped
|
||
Chrome Cache Entry: 264
|
Unicode text, UTF-8 text, with very long lines (65514), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 265
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 266
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 267
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 268
|
GIF image data, version 89a, 512 x 109
|
dropped
|
||
Chrome Cache Entry: 269
|
HTML document, Unicode text, UTF-8 text, with very long lines (49838)
|
downloaded
|
||
Chrome Cache Entry: 270
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 271
|
PNG image data, 28 x 7, 8-bit/color RGB, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 272
|
ASCII text, with very long lines (19711), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 273
|
Unicode text, UTF-8 text, with very long lines (65514), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 274
|
Unicode text, UTF-8 text, with very long lines (12183), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 275
|
ASCII text, with very long lines (10956), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 276
|
Unicode text, UTF-8 text, with very long lines (59934)
|
dropped
|
||
Chrome Cache Entry: 277
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 278
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 279
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 280
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 281
|
ASCII text, with very long lines (47531)
|
dropped
|
||
Chrome Cache Entry: 282
|
ASCII text, with very long lines (65448)
|
dropped
|
||
Chrome Cache Entry: 283
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 284
|
ASCII text, with very long lines (6371), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 285
|
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1080, components
3
|
dropped
|
||
Chrome Cache Entry: 286
|
ASCII text, with very long lines (1993), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 287
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 288
|
ASCII text, with very long lines (65451)
|
dropped
|
||
Chrome Cache Entry: 289
|
SVG Scalable Vector Graphics image
|
dropped
|
||
Chrome Cache Entry: 290
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 291
|
ASCII text, with very long lines (65451)
|
downloaded
|
||
Chrome Cache Entry: 292
|
PNG image data, 1200 x 682, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 293
|
Unicode text, UTF-8 text, with very long lines (6736)
|
downloaded
|
||
Chrome Cache Entry: 294
|
ASCII text, with very long lines (47531)
|
downloaded
|
||
Chrome Cache Entry: 295
|
PNG image data, 94 x 13, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 296
|
Unicode text, UTF-8 text, with very long lines (12183), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 297
|
GIF image data, version 89a, 512 x 109
|
downloaded
|
||
Chrome Cache Entry: 298
|
ASCII text, with very long lines (6371), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 299
|
PNG image data, 28 x 7, 8-bit/color RGB, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 300
|
SVG Scalable Vector Graphics image
|
downloaded
|
||
Chrome Cache Entry: 301
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 302
|
ASCII text, with very long lines (24745), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 303
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 304
|
PNG image data, 740 x 417, 8-bit/color RGBA, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 305
|
ASCII text, with very long lines (1888), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 306
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 307
|
RIFF (little-endian) data, Web/P image, VP8 encoding, 1920x1080, Scaling: [none]x[none], YUV color, decoders should clamp
|
downloaded
|
||
Chrome Cache Entry: 308
|
ASCII text, with very long lines (19711), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 309
|
ASCII text, with very long lines (21229)
|
dropped
|
||
Chrome Cache Entry: 310
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 311
|
ASCII text, with very long lines (12331)
|
downloaded
|
||
Chrome Cache Entry: 312
|
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 313
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 314
|
SVG Scalable Vector Graphics image
|
downloaded
|
There are 113 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
|
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Desktop\Douglas County Government.pdf"
|
||
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
|
"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
|
||
C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
|
"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService
--lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0"
--lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log"
--mojo-platform-channel-handle=2112 --field-trial-handle=1624,i,3420940882992899796,5918126225781464680,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "https://docsend.com/view/38rmsxw2rqttb6y7"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=2000,i,11787863858956306339,6698784503857347572,262144
/prefetch:8
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://douglascounty.kaisersupportcom.top/favicon.ico
|
104.21.38.65
|
||
https://douglascounty.kaisersupportcom.top/
|
|||
https://douglascounty.kaisersupportcom.top/cdn-cgi/challenge-platform/h/g/flow/ov1/1451975782:1729702611:0qtH7wiHSXfSm8ThNkB3Xmy0RtCRo-FmzlQZKEB5CkU/8d7548767f496bd4/afEE6SNnJBGCDUyJuS3NOD37egeHSO5NFDrSkyAE5.M-1729723794-1.1.1.1-YhwlWL.f1SLhhSNr53mvD.mTuxxEV7t8578_GEyCXLPDDRiiMN6xsmJ6JBauKZzF
|
104.21.38.65
|
||
https://douglascounty.kaisersupportcom.top/cdn-cgi/challenge-platform/h/g/orchestrate/chl_page/v1?ray=8d7548767f496bd4
|
104.21.38.65
|
||
https://douglascounty.kaisersupportcom.top/cdn-cgi/challenge-platform/h/g/flow/ov1/2090729619:1729702676:lJB0S3t_FBR248aVBsmmA0VT9wPuqkXGrG_urIqmhn4/8d75453998b7359f/rL1Iq3H6DZGqZiuPrzWLqGAd_06LswnA8PHkCSj1Y1Q-1729723662-1.1.1.1-d.7wQlTw_yRUJClTJ0cHDEF0qlvy7BQzWOVl_ntdEDvwJULkO0RCPpBA19PNqr3E
|
104.21.38.65
|
||
https://douglascounty.kaisersupportcom.top/cdn-cgi/challenge-platform/h/g/orchestrate/chl_page/v1?ray=8d75453998b7359f
|
104.21.38.65
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/xAb8mJ3D3jImhUIC6I781/4e5fcde46add21ab9e397610b06c8e32/security-waf.svg
|
104.16.123.96
|
||
https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015
|
104.16.79.73
|
||
https://www.cloudflare.com/webpack-runtime-9f6316ec3a7bc7220341.js
|
104.16.123.96
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/3D8wYZZswWtE486uIMyN5A/55dd91b1589218af33a25c22adb
|
unknown
|
||
https://www.cloudflare.com/cdn-cgi/rum?
|
104.16.123.96
|
||
https://px.ads.linkedin.com/collect/?pid=28851&fmt=gif
|
unknown
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=8d75488a5b3d3064&lang=auto
|
104.18.94.41
|
||
https://www.cloudflare.com/page-data/sq/d/3199558980.json
|
104.16.123.96
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8d75454d7933468c/1729723668032/a154fb0cdc278adbe6c18088ea129130318dd96aa8406207d93374e8bcdde6dd/SyApLHEKHWfWehu
|
104.18.94.41
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8d75488a5b3d3064/1729723801411/zLqcVgzpl2t984g
|
104.18.94.41
|
||
https://performance.radar.cloudflare.com/beacon.js
|
104.18.30.78
|
||
https://alb.reddit.com/rp.gif?event=PageVisit&id=t2_1upmecjq&ts=1729723826131&uuid=43e27674-ff4e-44a7-8d7c-46b4926f71c1&integration=reddit&opt_out=0&v=rdt_65e23bc4&sh=1024&sw=1280
|
151.101.129.140
|
||
https://www.cloudflare.com/component---src-components-page-page-template-tsx-d45b6e355a31d828fc9b.js
|
104.16.123.96
|
||
https://alb.reddit.com/rp.gif?event=PageVisit&id=t2_1upmecjq&ts=1729723826131&uuid=43e27674-ff4e-44a
|
unknown
|
||
https://px.ads.linkedin.com/collect/?fmt=js&v=2&url=https%3A%2F%2Fwww.cloudflare.com%2Fproducts%2Ftu
|
unknown
|
||
https://a.nel.cloudflare.com/report/v4?s=wRz4M57DftrcPij1TbHq3BDETA%2Fr6MXkH9Y32KMmSqmhDRzA48UcgkWjD2LMLAuWtMkk06jB7CiUWLCDuQIpylXQ2NG5V4X14H86Xs2WDTXAwoKtwh%2F7m5rGSZKd7%2BPhcthACMtjUquD%2BzamJRDPeEtqTdlt
|
35.190.80.1
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/3WQ3rA9q6N1W2Zig4rIoCu/66daf32fef3dda35b1150ad9e3a728ec/face-happy.svg
|
104.16.123.96
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/6wvLylL1UDvEfh7N5WBd32/44ff9093b6aa1feb33d12d020ce756df/Generic_Orange_Background.jpeg
|
104.16.123.96
|
||
https://ot.www.cloudflare.com/public/vendor/onetrust/scripttemplates/202407.2.0/otBannerSdk.js
|
104.16.123.96
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/6i8d186tH2iueYvgwVRaJf/ab27fd31033bdd31aea69065480
|
unknown
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/d8npb/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/normal/auto/
|
104.18.94.41
|
||
https://www.cloudflare.com/page-data/index/page-data.json
|
104.16.123.96
|
||
https://t.co/1/i/adsct?bci=4&eci=3&event=%7B%7D&event_id=42bbb843-2044-4f81-9b41-8a77f4dd2785&integration=advertiser&p_id=Twitter&p_user_id=0&pl_id=c383e5af-68a5-4f28-be33-250c81292123&restricted_data_use=restrict_optimization&tw_document_href=https%3A%2F%2Fwww.cloudflare.com%2Fproducts%2Fturnstile%2F%3Futm_source%3Dturnstile%26utm_campaign%3Dwidget&tw_iframe_status=0&txn_id=nvldc&type=javascript&version=2.3.30
|
162.159.140.229
|
||
https://www.cloudflare.com/static/z/i.js
|
104.16.123.96
|
||
https://s.company-target.com/s/sync?exc=lr
|
34.96.71.22
|
||
https://docsend.com/view/38rmsxw2rqttb6y7
|
18.173.205.79
|
||
https://ot.www.cloudflare.com/public/vendor/onetrust/consent/b1e05d49-f072-4bae-9116-bdb78af15448/b1e05d49-f072-4bae-9116-bdb78af15448.json
|
104.16.123.96
|
||
https://js.qualified.com/qualified.js?token=37pXYrro6wCZbsU7
|
104.18.17.5
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/4sfL2iS6H10uq2waT6ehym/ad18b77fa469ce07f23d22e19ab
|
unknown
|
||
https://www.cloudflare.com/page-data/products/turnstile/page-data.json?utm_source=turnstile&utm_campaign=widget
|
104.16.123.96
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/orchestrate/chl_api/v1?ray=8d75454d7933468c&lang=auto
|
104.18.94.41
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/pat/8d75488a5b3d3064/1729723801410/a6d042a86dd1c47f3825369b480c0efa18aaefb83874e96c1b0790da55ccc93e/BpKwii18EftUJz8
|
104.18.94.41
|
||
https://ot.www.cloudflare.com/public/vendor/onetrust/scripttemplates/otSDKStub.js
|
104.16.123.96
|
||
https://www.cloudflare.com/page-data/sq/d/3934964512.json
|
104.16.123.96
|
||
https://cdn.logr-ingest.com/logger-1.min.js
|
188.114.97.3
|
||
https://ot.www.cloudflare.com/public/vendor/onetrust/scripttemplates/202407.2.0/assets/otCommonStyles.css
|
104.16.123.96
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/6XZNNCKiwCK1UDu172GYRH/68e06d955363531a6af2d93b4fc
|
unknown
|
||
https://dpm.demdex.net/id?d_visid_ver=5.5.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_orgid=8AD56F28618A50850A495FB6%40AdobeOrg&d_nsid=0&ts=1729723826446
|
54.76.121.43
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/42XkFj9Uywkm8Jahf62RtP/0563d91cc1fa54da2bf2c50bad8
|
unknown
|
||
https://tag.demandbase.com/1be41a80498a5b73.min.js
|
3.161.119.112
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/flow/ov1/2060912702:1729702575:DRKz3oklNGXlKmLBY99PWZYhj1Aro0BM-NRRvPl6PbM/8d75488a5b3d3064/kLqEeiqkqUqakeivvXfabcBWAUiTT0rFYZ6tPpEtLG4-1729723798-1.1.1.1-xrfsGhmFwmFR4Jn5d.gkvP1YUXEctnOe0.4sJ_uJw1KNIHgYYFUoglcGam_icgR1
|
104.18.94.41
|
||
https://www.google.com/ads/ga-audiences?t=sr&aip=1&_r=4&v=1&_v=j86&tid=G-PGV1K2BN4M&cid=b101c247-b75c-4081-9bb0-3a819bcbbd80&_u=KGDAAEADQAAAAC%7E&z=1763847113&slf_rd=1
|
142.250.185.164
|
||
https://www.cloudflare.com/page-data/sq/d/1048862057.json
|
104.16.123.96
|
||
https://challenges.cloudflare.com/turnstile/v0/g/f2bbd6738e15/api.js
|
104.18.94.41
|
||
https://www.cloudflare.com/static/enablement-background-6de78040ef0acc8d2e8a596988c5f5d8.svg
|
104.16.123.96
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/6XZNNCKiwCK1UDu172GYRH/68e06d955363531a6af2d93b4fcaa543/BDES-4897_-_bot-analytics-hero-illustration.png
|
104.16.123.96
|
||
http://x1.i.lencr.org/
|
unknown
|
||
https://di.rlcdn.com/710030.gif?pdata=d=desktop,lc=US,utms=turnstile,utmc=widget
|
35.244.174.68
|
||
https://gateway.on24.com/wcc/eh/2153307/lp/4335273/
|
unknown
|
||
https://github.com/jonsuh/hamburgers
|
unknown
|
||
https://www.cloudflare.com/forrester-wave-bot-management-2024/
|
unknown
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/2atsfrGgvgOc3DZ91qMlKN/0412afa63e5fac20964377c70c1a9a17/turnstile_gif.gif
|
104.16.123.96
|
||
https://www.cloudflare.com/page-data/plans/enterprise/contact/page-data.json
|
104.16.123.96
|
||
https://jonsuh.com/hamburgers
|
unknown
|
||
https://cdn.bizible.com/scripts/bizible.js
|
152.195.15.58
|
||
https://www.cloudflare.com/cdn-cgi/scripts/7d0fa10a/cloudflare-static/rocket-loader.min.js
|
104.16.123.96
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/i/8d75454d7933468c/1729723668030/V-yd8zqzS3fbJpi
|
104.18.94.41
|
||
https://a.nel.cloudflare.com/report/v4?s=OFtQGotuHaJi21ZWKN2%2Fr3Esr9vt9BCSK6vovQmWYStuWYYfMlfxLSMvnMKYr5bga5y1zA5rPS1dPmrVilh4k%2Bwtaon7Ip1I9ZUTvEAzXXRj6dkW6Fmgq4eldD5X1hy90XTxSG4ms9xG5k%2BIka7kOH4HeB36
|
35.190.80.1
|
||
https://docsend.com/view/38rmsxw2rqttb6y7)
|
unknown
|
||
https://www.cloudflare.com/a06cff934e9579536ce1c10bad21c1d6d7f63ae0-90484db4602d401d94ca.js
|
104.16.123.96
|
||
https://www.cloudflare.com/static/z/t
|
104.16.123.96
|
||
https://www.cloudflare.com/static/z/s.js?z=
|
unknown
|
||
https://www.cloudflare.com/page-data/sq/d/333361657.json
|
104.16.123.96
|
||
https://www.cloudflare.com/627-507b7039361c0b7b039c.js
|
104.16.123.96
|
||
https://www.cloudflare.com
|
unknown
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/3D8wYZZswWtE486uIMyN5A/55dd91b1589218af33a25c22adb729e0/End_of_the_Road_for_Captchas.png
|
104.16.123.96
|
||
https://static.ads-twitter.com/uwt.js
|
199.232.188.157
|
||
https://www.cloudflare.com/174-242772ef10d8d161ae24.js
|
104.16.123.96
|
||
https://snap.licdn.com/li.lms-analytics/insight.min.js
|
unknown
|
||
https://api.company-target.com/api/v3/ip.json?referrer=&page=https%3A%2F%2Fwww.cloudflare.com%2Fproducts%2Fturnstile%2F%3Futm_source%3Dturnstile%26utm_campaign%3Dwidget&page_title=Cloudflare%20Turnstile%2C%20a%20free%20CAPTCHA%20replacement%20%7C%20Cloudflare
|
18.66.102.85
|
||
https://www.cloudflare.com/img/privacyoptions.svg
|
104.16.123.96
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/7p4ub/0x4AAAAAAADnPIDROrmt1Wwj/light/fbE/normal/auto/
|
104.18.94.41
|
||
https://stats.g.doubleclick.net/g/collect?t=dc&aip=1&_r=3&v=1&_v=j86&tid=G-PGV1K2BN4M&cid=b101c247-b75c-4081-9bb0-3a819bcbbd80&_u=KGDAAEADQAAAAC%7E&z=1763847113
|
64.233.166.154
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/6wvLylL1UDvEfh7N5WBd32/44ff9093b6aa1feb33d12d020ce
|
unknown
|
||
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/cmg/1
|
104.18.94.41
|
||
https://ot.www.cloudflare.com/public/vendor/onetrust/consent/b1e05d49-f072-4bae-9116-bdb78af15448/018debfb-4917-76f1-8862-8a2f83812baa/en.json
|
104.16.123.96
|
||
https://www.cloudflare.com/static/z/s.js?z=JTdCJTIyZXhlY3V0ZWQlMjIlM0ElNUIlNUQlMkMlMjJ0JTIyJTNBJTIyQ2xvdWRmbGFyZSUyMFR1cm5zdGlsZSUyQyUyMGElMjBmcmVlJTIwQ0FQVENIQSUyMHJlcGxhY2VtZW50JTIwJTdDJTIwQ2xvdWRmbGFyZSUyMiUyQyUyMnglMjIlM0EwLjI5Njg3ODY3NDY1MjgzODQ2JTJDJTIydyUyMiUzQTEyODAlMkMlMjJoJTIyJTNBMTAyNCUyQyUyMmolMjIlM0E4NzAlMkMlMjJlJTIyJTNBMTAzNCUyQyUyMmwlMjIlM0ElMjJodHRwcyUzQSUyRiUyRnd3dy5jbG91ZGZsYXJlLmNvbSUyRnByb2R1Y3RzJTJGdHVybnN0aWxlJTJGJTNGdXRtX3NvdXJjZSUzRHR1cm5zdGlsZSUyNnV0bV9jYW1wYWlnbiUzRHdpZGdldCUyMiUyQyUyMnIlMjIlM0ElMjIlMjIlMkMlMjJrJTIyJTNBMjQlMkMlMjJuJTIyJTNBJTIyVVRGLTglMjIlMkMlMjJvJTIyJTNBMjQwJTJDJTIycSUyMiUzQSU1QiU1RCU3RA==
|
104.16.123.96
|
||
https://www.cloudflare.com/page-data/app-data.json
|
104.16.123.96
|
||
https://github.com/js-cookie/js-cookie
|
unknown
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/mJZqOomHta2MLLB73P8Hs/9378861761815b3adf7bcb7734d6
|
unknown
|
||
https://www.cloudflare.com/favicon.ico
|
104.16.123.96
|
||
https://api.www.cloudflare.com/api/v1
|
unknown
|
||
https://www.cloudflare.com/app-abefbc6244796d8fb229.js
|
104.16.123.96
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
|||
https://www.cloudflare.com/framework-957a522640f43541ca6a.js
|
104.16.123.96
|
||
https://staging.mrk.cfdata.org/mrk/redwood-blade-repository/
|
unknown
|
||
https://cf-assets.www.cloudflare.com/slt3lc6tev37/59kOnwxfMccnWexgfv1Gqs/b0cb3ed59263bfe2c2a79e698a0d663f/leader-crown.png
|
104.16.123.96
|
There are 83 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
prod-default.lb.logrocket.network
|
104.198.23.205
|
||
static.cloudflareinsights.com
|
104.16.79.73
|
||
s.dsp-prod.demandbase.com
|
34.96.71.22
|
||
platform.twitter.map.fastly.net
|
199.232.188.157
|
||
stats.g.doubleclick.net
|
64.233.166.154
|
||
ot.www.cloudflare.com
|
104.16.123.96
|
||
tag.demandbase.com
|
3.161.119.112
|
||
t.co
|
162.159.140.229
|
||
performance.radar.cloudflare.com
|
104.18.30.78
|
||
www.google.com
|
142.250.185.100
|
||
demdex.net.ssl.sc.omtrdc.net
|
63.140.62.222
|
||
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
|
54.76.121.43
|
||
cf-assets.www.cloudflare.com
|
104.16.123.96
|
||
id.rlcdn.com
|
35.244.174.68
|
||
a.nel.cloudflare.com
|
35.190.80.1
|
||
s.twitter.com
|
104.244.42.195
|
||
js.qualified.com
|
104.18.17.5
|
||
ax-0001.ax-msedge.net
|
150.171.27.10
|
||
di.rlcdn.com
|
35.244.174.68
|
||
www.cloudflare.com
|
104.16.123.96
|
||
cdn.logr-ingest.com
|
188.114.97.3
|
||
reddit.map.fastly.net
|
151.101.129.140
|
||
dsum-sec.casalemedia.com
|
172.64.151.101
|
||
challenges.cloudflare.com
|
104.18.94.41
|
||
api.company-target.com
|
18.66.102.85
|
||
douglascounty.kaisersupportcom.top
|
104.21.38.65
|
||
fp2c5c.wac.kappacdn.net
|
152.195.15.58
|
||
partners-alb-1113315349.us-east-1.elb.amazonaws.com
|
54.159.177.233
|
||
713-xsc-918.mktoresp.com
|
192.28.144.124
|
||
docsend.com
|
18.173.205.79
|
||
alb.reddit.com
|
unknown
|
||
static.ads-twitter.com
|
unknown
|
||
cdn.bizibly.com
|
unknown
|
||
cm.everesttech.net
|
unknown
|
||
cloudflareinc.demdex.net
|
unknown
|
||
adobedc.demdex.net
|
unknown
|
||
cdn.bizible.com
|
unknown
|
||
dpm.demdex.net
|
unknown
|
||
s.company-target.com
|
unknown
|
||
x1.i.lencr.org
|
unknown
|
||
assets.adobedtm.com
|
unknown
|
||
www.linkedin.com
|
unknown
|
||
pixel.rubiconproject.com
|
unknown
|
||
px.ads.linkedin.com
|
unknown
|
||
munchkin.marketo.net
|
unknown
|
||
analytics.twitter.com
|
unknown
|
||
r.logr-ingest.com
|
unknown
|
||
snap.licdn.com
|
unknown
|
||
partners.tremorhub.com
|
unknown
|
There are 39 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
3.161.119.112
|
tag.demandbase.com
|
United States
|
||
152.195.15.58
|
fp2c5c.wac.kappacdn.net
|
United States
|
||
104.18.94.41
|
challenges.cloudflare.com
|
United States
|
||
192.168.2.7
|
unknown
|
unknown
|
||
142.250.185.100
|
www.google.com
|
United States
|
||
192.168.2.9
|
unknown
|
unknown
|
||
192.168.2.4
|
unknown
|
unknown
|
||
192.168.2.6
|
unknown
|
unknown
|
||
192.168.2.5
|
unknown
|
unknown
|
||
104.16.80.73
|
unknown
|
United States
|
||
104.18.30.78
|
performance.radar.cloudflare.com
|
United States
|
||
35.190.80.1
|
a.nel.cloudflare.com
|
United States
|
||
104.16.79.73
|
static.cloudflareinsights.com
|
United States
|
||
104.21.38.65
|
douglascounty.kaisersupportcom.top
|
United States
|
||
104.16.124.96
|
unknown
|
United States
|
||
192.168.2.11
|
unknown
|
unknown
|
||
104.18.17.5
|
js.qualified.com
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
18.173.205.79
|
docsend.com
|
United States
|
||
188.114.97.3
|
cdn.logr-ingest.com
|
European Union
|
||
188.114.96.3
|
unknown
|
European Union
|
||
199.232.188.157
|
platform.twitter.map.fastly.net
|
United States
|
||
151.101.129.140
|
reddit.map.fastly.net
|
United States
|
||
104.16.123.96
|
ot.www.cloudflare.com
|
United States
|
There are 14 hidden IPs, click here to show them.
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
aFS
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
tDIText
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
tFileName
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
tFileSource
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
sFileAncestors
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
sDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
sDate
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
uFileSize
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
uPageCount
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
sAssetId
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c1
|
bisSharedFile
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c2
|
aFS
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c2
|
tDIText
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c2
|
tFileName
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c2
|
sDI
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c2
|
sDate
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c2
|
uFileSize
|
||
HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral\cRecentFiles\c2
|
uPageCount
|
There are 8 hidden registries, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://douglascounty.kaisersupportcom.top/
|
||
https://douglascounty.kaisersupportcom.top/
|
||
https://douglascounty.kaisersupportcom.top/
|
||
https://douglascounty.kaisersupportcom.top/
|
||
https://douglascounty.kaisersupportcom.top/
|
||
https://douglascounty.kaisersupportcom.top/
|
||
https://douglascounty.kaisersupportcom.top/
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
||
https://www.cloudflare.com/products/turnstile/?utm_source=turnstile&utm_campaign=widget
|
There are 4 hidden doms, click here to show them.