IOC Report
https://track.federalsamregistration.com

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 39
MS Windows icon resource - 1 icon, 16x16
dropped
Chrome Cache Entry: 40
PNG image data, 281 x 67, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 41
MS Windows icon resource - 1 icon, 16x16
downloaded
Chrome Cache Entry: 42
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 43
PNG image data, 281 x 67, 8-bit/color RGBA, non-interlaced
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2244 --field-trial-handle=2216,i,9111778991082413358,12912146831204823576,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://track.federalsamregistration.com"

URLs

Name
IP
Malicious
https://track.federalsamregistration.com
https://track.federalsamregistration.com/
https://jangomail.com/anti-spam-policy/
unknown
https://jangomail.com/privacy-policy/
unknown
https://track.federalsamregistration.com/main-logo.png
104.248.15.35
https://www.jangomail.com/
unknown
https://track.federalsamregistration.com/favicon.ico
104.248.15.35

Domains

Name
IP
Malicious
track.federalsamregistration.com
unknown
malicious
jngo.net
104.248.15.35
www.google.com
142.250.181.100

IPs

IP
Domain
Country
Malicious
104.248.15.35
jngo.net
United States
239.255.255.250
unknown
Reserved
192.168.2.6
unknown
unknown
142.250.181.100
www.google.com
United States

DOM / HTML

URL
Malicious
https://track.federalsamregistration.com/