IOC Report
http://url2231.premiumid.nl/ls/click?upn=u001.6lm5lIwo2cRdSMMBnA0WfNFxGd9WK9xXN7cHxg-2FZL0Uqq96G10BNxAInXJXoyhC1nyP6942iVHlvk7lJFmLwXVMno49sd8W4EUXsOLrZvj-2BnczNfuAceBF0Lv9HJcMwhN6Sb_lgCmrA1vraV40GdNbRPgZWxHnGIge2sS2dg4uihnnV8keUHxPlFqh4soFj360ICb3F1xhpXMZY36U5e5SIldpLrSZ8PQx0SoFXrt2-2FE-2FWKuylt4Ta

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:46:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:46:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:46:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:46:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:46:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (2844)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 153
data
dropped
Chrome Cache Entry: 154
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 155
ASCII text, with very long lines (1096)
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (519)
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (507)
downloaded
Chrome Cache Entry: 159
JSON data
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (1003)
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (519)
downloaded
Chrome Cache Entry: 165
JSON data
downloaded
Chrome Cache Entry: 166
JSON data
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (507)
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (496), with no line terminators
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 170
JSON data
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (552)
dropped
Chrome Cache Entry: 172
ASCII text, with very long lines (45825)
dropped
Chrome Cache Entry: 173
JSON data
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (552)
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (496), with no line terminators
downloaded
Chrome Cache Entry: 176
HTML document, ASCII text, with very long lines (16160)
downloaded
Chrome Cache Entry: 177
Web Open Font Format, TrueType, length 45080, version 1.0
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (1096)
dropped
Chrome Cache Entry: 179
JSON data
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (45825)
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (1003)
dropped
Chrome Cache Entry: 182
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (65536), with no line terminators
dropped
There are 31 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2112 --field-trial-handle=2080,i,13924556699428189275,1106514958240379105,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://url2231.premiumid.nl/ls/click?upn=u001.6lm5lIwo2cRdSMMBnA0WfNFxGd9WK9xXN7cHxg-2FZL0Uqq96G10BNxAInXJXoyhC1nyP6942iVHlvk7lJFmLwXVMno49sd8W4EUXsOLrZvj-2BnczNfuAceBF0Lv9HJcMwhN6Sb_lgCmrA1vraV40GdNbRPgZWxHnGIge2sS2dg4uihnnV8keUHxPlFqh4soFj360ICb3F1xhpXMZY36U5e5SIldpLrSZ8PQx0SoFXrt2-2FE-2FWKuylt4TaCsRAKi24JUAj-2BgP163wbHouD-2BU0PHwt8fJom0nmvjqtzNi7ZB8u1V2saM3AB9ivsmdB-2B9a730COwA8QQ0m-2FrL6fgVs8SC4NzU-2FN0Q-3D-3D"

URLs

Name
IP
Malicious
http://url2231.premiumid.nl/ls/click?upn=u001.6lm5lIwo2cRdSMMBnA0WfNFxGd9WK9xXN7cHxg-2FZL0Uqq96G10BNxAInXJXoyhC1nyP6942iVHlvk7lJFmLwXVMno49sd8W4EUXsOLrZvj-2BnczNfuAceBF0Lv9HJcMwhN6Sb_lgCmrA1vraV40GdNbRPgZWxHnGIge2sS2dg4uihnnV8keUHxPlFqh4soFj360ICb3F1xhpXMZY36U5e5SIldpLrSZ8PQx0SoFXrt2-2FE-2FWKuylt4TaCsRAKi24JUAj-2BgP163wbHouD-2BU0PHwt8fJom0nmvjqtzNi7ZB8u1V2saM3AB9ivsmdB-2B9a730COwA8QQ0m-2FrL6fgVs8SC4NzU-2FN0Q-3D-3D
https://www.fedex.com/gdl/gdl-fedex.js
unknown
https://wwwtest.fedex.com/en-us/logistics.html
unknown
https://www.fedex.com/apps/shipadmin/
unknown
http://jquery.org/license
unknown
https://api.fedex.com
unknown
https://www.office.fedex.com/default/track
unknown
https://wwwdrt.idev.fedex.com/simplifiedhf/css/common-core_SHF.css
unknown
https://www.office.fedex.com/
unknown
https://www.fedex.com/secure-login/en-us/
unknown
http://jqueryui.com
unknown
https://wwwtest.fedex.com/en-us/billing-online.html
unknown
https://col.eum-appdynamics.com
unknown
https://www.fedex.com/en-us/shipping/packing.html
unknown
https://github.com/jquery/jquery-color
unknown
https://www.fedex.com/lite/lite-ship.html#address
unknown
https://newsroom.fedex.com/
unknown
https://wwwtest.fedex.com/en-us/home.html
unknown
https://www.fedex.com/?location=home
unknown
https://www.fedex.com/en-us/service-guide.html
unknown
https://wwwtest.fedex.com/en-us/shipping/drop-off-package.html
unknown
https://p11.techlab-cdn.com
unknown
https://wtrk-wiremock-release.app.cledev1-az3.paas.fedex.com
unknown
https://wwwtest.fedex.com/en-us/customer-support/contact-us.html
unknown
https://www.fedex.com/en-us/tracking.html
unknown
https://www.fedex.com/es-us/home.html
unknown
https://www.fedex.com/preferences/
unknown
https://wwwdrt.idev.fedex.com/simplifiedhf/js/script.js
unknown
https://www.fedex.com/content/dam/fedex-com/ens/DetailedTracking.jpg
unknown
https://wwwtest.fedex.com/en-us/trust-center.html
unknown
https://developer.fedex.com/api/en-us/home.html
unknown
https://www.fedex.com/ecap/report
unknown
https://wwwtest.fedex.com/en-us/blog.html
unknown
https://wwwtest.fedex.com/en-us/shipping/freight.html
unknown
https://www.fedex.com/swab/AddressMain.do?locale=en_US
unknown
https://c2p.clearance.fedex.com
unknown
https://npms.io/search?q
unknown
https://wwwtest.fedex.com/en-us/about/company-structure.html
unknown
https://openjsf.org/
unknown
https://www.fedex.com/etc/clientlibs/fedex/commoncore-min.css
unknown
https://wwwtest.fedex.com/en-us/shoprunner.html
unknown
https://wwwtest.fedex.com/en-us/cross-border.html
unknown
https://www.fedex.com/en-us/create-account/account-management.html
unknown
https://www.fedex.com/etc.clientlibs/fedex-core/clientlibs/clientlib-dependencies.min.b8f3ab9da52fa7
unknown
https://www.fedex.com/wtrk/track/?action=track&tracknumbers=779620999700
http://col.eum-appdynamics.com
unknown
https://wwwtest.fedex.com/en-us/terms-of-use.html
unknown
https://wwwtest.fedex.com/en-us/online/rating.html
unknown
https://wwwtest.fedex.com/en-us/printing/online-printing.html
unknown
https://lodash.com/
unknown
https://www.fedex.com/fdmenrollment/
unknown
https://investors.fedex.com/home/default.aspx
unknown
https://www.fedex.com/en-us/shipping.html
unknown
https://local.fedex.com/en-us
unknown
http://api.jqueryui.com/position/
unknown
https://www.fedex.com/en-us/customer-support/faqs.html
unknown
https://wwwtest.fedex.com/en-us/small-business.html
unknown
https://getbootstrap.com/)
unknown
https://www.fedex.com/assets/2d9e99e972ae5cd0a0e5f981ba0cc5db9001192124f
unknown
https://wwwtest.fedex.com/en-us/sitemap.html
unknown
http://underscorejs.org/LICENSE
unknown
https://wwwtest.fedex.com/en-us/about/corporate-social-responsibility.html
unknown
https://www.fedex.com/en-us/customer-support.html
unknown
https://careers.fedex.com/fedex/
unknown
https://www.fedex.com
unknown
https://cdn.optimizely.com/datafiles/REekk8dXzrWqMgJkWkpDJ.json
104.18.65.57
https://www.fedex.com/profile-overview
unknown
https://www.fedex.com/en-us/open-account.html
unknown
https://www.fedex.com/fedexbillingonline/pages/accountsummary/accountSummaryFBO.xhtml
unknown
https://wwwtest.fedex.com/en-us/compatible.html
unknown
https://wwwtest.fedex.com/es-us/home.html
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://lodash.com/license
unknown
https://wwwtest.fedex.com/en-us/office/services.html
unknown
https://www.fedex.com/en-us/shipping/schedule-manage-pickups.html
unknown
https://github.com/h5bp/html5-boilerplate/blob/master/src/css/main.css
unknown
https://www.fedex.com/en-us/shipping/international.html
unknown
https://www.fedex.com/en-us/shipping/returns.html
unknown
https://www.fedex.com/en-us/customer-support/claims.html
unknown
https://www.fedex.com/fedextracking/
unknown
https://api.ecom.fedex.com
unknown
https://cdn.optimizely.com/js/21023511730.js
unknown
There are 71 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
cdn.optimizely.com
104.18.65.57
sendgrid.net
167.89.118.109
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
172.217.16.196
fp2e7a.wpc.phicdn.net
192.229.221.95
p11.techlab-cdn.com
unknown
url2231.premiumid.nl
unknown
api.fedex.com
unknown
www.fedex.com
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
167.89.118.109
sendgrid.net
United States
172.217.16.196
www.google.com
United States
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
https://www.fedex.com/wtrk/track/?action=track&tracknumbers=779620999700
https://www.fedex.com/wtrk/track/?action=track&tracknumbers=779620999700