IOC Report
https://jobs.adidas-group.com/adidas/job/Bremen-Visual-Merchandiser-%28mfd%29-39hWoche%2C-befristet-12-Monate-FO-Bremen-HB/1118337101

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:45:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:45:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 07:00:51 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:45:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:45:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 21:45:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (452)
downloaded
Chrome Cache Entry: 101
ASCII text, with very long lines (2653)
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (3514), with no line terminators
downloaded
Chrome Cache Entry: 103
PNG image data, 500 x 120, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (539)
dropped
Chrome Cache Entry: 105
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (533)
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (36732), with no line terminators
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (399)
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (3648), with no line terminators
downloaded
Chrome Cache Entry: 112
HTML document, Unicode text, UTF-8 text, with very long lines (532), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 113
GIF image data, version 89a, 32 x 32
dropped
Chrome Cache Entry: 114
ASCII text, with very long lines (540)
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (452)
dropped
Chrome Cache Entry: 116
ASCII text
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (540)
dropped
Chrome Cache Entry: 118
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 2000x1333, components 3
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (546)
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (540)
downloaded
Chrome Cache Entry: 121
TrueType Font data, digitally signed, 19 tables, 1st "DSIG", 28 names, Macintosh, 2009 Albert-Jan Pool published by FSI FontShop International GmbHAdihausDINBoldAlbert-Jan Pool:
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (528)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (528)
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (539)
downloaded
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (1862), with no line terminators
dropped
Chrome Cache Entry: 126
ASCII text
downloaded
Chrome Cache Entry: 127
ASCII text
downloaded
Chrome Cache Entry: 128
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (399)
dropped
Chrome Cache Entry: 130
ASCII text
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (2108)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (38517)
downloaded
Chrome Cache Entry: 133
ASCII text
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (604)
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (528)
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (8892)
downloaded
Chrome Cache Entry: 137
ASCII text
dropped
Chrome Cache Entry: 138
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 2000x1333, components 3
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (528)
dropped
Chrome Cache Entry: 140
GIF image data, version 89a, 32 x 32
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (537)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (604)
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (537)
downloaded
Chrome Cache Entry: 144
TrueType Font data, digitally signed, 19 tables, 1st "DSIG", 28 names, Macintosh, 2009 Albert-Jan Pool published by FSI FontShop International GmbHAdihausDINRegularAlbert-Jan Poo
downloaded
Chrome Cache Entry: 145
Unicode text, UTF-8 text, with very long lines (1862), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (34981), with no line terminators
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (533)
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (19162)
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (39553)
downloaded
Chrome Cache Entry: 151
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 152
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 153
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 154
ASCII text
downloaded
Chrome Cache Entry: 155
ASCII text
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (8892)
dropped
Chrome Cache Entry: 157
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (2653)
downloaded
Chrome Cache Entry: 159
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (13841), with no line terminators
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (546)
downloaded
Chrome Cache Entry: 163
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 180x180, components 3
dropped
Chrome Cache Entry: 164
ASCII text, with very long lines (65369)
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (1611)
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (30837)
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (1611)
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (39553)
dropped
Chrome Cache Entry: 169
TrueType Font data, 16 tables, 1st "BASE", 30 names, Macintosh
downloaded
Chrome Cache Entry: 96
ASCII text
dropped
Chrome Cache Entry: 97
ASCII text, with very long lines (540)
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (2108)
dropped
Chrome Cache Entry: 99
ASCII text
downloaded
There are 70 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2508 --field-trial-handle=2228,i,16981757138069848687,10724990151858565193,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://jobs.adidas-group.com/adidas/job/Bremen-Visual-Merchandiser-%28mfd%29-39hWoche%2C-befristet-12-Monate-FO-Bremen-HB/1118337101"

URLs

Name
IP
Malicious
https://jobs.adidas-group.com/adidas/job/Bremen-Visual-Merchandiser-%28mfd%29-39hWoche%2C-befristet-12-Monate-FO-Bremen-HB/1118337101
http://fontawesome.io
unknown
https://jobs.adidas-group.com/platform/bootstrap/3.4.1/js/bootstrap.min.js
130.214.193.81
https://jobs.adidas-group.com/platform/css/j2w/min/sitebuilderframework.min.css?h=e9e34341
130.214.193.81
http://schema.org/PostalAddress
unknown
https://www.adidas-group.com/en/service/contact/
unknown
https://jobs.adidas-group.com/platform/js/search/search.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.agent.min.js?h=e9e34341
130.214.193.81
https://career5.successfactors.eu
unknown
http://www.fontfont.comhttp://www.fontfont.com/eula/license.html
unknown
https://jobs.adidas-group.com/platform/js/jquery/jquery.placeholder.2.0.7.min.js
130.214.193.81
http://www.fontfont.comhttp://www.fontfont.com/eula/license.html2009
unknown
https://jobs.adidas-group.com/platform/csb/css/navbar-fixed-top.css
130.214.193.81
https://jobs.adidas-group.com/platform/csb/css/header1.css?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/min/socialSubscribeRD.min.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/jquery/jquery.lightbox_me.js
130.214.193.81
http://crl.thawte.com/ThawteTimestampingCA.crl0
unknown
https://jobs.adidas-group.com/platform/images/ajax-indicator-big.gif
130.214.193.81
https://jobs.adidas-group.com/platform/css/search/BS3ColumnizedSearchHideLabels.css?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/
unknown
http://mckltype.com/
unknown
https://jobs.adidas-group.com/search/
unknown
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.employee.min.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/adidas/job/Bremen-Visual-Merchandiser-%28mfd%29-39hWoche%2C-befristet-12-Monate-FO-Bremen-HB/1118337101
https://jobs.adidas-group.com/platform/fontawesome4.7/css/font-awesome-4.7.0.min.css?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/jquery/jquery-migrate-1.4.1.js
130.214.193.81
https://jobs.adidas-group.com/services/cas/createpayload/
130.214.193.81
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.apply.min.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.sso.min.js?h=e9e34341
130.214.193.81
http://bugs.jquery.com/ticket/11820
unknown
https://lf-rmk.com/%E2%80%98//lf-rmk.com/assets/arrow-right-white.svg%E2%80%98
3.70.101.28
https://lf-rmk.com/rmk-custom-prod-min.css
3.70.101.28
https://lf-rmk.com
unknown
https://jobs.adidas-group.com/js/override.js?locale=en_US&i=1660719481
130.214.193.81
http://ocsp.thawte.com0
unknown
https://jobs.adidas-group.com/platform/css/j2w/min/BS3ColumnizedSearch.min.css?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.socialSubscribeCore.min.js?h=e9e34341
130.214.193.81
http://www.mckltype.comhttp://www.mckltype.com
unknown
http://www.mckltype.comhttp://www.mckltype.comhttp://mckltype.com/http://mckltype.com/This
unknown
https://lf-rmk.com/rmk-custom-prod-min.js
3.70.101.28
https://jobs.adidas-group.com/services/t/l?referrer=&ctid=9967c15b-5221-4b00-b187-39d847aa014f&landing=https%3A%2F%2Fjobs.adidas-group.com%2Fadidas%2Fjob%2FBremen-Visual-Merchandiser-%2528mfd%2529-39hWoche%252C-befristet-12-Monate-FO-Bremen-HB%2F1118337101&brand=adidas&_=1729896346186
130.214.193.81
https://www.adidas-group.com/en/service/legal-notice/
unknown
https://jobs.adidas-group.com/platform/js/j2w/j2w.bootstrap.dropdown.js
130.214.193.81
https://getbootstrap.com/)
unknown
http://schema.org/JobPosting
unknown
http://fontawesome.io/license
unknown
http://bugs.jquery.com/ticket/13335
unknown
https://interviewtutorial.careers.adidas-group.com/#/
unknown
https://jobs.adidas-group.com/platform/js/jquery/jquery-3.5.1.min.js
130.214.193.81
https://jobs.adidas-group.com/platform/js/localized/strings_en_US.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.core.min.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/adidas/job/Bremen-Visual-Merchandiser-%28mfd%29-39hWoche%2C-befristet-
unknown
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.tc.min.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/search?q
unknown
http://www.mckltype.com
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://rise.articulate.com/share/isHzluurpippeinF80XbBdFHl1nrwuTX
unknown
https://www.adidas-group.com/en/service/imprint/
unknown
https://jobs.adidas-group.com/platform/bootstrap/3.4.1/css/bootstrap.min.css
130.214.193.81
https://jobs.adidas-group.com/platform/js/jquery/jquery-migrate-3.1.0.min.js
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/min/j2w.user.min.js?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/jquery/js.cookie-2.2.1.min.js
130.214.193.81
https://jobs.adidas-group.com/platform/css/j2w/min/bootstrapV3.global.responsive.min.css?h=e9e34341
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/min/options-search.min.js?h=e9e34341
130.214.193.81
http://mths.be/placeholder
unknown
http://schema.org/Place
unknown
https://jobs.adidas-group.com/services/jobs/options/facetValues/
130.214.193.81
https://jobs.adidas-group.com/platform/js/j2w/j2w.bootstrap.collapse.js
130.214.193.81
There are 58 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
lf-rmk.com
3.70.101.28
www.google.com
142.250.186.132
RMK12.jobs2web.com
130.214.193.81
fp2e7a.wpc.phicdn.net
192.229.221.95
career5.successfactors.eu
unknown
rmkcdn.successfactors.com
unknown
jobs.adidas-group.com
unknown

IPs

IP
Domain
Country
Malicious
192.168.2.8
unknown
unknown
3.72.140.173
unknown
United States
192.168.2.9
unknown
unknown
192.168.2.6
unknown
unknown
130.214.193.81
RMK12.jobs2web.com
United States
239.255.255.250
unknown
Reserved
3.70.101.28
lf-rmk.com
United States
142.250.186.132
www.google.com
United States

DOM / HTML

URL
Malicious
https://jobs.adidas-group.com/adidas/job/Bremen-Visual-Merchandiser-%28mfd%29-39hWoche%2C-befristet-12-Monate-FO-Bremen-HB/1118337101