IOC Report
https://official-mailing.com/nl/login/?tracker=8OyQ79l8fzgMrJewcNuG3bEtcLf5zgt9p0NC

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 101
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 102
Web Open Font Format (Version 2), TrueType, length 28064, version 1.0
downloaded
Chrome Cache Entry: 103
PNG image data, 44 x 80, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
Web Open Font Format (Version 2), TrueType, length 20232, version 331.-31327
downloaded
Chrome Cache Entry: 105
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 106
ASCII text
dropped
Chrome Cache Entry: 107
Unicode text, UTF-8 text, with very long lines (61490)
downloaded
Chrome Cache Entry: 108
HTML document, Unicode text, UTF-8 text, with very long lines (949), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 109
PNG image data, 44 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 110
PNG image data, 1486 x 731, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (20087)
downloaded
Chrome Cache Entry: 112
ASCII text
downloaded
Chrome Cache Entry: 113
ASCII text
dropped
Chrome Cache Entry: 114
PNG image data, 715 x 467, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 115
PNG image data, 62 x 67, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 116
data
downloaded
Chrome Cache Entry: 117
ASCII text
downloaded
Chrome Cache Entry: 118
PNG image data, 2880 x 511, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 119
ASCII text
dropped
Chrome Cache Entry: 120
ISO Media, MP4 Base Media v1 [ISO 14496-12:2003]
downloaded
Chrome Cache Entry: 121
data
downloaded
Chrome Cache Entry: 64
data
downloaded
Chrome Cache Entry: 65
ASCII text
downloaded
Chrome Cache Entry: 66
PNG image data, 121 x 78, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 67
ASCII text, with very long lines (20087)
dropped
Chrome Cache Entry: 68
PNG image data, 1486 x 731, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 69
PNG image data, 238 x 46, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 70
Unicode text, UTF-8 text, with very long lines (65300)
downloaded
Chrome Cache Entry: 71
troff or preprocessor input, ASCII text
downloaded
Chrome Cache Entry: 72
PNG image data, 130 x 27, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 73
PNG image data, 121 x 78, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 74
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 75
HTML document, ASCII text, with very long lines (1238)
downloaded
Chrome Cache Entry: 76
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 77
Web Open Font Format (Version 2), TrueType, length 39380, version 1.0
downloaded
Chrome Cache Entry: 78
PNG image data, 715 x 467, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 79
PNG image data, 62 x 67, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 80
Unicode text, UTF-8 text, with very long lines (1016)
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (8098), with no line terminators
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 83
PNG image data, 238 x 46, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 84
ASCII text
downloaded
Chrome Cache Entry: 85
ASCII text
downloaded
Chrome Cache Entry: 86
ASCII text
downloaded
Chrome Cache Entry: 87
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 88
PNG image data, 2880 x 511, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 89
Unicode text, UTF-8 text, with very long lines (61490)
dropped
Chrome Cache Entry: 90
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 91
ASCII text
dropped
Chrome Cache Entry: 92
ASCII text
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (65397)
downloaded
Chrome Cache Entry: 94
ASCII text
downloaded
Chrome Cache Entry: 95
PNG image data, 130 x 27, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 96
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 97
HTML document, ASCII text, with very long lines (1238)
dropped
Chrome Cache Entry: 98
ASCII text, with very long lines (8107), with no line terminators
dropped
Chrome Cache Entry: 99
ASCII text
downloaded
There are 49 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2288 --field-trial-handle=1940,i,15838400745647305406,11125155622381018543,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://official-mailing.com/nl/login/?tracker=8OyQ79l8fzgMrJewcNuG3bEtcLf5zgt9p0NC"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5968 --field-trial-handle=1940,i,15838400745647305406,11125155622381018543,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://official-mailing.com/nl/login/?tracker=8OyQ79l8fzgMrJewcNuG3bEtcLf5zgt9p0NC
https://a.nel.cloudflare.com/report/v4?s=RoWjGgCDQgQub2TQOg9SZTXMeEChxU5uNGMVongmeQXsmU7YFn5bCLvdiHcbbNqakB5vXzClu7M61uhnnUZQ8t4fOx1t1i5bC5AY5Y54bsagfm8tt%2BTZ%2BUR0%2BFHhOpQrkfGLxUrjeg%3D%3D
35.190.80.1
https://popper.js.org
unknown
https://kit-pro.fontawesome.com/releases/v5.15.2/css/pro.min.css
unknown
http://wonko.com/post/html-escaping)
unknown
http://ejohn.org/blog/javascript-micro-templating/)
unknown
https://official-mailing.com/favicon.png
188.114.96.3
https://github.com/olado/doT).
unknown
http://ecma-international.org/ecma-262/7.0/#sec-patterns).
unknown
https://github.com/FezVrasta/popper.js/issues/373).
unknown
https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
unknown
https://promisesaplus.com/#point-75
unknown
https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled
unknown
https://official-mailing.com/assets/images/aftermath/check.svg
188.114.96.3
https://bugs.webkit.org/show_bug.cgi?id=29084
unknown
https://infra.spec.whatwg.org/#strip-and-collapse-ascii-whitespace
unknown
https://fontawesome.com
unknown
https://html.spec.whatwg.org/multipage/forms.html#concept-option-disabled
unknown
https://lodash.com/)
unknown
http://www.ecma-international.org/ecma-262/7.0/#sec-function.prototype.apply).
unknown
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
http://www.ecma-international.org/ecma-262/7.0/#sec-tointeger).
unknown
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
unknown
http://www.videolan.org/x264.html
unknown
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
unknown
https://official-mailing.com/assets/js/spinner.js
188.114.96.3
https://bugs.chromium.org/p/chromium/issues/detail?id=470258
unknown
https://official-mailing.com/assets/css/style.css
188.114.96.3
https://bugs.jquery.com/ticket/13378
unknown
https://www.quirksmode.org/blog/archives/2014/02/mouse_event_bub.html
unknown
https://mdn.io/clearTimeout).
unknown
https://promisesaplus.com/#point-64
unknown
https://mdn.io/Number/isSafeInteger).
unknown
https://openjsf.org/
unknown
http://eev.ee/blog/2015/09/12/dark-corners-of-unicode/).
unknown
https://promisesaplus.com/#point-61
unknown
https://official-mailing.com/assets/images/aftermath/logo.png
188.114.96.3
https://mdn.io/Number/isNaN)
unknown
http://www.html5rocks.com/en/tutorials/developertools/sourcemaps/#toc-sourceurl)
unknown
https://official-mailing.com/js/main.js
188.114.96.3
https://bugs.chromium.org/p/v8/issues/detail?id=90
unknown
http://dimsemenov.com/plugins/magnific-popup/
unknown
https://html.spec.whatwg.org/#nonce-attributes
unknown
https://mdn.io/toUpperCase).
unknown
https://github.com/jashkenas/underscore/pull/1247
unknown
https://official-mailing.com/assets/fonts/feather-font/css/iconfont.css
188.114.96.3
https://videojs.com/html5-video-support/
unknown
https://official-mailing.com/assets/images/aftermath/footer-bg.png);
unknown
http://ecma-international.org/ecma-262/7.0/#sec-properties-of-the-map-prototype-object)
unknown
https://jsperf.com/getall-vs-sizzle/2
unknown
https://mathiasbynens.be/notes/ambiguous-ampersands)
unknown
https://official-mailing.com/assets/js/template.js
188.114.96.3
https://official-mailing.com/js/jquery.magnific-popup.min.js
188.114.96.3
https://mdn.io/Number/isInteger).
unknown
https://official-mailing.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
188.114.96.3
http://underscorejs.org/LICENSE
unknown
https://developer.mozilla.org/en-US/docs/CSS/display
unknown
http://ecma-international.org/ecma-262/7.0/#sec-ecmascript-function-objects-call-thisargument-argume
unknown
https://bugs.webkit.org/show_bug.cgi?id=156034
unknown
https://jquery.com/
unknown
https://phishedacademy.io
unknown
http://ecma-international.org/ecma-262/7.0/#sec-object.prototype.tostring)
unknown
https://mths.be/he).
unknown
https://mdn.io/String/replace).
unknown
https://official-mailing.com/assets/css/bootstrap.min.css
188.114.96.3
https://official-mailing.com/assets/images/aftermath/icon2.png
188.114.96.3
https://github.com/jquery/sizzle/pull/225
unknown
https://bugs.jquery.com/ticket/4833
unknown
https://mathiasbynens.be/notes/javascript-unicode).
unknown
https://sizzlejs.com/
unknown
https://bugs.chromium.org/p/chromium/issues/detail?id=449857
unknown
https://js.foundation/
unknown
https://bugs.jquery.com/ticket/13393
unknown
https://official-mailing.com
unknown
https://bugs.chromium.org/p/v8/issues/detail?id=2070)
unknown
https://npms.io/search?q=ponyfill.
unknown
https://bugs.webkit.org/show_bug.cgi?id=136851
unknown
https://official-mailing.com/js/app.js
188.114.96.3
https://nodejs.org/api/http.html#http_message_headers
unknown
https://jsperf.com/thor-indexof-vs-for/5
unknown
https://bugs.jquery.com/ticket/12359
unknown
https://mdn.io/Object/assign).
unknown
http://ecma-international.org/ecma-262/7.0/#sec-object.keys)
unknown
https://official-mailing.com/assets/images/aftermath/footer-bg.png
188.114.96.3
https://github.com/FezVrasta/popper.js/pull/715
unknown
http://peter.michaux.ca/articles/lazy-function-definition-pattern)
unknown
https://html.spec.whatwg.org/#strip-and-collapse-whitespace
unknown
http://url.spec.whatwg.org/#urlutils
unknown
https://official-mailing.com/assets/images/aftermath/road.png
188.114.96.3
https://web.archive.org/web/20141116233347/http://fluidproject.org/blog/2008/01/09/getting-setting-a
unknown
https://official-mailing.com/assets/images/aftermath/1.png
188.114.96.3
https://drafts.csswg.org/cssom/#common-serializing-idioms
unknown
https://official-mailing.com/nl/login/?tracker=8OyQ79l8fzgMrJewcNuG3bEtcLf5zgt9p0NC
http://ecma-international.org/ecma-262/7.0/#sec-tolength).
unknown
https://github.com/jquery/jquery/pull/557)
unknown
https://mdn.io/Array/slice)
unknown
https://official-mailing.com/assets/images/aftermath/icon.png
188.114.96.3
https://bugs.chromium.org/p/chromium/issues/detail?id=378607
unknown
https://official-mailing.com/cdn-cgi/challenge-platform/h/b/jsd/r/8db278f97e883aa9
188.114.96.3
https://fontawesome.com/license
unknown
https://mdn.io/Number/isFinite).
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
a.nel.cloudflare.com
35.190.80.1
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.186.68
official-mailing.com
188.114.96.3
fp2e7a.wpc.phicdn.net
192.229.221.95
kit-pro.fontawesome.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
188.114.97.3
unknown
European Union
188.114.96.3
official-mailing.com
European Union
35.190.80.1
a.nel.cloudflare.com
United States

DOM / HTML

URL
Malicious
https://official-mailing.com/nl/login/?tracker=8OyQ79l8fzgMrJewcNuG3bEtcLf5zgt9p0NC
https://official-mailing.com/nl/login/?tracker=8OyQ79l8fzgMrJewcNuG3bEtcLf5zgt9p0NC