IOC Report
http://concursolutions.us.com

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
HTML document, ASCII text, with very long lines (1195), with no line terminators
downloaded
Chrome Cache Entry: 42
ASCII text, with very long lines (8048), with no line terminators
downloaded
Chrome Cache Entry: 43
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 44
ASCII text, with very long lines (8107), with no line terminators
dropped

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2324 --field-trial-handle=2268,i,16994800306515282835,10945144795009866704,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://concursolutions.us.com"

URLs

Name
IP
Malicious
http://concursolutions.us.com
https://concursolutions.us.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
104.21.36.74
https://concursolutions.us.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/e1a56f38220d/main.js?
104.21.36.74
https://concursolutions.us.com/favicon.ico
104.21.36.74
https://concursolutions.us.com/
https://a.nel.cloudflare.com/report/v4?s=tuV8spQCTvE%2FGm87szV%2FpwkL%2Blhhcv5o69MTL9DBBBFw1107DkBobobwyhAn%2FjvFSwcuVlR16XUta4A26VjlG7phtgN0llZmSQkLiqVS18tZF4NTCweH6kf%2BrT70HyxHftyd1tvcDyzi
35.190.80.1
https://concursolutions.us.com/cdn-cgi/challenge-platform/h/b/jsd/r/8d8302f11e332d3b
104.21.36.74
https://a.nel.cloudflare.com/report/v4?s=M2QCFp1blagVpqeyCiGz1oLV1yZQZBs93CXGltVkaLHYbbkPKh8lI7T8B%2FiNAidb5lXCOw53bzt2jX5xRITdRnkO%2FhsAYDpWC91oZiCyLGX8rgsvXFAl4khb5Zd4woO9dY9kJzDK1w9n
35.190.80.1
https://a.nel.cloudflare.com/report/v4?s=U8rFBbRBJqUHvGhTLktC8rlAaP4UTaErsjOHNKfYdA0q8OHt%2FWbNWTLkJXBxfLVcj00BhWBShgyJBLjNchO%2FofyVPUZHrBmsmYZ2BBPW5QLhYQ3CwqFCrN1D9iWSW3hOXVV8kq6l5i20
35.190.80.1

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
a.nel.cloudflare.com
35.190.80.1
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
www.google.com
142.250.184.196
concursolutions.us.com
104.21.36.74
s-part-0032.t-0009.t-msedge.net
13.107.246.60

IPs

IP
Domain
Country
Malicious
142.250.184.196
www.google.com
United States
239.255.255.250
unknown
Reserved
192.168.2.17
unknown
unknown
35.190.80.1
a.nel.cloudflare.com
United States
192.168.2.4
unknown
unknown
104.21.36.74
concursolutions.us.com
United States
172.67.190.96
unknown
United States

DOM / HTML

URL
Malicious
https://concursolutions.us.com/
https://concursolutions.us.com/
https://concursolutions.us.com/
https://concursolutions.us.com/