Analysis Report https://spark.adobe.com/page/BBFX2xdruIRdi/

Overview

General Information

Sample URL: https://spark.adobe.com/page/BBFX2xdruIRdi/
Analysis ID: 384874
Infos:

Most interesting Screenshot:

Detection

HTMLPhisher
Score: 80
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Phishing site detected (based on shot template match)
Yara detected HtmlPhish10
Yara detected HtmlPhish7
HTML body contains low number of good links
HTML title does not match URL

Classification

AV Detection:

barindex
Antivirus / Scanner detection for submitted sample
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ SlashNext: detection malicious, Label: Fake Login Page type: Phishing & Social Engineering
Antivirus detection for URL or domain
Source: https://nicklaussglen.buzz/011/ SlashNext: Label: Fake Login Page type: Phishing & Social Engineering
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/?page-mode=static SlashNext: Label: Fake Login Page type: Phishing & Social Engineering

Phishing:

barindex
Phishing site detected (based on shot template match)
Source: https://nicklaussglen.buzz/011/ Matcher: Template: outlook matched
Yara detected HtmlPhish10
Source: Yara match File source: 760639.2.links.csv, type: HTML
Source: Yara match File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\011[1].htm, type: DROPPED
Yara detected HtmlPhish7
Source: Yara match File source: 760639.2.links.csv, type: HTML
Source: Yara match File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\MEEXW4H4\011[1].htm, type: DROPPED
HTML body contains low number of good links
Source: https://nicklaussglen.buzz/011/ HTTP Parser: Number of links: 0
Source: https://nicklaussglen.buzz/011/ HTTP Parser: Number of links: 0
HTML title does not match URL
Source: https://nicklaussglen.buzz/011/ HTTP Parser: Title: Share Point Online does not match URL
Source: https://nicklaussglen.buzz/011/ HTTP Parser: Title: Share Point Online does not match URL
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: Title: PROPOSAL INVITAION does not match URL
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: Title: PROPOSAL INVITAION does not match URL
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: Title: PROPOSAL INVITAION does not match URL
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: Title: PROPOSAL INVITAION does not match URL
Source: https://nicklaussglen.buzz/011/ HTTP Parser: No <meta name="author".. found
Source: https://nicklaussglen.buzz/011/ HTTP Parser: No <meta name="author".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="author".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="author".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="author".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="author".. found
Source: https://nicklaussglen.buzz/011/ HTTP Parser: No <meta name="copyright".. found
Source: https://nicklaussglen.buzz/011/ HTTP Parser: No <meta name="copyright".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="copyright".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="copyright".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="copyright".. found
Source: https://spark.adobe.com/page/BBFX2xdruIRdi/ HTTP Parser: No <meta name="copyright".. found
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Source: unknown HTTPS traffic detected: 99.86.3.88:443 -> 192.168.2.3:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 99.86.3.88:443 -> 192.168.2.3:49714 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49717 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49719 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.216.239.117:443 -> 192.168.2.3:49725 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.216.239.117:443 -> 192.168.2.3:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.169.45:443 -> 192.168.2.3:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.3:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.3:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.3:49751 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.3:49752 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.148.64:443 -> 192.168.2.3:49764 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.148.64:443 -> 192.168.2.3:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.30.135.179:443 -> 192.168.2.3:49766 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.30.135.179:443 -> 192.168.2.3:49765 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.20.184.68:443 -> 192.168.2.3:49767 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.20.184.68:443 -> 192.168.2.3:49768 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.3:49772 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.3:49771 version: TLS 1.2
Source: unknown HTTPS traffic detected: 99.86.3.69:443 -> 192.168.2.3:49774 version: TLS 1.2
Source: unknown HTTPS traffic detected: 99.86.3.69:443 -> 192.168.2.3:49775 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.16.66:443 -> 192.168.2.3:49777 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.16.66:443 -> 192.168.2.3:49776 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.212.164.82:443 -> 192.168.2.3:49779 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.16.185.223:443 -> 192.168.2.3:49782 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.251.60.147:443 -> 192.168.2.3:49783 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.251.60.147:443 -> 192.168.2.3:49784 version: TLS 1.2
Source: unknown HTTPS traffic detected: 54.73.76.208:443 -> 192.168.2.3:49787 version: TLS 1.2
Source: unknown HTTPS traffic detected: 54.73.76.208:443 -> 192.168.2.3:49788 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.127.52.31:443 -> 192.168.2.3:49793 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.127.52.31:443 -> 192.168.2.3:49794 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.29.132.69:443 -> 192.168.2.3:49796 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.29.132.69:443 -> 192.168.2.3:49797 version: TLS 1.2
Source: unknown HTTPS traffic detected: 15.237.136.106:443 -> 192.168.2.3:49795 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.174.68:443 -> 192.168.2.3:49798 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.174.68:443 -> 192.168.2.3:49799 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.217.168.66:443 -> 192.168.2.3:49800 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.217.168.66:443 -> 192.168.2.3:49801 version: TLS 1.2
Source: unknown HTTPS traffic detected: 216.58.215.227:443 -> 192.168.2.3:49805 version: TLS 1.2
Source: unknown HTTPS traffic detected: 216.58.215.227:443 -> 192.168.2.3:49804 version: TLS 1.2
Source: global traffic HTTP traffic detected: GET /011 HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: nicklaussglen.buzzConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /011/ HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateConnection: Keep-AliveHost: nicklaussglen.buzz
Source: unsupported[1].htm.3.dr String found in binary or memory: <a href="https://www.facebook.com/AdobeSpark" target="_blank" data-analytics-context="footer" data-type="facebook" equals www.facebook.com (Facebook)
Source: scripts[1].js1.3.dr String found in binary or memory: if ($a.href.startsWith('https://www.facebook.')) { equals www.facebook.com (Facebook)
Source: scripts[1].js1.3.dr String found in binary or memory: if ($a.href.startsWith('https://www.linkedin.com')) { equals www.linkedin.com (Linkedin)
Source: scripts[1].js1.3.dr String found in binary or memory: if ($a.href.startsWith('https://www.youtube.com')) { equals www.youtube.com (Youtube)
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: <a id="gnav_1244" href="http://www.facebook.com/adobe" class="feds-navLink" target="_blank" data-feds-action="none" data-feds-element="link" daa-ll="Facebook-1"> equals www.facebook.com (Facebook)
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: <a id="gnav_1254" href="https://www.linkedin.com/company/adobe" class="feds-navLink" target="_blank" data-feds-action="none" data-feds-element="link" daa-ll="LinkedIn-3"> equals www.linkedin.com (Linkedin)
Source: unknown DNS traffic detected: queries for: page.adobespark-assets.com
Source: aksb.min[1].js.3.dr String found in binary or memory: http://code.google.com/p/episodes/
Source: m-unsupported-201552f0[1].js.3.dr String found in binary or memory: http://feross.org
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: http://github.com/janl/mustache.js
Source: hover[1].css.3.dr String found in binary or memory: http://ianlunn.co.uk/
Source: hover[1].css.3.dr String found in binary or memory: http://ianlunn.github.io/Hover/)
Source: publish.combined.fp-edc06d2196a984377367d5bc5109f275[1].js.3.dr String found in binary or memory: http://jedwatson.github.io/classnames
Source: chrome[1].js.3.dr String found in binary or memory: http://mathiasbynens.be/demo/url-regex
Source: m-unsupported-201552f0[1].js.3.dr String found in binary or memory: http://medialize.github.io/URI.js/
Source: BBFX2xdruIRdi[1].htm.3.dr String found in binary or memory: http://nicklaussglen.buzz/011
Source: popper.min[1].js.3.dr String found in binary or memory: http://opensource.org/licenses/MIT).
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000000000ffd9
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000132df
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000132e1
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000132e3
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000158d3
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000158d4
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000158d6
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000158d7
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000158d8
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000158d9
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000000001705b
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/0000000000000000000176ff
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/000000000000000000017701
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/000000000000000000017703
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/000000000000000000017706
Source: rbi5aua[1].js0.3.dr String found in binary or memory: http://typekit.com/eulas/000000000000000000017709
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9aee45
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9aee47
Source: onz5gap[1].js1.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3068
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3f83
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3f84
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3f85
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3f86
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3f88
Source: onz5gap[1].js1.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3f8a
Source: pps7abe[1].css0.3.dr String found in binary or memory: http://typekit.com/eulas/00000000000000003b9b3f8c
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: http://underscorejs.org/LICENSE
Source: marvelcommon-bb979c0a[1].js.3.dr, scripts[1].js1.3.dr, aksb.min[1].js.3.dr String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: chrome[1].js.3.dr String found in binary or memory: http://www.iport.it)
Source: m-unsupported-201552f0[1].js.3.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: http://www.opensource.org/licenses/mit-license.html
Source: RC1a83c357d323419db9d2ba211efeeaae-file.min[1].js.3.dr String found in binary or memory: https://ade0164.d41.co/sync/
Source: {40F7FB7C-99CC-11EB-90E4-ECF4BB862DED}.dat.1.dr String found in binary or memory: https://adobe.demdex.net/dest5.html?d_nsid=0
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://adobesearch.adobe.io/autocomplete/completions
Source: unsupported[1].htm.3.dr String found in binary or memory: https://adobespark.uservoice.com
Source: en-US_bundle-1b00eb00[1].js.3.dr String found in binary or memory: https://adobespark.zendesk.com/hc/en-us/articles/218956027
Source: en-US_bundle-1b00eb00[1].js.3.dr String found in binary or memory: https://adobespark.zendesk.com/hc/en-us/articles/219243657
Source: en-US_bundle-1b00eb00[1].js.3.dr String found in binary or memory: https://adobespark.zendesk.com/hc/en-us/articles/219243657-Can-students-use-Adobe-Spark-
Source: login[1].htm2.3.dr, unsupported[1].htm.3.dr String found in binary or memory: https://adobespark.zendesk.com/hc/en-us/categories/202688167-Adobe-Spark
Source: unsupported[1].htm.3.dr String found in binary or memory: https://adobespark.zendesk.com/hc/en-us/requests/new
Source: resume[1].htm.3.dr, logo[1].htm.3.dr String found in binary or memory: https://adobesparkpost.app.link/g8sk4xb8AV
Source: express[1].htm.3.dr String found in binary or memory: https://adobesparkpost.app.link/jsoIbkwCVeb
Source: express[1].htm.3.dr String found in binary or memory: https://adobesparkpost.app.link/nfQW2NoCVeb
Source: 011[1].htm.3.dr String found in binary or memory: https://ajax.googleapis.com/ajax/libs/jquery/2.2.4/jquery.min.js
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://apps.apple.com/sg/app/adobe-creative-cloud/id852473028
Source: express[1].htm.3.dr String found in binary or memory: https://apps.apple.com/us/app/adobe-spark-post-create-stunning/id1051937863
Source: login[1].htm2.3.dr String found in binary or memory: https://assets.adobedtm.com
Source: RC1a4f9c4f0d8a4bba917d5412b0c552b7-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC1a4f9c4f0d8a4bba917d5412b0c552b
Source: RC1a83c357d323419db9d2ba211efeeaae-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC1a83c357d323419db9d2ba211efeeaa
Source: RC1bc70f0c17a44296971da4381a721bda-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC1bc70f0c17a44296971da4381a721bd
Source: RC32e8eb91f06d47d18918e9b9bcc17a00-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC32e8eb91f06d47d18918e9b9bcc17a0
Source: RC419dbb68baed4e699648e06bb8cb6515-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC419dbb68baed4e699648e06bb8cb651
Source: RC508044d39da1421eb31de2476af8ac1e-source.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC508044d39da1421eb31de2476af8ac1
Source: RC6f46e43fa6d44dbeb45cc5801ffded0e-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC6f46e43fa6d44dbeb45cc5801ffded0
Source: RC7e9f4c1a441d45af93bf75d76d872cf0-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC7e9f4c1a441d45af93bf75d76d872cf
Source: RC89c6d3bd15f043db95a5a0a4b5cc9da0-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RC89c6d3bd15f043db95a5a0a4b5cc9da
Source: RCbbd93c1920fd422b84787f67ddbfbe55-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RCbbd93c1920fd422b84787f67ddbfbe5
Source: RCe26b98274fee43abbdb260d3b3d8fefc-file.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/d4d114c60e50/f3fbfbe0e7ca/bffb9ea23c0c/RCe26b98274fee43abbdb260d3b3d8fef
Source: launch-EN919758db9a654a17bac7d184b99c4820.min[1].js.3.dr String found in binary or memory: https://assets.adobedtm.com/launch-EN919758db9a654a17bac7d184b99c4820.js
Source: scripts[1].js1.3.dr String found in binary or memory: https://blog.adobespark.com/
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://cc-collab.adobe.io/profile
Source: login[1].htm2.3.dr String found in binary or memory: https://cdn.cookielaw.org
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://cdn.cookielaw.org/scripttemplates/otSDKStub.js
Source: 7a5eb705-95ed-4cc4-a11d-0cc5760e93db[1].js.3.dr String found in binary or memory: https://cdn.cookielaw.org/vendorlist/googleData.json
Source: 7a5eb705-95ed-4cc4-a11d-0cc5760e93db[1].js.3.dr String found in binary or memory: https://cdn.cookielaw.org/vendorlist/iab2Data.json
Source: 7a5eb705-95ed-4cc4-a11d-0cc5760e93db[1].js.3.dr String found in binary or memory: https://cdn.cookielaw.org/vendorlist/iabData.json
Source: 011[1].htm.3.dr String found in binary or memory: https://cdnjs.cloudflare.com/ajax/libs/popper.js/1.12.9/umd/popper.min.js
Source: 011[1].htm.3.dr String found in binary or memory: https://code.jquery.com/jquery-3.1.1.min.js
Source: 011[1].htm.3.dr String found in binary or memory: https://code.jquery.com/jquery-3.2.1.slim.min.js
Source: 011[1].htm.3.dr String found in binary or memory: https://code.jquery.com/jquery-3.3.1.js
Source: RC1bc70f0c17a44296971da4381a721bda-file.min[1].js.3.dr String found in binary or memory: https://connect.facebook.net/en_US/fbevents.js
Source: headIE.fp-457d9bd744a6e226ae87a5aeb36fb5c4[1].js.3.dr String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/API/NodeList/forEach
Source: publish.combined.fp-edc06d2196a984377367d5bc5109f275[1].js.3.dr String found in binary or memory: https://fb.me/react-polyfills
Source: m-unsupported-201552f0[1].js.3.dr String found in binary or memory: https://feross.org
Source: free.min[1].css.3.dr String found in binary or memory: https://fontawesome.com
Source: free.min[1].css.3.dr String found in binary or memory: https://fontawesome.com/license/free
Source: 011[1].htm.3.dr String found in binary or memory: https://fonts.googleapis.com/css?family=Yellowtail&display=swap
Source: css[1].css.3.dr String found in binary or memory: https://fonts.gstatic.com/s/yellowtail/v11/OZpGg_pnoDtINPfRIlLohlvHxw.woff)
Source: 7a5eb705-95ed-4cc4-a11d-0cc5760e93db[1].js.3.dr String found in binary or memory: https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location
Source: bootstrap.min[1].css.3.dr, bootstrap.min[1].js.3.dr String found in binary or memory: https://getbootstrap.com)
Source: hover[1].css.3.dr String found in binary or memory: https://github.com/IanLunn/Hover
Source: head.fp-1c6b8ee3dfac8039d9ead67e8b6d6138[1].js.3.dr String found in binary or memory: https://github.com/focus-trap/focus-trap/blob/master/LICENSE
Source: head.fp-1c6b8ee3dfac8039d9ead67e8b6d6138[1].js.3.dr String found in binary or memory: https://github.com/focus-trap/tabbable/blob/master/LICENSE
Source: chrome[1].js.3.dr String found in binary or memory: https://github.com/janl/mustache.js/issues/186
Source: chrome[1].js.3.dr String found in binary or memory: https://github.com/janl/mustache.js/issues/189
Source: chrome[1].js.3.dr String found in binary or memory: https://github.com/janl/mustache.js/issues/244
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: https://github.com/kriskowal/q/blob/v1/LICENSE
Source: bootstrap.min[1].css.3.dr, bootstrap.min[1].js.3.dr String found in binary or memory: https://github.com/twbs/bootstrap/blob/master/LICENSE)
Source: bootstrap.min[1].js.3.dr String found in binary or memory: https://github.com/twbs/bootstrap/graphs/contributors)
Source: chrome[1].js.3.dr String found in binary or memory: https://issues.apache.org/jira/browse/COUCHDB-577
Source: 585b051251[1].js.3.dr String found in binary or memory: https://ka-f.fontawesome.com
Source: 585b051251[1].js.3.dr String found in binary or memory: https://kit.fontawesome.com
Source: 011[1].htm.3.dr String found in binary or memory: https://kit.fontawesome.com/585b051251.js
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: https://lodash.com/
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: https://lodash.com/license
Source: 011[1].htm.3.dr String found in binary or memory: https://login.microsoftonline.com/common/login
Source: 011[1].htm.3.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/css/bootstrap.min.css
Source: 011[1].htm.3.dr String found in binary or memory: https://maxcdn.bootstrapcdn.com/bootstrap/4.0.0/js/bootstrap.min.js
Source: {40F7FB7C-99CC-11EB-90E4-ECF4BB862DED}.dat.1.dr String found in binary or memory: https://nicklaussglen.buzz/011/
Source: {40F7FB7C-99CC-11EB-90E4-ECF4BB862DED}.dat.1.dr String found in binary or memory: https://nicklaussglen.buzz/011/$Share
Source: ~DFA6731248B7E9CF32.TMP.1.dr String found in binary or memory: https://nicklaussglen.buzz/011/X2xdruIRdi/images/83634061-e5cf-4347-adb9-fcd6e83fb247.jpg?asset_id=b
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: https://npms.io/search?q=ponyfill.
Source: marvelcommon-bb979c0a[1].js.3.dr String found in binary or memory: https://openjsf.org/
Source: en-US_bundle-1b00eb00[1].js.3.dr String found in binary or memory: https://opsparc.gsfc.nasa.gov/?sdid=MC95SNMJ&mv=social
Source: rbi5aua[1].js0.3.dr, onz5gap[1].js1.3.dr, vtg4qoo[1].js0.3.dr String found in binary or memory: https://p.typekit.net/p.gif
Source: RCbbd93c1920fd422b84787f67ddbfbe55-file.min[1].js.3.dr String found in binary or memory: https://p13n-stage.adobe.io/psdk/v2/content
Source: RCbbd93c1920fd422b84787f67ddbfbe55-file.min[1].js.3.dr String found in binary or memory: https://p13n.adobe.io/psdk/v2/content
Source: BBFX2xdruIRdi[1].htm.3.dr String found in binary or memory: https://page.adobespark-assets.com/runtime/1.22/base-fonts.gz.js
Source: BBFX2xdruIRdi[1].htm.3.dr, imagestore.dat.3.dr, ~DFA6731248B7E9CF32.TMP.1.dr String found in binary or memory: https://page.adobespark-assets.com/runtime/1.22/images/favicon.ico
Source: BBFX2xdruIRdi[1].htm.3.dr String found in binary or memory: https://page.adobespark-assets.com/runtime/1.22/noscript.gz.css
Source: BBFX2xdruIRdi[1].htm.3.dr String found in binary or memory: https://page.adobespark-assets.com/runtime/1.22/runtime-prod.gz.js
Source: BBFX2xdruIRdi[1].htm.3.dr String found in binary or memory: https://page.adobespark-assets.com/runtime/1.22/runtime.gz.css
Source: BBFX2xdruIRdi[1].htm.3.dr String found in binary or memory: https://page.adobespark-assets.com/runtime/1.22/themes/crisp-fonts.gz.js
Source: BBFX2xdruIRdi[1].htm.3.dr String found in binary or memory: https://page.adobespark-assets.com/runtime/1.22/typekit-load.gz.js
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://play.google.com/store/apps/details?id=com.adobe.cc
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://prod.adobeccstatic.com/appl/latest/AppLauncher.css
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://prod.adobeccstatic.com/appl/latest/AppLauncher.js
Source: publish.combined.fp-edc06d2196a984377367d5bc5109f275[1].js.3.dr String found in binary or memory: https://reactjs.org/docs/error-decoder.html?invariant=
Source: {40F7FB7C-99CC-11EB-90E4-ECF4BB862DED}.dat.1.dr String found in binary or memory: https://servedby.flashtalking.com/container/13539;99030;10307;iframe/?ftXRef=&ftXValue=&ftXType=&ftX
Source: {40F7FB7C-99CC-11EB-90E4-ECF4BB862DED}.dat.1.dr String found in binary or memory: https://spark.ado
Source: {40F7FB7C-99CC-11EB-90E4-ECF4BB862DED}.dat.1.dr String found in binary or memory: https://spark.adobe.co
Source: login[1].htm2.3.dr String found in binary or memory: https://static.adobelogin.com&#x2F;imslib/imslib.min.js
Source: privacy[1].htm0.3.dr String found in binary or memory: https://static.adobelogin.com/imslib/imslib.min.js
Source: unsupported[1].htm.3.dr String found in binary or memory: https://support.apple.com/downloads/safari
Source: scripts[1].js1.3.dr String found in binary or memory: https://twitter.com
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://twitter.com/Adobe
Source: unsupported[1].htm.3.dr String found in binary or memory: https://twitter.com/AdobeSpark
Source: onz5gap[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/180c9d/00000000000000003b9b3f8a/27/
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/1da05b/0000000000000000000132df/27/
Source: onz5gap[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/37eaae/00000000000000003b9b3f83/27/
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/37eaae/00000000000000003b9b3f83/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/37eaae/00000000000000003b9b3f83/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/37eaae/00000000000000003b9b3f83/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/3d913c/000000000000000000017709/26/
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/40207f/0000000000000000000176ff/27/
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/4b3e87/000000000000000000017706/27/
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/6c57c4/0000000000000000000158d6/26/
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/74fc30/0000000000000000000158d4/26/
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/8f4e31/0000000000000000000132e3/27/
Source: onz5gap[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/949f99/00000000000000003b9b3068/27/
Source: onz5gap[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/97fbd1/00000000000000003b9b3f88/27/
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/97fbd1/00000000000000003b9b3f88/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/97fbd1/00000000000000003b9b3f88/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/97fbd1/00000000000000003b9b3f88/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: scripts[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/97fbd1/00000000000000003b9b3f88/27/l?primer=7cdcb44be4a7db8877ffa5c0007b8
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/9951d2/0000000000000000000158d7/26/
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/9d1933/00000000000000000001705b/26/
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/a0c22f/00000000000000003b9b3f84/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/a0c22f/00000000000000003b9b3f84/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/a0c22f/00000000000000003b9b3f84/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/aa41d0/00000000000000003b9b3f86/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/aa41d0/00000000000000003b9b3f86/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/aa41d0/00000000000000003b9b3f86/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/ad2a79/00000000000000003b9b3f8c/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/ad2a79/00000000000000003b9b3f8c/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/ad2a79/00000000000000003b9b3f8c/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: scripts[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/ad2a79/00000000000000003b9b3f8c/27/l?primer=7cdcb44be4a7db8877ffa5c0007b8
Source: onz5gap[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/b0c5f5/00000000000000003b9b3f85/27/
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/b0c5f5/00000000000000003b9b3f85/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/b0c5f5/00000000000000003b9b3f85/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/b0c5f5/00000000000000003b9b3f85/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: scripts[1].js1.3.dr String found in binary or memory: https://use.typekit.net/af/b0c5f5/00000000000000003b9b3f85/27/l?primer=7cdcb44be4a7db8877ffa5c0007b8
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/c8f445/00000000000000003b9aee47/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/c8f445/00000000000000003b9aee47/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/c8f445/00000000000000003b9aee47/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/cb695f/000000000000000000017701/27/
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/d5d9b2/00000000000000000000ffd9/26/
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/d8f71f/0000000000000000000132e1/27/
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/e030d3/0000000000000000000158d3/26/
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/e09494/00000000000000003b9aee45/27/a?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/e09494/00000000000000003b9aee45/27/d?primer=388f68b35a7cbf1ee3543172445c2
Source: pps7abe[1].css0.3.dr String found in binary or memory: https://use.typekit.net/af/e09494/00000000000000003b9aee45/27/l?primer=388f68b35a7cbf1ee3543172445c2
Source: vtg4qoo[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/eaf09c/000000000000000000017703/27/
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/edcf1e/0000000000000000000158d9/26/
Source: rbi5aua[1].js0.3.dr String found in binary or memory: https://use.typekit.net/af/fe9c8e/0000000000000000000158d8/26/
Source: privacy[1].htm0.3.dr String found in binary or memory: https://use.typekit.net/pps7abe.css
Source: login[1].htm2.3.dr String found in binary or memory: https://use.typekit.net/vtg4qoo.css
Source: unsupported[1].htm.3.dr String found in binary or memory: https://use.typekit.net/vtg4qoo.js
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://www.adobe.io/
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://www.adobeexchange.com/
Source: RC1a4f9c4f0d8a4bba917d5412b0c552b7-file.min[1].js.3.dr String found in binary or memory: https://www.everestjs.net/static/le/last-event-tag-latest.min.js
Source: scripts[1].js1.3.dr String found in binary or memory: https://www.facebook.
Source: unsupported[1].htm.3.dr String found in binary or memory: https://www.google.com/chrome/browser/desktop/index.html
Source: chrome[1].js.3.dr String found in binary or memory: https://www.googletagmanager.com/gtag/js?
Source: scripts[1].js1.3.dr String found in binary or memory: https://www.instagram.com
Source: unsupported[1].htm.3.dr String found in binary or memory: https://www.instagram.com/AdobeSpark
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://www.instagram.com/adobe/
Source: scripts[1].js1.3.dr String found in binary or memory: https://www.linkedin.com
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://www.linkedin.com/company/adobe
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://www.marketo.com/
Source: unsupported[1].htm.3.dr String found in binary or memory: https://www.mozilla.org/firefox
Source: scripts[1].js1.3.dr String found in binary or memory: https://www.pinterest.
Source: www.adobe.com[2].htm.3.dr String found in binary or memory: https://www.workfront.com/
Source: scripts[1].js1.3.dr String found in binary or memory: https://www.youtube.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 49800 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49794 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49805
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49804
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49801
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49800
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765
Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49719 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49793 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49797 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49719
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 49715 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49715
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49794
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49793
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49804 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown HTTPS traffic detected: 99.86.3.88:443 -> 192.168.2.3:49715 version: TLS 1.2
Source: unknown HTTPS traffic detected: 99.86.3.88:443 -> 192.168.2.3:49714 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49718 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49717 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49719 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.25.66:443 -> 192.168.2.3:49720 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.216.239.117:443 -> 192.168.2.3:49725 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.216.239.117:443 -> 192.168.2.3:49724 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.67.169.45:443 -> 192.168.2.3:49740 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.3:49745 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.18.10.207:443 -> 192.168.2.3:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.3:49751 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.19.94:443 -> 192.168.2.3:49752 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.148.64:443 -> 192.168.2.3:49764 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.16.148.64:443 -> 192.168.2.3:49763 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.30.135.179:443 -> 192.168.2.3:49766 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.30.135.179:443 -> 192.168.2.3:49765 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.20.184.68:443 -> 192.168.2.3:49767 version: TLS 1.2
Source: unknown HTTPS traffic detected: 104.20.184.68:443 -> 192.168.2.3:49768 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.3:49772 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.181.18.61:443 -> 192.168.2.3:49771 version: TLS 1.2
Source: unknown HTTPS traffic detected: 99.86.3.69:443 -> 192.168.2.3:49774 version: TLS 1.2
Source: unknown HTTPS traffic detected: 99.86.3.69:443 -> 192.168.2.3:49775 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.16.66:443 -> 192.168.2.3:49777 version: TLS 1.2
Source: unknown HTTPS traffic detected: 13.32.16.66:443 -> 192.168.2.3:49776 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.212.164.82:443 -> 192.168.2.3:49779 version: TLS 1.2
Source: unknown HTTPS traffic detected: 52.16.185.223:443 -> 192.168.2.3:49782 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.251.60.147:443 -> 192.168.2.3:49783 version: TLS 1.2
Source: unknown HTTPS traffic detected: 34.251.60.147:443 -> 192.168.2.3:49784 version: TLS 1.2
Source: unknown HTTPS traffic detected: 54.73.76.208:443 -> 192.168.2.3:49787 version: TLS 1.2
Source: unknown HTTPS traffic detected: 54.73.76.208:443 -> 192.168.2.3:49788 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.127.52.31:443 -> 192.168.2.3:49793 version: TLS 1.2
Source: unknown HTTPS traffic detected: 3.127.52.31:443 -> 192.168.2.3:49794 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.29.132.69:443 -> 192.168.2.3:49796 version: TLS 1.2
Source: unknown HTTPS traffic detected: 185.29.132.69:443 -> 192.168.2.3:49797 version: TLS 1.2
Source: unknown HTTPS traffic detected: 15.237.136.106:443 -> 192.168.2.3:49795 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.174.68:443 -> 192.168.2.3:49798 version: TLS 1.2
Source: unknown HTTPS traffic detected: 35.244.174.68:443 -> 192.168.2.3:49799 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.217.168.66:443 -> 192.168.2.3:49800 version: TLS 1.2
Source: unknown HTTPS traffic detected: 172.217.168.66:443 -> 192.168.2.3:49801 version: TLS 1.2
Source: unknown HTTPS traffic detected: 216.58.215.227:443 -> 192.168.2.3:49805 version: TLS 1.2
Source: unknown HTTPS traffic detected: 216.58.215.227:443 -> 192.168.2.3:49804 version: TLS 1.2
Source: classification engine Classification label: mal80.phis.win@3/280@30/22
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\High Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File created: C:\Users\user\AppData\Local\Temp\~DFD1D3DBE1258A3BD2.TMP Jump to behavior
Source: C:\Program Files\internet explorer\iexplore.exe File read: C:\Users\desktop.ini Jump to behavior
Source: unknown Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5808 CREDAT:17410 /prefetch:2
Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:5808 CREDAT:17410 /prefetch:2 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior
Source: Contact_72px_lt-gray[1].svg.3.dr Binary or memory string: NEIBESjjzwKWaQEmuhbGgACFWDKdB5OZZSX+agjjkcZegD1y0h+ELA7oCf9h2TzH5Lk87RNpJWUz
Source: LawEnforcement_72px_lt-gray[1].svg.3.dr Binary or memory string: 4RfwbOThACGyTEZ5moRPrV2QweL6BvvMQAZIZXEdT2O5NEPgUsRJGSwFUuYlgyhgfSp3NY2hgKUv
Source: Policies_72px_lt-gray[1].svg.3.dr Binary or memory string: 4tB1EVplopO2rztHQjrQqeMUbUqdlUYbWkVkAS0rzSFGk5qfcFFaK8X2oKw7N1FayNdH7BQ+Tst9
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 384874 URL: https://spark.adobe.com/pag... Startdate: 10/04/2021 Architecture: WINDOWS Score: 80 15 page.adobespark-assets.com 2->15 17 clientconfig.passport.net 2->17 25 Antivirus detection for URL or domain 2->25 27 Antivirus / Scanner detection for submitted sample 2->27 29 Phishing site detected (based on shot template match) 2->29 31 2 other signatures 2->31 7 iexplore.exe 6 67 2->7         started        signatures3 process4 process5 9 iexplore.exe 7 354 7->9         started        dnsIp6 19 pixel-origin.mathtag.com 185.29.132.69, 443, 49796, 49797 MEDIAMATH-INCUS United Kingdom 9->19 21 googleads.g.doubleclick.net 172.217.168.66, 443, 49800, 49801 GOOGLEUS United States 9->21 23 39 other IPs or domains 9->23 13 C:\Users\user\AppData\Local\...\011[1].htm, HTML 9->13 dropped file7
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs

Contacted Public IPs

IP Domain Country Flag ASN ASN Name Malicious
104.18.10.207
maxcdn.bootstrapcdn.com United States
13335 CLOUDFLARENETUS false
3.127.52.31
aa-agkn-com-https-2145740884.eu-central-1.elb.amazonaws.com United States
16509 AMAZON-02US false
99.86.3.88
spark.adobeprojectm.com United States
16509 AMAZON-02US false
104.16.148.64
cdn.cookielaw.org United States
13335 CLOUDFLARENETUS false
104.20.184.68
geolocation.onetrust.com United States
13335 CLOUDFLARENETUS false
172.217.168.66
googleads.g.doubleclick.net United States
15169 GOOGLEUS false
13.32.25.66
page.adobespark-assets.com United States
7018 ATT-INTERNET4US false
52.16.185.223
services.prod.ims.adobejanus.com United States
16509 AMAZON-02US false
52.216.239.117
s3.amazonaws.com United States
16509 AMAZON-02US false
172.67.169.45
nicklaussglen.buzz United States
13335 CLOUDFLARENETUS false
52.212.164.82
adobe.tt.omtrdc.net United States
16509 AMAZON-02US false
216.58.215.227
www.google.ch United States
15169 GOOGLEUS false
15.237.136.106
demdex.net.ssl.sc.omtrdc.net United States
16509 AMAZON-02US false
52.30.135.179
dcs-edge-irl1-876252164.eu-west-1.elb.amazonaws.com United States
16509 AMAZON-02US false
54.73.76.208
adobelogin-origin.prod.ims.adobejanus.com United States
16509 AMAZON-02US false
34.251.60.147
unknown United States
16509 AMAZON-02US false
99.86.3.69
api.demandbase.com United States
16509 AMAZON-02US false
35.181.18.61
adobe.com.ssl.d1.sc.omtrdc.net United States
16509 AMAZON-02US false
185.29.132.69
pixel-origin.mathtag.com United Kingdom
30419 MEDIAMATH-INCUS false
13.32.16.66
dd20fzx9mj46f.cloudfront.net United States
7018 ATT-INTERNET4US false
35.244.174.68
idsync.rlcdn.com United States
15169 GOOGLEUS false
104.16.19.94
cdnjs.cloudflare.com United States
13335 CLOUDFLARENETUS false

Contacted Domains

Name IP Active
dd20fzx9mj46f.cloudfront.net 13.32.16.66 true
pixel-origin.mathtag.com 185.29.132.69 true
adobelogin-origin.prod.ims.adobejanus.com 54.73.76.208 true
services.prod.ims.adobejanus.com 52.16.185.223 true
maxcdn.bootstrapcdn.com 104.18.10.207 true
dcs-edge-irl1-876252164.eu-west-1.elb.amazonaws.com 52.30.135.179 true
spark.adobeprojectm.com 99.86.3.88 true
idsync.rlcdn.com 35.244.174.68 true
s3.amazonaws.com 52.216.239.117 true
googleads.g.doubleclick.net 172.217.168.66 true
nicklaussglen.buzz 172.67.169.45 true
cdnjs.cloudflare.com 104.16.19.94 true
adobe.com.ssl.d1.sc.omtrdc.net 35.181.18.61 true
api.demandbase.com 99.86.3.69 true
aa-agkn-com-https-2145740884.eu-central-1.elb.amazonaws.com 3.127.52.31 true
demdex.net.ssl.sc.omtrdc.net 15.237.136.106 true
adobe.tt.omtrdc.net 52.212.164.82 true
www.google.ch 216.58.215.227 true
page.adobespark-assets.com 13.32.25.66 true
cdn.cookielaw.org 104.16.148.64 true
geolocation.onetrust.com 104.20.184.68 true
ka-f.fontawesome.com unknown unknown
ims-na1.adobelogin.com unknown unknown
ds-aksb-a.akamaihd.net unknown unknown
cm.everesttech.net unknown unknown
code.jquery.com unknown unknown
adobedc.demdex.net unknown unknown
dpm.demdex.net unknown unknown
aa.agkn.com unknown unknown
static.adobelogin.com unknown unknown
adobe.demdex.net unknown unknown
use.typekit.net unknown unknown
kit.fontawesome.com unknown unknown
assets.adobedtm.com unknown unknown
p.typekit.net unknown unknown
clientconfig.passport.net unknown unknown
sync.mathtag.com unknown unknown

Contacted URLs

Name Malicious Antivirus Detection Reputation
https://nicklaussglen.buzz/011/ true
  • SlashNext: Fake Login Page type: Phishing & Social Engineering
unknown