IOC Report
https://u13762205.ct.sendgrid.net/ls/click?upn=u001.2N-2FFSd8Mh5tdTcK2pEXUToH0F5-2Fq3FDo8pnKFzcXMK24EOVQRPQXOzov3WP6TeQDbpOFMAzOhzk6g52qaRBXMg-3D-3DIjNL_PKcFXsnzduNOkTk1M1BuFSXBwpDtJ5JnfBBGS8mWfSDpSIzzZrzaRAqzsWn9I2SACyGbOCQAHofmU9ue-2Bfpl8m5UVDAXfATbU3zHgCM2w6TpOzhFbmwlUQoZzHTxRoJD6sBCzgzJz3SY7rmsp

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 48
ASCII text, with very long lines (54522), with CRLF line terminators
downloaded
Chrome Cache Entry: 49
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 50
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 51
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 52
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 53
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 54
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 55
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 56
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 57
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 58
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 59
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 60
ISO Media, AVIF Image
dropped
Chrome Cache Entry: 61
Unicode text, UTF-8 text, with very long lines (503), with CRLF line terminators
downloaded
Chrome Cache Entry: 62
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 63
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 64
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 65
ASCII text, with very long lines (65324)
downloaded
Chrome Cache Entry: 66
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 67
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 68
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 69
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 70
Web Open Font Format, TrueType, length 37153, version 1.0
downloaded
Chrome Cache Entry: 71
SVG Scalable Vector Graphics image
downloaded
There are 15 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=2020,i,4555037124408769600,15649146501260227091,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u13762205.ct.sendgrid.net/ls/click?upn=u001.2N-2FFSd8Mh5tdTcK2pEXUToH0F5-2Fq3FDo8pnKFzcXMK24EOVQRPQXOzov3WP6TeQDbpOFMAzOhzk6g52qaRBXMg-3D-3DIjNL_PKcFXsnzduNOkTk1M1BuFSXBwpDtJ5JnfBBGS8mWfSDpSIzzZrzaRAqzsWn9I2SACyGbOCQAHofmU9ue-2Bfpl8m5UVDAXfATbU3zHgCM2w6TpOzhFbmwlUQoZzHTxRoJD6sBCzgzJz3SY7rmsp-2BquYHmL2DTOkQggmMFIfKhNPVaBf8NTmimDBPZdcr9YqjF8L6hryY10MBbjsSOUH778gw-3D-3D"

URLs

Name
IP
Malicious
https://u13762205.ct.sendgrid.net/ls/click?upn=u001.2N-2FFSd8Mh5tdTcK2pEXUToH0F5-2Fq3FDo8pnKFzcXMK24EOVQRPQXOzov3WP6TeQDbpOFMAzOhzk6g52qaRBXMg-3D-3DIjNL_PKcFXsnzduNOkTk1M1BuFSXBwpDtJ5JnfBBGS8mWfSDpSIzzZrzaRAqzsWn9I2SACyGbOCQAHofmU9ue-2Bfpl8m5UVDAXfATbU3zHgCM2w6TpOzhFbmwlUQoZzHTxRoJD6sBCzgzJz3SY7rmsp-2BquYHmL2DTOkQggmMFIfKhNPVaBf8NTmimDBPZdcr9YqjF8L6hryY10MBbjsSOUH778gw-3D-3D
malicious
https://mcenter.backend.aait-d.com/en-us/account/login?ZQLQepa=ipodSpLTkjoDqryYHxxMzUZGLdzjmlaIhmdLcDgMgwHKsFxnPTjtYEMoFznsXCWByXr=JLrzvKBm
malicious
https://mcenter.backend.aait-d.com/en-us/account/0304e3a9e1210479aa08ce476cea2af4/images/favicon/c69dc020e79407a9e02681a7b7e24f15.ico
65.108.205.228
https://mcenter.backend.aait-d.com/en-us/account/6b7938ca6d400e3974df82f198b41041/images/dls-logo-stack/62c3317b20fe962104ceefb835d0ac5b.svg
65.108.205.228
https://mcenter.backend.aait-d.com/en-us/account/53c2176daaeb6f12f40c6bfa1343a559/images/dls-logo-stack/262a21c90cbe477939a5712a103303ef.svg
65.108.205.228
https://mcenter.backend.aait-d.com/en-us/account/369c08e101923baaf02d3bbd2d3501dc/images/dls-logo-stack/aeb255e612b7d871faaa4178f463ea14.svg
65.108.205.228
https://mcenter.backend.aait-d.com/en-us/account/462d4b9144cf1cb8b96709ef87082958/images/dls-flag-us(1)/46bb38987c2142f1540a9d7e60cbcb25.svg
65.108.205.228
https://kidshine.in/favicon.ico
217.21.85.6
https://kidshine.in/r.php?id=h1rx9p2x00
https://mcenter.backend.aait-d.com/96e904bccbceb08149da688da5f3c272/do
65.108.205.228
https://mcenter.backend.aait-d.com/en-us/account/f7fe201a703a9db2af462b01fc2a8525/images/0xls/8670dfbbcc639b54338aa5378a9a8b2f.jpg
65.108.205.228
https://kidshine.in/rrt.php
217.21.85.6
https://mcenter.backend.aait-d.com/en-us/account/3ab01c699c4763b10a56bfb4990758cb/css/9fa/1d97601051b0ab89fbae5efaec128f43.css
65.108.205.228
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://mcenter.backend.aait-d.com/en-us/account/4e82855a23a9cc8ff4370a53ca86e6c8/css/dls.min/4de5a4a665d3d8232766b8d71996118d.css
65.108.205.228
https://u13762205.ct.sendgrid.net/ls/click?upn=u001.2N-2FFSd8Mh5tdTcK2pEXUToH0F5-2Fq3FDo8pnKFzcXMK24EOVQRPQXOzov3WP6TeQDbpOFMAzOhzk6g52qaRBXMg-3D-3DIjNL_PKcFXsnzduNOkTk1M1BuFSXBwpDtJ5JnfBBGS8mWfSDpSIzzZrzaRAqzsWn9I2SACyGbOCQAHofmU9ue-2Bfpl8m5UVDAXfATbU3zHgCM2w6TpOzhFbmwlUQoZzHTxRoJD6sBCzgzJz3SY7rmsp-2BquYHmL2DTOkQggmMFIfKhNPVaBf8NTmimDBPZdcr9YqjF8L6hryY10MBbjsSOUH778gw-3D-3D
167.89.123.78
https://mcenter.backend.aait-d.com/en-us/account/dd1b7ad99c70f528a0cd15bad090930d/images/dls-logo-stack/6e26798dd671334db0705a7a435a5657.svg
65.108.205.228
https://mcenter.backend.aait-d.com/?SignIn
65.108.205.228
https://getbootstrap.com/)
unknown
https://stackpath.bootstrapcdn.com/bootstrap/4.4.1/css/bootstrap.min.css
104.18.10.207
https://mcenter.backend.aait-d.com/en-us/account/acfa3762ccf69b52db0d99e46e9958be/images/dls-logo-line/719ff4c751996497d8358ff59e9b8d90.svg
65.108.205.228
https://mcenter.backend.aait-d.com/en-us/account/cfa36d1eb67be55494c289df78c858a2/css/mlg/1fba342c6c8f7589a6930ace25a3551f.css
65.108.205.228
https://mcenter.backend.aait-d.com/en-us/account/7d2d11bab0f55db52b8512bb93e31a2e/images/dls-logo-bluebox-solid/2b38a48ec16b2e077b41d4966a567b6f.svg
65.108.205.228
There are 12 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
stackpath.bootstrapcdn.com
104.18.10.207
kidshine.in
217.21.85.6
mcenter.backend.aait-d.com
65.108.205.228
s-part-0017.t-0009.t-msedge.net
13.107.246.45
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
www.google.com
142.250.186.36
u13762205.ct.sendgrid.net
167.89.123.78
www.aexp-static.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.36
www.google.com
United States
104.18.10.207
stackpath.bootstrapcdn.com
United States
217.21.85.6
kidshine.in
United Kingdom
192.168.2.4
unknown
unknown
65.108.205.228
mcenter.backend.aait-d.com
United States
192.168.2.22
unknown
unknown
239.255.255.250
unknown
Reserved
192.168.2.23
unknown
unknown
192.168.2.15
unknown
unknown
167.89.123.78
u13762205.ct.sendgrid.net
United States

DOM / HTML

URL
Malicious
https://mcenter.backend.aait-d.com/en-us/account/login?ZQLQepa=ipodSpLTkjoDqryYHxxMzUZGLdzjmlaIhmdLcDgMgwHKsFxnPTjtYEMoFznsXCWByXr=JLrzvKBm
malicious
https://kidshine.in/r.php?id=h1rx9p2x00