IOC Report
https://publuu.com/flip-book/518284/1161698

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:51:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:51:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:51:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:51:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri May 24 18:51:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 144
Ogg data, Vorbis audio, stereo, 44100 Hz, ~112000 bps
downloaded
Chrome Cache Entry: 145
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (20983), with no line terminators
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (1827), with no line terminators
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (21282)
downloaded
Chrome Cache Entry: 149
PNG image data, 225 x 225, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (13032), with no line terminators
downloaded
Chrome Cache Entry: 153
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 156
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 157
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 158
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 159
HTML document, ASCII text, with very long lines (4700), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (16825)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (7441)
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (28295)
downloaded
Chrome Cache Entry: 163
Web Open Font Format (Version 2), TrueType, length 13976, version 1.0
downloaded
Chrome Cache Entry: 164
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 166
RIFF (little-endian) data, Web/P image, VP8 encoding, 963x1200, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 168
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (27106)
downloaded
Chrome Cache Entry: 170
JSON data
dropped
Chrome Cache Entry: 173
ASCII text, with very long lines (8570), with no line terminators
downloaded
Chrome Cache Entry: 174
Audio file with ID3 version 2.3.0, contains: MPEG ADTS, layer III, v1, 96 kbps, 44.1 kHz, JntStereo
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 176
Web Open Font Format (Version 2), TrueType, length 14148, version 1.0
downloaded
Chrome Cache Entry: 177
Web Open Font Format (Version 2), TrueType, length 13904, version 1.0
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (10364)
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (7685), with no line terminators
downloaded
Chrome Cache Entry: 180
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=GIMP 2.8.22, datetime=2021:05:04 16:29:54], baseline, precision 8, 1279x719, components 1
dropped
Chrome Cache Entry: 181
ASCII text, with very long lines (5300), with no line terminators
downloaded
Chrome Cache Entry: 183
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 184
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 185
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 187
RIFF (little-endian) data, Web/P image, VP8 encoding, 321x400, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 188
Ogg data, Vorbis audio, mono, 44100 Hz, ~80000 bps
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (42033)
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (1512), with no line terminators
downloaded
There are 34 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://publuu.com/flip-book/518284/1161698
https://publuu.com/flip-book/518284/1161698

Domains

Name
IP
Malicious
d1uiew9hysv4w7.cloudfront.net
18.66.137.144
publuu.com
3.136.115.193
www.google.com
142.250.185.164
d1u9ua4yk0lyeu.cloudfront.net
18.238.248.110
utty56o2qi.execute-api.us-east-2.amazonaws.com
3.19.254.28
dkl18tmi4r0t8.cloudfront.net
18.239.47.59

IPs

IP
Domain
Country
Malicious
1.1.1.1
unknown
Australia
34.104.35.123
unknown
United States
74.125.133.84
unknown
United States
192.168.2.16
unknown
unknown
142.250.185.106
unknown
United States
18.66.137.144
d1uiew9hysv4w7.cloudfront.net
United States
172.217.23.110
unknown
United States
18.189.90.121
unknown
United States
239.255.255.250
unknown
Reserved
172.217.23.99
unknown
United States
3.22.179.31
unknown
United States
142.250.185.164
www.google.com
United States
18.238.248.76
unknown
United States
142.250.184.238
unknown
United States
18.238.248.110
d1u9ua4yk0lyeu.cloudfront.net
United States
3.19.254.28
utty56o2qi.execute-api.us-east-2.amazonaws.com
United States
18.239.47.185
unknown
United States
172.217.16.195
unknown
United States
18.239.47.59
dkl18tmi4r0t8.cloudfront.net
United States
3.136.115.193
publuu.com
United States
99.86.153.199
unknown
United States
There are 11 hidden IPs, click here to show them.