IOC Report
https://securemail-sscu.net/s/e?m=ABAp6Mu6Zt2AaGYB32H369op&c=ABD8nOWzFGfOvucyDa774Okj&em=Smckenzie%40op%2df%2eorg

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:15:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:15:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:15:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:15:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 13:15:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 67
ASCII text, with very long lines (736)
downloaded
Chrome Cache Entry: 68
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 69
ASCII text
downloaded
Chrome Cache Entry: 70
ASCII text, with very long lines (1004)
downloaded
Chrome Cache Entry: 71
ASCII text
downloaded
Chrome Cache Entry: 72
ASCII text, with very long lines (545)
downloaded
Chrome Cache Entry: 73
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 74
GIF image data, version 89a, 1200 x 130
dropped
Chrome Cache Entry: 75
C source, ASCII text
downloaded
Chrome Cache Entry: 76
ASCII text
downloaded
Chrome Cache Entry: 77
ASCII text
downloaded
Chrome Cache Entry: 78
ASCII text
downloaded
Chrome Cache Entry: 79
ASCII text, with very long lines (342)
downloaded
Chrome Cache Entry: 80
ASCII text
downloaded
Chrome Cache Entry: 81
GIF image data, version 89a, 1200 x 130
downloaded
Chrome Cache Entry: 82
GIF image data, version 89a, 185 x 60
dropped
Chrome Cache Entry: 83
ASCII text
downloaded
Chrome Cache Entry: 84
ASCII text
downloaded
Chrome Cache Entry: 85
ASCII text
downloaded
Chrome Cache Entry: 86
C source, ASCII text
downloaded
Chrome Cache Entry: 87
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 88
GIF image data, version 89a, 185 x 60
downloaded
Chrome Cache Entry: 89
ASCII text
downloaded
Chrome Cache Entry: 90
ASCII text
downloaded
Chrome Cache Entry: 91
ASCII text
downloaded
There are 22 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://securemail-sscu.net/s/e?m=ABAp6Mu6Zt2AaGYB32H369op&c=ABD8nOWzFGfOvucyDa774Okj&em=Smckenzie%40op%2df%2eorg
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2068 --field-trial-handle=1940,i,18419103110123412338,14174858769471850138,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://securemail-sscu.net/s/e?m=ABAp6Mu6Zt2AaGYB32H369op&c=ABD8nOWzFGfOvucyDa774Okj&em=Smckenzie%40op%2df%2eorg
http://jqueryui.com/menu/
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/2ndGen/base/stylesheet_print.css
63.71.13.102
https://securemail-sscu.net/s/e?m=ABAp6Mu6Zt2AaGYB32H369op&c=ABD8nOWzFGfOvucyDa774Okj&em=Smckenzie%40op%2df%2eorg
http://api.jqueryui.com/slide-effect/
unknown
http://jqueryui.com/accordion/
unknown
http://api.jqueryui.com/data-selector/
unknown
http://api.jqueryui.com/tooltip/
unknown
http://jqueryui.com
unknown
https://web.archive.org/web/20100324014747/http://blindsignals.com/index.php/2009/07/jquery-delay/
unknown
http://jsfiddle.net/JZSMt/3/
unknown
http://api.jqueryui.com/mouse/
unknown
https://github.com/jquery/jquery-color
unknown
https://promisesaplus.com/#point-75
unknown
http://jqueryui.com/position/
unknown
http://api.jqueryui.com/jQuery.widget/
unknown
https://html.spec.whatwg.org/multipage/forms.html#concept-fe-disabled
unknown
https://bugs.webkit.org/show_bug.cgi?id=29084
unknown
http://jqueryui.com/button/
unknown
http://api.jqueryui.com/focusable-selector/
unknown
https://infra.spec.whatwg.org/#strip-and-collapse-ascii-whitespace
unknown
https://bugzilla.mozilla.org/show_bug.cgi?id=561664
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/attributeDefinitions.js
63.71.13.102
https://html.spec.whatwg.org/multipage/forms.html#concept-option-disabled
unknown
https://securemail-sscu.net/i/sevenseventeen/top_20180418_1239.gif
63.71.13.102
http://api.jqueryui.com/fade-effect/
unknown
http://bugs.jquery.com/ticket/11778
unknown
http://api.jqueryui.com/draggable/
unknown
https://bugs.webkit.org/show_bug.cgi?id=107380
unknown
https://github.com/jrburke/requirejs/wiki/Updating-existing-libraries#wiki-anon
unknown
http://api.jqueryui.com/form-reset-mixin/
unknown
http://api.jqueryui.com/fold-effect/
unknown
http://api.jqueryui.com/button/
unknown
https://bugzilla.mozilla.org/show_bug.cgi?id=687787
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/2ndGen/base/stylesheet_mobileLandscape.css
63.71.13.102
https://securemail-sscu.net/favicon.ico
63.71.13.102
https://bugs.chromium.org/p/chromium/issues/detail?id=470258
unknown
https://bugs.jquery.com/ticket/13378
unknown
http://jqueryui.com/spinner/
unknown
https://promisesaplus.com/#point-64
unknown
http://api.jqueryui.com/size-effect/
unknown
https://promisesaplus.com/#point-61
unknown
http://api.jqueryui.com/spinner/
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/userNotifier.js
63.71.13.102
http://api.jqueryui.com/tabs/
unknown
http://api.jqueryui.com/puff-effect/
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/default_registerview_validator.js
63.71.13.102
http://api.jqueryui.com/uniqueId/
unknown
https://securemail-sscu.net/s/CON-3e12d828/sevenseventeen_stylesheet.css
63.71.13.102
http://api.jqueryui.com/slider/
unknown
http://api.jqueryui.com/checkboxradio/
unknown
https://securemail-sscu.net/s/stylesheets/skipnav.css
63.71.13.102
https://html.spec.whatwg.org/#nonce-attributes
unknown
http://api.jqueryui.com/selectable/
unknown
http://jqueryui.com/slider/
unknown
https://jsperf.com/getall-vs-sizzle/2
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/scripts/jquery/jquery.js
63.71.13.102
http://api.jqueryui.com/disableSelection/
unknown
https://code.google.com/p/chromium/issues/detail?id=313082
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/default_validatorconstants_en.js
63.71.13.102
http://jqueryui.com/droppable/
unknown
http://jqueryui.com/controlgroup/
unknown
http://api.jqueryui.com/pulsate-effect/
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/emailfieldvalue.js
63.71.13.102
https://developer.mozilla.org/en-US/docs/CSS/display
unknown
http://api.jqueryui.com/scrollParent/
unknown
https://jquery.com/
unknown
http://bugs.jqueryui.com/ticket/7552
unknown
http://jqueryui.com/draggable/
unknown
http://jqueryui.com/sortable/
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/2ndGen/base/stylesheet_desktopFallthrough.css
63.71.13.102
https://github.com/jquery/jquery/issues/4382
unknown
http://api.jqueryui.com/resizable/
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/fieldvalue.js
63.71.13.102
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/2ndGen/base/stylesheet_tablet.css
63.71.13.102
http://api.jqueryui.com/transfer-effect/
unknown
https://github.com/jquery/sizzle/pull/225
unknown
https://bugs.jquery.com/ticket/4833
unknown
https://sizzlejs.com/
unknown
https://bugs.chromium.org/p/chromium/issues/detail?id=449857
unknown
https://js.foundation/
unknown
http://api.jqueryui.com/labels/
unknown
https://bugs.webkit.org/show_bug.cgi?id=47182
unknown
http://www.robertpenner.com/easing)
unknown
https://bugs.jquery.com/ticket/13393
unknown
http://api.jqueryui.com/sortable/
unknown
http://jqueryui.com/datepicker/
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/scripts/jqueryui/jquery-ui.js
63.71.13.102
Http://bugs.jqueryui.com/ticket/9446
unknown
http://api.jqueryui.com/tabbable-selector/
unknown
http://api.jqueryui.com/datepicker/
unknown
https://bugs.webkit.org/show_bug.cgi?id=136851
unknown
http://jquery.org/license
unknown
https://securemail-sscu.net/s/REL-6.3.13-release.3.41521/2ndGen/base/stylesheet_mobile.css
63.71.13.102
http://api.jqueryui.com/highlight-effect/
unknown
https://jsperf.com/thor-indexof-vs-for/5
unknown
https://bugs.jquery.com/ticket/12359
unknown
https://code.google.com/p/maashaack/source/browse/packages/graphics/trunk/src/graphics/colors/HUE2RG
unknown
https://securemail-sscu.net/s/CON-566f38d3/sevenseventeen_stylesheet_mobile.css
63.71.13.102
http://api.jqueryui.com/drop-effect/
unknown
https://html.spec.whatwg.org/#strip-and-collapse-whitespace
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.google.com
172.253.63.147
securemail-sscu.net
63.71.13.102

IPs

IP
Domain
Country
Malicious
63.71.13.102
securemail-sscu.net
United States
239.255.255.250
unknown
Reserved
192.168.2.16
unknown
unknown
172.253.63.147
www.google.com
United States

DOM / HTML

URL
Malicious
https://securemail-sscu.net/s/e?m=ABAp6Mu6Zt2AaGYB32H369op&c=ABD8nOWzFGfOvucyDa774Okj&em=Smckenzie%40op%2df%2eorg