IOC Report
https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:31:29 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:31:28 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 09:23:19 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:31:28 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:31:28 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:31:28 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 140
JSON data
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (680)
downloaded
Chrome Cache Entry: 142
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 143
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 144
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 145
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 146
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (41012)
downloaded
Chrome Cache Entry: 148
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 149
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 150
Unicode text, UTF-8 text, with very long lines (40329), with NEL line terminators
downloaded
Chrome Cache Entry: 151
JSON data
downloaded
Chrome Cache Entry: 152
JSON data
downloaded
Chrome Cache Entry: 153
JSON data
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (12703)
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 156
JSON data
downloaded
Chrome Cache Entry: 157
Unicode text, UTF-8 text, with very long lines (65136), with no line terminators
downloaded
Chrome Cache Entry: 158
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (44065)
downloaded
Chrome Cache Entry: 160
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (6634)
downloaded
Chrome Cache Entry: 162
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 163
ASCII text, with very long lines (4077)
downloaded
Chrome Cache Entry: 164
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (798)
downloaded
Chrome Cache Entry: 166
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 167
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 168
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 169
JSON data
dropped
Chrome Cache Entry: 170
Unicode text, UTF-8 text, with very long lines (59929), with no line terminators
downloaded
Chrome Cache Entry: 171
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 172
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 173
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 174
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 175
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 176
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 177
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 178
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 179
Unicode text, UTF-8 text, with very long lines (3256), with no line terminators
downloaded
Chrome Cache Entry: 180
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 181
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 182
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 183
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 184
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 185
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 186
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 187
Web Open Font Format, TrueType, length 37153, version 1.0
downloaded
Chrome Cache Entry: 188
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 189
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 190
Unicode text, UTF-8 text, with very long lines (32812), with NEL line terminators
downloaded
Chrome Cache Entry: 191
JSON data
dropped
Chrome Cache Entry: 192
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 193
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 194
JSON data
downloaded
Chrome Cache Entry: 195
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 196
JSON data
downloaded
Chrome Cache Entry: 197
JSON data
dropped
Chrome Cache Entry: 198
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 199
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 200
ASCII text, with very long lines (41245)
downloaded
Chrome Cache Entry: 201
Unicode text, UTF-8 text, with very long lines (3704)
downloaded
Chrome Cache Entry: 202
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 203
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 204
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 205
ASCII text, with very long lines (778), with no line terminators
downloaded
Chrome Cache Entry: 206
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 207
Web Open Font Format, TrueType, length 69766, version 1.0
downloaded
Chrome Cache Entry: 208
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 209
ASCII text, with very long lines (44208)
downloaded
Chrome Cache Entry: 210
ASCII text, with very long lines (43906)
downloaded
Chrome Cache Entry: 211
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 212
Web Open Font Format, TrueType, length 37153, version 1.0
downloaded
Chrome Cache Entry: 213
ASCII text, with very long lines (15984), with no line terminators
downloaded
Chrome Cache Entry: 214
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 215
Unicode text, UTF-8 text, with very long lines (32966), with LF, NEL line terminators
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (2026)
downloaded
Chrome Cache Entry: 217
JSON data
dropped
Chrome Cache Entry: 218
Unicode text, UTF-8 text, with very long lines (45542)
downloaded
Chrome Cache Entry: 219
JSON data
downloaded
Chrome Cache Entry: 220
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 221
JSON data
downloaded
Chrome Cache Entry: 222
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 223
ASCII text, with very long lines (33449)
downloaded
Chrome Cache Entry: 224
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (65536), with no line terminators, with escape sequences
downloaded
Chrome Cache Entry: 226
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 227
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 228
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 229
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 230
ASCII text, with very long lines (3960)
downloaded
Chrome Cache Entry: 231
Unicode text, UTF-8 text, with very long lines (50713), with NEL line terminators
downloaded
Chrome Cache Entry: 232
JSON data
dropped
Chrome Cache Entry: 233
ASCII text, with very long lines (2009)
downloaded
Chrome Cache Entry: 234
data
downloaded
Chrome Cache Entry: 235
JSON data
downloaded
Chrome Cache Entry: 236
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 237
JSON data
downloaded
Chrome Cache Entry: 238
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 239
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 240
Unicode text, UTF-8 text, with very long lines (41211), with LF, NEL line terminators
downloaded
Chrome Cache Entry: 241
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 242
ASCII text, with very long lines (64772)
downloaded
Chrome Cache Entry: 243
JSON data
downloaded
Chrome Cache Entry: 244
Unicode text, UTF-8 text, with very long lines (34692)
downloaded
Chrome Cache Entry: 245
Unicode text, UTF-8 text, with very long lines (46587)
downloaded
Chrome Cache Entry: 246
ASCII text, with very long lines (9025), with no line terminators
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (39720)
downloaded
Chrome Cache Entry: 248
JSON data
dropped
Chrome Cache Entry: 249
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 250
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 251
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 252
JSON data
dropped
Chrome Cache Entry: 253
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 254
ASCII text, with very long lines (59970)
downloaded
Chrome Cache Entry: 255
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 256
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 257
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 258
JSON data
dropped
Chrome Cache Entry: 259
ASCII text, with very long lines (36023)
downloaded
Chrome Cache Entry: 260
ASCII text, with very long lines (1680)
downloaded
Chrome Cache Entry: 261
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 262
ASCII text, with very long lines (46099)
downloaded
Chrome Cache Entry: 263
ASCII text, with very long lines (44597)
downloaded
Chrome Cache Entry: 264
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 265
ASCII text, with very long lines (37328)
downloaded
Chrome Cache Entry: 266
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 267
JSON data
dropped
Chrome Cache Entry: 268
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 269
JSON data
dropped
Chrome Cache Entry: 270
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 271
ASCII text, with very long lines (41290)
downloaded
Chrome Cache Entry: 272
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 273
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 274
ASCII text, with very long lines (28410)
downloaded
Chrome Cache Entry: 275
ASCII text, with very long lines (32092), with CRLF line terminators
downloaded
Chrome Cache Entry: 276
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 277
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 278
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 279
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 280
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 281
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 282
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 283
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (31865)
downloaded
Chrome Cache Entry: 285
JSON data
dropped
Chrome Cache Entry: 286
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 287
ASCII text, with very long lines (31923), with CRLF line terminators
downloaded
Chrome Cache Entry: 288
Unicode text, UTF-8 text, with very long lines (3704)
downloaded
Chrome Cache Entry: 289
JSON data
dropped
Chrome Cache Entry: 290
ASCII text, with very long lines (2693), with no line terminators
downloaded
There are 148 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1776 --field-trial-handle=1948,i,17101978054004084476,12410038309744272020,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter
https://assets.adobedtm.com/dcb19cbd6cbf/8e98299b4e37/launch-f60a62d583bd.min.js
unknown
https://assets.adobedtm.com/98caf8fccc463fd7e47088b35e73b27720bb5cc1/satelliteLib-c5299abd23ef05bd6d
unknown
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=7&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
64.233.177.103
https://assets.adobedtm.com/dcb19cbd6cbf/8e98299b4e37/launch-186af9da7404-staging.min.js
unknown
https://lodash.com/
unknown
https://www.google.com/async/newtab_promos
64.233.177.103
https://www.dynatrace.com/company/trust-center/customers/reports/
unknown
https://assets.adobedtm.com/dcb19cbd6cbf/8fe231718838/launch-5a77dcd96b5f-staging.min.js
unknown
https://assets.adobedtm.com/dcb19cbd6cbf/66bfa1f1c370/launch-a84bcfcd9f88-staging.min.js
unknown
https://www.google.com/sorry/index?continue=https://www.google.com/async/ddljson%3Fasync%3Dntp:2&q=EgRRtTk0GNv7-bAGIjAB5ca-1h2npjbKyRJrY0x7oVX9EvE_hx3CS29R-qtGI7R0K5dKFNaff9s5a-f5vCUyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
64.233.177.103
https://assets.adobedtm.com/dcb19cbd6cbf/6ea2f89ca33d/launch-ffeccfbfebd3.min.js
unknown
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRRtTk0GNv7-bAGIjCutrdc__jP0Ewy3i-m2egggo-7ZmryQzEGXexmB4-11OBM3nprFLRWxeudB_gRK98yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
64.233.177.103
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
64.233.177.103
https://assets.adobedtm.com/dcb19cbd6cbf/61650f53735f/launch-77374eae9c9b-staging.min.js
unknown
https://assets.adobedtm.com/dcb19cbd6cbf/333b39a46679/launch-df6a13efe609-staging.min.js
unknown
https://assets.adobedtm.com/98caf8fccc463fd7e47088b35e73b27720bb5cc1/satelliteLib-f424e4c1e880782914
unknown
http://underscorejs.org/LICENSE
unknown
https://www.google.com/async/ddljson?async=ntp:2
64.233.177.103
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRRtTk0GNv7-bAGIjDiFp97vxk7IW7qwjFYYBhxwkHmojLuIhALKDnO0DQ2z_YXRZ4ybx5vwHqH-UJyuSIyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
64.233.177.103
https://raw.githubusercontent.com/stefanpenner/es6-promise/master/LICENSE
unknown
https://assets.adobedtm.com/98caf8fccc463fd7e47088b35e73b27720bb5cc1/satelliteLib-4454a9ef97c1c8cd89
unknown
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
64.233.177.103
https://feross.org/opensource
unknown
https://lodash.com/license
unknown
https://dpm.demdex.net/id?d_visid_ver=5.0.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=5C36123F5245AF470A490D45%40AdobeOrg&d_nsid=15&ts=1713274301023
52.4.85.254
https://dpm.demdex.net/id/rd?d_visid_ver=5.0.0&d_fieldgroup=MC&d_rtbd=json&d_ver=2&d_verify=1&d_orgid=5C36123F5245AF470A490D45%40AdobeOrg&d_nsid=15&ts=1713274301023
52.4.85.254
https://github.com/js-cookie/js-cookie
unknown
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
64.233.177.103
http://feross.org
unknown
https://assets.adobedtm.com/98caf8fccc463fd7e47088b35e73b27720bb5cc1/satelliteLib-bea3c9697c62409967
unknown
https://openjsf.org/
unknown
https://assets.adobedtm.com/dcb19cbd6cbf/6ea2f89ca33d/launch-25c1ded7854b-staging.min.js
unknown
https://github.com/facebook/regenerator/blob/main/LICENSE
unknown
http://jedwatson.github.io/classnames
unknown
There are 24 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
dcs-public-edge-va6-158015560.us-east-1.elb.amazonaws.com
52.4.85.254
www.google.com
64.233.177.103
americanexpress.com.ssl.d2.sc.omtrdc.net
63.140.38.236
commerce.ss-omtrdc.net
192.243.240.8
sp100500b5.guided.ss-omtrdc.net
unknown
graph.americanexpress.com
unknown
assets.adobedtm.com
unknown
siteintercept.qualtrics.com
unknown
dynatracepsg.americanexpress.com
unknown
mycaoneslinger.americanexpress.com
unknown
iwmapapi.americanexpress.com
unknown
inbound.americanexpress.com
unknown
apigw.americanexpress.com
unknown
omns.americanexpress.com
unknown
one-xp.americanexpress.com
unknown
functions.americanexpress.com
unknown
global.americanexpress.com
unknown
dpm.demdex.net
unknown
www.aexp-static.com
unknown
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.168.2.18
unknown
unknown
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
63.140.39.72
unknown
United States
192.243.240.8
commerce.ss-omtrdc.net
United States
52.4.85.254
dcs-public-edge-va6-158015560.us-east-1.elb.amazonaws.com
United States
63.140.38.236
americanexpress.com.ssl.d2.sc.omtrdc.net
United States
3.223.253.145
unknown
United States
239.255.255.250
unknown
Reserved
64.233.177.103
www.google.com
United States
There are 1 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter
https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter
https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter
https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter
https://global.americanexpress.com/help?inav=iNUtlContact&extlink=us-em-serv-footer-helpcenter