IOC Report
https://u47061537.ct.sendgrid.net/asm/?user_id=47061537&data=wC-jv8IMxAkdiHnCMWyk-neV5g5HnOQ3gB0mlQ4O8I9oMDAwdTAwMJynV_0Rtep0BopOoRcWUYlWHf8jaIMzNTgXiQOPH1xAo8MTRqkOrS5JtkkSGabqpSe2qafaIntcg0yqpjWBmHoL7SH9TqignK9zn1FmLN-QVa7rsiyiwOaWmK0T5ZVElXYBFTlrp3JrQXeeG90bqf81YTWTIA7bZo31iosAdgHAY7XxCPcSXjKaNlQ

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 43
Web Open Font Format (Version 2), TrueType, length 20388, version 1.0
downloaded
Chrome Cache Entry: 44
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 45
Web Open Font Format (Version 2), TrueType, length 20276, version 1.0
downloaded
Chrome Cache Entry: 46
ASCII text
downloaded
Chrome Cache Entry: 47
ASCII text
downloaded
Chrome Cache Entry: 48
ASCII text
dropped
Chrome Cache Entry: 49
HTML document, ASCII text, with very long lines (1152)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2044 --field-trial-handle=1744,i,11154345644276576522,4461382776646555244,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u47061537.ct.sendgrid.net/asm/?user_id=47061537&data=wC-jv8IMxAkdiHnCMWyk-neV5g5HnOQ3gB0mlQ4O8I9oMDAwdTAwMJynV_0Rtep0BopOoRcWUYlWHf8jaIMzNTgXiQOPH1xAo8MTRqkOrS5JtkkSGabqpSe2qafaIntcg0yqpjWBmHoL7SH9TqignK9zn1FmLN-QVa7rsiyiwOaWmK0T5ZVElXYBFTlrp3JrQXeeG90bqf81YTWTIA7bZo31iosAdgHAY7XxCPcSXjKaNlQsKV62vc1rc5OZ4_Ry7iEMfm96HfgfwSDNBBY8YEXbnnDDMEKwRLVb5Rf8hrLP4RGuYvLx_J7Cs_xpSTeCbrcXe8qLitinTwoQpPz9Xp-RpdsWEAjeIU5I3pgOoTNJzhI0rOBJ2heKTbCKnaj2lfQhiKQs5CY14uXHW_ZpqaWYmkFgFb29R8oqyL5snRw7aR0hkGIyY4Lh_55uEzxqw3WOHg2qv8azdJEhb0izN6kekIEDOrhsxCbw-_Wi2F_ru0lb29kwYBcyFS1GdvjpfegW8mWlLwmcxFpP4buOPWoqcil8SPrS_aTpaKNorbN9mhWZWSEs1tXiXg2yXMtyMEg7Hhsxk29GeDutnfkErosRQEXW5Acim1pmB3267X7RKYzMQYX2VdSJ3P5rltP2YIpilPLMXSmF-hfyzixNPVMlY12-15z5zaov1QoPi6bRWynEbrFPFcseiEzMhDmEY026NK1BTptguXt1BO_FM_7JkPiOMkmew7Vq_5d4--AJr2PMYc7htOamyhf0O9W2cpNB2QJ_G1LpAZ1_us6vhfd_4L3XKZmcVv_1Gz8ne0t03ygSIrlLIB_lWK7I26A_CNc6ZVyXK4aVLAkriqi29IbforP38ya5TAuvB5toz5gn9LhbNXTt_qaVgg784Or6mQQDQSq5sjS_d9wuxHRfzKeQl3OaFUoEry4TglTkBEL3frzSNUJMoM32HocdsVazbYt8RI6qnwbl52MGihaHszP7RHwUY457d9GL262r7voUpF2q0KybwVCK_GgbrWdgOGFUJ-CNXqKAgGaDHZFNqeXr9BNjbZXD8OOsNFNaX7gltqlZOHdYOg=="

URLs

Name
IP
Malicious
https://u47061537.ct.sendgrid.net/asm/?user_id=47061537&data=wC-jv8IMxAkdiHnCMWyk-neV5g5HnOQ3gB0mlQ4O8I9oMDAwdTAwMJynV_0Rtep0BopOoRcWUYlWHf8jaIMzNTgXiQOPH1xAo8MTRqkOrS5JtkkSGabqpSe2qafaIntcg0yqpjWBmHoL7SH9TqignK9zn1FmLN-QVa7rsiyiwOaWmK0T5ZVElXYBFTlrp3JrQXeeG90bqf81YTWTIA7bZo31iosAdgHAY7XxCPcSXjKaNlQsKV62vc1rc5OZ4_Ry7iEMfm96HfgfwSDNBBY8YEXbnnDDMEKwRLVb5Rf8hrLP4RGuYvLx_J7Cs_xpSTeCbrcXe8qLitinTwoQpPz9Xp-RpdsWEAjeIU5I3pgOoTNJzhI0rOBJ2heKTbCKnaj2lfQhiKQs5CY14uXHW_ZpqaWYmkFgFb29R8oqyL5snRw7aR0hkGIyY4Lh_55uEzxqw3WOHg2qv8azdJEhb0izN6kekIEDOrhsxCbw-_Wi2F_ru0lb29kwYBcyFS1GdvjpfegW8mWlLwmcxFpP4buOPWoqcil8SPrS_aTpaKNorbN9mhWZWSEs1tXiXg2yXMtyMEg7Hhsxk29GeDutnfkErosRQEXW5Acim1pmB3267X7RKYzMQYX2VdSJ3P5rltP2YIpilPLMXSmF-hfyzixNPVMlY12-15z5zaov1QoPi6bRWynEbrFPFcseiEzMhDmEY026NK1BTptguXt1BO_FM_7JkPiOMkmew7Vq_5d4--AJr2PMYc7htOamyhf0O9W2cpNB2QJ_G1LpAZ1_us6vhfd_4L3XKZmcVv_1Gz8ne0t03ygSIrlLIB_lWK7I26A_CNc6ZVyXK4aVLAkriqi29IbforP38ya5TAuvB5toz5gn9LhbNXTt_qaVgg784Or6mQQDQSq5sjS_d9wuxHRfzKeQl3OaFUoEry4TglTkBEL3frzSNUJMoM32HocdsVazbYt8RI6qnwbl52MGihaHszP7RHwUY457d9GL262r7voUpF2q0KybwVCK_GgbrWdgOGFUJ-CNXqKAgGaDHZFNqeXr9BNjbZXD8OOsNFNaX7gltqlZOHdYOg==
https://u47061537.ct.sendgrid.net/asm/assets/stylesheets/app.css
167.89.118.74
https://u47061537.ct.sendgrid.net/asm/assets/fonts/colfax-regular.woff2
167.89.118.74
https://u47061537.ct.sendgrid.net/asm/assets/fonts/colfax-medium.woff2
167.89.118.74
https://u47061537.ct.sendgrid.net/favicon.ico
167.89.118.74
https://u47061537.ct.sendgrid.net/asm/assets/javascripts/app.js
167.89.118.74

Domains

Name
IP
Malicious
u47061537.ct.sendgrid.net
167.89.118.74
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
216.58.206.68
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
167.89.118.74
u47061537.ct.sendgrid.net
United States
239.255.255.250
unknown
Reserved
167.89.118.35
unknown
United States
192.168.2.6
unknown
unknown
216.58.206.68
www.google.com
United States

DOM / HTML

URL
Malicious
https://u47061537.ct.sendgrid.net/asm/?user_id=47061537&data=wC-jv8IMxAkdiHnCMWyk-neV5g5HnOQ3gB0mlQ4O8I9oMDAwdTAwMJynV_0Rtep0BopOoRcWUYlWHf8jaIMzNTgXiQOPH1xAo8MTRqkOrS5JtkkSGabqpSe2qafaIntcg0yqpjWBmHoL7SH9TqignK9zn1FmLN-QVa7rsiyiwOaWmK0T5ZVElXYBFTlrp3JrQXeeG90bqf81YTWTIA7bZo31iosAdgHAY7XxCPcSXjKaNlQsKV62vc1rc5OZ4_Ry7iEMfm96HfgfwSDNBBY8YEXbnnDDMEKwRLVb5Rf8hrLP4RGuYvLx_J7Cs_xpSTeCbrcXe8qLitinTwoQpPz9Xp-RpdsWEAjeIU5I3pgOoTNJzhI0rOBJ2heKTbCKnaj2lfQhiKQs5CY14uXHW_ZpqaWYmkFgFb29R8oqyL5snRw7aR0hkGIyY4Lh_55uEzxqw3WOHg2qv8azdJEhb0izN6kekIEDOrhsxCbw-_Wi2F_ru0lb29kwYBcyFS1GdvjpfegW8mWlLwmcxFpP4buOPWoqcil8SPrS_aTpaKNorbN9mhWZWSEs1tXiXg2yXMtyMEg7Hhsxk29GeDutnfkErosRQEXW5Acim1pmB3267X7RKYzMQYX2VdSJ3P5rltP2YIpilPLMXSmF-hfyzixNPVMlY12-15z5zaov1QoPi6bRWynEbrFPFcseiEzMhDmEY026NK1BTptguXt1BO_FM_7JkPiOMkmew7Vq_5d4--AJr2PMYc7htOamyhf0O9W2cpNB2QJ_G1LpAZ1_us6vhfd_4L3XKZmcVv_1Gz8ne0t03ygSIrlLIB_lWK7I26A_CNc6ZVyXK4aVLAkriqi29IbforP38ya5TAuvB5toz5gn9LhbNXTt_qaVgg784Or6mQQDQSq5sjS_d9wuxHRfzKeQl3OaFUoEry4TglTkBEL3frzSNUJMoM32HocdsVazbYt
https://u47061537.ct.sendgrid.net/asm/?user_id=47061537&data=wC-jv8IMxAkdiHnCMWyk-neV5g5HnOQ3gB0mlQ4O8I9oMDAwdTAwMJynV_0Rtep0BopOoRcWUYlWHf8jaIMzNTgXiQOPH1xAo8MTRqkOrS5JtkkSGabqpSe2qafaIntcg0yqpjWBmHoL7SH9TqignK9zn1FmLN-QVa7rsiyiwOaWmK0T5ZVElXYBFTlrp3JrQXeeG90bqf81YTWTIA7bZo31iosAdgHAY7XxCPcSXjKaNlQsKV62vc1rc5OZ4_Ry7iEMfm96HfgfwSDNBBY8YEXbnnDDMEKwRLVb5Rf8hrLP4RGuYvLx_J7Cs_xpSTeCbrcXe8qLitinTwoQpPz9Xp-RpdsWEAjeIU5I3pgOoTNJzhI0rOBJ2heKTbCKnaj2lfQhiKQs5CY14uXHW_ZpqaWYmkFgFb29R8oqyL5snRw7aR0hkGIyY4Lh_55uEzxqw3WOHg2qv8azdJEhb0izN6kekIEDOrhsxCbw-_Wi2F_ru0lb29kwYBcyFS1GdvjpfegW8mWlLwmcxFpP4buOPWoqcil8SPrS_aTpaKNorbN9mhWZWSEs1tXiXg2yXMtyMEg7Hhsxk29GeDutnfkErosRQEXW5Acim1pmB3267X7RKYzMQYX2VdSJ3P5rltP2YIpilPLMXSmF-hfyzixNPVMlY12-15z5zaov1QoPi6bRWynEbrFPFcseiEzMhDmEY026NK1BTptguXt1BO_FM_7JkPiOMkmew7Vq_5d4--AJr2PMYc7htOamyhf0O9W2cpNB2QJ_G1LpAZ1_us6vhfd_4L3XKZmcVv_1Gz8ne0t03ygSIrlLIB_lWK7I26A_CNc6ZVyXK4aVLAkriqi29IbforP38ya5TAuvB5toz5gn9LhbNXTt_qaVgg784Or6mQQDQSq5sjS_d9wuxHRfzKeQl3OaFUoEry4TglTkBEL3frzSNUJMoM32HocdsVazbYt