IOC Report
https://backup-mailer.com/nl/uitloggen/?secret=oEaM4qMC3jhlycbbxxQlLbCFI2HdDsJrTdsW

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
PNG image data, 715 x 467, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 101
data
downloaded
Chrome Cache Entry: 102
PNG image data, 1486 x 731, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 103
PNG image data, 2880 x 511, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
data
downloaded
Chrome Cache Entry: 105
Unicode text, UTF-8 text, with very long lines (61490)
downloaded
Chrome Cache Entry: 106
ISO Media, MP4 Base Media v1 [ISO 14496-12:2003]
downloaded
Chrome Cache Entry: 107
ASCII text
downloaded
Chrome Cache Entry: 108
ASCII text
downloaded
Chrome Cache Entry: 109
PNG image data, 715 x 467, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 110
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 111
HTML document, ASCII text
downloaded
Chrome Cache Entry: 112
ASCII text
dropped
Chrome Cache Entry: 113
HTML document, Unicode text, UTF-8 text, with very long lines (594), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 114
Web Open Font Format (Version 2), TrueType, length 28064, version 1.0
downloaded
Chrome Cache Entry: 115
PNG image data, 130 x 27, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 116
ASCII text
dropped
Chrome Cache Entry: 117
ASCII text
dropped
Chrome Cache Entry: 118
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 119
data
downloaded
Chrome Cache Entry: 120
ASCII text
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (32058)
dropped
Chrome Cache Entry: 122
ASCII text
downloaded
Chrome Cache Entry: 123
data
downloaded
Chrome Cache Entry: 124
troff or preprocessor input, ASCII text
downloaded
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (1016)
downloaded
Chrome Cache Entry: 126
PNG image data, 1486 x 731, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 127
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 128
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 129
HTML document, ASCII text, with very long lines (356), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 130
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 131
PNG image data, 121 x 78, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (65300)
downloaded
Chrome Cache Entry: 133
PNG image data, 238 x 46, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 134
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 135
ASCII text
downloaded
Chrome Cache Entry: 136
ASCII text
dropped
Chrome Cache Entry: 137
PNG image data, 62 x 67, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 139
data
downloaded
Chrome Cache Entry: 140
Web Open Font Format (Version 2), TrueType, length 20232, version 331.-31327
downloaded
Chrome Cache Entry: 141
HTML document, ASCII text, with very long lines (1238)
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (48664)
dropped
Chrome Cache Entry: 143
PNG image data, 238 x 46, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 144
ASCII text
downloaded
Chrome Cache Entry: 145
HTML document, ASCII text
dropped
Chrome Cache Entry: 77
ASCII text, with very long lines (65397)
downloaded
Chrome Cache Entry: 78
ASCII text
downloaded
Chrome Cache Entry: 79
PNG image data, 44 x 80, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 80
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 81
Unicode text, UTF-8 text, with very long lines (61490)
dropped
Chrome Cache Entry: 82
PNG image data, 62 x 67, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 83
HTML document, ASCII text, with very long lines (1238)
dropped
Chrome Cache Entry: 84
ASCII text, with very long lines (48664)
downloaded
Chrome Cache Entry: 85
ASCII text
downloaded
Chrome Cache Entry: 86
ASCII text
downloaded
Chrome Cache Entry: 87
ASCII text, with very long lines (20087)
dropped
Chrome Cache Entry: 88
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 89
ASCII text, with very long lines (32058)
downloaded
Chrome Cache Entry: 90
ASCII text, with very long lines (20087)
downloaded
Chrome Cache Entry: 91
PNG image data, 130 x 27, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 92
data
downloaded
Chrome Cache Entry: 93
data
downloaded
Chrome Cache Entry: 94
PNG image data, 2880 x 511, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 95
PNG image data, 121 x 78, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 96
PNG image data, 44 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 97
ASCII text, with very long lines (65325)
downloaded
Chrome Cache Entry: 98
Web Open Font Format (Version 2), TrueType, length 39380, version 1.0
downloaded
Chrome Cache Entry: 99
SVG Scalable Vector Graphics image
downloaded
There are 60 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2312 --field-trial-handle=2228,i,16754288020780876168,17948243108775276119,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://backup-mailer.com/nl/uitloggen/?secret=oEaM4qMC3jhlycbbxxQlLbCFI2HdDsJrTdsW"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=4184 --field-trial-handle=2228,i,16754288020780876168,17948243108775276119,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://backup-mailer.com/nl/uitloggen/?secret=oEaM4qMC3jhlycbbxxQlLbCFI2HdDsJrTdsW
https://backup-mailer.com/assets/images/aftermath/logo.png
104.21.92.82
https://popper.js.org
unknown
https://kit-pro.fontawesome.com/releases/v5.15.2/css/pro.min.css
unknown
http://wonko.com/post/html-escaping)
unknown
https://backup-mailer.com/css/app.css
104.21.92.82
http://ejohn.org/blog/javascript-micro-templating/)
unknown
https://github.com/olado/doT).
unknown
http://ecma-international.org/ecma-262/7.0/#sec-patterns).
unknown
https://github.com/FezVrasta/popper.js/issues/373).
unknown
https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
unknown
https://backup-mailer.com/assets/css/magnific-popup.css
104.21.92.82
https://promisesaplus.com/#point-75
unknown
https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled
unknown
https://bugs.webkit.org/show_bug.cgi?id=29084
unknown
https://infra.spec.whatwg.org/#strip-and-collapse-ascii-whitespace
unknown
https://fontawesome.com
unknown
https://html.spec.whatwg.org/multipage/forms.html#concept-option-disabled
unknown
https://lodash.com/)
unknown
http://www.ecma-international.org/ecma-262/7.0/#sec-function.prototype.apply).
unknown
https://backup-mailer.com/assets/images/404.svg
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
http://www.ecma-international.org/ecma-262/7.0/#sec-tointeger).
unknown
https://backup-mailer.com/js/jquery.magnific-popup.min.js
104.21.92.82
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
unknown
http://www.videolan.org/x264.html
unknown
https://backup-mailer.com/assets/images/aftermath/footer-logo.png
104.21.92.82
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
unknown
https://bugs.chromium.org/p/chromium/issues/detail?id=470258
unknown
https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
104.18.11.207
https://bugs.jquery.com/ticket/13378
unknown
https://www.quirksmode.org/blog/archives/2014/02/mouse_event_bub.html
unknown
https://mdn.io/clearTimeout).
unknown
https://promisesaplus.com/#point-64
unknown
https://mdn.io/Number/isSafeInteger).
unknown
https://openjsf.org/
unknown
http://eev.ee/blog/2015/09/12/dark-corners-of-unicode/).
unknown
https://promisesaplus.com/#point-61
unknown
https://mdn.io/Number/isNaN)
unknown
http://www.html5rocks.com/en/tutorials/developertools/sourcemaps/#toc-sourceurl)
unknown
https://backup-mailer.com/assets/js/spinner.js
104.21.92.82
https://backup-mailer.com/assets/css/style.css
104.21.92.82
https://bugs.chromium.org/p/v8/issues/detail?id=90
unknown
http://dimsemenov.com/plugins/magnific-popup/
unknown
https://html.spec.whatwg.org/#nonce-attributes
unknown
https://mdn.io/toUpperCase).
unknown
https://github.com/jashkenas/underscore/pull/1247
unknown
https://videojs.com/html5-video-support/
unknown
http://ecma-international.org/ecma-262/7.0/#sec-properties-of-the-map-prototype-object)
unknown
https://jsperf.com/getall-vs-sizzle/2
unknown
https://mathiasbynens.be/notes/ambiguous-ampersands)
unknown
https://mdn.io/Number/isInteger).
unknown
https://backup-mailer.com/assets/css/bootstrap.min.css
104.21.92.82
https://backup-mailer.com/assets/images/aftermath/alert.svg
104.21.92.82
http://underscorejs.org/LICENSE
unknown
https://developer.mozilla.org/en-US/docs/CSS/display
unknown
http://ecma-international.org/ecma-262/7.0/#sec-ecmascript-function-objects-call-thisargument-argume
unknown
https://backup-mailer.com/favicon.png
104.21.92.82
https://bugs.webkit.org/show_bug.cgi?id=156034
unknown
https://jquery.com/
unknown
https://phishedacademy.io
unknown
http://ecma-international.org/ecma-262/7.0/#sec-object.prototype.tostring)
unknown
https://backup-mailer.com/assets/images/aftermath/arrow.svg
104.21.92.82
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://mths.be/he).
unknown
https://mdn.io/String/replace).
unknown
https://backup-mailer.com/assets/fonts/feather-font/css/iconfont.css
104.21.92.82
https://github.com/jquery/sizzle/pull/225
unknown
https://bugs.jquery.com/ticket/4833
unknown
https://mathiasbynens.be/notes/javascript-unicode).
unknown
https://sizzlejs.com/
unknown
https://bugs.chromium.org/p/chromium/issues/detail?id=449857
unknown
https://js.foundation/
unknown
https://bugs.jquery.com/ticket/13393
unknown
https://backup-mailer.com/assets/css/responsive.css
104.21.92.82
https://bugs.chromium.org/p/v8/issues/detail?id=2070)
unknown
https://npms.io/search?q=ponyfill.
unknown
https://backup-mailer.com/assets/images/aftermath/road.png
104.21.92.82
https://bugs.webkit.org/show_bug.cgi?id=136851
unknown
https://phished.io/contact
unknown
https://nodejs.org/api/http.html#http_message_headers
unknown
https://jsperf.com/thor-indexof-vs-for/5
unknown
https://bugs.jquery.com/ticket/12359
unknown
https://mdn.io/Object/assign).
unknown
http://ecma-international.org/ecma-262/7.0/#sec-object.keys)
unknown
https://github.com/FezVrasta/popper.js/pull/715
unknown
http://peter.michaux.ca/articles/lazy-function-definition-pattern)
unknown
https://html.spec.whatwg.org/#strip-and-collapse-whitespace
unknown
https://backup-mailer.com/assets/images/aftermath/1.png
104.21.92.82
http://url.spec.whatwg.org/#urlutils
unknown
https://web.archive.org/web/20141116233347/http://fluidproject.org/blog/2008/01/09/getting-setting-a
unknown
https://drafts.csswg.org/cssom/#common-serializing-idioms
unknown
https://backup-mailer.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js
104.21.92.82
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.2.1/jquery.min.js
104.17.24.14
http://ecma-international.org/ecma-262/7.0/#sec-tolength).
unknown
https://github.com/jquery/jquery/pull/557)
unknown
https://mdn.io/Array/slice)
unknown
https://bugs.chromium.org/p/chromium/issues/detail?id=378607
unknown
https://fontawesome.com/license
unknown
https://mdn.io/Number/isFinite).
unknown
https://lodash.com/custom-builds).
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
cdnjs.cloudflare.com
104.17.24.14
maxcdn.bootstrapcdn.com
104.18.11.207
www.google.com
142.250.74.196
fp2e7a.wpc.phicdn.net
192.229.221.95
backup-mailer.com
104.21.92.82
kit-pro.fontawesome.com
unknown

IPs

IP
Domain
Country
Malicious
104.17.24.14
cdnjs.cloudflare.com
United States
104.21.92.82
backup-mailer.com
United States
192.168.2.6
unknown
unknown
104.18.11.207
maxcdn.bootstrapcdn.com
United States
239.255.255.250
unknown
Reserved
142.250.74.196
www.google.com
United States

DOM / HTML

URL
Malicious
https://backup-mailer.com/nl/uitloggen/?secret=oEaM4qMC3jhlycbbxxQlLbCFI2HdDsJrTdsW
https://backup-mailer.com/nl/di