Windows Analysis Report https://click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$

Overview

General Information

Sample URL: https://click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$
Analysis ID: 491721
Infos:

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

URL contains potential PII (phishing indication)

Classification

Phishing:

barindex
URL contains potential PII (phishing indication)
Source: https://click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$ Sample URL: PII: YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
Source: unknown DNS traffic detected: queries for: accounts.google.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49700
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49763
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49686
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49681
Source: unknown Network traffic detected: HTTP traffic on port 49702 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49701 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49688 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49679
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 49679 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49763 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49689 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 49681 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49702
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49701
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.41.209
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.26.236
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.26.236
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.26.236
Source: unknown TCP traffic detected without corresponding DNS query: 104.89.41.209
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.200
Source: unknown TCP traffic detected without corresponding DNS query: 131.253.33.200
Source: unknown TCP traffic detected without corresponding DNS query: 20.199.120.151
Source: unknown TCP traffic detected without corresponding DNS query: 20.199.120.151
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.9
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.9
Source: unknown TCP traffic detected without corresponding DNS query: 20.199.120.151
Source: unknown TCP traffic detected without corresponding DNS query: 20.199.120.151
Source: global traffic HTTP traffic detected: GET /v8.0/oemdiscovery?oemId=&scmId=&phoneManufacturerName=&smBiosManufacturerName=VMware%2C+Inc.&phoneDeviceModel=&smBiosDm=VMware7%2C1 HTTP/1.1Accept-Encoding: gzip, deflateAccept: */*TASIGNORE: YESMS-PreciseDeviceFamilyVersion: 2814750890000385User-Agent: WindowsStore/11712.1001.23.0MS-CV: bjBxWT9GdUWKFYOG.1Accept-Language: en-USHost: storeedgefd.dsx.mp.microsoft.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Thu, 20 Apr 2017 16:10:39 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global traffic HTTP traffic detected: GET /link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$ HTTP/1.1Host: click.mlsend.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-US&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-85.0.4183.121Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundDate: Mon, 27 Sep 2021 18:42:08 GMTTransfer-Encoding: chunkedConnection: closeStrict-Transport-Security: max-age=15724800; includeSubDomainsCF-Cache-Status: DYNAMICExpect-CT: max-age=604800, report-uri="https://report-uri.cloudflare.com/cdn-cgi/beacon/expect-ct"Server: cloudflareCF-RAY: 6956dec1bdbc021d-ZRH
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, manifest.json0.0.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://accounts.google.com
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, manifest.json0.0.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://apis.google.com
Source: Current Session.0.dr String found in binary or memory: https://click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28x
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.0.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.0.dr String found in binary or memory: https://content.googleapis.com
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 8943d8df-09ef-49d7-855f-9a1f66f4e4bd.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr, 3445d43a-94b1-457a-99fd-8f8b2e1257a5.tmp.2.dr String found in binary or memory: https://dns.google
Source: manifest.json0.0.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.googleapis.com;
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.0.dr String found in binary or memory: https://hangouts.google.com/
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.0.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://play.google.com
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr String found in binary or memory: https://r1---sn-1gi7znes.gvt1.com
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr String found in binary or memory: https://redirector.gvt1.com
Source: manifest.json.0.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json41.0.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, manifest.json0.0.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://www.google.com
Source: manifest.json.0.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.google.com;
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.0.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.0.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: a7021747-ac4c-491a-98f1-45a916561366.tmp.2.dr, 07eb20fb-69f4-44bb-bad7-2303dd5d1f2e.tmp.2.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.0.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown HTTP traffic detected: POST /ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard HTTP/1.1Host: accounts.google.comConnection: keep-aliveContent-Length: 1Origin: https://www.google.comContent-Type: application/x-www-form-urlencodedSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\3c5f0351-3d56-407e-9b1c-1698d3457834.tmp Jump to behavior
Source: classification engine Classification label: clean0.win@32/203@4/9
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'https://click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1632,7917245711965538015,1909696203157690960,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1692 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1632,7917245711965538015,1909696203157690960,131072 --lang=en-US --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1692 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-61528F0A-1A1C.pma Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Directory created: C:\Program Files\Google\Chrome\Application\Dictionaries\en-US-9-0.bdic Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs