IOC Report
http://click.mail.virtualtrainings.co/?qs=a34a2802da5b987c99d77a91eed125396201717cd0f438a37385f1fc09098d865bd08e754a10ba4cb3e6cf96b351a18785c7d54a48824461a3034c0088963a71

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 10:56:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 10:56:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 10:56:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 10:56:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 10:56:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 600x300, components 3
downloaded
Chrome Cache Entry: 101
PNG image data, 180 x 78, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 102
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 103
Unicode text, UTF-8 text, with very long lines (24228)
downloaded
Chrome Cache Entry: 104
GIF image data, version 89a, 131 x 32
downloaded
Chrome Cache Entry: 105
ASCII text
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (14044), with no line terminators
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (65307)
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (10187), with no line terminators
downloaded
Chrome Cache Entry: 109
ASCII text, with very long lines (12531), with no line terminators
downloaded
Chrome Cache Entry: 110
ASCII text
downloaded
Chrome Cache Entry: 111
HTML document, Unicode text, UTF-8 text, with very long lines (1872), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 112
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 600x400, components 3
dropped
Chrome Cache Entry: 113
MS Windows icon resource - 1 icon, 48x48, 32 bits/pixel
dropped
Chrome Cache Entry: 114
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 115
Web Open Font Format (Version 2), TrueType, length 112440, version 1.0
downloaded
Chrome Cache Entry: 116
ASCII text, with very long lines (15491), with no line terminators
downloaded
Chrome Cache Entry: 117
PNG image data, 180 x 78, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 118
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 600x400, components 3
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (65299)
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (2165)
downloaded
Chrome Cache Entry: 121
Unicode text, UTF-8 text, with very long lines (65306)
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (3651)
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (324)
downloaded
Chrome Cache Entry: 124
MS Windows icon resource - 1 icon, 48x48, 32 bits/pixel
downloaded
Chrome Cache Entry: 125
JSON data
downloaded
Chrome Cache Entry: 126
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 127
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 600x300, components 3
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 129
ASCII text
downloaded
Chrome Cache Entry: 130
ASCII text
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 132
ASCII text
downloaded
Chrome Cache Entry: 133
GIF image data, version 89a, 131 x 32
dropped
Chrome Cache Entry: 134
PNG image data, 630 x 101, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 135
ASCII text
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (2237)
downloaded
Chrome Cache Entry: 137
Unicode text, UTF-8 text, with very long lines (18016), with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (65307)
downloaded
Chrome Cache Entry: 139
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 140
exported SGML document, ASCII text
downloaded
Chrome Cache Entry: 141
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 142
PNG image data, 630 x 101, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 93
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 94
ASCII text, with very long lines (10918)
downloaded
Chrome Cache Entry: 95
ASCII text, with very long lines (30186), with no line terminators
downloaded
Chrome Cache Entry: 96
JSON data
dropped
Chrome Cache Entry: 97
JSON data
dropped
Chrome Cache Entry: 98
ASCII text
downloaded
Chrome Cache Entry: 99
JSON data
downloaded
There are 47 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http://click.mail.virtualtrainings.co/?qs=a34a2802da5b987c99d77a91eed125396201717cd0f438a37385f1fc09098d865bd08e754a10ba4cb3e6cf96b351a18785c7d54a48824461a3034c0088963a71
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2172 --field-trial-handle=1976,i,2042860566312350945,17922558497378661450,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
http://click.mail.virtualtrainings.co/?qs=a34a2802da5b987c99d77a91eed125396201717cd0f438a37385f1fc09098d865bd08e754a10ba4cb3e6cf96b351a18785c7d54a48824461a3034c0088963a71
https://stats.g.doubleclick.net/g/collect
unknown
https://www.virtualtrainings.com:443
unknown
http://jquery.org/license
unknown
https://github.com/carhartl/jquery-cookie
unknown
https://www.virtualtrainings.com/common/js/jquery/plugins/browser-plugin/jquery.browser-0.1.0.min.js
199.119.121.25
https://www.macromedia.com/go/getflashplayer
unknown
https://www.virtualtrainings.com/ecommerce/css/virtualClassesDesign.css
199.119.121.25
https://www.virtualtrainings.com:443/newcustomer
unknown
https://www.virtualtrainings.com/common/js/jquery/ui/js/jquery.cookie-1.4.0.js
199.119.121.25
https://static.zdassets.com/web_widget/messenger/latest/web-widget-main-7bc1c0f.js
104.18.70.113
https://virtualtrainingsofficial.zendesk.com/frontendevents/pv?client=1B752747-577B-429A-A0E0-83861AF69088
104.16.53.111
https://ampcid.google.com/v1/publisher:getClientId
unknown
about:blank
https://static.zdassets.com/web_widget/messenger/latest/web-widget-locales/messenger/en-us-json-7bc1c0f.js
104.18.70.113
https://www.google.com
unknown
https://www.youtube.com/iframe_api
unknown
https://www.virtualtrainings.com
unknown
http://www.opensource.org/licenses/mit-license.php
unknown
https://www.virtualtrainings.com/images/fonts/bootstrap-icons.woff2?8d200481aa7f02a2d63a331fc782cfaf
199.119.121.25
https://github.com/twbs/bootstrap/graphs/contributors)
unknown
https://www.virtualtrainings.com/images/icons/cart_icon.svg
199.119.121.25
https://virtualtrainingsofficial.zendesk.com/sc/sdk
unknown
https://github.com/gabceb/jquery-browser-plugin
unknown
https://ekr.zdassets.com/compose/761f8a3e-696b-481a-8eea-d01f44cf0939
104.18.72.113
https://github.com/gabceb
unknown
https://virtualtrainingsofficial.zendesk.com/embeddable/config
104.16.53.111
https://static.zdassets.com/web_widget/messenger/latest/web-widget-92795-7bc1c0f.js
104.18.70.113
https://www.virtualtrainings.com/images/favicon.png
199.119.121.25
https://stats.g.doubleclick.net/j/collect
unknown
https://static.zdassets.com/web_widget/messenger/latest/web-widget-84852-7bc1c0f.js
104.18.70.113
https://www.virtualtrainings.com:443/live-virtual-classes
unknown
http://click.mail.virtualtrainings.co/?qs=a34a2802da5b987c99d77a91eed125396201717cd0f438a37385f1fc09098d865bd08e754a10ba4cb3e6cf96b351a18785c7d54a48824461a3034c0088963a71
13.110.196.1
https://www.virtualtrainings.com:443/main
unknown
https://static.zdassets.com/web_widget/messenger/latest/web-widget-15178-7bc1c0f.js
104.18.70.113
https://www.virtualtrainings.com/ecommerce/images/productAdditionalView.js
199.119.121.25
http://jstree.com/
unknown
http://www.apache.org/licenses/LICENSE-2.0
unknown
https://www.virtualtrainings.com/images/favicon-32.png
199.119.121.25
https://www.virtualtrainings.com/common/js/jquery/jquery-3.5.1.min.js
199.119.121.25
https://jqueryvalidation.org/
unknown
https://www.virtualtrainings.com/common/js/jquery/plugins/validate/jquery.validate.min.js
199.119.121.25
https://a.nel.cloudflare.com/report/v4?s=z1O4l%2Frx%2F2jkKesJFNUlDgYw4y7tBVYjb29DniysjiW7jZoWlrQKKAe7rEZrudcTax9Qq06%2BAC6cdYNWpxG1PGHDCi75q6PTgJdlZ4GeKxRh79kWpBDxCSUvOdziRq3CCJjZ%2FiL7uXtsKDQUQUfcpQRP61vwug%3D%3D
35.190.80.1
https://static.zdassets.com/web_widget/messenger/latest/web-widget-9527-7bc1c0f.js
104.18.70.113
https://www.virtualtrainings.com/ecommerce/css/custom.css
199.119.121.25
https://github.com/twbs/bootstrap/blob/main/LICENSE)
unknown
https://www.virtualtrainings.com/images/products/51368/large.jpg
199.119.121.25
https://tagassistant.google.com/
unknown
https://www.virtualtrainings.com:443/recorded-virtual-classes
unknown
https://ekr.zendesk.com/compose_product/web_widget/7bc1c0f290501106fa41dc515076261e2325fb83?features
unknown
https://seal.godaddy.com/getSeal?sealID=Oc76TMkaRhWVh7zztF9rCUqYZpNXmcuZ9ecsi0slBZt2HxJeh6TvluCyYjNe
unknown
https://adservice.google.com/pagead/regclk
unknown
https://www.virtualtrainings.com/ecommerce/css/bootstrap-icons.css
199.119.121.25
https://getbootstrap.com/)
unknown
https://www.virtualtrainings.com/common/js/jquery/plugins/datetimepicker/i18n/jquery-ui-timepicker-en.js
199.119.121.25
https://static.zdassets.com/web_widget/messenger/latest/web-widget-59535-7bc1c0f.js
104.18.70.113
https://cct.google/taggy/agent.js
unknown
https://www.virtualtrainings.com/images/VirtualTrainingsLogo.png
199.119.121.25
https://www.virtualtrainings.com/common/js/jquery/jquery-migrate-3.3.0.min.js
199.119.121.25
https://www.virtualtrainings.com/images/favicon.ico
199.119.121.25
https://developer.zendesk.com/documentation/classic-web-widget-sdks/web-widget/getting-started/legal
unknown
https://www.virtualtrainings.com/common/js/jquery/plugins/jsTree/jquery.jstree.js
199.119.121.25
https://www.virtualtrainings.com/common/js/util/miscAjaxFunctions.js
199.119.121.25
https://www.virtualtrainings.com/images/secure-payment-stripe.png
199.119.121.25
https://www.google.com/ads/ga-audiences
unknown
https://www.virtualtrainings.com:443/checkLogin/w_product
unknown
https://www.google.%/ads/ga-audiences
unknown
https://static.zdassets.com/ekr/snippet.js?key=761f8a3e-696b-481a-8eea-d01f44cf0939
104.18.70.113
https://td.doubleclick.net
unknown
https://www.merchant-center-analytics.goog
unknown
https://github.com/mde/timezone-js
unknown
https://www.virtualtrainings.com/virtual-class/ai-powered-office-mastery:-chatgpt-in-excel,-powerpoint-and-word-51368live
https://www.virtualtrainings.com/ecommerce/js/bootstrap/js/bootstrap.bundle.min.js
199.119.121.25
https://stats.g.doubleclick.net/g/collect?v=2&
unknown
http://www.gnu.org/licenses/gpl.html
unknown
https://www.virtualtrainings.com/images/have-any-queries.jpg
199.119.121.25
https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=5
unknown
https://www.virtualtrainings.com/ecommerce/js/bootstrap/css/bootstrap.min.css
199.119.121.25
There are 67 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
click.s12.exacttarget.com
13.110.196.1
static.zdassets.com
104.18.70.113
a.nel.cloudflare.com
35.190.80.1
virtualtrainings.com
199.119.121.25
ekr.zdassets.com
104.18.72.113
www.google.com
172.217.215.104
virtualtrainingsofficial.zendesk.com
104.16.53.111
seal.godaddy.com
unknown
click.mail.virtualtrainings.co
unknown
www.virtualtrainings.com
unknown

IPs

IP
Domain
Country
Malicious
172.217.215.104
www.google.com
United States
104.16.53.111
virtualtrainingsofficial.zendesk.com
United States
192.168.2.16
unknown
unknown
13.110.196.1
click.s12.exacttarget.com
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
104.18.70.113
static.zdassets.com
United States
104.16.51.111
unknown
United States
192.168.2.23
unknown
unknown
192.168.2.15
unknown
unknown
199.119.121.25
virtualtrainings.com
United States
104.18.72.113
ekr.zdassets.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.virtualtrainings.com/virtual-class/ai-powered-office-mastery:-chatgpt-in-excel,-powerpoint-and-word-51368live
https://www.virtualtrainings.com/virtual-class/ai-powered-office-mastery:-chatgpt-in-excel,-powerpoint-and-word-51368live
about:blank
about:blank
about:blank
about:blank
about:blank
about:blank