IOC Report
https://brightmorningteam.acemlna.com/lt.php?x=3DZy~GE4JILM6X77_gxIURWf1HNRj_P1k-1iZKM6KXec5aKvzUy.0OFy1nRzkNfulfYwbHPJJFKa

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 60
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 61
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 62
Unicode text, UTF-8 text, with very long lines (33260), with no line terminators
dropped
Chrome Cache Entry: 63
HTML document, ASCII text, with very long lines (58863)
downloaded
Chrome Cache Entry: 64
ASCII text, with very long lines (65460)
downloaded
Chrome Cache Entry: 65
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 66
Web Open Font Format (Version 2), TrueType, length 18260, version 1.0
downloaded
Chrome Cache Entry: 67
Web Open Font Format (Version 2), TrueType, length 10180, version 1.0
downloaded
Chrome Cache Entry: 68
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 69
JSON data
dropped
Chrome Cache Entry: 70
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 71
Web Open Font Format (Version 2), TrueType, length 10048, version 1.0
downloaded
Chrome Cache Entry: 72
ASCII text, with very long lines (1497), with no line terminators
dropped
Chrome Cache Entry: 73
Web Open Font Format (Version 2), TrueType, length 18668, version 1.0
downloaded
Chrome Cache Entry: 74
ASCII text, with very long lines (65460)
dropped
Chrome Cache Entry: 75
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 76
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 77
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 78
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 79
Unicode text, UTF-8 text, with very long lines (33260), with no line terminators
downloaded
Chrome Cache Entry: 80
HTML document, ASCII text, with very long lines (654)
dropped
Chrome Cache Entry: 81
PNG image data, 2160 x 1260, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 82
ASCII text, with very long lines (18318)
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (1445)
downloaded
Chrome Cache Entry: 84
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 85
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 86
HTML document, ASCII text, with very long lines (654)
downloaded
Chrome Cache Entry: 87
ASCII text, with very long lines (18318)
dropped
Chrome Cache Entry: 88
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 89
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 90
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 91
ASCII text, with very long lines (1497), with no line terminators
downloaded
Chrome Cache Entry: 92
HTML document, ASCII text, with very long lines (654)
downloaded
Chrome Cache Entry: 93
PNG image data, 2160 x 1260, 8-bit/color RGB, non-interlaced
downloaded
There are 25 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2396 --field-trial-handle=2364,i,14294915167031781044,245127136332851644,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://brightmorningteam.acemlna.com/lt.php?x=3DZy~GE4JILM6X77_gxIURWf1HNRj_P1k-1iZKM6KXec5aKvzUy.0OFy1nRzkNfulfYwbHPJJFKa"

URLs

Name
IP
Malicious
https://brightmorningteam.acemlna.com/lt.php?x=3DZy~GE4JILM6X77_gxIURWf1HNRj_P1k-1iZKM6KXec5aKvzUy.0OFy1nRzkNfulfYwbHPJJFKa
https://bam.nr-data.net/jserrors/1/d3d5c809d5?a=456978955&v=1.278.2&to=M1JQYEMHVhFXB0AMXAoYZ0ZYSV5NQA1REh0UX0I%3D&rst=71509&ck=0&s=94640e84d6b39649&ref=https://brightmorningteam.activehosted.com/f/158&ptid=3a23e012b4bdc605
162.247.243.29
https://bam.nr-data.net/1/d3d5c809d5?a=456978955&v=1.278.2&to=M1JQYEMHVhFXB0AMXAoYZ0ZYSV5NQA1REh0UX0I%3D&rst=10822&ck=0&s=94640e84d6b39649&ref=https://brightmorningteam.activehosted.com/f/158&ptid=3a23e012b4bdc605&af=err,spa,xhr,stn,ins&ap=322&be=2643&fe=7361&dc=1116&at=HxVHFgsdRU4UBRZfSBlK&fsh=1&perf=%7B%22timing%22:%7B%22of%22:1736959595292,%22n%22:0,%22f%22:1713,%22dn%22:1716,%22dne%22:1716,%22c%22:1716,%22s%22:1717,%22ce%22:2175,%22rq%22:2175,%22rp%22:2643,%22rpe%22:2911,%22di%22:3758,%22ds%22:3758,%22de%22:3759,%22dc%22:9998,%22l%22:9998,%22le%22:10004%7D,%22navigation%22:%7B%7D%7D&fp=3767&fcp=3767
162.247.243.29
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-ext-700-normal.woff2)
unknown
https://prism.app-us1.com/?a=1002421028&u=https%3A%2F%2Fbrightmorningteam.activehosted.com%2Ff%2F158%3Fs%3Dc7bc722fa31ed07a45768c9be8733ff5%26nl%3D1%26c%3D1728%26m%3D9908%26utm_source%3DActiveCampaign%26utm_medium%3Demail%26utm_content%3DNeuroscience%2520tips%2520for%2520better%2520team%2520leadership%26utm_campaign%3DM%252C%25201%252F13%252F25%2520-%2520Newsletter
104.17.31.174
https://support.google.com/recaptcha#6262736
unknown
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-400-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-vietnamese-400-normal.woff2)
unknown
https://www.google.com/js/bg/CY4IdQ8PNOqs9ugPxTaJh2hYWy8m1lFu__OIecPWn-w.js
172.217.18.4
https://fonts.bunny.net/open-sans/files/open-sans-math-400-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-symbols-400-normal.woff2
169.150.236.105
https://fonts.bunny.net/css?family=open-sans:400
unknown
https://fonts.bunny.net/open-sans/files/open-sans-latin-400-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-latin-700-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-vietnamese-700-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-ext-400-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-ext-700-normal.woff)
unknown
https://d226aj4ao1t61q.cloudfront.net/haao08fw5_ac_symbol_blue.png
unknown
https://www.google.com/recaptcha/api2/bframe?hl=en&v=zIriijn3uj5Vpknvt_LnfNbF&k=6LcwIw8TAAAAACP1ysM08EhCgzd6q5JAOUR1a0Go
172.217.18.4
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-700-normal.woff)
unknown
https://cloud.google.com/contact
unknown
https://fonts.bunny.net/open-sans/files/open-sans-symbols-400-normal.woff)
unknown
https://diffuser-cdn.app-us1.com/diffuser/diffuser.js
104.17.31.174
https://fonts.bunny.net/open-sans/files/open-sans-latin-400-normal.woff2
169.150.236.105
https://fonts.bunny.net/open-sans/files/open-sans-latin-ext-400-normal.woff2)
unknown
https://www.gstatic.c..?/recaptcha/releases/zIriijn3uj5Vpknvt_LnfNbF/recaptcha__.
unknown
https://support.google.com/recaptcha/#6175971
unknown
https://fonts.bunny.net/open-sans/files/open-sans-symbols-400-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-symbols-700-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-ext-400-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-greek-700-normal.woff)
unknown
https://www.google.com/recaptcha/api2/webworker.js?hl=en&v=zIriijn3uj5Vpknvt_LnfNbF
172.217.18.4
https://fonts.bunny.net/open-sans/files/open-sans-latin-400-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-vietnamese-400-normal.woff)
unknown
https://www.google.com/recaptcha/api2/
unknown
https://brightmorningteam.acemlna.com/lt.php?x=3DZy~GE4JILM6X77_gxIURWf1HNRj_P1k-1iZKM6KXec5aKvzUy.0OFy1nRzkNfulfYwbHPJJFKa
54.82.80.250
https://brightmorningteam.activehosted.com/proc.php?jsonp=true
unknown
https://fonts.bunny.net/open-sans/files/open-sans-hebrew-400-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-latin-ext-700-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-math-700-normal.woff2)
unknown
https://bam.nr-data.net/jserrors/1/d3d5c809d5?a=456978955&v=1.278.2&to=M1JQYEMHVhFXB0AMXAoYZ0ZYSV5NQA1REh0UX0I%3D&rst=41499&ck=0&s=94640e84d6b39649&ref=https://brightmorningteam.activehosted.com/f/158&ptid=3a23e012b4bdc605
162.247.243.29
https://fonts.bunny.net/open-sans/files/open-sans-math-400-normal.woff2)
unknown
https://support.google.com/recaptcha
unknown
https://fonts.bunny.net/open-sans/files/open-sans-math-700-normal.woff)
unknown
https://bam.nr-data.net/events/1/d3d5c809d5?a=456978955&v=1.278.2&to=M1JQYEMHVhFXB0AMXAoYZ0ZYSV5NQA1REh0UX0I%3D&rst=41493&ck=0&s=94640e84d6b39649&ref=https://brightmorningteam.activehosted.com/f/158&ptid=3a23e012b4bdc605
162.247.243.29
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-400-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-latin-700-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-greek-ext-700-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-latin-700-normal.woff2
169.150.236.105
https://brightmorningteam.activehosted.com/f/158?s=c7bc722fa31ed07a45768c9be8733ff5&nl=1&c=1728&m=9908&utm_source=ActiveCampaign&utm_medium=email&utm_content=Neuroscience%20tips%20for%20better%20team%20leadership&utm_campaign=M%2C%201%2F13%2F25%20-%20Newsletter
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://fonts.bunny.net/open-sans/files/open-sans-hebrew-700-normal.woff)
unknown
https://content.app-us1.com/ZzEmW/2024/11/07/0ec39b53-b720-4ff5-9d4e-80ae5d2b0133.png
104.17.31.174
https://fonts.bunny.net/open-sans/files/open-sans-greek-ext-700-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-cyrillic-700-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-latin-ext-700-normal.woff)
unknown
https://unpkg.com/intl-tel-input
unknown
https://d3rxaij56vjege.cloudfront.net/media/favicon.ico
18.245.45.143
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://fonts.bunny.net/open-sans/files/open-sans-greek-ext-400-normal.woff2)
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://fonts.bunny.net/open-sans/files/open-sans-vietnamese-700-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-latin-ext-400-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-greek-400-normal.woff)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-greek-ext-400-normal.woff)
unknown
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LcwIw8TAAAAACP1ysM08EhCgzd6q5JAOUR1a0Go&co=aHR0cHM6Ly9icmlnaHRtb3JuaW5ndGVhbS5hY3RpdmVob3N0ZWQuY29tOjQ0Mw..&hl=en&v=zIriijn3uj5Vpknvt_LnfNbF&size=normal&cb=z1bw6zgaogfz
172.217.18.4
https://js-agent.newrelic.com/nr-spa-1.278.2.min.js
162.247.243.39
https://fonts.bunny.net/open-sans/files/open-sans-greek-400-normal.woff2)
unknown
https://fonts.bunny.net/open-sans/files/open-sans-greek-700-normal.woff2)
unknown
https://fonts.bunny.net/css?family=open-sans:400,700
169.150.236.105
https://fonts.bunny.net/open-sans/files/open-sans-symbols-700-normal.woff)
unknown
https://brightmorningteam.activehosted.com/proc.php
unknown
https://bam.nr-data.net/events/1/d3d5c809d5?a=456978955&v=1.278.2&to=M1JQYEMHVhFXB0AMXAoYZ0ZYSV5NQA1REh0UX0I%3D&rst=11489&ck=0&s=94640e84d6b39649&ref=https://brightmorningteam.activehosted.com/f/158&ptid=3a23e012b4bdc605
162.247.243.29
https://fonts.bunny.net/open-sans/files/open-sans-symbols-700-normal.woff2
169.150.236.105
https://fonts.bunny.net/open-sans/files/open-sans-hebrew-700-normal.woff2)
unknown
https://brightmorningteam.activehosted.com/lt.php?x=3DZy~GE4JILM6X77_gxIURWf1HNRj_P1k-1iZKM6KXec5aKvzUy.0OFy1nRzkNfulfYwbHPJJFKa
104.17.205.31
https://brightmorningteam.activehosted.com/proc.php?
unknown
https://fonts.bunny.net/open-sans/files/open-sans-hebrew-400-normal.woff2)
unknown
There are 70 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
brightmorningteam.activehosted.com
104.17.205.31
fastly-tls12-bam.nr-data.net
162.247.243.29
prism.app-us1.com
104.17.31.174
brightmorningteam.acemlna.com
54.82.80.250
content.app-us1.com
104.17.31.174
diffuser-cdn.app-us1.com
104.17.31.174
js-agent.newrelic.com
162.247.243.39
www.google.com
142.250.181.228
d3rxaij56vjege.cloudfront.net
18.245.45.143
bunnyfonts.b-cdn.net
169.150.236.105
fonts.bunny.net
unknown
bam.nr-data.net
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
18.245.45.143
d3rxaij56vjege.cloudfront.net
United States
192.168.2.16
unknown
unknown
192.168.2.4
unknown
unknown
104.18.128.216
unknown
United States
162.247.243.39
js-agent.newrelic.com
United States
18.245.45.59
unknown
United States
142.250.185.68
unknown
United States
172.217.18.4
unknown
United States
216.58.206.68
unknown
United States
169.150.236.105
bunnyfonts.b-cdn.net
United States
239.255.255.250
unknown
Reserved
54.82.80.250
brightmorningteam.acemlna.com
United States
104.17.205.31
brightmorningteam.activehosted.com
United States
142.250.181.228
www.google.com
United States
162.247.243.29
fastly-tls12-bam.nr-data.net
United States
104.17.31.174
prism.app-us1.com
United States
There are 6 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://brightmorningteam.activehosted.com/f/158?s=c7bc722fa31ed07a45768c9be8733ff5&nl=1&c=1728&m=9908&utm_source=ActiveCampaign&utm_medium=email&utm_content=Neuroscience%20tips%20for%20better%20team%20leadership&utm_campaign=M%2C%201%2F13%2F25%20-%20Newsletter
https://brightmorningteam.activehosted.com/f/158?s=c7bc722fa31ed07a45768c9be8733ff5&nl=1&c=1728&m=9908&utm_source=ActiveCampaign&utm_medium=email&utm_content=Neuroscience%20tips%20for%20better%20team%20leadership&utm_campaign=M%2C%201%2F13%2F25%20-%20Newsletter
https://brightmorningteam.activehosted.com/f/158?s=c7bc722fa31ed07a45768c9be8733ff5&nl=1&c=1728&m=9908&utm_source=ActiveCampaign&utm_medium=email&utm_content=Neuroscience%20tips%20for%20better%20team%20leadership&utm_campaign=M%2C%201%2F13%2F25%20-%20Newsletter
https://brightmorningteam.activehosted.com/f/158?s=c7bc722fa31ed07a45768c9be8733ff5&nl=1&c=1728&m=9908&utm_source=ActiveCampaign&utm_medium=email&utm_content=Neuroscience%20tips%20for%20better%20team%20leadership&utm_campaign=M%2C%201%2F13%2F25%20-%20Newsletter
https://brightmorningteam.activehosted.com/f/158?s=c7bc722fa31ed07a45768c9be8733ff5&nl=1&c=1728&m=9908&utm_source=ActiveCampaign&utm_medium=email&utm_content=Neuroscience%20tips%20for%20better%20team%20leadership&utm_campaign=M%2C%201%2F13%2F25%20-%20Newsletter
https://brightmorningteam.activehosted.com/f/158?s=c7bc722fa31ed07a45768c9be8733ff5&nl=1&c=1728&m=9908&utm_source=ActiveCampaign&utm_medium=email&utm_content=Neuroscience%20tips%20for%20better%20team%20leadership&utm_campaign=M%2C%201%2F13%2F25%20-%20Newsletter