IOC Report
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 13:53:22 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 13:53:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 13:53:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 13:53:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 13:53:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 133
Web Open Font Format (Version 2), TrueType, length 18508, version 1.6553
downloaded
Chrome Cache Entry: 134
Web Open Font Format (Version 2), TrueType, length 26700, version 1.0
downloaded
Chrome Cache Entry: 135
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (554)
downloaded
Chrome Cache Entry: 137
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 138
ASCII text, with very long lines (7498)
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (3744), with no line terminators
downloaded
Chrome Cache Entry: 140
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 141
Unicode text, UTF-8 text, with very long lines (64598), with no line terminators
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (14451)
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (59681)
downloaded
Chrome Cache Entry: 144
gzip compressed data, max compression, from Unix, original size modulo 2^32 304649
downloaded
Chrome Cache Entry: 145
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (56398), with no line terminators
downloaded
Chrome Cache Entry: 147
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 80x90, components 3
dropped
Chrome Cache Entry: 148
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (17688)
downloaded
Chrome Cache Entry: 150
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 151
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (20984), with no line terminators
downloaded
Chrome Cache Entry: 153
JSON data
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (65465)
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (45058)
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (62676)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (17910)
downloaded
Chrome Cache Entry: 158
Unicode text, UTF-8 text, with very long lines (65406)
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (1680)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (28410)
downloaded
Chrome Cache Entry: 161
HTML document, ASCII text
dropped
Chrome Cache Entry: 162
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 163
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 164
Unicode text, UTF-8 text, with very long lines (32565)
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (686)
downloaded
Chrome Cache Entry: 166
Web Open Font Format (Version 2), CFF, length 25368, version 1.6553
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (2483), with no line terminators
downloaded
Chrome Cache Entry: 168
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 80x90, components 3
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (1719), with no line terminators
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (554)
downloaded
Chrome Cache Entry: 171
ASCII text, with very long lines (56506)
downloaded
Chrome Cache Entry: 172
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 173
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 174
ASCII text, with very long lines (731), with no line terminators
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (64772)
downloaded
Chrome Cache Entry: 176
Web Open Font Format (Version 2), TrueType, length 27457, version 1.0
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (47123)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (6696), with no line terminators
downloaded
Chrome Cache Entry: 179
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 180
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (65507)
downloaded
Chrome Cache Entry: 182
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 183
ASCII text, with very long lines (6634)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (65463)
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (16380), with no line terminators
downloaded
Chrome Cache Entry: 186
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (54198)
downloaded
Chrome Cache Entry: 188
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 189
ASCII text, with very long lines (23093), with no line terminators
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (487), with no line terminators
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 192
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 193
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (65507)
downloaded
Chrome Cache Entry: 195
MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (65472)
downloaded
Chrome Cache Entry: 197
MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
dropped
There are 62 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2252 --field-trial-handle=2220,i,9979228790744850242,13951223927845644504,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79"

URLs

Name
IP
Malicious
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79
https://www.paypalobjects.com/web/res/606/438d50ecd521570fa11c69a9a17ef/jsx/payerview/payerViewBundle.js
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Regular.woff)
unknown
https://www.paypal.com/myaccount/privacy/cookieprefs/cookies?eventSource=afterPageLoad&page=main:inv3:desktoppayer::bnplmessaging:::&component=invoicingnodeweb
151.101.65.21
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://www.paypal.com/sdk/js?client-id=AcoSQ-EMf7YxRYtdNt1LFCvYyOe8ZDGvi7Jj7mzhEwq_uibxnztuzMVNWcAQpEuO2UBmrVVyFwbEi2a-&merchant-id=FPTDSZSSZ6VM4&components=buttons&enable-funding=credit,paylater,venmo,card&currency=USD&locale=en_US&disable-funding=bancontact,blik,eps,giropay,ideal,mercadopago,mybank,p24,sepa,sofort
151.101.65.21
https://www.recaptcha.net/recaptcha/enterprise/clr?k=6LdCCOUUAAAAAHTE-Snr6hi4HJGtJk_d1_ce-gWB
172.217.215.94
https://github.com/zloirock/core-js
unknown
https://www.paypal.com/invoice/wr-metadata/438d50ecd521570fa11c69a9a17ef?locale=en-US&timeZone=America/Los_Angeles&page=payerview
151.101.65.21
https://support.google.com/recaptcha#6262736
unknown
https://www.recaptcha.net/recaptcha/enterprise/anchor?ar=1&k=6LdCCOUUAAAAAHTE-Snr6hi4HJGtJk_d1_ce-gWB&co=aHR0cHM6Ly93d3cucGF5cGFsLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=invisible&cb=8ppk40nax8d
https://c.paypal.com/v1/r/d/b/w?f=f82837d6789541c9a7de63ab15a865f0&s=invoicingnodeweb_s_update&d=%7B%22rDT%22%3A%2221132%2C20927%2C27611%3A41634%2C41411%2C42978%3A46763%2C46530%2C46149%3A46779%2C46519%2C46124%3A10924%2C10654%2C10292%3A51919%2C51631%2C51246%3A51924%2C51627%2C51244%3A10951%2C10636%2C10264%3A36577%2C36243%2C35905%3A16091%2C15748%2C15385%3A21219%2C20867%2C20510%3A5867%2C5487%2C5168%3A41733%2C41344%2C41001%3A31504%2C31087%2C30789%3A46884%2C46449%2C46124%3A46889%2C46445%2C46147%3A26402%2C25949%2C25631%3A11044%2C10573%2C10292%3A11055%2C10565%2C10263%3A11066%2C10558%2C10292%3A18321%2C21%22%7D
151.101.193.21
about:blank
https://www.paypalobjects.com/web/res/606/438d50ecd521570fa11c69a9a17ef/jsx/payerview/payerViewBundle.css
151.101.130.133
https://www.paypalobjects.com/paypal-ui/logos/svg/paypal-mark-color.svg
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Regular.svg)
unknown
https://www.paypalobjects.com/paypal-ui/icons/v3/svg/download.svg
151.101.130.133
https://www.paypalobjects.com/digitalassets/c/paypal-ui/logos/svg/paypal-color.svg
151.101.130.133
https://www.paypal.com/xoplatform/logger/api/logger?disableSetCookie=true
151.101.65.21
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansSmall-Regular.woff2)
unknown
https://www.paypalobjects.com/web/res/644/8e2aa8780a4d9e791ce3c4a227dbc/js/client/4084.bundle.js
151.101.130.133
https://www.paypal.com/signin
151.101.193.21
https://www.paypal.com/csplog/api/log/csp
151.101.65.21
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansSmall-Regular.woff)
unknown
https://support.google.com/recaptcha/#6175971
unknown
https://tinyurl.com/y2uuvskb
unknown
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Regular.woff2
151.101.130.133
https://www.paypalobjects.com/pa/3pjs/qualtrics/1.64.1/17.0e47ac923c1fa85e46cf.chunk.js?Q_CLIENTVERSION=1.64.1&Q_CLIENTTYPE=hostedjs&Q_BRANDID=paypalxm
151.101.130.133
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79
https://c.paypal.com/v1/r/d/b/p1
151.101.193.21
https://www.paypalobjects.com/paypal-ui/fonts/PayPalOpen-Regular.woff2)
unknown
https://c.paypal.com/v1/r/d/b/p2
151.101.193.21
https://support.google.com/recaptcha
unknown
https://www.paypalobjects.com/paypal-ui/fonts/PayPalOpen-Regular.woff2
151.101.130.133
https://www.paypalobjects.com/paypal-ui/icons/font_icon/0-0-29/PPUI-Icons.eot?#iefix)
unknown
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansSmall-Regular.svg)
unknown
https://www.paypalobjects.com/paypal-ui/icons/font_icon/0-0-29/PPUI-Icons.svg)
unknown
https://t.paypal.com/ts?v=1.8.16&t=1713452003501&g=-120&pgrp=main%3Aprivacy%3Apolicy&page=main%3Aprivacy%3Apolicy%3Accpa&pgst=1713452002839&calc=f7632097f1927&nsid=r6lRnsuaXnayhjAHpU20-qsD-gnN1xSb&rsta=en_US&pgtf=Nodejs&env=live&s=ci&ccpg=US&csci=71efc635368946ce8b1a57c926c996f8&comp=invoicingnodeweb&tsrce=invoicingnodeweb&cu=0&ef_policy=ccpa&xe=109128%2C105410%2C105409%2C104759%2C109059%2C104406%2C104407&xt=143658%2C123956%2C123954%2C120842%2C143369%2C119037%2C119038&event_category=full_page_load&api_name=cookieBanner&displaypage=invoicingnodeweb%2F.dust&ppage=privacy_banner&bannertype=cookiebanner&flag=ccpa&bannerversion=v4&bannersource=ConsentNodeServ&eligibility_reason=true&is_native=false&cookie_disabled=false&event_name=cookie_banner_shown&e=ac
151.101.1.35
https://www.paypalobjects.com/paypal-ui/fonts/PayPalOpen-Bold.woff)
unknown
https://pics.paypal.com/00/s/MTQ3OVgxMzA5WEpQRw/p/ZWQ3MDNhOTMtZDc5MS00NTk0LTg1YjctY2E5NGYzZGNjODg4/image_109.JPG
151.101.129.21
https://www.paypalobjects.com/web/res/606/438d50ecd521570fa11c69a9a17ef/jsx/payerview/common_vendor.js
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalOpen-Bold.woff2
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Light.woff)
unknown
https://www.paypalobjects.com/pa/3pjs/qualtrics/1.64.1/12.2e4d3453d92fa382c1f6.chunk.js?Q_CLIENTVERSION=1.64.1&Q_CLIENTTYPE=hostedjs&Q_BRANDID=paypalxm
151.101.130.133
https://www.paypal.com/auth/recaptcha/grcenterprise_v3.html
https://www.paypalobjects.com/web/res/606/438d50ecd521570fa11c69a9a17ef/jsx/payerview/common_vendor.css
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Light.woff2)
unknown
https://b.stats.paypal.com/v2/counter.cgi?p=f82837d6789541c9a7de63ab15a865f0&s=invoicingnodeweb_s_update
35.235.122.5
https://www.paypal.com/invoice/s/pay/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79&isInitialLoad=true
151.101.65.21
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://www.paypalobjects.com/webcaptcha/ngrlCaptcha.min.js
151.101.130.133
https://www.paypalobjects.com/webstatic/icon/pp32.png
151.101.130.133
https://play.google.com/log?format=json&hasfast=true
unknown
https://t.paypal.com/ts?v=1.8.16&t=1713452003337&g=-120&e=ac&tsrce=unp&ppid=RT000274&space_key=SKCPAD&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&cnac=US&rsta=en_US(en-US)&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&s=ci&mail=sys&appVersion=1.246.0&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79&event_name=external_deep_link_processed
151.101.1.35
https://www.paypal.com/platform/tealeaftarget
151.101.65.21
https://www.paypalobjects.com/web/res/606/438d50ecd521570fa11c69a9a17ef/js/xhr-ads.min.js
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Medium.woff)
unknown
https://www.paypalobjects.com/web/res/644/8e2aa8780a4d9e791ce3c4a227dbc/js/client/792.bundle.js
151.101.130.133
https://www.paypal.com/auth/createchallenge/ee3b6d717afdb08b/recaptchav3.js?_sessionID=r6lRnsuaXnayhjAHpU20-qsD-gnN1xSb
151.101.65.21
https://www.paypalobjects.com/web/res/644/8e2aa8780a4d9e791ce3c4a227dbc/js/client/bundle.js
151.101.130.133
https://lvs.stats.paypal.com/v2/counter2.cgi?p=f82837d6789541c9a7de63ab15a865f0&s=invoicingnodeweb_s_update
35.235.122.5
https://www.paypal.com/myaccount/privacy/cookieprefs/cookies?eventSource=declineCookieBanner&page=invoicingnodeweb/.dust&component=invoicingnodeweb
151.101.65.21
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Regular.woff2)
unknown
https://www.paypalobjects.com/web/res/644/8e2aa8780a4d9e791ce3c4a227dbc/js/client/6053.bundle.js
151.101.130.133
https://api.sprig.com/sdk/1/environments/R1vNINtA1U/config
34.198.52.31
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Light.eot?#iefix)
unknown
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Light.svg)
unknown
https://www.paypal.com/favicon.ico
151.101.65.21
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Medium.woff2)
unknown
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Medium.woff2
151.101.130.133
https://www.paypalobjects.com/web/res/644/8e2aa8780a4d9e791ce3c4a227dbc/js/client/3995.bundle.js
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansBig-Medium.eot?#iefix)
unknown
https://www.gstatic.c..?/recaptcha/releases/rz4DvU-cY2JYCwHSTck0_qm-/recaptcha__.
unknown
https://www.paypalobjects.com/paypal-ui/icons/font_icon/0-0-29/PPUI-Icons.woff)
unknown
https://www.paypalobjects.com/js-sdk-logos/2.2.7/card-white.svg
151.101.130.133
https://cloud.google.com/contact
unknown
https://www.paypal.com/invoice/s/pdf/pay/INV2-39KY-4Q9V-5QK7-9H79?skipAuth=true&time=1713452016127&removeQr=false
https://www.paypalobjects.com/web/res/644/8e2aa8780a4d9e791ce3c4a227dbc/js/client/5761.bundle.js
151.101.130.133
https://www.paypalobjects.com/pa/mi/paypal/latmconf.js
151.101.130.133
https://www.recaptcha.net/recaptcha/enterprise/webworker.js?hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-
172.217.215.94
https://c6.paypal.com/v1/r/d/b/p3?f=f82837d6789541c9a7de63ab15a865f0&s=invoicingnodeweb_s_update
151.101.1.35
https://www.paypal.com/myaccount/privacy/cookiePrefs?locale=en_US
https://www.paypalobjects.com/webstatic/icon/favicon.ico
151.101.130.133
https://www.paypalobjects.com/pa/3pjs/qualtrics/1.64.1/1.1303dc17a61da0f506d3.chunk.js?Q_CLIENTVERSION=1.64.1&Q_CLIENTTYPE=hostedjs&Q_BRANDID=paypalxm
151.101.130.133
https://www.recaptcha.net/recaptcha/enterprise/reload?k=6LdCCOUUAAAAAHTE-Snr6hi4HJGtJk_d1_ce-gWB
172.217.215.94
https://www.paypal.com/error?code=404&ref=tealeaf
151.101.193.21
https://www.paypalobjects.com/pa/3pjs/qualtrics/1.64.1/CoreModule.js?Q_CLIENTVERSION=1.64.1&Q_CLIENTTYPE=hostedjs&Q_BRANDID=paypalxm
151.101.130.133
https://www.paypalobjects.com/pa/3pjs/qualtrics/1.64.1/OrchestratorMain.js
151.101.130.133
https://www.paypalobjects.com/paypal-ui/icons/font_icon/0-0-29/PPUI-Icons.woff2)
unknown
https://www.paypalobjects.com/pa/3pjs/tl/6.4.65/patleaf.js
151.101.130.133
https://www.paypal.com/invoice/s/pay/bnpl-messaging/INV2-39KY-4Q9V-5QK7-9H79
151.101.65.21
https://www.paypalobjects.com/paypal-ui/fonts/PayPalSansSmall-Regular.eot?#iefix)
unknown
https://www.recaptcha.net/recaptcha/enterprise.js?render=6LdCCOUUAAAAAHTE-Snr6hi4HJGtJk_d1_ce-gWB&hl=en
142.250.105.94
https://www.google.com/recaptcha/api2/
unknown
https://www.paypalobjects.com/pa/3pjs/tl/6.4.65/patlcfg.js
151.101.130.133
https://www.paypalobjects.com/paypal-ui/web/fonts-and-normalize/1-1-0/fonts-and-normalize.min.css
151.101.130.133
https://www.paypalobjects.com/paypal-ui/fonts/PayPalOpen-Regular.woff)
unknown
https://github.com/zloirock/core-js/blob/v3.30.1/LICENSE
unknown
https://www.paypalobjects.com/paypal-ui/web/icon-font/0-0-1/icon-font.min.css
151.101.130.133
https://www.paypalobjects.com/pa/js/pa.js
151.101.130.133
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
paypal.map.fastly.net
151.101.130.133
paypal-dynamic-2.map.fastly.net
151.101.1.35
dualstack.paypal-dynamic-2.map.fastly.net
151.101.1.35
cs1150.wpc.betacdn.net
192.229.210.155
paypal-dynamic.map.fastly.net
151.101.65.21
api.sprig.com
34.198.52.31
www.recaptcha.net
142.250.105.94
www.google.com
74.125.138.105
stats.glb.paypal.com
35.235.122.5
lvs.stats.paypal.com
35.235.122.5
c.paypal.com
unknown
c6.paypal.com
unknown
b.stats.paypal.com
unknown
zn1ynnliufrct75cb-paypalxm.siteintercept.qualtrics.com
unknown
pics.paypal.com
unknown
t.paypal.com
unknown
www.paypalobjects.com
unknown
www.paypal.com
unknown
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
34.198.52.31
api.sprig.com
United States
151.101.130.133
paypal.map.fastly.net
United States
3.228.185.195
unknown
United States
151.101.1.35
paypal-dynamic-2.map.fastly.net
United States
35.235.122.5
stats.glb.paypal.com
United States
192.168.2.6
unknown
unknown
192.168.2.5
unknown
unknown
151.101.129.35
unknown
United States
142.251.15.99
unknown
United States
172.217.215.94
unknown
United States
151.101.193.21
unknown
United States
74.125.138.105
www.google.com
United States
142.250.105.94
www.recaptcha.net
United States
192.229.210.155
cs1150.wpc.betacdn.net
United States
151.101.129.21
unknown
United States
239.255.255.250
unknown
Reserved
151.101.65.21
paypal-dynamic.map.fastly.net
United States
There are 7 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79
https://www.paypal.com/invoice/payerView/details/INV2-39KY-4Q9V-5QK7-9H79?locale.x=en_US&v=1&utm_source=unp&utm_medium=email&utm_campaign=RT000274&utm_unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&ppid=RT000274&cnac=US&rsta=en_US%28en-US%29&cust=&unptid=f3343294-fd8c-11ee-a9dd-3cecef442b8a&calc=4c4aae1cde8fb&unp_tpcid=invoice-buyer-reminder&page=main%3Aemail%3ART000274&pgrp=main%3Aemail&e=cl&mchn=em&s=ci&mail=sys&appVersion=1.246.0&tenant_name=&xt=145585%2C134643%2C104038%2C124817&link_ref=details_inv2-39ky-4q9v-5qk7-9h79
https://www.paypal.com/auth/recaptcha/grcenterprise_v3.html
https://www.paypal.com/auth/recaptcha/grcenterprise_v3.html
https://www.paypal.com/auth/recaptcha/grcenterprise_v3.html
about:blank
about:blank
about:blank
https://c.paypal.com/v1/r/d/i?js_src=https://c.paypal.com/da/r/fb.js
https://www.paypal.com/smart/buttons?fundingSource=paypal&allowBillingPayments=true&applePaySupport=false&buttonSessionID=uid_256ac9ee6b_mtq6ntm6mjy&buttonSize=medium&clientID=AcoSQ-EMf7YxRYtdNt1LFCvYyOe8ZDGvi7Jj7mzhEwq_uibxnztuzMVNWcAQpEuO2UBmrVVyFwbEi2a-&clientMetadataID=f82837d6789541c9a7de63ab15a865f0&commit=true&components.0=buttons&currency=USD&debug=false&disableFunding.0=bancontact&disableFunding.1=blik&disableFunding.2=eps&disableFunding.3=giropay&disableFunding.4=ideal&disableFunding.5=mercadopago&disableFunding.6=mybank&disableFunding.7=p24&disableFunding.8=sepa&disableFunding.9=sofort&disableSetCookie=true&enableFunding.0=credit&enableFunding.1=paylater&enableFunding.2=venmo&enableFunding.3=card&env=production&experiment.enableVenmo=false&flow=purchase&fundingEligibility=eyJwYXlwYWwiOnsiZWxpZ2libGUiOnRydWUsInZhdWx0YWJsZSI6ZmFsc2V9LCJwYXlsYXRlciI6eyJlbGlnaWJsZSI6ZmFsc2UsInZhdWx0YWJsZSI6ZmFsc2UsInByb2R1Y3RzIjp7InBheUluMyI6eyJlbGlnaWJsZSI6ZmFsc2UsInZhcmlhbnQiOm51bGx9LCJwYXlJbjQiOnsiZWxpZ2libGUiOmZhbH
https://www.paypal.com/smart/buttons?style.layout=vertical&style.color=black&style.shape=rect&style.tagline=false&style.menuPlacement=below&fundingSource=card&allowBillingPayments=true&applePaySupport=false&buttonSessionID=uid_bca41ff5b0_mtq6ntm6mjy&buttonSize=medium&clientID=AcoSQ-EMf7YxRYtdNt1LFCvYyOe8ZDGvi7Jj7mzhEwq_uibxnztuzMVNWcAQpEuO2UBmrVVyFwbEi2a-&clientMetadataID=f82837d6789541c9a7de63ab15a865f0&commit=true&components.0=buttons&currency=USD&debug=false&disableFunding.0=bancontact&disableFunding.1=blik&disableFunding.2=eps&disableFunding.3=giropay&disableFunding.4=ideal&disableFunding.5=mercadopago&disableFunding.6=mybank&disableFunding.7=p24&disableFunding.8=sepa&disableFunding.9=sofort&disableSetCookie=true&enableFunding.0=credit&enableFunding.1=paylater&enableFunding.2=venmo&enableFunding.3=card&env=production&experiment.enableVenmo=false&flow=purchase&fundingEligibility=eyJwYXlwYWwiOnsiZWxpZ2libGUiOnRydWUsInZhdWx0YWJsZSI6ZmFsc2V9LCJwYXlsYXRlciI6eyJlbGlnaWJsZSI6ZmFsc2UsInZhdWx0YWJsZSI6ZmFsc2UsInByb
https://www.recaptcha.net/recaptcha/enterprise/anchor?ar=1&k=6LdCCOUUAAAAAHTE-Snr6hi4HJGtJk_d1_ce-gWB&co=aHR0cHM6Ly93d3cucGF5cGFsLmNvbTo0NDM.&hl=en&v=rz4DvU-cY2JYCwHSTck0_qm-&size=invisible&cb=8ppk40nax8d
https://www.paypal.com/invoice/s/pdf/pay/INV2-39KY-4Q9V-5QK7-9H79?skipAuth=true&time=1713452016127&removeQr=false
https://www.paypal.com/myaccount/privacy/cookiePrefs?locale=en_US
https://www.paypal.com/myaccount/privacy/cookiePrefs?locale=en_US
There are 8 hidden doms, click here to show them.