Windows Analysis Report http://https:/click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$

Overview

General Information

Sample URL: http://https:/click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$
Analysis ID: 491722
Infos:

Most interesting Screenshot:

Detection

Score: 0
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

URL contains potential PII (phishing indication)

Classification

Phishing:

barindex
URL contains potential PII (phishing indication)
Source: http://https:/click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$ Sample URL: PII: YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$
Source: global traffic HTTP traffic detected: GET /service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=85.0.4183.121&lang=en-GB&acceptformat=crx3&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1&x=id%3Dpkedcjkdefgpdelpbcmbmeomcjbeemfm%26v%3D0.0.0.0%26installedby%3Dother%26uc%26ping%3Dr%253D-1%2526e%253D1 HTTP/1.1Host: clients2.google.comConnection: keep-aliveX-Goog-Update-Interactivity: fgX-Goog-Update-AppId: nmmhkkegccagdldgiimedpiccmgmieda,pkedcjkdefgpdelpbcmbmeomcjbeemfmX-Goog-Update-Updater: chromecrx-85.0.4183.121Sec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: global traffic HTTP traffic detected: GET /crx/blobs/Acy1k0bLIjHsvnKaKN_oRpVaYYvFs25d7GKYF1WXrT6yizCMksBO0c_ggE0B6tx6HPRHe6q1GOEe3_NcIbSiGG8kXeLMUY0sAKVvC6R89zvKM13s5VqoAMZSmuUgjQL5vlygJuArQghXXE_qTL7NlQ/extension_8520_615_0_5.crx HTTP/1.1Host: clients2.googleusercontent.comConnection: keep-aliveSec-Fetch-Site: noneSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.36Accept-Encoding: gzip, deflate, brAccept-Language: en-GB,en-US;q=0.9,en;q=0.8
Source: unknown DNS traffic detected: queries for: accounts.google.com
Source: Ruleset Data.1.dr String found in binary or memory: www.facebook.com equals www.facebook.com (Facebook)
Source: Ruleset Data.1.dr String found in binary or memory: www.facebook.com/ajax/ads/ equals www.facebook.com (Facebook)
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49685
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49693
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49691
Source: unknown Network traffic detected: HTTP traffic on port 49691 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49685 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49709
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49708
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49707
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: Current Session.1.dr String found in binary or memory: http://https/click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, manifest.json0.1.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://accounts.google.com
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, manifest.json0.1.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://apis.google.com
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://clients2.google.com
Source: manifest.json0.1.dr String found in binary or memory: https://clients2.google.com/service/update2/crx
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://clients2.googleusercontent.com
Source: manifest.json0.1.dr String found in binary or memory: https://content.googleapis.com
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, 8342e5f3-4432-45c3-913e-b99b008a26d4.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr, 99297bb2-56d6-41cc-853e-eb7a4d470f10.tmp.3.dr String found in binary or memory: https://dns.google
Source: manifest.json0.1.dr String found in binary or memory: https://feedback.googleusercontent.com
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://fonts.googleapis.com
Source: manifest.json0.1.dr String found in binary or memory: https://fonts.googleapis.com;
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://fonts.gstatic.com
Source: manifest.json0.1.dr String found in binary or memory: https://fonts.gstatic.com;
Source: manifest.json0.1.dr String found in binary or memory: https://hangouts.google.com/
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://ogs.google.com
Source: manifest.json.1.dr String found in binary or memory: https://payments.google.com/payments/v4/js/integrator.js
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://play.google.com
Source: ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://r5---sn-h0jeln7l.gvt1.com
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://redirector.gvt1.com
Source: manifest.json.1.dr String found in binary or memory: https://sandbox.google.com/payments/v4/js/integrator.js
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://ssl.gstatic.com
Source: messages.json83.1.dr String found in binary or memory: https://support.google.com/chromecast/answer/2998456
Source: messages.json83.1.dr String found in binary or memory: https://support.google.com/chromecast/troubleshooter/2995236
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, manifest.json0.1.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://www.google.com
Source: manifest.json.1.dr String found in binary or memory: https://www.google.com/
Source: manifest.json0.1.dr String found in binary or memory: https://www.google.com;
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://www.googleapis.com
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/calendar.readonly
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/cast-edu-messaging
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/chromewebstore.readonly
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/clouddevices
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/hangouts.readonly
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/meetings
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/plus.peopleapi.readwrite
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/sierra
Source: manifest.json.1.dr String found in binary or memory: https://www.googleapis.com/auth/sierrasandbox
Source: manifest.json0.1.dr String found in binary or memory: https://www.googleapis.com/auth/userinfo.email
Source: 85364a16-7c0a-4472-8ad5-d2b2d2c52347.tmp.3.dr, ed3e8e5e-b9f8-4320-84f2-f80fa26115b4.tmp.3.dr String found in binary or memory: https://www.gstatic.com
Source: manifest.json0.1.dr String found in binary or memory: https://www.gstatic.com;
Source: unknown HTTP traffic detected: POST /RST2.srf HTTP/1.0Connection: Keep-AliveContent-Type: application/soap+xmlAccept: */*User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 10.0; Win64; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729; IDCRL 18.10.0.17134.0.0; IDCRL-cfg 16.000.27716.00; App svchost.exe, 10.0.17134.1, {DF60E2DF-88AD-4526-AE21-83D130EF0F68})Content-Length: 4776Host: login.live.com
Source: unknown TCP traffic detected without corresponding DNS query: 209.197.3.8
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.185
Source: unknown TCP traffic detected without corresponding DNS query: 23.0.174.200
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 8.241.11.126
Source: unknown TCP traffic detected without corresponding DNS query: 8.241.11.126
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 2.22.152.11
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 209.197.3.8
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 209.197.3.8
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 40.126.31.140
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.9
Source: unknown TCP traffic detected without corresponding DNS query: 20.190.160.9
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: unknown TCP traffic detected without corresponding DNS query: 93.184.220.29
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Temp\4fd4e57a-bd65-4a5b-90ed-5167ff5cc709.tmp Jump to behavior
Source: classification engine Classification label: clean0.win@40/254@5/8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --start-maximized --enable-automation 'http://https:/click.mlsend.com/link/c/YT0xNzgwNTgyNzcyODUxNjEyMzc4JmM9YTJvMyZlPTAmYj03MzA5NDkyNzYmZD1qM28xcDl6.76kPI0GdTCuUeDG1YTAuaJ8I6DyQXZH3GTSNSDjlphU*nigel.collins@americold.com__;Iw!!OmjbmCgVfA!KAxDAIbWnQAQpz-nZZsFLtNNxM4mTFa_8QGVGGMhz1b-R28vylcQ4AL4lxQZS-l7WiQL$'
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1560,7090434380473497788,8775589663695397610,131072 --lang=en-GB --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1688 /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe 'C:\Program Files\Google\Chrome\Application\chrome.exe' --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1560,7090434380473497788,8775589663695397610,131072 --lang=en-GB --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1688 /prefetch:8 Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\BrowserMetrics\BrowserMetrics-615210D5-19B8.pma Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs