IOC Report
https://u25072735.ct.sendgrid.net/ls/click?upn=u001.v-2Bitc7k3RoUxJPo3ktLJswTrqDd-2B6uuwoTdLIhT5W5HuE1LMSSnkjqbJpJWqYRB54TrRzsVqK-2B7tJLGEWaKEA6DbiSKX4ccvfmjgMnjJQk8-3DWGJZ_7NHJh-2F-2B9AERgcOTQKlLAV7I3wJMSqDmNQRytCqXhqe5jlc7kTO2cTaXGA-2FuXs1YxOtK9R7YV1ljUrEMGilZFJ78NsSfXjSu8332GWVg8ddAwawjTXzN-2Bfmq

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
ASCII text, with very long lines (13479)
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (5386)
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (1088)
dropped
Chrome Cache Entry: 103
ASCII text, with very long lines (18798)
downloaded
Chrome Cache Entry: 104
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 105
ASCII text
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 107
data
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (1088)
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (8171), with no line terminators
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (53869)
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (18798)
dropped
Chrome Cache Entry: 112
ASCII text, with very long lines (6425)
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (6241)
dropped
Chrome Cache Entry: 114
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 115
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 116
PNG image data, 959 x 259, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 117
ASCII text, with very long lines (6625), with no line terminators
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (65460)
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (65460)
dropped
Chrome Cache Entry: 68
ASCII text, with very long lines (58981)
downloaded
Chrome Cache Entry: 69
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (6241)
downloaded
Chrome Cache Entry: 71
ASCII text, with very long lines (1391)
dropped
Chrome Cache Entry: 72
ASCII text, with very long lines (6625), with no line terminators
dropped
Chrome Cache Entry: 73
ASCII text, with very long lines (2656)
downloaded
Chrome Cache Entry: 74
ASCII text, with very long lines (28437)
downloaded
Chrome Cache Entry: 75
Unicode text, UTF-8 text, with very long lines (38582), with no line terminators
dropped
Chrome Cache Entry: 76
ASCII text, with very long lines (316)
dropped
Chrome Cache Entry: 77
data
downloaded
Chrome Cache Entry: 78
ASCII text, with very long lines (4272)
dropped
Chrome Cache Entry: 79
ASCII text, with very long lines (4272)
downloaded
Chrome Cache Entry: 80
ASCII text, with very long lines (13479)
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (6026)
downloaded
Chrome Cache Entry: 82
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 83
Unicode text, UTF-8 text, with very long lines (38582), with no line terminators
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (2442)
downloaded
Chrome Cache Entry: 85
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 86
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 87
ASCII text, with very long lines (1391)
downloaded
Chrome Cache Entry: 88
JSON data
dropped
Chrome Cache Entry: 89
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 90
ASCII text, with very long lines (316)
downloaded
Chrome Cache Entry: 91
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 92
HTML document, ASCII text, with very long lines (57286)
downloaded
Chrome Cache Entry: 93
ASCII text, with very long lines (8171), with no line terminators
dropped
Chrome Cache Entry: 94
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 95
ASCII text, with very long lines (5386)
dropped
Chrome Cache Entry: 96
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 97
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 98
ASCII text
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (53869)
downloaded
There are 43 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=2040,i,7558815810444344806,14985835211176537731,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u25072735.ct.sendgrid.net/ls/click?upn=u001.v-2Bitc7k3RoUxJPo3ktLJswTrqDd-2B6uuwoTdLIhT5W5HuE1LMSSnkjqbJpJWqYRB54TrRzsVqK-2B7tJLGEWaKEA6DbiSKX4ccvfmjgMnjJQk8-3DWGJZ_7NHJh-2F-2B9AERgcOTQKlLAV7I3wJMSqDmNQRytCqXhqe5jlc7kTO2cTaXGA-2FuXs1YxOtK9R7YV1ljUrEMGilZFJ78NsSfXjSu8332GWVg8ddAwawjTXzN-2BfmqT9cerGzw1jhEz54hRoVN8J1ZRPx9DtghuInKT7JpAlxZW3UFCB8gG9Dmjxfxd7vrdGob89Txi-2F1rLDqMUsY5Y06UQh7tK7A-3D-3D"

URLs

Name
IP
Malicious
https://u25072735.ct.sendgrid.net/ls/click?upn=u001.v-2Bitc7k3RoUxJPo3ktLJswTrqDd-2B6uuwoTdLIhT5W5HuE1LMSSnkjqbJpJWqYRB54TrRzsVqK-2B7tJLGEWaKEA6DbiSKX4ccvfmjgMnjJQk8-3DWGJZ_7NHJh-2F-2B9AERgcOTQKlLAV7I3wJMSqDmNQRytCqXhqe5jlc7kTO2cTaXGA-2FuXs1YxOtK9R7YV1ljUrEMGilZFJ78NsSfXjSu8332GWVg8ddAwawjTXzN-2BfmqT9cerGzw1jhEz54hRoVN8J1ZRPx9DtghuInKT7JpAlxZW3UFCB8gG9Dmjxfxd7vrdGob89Txi-2F1rLDqMUsY5Y06UQh7tK7A-3D-3D
https://www.southeastbank.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=3.15.0
23.185.0.4
https://www.southeastbank.com/wp-admin/admin.php?page=Wordfence
23.185.0.4
https://bam.nr-data.net/jserrors/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=43772&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://www.southeastbank.com/wp-includes/js/dist/hooks.min.js?ver=2810c76e705dd1a53b18
23.185.0.4
https://www.southeastbank.com/wp-content/plugins/wordfence/modules/login-security/js/login.171215729
unknown
https://bam.nr-data.net/events/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=13755&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://www.southeastbank.com/wp-admin/css/login.min.css?ver=6.5.3
23.185.0.4
https://www.southeastbank.com/wp-login.php?redirect_to=https%3A%2F%2Fwww.southeastbank.com%2Fwp-admin%2Fadmin.php%3Fpage%3DWordfence&reauth=1
https://www.southeastbank.com/wp-content/themes/southeastbank/dist/styles/login.css?id=175a2c6eb30484547f37&ver=6.5.3
23.185.0.4
https://www.southeastbank.com/wp-admin/js/user-profile.min.js?ver=6.5.3
23.185.0.4
https://www.southeastbank.com/wp-login.php
unknown
https://www.southeastbank.com/wp-content/plugins/wordfence/modules/login-security/css/login.1712157296.css?ver=1.1.11
23.185.0.4
https://bam.nr-data.net/events/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=43757&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://www.southeastbank.com/wp-admin/css/forms.min.css?ver=6.5.3
23.185.0.4
https://www.southeastbank.com/wp-includes/js/dist/i18n.min.js?ver=5e580eb46a90c2b997e6
23.185.0.4
https://www.southeastbank.com/wp-content/uploads/2022/12/cropped-Favicon-180x180.png
unknown
https://bam.nr-data.net/jserrors/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=73819&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://www.southeastbank.com/wp-content/plugins/wordfence/modules/login-security/css/login.17121572
unknown
https://www.southeastbank.com/wp-includes/js/zxcvbn.min.js
23.185.0.4
https://www.southeastbank.com/wp-includes/js/underscore.min.js?ver=1.13.4
23.185.0.4
https://www.southeastbank.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.1
23.185.0.4
https://www.southeastbank.com/wp-content/themes/southeastbank/dist/styles/login.css?id=175a2c6eb3048
unknown
https://www.southeastbank.com/wp-includes/js/dist/vendor/regenerator-runtime.min.js?ver=0.14.0
23.185.0.4
https://www.southeastbank.com/wp-content/themes/southeastbank/dist/images/logo.png
23.185.0.4
https://www.southeastbank.com/wp-content/uploads/2022/12/cropped-Favicon-270x270.png
unknown
https://bam.nr-data.net/jserrors/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=63803&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://www.southeastbank.com/
unknown
https://www.southeastbank.com/wp-content/uploads/2022/12/cropped-Favicon-192x192.png
unknown
https://www.southeastbank.com/wp-includes/css/buttons.min.css?ver=6.5.3
23.185.0.4
https://www.southeastbank.com/wp-includes/js/zxcvbn-async.min.js?ver=1.0
23.185.0.4
https://www.southeastbank.com/wp-admin/js/password-strength-meter.min.js?ver=6.5.3
23.185.0.4
https://www.southeastbank.com
unknown
https://bam.nr-data.net/jserrors/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=33764&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://www.southeastbank.com/wp-includes/js/jquery/jquery.min.js?ver=3.7.1
23.185.0.4
https://www.southeastbank.com/wp-includes/js/wp-util.min.js?ver=6.5.3
23.185.0.4
https://www.southeastbank.com/wp-login.php?action=lostpassword
unknown
https://bam.nr-data.net/jserrors/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=53788&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://bam.nr-data.net/ins/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=43763&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb&at=SUFWRAhIGRs%3D
162.247.243.29
https://js-agent.newrelic.com/nr-spa-1.270.3.min.js
162.247.243.39
https://bam.nr-data.net/jserrors/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=23758&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb
162.247.243.29
https://www.southeastbank.com/wp-includes/css/dashicons.min.css?ver=6.5.3
23.185.0.4
https://u25072735.ct.sendgrid.net/ls/click?upn=u001.v-2Bitc7k3RoUxJPo3ktLJswTrqDd-2B6uuwoTdLIhT5W5HuE1LMSSnkjqbJpJWqYRB54TrRzsVqK-2B7tJLGEWaKEA6DbiSKX4ccvfmjgMnjJQk8-3DWGJZ_7NHJh-2F-2B9AERgcOTQKlLAV7I3wJMSqDmNQRytCqXhqe5jlc7kTO2cTaXGA-2FuXs1YxOtK9R7YV1ljUrEMGilZFJ78NsSfXjSu8332GWVg8ddAwawjTXzN-2BfmqT9cerGzw1jhEz54hRoVN8J1ZRPx9DtghuInKT7JpAlxZW3UFCB8gG9Dmjxfxd7vrdGob89Txi-2F1rLDqMUsY5Y06UQh7tK7A-3D-3D
167.89.118.106
http://www.southeastbank.com/wp-admin/admin.php?page=Wordfence
23.185.0.4
https://www.southeastbank.com/wp-includes/js/dist/vendor/wp-polyfill-inert.min.js?ver=3.1.2
23.185.0.4
https://www.southeastbank.com/wp-content/uploads/2022/12/cropped-Favicon-32x32.png
23.185.0.4
https://github.com/dropbox/zxcvbn
unknown
https://www.southeastbank.com/wp-content/plugins/wordfence/modules/login-security/js/login.1712157296.js?ver=1.1.11
23.185.0.4
https://www.southeastbank.com/wp-admin/css/l10n.min.css?ver=6.5.3
23.185.0.4
https://bam.nr-data.net/1/NRJS-c4fae05357fb6890012?a=574109562&v=1.270.3&to=ZQZVMkBSChUCVBAIDFxMYhRbHEsRExoIDgRbDRkWWkM%3D&rst=12858&ck=0&s=4fd17572417e3cd9&ref=https://www.southeastbank.com/wp-login.php&ptid=b2b5f023bf2573eb&af=err,spa,xhr,stn,ins&ap=444&be=8054&fe=3682&dc=3532&at=SUFWRAhIGRs%3D&fsh=1&perf=%7B%22timing%22:%7B%22of%22:1730465071185,%22n%22:0,%22f%22:5620,%22dn%22:5621,%22dne%22:5621,%22c%22:5621,%22s%22:5621,%22ce%22:6240,%22rq%22:6240,%22rp%22:8054,%22rpe%22:8294,%22di%22:11585,%22ds%22:11585,%22de%22:11586,%22dc%22:11732,%22l%22:11732,%22le%22:11736%7D,%22navigation%22:%7B%7D%7D&fp=10279&fcp=10279
162.247.243.29
There are 39 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
fastly-tls12-bam.nr-data.net
162.247.243.29
bg.microsoft.map.fastly.net
199.232.210.172
u25072735.ct.sendgrid.net
167.89.118.106
js-agent.newrelic.com
162.247.243.39
www.southeastbank.com
23.185.0.4
www.google.com
142.250.186.132
fp2e7a.wpc.phicdn.net
192.229.221.95
bam.nr-data.net
unknown

IPs

IP
Domain
Country
Malicious
167.89.118.106
u25072735.ct.sendgrid.net
United States
192.168.2.6
unknown
unknown
239.255.255.250
unknown
Reserved
23.185.0.4
www.southeastbank.com
United States
162.247.243.29
fastly-tls12-bam.nr-data.net
United States
142.250.186.132
www.google.com
United States
162.247.243.39
js-agent.newrelic.com
United States

DOM / HTML

URL
Malicious
https://www.southeastbank.com/wp-login.php?redirect_to=https%3A%2F%2Fwww.southeastbank.com%2Fwp-admin%2Fadmin.php%3Fpage%3DWordfence&reauth=1
https://www.southeastbank.com/wp-login.php?redirect_to=https%3A%2F%2Fwww.southeastbank.com%2Fwp-admin%2Fadmin.php%3Fpage%3DWordfence&reauth=1