IOC Report
https://eu.knowbe4.com/auth/saml/c33d8069242e

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 128
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 406986
dropped
Chrome Cache Entry: 129
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
dropped
Chrome Cache Entry: 130
HTML document, ASCII text, with very long lines (3450), with CRLF line terminators
downloaded
Chrome Cache Entry: 131
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 200x95, components 3
downloaded
Chrome Cache Entry: 132
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113401
downloaded
Chrome Cache Entry: 133
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 119648
dropped
Chrome Cache Entry: 134
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 406986
downloaded
Chrome Cache Entry: 135
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 57443
dropped
Chrome Cache Entry: 136
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113769
dropped
Chrome Cache Entry: 137
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 119648
downloaded
Chrome Cache Entry: 138
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 11970
downloaded
Chrome Cache Entry: 139
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
downloaded
Chrome Cache Entry: 140
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 11970
dropped
Chrome Cache Entry: 141
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1310, components 3
dropped
Chrome Cache Entry: 142
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1310, components 3
downloaded
Chrome Cache Entry: 143
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113769
downloaded
Chrome Cache Entry: 144
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 9285
downloaded
Chrome Cache Entry: 145
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 15755
dropped
Chrome Cache Entry: 146
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 57443
downloaded
Chrome Cache Entry: 147
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 9285
dropped
Chrome Cache Entry: 148
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
downloaded
Chrome Cache Entry: 149
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 15755
downloaded
Chrome Cache Entry: 150
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
dropped
Chrome Cache Entry: 151
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 152
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 449844
dropped
Chrome Cache Entry: 153
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 154
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 155
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 156
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 157
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 158
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1310, components 3
downloaded
Chrome Cache Entry: 159
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 160
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 449844
downloaded
Chrome Cache Entry: 161
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 200x95, components 3
dropped
There are 25 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1656 --field-trial-handle=1936,i,5408255694739210393,11818520442255201119,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://eu.knowbe4.com/auth/saml/c33d8069242e"

URLs

Name
IP
Malicious
https://eu.knowbe4.com/auth/saml/c33d8069242e
https://aadcdn.msauthimages.net/c1c6b6c8-obob6uz3nidzuuv1qwz2jtykzbgxef3vz5oy-e2m4f4/logintenantbranding/0/illustration?ts=636374910507629828
152.199.21.175
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
https://aadcdn.msftauthimages.net/c1c6b6c8-obob6uz3nidzuuv1qwz2jtykzbgxef3vz5oy-e2m4f4/logintenantbranding/0/illustration?ts=636374910507629828
13.107.246.60
https://login.microsoftonline.com
unknown
https://eu.knowbe4.com/auth/saml/c33d8069242e
52.222.236.7
https://aadcdn.msauthimages.net/c1c6b6c8-obob6uz3nidzuuv1qwz2jtykzbgxef3vz5oy-e2m4f4/logintenantbranding/0/bannerlogo?ts=636374909487213813
152.199.21.175
https://login.windows-ppe.net
unknown
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D
https://autologon.microsoftazuread-sso.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/winauth/ssoprobe?client-request-id=86f3327a-513a-4b17-80a7-f8671ca05158&_=1728655788321
20.190.159.75

Domains

Name
IP
Malicious
eu.knowbe4.com
52.222.236.7
bg.microsoft.map.fastly.net
199.232.214.172
s-part-0023.t-0009.t-msedge.net
13.107.246.51
sni1gl.wpc.upsiloncdn.net
152.199.21.175
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
sni1gl.wpc.omegacdn.net
152.199.21.175
www.google.com
142.250.186.36
s-part-0032.t-0009.t-msedge.net
13.107.246.60
fp2e7a.wpc.phicdn.net
192.229.221.95
autologon.microsoftazuread-sso.com
20.190.159.75
aadcdn.msauthimages.net
unknown
identity.nel.measure.office.net
unknown
aadcdn.msftauth.net
unknown
login.microsoftonline.com
unknown
aadcdn.msftauthimages.net
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.51
s-part-0023.t-0009.t-msedge.net
United States
142.250.186.36
www.google.com
United States
13.107.253.45
s-part-0017.t-0009.fb-t-msedge.net
United States
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States
192.168.2.6
unknown
unknown
20.190.159.75
autologon.microsoftazuread-sso.com
United States
239.255.255.250
unknown
Reserved
152.199.21.175
sni1gl.wpc.upsiloncdn.net
United States
52.222.236.7
eu.knowbe4.com
United States

DOM / HTML

URL
Malicious
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true
https://login.microsoftonline.com/b7dba93e-7b6e-4933-abb6-e1739feb42e5/saml2?SAMLRequest=fZLBbtswEER%2FRTeeKIkSLUuEZUCJUcCoWxR2mkMvAUmtGiIU6XKpuv37ygqCuof0uph5s5jdDcrRnkU3xWd3hB8TYEw6RAjReHfvHU4jhBOEn0bD1%2BOhJc8xnlFkGUzpi%2FMXBTzVfszkDMiurEyXZV%2FnVVPwAjItrVVSv5BkN5ONk1fsX4j1341LR6ODRz9E76xxsPDUuleyKYGuVQWUN2VJpVIVBbYumwHUDF8teQVJ9ruWPFVDw1d1VdK%2B7iXlOQMqtaopg7Lm0Cs2VKtZijjB3mGULrakyAtOWU4Ze2Bc5I3g%2BTeSPELAZcsizUnya7QOxTWpJVNwwks0KJwcAUXU4tR9OohZKORbabeW8%2F895%2BCj196S7eaqFst2Yftx7vUO%2BCa7HW5eD%2FV5hux3X7w1%2BnfSWesv9wFkhJbEMAFJPvgwyvh%2BLEvZMjE9HRapgFEa2%2FV9AESSbV9T%2F%2F2I7R8%3D&sso_reload=true