IOC Report
https://u47860934.ct.sendgrid.net/asm/unsubscribe/?user_id=47860934&data=hC3xl-lgkM8YTVgFw1ynd63_65kh6CtqvDm5Gr5N1DVoMDAwdTAwMDJZ6OOSZ8e8QC0lhHSqZbVwjcHQ7JLSZKWfF6VqwaHnIGCsSvoju1ICqZtdQit5MzxTwYJzG2nnZuzkyJcDE16cXyQNJO67vUaAQPYeQFSVW0WOIUxVj4MJnaccS9XuPGMHj5eg2qV5QZY_RXQhwe-NHgEP7ix180s91VBoEdDFenz

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 43
Web Open Font Format (Version 2), TrueType, length 20276, version 1.0
downloaded
Chrome Cache Entry: 44
PNG image data, 56 x 56, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 45
ASCII text
downloaded
Chrome Cache Entry: 46
PNG image data, 56 x 56, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 47
ASCII text
downloaded
Chrome Cache Entry: 48
ASCII text
dropped
Chrome Cache Entry: 49
HTML document, ASCII text, with very long lines (1166)
downloaded
Chrome Cache Entry: 50
Web Open Font Format (Version 2), TrueType, length 20388, version 1.0
downloaded
Chrome Cache Entry: 51
HTML document, ASCII text, with very long lines (1172)
downloaded
Chrome Cache Entry: 52
HTML document, ASCII text, with very long lines (1172)
downloaded
Chrome Cache Entry: 53
HTML document, ASCII text, with CRLF line terminators
downloaded
There are 2 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2272 --field-trial-handle=2220,i,4729958559204312130,14849540772647102609,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u47860934.ct.sendgrid.net/asm/unsubscribe/?user_id=47860934&data=hC3xl-lgkM8YTVgFw1ynd63_65kh6CtqvDm5Gr5N1DVoMDAwdTAwMDJZ6OOSZ8e8QC0lhHSqZbVwjcHQ7JLSZKWfF6VqwaHnIGCsSvoju1ICqZtdQit5MzxTwYJzG2nnZuzkyJcDE16cXyQNJO67vUaAQPYeQFSVW0WOIUxVj4MJnaccS9XuPGMHj5eg2qV5QZY_RXQhwe-NHgEP7ix180s91VBoEdDFenzFlaxNpErbvJgQdx4uHjWu-6mqcbi_8-Cmq9UBHPSFF_Xkji4v8QOfyKILSy2xb0F33iCS1ymaLcGTKKZvZUcfZDDn0hn4dPYfTf2JVZrV_KQxkRyWLc-wROFA0j3TQttNHIuMcG1l2b47Ntecq6SULIsbCoMKotgnWtlpkSuliJ_NgdL5cKsRgAC9Otw9fpRk5mNCB2TTU0mXgGaNm7Nin6Rh3YjS6TLxZ83hvaVWX_Hvb4lt7TEjSQzZ64vOJaVvKHmp3VlXI7MJrFzWDCgnw3xW0PM_xywu-XrwSWuPDz0PUSknVMXv3LcvP7VuEWzPAcjXA1zcljvMb7iSOo9gwQkg_5KkMnf4ic2uxOPjPRogSb-Ad6Ft6yK0FHGCle6IaXcIi-6WD4a5lSvbod7JPvvDG9NRw1TB0IrpSFwRhNB0Re5ev5gIOGQ96BW5WDz4Hg7rrI-Znjf0Jh2v4Hu8IG9iaR3q5DjKN9V4eN00U6Stnmgy956D8wkBqRyYAtd80sagI87tC4Y4Fy-6Rf2kInnoiOB9VkSMr9udOQ4nuK1k7oabgsSWrZS56_7Y59VAY_wNrYvmtQNz-j91c3Fk5EgNkefFvV9QG_Cl1qFy3vysVzVrf9dTIgFlttZj9PMxObT0GqfD6YCocIxDaj9h0onLgj-2ns3uV4myb3KQgh8GibeJjfnPpPxIS_rbhmelMbJxCtRdciFTJbvbKMwr3lct9bV2HYMt1nc7izlPWyI_h3l8D5nPglJMb6IU7pxd4NWW3CuMsgAnxRkiNNBrLpChQX4iBmWmSpD1zK3OOBWMm9wyxUVvX05DFTJ-l_VbX17LP50_W9HgB-yL4aC0RaD6JbPJdn0OheLwu0A="

URLs

Name
IP
Malicious
https://u47860934.ct.sendgrid.net/asm/unsubscribe/?user_id=47860934&data=hC3xl-lgkM8YTVgFw1ynd63_65kh6CtqvDm5Gr5N1DVoMDAwdTAwMDJZ6OOSZ8e8QC0lhHSqZbVwjcHQ7JLSZKWfF6VqwaHnIGCsSvoju1ICqZtdQit5MzxTwYJzG2nnZuzkyJcDE16cXyQNJO67vUaAQPYeQFSVW0WOIUxVj4MJnaccS9XuPGMHj5eg2qV5QZY_RXQhwe-NHgEP7ix180s91VBoEdDFenzFlaxNpErbvJgQdx4uHjWu-6mqcbi_8-Cmq9UBHPSFF_Xkji4v8QOfyKILSy2xb0F33iCS1ymaLcGTKKZvZUcfZDDn0hn4dPYfTf2JVZrV_KQxkRyWLc-wROFA0j3TQttNHIuMcG1l2b47Ntecq6SULIsbCoMKotgnWtlpkSuliJ_NgdL5cKsRgAC9Otw9fpRk5mNCB2TTU0mXgGaNm7Nin6Rh3YjS6TLxZ83hvaVWX_Hvb4lt7TEjSQzZ64vOJaVvKHmp3VlXI7MJrFzWDCgnw3xW0PM_xywu-XrwSWuPDz0PUSknVMXv3LcvP7VuEWzPAcjXA1zcljvMb7iSOo9gwQkg_5KkMnf4ic2uxOPjPRogSb-Ad6Ft6yK0FHGCle6IaXcIi-6WD4a5lSvbod7JPvvDG9NRw1TB0IrpSFwRhNB0Re5ev5gIOGQ96BW5WDz4Hg7rrI-Znjf0Jh2v4Hu8IG9iaR3q5DjKN9V4eN00U6Stnmgy956D8wkBqRyYAtd80sagI87tC4Y4Fy-6Rf2kInnoiOB9VkSMr9udOQ4nuK1k7oabgsSWrZS56_7Y59VAY_wNrYvmtQNz-j91c3Fk5EgNkefFvV9QG_Cl1qFy3vysVzVrf9dTIgFlttZj9PMxObT0GqfD6YCocIxDaj9h0onLgj-2ns3uV4myb3KQgh8GibeJjfnPpPxIS_rbhmelMbJxCtRdciFTJbvbKMwr3lct9bV2HYMt1nc7izlPWyI_h3l8D5nPglJMb6IU7pxd4NWW3CuMsgAnxRkiNNBrLpChQX4iBmWmSpD1zK3OOBWMm9wyxUVvX05DFTJ-l_VbX17LP50_W9HgB-yL4aC0RaD6JbPJdn0OheLwu0A=
https://u47860934.ct.sendgrid.net/asm/unsubscribe/?user_id=47860934&data=hC3xl-lgkM8YTVgFw1ynd63_65kh6CtqvDm5Gr5N1DVoMDAwdTAwMDJZ6OOSZ8e8QC0lhHSqZbVwjcHQ7JLSZKWfF6VqwaHnIGCsSvoju1ICqZtdQit5MzxTwYJzG2nnZuzkyJcDE16cXyQNJO67vUaAQPYeQFSVW0WOIUxVj4MJnaccS9XuPGMHj5eg2qV5QZY_RXQhwe-NHgEP7ix180s91VBoEdDFenzFlaxNpErbvJgQdx4uHjWu-6mqcbi_8-Cmq9UBHPSFF_Xkji4v8QOfyKILSy2xb0F33iCS1ymaLcGTKKZvZUcfZDDn0hn4dPYfTf2JVZrV_KQxkRyWLc-wROFA0j3TQttNHIuMcG1l2b47Ntecq6SULIsbCoMKotgnWtlpkSuliJ_NgdL5cKsRgAC9Otw9fpRk5mNCB2TTU0mXgGaNm7Nin6Rh3YjS6TLxZ83hvaVWX_Hvb4lt7TEjSQzZ64vOJaVvKHmp3VlXI7MJrFzWDCgnw3xW0PM_xywu-XrwSWuPDz0PUSknVMXv3LcvP7VuEWzPAcjXA1zcljvMb7iSOo9gwQkg_5KkMnf4ic2uxOPjPRogSb-Ad6Ft6yK0FHGCle6IaXcIi-6WD4a5lSvbod7JPvvDG9NRw1TB0IrpSFwRhNB0Re5ev5gIOGQ96BW5WDz4Hg7rrI-Znjf0Jh2v4Hu8IG9iaR3q5DjKN9V4eN00U6Stnmgy956D8wkBqRyYAtd80sagI87tC4Y4Fy-6Rf2kInnoiOB9VkSMr9udOQ4nuK1k7oabgsSWrZS56_7Y59VAY_wNrYvmtQNz-j91c3Fk5EgNkefFvV9QG_Cl1qFy3vysVzVrf9dTIgFlttZj9PMxObT0GqfD6YCocIxDaj9h0onLgj-2ns3uV4myb3KQgh8GibeJjfnPpPxIS_rbhmelMbJxCtRdciFTJbvbKMwr3lct9bV2HYMt1nc7izlPWyI_h3l8D5nPglJMb6IU7pxd4NWW3CuMsgAnxRkiNNBrLpChQX4iBmWmSpD1zK3OOBWMm9wyxUVvX05DFTJ-l_VbX17LP50_W9HgB-yL4aC0RaD6JbPJdn0OheLwu0A=
https://u47860934.ct.sendgrid.net/asm/assets/images/success.png
167.89.115.147
https://u47860934.ct.sendgrid.net/asm/assets/stylesheets/app.css
167.89.115.147
https://u47860934.ct.sendgrid.net/asm/assets/fonts/colfax-regular.woff2
167.89.115.147
https://u47860934.ct.sendgrid.net/asm/?user_id=47860934&data=hC3xl-lgkM8YTVgFw1ynd63_65kh6CtqvDm5Gr5N1DVoMDAwdTAwMDJZ6OOSZ8e8QC0lhHSqZbVwjcHQ7JLSZKWfF6VqwaHnIGCsSvoju1ICqZtdQit5MzxTwYJzG2nnZuzkyJcDE16cXyQNJO67vUaAQPYeQFSVW0WOIUxVj4MJnaccS9XuPGMHj5eg2qV5QZY_RXQhwe-NHgEP7ix180s91VBoEdDFenzFlaxNpErbvJgQdx4uHjWu-6mqcbi_8-Cmq9UBHPSFF_Xkji4v8QOfyKILSy2xb0F33iCS1ymaLcGTKKZvZUcfZDDn0hn4dPYfTf2JVZrV_KQxkRyWLc-wROFA0j3TQttNHIuMcG1l2b47Ntecq6SULIsbCoMKotgnWtlpkSuliJ_NgdL5cKsRgAC9Otw9fpRk5mNCB2TTU0mXgGaNm7Nin6Rh3YjS6TLxZ83hvaVWX_Hvb4lt7TEjSQzZ64vOJaVvKHmp3VlXI7MJrFzWDCgnw3xW0PM_xywu-XrwSWuPDz0PUSknVMXv3LcvP7VuEWzPAcjXA1zcljvMb7iSOo9gwQkg_5KkMnf4ic2uxOPjPRogSb-Ad6Ft6yK0FHGCle6IaXcIi-6WD4a5lSvbod7JPvvDG9NRw1TB0IrpSFwRhNB0Re5ev5gIOGQ96BW5WDz4Hg7rrI-Znjf0Jh2v4Hu8IG9iaR3q5DjKN9V4eN00U6Stnmgy956D8wkBqRyYAtd80sagI87tC4Y4Fy-6Rf2kInnoiOB9VkSMr9udOQ4nuK1k7oabgsSWrZS56_7Y59VAY_wNrYvmtQNz-j91c3Fk5EgNkefFvV9QG_Cl1qFy3vysVzVrf9dTIgFlttZj9PMxObT0GqfD6YCocIxDaj9h0onLgj-2ns3uV4myb3KQgh8GibeJjfnPpPxIS_rbhmelMbJxCtRdciFTJbvbKMwr3lct9bV2HYMt1nc7izlPWyI_h3l8D5nPglJMb6IU7pxd4NWW3CuMsgAnxRkiNNBrLpChQX4iBmWmSpD1zK3OOBWMm9wyxUVvX05DFTJ-l_VbX17LP50_W9HgB-yL4aC0RaD6JbPJdn0OheLwu0A=
https://u47860934.ct.sendgrid.net/asm/assets/fonts/colfax-medium.woff2
167.89.115.147
https://u47860934.ct.sendgrid.net/asm/assets/javascripts/app.js
167.89.115.147
https://u47860934.ct.sendgrid.net/favicon.ico
167.89.115.147

Domains

Name
IP
Malicious
s-part-0036.t-0009.fb-t-msedge.net
13.107.253.64
u47860934.ct.sendgrid.net
167.89.115.147
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.184.196
fp2e7a.wpc.phicdn.net
192.229.221.95

IPs

IP
Domain
Country
Malicious
142.250.184.196
www.google.com
United States
239.255.255.250
unknown
Reserved
192.168.2.13
unknown
unknown
167.89.115.147
u47860934.ct.sendgrid.net
United States
167.89.115.58
unknown
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://u47860934.ct.sendgrid.net/asm/unsubscribe/?user_id=47860934&data=hC3xl-lgkM8YTVgFw1ynd63_65kh6CtqvDm5Gr5N1DVoMDAwdTAwMDJZ6OOSZ8e8QC0lhHSqZbVwjcHQ7JLSZKWfF6VqwaHnIGCsSvoju1ICqZtdQit5MzxTwYJzG2nnZuzkyJcDE16cXyQNJO67vUaAQPYeQFSVW0WOIUxVj4MJnaccS9XuPGMHj5eg2qV5QZY_RXQhwe-NHgEP7ix180s91VBoEdDFenzFlaxNpErbvJgQdx4uHjWu-6mqcbi_8-Cmq9UBHPSFF_Xkji4v8QOfyKILSy2xb0F33iCS1ymaLcGTKKZvZUcfZDDn0hn4dPYfTf2JVZrV_KQxkRyWLc-wROFA0j3TQttNHIuMcG1l2b47Ntecq6SULIsbCoMKotgnWtlpkSuliJ_NgdL5cKsRgAC9Otw9fpRk5mNCB2TTU0mXgGaNm7Nin6Rh3YjS6TLxZ83hvaVWX_Hvb4lt7TEjSQzZ64vOJaVvKHmp3VlXI7MJrFzWDCgnw3xW0PM_xywu-XrwSWuPDz0PUSknVMXv3LcvP7VuEWzPAcjXA1zcljvMb7iSOo9gwQkg_5KkMnf4ic2uxOPjPRogSb-Ad6Ft6yK0FHGCle6IaXcIi-6WD4a5lSvbod7JPvvDG9NRw1TB0IrpSFwRhNB0Re5ev5gIOGQ96BW5WDz4Hg7rrI-Znjf0Jh2v4Hu8IG9iaR3q5DjKN9V4eN00U6Stnmgy956D8wkBqRyYAtd80sagI87tC4Y4Fy-6Rf2kInnoiOB9VkSMr9udOQ4nuK1k7oabgsSWrZS56_7Y59VAY_wNrYvmtQNz-j91c3Fk5EgNkefFvV9QG_Cl1qFy3vysVzVrf9dTIgFlttZj9PMxObT0GqfD6YCocIxDaj9h0onLgj-2ns3uV4myb3KQgh8GibeJjfnPpPxIS_rbhmelMbJxCtRdciFTJbvbKMw
https://u47860934.ct.sendgrid.net/asm/?user_id=47860934&data=hC3xl-lgkM8YTVgFw1ynd63_65kh6CtqvDm5Gr5N1DVoMDAwdTAwMDJZ6OOSZ8e8QC0lhHSqZbVwjcHQ7JLSZKWfF6VqwaHnIGCsSvoju1ICqZtdQit5MzxTwYJzG2nnZuzkyJcDE16cXyQNJO67vUaAQPYeQFSVW0WOIUxVj4MJnaccS9XuPGMHj5eg2qV5QZY_RXQhwe-NHgEP7ix180s91VBoEdDFenzFlaxNpErbvJgQdx4uHjWu-6mqcbi_8-Cmq9UBHPSFF_Xkji4v8QOfyKILSy2xb0F33iCS1ymaLcGTKKZvZUcfZDDn0hn4dPYfTf2JVZrV_KQxkRyWLc-wROFA0j3TQttNHIuMcG1l2b47Ntecq6SULIsbCoMKotgnWtlpkSuliJ_NgdL5cKsRgAC9Otw9fpRk5mNCB2TTU0mXgGaNm7Nin6Rh3YjS6TLxZ83hvaVWX_Hvb4lt7TEjSQzZ64vOJaVvKHmp3VlXI7MJrFzWDCgnw3xW0PM_xywu-XrwSWuPDz0PUSknVMXv3LcvP7VuEWzPAcjXA1zcljvMb7iSOo9gwQkg_5KkMnf4ic2uxOPjPRogSb-Ad6Ft6yK0FHGCle6IaXcIi-6WD4a5lSvbod7JPvvDG9NRw1TB0IrpSFwRhNB0Re5ev5gIOGQ96BW5WDz4Hg7rrI-Znjf0Jh2v4Hu8IG9iaR3q5DjKN9V4eN00U6Stnmgy956D8wkBqRyYAtd80sagI87tC4Y4Fy-6Rf2kInnoiOB9VkSMr9udOQ4nuK1k7oabgsSWrZS56_7Y59VAY_wNrYvmtQNz-j91c3Fk5EgNkefFvV9QG_Cl1qFy3vysVzVrf9dTIgFlttZj9PMxObT0GqfD6YCocIxDaj9h0onLgj-2ns3uV4myb3KQgh8GibeJjfnPpPxIS_rbhmelMbJxCtRdciFTJbvbKMwr3lct9bV2HYM