IOC Report
https://links.iterable.com/u/click?_t=97542eafdd6a4caeb09c402c826b341c&_m=b1a641c0d491444ea7edaeec7d6ded7b&_e=h3_oYYlxigb0pnJBJO8zIFe13_t-1KmNMrYo6cOsmyt98yEpp__SLnEoda6hv-3kMLrDc_hn0ZJibdOzTEecmv9R9BQ8ipyew9dOozaIAKp3-MoJ2SbzKjOI_5IYLlTwyFUT0dfUCLrxD_WmZcN9LOBSog-Zqr3vMiTJ5NvpEw6NhDE7dyVPxE9pJAPJkh

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 04:20:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 04:20:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 04:20:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 04:20:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Nov 25 04:20:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 106
ASCII text, with very long lines (16787), with no line terminators
dropped
Chrome Cache Entry: 107
PNG image data, 300 x 287, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 109
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 110
Unicode text, UTF-8 text, with very long lines (46555), with CRLF line terminators
dropped
Chrome Cache Entry: 111
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
dropped
Chrome Cache Entry: 112
ASCII text, with very long lines (25304), with no line terminators
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (9817), with no line terminators
downloaded
Chrome Cache Entry: 114
ASCII text, with very long lines (19948), with no line terminators
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (34462), with no line terminators
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (33193), with no line terminators
downloaded
Chrome Cache Entry: 117
Unicode text, UTF-8 text, with very long lines (44001), with no line terminators
dropped
Chrome Cache Entry: 118
ASCII text, with very long lines (27319), with no line terminators
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (8132), with no line terminators
dropped
Chrome Cache Entry: 120
PNG image data, 256 x 256, 4-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 121
ASCII text, with very long lines (11904), with no line terminators
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (42738), with no line terminators
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (53924), with no line terminators
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (12210), with no line terminators
dropped
Chrome Cache Entry: 125
ASCII text, with very long lines (6166), with no line terminators
downloaded
Chrome Cache Entry: 126
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 127
PNG image data, 256 x 256, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (14452), with no line terminators
downloaded
Chrome Cache Entry: 129
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (12210), with no line terminators
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 132
Web Open Font Format (Version 2), TrueType, length 39188, version 1.0
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (53478), with no line terminators
dropped
Chrome Cache Entry: 134
ASCII text, with very long lines (14171), with no line terminators
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (14171), with no line terminators
downloaded
Chrome Cache Entry: 136
PNG image data, 1800 x 402, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (16746), with no line terminators
downloaded
Chrome Cache Entry: 139
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 140
PNG image data, 300 x 287, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (32694), with no line terminators
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (6166), with no line terminators
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (16787), with no line terminators
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (32694), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (9817), with no line terminators
dropped
Chrome Cache Entry: 147
ASCII text, with very long lines (8129), with no line terminators
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (14452), with no line terminators
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (27575), with no line terminators
dropped
Chrome Cache Entry: 150
Unicode text, UTF-8 text, with very long lines (44001), with no line terminators
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (27575), with no line terminators
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (19948), with no line terminators
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (473), with no line terminators
downloaded
Chrome Cache Entry: 154
Unicode text, UTF-8 text, with very long lines (46555), with CRLF line terminators
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (4955), with no line terminators
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (25304), with no line terminators
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (42738), with no line terminators
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (4955), with no line terminators
downloaded
Chrome Cache Entry: 159
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 160
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
downloaded
Chrome Cache Entry: 161
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (45421), with no line terminators
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (53478), with no line terminators
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (473), with no line terminators
dropped
There are 56 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2192 --field-trial-handle=1968,i,17615178085349927159,12926727792294290791,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://links.iterable.com/u/click?_t=97542eafdd6a4caeb09c402c826b341c&_m=b1a641c0d491444ea7edaeec7d6ded7b&_e=h3_oYYlxigb0pnJBJO8zIFe13_t-1KmNMrYo6cOsmyt98yEpp__SLnEoda6hv-3kMLrDc_hn0ZJibdOzTEecmv9R9BQ8ipyew9dOozaIAKp3-MoJ2SbzKjOI_5IYLlTwyFUT0dfUCLrxD_WmZcN9LOBSog-Zqr3vMiTJ5NvpEw6NhDE7dyVPxE9pJAPJkhBg0MGQAhMOwwXk7fqRPavsfYmP7IZY6G9W6SEb-uW9DRl4v6-vQHKvXIf_WnhzJFtXm7VO8EmkYzlPg_eJe-0mo80zMKamRjreeRnxqZdMSqJUKMj-SNsrznaruikkbUI61oHtMdwf9PfZwroYT88h764aWeTjm5y_XQ4wNevjp1mns3U1qo-qS0BloPGlGOgHEEkp58u_BJRzR4RC4vsM_EhhtwCSEYSlLPFZ9KuryfV6BtV5qdOTrnoRjZHXDEFn"

URLs

Name
IP
Malicious
https://links.iterable.com/u/click?_t=97542eafdd6a4caeb09c402c826b341c&_m=b1a641c0d491444ea7edaeec7d6ded7b&_e=h3_oYYlxigb0pnJBJO8zIFe13_t-1KmNMrYo6cOsmyt98yEpp__SLnEoda6hv-3kMLrDc_hn0ZJibdOzTEecmv9R9BQ8ipyew9dOozaIAKp3-MoJ2SbzKjOI_5IYLlTwyFUT0dfUCLrxD_WmZcN9LOBSog-Zqr3vMiTJ5NvpEw6NhDE7dyVPxE9pJAPJkhBg0MGQAhMOwwXk7fqRPavsfYmP7IZY6G9W6SEb-uW9DRl4v6-vQHKvXIf_WnhzJFtXm7VO8EmkYzlPg_eJe-0mo80zMKamRjreeRnxqZdMSqJUKMj-SNsrznaruikkbUI61oHtMdwf9PfZwroYT88h764aWeTjm5y_XQ4wNevjp1mns3U1qo-qS0BloPGlGOgHEEkp58u_BJRzR4RC4vsM_EhhtwCSEYSlLPFZ9KuryfV6BtV5qdOTrnoRjZHXDEFn
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/css/85e5a8b7db92b467.css
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/3586-10f735d23dc9c634.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/9187-e5bb607c80c36208.js
172.64.148.160
https://www.moneylion.com/favicon.ico
172.64.148.160
https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015
104.16.80.73
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/798-7a6df174a89c50af.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/2533-0ccff9eb6f1c86fb.js
172.64.148.160
https://www.moneylion.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/css/0a5cc0bc0bf48df9.css
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/media/21ed5661b47f7f6d-s.p.woff2
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/css/5435e5dd9dc3b4ce.css
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/6808-2a64741725d3d985.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/3904-d98ded95c9b11e1f.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/5995-d79172561e06fea8.js
172.64.148.160
https://s3.amazonaws.com/images.evenfinancial.com/logos/dev/netcredit_-_pl-378-ww2kk3a2.svg
3.5.31.199
https://www.datadoghq-browser-agent.com/us1/v5/datadog-rum.js
18.165.221.183
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/6243-3fcbebf18cfa692e.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/css/2c4a9640ddeec33a.css
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/css/a07c9cc4d69e42b4.css
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/7909-23a77fa16bf184cd.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/main-app-8fd4865b46eb13d1.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/3510-39ad3f9972859ae6.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/4383-ebcec45ede2bf3cd.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/310-7a9da186b0c754df.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/css/4549453db995bf41.css
172.64.148.160
https://www.moneylion.com/cnf/thumbor/unsafe/images/logo.svg
172.64.148.160
https://www.moneylion.com/network/moneylion/loans/compare/2ff3a0ae-4bd5-498f-a1b1-42bb68eb09cb?tag.source=email&tag.messageId=b1a641c0d491444ea7edaeec7d6ded7b&tag.campaignId=11208423&step=results
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/css/90f4e7e6f1097be7.css
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/7698-9c9fb953921126e9.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/app/layout-a8c775d16f521023.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/webpack-3645308954dce40f.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/8099-d40d59232803a82e.js
172.64.148.160
https://links.iterable.com/u/click?_t=97542eafdd6a4caeb09c402c826b341c&_m=b1a641c0d491444ea7edaeec7d6ded7b&_e=h3_oYYlxigb0pnJBJO8zIFe13_t-1KmNMrYo6cOsmyt98yEpp__SLnEoda6hv-3kMLrDc_hn0ZJibdOzTEecmv9R9BQ8ipyew9dOozaIAKp3-MoJ2SbzKjOI_5IYLlTwyFUT0dfUCLrxD_WmZcN9LOBSog-Zqr3vMiTJ5NvpEw6NhDE7dyVPxE9pJAPJkhBg0MGQAhMOwwXk7fqRPavsfYmP7IZY6G9W6SEb-uW9DRl4v6-vQHKvXIf_WnhzJFtXm7VO8EmkYzlPg_eJe-0mo80zMKamRjreeRnxqZdMSqJUKMj-SNsrznaruikkbUI61oHtMdwf9PfZwroYT88h764aWeTjm5y_XQ4wNevjp1mns3U1qo-qS0BloPGlGOgHEEkp58u_BJRzR4RC4vsM_EhhtwCSEYSlLPFZ9KuryfV6BtV5qdOTrnoRjZHXDEFn
54.80.215.93
https://www.moneylion.com/cdn-cgi/rum?
172.64.148.160
https://www.moneylion.com/cdn-cgi/challenge-platform/h/g/jsd/r/8e7f3067ca4a43af
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/a331c16e-037a6d5ac84619a3.js
172.64.148.160
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/app/compare/%5Bratetable%5D/@offers/page-01fc21d24dc4f3e4.js
172.64.148.160
https://images.evenfinancial.com/icons/eho-black.png
13.226.2.66
https://www.moneylion.com/_resources/apps/lending/stable/_next/static/chunks/2174-225904cc11941622.js
172.64.148.160
https://www.moneylion.com/cdn-cgi/challenge-platform/h/g/scripts/jsd/e4025c85ea63/main.js?
172.64.148.160
There are 30 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s3.amazonaws.com
3.5.31.199
static.cloudflareinsights.com
104.16.80.73
d3jknm19jeqt5y.cloudfront.net
13.226.2.66
www.datadoghq-browser-agent.com
18.165.221.183
links.iterable.com
54.80.215.93
www.moneylion.com
172.64.148.160
www.google.com
142.250.181.68
images.evenfinancial.com
unknown

IPs

IP
Domain
Country
Malicious
104.18.39.96
unknown
United States
54.80.215.93
links.iterable.com
United States
192.168.2.16
unknown
unknown
13.226.2.66
d3jknm19jeqt5y.cloudfront.net
United States
3.5.31.199
s3.amazonaws.com
United States
104.16.80.73
static.cloudflareinsights.com
United States
172.64.148.160
www.moneylion.com
United States
13.226.2.124
unknown
United States
239.255.255.250
unknown
Reserved
18.165.221.183
www.datadoghq-browser-agent.com
United States
142.250.181.68
www.google.com
United States
54.231.168.168
unknown
United States
104.16.79.73
unknown
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.moneylion.com/network/moneylion/loans/compare/2ff3a0ae-4bd5-498f-a1b1-42bb68eb09cb?tag.source=email&tag.messageId=b1a641c0d491444ea7edaeec7d6ded7b&tag.campaignId=11208423&step=results
https://www.moneylion.com/network/moneylion/loans/compare/2ff3a0ae-4bd5-498f-a1b1-42bb68eb09cb?tag.source=email&tag.messageId=b1a641c0d491444ea7edaeec7d6ded7b&tag.campaignId=11208423&step=results
https://www.moneylion.com/network/moneylion/loans/compare/2ff3a0ae-4bd5-498f-a1b1-42bb68eb09cb?tag.source=email&tag.messageId=b1a641c0d491444ea7edaeec7d6ded7b&tag.campaignId=11208423&step=results
https://www.moneylion.com/network/moneylion/loans/compare/2ff3a0ae-4bd5-498f-a1b1-42bb68eb09cb?tag.source=email&tag.messageId=b1a641c0d491444ea7edaeec7d6ded7b&tag.campaignId=11208423&step=results