IOC Report
https://proofpoint.onelogin.sso-signon.com/

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 44
Web Open Font Format (Version 2), TrueType, length 19196, version 1.0
downloaded
Chrome Cache Entry: 45
PNG image data, 1 x 1, 1-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 46
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 47
PNG image data, 1 x 1, 1-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 48
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 928x1160, components 3
dropped
Chrome Cache Entry: 49
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 50
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 51
HTML document, ASCII text, with very long lines (309)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2084 --field-trial-handle=1968,i,9740115810024139992,438052550857420297,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://proofpoint.onelogin.sso-signon.com/"

URLs

Name
IP
Malicious
https://proofpoint.onelogin.sso-signon.com/
malicious
https://proofpoint.onelogin.sso-signon.com/
malicious
https://proofpoint.onelogin.sso-signon.com/favicon.ico
3.144.141.109
https://images.unsplash.com/photo-1525547719571-a2d4ac8945e2?ixlib=rb-1.2.1&ixid=MnwxMjA3fDB8MHxwaG9
unknown
https://images.unsplash.com/photo-1525547719571-a2d4ac8945e2?ixlib=rb-1.2.1&ixid=MnwxMjA3fDB8MHxwaG90by1wYWdlfHx8fGVufDB8fHx8&auto=format&fit=crop&w=928&q=80
151.101.2.208

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
www.google.com
74.125.136.103
proofpoint.onelogin.sso-signon.com
3.144.141.109
dualstack.com.imgix.map.fastly.net
151.101.2.208
fp2e7a.wpc.phicdn.net
192.229.211.108
images.unsplash.com
unknown

IPs

IP
Domain
Country
Malicious
3.144.141.109
proofpoint.onelogin.sso-signon.com
United States
192.168.2.4
unknown
unknown
151.101.2.208
dualstack.com.imgix.map.fastly.net
United States
239.255.255.250
unknown
Reserved
151.101.66.208
unknown
United States
74.125.136.103
www.google.com
United States

DOM / HTML

URL
Malicious
https://proofpoint.onelogin.sso-signon.com/