| URL: | https://broadridgefinancial-mid-prod8.campaign.adobe.com/r/?id=h11336a3,214e086,80a8e&p1=redirect-20250729-676090001-us-east-1.s3.us-east-1.amazonaws.com/parg#87634598Family=ai5icmVtbmVyQG1hbGluZ3JvdXAuY29t https://broadridgefinancial-mid-prod8.campaign.adobe.com/r/?id=h11336a3,214e086,80a8e&p1=redirect-20250729-676090001-us-east-1.s3.us-east-1.amazonaws.com/parg#87634598Family=ai5icmVtbmVyQG1hbGluZ3JvdXAuY29t |
| Full analysis: | https://app.any.run/tasks/983f98ad-41d6-4d28-8265-0646dcabce63 |
| Verdict: | Malicious activity |
| Analysis date: | January 13, 2026, 14:16:53 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 0BDB70EEB39F9E496D0028996F37F436 |
| SHA1: | 6F46E43D997F0A91044F02A115BD690F517A7211 |
| SHA256: | BBF126056DC30FF3B3FF295194A4B28D3B6E1FBA2D9D61B3783D6EFB3205CDCE |
| SSDEEP: | 12:28V5tU0BOAMufTnS/5ukV5tU0BOAMufTnS/5n:2+B1d2/HB1d2/V |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1348 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=11 --field-trial-handle=4528,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3760 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2568 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=9 --field-trial-handle=4524,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3728 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 2568 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --field-trial-handle=3524,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=1800 /prefetch:8 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 4516 | "C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe" -ServerName:InputApp.AppXjd5de1g66v206tj52m9d0dtpppx4cgpn.mca | C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Version: 123.26505.0.0 Modules
| |||||||||||||||
| 4636 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=10 --field-trial-handle=4640,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3120 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 5284 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=12 --field-trial-handle=4904,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3148 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 5612 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=16 --field-trial-handle=4852,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3196 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| 5636 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=20 --field-trial-handle=5676,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=5708 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Version: 133.0.6943.127 Modules
| |||||||||||||||
| 7232 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=13 --field-trial-handle=3420,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=3400 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
| 7264 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --string-annotations --enable-dinosaur-easter-egg-alt-images --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=14 --field-trial-handle=4964,i,9825079534452362661,6414713242320230888,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250221-144540.991000 --mojo-platform-channel-handle=4996 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 133.0.6943.127 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old~RFfdcca.TMP | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\ClientCertificates\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RFfdce9.TMP | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RFfdce9.TMP | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RFfdcf9.TMP | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\LOG.old~RFfdcf9.TMP | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB\LOG.old | — | |
MD5:— | SHA256:— | |||
| 7524 | chrome.exe | C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RFfdcf9.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7780 | chrome.exe | GET | 302 | 146.112.255.69:443 | https://secure-web.cisco.com/14qDRwkKaf38qfzaremwsWia5y9ahuusP6HCfYgfai8RQVaHmrz3k-YXH2JRcJXW7Ym0vRb-Dh_lq48zHsr4lhSNGMZr8FmC1oZRqNykNc5Fg97uW0gHbtBbp8Lza54koxc-OtdtedA8bjjzpnIQyDB2Oumhncf42qXTdibV5hXFYcuEM3XTX4Yh96FWmsjSwBGCb9Mp66z45FtIwA5AAMC1hiov1hHcy4fGiG-lZodhkkAbhgT0aLfNGsw-y8vLtELNpZCmi9yY6HSQ-gJuM2Zyqoonfr44f-yE7AYGANKKkSL5q2dG4yRGiCPZ4oYN4Rz2jWE7tDDP8QBlZc5QjMpW7SHFdKJyF5rM9qks7RQHeSWXbf3zR4-tN8vKjRZKXJ3wrmmdKgBTvg6_wbOuvcPKB7i1YU-1UJkjlPr1wp6Q/https%3A%2F%2Fca-central-1.protection.sophos.com%2F%3Fd%3Dgoogle.com%26u%3DaHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS91cmw_cT1odHRwcyUzQSUyRiUyRm0zc2VydmljZXMuaW4lMkZxcXFxJTJGJnNhPUQmc250ej0xJnVzZz1BT3ZWYXcxWVdXQVJDWHN3TjY0Umdrc0dMRUJ5%26p%3Dm%26i%3DNjk2MDI3M2RkMzdkM2I0NTNkNDE4MTU5%26t%3DdDMyUTZGZmJVcllPZk92SXpxMDk3ZlJ5N3VvL1pMbS9aYk5halVCZmFOWT0%3D%26h%3Dd48e0893b3a445c9867dda51ee284114%26s%3DAVNPUEhUT0NFTkNSWVBUSVbk20azNIK_YBzDS31Ufsy8c0_ugWt8zMM4oMqJirDSdg | US | — | — | unknown |
7780 | chrome.exe | GET | 302 | 146.112.255.69:443 | https://secure-web.cisco.com/14qDRwkKaf38qfzaremwsWia5y9ahuusP6HCfYgfai8RQVaHmrz3k-YXH2JRcJXW7Ym0vRb-Dh_lq48zHsr4lhSNGMZr8FmC1oZRqNykNc5Fg97uW0gHbtBbp8Lza54koxc-OtdtedA8bjjzpnIQyDB2Oumhncf42qXTdibV5hXFYcuEM3XTX4Yh96FWmsjSwBGCb9Mp66z45FtIwA5AAMC1hiov1hHcy4fGiG-lZodhkkAbhgT0aLfNGsw-y8vLtELNpZCmi9yY6HSQ-gJuM2Zyqoonfr44f-yE7AYGANKKkSL5q2dG4yRGiCPZ4oYN4Rz2jWE7tDDP8QBlZc5QjMpW7SHFdKJyF5rM9qks7RQHeSWXbf3zR4-tN8vKjRZKXJ3wrmmdKgBTvg6_wbOuvcPKB7i1YU-1UJkjlPr1wp6Q/https%3A%2F%2Fca-central-1.protection.sophos.com%2F%3Fd%3Dgoogle.com%26u%3DaHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS91cmw_cT1odHRwcyUzQSUyRiUyRm0zc2VydmljZXMuaW4lMkZxcXFxJTJGJnNhPUQmc250ej0xJnVzZz1BT3ZWYXcxWVdXQVJDWHN3TjY0Umdrc0dMRUJ5%26p%3Dm%26i%3DNjk2MDI3M2RkMzdkM2I0NTNkNDE4MTU5%26t%3DdDMyUTZGZmJVcllPZk92SXpxMDk3ZlJ5N3VvL1pMbS9aYk5halVCZmFOWT0%3D%26h%3Dd48e0893b3a445c9867dda51ee284114%26s%3DAVNPUEhUT0NFTkNSWVBUSVbk20azNIK_YBzDS31Ufsy8c0_ugWt8zMM4oMqJirDSdg | US | — | — | unknown |
7780 | chrome.exe | GET | 302 | 13.226.244.66:443 | https://ca-central-1.protection.sophos.com/?d=google.com&u=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS91cmw_cT1odHRwcyUzQSUyRiUyRm0zc2VydmljZXMuaW4lMkZxcXFxJTJGJnNhPUQmc250ej0xJnVzZz1BT3ZWYXcxWVdXQVJDWHN3TjY0Umdrc0dMRUJ5&p=m&i=Njk2MDI3M2RkMzdkM2I0NTNkNDE4MTU5&t=dDMyUTZGZmJVcllPZk92SXpxMDk3ZlJ5N3VvL1pMbS9aYk5halVCZmFOWT0=&h=d48e0893b3a445c9867dda51ee284114&s=AVNPUEhUT0NFTkNSWVBUSVbk20azNIK_YBzDS31Ufsy8c0_ugWt8zMM4oMqJirDSdg | US | — | — | unknown |
7780 | chrome.exe | GET | 302 | 13.226.244.66:443 | https://ca-central-1.protection.sophos.com/?d=google.com&u=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS91cmw_cT1odHRwcyUzQSUyRiUyRm0zc2VydmljZXMuaW4lMkZxcXFxJTJGJnNhPUQmc250ej0xJnVzZz1BT3ZWYXcxWVdXQVJDWHN3TjY0Umdrc0dMRUJ5&p=m&i=Njk2MDI3M2RkMzdkM2I0NTNkNDE4MTU5&t=dDMyUTZGZmJVcllPZk92SXpxMDk3ZlJ5N3VvL1pMbS9aYk5halVCZmFOWT0=&h=d48e0893b3a445c9867dda51ee284114&s=AVNPUEhUT0NFTkNSWVBUSVbk20azNIK_YBzDS31Ufsy8c0_ugWt8zMM4oMqJirDSdg | US | — | — | unknown |
7780 | chrome.exe | GET | 200 | 16.15.180.1:443 | https://redirect-20250729-676090001-us-east-1.s3.us-east-1.amazonaws.com/parg | US | html | 1.50 Kb | malicious |
7780 | chrome.exe | GET | 200 | 16.15.180.1:443 | https://redirect-20250729-676090001-us-east-1.s3.us-east-1.amazonaws.com/parg | US | html | 1.50 Kb | malicious |
7780 | chrome.exe | POST | 200 | 64.233.167.84:443 | https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard | US | text | 17 b | whitelisted |
7780 | chrome.exe | GET | 200 | 142.250.185.202:443 | https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=AIzaSyA2KlwBX3mkFo30om9LUFYQhpqLoa_BNhE | US | binary | 41 b | whitelisted |
7780 | chrome.exe | GET | 302 | 35.84.125.28:443 | https://broadridgefinancial-mid-prod8.campaign.adobe.com/r/?id=h11336a3,214e086,80a8e&p1=redirect-20250729-676090001-us-east-1.s3.us-east-1.amazonaws.com/parg | US | text | 17 b | whitelisted |
7780 | chrome.exe | GET | 200 | 142.250.185.174:80 | http://clients2.google.com/time/1/current?cup2key=8:X9MXn8MjBJ_zp9O3vGj0rpyOiOZWfHfJ9FZgJBKvJJg&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | US | text | 107 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6768 | MoUsoCoreWorker.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
3796 | RUXIMICS.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6956 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
7780 | chrome.exe | 142.250.185.174:80 | clients2.google.com | GOOGLE | US | whitelisted |
7780 | chrome.exe | 142.250.185.202:443 | safebrowsingohttpgateway.googleapis.com | GOOGLE | US | whitelisted |
7780 | chrome.exe | 35.84.125.28:443 | broadridgefinancial-mid-prod8.campaign.adobe.com | AMAZON-02 | US | unknown |
7780 | chrome.exe | 64.233.167.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
7780 | chrome.exe | 16.15.180.1:443 | redirect-20250729-676090001-us-east-1.s3.us-east-1.amazonaws.com | AMAZON-AES | US | malicious |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
clients2.google.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| whitelisted |
broadridgefinancial-mid-prod8.campaign.adobe.com |
| unknown |
accounts.google.com |
| whitelisted |
redirect-20250729-676090001-us-east-1.s3.us-east-1.amazonaws.com |
| malicious |
secure-web.cisco.com |
| whitelisted |
ca-central-1.protection.sophos.com |
| unknown |
client.wns.windows.com |
| whitelisted |
www.google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Bucket Object Storage service (.linodeobjects .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Bucket Object Storage service (.linodeobjects .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] BootstrapCDN (stackpath .bootstrapcdn .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] BootstrapCDN (stackpath .bootstrapcdn .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] BootstrapCDN (maxcdn .bootstrapcdn .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare content delivery network (cdnjs .cloudflare .com) |
7780 | chrome.exe | Not Suspicious Traffic | INFO [ANY.RUN] Google Hosted Libraries (ajax .googleapis .com) |