IOC Report
https://www.canva.com/link?target=https%3A%2F%2Fxxx.f2e48acf9fceba4c863bc3ac7ba32a0f29b4cb01.site&design=DAGUl-uYzdA&accessRole=viewer&linkSource=document

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 56
ASCII text, with very long lines (48296)
downloaded
Chrome Cache Entry: 57
HTML document, Unicode text, UTF-8 text, with very long lines (1979)
downloaded
Chrome Cache Entry: 58
HTML document, Unicode text, UTF-8 text, with very long lines (1979)
dropped
Chrome Cache Entry: 59
ASCII text, with very long lines (8181), with no line terminators
dropped
Chrome Cache Entry: 60
ASCII text, with very long lines (55289)
downloaded
Chrome Cache Entry: 61
ASCII text, with very long lines (19948), with no line terminators
dropped
Chrome Cache Entry: 62
ASCII text, with very long lines (65455)
dropped
Chrome Cache Entry: 63
ASCII text, with very long lines (65455)
downloaded
Chrome Cache Entry: 64
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 65
ASCII text, with very long lines (8052), with no line terminators
downloaded
Chrome Cache Entry: 66
ASCII text, with very long lines (65455)
dropped
Chrome Cache Entry: 67
ASCII text, with very long lines (11068)
downloaded
Chrome Cache Entry: 68
ASCII text, with very long lines (19948), with no line terminators
downloaded
Chrome Cache Entry: 69
ASCII text, with very long lines (11068)
dropped
Chrome Cache Entry: 70
ASCII text, with very long lines (65455)
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (55289)
dropped
Chrome Cache Entry: 72
MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 73
ASCII text, with very long lines (579)
downloaded
There are 9 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2012 --field-trial-handle=1976,i,3445806602069595460,3655185590131097478,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.canva.com/link?target=https%3A%2F%2Fxxx.f2e48acf9fceba4c863bc3ac7ba32a0f29b4cb01.site&design=DAGUl-uYzdA&accessRole=viewer&linkSource=document"

URLs

Name
IP
Malicious
https://www.canva.com/link?target=https%3A%2F%2Fxxx.f2e48acf9fceba4c863bc3ac7ba32a0f29b4cb01.site&design=DAGUl-uYzdA&accessRole=viewer&linkSource=document
https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015
104.16.79.73
https://o13855.ingest.sentry.io/api/5403944/envelope/?sentry_key=c50fa9f3bfcc4ee3bd4a5eca6add3a1b&sentry_version=7&sentry_client=sentry.javascript.browser%2F7.16.0
34.120.195.249
https://a.nel.cloudflare.com/report/v4?s=s70mUGCgEkJKJiZ8aPZxfepMUzV8%2FS0mJAjcQpiGBEfgcXVkI%2BKQOLauCvUaX7BbcFM5iXvHCl8UBRn27VmxBjFR0JfGr0JZf5FZx0eIJ%2Fq7DwMt4Fq%2BeNSu%2BoZEwy4%3D
35.190.80.1
https://static.canva.com/static/images/favicon-1.ico
104.16.103.112
https://www.canva.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/e1a56f38220d/main.js?
104.16.103.112
https://static.canva.com/web/lrxlcv.40cddb0fa0d4dfad.ltr.css
104.16.103.112
https://static.canva.com/web/143b3cccb450cc5d.strings.js
104.16.103.112
https://static.canva.com/web/205dddee09e475f6.runtime.js
104.16.103.112
https://static.canva.com/web/lrxlcv.6f252c89c2f71f57.js
104.16.103.112
https://a.nel.cloudflare.com/report/v4?s=bac7nTFLeSwiHRrvUckC%2FEtvsS7Zx3AbrL3WxBUqgH3EN6r6WHvYh%2FdpTbYKahRi%2BQW3FCX0ss1%2Fco8FQ1ulmBaBRuiRcKMHwKg6oLsiryxfTNVrbdh5FNx4%2FiI6%2BrMI%2BBU%3D
35.190.80.1
https://www.canva.com/link?target=https%3A%2F%2Fxxx.f2e48acf9fceba4c863bc3ac7ba32a0f29b4cb01.site&design=DAGUl-uYzdA&accessRole=viewer&linkSource=document
https://www.canva.com/cdn-cgi/rum?
104.16.103.112
https://static.canva.com/static/lib/sentry/7.16.0.min.js
104.16.103.112
https://static.canva.com/web/387e316e7fce97e3.vendor.js
104.16.103.112
https://static.canva.com/web/9a2311e7590ee117.vendor.js
104.16.103.112
https://github.com/getsentry/sentry-javascript
unknown
https://www.canva.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
104.16.103.112
https://www.canva.com/cdn-cgi/challenge-platform/h/b/jsd/r/8d84eb191be92cab
104.16.103.112
There are 8 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
static.cloudflareinsights.com
104.16.79.73
o13855.ingest.sentry.io
34.120.195.249
static.canva.com
104.16.103.112
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.186.68
www.canva.com
104.16.103.112
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
192.168.2.16
unknown
unknown
104.16.103.112
static.canva.com
United States
192.168.2.4
unknown
unknown
104.16.102.112
unknown
United States
239.255.255.250
unknown
Reserved
35.190.80.1
a.nel.cloudflare.com
United States
104.16.79.73
static.cloudflareinsights.com
United States
34.120.195.249
o13855.ingest.sentry.io
United States

DOM / HTML

URL
Malicious
https://www.canva.com/link?target=https%3A%2F%2Fxxx.f2e48acf9fceba4c863bc3ac7ba32a0f29b4cb01.site&design=DAGUl-uYzdA&accessRole=viewer&linkSource=document
https://www.canva.com/link?target=https%3A%2F%2Fxxx.f2e48acf9fceba4c863bc3ac7ba32a0f29b4cb01.site&design=DAGUl-uYzdA&accessRole=viewer&linkSource=document