IOC Report
https://ru-netpallet.mailinetservice.net/ru.netpallet/pub/mail/click.php?tag=sender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5In0%3D&url=https%3A%2F%2Fru-netpallet.mailinetservice.net%2Fru.netpallet%2Fpub%2Fmail%2Funsubscribe.php%3Ftag%3Dsender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5IiwiQ09OVEFDVF9JRCI6IjU1MzUiLCJNQ

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 122
ASCII text, with very long lines (13404)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (14156)
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (25331)
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (9200)
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (1467), with no line terminators
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (858), with no line terminators
downloaded
Chrome Cache Entry: 129
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (65418)
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (2554), with no line terminators
downloaded
Chrome Cache Entry: 133
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (49478)
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (23463), with no line terminators
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (2449)
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (1803), with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (32174), with no line terminators
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (6659), with no line terminators
downloaded
There are 9 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2052 --field-trial-handle=1956,i,6605174925357746350,3975537273266710476,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://ru-netpallet.mailinetservice.net/ru.netpallet/pub/mail/click.php?tag=sender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5In0%3D&url=https%3A%2F%2Fru-netpallet.mailinetservice.net%2Fru.netpallet%2Fpub%2Fmail%2Funsubscribe.php%3Ftag%3Dsender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5IiwiQ09OVEFDVF9JRCI6IjU1MzUiLCJNQUlMSU5HX0lEIjoiMSIsIkVNQUlMIjoiaW5mb0BkZS1mYW1pbGxlLnJ1IiwiQ09ERSI6ImluZm9AZGUtZmFtaWxsZS5ydSIsIlRFU1QiOiJOIn0%253D.65b3db8c86c4ab45a5fab658d8d49013ae26b314a9cb1f497ca641e069779b7e%26bx_sender_conversion_id%3D8670499%26utm_source%3Dnewsletter%26utm_medium%3Dmail%26utm_campaign%3Dobnov510&sign=9220b06fb9238aea629501aece3a5b0217bd623ceaa16fbb411f371cac28acbd"

URLs

Name
IP
Malicious
https://ru-netpallet.mailinetservice.net/ru.netpallet/pub/mail/click.php?tag=sender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5In0%3D&url=https%3A%2F%2Fru-netpallet.mailinetservice.net%2Fru.netpallet%2Fpub%2Fmail%2Funsubscribe.php%3Ftag%3Dsender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5IiwiQ09OVEFDVF9JRCI6IjU1MzUiLCJNQUlMSU5HX0lEIjoiMSIsIkVNQUlMIjoiaW5mb0BkZS1mYW1pbGxlLnJ1IiwiQ09ERSI6ImluZm9AZGUtZmFtaWxsZS5ydSIsIlRFU1QiOiJOIn0%253D.65b3db8c86c4ab45a5fab658d8d49013ae26b314a9cb1f497ca641e069779b7e%26bx_sender_conversion_id%3D8670499%26utm_source%3Dnewsletter%26utm_medium%3Dmail%26utm_campaign%3Dobnov510&sign=9220b06fb9238aea629501aece3a5b0217bd623ceaa16fbb411f371cac28acbd
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/components/bitrix/main.mail.unsubscribe/templates/.default/script.min.js?1518018584858
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/ui/buttons/dist/ui.buttons.bundle.min.css?171076220032174
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/main/popup/dist/main.popup.bundle.min.js?170185523765824
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/ui/buttons/dist/ui.buttons.bundle.min.js?171076220041234
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/pull/protobuf/model.min.js?159231549114190
52.29.77.149
https://ru-netpallet.mailinetservice.net/favicon.ico
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/components/bitrix/main.mail.unsubscribe/templates/.default/style.min.css?17169973951803
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/ui/design-tokens/dist/ui.design-tokens.min.css?171327662823463
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/pull/client/pull.client.min.js?171929841849656
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/main/core/core.min.js?1716997395225422
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/pub/mail/click.php?tag=sender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5In0%3D&url=https%3A%2F%2Fru-netpallet.mailinetservice.net%2Fru.netpallet%2Fpub%2Fmail%2Funsubscribe.php%3Ftag%3Dsender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5IiwiQ09OVEFDVF9JRCI6IjU1MzUiLCJNQUlMSU5HX0lEIjoiMSIsIkVNQUlMIjoiaW5mb0BkZS1mYW1pbGxlLnJ1IiwiQ09ERSI6ImluZm9AZGUtZmFtaWxsZS5ydSIsIlRFU1QiOiJOIn0%253D.65b3db8c86c4ab45a5fab658d8d49013ae26b314a9cb1f497ca641e069779b7e%26bx_sender_conversion_id%3D8670499%26utm_source%3Dnewsletter%26utm_medium%3Dmail%26utm_campaign%3Dobnov510&sign=9220b06fb9238aea629501aece3a5b0217bd623ceaa16fbb411f371cac28acbd
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/main/popup/dist/main.popup.bundle.min.css?168130229626598
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/ui/fonts/opensans/ui.font.opensans.min.css?16620208132320
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/rest/client/rest.client.min.js?16015491189240
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/main/core/core_promise.min.js?15551566002490
52.29.77.149
https://bitrix.info/ba.js
54.78.19.136
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/intranet/design-tokens/bitrix24/bitrix24-design-tokens.min.css?16854388541467
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/bitrix/js/pull/protobuf/protobuf.min.js?159231549176433
52.29.77.149
https://ru-netpallet.mailinetservice.net/ru.netpallet/pub/mail/unsubscribe.php?tag=sender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5IiwiQ09OVEFDVF9JRCI6IjU1MzUiLCJNQUlMSU5HX0lEIjoiMSIsIkVNQUlMIjoiaW5mb0BkZS1mYW1pbGxlLnJ1IiwiQ09ERSI6ImluZm9AZGUtZmFtaWxsZS5ydSIsIlRFU1QiOiJOIn0%3D.65b3db8c86c4ab45a5fab658d8d49013ae26b314a9cb1f497ca641e069779b7e&bx_sender_conversion_id=8670499&utm_source=newsletter&utm_medium=mail&utm_campaign=obnov510
There are 9 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
www.google.com
142.250.186.68
bitrix.info
54.78.19.136
ru-netpallet.mailinetservice.net
52.29.77.149
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
239.255.255.250
unknown
Reserved
54.78.19.136
bitrix.info
United States
52.29.77.149
ru-netpallet.mailinetservice.net
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://ru-netpallet.mailinetservice.net/ru.netpallet/pub/mail/unsubscribe.php?tag=sender.eyJSRUNJUElFTlRfSUQiOiI4NjcwNDk5IiwiQ09OVEFDVF9JRCI6IjU1MzUiLCJNQUlMSU5HX0lEIjoiMSIsIkVNQUlMIjoiaW5mb0BkZS1mYW1pbGxlLnJ1IiwiQ09ERSI6ImluZm9AZGUtZmFtaWxsZS5ydSIsIlRFU1QiOiJOIn0%3D.65b3db8c86c4ab45a5fab658d8d49013ae26b314a9cb1f497ca641e069779b7e&bx_sender_conversion_id=8670499&utm_source=newsletter&utm_medium=mail&utm_campaign=obnov510