IOC Report
https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6f

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
XML 1.0 document, ASCII text
downloaded
Chrome Cache Entry: 42
PDF document, version 1.6 (zip deflate encoded)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1984,i,9554475306055727456,10145289589561791208,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX-"

URLs

Name
IP
Malicious
https://email.notifications.joinhandshake.com/c/eJx0j82u2yAQhZ8Gb6prASbgLLyoklqq1EWlSt1GExhiGvMjwKlyn74yybYrvjliPs0xEzdHqTqcmGKcH4RgY7dMUl3tSAVTVF6VpVKygzyMylItjxYk69zEKRdUUMFGNgyq16C5tHzk4ng0SlEiaIjVWaehuhhK_ye6sEAwZYE79jr6bp2WWlMhw1fCZ8JnHUPFUD80rCmuzw80W1-GHjx8xgB_y760f4OMmAvmh9NYCJ8Z4bOJevMY6j6fYCX8wOnPuD4b7Kc2-JWyC7eGp2ZpOIN7wTef1vh8p6cF9b3RD1dqAwimvd-Djdm3Xm3-zftkLBnmrfpLiVvWSIbzq_5uk3vu0bjNk-GMHtz6DjX4BO4WyHAuGMwl482Vmpv6Ainl-EDTpRzNpuvluuk71ul1-hcLLpcuTx5XVwr0fgvxkwhqytJr6G_x0dXp_9Z_AQAA__-oyKX-
https://content-calpoly-edu.s3.amazonaws.com/favicon.ico
52.219.220.161
https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approved

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
www.google.com
64.233.176.147
mailgun.org
34.110.180.34
s3-us-west-1-w.amazonaws.com
52.219.220.161
fp2e7a.wpc.phicdn.net
192.229.211.108
email.notifications.joinhandshake.com
unknown
content-calpoly-edu.s3.amazonaws.com
unknown

IPs

IP
Domain
Country
Malicious
34.110.180.34
mailgun.org
United States
239.255.255.250
unknown
Reserved
52.219.220.161
s3-us-west-1-w.amazonaws.com
United States
64.233.176.147
www.google.com
United States
192.168.2.4
unknown
unknown

DOM / HTML

URL
Malicious
https://content-calpoly-edu.s3.amazonaws.com/careerservices/1/documents/Cal%20Poly%202024%20Spring%20Career%20Fair%20Employer%20Check%20List%20and%20Information%20V2.pdf?utm_source=notifier&utm_medium=email&utm_campaign=send_registration_approved