IOC Report
https://u44056869.ct.sendgrid.net/ls/click?upn=u001.nH1ryR-2Btr2av-2Bkfc8quLEXKlGRKFonctFf3nB-2FAP-2Bjae3IsQgCoKtK-2FQ57cEEmmhZzRyd07G16kQ6rsc4EaJT6S7Rh48kOVsBPHV-2Fkkk9Vfz7cojLOCLuj4sUGVMM7pbdmwtinmtiLhfYkhEkgve628OiJsccHyeYc3lkmkn6epsOmmj4-2Fi-2BWjxfm73m7vUzCOGnDWnQJBmmd6DmkDcfIw-3D-3DlLb9_7VBE-2B

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 18:53:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 18:53:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 18:53:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 18:53:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 23 18:53:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 101
HTML document, ASCII text, with very long lines (1048)
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (1437), with CRLF line terminators
downloaded
Chrome Cache Entry: 103
PNG image data, 2446 x 899, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (42414)
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (23398), with no line terminators
downloaded
Chrome Cache Entry: 106
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 107
Web Open Font Format, TrueType, length 36696, version 1.0
downloaded
Chrome Cache Entry: 108
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 109
JSON data
downloaded
Chrome Cache Entry: 110
PNG image data, 1174 x 1108, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 111
Web Open Font Format (Version 2), TrueType, length 28000, version 1.66
downloaded
Chrome Cache Entry: 112
Web Open Font Format (Version 2), TrueType, length 43596, version 1.0
downloaded
Chrome Cache Entry: 113
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 114
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (1222), with no line terminators
downloaded
Chrome Cache Entry: 116
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 117
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 118
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (597)
downloaded
Chrome Cache Entry: 120
HTML document, ASCII text
downloaded
Chrome Cache Entry: 121
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 122
HTML document, ASCII text, with very long lines (1048)
dropped
Chrome Cache Entry: 123
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 124
HTML document, ASCII text, with very long lines (59377), with CRLF line terminators
downloaded
Chrome Cache Entry: 125
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 126
HTML document, ASCII text, with very long lines (1048)
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (65461)
downloaded
Chrome Cache Entry: 128
PNG image data, 108 x 24, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 129
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 130
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 131
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 132
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (45667)
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 135
PNG image data, 32 x 67, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 136
PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 137
HTML document, ASCII text, with very long lines (1445), with CRLF line terminators
downloaded
Chrome Cache Entry: 138
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 139
PNG image data, 1174 x 1108, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 140
PNG image data, 32 x 67, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 141
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 89
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 90
Web Open Font Format (Version 2), TrueType, length 28584, version 1.66
downloaded
Chrome Cache Entry: 91
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 92
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 93
PNG image data, 2160 x 443, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 94
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 95
Web Open Font Format, TrueType, length 35970, version 1.0
downloaded
Chrome Cache Entry: 96
PNG image data, 506 x 303, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 97
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 98
JSON data
dropped
Chrome Cache Entry: 99
Web Open Font Format (Version 2), TrueType, length 93276, version 1.0
downloaded
There are 50 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1900,i,322101976962123545,3161144122731674671,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://u44056869.ct.sendgrid.net/ls/click?upn=u001.nH1ryR-2Btr2av-2Bkfc8quLEXKlGRKFonctFf3nB-2FAP-2Bjae3IsQgCoKtK-2FQ57cEEmmhZzRyd07G16kQ6rsc4EaJT6S7Rh48kOVsBPHV-2Fkkk9Vfz7cojLOCLuj4sUGVMM7pbdmwtinmtiLhfYkhEkgve628OiJsccHyeYc3lkmkn6epsOmmj4-2Fi-2BWjxfm73m7vUzCOGnDWnQJBmmd6DmkDcfIw-3D-3DlLb9_7VBE-2BPKrWdDFE8TeQU0FNoYmRNt3BbsAfHCQfpyMVcUv91cWM1GbR6tMnpfVZqwoeCii1Z-2FHB6Wp4CGi-2FJ4Nq2flvhbRyRKwbWUqyssDslf87wBQZbBQ0EZsTXlvzjuj1ZnarL4QCJJlvUup-2FiM-2F9GPG6X3nhhKKp6sQ0v-2BBs5Jrrpzc3e5B2aUKKEJUx1Hjrx3xc16wmpK1HmM2sLiNIweMaJlJ9frDis7-2BK565mLw-3D"

URLs

Name
IP
Malicious
https://u44056869.ct.sendgrid.net/ls/click?upn=u001.nH1ryR-2Btr2av-2Bkfc8quLEXKlGRKFonctFf3nB-2FAP-2Bjae3IsQgCoKtK-2FQ57cEEmmhZzRyd07G16kQ6rsc4EaJT6S7Rh48kOVsBPHV-2Fkkk9Vfz7cojLOCLuj4sUGVMM7pbdmwtinmtiLhfYkhEkgve628OiJsccHyeYc3lkmkn6epsOmmj4-2Fi-2BWjxfm73m7vUzCOGnDWnQJBmmd6DmkDcfIw-3D-3DlLb9_7VBE-2BPKrWdDFE8TeQU0FNoYmRNt3BbsAfHCQfpyMVcUv91cWM1GbR6tMnpfVZqwoeCii1Z-2FHB6Wp4CGi-2FJ4Nq2flvhbRyRKwbWUqyssDslf87wBQZbBQ0EZsTXlvzjuj1ZnarL4QCJJlvUup-2FiM-2F9GPG6X3nhhKKp6sQ0v-2BBs5Jrrpzc3e5B2aUKKEJUx1Hjrx3xc16wmpK1HmM2sLiNIweMaJlJ9frDis7-2BK565mLw-3D
malicious
https://o5u7g.zleu9.com/XhaQEKHwmqeXiuCbMVTRVruGRjRPRIDWFUPFICPEYZGBHMWGEVVPPBXVQDKEPFCXWUJ?MCFKKCTFWYSAEFPSCNVZQJIUBPpheTomFVBFOCNFEXHSGGZYDODQKSWFTPNMNKEYPKASTONRVGUROOMDEYM#
malicious
https://o5u7g.zleu9.com/O5u7Gw/
malicious
https://O5u7G.zleu9.com/O5u7Gw/
unknown
malicious
https://o5u7g.zleu9.com/XhaQEKHwmqeXiuCbMVTRVruGRjRPRIDWFUPFICPEYZGBHMWGEVVPPBXVQDKEPFCXWUJ?MCFKKCTFWYSAEFPSCNVZQJIUBPpheTomFVBFOCNFEXHSGGZYDODQKSWFTPNMNKEYPKASTONRVGUROOMDEYM
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/tbxob/0x4AAAAAAAXj4ylnvzeCbeUc/auto/normal
https://code.jquery.com/jquery-3.6.0.min.js
151.101.194.137
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://o5u7g.zleu9.com/wxU2EPAQmKCucHi94Nct3opto7kIWmKk6EPt8vWRE90180
172.67.143.205
https://assets-usa.mkt.dynamics.com/4df527c8-5afd-ee11-9048-000d3a10682d/digitalassets/forms/845fbd3
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/pat/879066af2d254527/1713902022573/2c54c2e92cd6a1adf7ce103072c3ed1a2e53daac1a2c103e1868b6da0e2a356b/KqKxEDIwFgWsKX_
104.17.3.184
https://support.google.com/recaptcha#6262736
unknown
https://assets-usa.mkt.dynamics.com/4df527c8-5afd-ee11-9048-000d3a10682d/digitalassets/images/1cf4ec
unknown
https://o5u7g.zleu9.com/ioA9WkaHpGHbSxWyGOmyjZ4CeUqai9zYvvo9IvKLdFjDvXel
172.67.143.205
https://assets-usa.mkt.dynamics.com/favicon.ico
13.107.246.41
https://o5u7g.zleu9.com/efhiWlN0k9o3QYTD34NIiKf6YeHKyzkl100
172.67.143.205
https://o5u7g.zleu9.com/mndHSfQb7XvbrLZM9aX9ijbdgEYSAxo5cJl78150
172.67.143.205
https://support.google.com/recaptcha/?hl=en#6223828
unknown
https://o5u7g.zleu9.com/45lqabaypR8xixiJ6pi09abYdPVRJTWCXvw70
172.67.143.205
https://cloud.google.com/contact
unknown
https://public-usa.mkt.dynamics.com/api/v1.0/orgs/4df527c8-5afd-ee11-9048-000d3a10682d/landingpagefo
unknown
https://o5u7g.zleu9.com/web8socket/socket.io/?type=User&appnum=1&EIO=4&transport=websocket
172.67.143.205
https://a.nel.cloudflare.com/report/v4?s=Y7V3%2Fn6U%2F5sNHmUZQd93nQsa0GOvwG2%2FnqGaIIa3ZNHQALwgfFQn6mtTnUbnh%2FBXtTQtKsu87S%2BaRDTq9bT4tnQtuKBX8wJwnMeo9eLg6qB%2BCQn5lwebysOUTfRuAA%3D%3D
35.190.80.1
https://assets-usa.mkt.dynamics.com/4df527c8-5afd-ee11-9048-000d3a10682d/digitalassets/images/1cf4ecdd-c500-ef11-a1fd-7c1e521c0288?ts=638494003333783206
13.107.246.41
https://a.nel.cloudflare.com/report/v4?s=HuGAIXqQUHUwoTYEVZ%2FLXVAHfKcrKLZho2oWL0hdPyB1xFXQKec8fDnsXSoBen%2FANSad0as%2Be%2FJL41ZAJLMLZek3%2FbwBkF45GMNcZomG6tN9WvynUFWaQKraFvhQ3A%3D%3D
35.190.80.1
https://www.google.com/recaptcha/api.js
172.253.124.99
https://support.google.com/recaptcha/#6175971
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/cmg/1/wh0E0SXYnx6pTBdJW%2Fl926I%2BPRUplRdtQz3K9lHXs%2Fs%3D
104.17.3.184
https://o5u7g.zleu9.com/klOBAXKkM7zxA0PBXtuGSU6IpHSSzXjjkyJZcdNfRjNwpgHUKsNeFPOpTVPLe578167
172.67.143.205
https://o5u7g.zleu9.com/56AdOYKMMLgoJxyRlCwu18915
172.67.143.205
https://assets-usa.mkt.dynamics.com/4df527c8-5afd-ee11-9048-000d3a10682d/digitalassets/standaloneforms/845fbd3d-a401-ef11-a1fd-7c1e521c0288
https://www.google.com/recaptcha/api2/
unknown
https://assets-usa.mkt.dynamics.com/4df527c8-5afd-ee11-9048-000d3a10682d/digitalassets/forms/845fbd3d-a401-ef11-a1fd-7c1e521c0288
13.107.246.41
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/flow/ov1/693555097:1713899458:awaYsz5cS08XnYE1eWdisJAHNg9uYwgpGaBpyil3TXY/879066af2d254527/783a92b798bfbc6
104.17.3.184
https://support.google.com/recaptcha
unknown
https://o5u7g.zleu9.com/uv6N4AFPttA1rsB4OrhISLW7u68mn9vUiv3nGs2KGxWywnndfrLnMDhNBKWNovufref260
172.67.143.205
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/i/879066af2d254527/1713902022571/cfsO0aDF5k_W65H
104.17.3.184
https://o5u7g.zleu9.com/opPltSeSUXK9DHBf9DPq9LBD1mnqke1dpQ2aQUfvH45131
172.67.143.205
https://cloud.google.com/recaptcha-enterprise/billing-information
unknown
https://recaptcha.net
unknown
https://www.apache.org/licenses/
unknown
https://o5u7g.zleu9.com/favicon.ico
172.67.143.205
https://u44056869.ct.sendgrid.net/ls/click?upn=u001.nH1ryR-2Btr2av-2Bkfc8quLEXKlGRKFonctFf3nB-2FAP-2Bjae3IsQgCoKtK-2FQ57cEEmmhZzRyd07G16kQ6rsc4EaJT6S7Rh48kOVsBPHV-2Fkkk9Vfz7cojLOCLuj4sUGVMM7pbdmwtinmtiLhfYkhEkgve628OiJsccHyeYc3lkmkn6epsOmmj4-2Fi-2BWjxfm73m7vUzCOGnDWnQJBmmd6DmkDcfIw-3D-3DlLb9_7VBE-2BPKrWdDFE8TeQU0FNoYmRNt3BbsAfHCQfpyMVcUv91cWM1GbR6tMnpfVZqwoeCii1Z-2FHB6Wp4CGi-2FJ4Nq2flvhbRyRKwbWUqyssDslf87wBQZbBQ0EZsTXlvzjuj1ZnarL4QCJJlvUup-2FiM-2F9GPG6X3nhhKKp6sQ0v-2BBs5Jrrpzc3e5B2aUKKEJUx1Hjrx3xc16wmpK1HmM2sLiNIweMaJlJ9frDis7-2BK565mLw-3D
167.89.123.16
https://o5u7g.zleu9.com/oprLHzrLMng80jZ02qEKLjc5gebwyGRZI3hfJd0cfOTOSMcWKHstAxOa6DJMyy9rR893W0bISCPqBNcd237
172.67.143.205
https://www.gstatic.c..?/recaptcha/releases/QoukH5jSO3sKFzVEA7Vc8VgC/recaptcha__.
unknown
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/orchestrate/chl_api/v1?ray=879066af2d254527
104.17.3.184
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://o5u7g.zleu9.com/90LHee5UjNMUuFaF7C23ZIhMnMnuv58
172.67.143.205
https://play.google.com/log?format=json&hasfast=true
unknown
https://developers.google.com/recaptcha/docs/faq#are-there-any-qps-or-daily-limits-on-my-use-of-reca
unknown
https://cdn.socket.io/4.6.0/socket.io.min.js
99.84.108.67
https://o5u7g.zleu9.com/uvReLdUstUtCbWsqopShVHLQdjK9um4BlP12130
172.67.143.205
https://public-usa.mkt.dynamics.com/api/v1.0/orgs/4df527c8-5afd-ee11-9048-000d3a10682d/landingpageforms/forms/845fbd3d-a401-ef11-a1fd-7c1e521c0288
52.146.76.30
https://o5u7g.zleu9.com/pqEwuigvKgPpV6LFzQ34GsmKuv38
172.67.143.205
https://o5u7g.zleu9.com/12K3yC85Zl4Gjr78g8Ljxqr50
172.67.143.205
https://o5u7g.zleu9.com/hwQyLxyNOyWBlYH9r31Ztr
172.67.143.205
https://public-usa.mkt.dynamics.com/api/v1.0/orgs/4df527c8-5afd-ee11-9048-000d3a10682d/landingpageforms/forms/845fbd3d-a401-ef11-a1fd-7c1e521c0288/visits
52.146.76.30
https://o5u7g.zleu9.com/90HTVtl1EQGeUVQ777gjOfGgcdMHIfEQyz73
172.67.143.205
https://o5u7g.zleu9.com/O5u7Gw/?Z
172.67.143.205
https://o5u7g.zleu9.com/mnl2tHQ07yj2qZbGoQPLc2rws7XKCbM9CrmJtCNM7qbSB856rqfsEpXq5H383Fjyek8KV2n6SNuv220
172.67.143.205
https://o5u7g.zleu9.com/3409ErMmbVIWH6V2dQUQwijgLL2yQXIIAO89104
172.67.143.205
https://o5u7g.zleu9.com/xyt4uiudpq34gh30
172.67.143.205
There are 51 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
part-0013.t-0009.t-msedge.net
13.107.246.41
a.nel.cloudflare.com
35.190.80.1
code.jquery.com
151.101.194.137
d2vgu95hoyrpkh.cloudfront.net
99.84.108.67
challenges.cloudflare.com
104.17.2.184
www.google.com
74.125.136.103
prdia888eus0aks.mkt.dynamics.com
52.146.76.30
o5u7g.zleu9.com
172.67.143.205
u44056869.ct.sendgrid.net
167.89.123.16
fp2e7a.wpc.phicdn.net
192.229.211.108
public-usa.mkt.dynamics.com
unknown
assets-usa.mkt.dynamics.com
unknown
cdn.socket.io
unknown
There are 4 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.41
part-0013.t-0009.t-msedge.net
United States
167.89.123.16
u44056869.ct.sendgrid.net
United States
172.253.124.99
unknown
United States
99.84.108.67
d2vgu95hoyrpkh.cloudfront.net
United States
52.146.76.30
prdia888eus0aks.mkt.dynamics.com
United States
192.168.2.5
unknown
unknown
104.17.3.184
unknown
United States
172.67.143.205
o5u7g.zleu9.com
United States
239.255.255.250
unknown
Reserved
13.107.213.41
unknown
United States
74.125.136.103
www.google.com
United States
151.101.194.137
code.jquery.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
104.17.2.184
challenges.cloudflare.com
United States
There are 4 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://o5u7g.zleu9.com/XhaQEKHwmqeXiuCbMVTRVruGRjRPRIDWFUPFICPEYZGBHMWGEVVPPBXVQDKEPFCXWUJ?MCFKKCTFWYSAEFPSCNVZQJIUBPpheTomFVBFOCNFEXHSGGZYDODQKSWFTPNMNKEYPKASTONRVGUROOMDEYM
malicious
https://o5u7g.zleu9.com/XhaQEKHwmqeXiuCbMVTRVruGRjRPRIDWFUPFICPEYZGBHMWGEVVPPBXVQDKEPFCXWUJ?MCFKKCTFWYSAEFPSCNVZQJIUBPpheTomFVBFOCNFEXHSGGZYDODQKSWFTPNMNKEYPKASTONRVGUROOMDEYM#
malicious
https://assets-usa.mkt.dynamics.com/4df527c8-5afd-ee11-9048-000d3a10682d/digitalassets/standaloneforms/845fbd3d-a401-ef11-a1fd-7c1e521c0288
https://assets-usa.mkt.dynamics.com/4df527c8-5afd-ee11-9048-000d3a10682d/digitalassets/standaloneforms/845fbd3d-a401-ef11-a1fd-7c1e521c0288
https://o5u7g.zleu9.com/O5u7Gw/
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/tbxob/0x4AAAAAAAXj4ylnvzeCbeUc/auto/normal
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/b/turnstile/if/ov2/av0/rcv0/0/tbxob/0x4AAAAAAAXj4ylnvzeCbeUc/auto/normal