IOC Report
https://d39vnq04.eu1.hubspotlinks.com/Ctc/DP+113/d39vnq04/VVJNkt5B8l83W36Mw9F26PtFtW5g6HvJ5m7kFkN1n_9Zj5nXHsW8wM7ks6lZ3kPW43F0KM83fTV3W6-72q54XMm6RW2r0F7w5RqFjRN1cg5JdQQVBvW98xQ8h7p5rKDW2_b-2v7Tg9Y9N3PdFbnN1vD0N76tqFj4lGfRW4XcZ4Z3h-qymW7xfF4v1wTQWrW4x2hrh3mx3T-W8S2k5m89m-Q9W2C9dtK5qPQWBW5bcQx18dCG9W

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 47
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 48
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 49
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 50
PNG image data, 439 x 519, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 51
RIFF (little-endian) data, Web/P image, VP8 encoding, 1200x114, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 52
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 53
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 54
HTML document, Unicode text, UTF-8 text, with very long lines (1183)
downloaded
Chrome Cache Entry: 55
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 56
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 57
PNG image data, 164 x 100, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 58
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 439x519, components 3
dropped
Chrome Cache Entry: 59
PNG image data, 164 x 100, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 60
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 61
PNG image data, 600 x 350, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 62
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 63
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1200x114, components 3
dropped
Chrome Cache Entry: 64
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 65
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1200x114, components 3
dropped
Chrome Cache Entry: 66
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 439x519, components 3
dropped
Chrome Cache Entry: 67
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 68
HTML document, Unicode text, UTF-8 text, with very long lines (1477)
downloaded
Chrome Cache Entry: 69
RIFF (little-endian) data, Web/P image, VP8 encoding, 1200x114, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 70
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 71
PNG image data, 439 x 519, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 72
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 73
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 439x519, components 3
downloaded
Chrome Cache Entry: 74
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 75
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 439x519, components 3
downloaded
Chrome Cache Entry: 76
PNG image data, 200 x 50, 8-bit/color RGBA, non-interlaced
dropped
There are 21 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2260 --field-trial-handle=2228,i,14759548794007020436,12195919432113306144,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://d39vnq04.eu1.hubspotlinks.com/Ctc/DP+113/d39vnq04/VVJNkt5B8l83W36Mw9F26PtFtW5g6HvJ5m7kFkN1n_9Zj5nXHsW8wM7ks6lZ3kPW43F0KM83fTV3W6-72q54XMm6RW2r0F7w5RqFjRN1cg5JdQQVBvW98xQ8h7p5rKDW2_b-2v7Tg9Y9N3PdFbnN1vD0N76tqFj4lGfRW4XcZ4Z3h-qymW7xfF4v1wTQWrW4x2hrh3mx3T-W8S2k5m89m-Q9W2C9dtK5qPQWBW5bcQx18dCG9WW5CtmLz7rc-lqW8xfNkq7c0sNdW5F57S92n6yZvW2Q3p5q7FnnvnN11m78GXqL9PVwsBQp81kZlFW2bFNH755rk9FW6WdsyK8-RqJnW7f_7W32jZ9GzW6zXL6L1JtyyqW7Vb0bF3kgttPW3xyvQv3NXx1KW7cBS6W4VgPS9W6Ts6n28M01mvV19wnH3ZRNfkW821nys2yM5RSMLMPsRCqd0RN6ql3D9wsnQ_W5nJMsz95GqbjW5wwl7v2fYJrDW14N7cT2QcSq_W68B3bW1S1kcTW7kPFvH5NDpmvW9dRrYW4y9Xq2W2S9dxz1h8gxrW4DR4pT7l5GB9VrPTRh3pYq7WW89KkN03TKL2_W9dGp_l2Xx7twVkSNr84CgX2Kf1k5FqR04"

URLs

Name
IP
Malicious
https://d39vnq04.eu1.hubspotlinks.com/Ctc/DP+113/d39vnq04/VVJNkt5B8l83W36Mw9F26PtFtW5g6HvJ5m7kFkN1n_9Zj5nXHsW8wM7ks6lZ3kPW43F0KM83fTV3W6-72q54XMm6RW2r0F7w5RqFjRN1cg5JdQQVBvW98xQ8h7p5rKDW2_b-2v7Tg9Y9N3PdFbnN1vD0N76tqFj4lGfRW4XcZ4Z3h-qymW7xfF4v1wTQWrW4x2hrh3mx3T-W8S2k5m89m-Q9W2C9dtK5qPQWBW5bcQx18dCG9WW5CtmLz7rc-lqW8xfNkq7c0sNdW5F57S92n6yZvW2Q3p5q7FnnvnN11m78GXqL9PVwsBQp81kZlFW2bFNH755rk9FW6WdsyK8-RqJnW7f_7W32jZ9GzW6zXL6L1JtyyqW7Vb0bF3kgttPW3xyvQv3NXx1KW7cBS6W4VgPS9W6Ts6n28M01mvV19wnH3ZRNfkW821nys2yM5RSMLMPsRCqd0RN6ql3D9wsnQ_W5nJMsz95GqbjW5wwl7v2fYJrDW14N7cT2QcSq_W68B3bW1S1kcTW7kPFvH5NDpmvW9dRrYW4y9Xq2W2S9dxz1h8gxrW4DR4pT7l5GB9VrPTRh3pYq7WW89KkN03TKL2_W9dGp_l2Xx7twVkSNr84CgX2Kf1k5FqR04
https://d39vnq04.eu1.hubspotlinks.com/events/public/v1/encoded/track/tc/DP+113/d39vnq04/VVJNkt5B8l83W36Mw9F26PtFtW5g6HvJ5m7kFkN1n_9Zj5nXHsW8wM7ks6lZ3kPW43F0KM83fTV3W6-72q54XMm6RW2r0F7w5RqFjRN1cg5JdQQVBvW98xQ8h7p5rKDW2_b-2v7Tg9Y9N3PdFbnN1vD0N76tqFj4lGfRW4XcZ4Z3h-qymW7xfF4v1wTQWrW4x2hrh3mx3T-W8S2k5m89m-Q9W2C9dtK5qPQWBW5bcQx18dCG9WW5CtmLz7rc-lqW8xfNkq7c0sNdW5F57S92n6yZvW2Q3p5q7FnnvnN11m78GXqL9PVwsBQp81kZlFW2bFNH755rk9FW6WdsyK8-RqJnW7f_7W32jZ9GzW6zXL6L1JtyyqW7Vb0bF3kgttPW3xyvQv3NXx1KW7cBS6W4VgPS9W6Ts6n28M01mvV19wnH3ZRNfkW821nys2yM5RSMLMPsRCqd0RN6ql3D9wsnQ_W5nJMsz95GqbjW5wwl7v2fYJrDW14N7cT2QcSq_W68B3bW1S1kcTW7kPFvH5NDpmvW9dRrYW4y9Xq2W2S9dxz1h8gxrW4DR4pT7l5GB9VrPTRh3pYq7WW89KkN03TKL2_W9dGp_l2Xx7twVkSNr84CgX2Kf1k5FqR04?_ud=210ca827-0ab3-499d-b0c8-e21e06f1332b&_jss=1&_fl=8&_pl=5&_hc=4&_lg=en-US,en&_plt=Win32&_scr=1280,1024
172.65.220.77
https://d39vnq04.eu1.hubspotlinks.com/events/public/v1/encoded/track/tc/DP
unknown
https://edenred.pt/novidades/edenred/edenred-portugal-distinguida-como-marca-superbrands-2023/?utm_c
unknown
https://edenred.pt/novidades/edenred/euroticket-refeicao-e-marca-recomendada-2023/?utm_campaign=MFA%
unknown
https://www.edenred.pt/wp-content/uploads/2024/01/superbrands-1.jpg
107.162.184.232
https://27003262.hs-sites-eu1.com/informa%C3%A7%C3%A3o-sobre-atualiza%C3%A7%C3%A3o-no-portal-cliente-%E2%9A%A0%EF%B8%8F?ecid=AOKeC1bLyOZj9_NJ4Kz9NKQS_ZaLkkDFNsgv1PuIqJ2wvGPCRJcNHKTMYPPESNZczf1BXTvt362c&utm_campaign=MFA%20Portal%20Cliente&utm_medium=email&_hsenc=p2ANqtz-_-ecLxVA95QqG3Kf-445-LvJkk8gTUl0XmFE1t6JgWJyc7LJGJn4eY9pPFtczdWkrGuTv-TqFvz4C-JdtYOIjm1QEgQg&_hsmi=96739534&utm_content=96739534&utm_source=hs_email
https://hs-27003262.f.hubspotemail-eu1.net/hub/27003262/hubfs/Header%20email.png?upscale=true&width=1200&upscale=true&name=Header%20email.png
172.65.249.76
https://www.edenred.pt/wp-content/uploads/2024/01/google-1.png
107.162.184.232
https://hs-27003262.f.hubspotemail-eu1.net/hub/27003262/hubfs/Group%201%20(1).jpg?upscale=true&width=1200&upscale=true&name=Group%201%20(1).jpg
172.65.249.76
http://cliente.edenred.pt/?utm_campaign=MFA%20Portal%20Cliente&utm_source=hs_email&utm_mediu
unknown
http://27003262.hs-sites-eu1.com/informa
unknown
http://27003262.hs-sites-eu1.com/informa%C3%A7%C3%A3o-sobre-atualiza%C3%A7%C3%A3o-no-portal-cliente-
unknown
https://edenred.pt/termos-condicoes/politica-de-privacidade-dados-pessoais/?utm_campaign=MFA%20Porta
unknown
https://www.edenred.pt/wp-content/uploads/2024/01/recomendada-1.png
107.162.184.232
https://edenred.pt/novidades/edenred/edenred-distinguida-com-premio-cinco-estrelas-pelo-segundo-ano-
unknown
https://edenred.pt/wp-content/uploads/2022/01/logo-edenred.png
107.162.184.232
https://www.edenred.pt/wp-content/uploads/2024/01/linkedin-1.jpg
107.162.184.232
https://play.google.com/store/apps/details?id=pt.bes.pp.edenred&utm_campaign=Users%20-%20Digest&
unknown
https://www.edenred.pt/wp-content/uploads/2024/01/instagram-1.jpg
107.162.184.232
https://27003262.fs1.hubspotusercontent-eu1.net/hubfs/27003262/favicon-32x32.png
141.101.90.96
https://d39vnq04.eu1.hubspotlinks.com/Ctc/DP+113/d39vnq04/VVJNkt5B8l83W36Mw9F26PtFtW5g6HvJ5m7kFkN1n_9Zj5nXHsW8wM7ks6lZ3kPW43F0KM83fTV3W6-72q54XMm6RW2r0F7w5RqFjRN1cg5JdQQVBvW98xQ8h7p5rKDW2_b-2v7Tg9Y9N3PdFbnN1vD0N76tqFj4lGfRW4XcZ4Z3h-qymW7xfF4v1wTQWrW4x2hrh3mx3T-W8S2k5m89m-Q9W2C9dtK5qPQWBW5bcQx18dCG9WW5CtmLz7rc-lqW8xfNkq7c0sNdW5F57S92n6yZvW2Q3p5q7FnnvnN11m78GXqL9PVwsBQp81kZlFW2bFNH755rk9FW6WdsyK8-RqJnW7f_7W32jZ9GzW6zXL6L1JtyyqW7Vb0bF3kgttPW3xyvQv3NXx1KW7cBS6W4VgPS9W6Ts6n28M01mvV19wnH3ZRNfkW821nys2yM5RSMLMPsRCqd0RN6ql3D9wsnQ_W5nJMsz95GqbjW5wwl7v2fYJrDW14N7cT2QcSq_W68B3bW1S1kcTW7kPFvH5NDpmvW9dRrYW4y9Xq2W2S9dxz1h8gxrW4DR4pT7l5GB9VrPTRh3pYq7WW89KkN03TKL2_W9dGp_l2Xx7twVkSNr84CgX2Kf1k5FqR04
172.65.220.77
https://27003262.hs-sites-eu1.com/favicon.ico
141.101.90.96
https://www.instagram.com/edenred.portugal/?utm_campaign=Users%20-%20Digest&utm_medium=email&amp
unknown
https://www.linkedin.com/company/edenred-portugal/?utm_campaign=Users%20-%20Digest&utm_medium=em
unknown
https://hs-27003262.f.hubspotemail-eu1.net/hub/27003262/hubfs/Header%20email.png?upscale=true&wi
unknown
https://www.edenred.pt/wp-content/uploads/2024/01/apple-1.png
107.162.184.232
https://www.edenred.pt/wp-content/uploads/2024/01/app-gallery-1.png
107.162.184.232
https://hs-27003262.f.hubspotemail-eu1.net/hub/27003262/hubfs/Group%201.jpg?upscale=true&width=1
unknown
https://hs-27003262.s.hubspotemail-eu1.net/hs/preferences-center/pt/direct?data=W2nVjwf3Y2x08W2qQ13s
unknown
https://www.edenred.pt/wp-content/uploads/2024/01/cinco-estrelas-1.jpg
107.162.184.232
https://hs-27003262.f.hubspotemail-eu1.net/hub/27003262/hubfs/Group%201.jpg?upscale=true&width=1200&upscale=true&name=Group%201.jpg
172.65.249.76
https://appgallery.huawei.com/app/C101543449?utm_campaign=Users%20-%20Digest&utm_medium=email&am
unknown
https://hs-27003262.f.hubspotemail-eu1.net/hub/27003262/hubfs/Group%201%20(1).jpg?upscale=true&w
unknown
https://www.edenred.pt/wp-content/uploads/2024/01/facebook-1.jpg
107.162.184.232
https://www.myedenred.pt/?utm_campaign=Users%20-%20Digest&utm_medium=email&_hsmi=2&utm_c
unknown
There are 25 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
63e60b3a034d44d3a1fab576330c600e.pacloudflare.com
172.65.220.77
61f25580d9864b27b5f1ee2d435ed67e.pacloudflare.com
172.65.249.76
27003262.fs1.hubspotusercontent-eu1.net
141.101.90.96
edenred.pt
107.162.184.232
27003262.hs-sites-eu1.com
141.101.90.96
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.185.68
www.edenred.pt
107.162.184.232
fp2e7a.wpc.phicdn.net
192.229.221.95
s-part-0032.t-0009.t-msedge.net
13.107.246.60
hs-27003262.f.hubspotemail-eu1.net
unknown
d39vnq04.eu1.hubspotlinks.com
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.68
www.google.com
United States
141.101.90.96
27003262.fs1.hubspotusercontent-eu1.net
European Union
192.168.2.7
unknown
unknown
107.162.184.232
edenred.pt
United States
192.168.2.4
unknown
unknown
172.65.249.76
61f25580d9864b27b5f1ee2d435ed67e.pacloudflare.com
United States
239.255.255.250
unknown
Reserved
172.65.220.77
63e60b3a034d44d3a1fab576330c600e.pacloudflare.com
United States

DOM / HTML

URL
Malicious
https://27003262.hs-sites-eu1.com/informa%C3%A7%C3%A3o-sobre-atualiza%C3%A7%C3%A3o-no-portal-cliente-%E2%9A%A0%EF%B8%8F?ecid=AOKeC1bLyOZj9_NJ4Kz9NKQS_ZaLkkDFNsgv1PuIqJ2wvGPCRJcNHKTMYPPESNZczf1BXTvt362c&utm_campaign=MFA%20Portal%20Cliente&utm_medium=email&_hsenc=p2ANqtz-_-ecLxVA95QqG3Kf-445-LvJkk8gTUl0XmFE1t6JgWJyc7LJGJn4eY9pPFtczdWkrGuTv-TqFvz4C-JdtYOIjm1QEgQg&_hsmi=96739534&utm_content=96739534&utm_source=hs_email
https://27003262.hs-sites-eu1.com/informa%C3%A7%C3%A3o-sobre-atualiza%C3%A7%C3%A3o-no-portal-cliente-%E2%9A%A0%EF%B8%8F?ecid=AOKeC1bLyOZj9_NJ4Kz9NKQS_ZaLkkDFNsgv1PuIqJ2wvGPCRJcNHKTMYPPESNZczf1BXTvt362c&utm_campaign=MFA%20Portal%20Cliente&utm_medium=email&_hsenc=p2ANqtz-_-ecLxVA95QqG3Kf-445-LvJkk8gTUl0XmFE1t6JgWJyc7LJGJn4eY9pPFtczdWkrGuTv-TqFvz4C-JdtYOIjm1QEgQg&_hsmi=96739534&utm_content=96739534&utm_source=hs_email