IOC Report
https://www.maultalk.com/url.php?to=https://www.serserijeans.com/gdy9haBM2BM2Fe5rss3RhBM2i2Pdk17x0qvi2PFe5nnaai2PrpWO3rk17dy9s3RWO3BM2

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 50
Unicode text, UTF-8 (with BOM) text, with very long lines (523), with CRLF line terminators
downloaded
Chrome Cache Entry: 51
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1420x946, components 3
downloaded
Chrome Cache Entry: 52
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 53
PNG image data, 383 x 125, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 54
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 1420x946, components 3
dropped
Chrome Cache Entry: 55
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 56
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141339
downloaded
Chrome Cache Entry: 57
PNG image data, 383 x 125, 8-bit/color RGBA, non-interlaced
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2256 --field-trial-handle=2180,i,16645406805787686568,15006377985678471521,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.maultalk.com/url.php?to=https://www.serserijeans.com/gdy9haBM2BM2Fe5rss3RhBM2i2Pdk17x0qvi2PFe5nnaai2PrpWO3rk17dy9s3RWO3BM2"

URLs

Name
IP
Malicious
https://www.maultalk.com/url.php?to=https://www.serserijeans.com/gdy9haBM2BM2Fe5rss3RhBM2i2Pdk17x0qvi2PFe5nnaai2PrpWO3rk17dy9s3RWO3BM2
malicious
https://www.maultalk.com/url.php?to=https://www.serserijeans.com/gdy9haBM2BM2Fe5rss3RhBM2i2Pdk17x0qvi2PFe5nnaai2PrpWO3rk17dy9s3RWO3BM2
172.67.129.156
https://fs.viennaairport.com/adfs/portal/illustration/illustration.jpg?id=118FB0D9D56244BD5AFE03D3F85A97AA9AF77AACF57B15DC95B46DC287C2C180
193.43.158.108
https://login.microsoftonline.com/?organisation=viennaairport.com&username=g.hammerschmidt%40viennaairport.com#/common/authorize?document=0.71510277768369-0ff1-0.88917616609911&auth=10.66378078081821-0.23214203409485
https://fs.viennaairport.com/adfs/portal/logo/logo.png?id=D116A9A391AA333DE42BBDB7F41A6EE30B0FEB4A9E4F4B333B5655A8428A5362
193.43.158.108
https://esign.joahelms.design/?organisation=viennaairport.com&dse=Zy5oYW1tZXJzY2htaWR0QHZpZW5uYWFpcnBvcnQuY29t#/common/authorize?document=0.71510277768369-0ff1-0.88917616609911&auth=10.66378078081821-0.23214203409485
https://fs.viennaairport.com/adfs/ls/?login_hint=g.hammerschmidt%40viennaairport.com&client-request-id=e4661904-c8f1-440d-98e1-717e5bb7657e&username=g.hammerschmidt%40viennaairport.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuARYJNOefDzB6zLjYWFd9PbUulWMyoSN0L_AyPiCkXESk2K6XkZibm5qUXFyRm5mSolDWWZqXl5iYmYRSDNI6S0mQf-idM-U8GK31JTUosSSzPy8R8yE9V1gEXjFwmPAbMXBwSXAIMGgwPCDhXERK9DFQt_0z6ZbrfbqKP_Q-fiNCMMpVn1PV98I_bzE4mxfx4giE9PS4KCo5Aojv_Jy_wxDp6ycYssk7cSgZJ_ULM9IWwMrwwlsQhPYmE6xMXxgY-xgZ5jFznCAk_EAL8MPviv9nesPdMx857FBgAEA0&pullStatus=0
https://fs.viennaairport.com/favicon.ico
193.43.158.108
https://www.serserijeans.com/gdy9haBM2BM2Fe5rss3RhBM2i2Pdk17x0qvi2PFe5nnaai2PrpWO3rk17dy9s3RWO3BM2
185.106.211.102
https://fs.viennaairport.com/adfs/ls/?login_hint=g.hammerschmidt%40viennaairport.com&client-request-id=e4661904-c8f1-440d-98e1-717e5bb7657e&username=g.hammerschmidt%40viennaairport.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuARYJNOefDzB6zLjYWFd9PbUulWMyoSN0L_AyPiCkXESk2K6XkZibm5qUXFyRm5mSolDWWZqXl5iYmYRSDNI6S0mQf-idM-U8GK31JTUosSSzPy8R8yE9V1gEXjFwmPAbMXBwSXAIMGgwPCDhXERK9DFQt_0z6ZbrfbqKP_Q-fiNCMMpVn1PV98I_bzE4mxfx4giE9PS4KCo5Aojv_Jy_wxDp6ycYssk7cSgZJ_ULM9IWwMrwwlsQhPYmE6xMXxgY-xgZ5jFznCAk_EAL8MPviv9nesPdMx857FBgAEA0
193.43.158.108
https://serserijeans.com/gdy9haBM2BM2Fe5rss3RhBM2i2Pdk17x0qvi2PFe5nnaai2PrpWO3rk17dy9s3RWO3BM2
185.106.211.102
https://esign.joahelms.design/?organisation=viennaairport.com&dse=Zy5oYW1tZXJzY2htaWR0QHZpZW5uYWFpcnBvcnQuY29t
89.187.28.219
https://fs.viennaairport.com/adfs/portal/css/style.css?id=36478A6D134BE3AAFBB086EE217D3815A49AC0E7AA0A3FD8DA2403A595467E17
193.43.158.108
There are 2 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.214.172
fs.viennaairport.com
193.43.158.108
www.maultalk.com
172.67.129.156
esign.joahelms.design
89.187.28.219
part-0041.t-0009.t-msedge.net
13.107.213.69
serserijeans.com
185.106.211.102
www.google.com
142.250.101.105
fp2e7a.wpc.phicdn.net
192.229.211.108
identity.nel.measure.office.net
unknown
login.microsoftonline.com
unknown
www.serserijeans.com
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.101.105
www.google.com
United States
192.168.2.6
unknown
unknown
89.187.28.219
esign.joahelms.design
Ukraine
13.107.213.69
part-0041.t-0009.t-msedge.net
United States
239.255.255.250
unknown
Reserved
172.67.129.156
www.maultalk.com
United States
185.106.211.102
serserijeans.com
Turkey
193.43.158.108
fs.viennaairport.com
Austria

DOM / HTML

URL
Malicious
https://esign.joahelms.design/?organisation=viennaairport.com&dse=Zy5oYW1tZXJzY2htaWR0QHZpZW5uYWFpcnBvcnQuY29t#/common/authorize?document=0.71510277768369-0ff1-0.88917616609911&auth=10.66378078081821-0.23214203409485
https://esign.joahelms.design/?organisation=viennaairport.com&dse=Zy5oYW1tZXJzY2htaWR0QHZpZW5uYWFpcnBvcnQuY29t#/common/authorize?document=0.71510277768369-0ff1-0.88917616609911&auth=10.66378078081821-0.23214203409485
https://login.microsoftonline.com/?organisation=viennaairport.com&username=g.hammerschmidt%40viennaairport.com#/common/authorize?document=0.71510277768369-0ff1-0.88917616609911&auth=10.66378078081821-0.23214203409485
https://fs.viennaairport.com/adfs/ls/?login_hint=g.hammerschmidt%40viennaairport.com&client-request-id=e4661904-c8f1-440d-98e1-717e5bb7657e&username=g.hammerschmidt%40viennaairport.com&wa=wsignin1.0&wtrealm=urn%3afederation%3aMicrosoftOnline&wctx=estsredirect%3d2%26estsrequest%3drQQIARAA42Kw0skoKSkottLXL8gvKknM0cvNTC7KL85PK8nPy8nMS9VLzs_Vyy9Kz0wBsYqEuARYJNOefDzB6zLjYWFd9PbUulWMyoSN0L_AyPiCkXESk2K6XkZibm5qUXFyRm5mSolDWWZqXl5iYmYRSDNI6S0mQf-idM-U8GK31JTUosSSzPy8R8yE9V1gEXjFwmPAbMXBwSXAIMGgwPCDhXERK9DFQt_0z6ZbrfbqKP_Q-fiNCMMpVn1PV98I_bzE4mxfx4giE9PS4KCo5Aojv_Jy_wxDp6ycYssk7cSgZJ_ULM9IWwMrwwlsQhPYmE6xMXxgY-xgZ5jFznCAk_EAL8MPviv9nesPdMx857FBgAEA0&pullStatus=0