Edit tour

Windows Analysis Report
http://www.accessmyig.com

Overview

General Information

Sample URL:http://www.accessmyig.com
Analysis ID:1662612
Infos:

Detection

Score:21
Range:0 - 100
Confidence:100%

Signatures

AI detected suspicious URL
Creates files inside the system directory
Deletes files inside the Windows folder
HTML page contains hidden javascript code

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
  • System is w11x64_office
  • chrome.exe (PID: 3848 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
    • chrome.exe (PID: 6820 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1840,i,13147103949837779127,4464250942964002012,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=2200 /prefetch:11 MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
  • chrome.exe (PID: 3788 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.accessmyig.com" MD5: DBE43C1D0092437B88CFF7BD9ABC336C)
  • cleanup
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Phishing

barindex
Source: http://ww1.accessmyig.comJoe Sandbox AI: The URL 'accessmyig.com' appears to be targeting Instagram users by using 'ig', a common abbreviation for Instagram. The subdomain 'ww1' is a common tactic used in typosquatting to mimic 'www'. The domain structure suggests an attempt to confuse users into thinking they are accessing Instagram-related services. The use of 'accessmy' implies a service related to account access, which could mislead users into believing it is a legitimate Instagram service. The similarity score is high due to the use of 'ig' and the structural mimicry of 'www'. The likelihood of typosquatting is also high given the context and the potential for user confusion.
Source: http://ww1.accessmyig.com/?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20ServicesHTTP Parser: Base64 decoded: {"uuid":"99a36b44-03e7-4901-93e8-205729954edd","page_time":1744322718,"page_url":"http://ww1.accessmyig.com/?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20Services","page_method"...
Source: http://ww1.accessmyig.com/?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20ServicesHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 5.79.79.212:443 -> 192.168.2.26:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.26:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.26:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.26:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.238:443 -> 192.168.2.26:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.238:443 -> 192.168.2.26:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49730 version: TLS 1.2
Source: chrome.exeMemory has grown: Private usage: 6MB later: 37MB
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.149
Source: unknownTCP traffic detected without corresponding DNS query: 208.89.73.149
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 142.251.40.131
Source: unknownTCP traffic detected without corresponding DNS query: 23.203.176.221
Source: unknownTCP traffic detected without corresponding DNS query: 23.203.176.221
Source: unknownTCP traffic detected without corresponding DNS query: 23.203.176.221
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.203.176.221
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.130
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.130
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.64
Source: unknownTCP traffic detected without corresponding DNS query: 2.19.122.64
Source: unknownTCP traffic detected without corresponding DNS query: 20.190.190.130
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.46.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.46.32
Source: unknownTCP traffic detected without corresponding DNS query: 23.33.46.32
Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.accessmyig.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adsense/domains/caf.js?abp=1&bodis=true HTTP/1.1Host: www.google.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*X-Client-Data: CI+2yQEIprbJAQiJksoBCKmdygEI44nLAQiSocsBCIWgzQEIyOHOAQ==Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: http://ww1.accessmyig.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /afs/ads?adtest=off&psid=3113057640&pcsa=false&channel=pid-bodis-gcontrol97%2Cpid-bodis-gcontrol122%2Cpid-bodis-gcontrol488%2Cpid-bodis-gcontrol152%2Cpid-bodis-gcontrol162&client=dp-bodis30_3ph&r=m&hl=en&ivt=1&rpbu=http%3A%2F%2Fww1.accessmyig.com%2F%3Fcaf%3D1%26bpt%3D345%26terms%3DTest%2BResults%2Band%2BElectronic%2BMedical%2BRecords%252COnline%2BAppointment%2BScheduling%2BSystem%252CMedical%2BBilling%2BServices&terms=Test%20Results%20and%20Electronic%20Medical%20Records%2COnline%20Appointment%20Scheduling%20System%2CMedical%20Billing%20Services&kw=Test%20Results%20and%20Electronic%20Medical%20Records&max_radlink_len=50&type=3&uiopt=false&swp=as-drid-2298147197369106&oe=UTF-8&ie=UTF-8&fexp=21404%2C17300000%2C17301431%2C17301433%2C17301436%2C17301548%2C17301266%2C72717108&format=r3&nocache=5801744322719215&num=0&output=afd_ads&domain_name=ww1.accessmyig.com&v=3&bsl=8&pac=0&u_his=1&u_tz=-240&dt=1744322719216&u_w=1280&u_h=1024&biw=1280&bih=889&psw=1280&psh=800&frm=0&uio=-&cont=rs&drt=0&jsid=caf&nfp=1&jsv=744711979&rurl=http%3A%2F%2Fww1.accessmyig.com%2F%3Fterms%3DTest%2520Results%2520and%2520Electronic%2520Medical%2520Records%2COnline%2520Appointment%2520Scheduling%2520System%2CMedical%2520Billing%2520Services HTTP/1.1Host: syndicatedsearch.googConnection: keep-alivesec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: cross-siteSec-Fetch-Mode: navigateSec-Fetch-Dest: iframeSec-Fetch-Storage-Access: activeReferer: http://ww1.accessmyig.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /adsense/domains/caf.js?pac=0 HTTP/1.1Host: syndicatedsearch.googConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptSec-Fetch-Storage-Access: activeReferer: https://syndicatedsearch.goog/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/chevron.svg?c=%2302198b HTTP/1.1Host: afs.googleusercontent.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CI+2yQEIprbJAQiJksoBCKmdygEI44nLAQiSocsBCIWgzQEIyOHOAQ==Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://syndicatedsearch.goog/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/chevron.svg?c=%23ffffff HTTP/1.1Host: afs.googleusercontent.comConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8X-Client-Data: CI+2yQEIprbJAQiJksoBCKmdygEI44nLAQiSocsBCIWgzQEIyOHOAQ==Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: https://syndicatedsearch.goog/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/chevron.svg?c=%2302198b HTTP/1.1Host: afs.googleusercontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*X-Client-Data: CI+2yQEIprbJAQiJksoBCKmdygEI44nLAQiSocsBCIWgzQEIyOHOAQ==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /ad_icons/standard/publisher_icon_image/chevron.svg?c=%23ffffff HTTP/1.1Host: afs.googleusercontent.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*X-Client-Data: CI+2yQEIprbJAQiJksoBCKmdygEI44nLAQiSocsBCIWgzQEIyOHOAQ==Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptySec-Fetch-Storage-Access: activeAccept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /afs/gen_204?client=dp-bodis30_3ph&output=uds_ads_only&zx=8zqickay92r0&cd_fexp=72717108&aqid=oED4Z7qCHq2QnboP6ba1yAU&psid=3113057640&pbt=bs&adbx=282.5&adby=143&adbh=363&adbw=700&adbah=114%2C114%2C114&adbn=master-1&eawp=partner-dp-bodis30_3ph&errv=744711979&csala=5%7C0%7C1130%7C825%7C33&lle=0&ifv=1&hpt=0 HTTP/1.1Host: syndicatedsearch.googConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: http://ww1.accessmyig.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /afs/gen_204?client=dp-bodis30_3ph&output=uds_ads_only&zx=j6081z80lxbo&cd_fexp=72717108&aqid=oED4Z7qCHq2QnboP6ba1yAU&psid=3113057640&pbt=bv&adbx=282.5&adby=143&adbh=363&adbw=700&adbah=114%2C114%2C114&adbn=master-1&eawp=partner-dp-bodis30_3ph&errv=744711979&csala=5%7C0%7C1130%7C825%7C33&lle=0&ifv=1&hpt=0 HTTP/1.1Host: syndicatedsearch.googConnection: keep-alivesec-ch-ua-platform: "Windows"User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36sec-ch-ua: "Chromium";v="134", "Not:A-Brand";v="24", "Google Chrome";v="134"sec-ch-ua-mobile: ?0Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageSec-Fetch-Storage-Access: activeReferer: http://ww1.accessmyig.com/Accept-Encoding: gzip, deflate, br, zstdAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20Services HTTP/1.1Host: ww1.accessmyig.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /bNsLPPKiU.js HTTP/1.1Host: ww1.accessmyig.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Referer: http://ww1.accessmyig.com/?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20ServicesAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: parking_session=99a36b44-03e7-4901-93e8-205729954edd
Source: global trafficHTTP traffic detected: GET /_fd?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20Services HTTP/1.1Host: ww1.accessmyig.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: parking_session=99a36b44-03e7-4901-93e8-205729954edd
Source: global trafficHTTP traffic detected: GET /_tr HTTP/1.1Host: ww1.accessmyig.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: */*Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: parking_session=99a36b44-03e7-4901-93e8-205729954edd; __gsas=ID=332023f89360bc1e:T=1744322720:RT=1744322720:S=ALNI_MZGhgSGWqjjVPcfpVE8-SqRuBiUqA
Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
Source: global trafficDNS traffic detected: DNS query: www.accessmyig.com
Source: global trafficDNS traffic detected: DNS query: ww1.accessmyig.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: syndicatedsearch.goog
Source: global trafficDNS traffic detected: DNS query: afs.googleusercontent.com
Source: unknownHTTP traffic detected: POST /_fd?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20Services HTTP/1.1Host: ww1.accessmyig.comConnection: keep-aliveContent-Length: 0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36Accept: application/jsonContent-Type: application/jsonOrigin: http://ww1.accessmyig.comReferer: http://ww1.accessmyig.com/?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20ServicesAccept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9Cookie: parking_session=99a36b44-03e7-4901-93e8-205729954edd
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49684
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49683
Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49684 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49683 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 5.79.79.212:443 -> 192.168.2.26:49710 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.26:49716 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.26:49717 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.35.164:443 -> 192.168.2.26:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.238:443 -> 192.168.2.26:49721 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.238:443 -> 192.168.2.26:49723 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49727 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49728 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49729 version: TLS 1.2
Source: unknownHTTPS traffic detected: 142.251.40.225:443 -> 192.168.2.26:49730 version: TLS 1.2
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile created: C:\Windows\SystemTemp\scoped_dir3848_222832028
Source: C:\Program Files\Google\Chrome\Application\chrome.exeFile deleted: C:\Windows\SystemTemp\scoped_dir3848_222832028
Source: classification engineClassification label: sus21.win@20/7@22/136
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1840,i,13147103949837779127,4464250942964002012,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=2200 /prefetch:11
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.accessmyig.com"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1840,i,13147103949837779127,4464250942964002012,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=2200 /prefetch:11
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Browser Extensions
1
Process Injection
1
Masquerading
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
Extra Window Memory Injection
1
Process Injection
LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
File Deletion
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Extra Window Memory Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
http://www.accessmyig.com0%Avira URL Cloudsafe
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://ww1.accessmyig.com/_fd?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20Services0%Avira URL Cloudsafe
https://www.accessmyig.com/0%Avira URL Cloudsafe
http://ww1.accessmyig.com/_tr0%Avira URL Cloudsafe
http://ww1.accessmyig.com/bNsLPPKiU.js0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
80880.bodis.com
199.59.243.228
truefalse
    unknown
    syndicatedsearch.goog
    142.251.40.238
    truefalse
      high
      www.accessmyig.com
      5.79.79.212
      truefalse
        high
        www.google.com
        142.251.35.164
        truefalse
          high
          googlehosted.l.googleusercontent.com
          142.251.40.225
          truefalse
            high
            ww1.accessmyig.com
            unknown
            unknownfalse
              high
              afs.googleusercontent.com
              unknown
              unknownfalse
                high
                NameMaliciousAntivirus DetectionReputation
                http://ww1.accessmyig.com/_fd?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20Servicestrue
                • Avira URL Cloud: safe
                unknown
                http://ww1.accessmyig.com/bNsLPPKiU.jstrue
                • Avira URL Cloud: safe
                unknown
                http://ww1.accessmyig.com/_trtrue
                • Avira URL Cloud: safe
                unknown
                http://c.pki.goog/r/gsr1.crlfalse
                  high
                  http://c.pki.goog/r/r4.crlfalse
                    high
                    https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/chevron.svg?c=%23fffffffalse
                      high
                      http://ww1.accessmyig.com/?terms=Test%20Results%20and%20Electronic%20Medical%20Records,Online%20Appointment%20Scheduling%20System,Medical%20Billing%20Servicestrue
                        unknown
                        https://syndicatedsearch.goog/adsense/domains/caf.js?pac=0false
                          high
                          https://afs.googleusercontent.com/ad_icons/standard/publisher_icon_image/chevron.svg?c=%2302198bfalse
                            high
                            https://www.accessmyig.com/false
                            • Avira URL Cloud: safe
                            unknown
                            https://www.google.com/adsense/domains/caf.js?abp=1&bodis=truefalse
                              high
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              142.250.65.170
                              unknownUnited States
                              15169GOOGLEUSfalse
                              1.1.1.1
                              unknownAustralia
                              13335CLOUDFLARENETUSfalse
                              142.250.65.174
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.251.40.238
                              syndicatedsearch.googUnited States
                              15169GOOGLEUSfalse
                              142.251.32.99
                              unknownUnited States
                              15169GOOGLEUSfalse
                              199.59.243.228
                              80880.bodis.comUnited States
                              395082BODIS-NJUSfalse
                              142.250.81.226
                              unknownUnited States
                              15169GOOGLEUSfalse
                              5.79.79.212
                              www.accessmyig.comNetherlands
                              60781LEASEWEB-NL-AMS-01NetherlandsNLfalse
                              142.251.40.225
                              googlehosted.l.googleusercontent.comUnited States
                              15169GOOGLEUSfalse
                              142.251.40.131
                              unknownUnited States
                              15169GOOGLEUSfalse
                              142.251.35.164
                              www.google.comUnited States
                              15169GOOGLEUSfalse
                              172.253.115.84
                              unknownUnited States
                              15169GOOGLEUSfalse
                              IP
                              192.168.2.26
                              Joe Sandbox version:42.0.0 Malachite
                              Analysis ID:1662612
                              Start date and time:2025-04-11 00:04:01 +02:00
                              Joe Sandbox product:CloudBasic
                              Overall analysis duration:
                              Hypervisor based Inspection enabled:false
                              Report type:full
                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                              Sample URL:http://www.accessmyig.com
                              Analysis system description:Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09
                              Run name:Potential for more IOCs and behavior
                              Number of analysed new started processes analysed:22
                              Number of new started drivers analysed:0
                              Number of existing processes analysed:0
                              Number of existing drivers analysed:0
                              Number of injected processes analysed:0
                              Technologies:
                              • EGA enabled
                              Analysis Mode:stream
                              Analysis stop reason:Timeout
                              Detection:SUS
                              Classification:sus21.win@20/7@22/136
                              • Exclude process from analysis (whitelisted): SIHClient.exe, svchost.exe
                              • Excluded IPs from analysis (whitelisted): 104.18.38.233, 172.64.149.23
                              • Excluded domains from analysis (whitelisted): crt.comodoca.com.cdn.cloudflare.net, crt.comodoca.com
                              • Not all processes where analyzed, report is missing behavior information
                              • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                              • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                              • VT rate limit hit for: http://www.accessmyig.com
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (1831)
                              Category:downloaded
                              Size (bytes):144073
                              Entropy (8bit):5.533533637608921
                              Encrypted:false
                              SSDEEP:
                              MD5:1748489B2C19BF31291C10505778F074
                              SHA1:022130C092FFAE22553E8F316294ABEB43F7259F
                              SHA-256:55732741CBF4284F94871D244ADB98B3EE70F439FB630AFE7F0FD726232A51E1
                              SHA-512:09751B4F8BF66AB6A70C3D8121FE6245EC79D49D4D6A53CA0FEA73B5310324F1C7541162409833911860BE67F50F3A18311AF5AD7E88A6247144C2E8425E4678
                              Malicious:false
                              Reputation:unknown
                              URL:https://www.google.com/adsense/domains/caf.js?abp=1&bodis=true
                              Preview:if(!window['googleNDT_']){window['googleNDT_']=(new Date()).getTime();}(function() {window.googleAltLoader=3;var sffeData_={service_host:"www.google.com",hash:"5974082084498614723",packages:"domains",module:"ads",version:"1",m:{cei:"17300000,17301431,17301433,17301436,17301548,17301266",ah:true,uatm:500,ecfc2:true,llrm:1000,lldl:"bS5zZWFycy5jb20=",abf:{"_disableAdRequestForNewConsentStrategy":true,"_enableNewConsentStrategy":true,"_fixCtcLinksOnIos":true,"_googEnableQup":true,"_switchGwsRequestToUseAdsenseDomain":true,"_useServerProvidedDomain":true,"_waitOnConsentForFirstPartyCookie":true,"enableEnhancedTargetingRsonc":true,"enableNonblockingSasCookie":true},mdp:1800000,ssdl:"YXBwc3BvdC5jb20sYmxvZ3Nwb3QuY29tLGJyLmNvbSxjby5jb20sY2xvdWRmcm9udC5uZXQsZXUuY29tLGhvcHRvLm9yZyxpbi5uZXQsdHJhbnNsYXRlLmdvb2csdWsuY29tLHVzLmNvbSx3ZWIuYXBw",cdl:false,cdh:"syndicatedsearch.goog",cdem:{"afs_aa_baseline":500,"afs_gpp_api":0,"disable_usp_api":50,"heterodyne_test":851,"ifr_unif":0,"ivt_changes":0,"rs_tc
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:HTML document, ASCII text, with very long lines (13488)
                              Category:downloaded
                              Size (bytes):14059
                              Entropy (8bit):5.309143583565157
                              Encrypted:false
                              SSDEEP:
                              MD5:9FDBBF5EF4A24DDC7B8B037B677508DB
                              SHA1:6BA085AE6130074474780340837FB7EC234DF1D7
                              SHA-256:71F2C996F96A192E4A08F9913F289DE9A4A7315514992D77F396F5B9C66CDAF3
                              SHA-512:6FA53E10BB32D1162BD31679B0FB9DA894CBDCA41BC4893C0D8F8981FECBC36BEF45B460A416598ABF9FF1B19FD09CB2EA9685E9AD0A0E6ECC7A12B02046B513
                              Malicious:false
                              Reputation:unknown
                              URL:https://syndicatedsearch.goog/afs/ads?adtest=off&psid=3113057640&pcsa=false&channel=pid-bodis-gcontrol97%2Cpid-bodis-gcontrol122%2Cpid-bodis-gcontrol488%2Cpid-bodis-gcontrol152%2Cpid-bodis-gcontrol162&client=dp-bodis30_3ph&r=m&hl=en&ivt=1&rpbu=http%3A%2F%2Fww1.accessmyig.com%2F%3Fcaf%3D1%26bpt%3D345%26terms%3DTest%2BResults%2Band%2BElectronic%2BMedical%2BRecords%252COnline%2BAppointment%2BScheduling%2BSystem%252CMedical%2BBilling%2BServices&terms=Test%20Results%20and%20Electronic%20Medical%20Records%2COnline%20Appointment%20Scheduling%20System%2CMedical%20Billing%20Services&kw=Test%20Results%20and%20Electronic%20Medical%20Records&max_radlink_len=50&type=3&uiopt=false&swp=as-drid-2298147197369106&oe=UTF-8&ie=UTF-8&fexp=21404%2C17300000%2C17301431%2C17301433%2C17301436%2C17301548%2C17301266%2C72717108&format=r3&nocache=5801744322719215&num=0&output=afd_ads&domain_name=ww1.accessmyig.com&v=3&bsl=8&pac=0&u_his=1&u_tz=-240&dt=1744322719216&u_w=1280&u_h=1024&biw=1280&bih=889&psw=1280&psh=800&frm=0&uio=-&cont=rs&drt=0&jsid=caf&nfp=1&jsv=744711979&rurl=http%3A%2F%2Fww1.accessmyig.com%2F%3Fterms%3DTest%2520Results%2520and%2520Electronic%2520Medical%2520Records%2COnline%2520Appointment%2520Scheduling%2520System%2CMedical%2520Billing%2520Services
                              Preview:<!doctype html><html lang="en"> <head> <style id="ssr-boilerplate">body{-webkit-text-size-adjust:100%; font-family:arial,sans-serif; margin:0;}.div{-webkit-box-flex:0 0; -webkit-flex-shrink:0; flex-shrink:0;max-width:100%;}.span:last-child, .div:last-child{-webkit-box-flex:1 0; -webkit-flex-shrink:1; flex-shrink:1;}.a{text-decoration:none; text-transform:none; color:inherit; display:inline-block;}.span{-webkit-box-flex:0 0; -webkit-flex-shrink:0; flex-shrink:0;display:inline-block; overflow:hidden; text-transform:none;}.img{border:none; max-width:100%; max-height:100%;}.i_{display:-ms-flexbox; display:-webkit-box; display:-webkit-flex; display:flex;-ms-flex-align:start; -webkit-box-align:start; -webkit-align-items:flex-start; align-items:flex-start;box-sizing:border-box; overflow:hidden;}.v_{-webkit-box-flex:1 0; -webkit-flex-shrink:1; flex-shrink:1;}.j_>span:last-child, .j_>div:last-child, .w_, .w_:last-child{-webkit-box-flex:0 0; -webkit-flex-shrink:0; flex-shrink:0;}.l_{-ms-overflow
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (1831)
                              Category:downloaded
                              Size (bytes):144071
                              Entropy (8bit):5.533328104293215
                              Encrypted:false
                              SSDEEP:
                              MD5:0A54371F255AC26AC0DF2A5E1632FEB1
                              SHA1:E5B2D47FF51126504C6D7D12577107E55071596C
                              SHA-256:FE6158E6F5C22825A98C1F15E2361A9F11C3BF16FC3117937EA67105DD4577C9
                              SHA-512:857190C97AFF10ECF1C080466BAE32EE1CCB7F9123DAA7B9B80D26FBCFDF73ADAAA165D6F3690AC7A066CBFE27734352BDA2710AF5573362640D7ADCBBD56F68
                              Malicious:false
                              Reputation:unknown
                              URL:https://syndicatedsearch.goog/adsense/domains/caf.js?pac=0
                              Preview:if(!window['googleNDT_']){window['googleNDT_']=(new Date()).getTime();}(function() {window.googleAltLoader=3;var sffeData_={service_host:"syndicatedsearch.goog",hash:"5974082084498614723",packages:"domains",module:"ads",version:"1",m:{cei:"17301431,17301433,17301436,17301548,17301266",ah:true,uatm:500,ecfc2:true,llrm:1000,lldl:"bS5zZWFycy5jb20=",abf:{"_disableAdRequestForNewConsentStrategy":true,"_enableNewConsentStrategy":true,"_fixCtcLinksOnIos":true,"_googEnableQup":true,"_switchGwsRequestToUseAdsenseDomain":true,"_useServerProvidedDomain":true,"_waitOnConsentForFirstPartyCookie":true,"enableEnhancedTargetingRsonc":true,"enableNonblockingSasCookie":true},mdp:1800000,ssdl:"YXBwc3BvdC5jb20sYmxvZ3Nwb3QuY29tLGJyLmNvbSxjby5jb20sY2xvdWRmcm9udC5uZXQsZXUuY29tLGhvcHRvLm9yZyxpbi5uZXQsdHJhbnNsYXRlLmdvb2csdWsuY29tLHVzLmNvbSx3ZWIuYXBw",cdl:false,cdh:"syndicatedsearch.goog",cdem:{"afs_aa_baseline":500,"afs_gpp_api":0,"disable_usp_api":50,"heterodyne_test":851,"ifr_unif":0,"ivt_changes":0,"rs_tcf"
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:SVG Scalable Vector Graphics image
                              Category:dropped
                              Size (bytes):200
                              Entropy (8bit):5.025855206845441
                              Encrypted:false
                              SSDEEP:
                              MD5:11B3089D616633CA6B73B57AA877EEB4
                              SHA1:07632F63E06B30D9B63C97177D3A8122629BDA9B
                              SHA-256:809FB4619D2A2F1A85DBDA8CC69A7F1659215212D708A098D62150EEE57070C1
                              SHA-512:079B0E35B479DFDBE64A987661000F4A034B10688E26F2A5FE6AAA807E81CCC5593D40609B731AB3340E687D83DD08DE4B8B1E01CDAC9D4523A9F6BB3ACFCBA0
                              Malicious:false
                              Reputation:unknown
                              Preview:<svg fill='#ffffff' xmlns="http://www.w3.org/2000/svg" height="24" viewBox="0 0 24 24" width="24"><path d="M0 0h24v24H0z" fill="none"/><path d="M5.88 4.12L13.76 12l-7.88 7.88L8 22l10-10L8 2z"/></svg>
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:Unicode text, UTF-8 text, with very long lines (35690)
                              Category:downloaded
                              Size (bytes):35693
                              Entropy (8bit):5.355418254879725
                              Encrypted:false
                              SSDEEP:
                              MD5:CB86DE4DC8F98AF79C860D6F8B48338F
                              SHA1:09D0EFEE4BCA1AEC0FB30BE9E6B9DF26F3D8A0C4
                              SHA-256:CBB9BA1A796129D45B456BAAEDCCF36FB95D4CDB8D302492B71BAA155C57D12A
                              SHA-512:5F3C3A7BAC6377AC10419A6F081FAEBD9FD9173B6157AC92D4D18C509D6C8AFE8C8E3F6DB1817B1A830CE06F1CE46D7D64E1D01F7367817BB00E78626CBB6F65
                              Malicious:false
                              Reputation:unknown
                              URL:http://ww1.accessmyig.com/bNsLPPKiU.js
                              Preview:!function(e,t){"object"==typeof exports&&"undefined"!=typeof module?t(exports):"function"==typeof define&&define.amd?define(["exports"],t):t((e="undefined"!=typeof globalThis?globalThis:e||self).version={})}(this,(function(exports){"use strict";function __awaiter(e,t,n,i){return new(n||(n=Promise))((function(s,a){function o(e){try{d(i.next(e))}catch(e){a(e)}}function r(e){try{d(i.throw(e))}catch(e){a(e)}}function d(e){var t;e.done?s(e.value):(t=e.value,t instanceof n?t:new n((function(e){e(t)}))).then(o,r)}d((i=i.apply(e,t||[])).next())}))}var Blocking;"function"==typeof SuppressedError&&SuppressedError,function(e){e.PENDING="pending",e.NONE="none",e.BLOCKED="blocked",e.ALLOWED="allowed"}(Blocking||(Blocking={}));class Adblock{constructor(e){this.state=Blocking.PENDING,this._mocked=!1,e?(this.state=e,this._mocked=!0):this.state=Blocking.ALLOWED}inject(){return __awaiter(this,void 0,void 0,(function*(){}))}hasAdblocker(){if(void 0===window.google)return!0;const e=document.querySelectorA
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:SVG Scalable Vector Graphics image
                              Category:dropped
                              Size (bytes):200
                              Entropy (8bit):5.044104743214503
                              Encrypted:false
                              SSDEEP:
                              MD5:D47125B2BA92BE53DCFF07BA322CE1DE
                              SHA1:E4A70C8A133BACF1699FDFA4C10E24ED5B3E0C28
                              SHA-256:5A0687EA8C9AA404A7724490F046E30023EC6B5AA81D01AE4F225889A64174F6
                              SHA-512:78A1BF7547B1C28F600163689161955BC56A621ACE3228C9169143BE933CCF789FC6106BBF729F2E9483BCAA03271529D3913088094C7FB906B44673E13F1F92
                              Malicious:false
                              Reputation:unknown
                              Preview:<svg fill='#02198b' xmlns="http://www.w3.org/2000/svg" height="24" viewBox="0 0 24 24" width="24"><path d="M0 0h24v24H0z" fill="none"/><path d="M5.88 4.12L13.76 12l-7.88 7.88L8 22l10-10L8 2z"/></svg>
                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                              File Type:ASCII text, with very long lines (382), with no line terminators
                              Category:downloaded
                              Size (bytes):382
                              Entropy (8bit):5.445533817817426
                              Encrypted:false
                              SSDEEP:
                              MD5:692345BE8405D5318D3BD62733666F80
                              SHA1:911BDC4F660332E37E8B734B5D6AF847EFFBB9DA
                              SHA-256:D60C0B054A7F9030AD475156C768D55329801E85ED2C3324317942028BD09B1E
                              SHA-512:CD5F08787544F022112E4721395BCD18B4981FD359AC1FF6590BF76DA738DA4FB7B63E4561576F2B5D65D77CF95D59F9555B90B3D86F26A5C59C5DC7FE57D0B8
                              Malicious:false
                              Reputation:unknown
                              URL:https://partner.googleadservices.com/gampad/cookie.js?domain=ww1.accessmyig.com&client=partner-dp-bodis30_3ph&product=SAS&callback=__sasCookie&cookie_types=v1%2Cv2
                              Preview:__sasCookie({"_cookies_":[{"_value_":"ID=332023f89360bc1e:T=1744322720:RT=1744322720:S=ALNI_MZGhgSGWqjjVPcfpVE8-SqRuBiUqA","_expires_":1778018720,"_path_":"/","_domain_":"accessmyig.com","_version_":1},{"_value_":"UID=0000100bd9329776:T=1744322720:RT=1744322720:S=ALNI_Mb_nA1OgA2GI_xpz_gLaNNLOhojsw","_expires_":1778018720,"_path_":"/","_domain_":"accessmyig.com","_version_":2}]});
                              No static file info