IOC Report
http://t.infomail.microsoft.com

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 101
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 102
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 103
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 104
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1280, components 3
dropped
Chrome Cache Entry: 105
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 106
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 107
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 108
JSON data
dropped
Chrome Cache Entry: 109
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 110
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 111
JSON data
dropped
Chrome Cache Entry: 112
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 113
Web Open Font Format (Version 2), CFF, length 29752, version 1.0
downloaded
Chrome Cache Entry: 114
Unicode text, UTF-8 text, with very long lines (2258)
downloaded
Chrome Cache Entry: 115
JSON data
downloaded
Chrome Cache Entry: 116
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 117
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 118
JSON data
dropped
Chrome Cache Entry: 57
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 58
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 59
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 60
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 61
PNG image data, 130 x 130, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 62
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 63
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 64
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 65
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 66
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 67
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 68
JSON data
downloaded
Chrome Cache Entry: 69
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 70
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 71
PNG image data, 130 x 130, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 72
JSON data
downloaded
Chrome Cache Entry: 73
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 74
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 75
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 76
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 77
HTML document, Unicode text, UTF-8 text, with very long lines (28511)
downloaded
Chrome Cache Entry: 78
Unicode text, UTF-8 text, with very long lines (65297)
dropped
Chrome Cache Entry: 79
Web Open Font Format (Version 2), CFF, length 29924, version 1.0
downloaded
Chrome Cache Entry: 80
Unicode text, UTF-8 text, with very long lines (2258)
dropped
Chrome Cache Entry: 81
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 82
Web Open Font Format (Version 2), CFF, length 29980, version 1.0
downloaded
Chrome Cache Entry: 83
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 84
JSON data
downloaded
Chrome Cache Entry: 85
JSON data
dropped
Chrome Cache Entry: 86
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 87
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 88
Unicode text, UTF-8 text, with very long lines (65297)
downloaded
Chrome Cache Entry: 89
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 90
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1280, components 3
downloaded
Chrome Cache Entry: 91
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 92
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 93
JSON data
dropped
Chrome Cache Entry: 94
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 95
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 96
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 97
JSON data
downloaded
Chrome Cache Entry: 98
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 99
SVG Scalable Vector Graphics image
downloaded
There are 53 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2160 --field-trial-handle=1972,i,9717232464057261945,7593321771201276429,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://t.infomail.microsoft.com"

URLs

Name
IP
Malicious
http://t.infomail.microsoft.com
https://use.typekit.net/af/40207f/0000000000000000000176ff/27/
unknown
https://dpm.demdex.net/id/rd?d_visid_ver=5.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1730448854177
34.241.19.39
https://sso.behance.net/ims
unknown
https://dpm.demdex.net/id?d_visid_ver=5.4.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=9E1005A551ED61CA0A490D45%40AdobeOrg&d_nsid=0&ts=1730448854177
34.241.19.39
https://github.com/WebReflection/url-search-params/blob/master/README.md#ios-10--other-platforms-bug
unknown
https://p.typekit.net/p.gif
unknown
http://typekit.com/eulas/0000000000000000000176ff
unknown
https://use.typekit.net/af/eaf09c/000000000000000000017703/27/
unknown
http://typekit.com/eulas/000000000000000000017701
unknown
http://typekit.com/eulas/000000000000000000017703
unknown
https://use.typekit.net/af/cb695f/000000000000000000017701/27/
unknown
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
adobe.com.ssl.d1.sc.omtrdc.net
63.140.62.222
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.186.100
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
34.241.19.39
fp2e7a.wpc.phicdn.net
192.229.221.95
use.typekit.net
unknown
p.typekit.net
unknown
dpm.demdex.net
unknown

IPs

IP
Domain
Country
Malicious
34.241.19.39
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
63.140.62.222
adobe.com.ssl.d1.sc.omtrdc.net
United States
142.250.186.100
www.google.com
United States
54.247.166.172
unknown
United States

DOM / HTML

URL
Malicious
https://auth.services.adobe.com/en_US/deeplink.html?deeplink=ssofirst&callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2FCampaign1%2FAdobeID%2Fcode%3Fredirect_uri%3Dhttps%253A%252F%252Fadobe.com%26code_challenge_method%3Dplain%26use_ms_for_expiry%3Dtrue&client_id=Campaign1&scope=AdobeID%2Cperson%2Csession%2Cadditional_info.projectedProductContext%2Cread_organizations%2Cadditional_info.user_image_url%2Cwrite_pc%2Caudiencemanager_api%2Copenid%2Ctriggers&relay=8c936133-7454-49b0-9379-725bf4a3e0a4&locale=en_US&flow_type=code&idp_flow_type=login&s_p=google%2Cfacebook%2Capple%2Cmicrosoft%2Cline%2Ckakao&response_type=code&code_challenge_method=plain&redirect_uri=https%3A%2F%2Fadobe.com&use_ms_for_expiry=true#/
https://auth.services.adobe.com/en_US/deeplink.html?deeplink=ssofirst&callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2FCampaign1%2FAdobeID%2Fcode%3Fredirect_uri%3Dhttps%253A%252F%252Fadobe.com%26code_challenge_method%3Dplain%26use_ms_for_expiry%3Dtrue&client_id=Campaign1&scope=AdobeID%2Cperson%2Csession%2Cadditional_info.projectedProductContext%2Cread_organizations%2Cadditional_info.user_image_url%2Cwrite_pc%2Caudiencemanager_api%2Copenid%2Ctriggers&relay=8c936133-7454-49b0-9379-725bf4a3e0a4&locale=en_US&flow_type=code&idp_flow_type=login&s_p=google%2Cfacebook%2Capple%2Cmicrosoft%2Cline%2Ckakao&response_type=code&code_challenge_method=plain&redirect_uri=https%3A%2F%2Fadobe.com&use_ms_for_expiry=true#/
https://auth.services.adobe.com/en_US/deeplink.html?deeplink=ssofirst&callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2FCampaign1%2FAdobeID%2Fcode%3Fredirect_uri%3Dhttps%253A%252F%252Fadobe.com%26code_challenge_method%3Dplain%26use_ms_for_expiry%3Dtrue&client_id=Campaign1&scope=AdobeID%2Cperson%2Csession%2Cadditional_info.projectedProductContext%2Cread_organizations%2Cadditional_info.user_image_url%2Cwrite_pc%2Caudiencemanager_api%2Copenid%2Ctriggers&relay=8c936133-7454-49b0-9379-725bf4a3e0a4&locale=en_US&flow_type=code&idp_flow_type=login&s_p=google%2Cfacebook%2Capple%2Cmicrosoft%2Cline%2Ckakao&response_type=code&code_challenge_method=plain&redirect_uri=https%3A%2F%2Fadobe.com&use_ms_for_expiry=true#/signup
https://auth.services.adobe.com/en_US/deeplink.html?deeplink=ssofirst&callback=https%3A%2F%2Fims-na1.adobelogin.com%2Fims%2Fadobeid%2FCampaign1%2FAdobeID%2Fcode%3Fredirect_uri%3Dhttps%253A%252F%252Fadobe.com%26code_challenge_method%3Dplain%26use_ms_for_expiry%3Dtrue&client_id=Campaign1&scope=AdobeID%2Cperson%2Csession%2Cadditional_info.projectedProductContext%2Cread_organizations%2Cadditional_info.user_image_url%2Cwrite_pc%2Caudiencemanager_api%2Copenid%2Ctriggers&relay=8c936133-7454-49b0-9379-725bf4a3e0a4&locale=en_US&flow_type=code&idp_flow_type=login&s_p=google%2Cfacebook%2Capple%2Cmicrosoft%2Cline%2Ckakao&response_type=code&code_challenge_method=plain&redirect_uri=https%3A%2F%2Fadobe.com&use_ms_for_expiry=true#/signup