IOC Report
https://enerpac.my.salesforce.com/00QNx000009t34v

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:19:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:19:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:19:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:19:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:19:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://enerpac.my.salesforce.com/00QNx000009t34v
https://enerpac.my.salesforce.com/s.gif
https://enerpac.my.salesforce.com/?ec=302&startURL=%2F00QNx000009t34v
https://login.salesforce.com/login/sessionserver212.html

Domains

Name
IP
Malicious
part-0017.t-0009.t-msedge.net
13.107.246.45
cs1100.wpc.omegacdn.net
152.199.23.37
dscm.li
188.114.96.3
cdn.evgnet.com
151.101.192.114
usa238.sfdc-lywfpd.salesforce.com
34.218.131.71
sni1gl.wpc.upsiloncdn.net
152.199.21.175
www.google.com
142.250.186.100
login.l2.salesforce.com
85.222.152.195
salesforce.us-1.evergage.com
3.216.65.206
geolocation.onetrust.com
104.18.32.137
st1.edge.sfdc-yzvdd4.edge2.salesforce.com
35.158.127.51
login.salesforce.com
unknown
aadcdn.msftauth.net
unknown
aadcdn.msauthimages.net
unknown
enerpac.my.salesforce.com
unknown
c.salesforce.com
unknown
identity.nel.measure.office.net
unknown
a.sfdcstatic.com
unknown
login.microsoftonline.com
unknown
www.salesforce.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.99
unknown
United States
142.250.186.67
unknown
United States
13.107.246.45
part-0017.t-0009.t-msedge.net
United States
173.194.76.84
unknown
United States
192.168.2.16
unknown
unknown
104.18.32.137
geolocation.onetrust.com
United States
142.250.184.200
unknown
United States
142.250.186.138
unknown
United States
2.18.64.17
unknown
European Union
172.217.16.202
unknown
United States
1.1.1.1
unknown
Australia
151.101.192.114
cdn.evgnet.com
United States
2.18.64.7
unknown
European Union
92.123.12.154
unknown
European Union
95.101.54.121
unknown
European Union
34.218.131.71
usa238.sfdc-lywfpd.salesforce.com
United States
20.190.159.73
unknown
United States
3.216.65.206
salesforce.us-1.evergage.com
United States
20.190.159.71
unknown
United States
172.64.155.119
unknown
United States
2.18.64.11
unknown
European Union
35.158.127.51
st1.edge.sfdc-yzvdd4.edge2.salesforce.com
United States
239.255.255.250
unknown
Reserved
188.114.96.3
dscm.li
European Union
152.199.21.175
sni1gl.wpc.upsiloncdn.net
United States
142.250.186.100
www.google.com
United States
142.250.184.238
unknown
United States
85.222.152.195
login.l2.salesforce.com
United Kingdom
There are 18 hidden IPs, click here to show them.