IOC Report
https://1drv.ms/b/c/76a2f2769a0f2d92/EVBBlcPr69hPlwB4teIJkR8BhOEwtE3haDg1sSdukRfZrw?e=geYoLr

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\41861b96-f7f0-435b-aa96-15ca15ee66a9.tmp
PDF document, version 1.7, 1 pages
dropped
C:\Users\user\Downloads\4f99d8b1-1501-4166-b028-b1848151f12d.tmp
PDF document, version 1.7, 1 pages
dropped
C:\Users\user\Downloads\Kinetic Construction Quotation Request.pdf (copy)
PDF document, version 1.7, 1 pages
dropped
C:\Users\user\Downloads\Kinetic Construction Quotation Request.pdf.crdownload (copy)
PDF document, version 1.7, 1 pages
dropped
Chrome Cache Entry: 244
Unicode text, UTF-8 text, with very long lines (18788)
downloaded
Chrome Cache Entry: 245
ASCII text, with very long lines (5509)
downloaded
Chrome Cache Entry: 246
ASCII text, with very long lines (27775)
downloaded
Chrome Cache Entry: 248
ASCII text
downloaded
Chrome Cache Entry: 249
ASCII text, with very long lines (2516)
downloaded
Chrome Cache Entry: 252
Web Open Font Format, TrueType, length 25132, version 1.3277
downloaded
Chrome Cache Entry: 253
ASCII text, with very long lines (3202)
downloaded
Chrome Cache Entry: 254
ASCII text, with very long lines (15962)
downloaded
Chrome Cache Entry: 255
ASCII text, with very long lines (23314)
downloaded
Chrome Cache Entry: 256
ASCII text, with very long lines (17192)
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (1798)
downloaded
Chrome Cache Entry: 258
ASCII text, with very long lines (2710)
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (17909)
downloaded
Chrome Cache Entry: 260
Unicode text, UTF-8 text, with very long lines (1679)
downloaded
Chrome Cache Entry: 261
ASCII text, with very long lines (4487)
downloaded
Chrome Cache Entry: 262
ASCII text, with very long lines (47927)
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (2871)
downloaded
Chrome Cache Entry: 265
ASCII text, with very long lines (4725)
downloaded
Chrome Cache Entry: 266
ASCII text, with very long lines (13117)
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (42917)
downloaded
Chrome Cache Entry: 268
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=4, xresolution=62, yresolution=70, resolutionunit=2, software=paint.net 4.2.9], baseline, precision 8, 50x28, components 3
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (6949)
downloaded
Chrome Cache Entry: 270
Unicode text, UTF-8 text, with very long lines (18788)
downloaded
Chrome Cache Entry: 271
ASCII text, with very long lines (10292)
downloaded
Chrome Cache Entry: 272
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 273
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 625x809, components 3
downloaded
Chrome Cache Entry: 274
ASCII text, with very long lines (12172)
downloaded
Chrome Cache Entry: 275
ASCII text, with very long lines (8589)
downloaded
Chrome Cache Entry: 277
ASCII text, with very long lines (63719)
downloaded
Chrome Cache Entry: 278
ASCII text, with very long lines (8011)
downloaded
Chrome Cache Entry: 279
Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (7791)
downloaded
Chrome Cache Entry: 281
ASCII text, with very long lines (65470)
downloaded
Chrome Cache Entry: 282
ASCII text, with very long lines (3156)
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (65470)
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (5303)
downloaded
Chrome Cache Entry: 285
ASCII text, with very long lines (20717)
downloaded
Chrome Cache Entry: 286
ASCII text, with very long lines (8840)
downloaded
Chrome Cache Entry: 287
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 288
Unicode text, UTF-8 text, with very long lines (6926)
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (10777)
downloaded
Chrome Cache Entry: 292
ASCII text, with very long lines (9839)
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (3341)
downloaded
Chrome Cache Entry: 296
ASCII text, with very long lines (26443)
downloaded
Chrome Cache Entry: 297
ASCII text, with very long lines (14096)
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (768)
downloaded
Chrome Cache Entry: 299
ASCII text, with very long lines (9794)
downloaded
Chrome Cache Entry: 300
ASCII text, with very long lines (30298)
downloaded
Chrome Cache Entry: 301
JSON data
dropped
Chrome Cache Entry: 302
ASCII text, with very long lines (20717)
downloaded
Chrome Cache Entry: 303
ASCII text, with very long lines (30298)
downloaded
Chrome Cache Entry: 304
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 305
ASCII text, with very long lines (5739)
downloaded
Chrome Cache Entry: 306
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 307
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 308
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113355
downloaded
Chrome Cache Entry: 309
ASCII text, with very long lines (32483)
downloaded
Chrome Cache Entry: 310
Unicode text, UTF-8 text, with very long lines (65308), with no line terminators
downloaded
Chrome Cache Entry: 311
Java source, ASCII text
dropped
Chrome Cache Entry: 312
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 313
ASCII text, with very long lines (11652), with no line terminators
downloaded
Chrome Cache Entry: 314
ASCII text, with very long lines (25903)
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (60031)
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (20931)
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (26983)
downloaded
Chrome Cache Entry: 319
ASCII text, with very long lines (4849)
downloaded
Chrome Cache Entry: 320
Unicode text, UTF-8 text, with very long lines (22752)
downloaded
Chrome Cache Entry: 321
ASCII text, with very long lines (51887)
downloaded
Chrome Cache Entry: 322
JPEG image data, baseline, precision 8, 1920x1080, components 3
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (4134)
downloaded
Chrome Cache Entry: 324
Unicode text, UTF-8 text, with very long lines (31254)
downloaded
Chrome Cache Entry: 325
ASCII text, with very long lines (3225)
downloaded
Chrome Cache Entry: 326
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 327
ASCII text, with very long lines (1538)
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (8690)
downloaded
Chrome Cache Entry: 329
Unicode text, UTF-8 text, with very long lines (11467)
downloaded
Chrome Cache Entry: 330
JSON data
dropped
Chrome Cache Entry: 331
ASCII text, with very long lines (10605)
downloaded
Chrome Cache Entry: 332
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 333
ASCII text, with very long lines (11510)
downloaded
Chrome Cache Entry: 334
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 335
ASCII text, with very long lines (65436)
downloaded
Chrome Cache Entry: 336
ASCII text, with very long lines (1845)
downloaded
Chrome Cache Entry: 337
ASCII text, with very long lines (12902)
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (5808)
downloaded
Chrome Cache Entry: 339
ASCII text, with very long lines (5382)
downloaded
Chrome Cache Entry: 341
ASCII text, with very long lines (8263)
downloaded
Chrome Cache Entry: 342
JSON data
dropped
Chrome Cache Entry: 343
PNG image data, 342 x 72, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 345
ASCII text, with very long lines (14178)
downloaded
Chrome Cache Entry: 346
ASCII text, with very long lines (17285)
downloaded
Chrome Cache Entry: 348
ASCII text, with very long lines (14342)
downloaded
Chrome Cache Entry: 350
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
dropped
Chrome Cache Entry: 352
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
dropped
Chrome Cache Entry: 353
ASCII text, with very long lines (26474)
downloaded
Chrome Cache Entry: 354
Unicode text, UTF-8 text, with very long lines (2805)
downloaded
Chrome Cache Entry: 355
ASCII text, with very long lines (27320)
downloaded
Chrome Cache Entry: 356
ASCII text, with very long lines (6859)
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (24757)
downloaded
Chrome Cache Entry: 358
ASCII text, with very long lines (9544)
downloaded
Chrome Cache Entry: 359
ASCII text, with very long lines (18199)
downloaded
Chrome Cache Entry: 360
ASCII text, with very long lines (456)
downloaded
Chrome Cache Entry: 361
C source, ASCII text, with very long lines (11302)
downloaded
Chrome Cache Entry: 362
ASCII text, with very long lines (6372)
downloaded
Chrome Cache Entry: 363
ASCII text, with very long lines (7082)
downloaded
Chrome Cache Entry: 364
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 365
ASCII text, with very long lines (4808)
downloaded
Chrome Cache Entry: 366
ASCII text, with very long lines (16511)
downloaded
Chrome Cache Entry: 367
ASCII text, with very long lines (3992)
downloaded
Chrome Cache Entry: 368
ASCII text, with very long lines (4502)
downloaded
Chrome Cache Entry: 369
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 371
ASCII text, with very long lines (15989)
downloaded
Chrome Cache Entry: 372
ASCII text, with very long lines (7798)
downloaded
Chrome Cache Entry: 373
ASCII text, with very long lines (3161)
downloaded
Chrome Cache Entry: 374
ASCII text, with very long lines (4558)
downloaded
Chrome Cache Entry: 377
ASCII text, with very long lines (9782)
downloaded
Chrome Cache Entry: 378
JSON data
downloaded
Chrome Cache Entry: 381
ASCII text, with very long lines (6099)
downloaded
Chrome Cache Entry: 382
ASCII text, with very long lines (2224), with no line terminators
downloaded
Chrome Cache Entry: 383
ASCII text, with very long lines (50396)
downloaded
Chrome Cache Entry: 384
Unicode text, UTF-8 text, with very long lines (41512)
downloaded
Chrome Cache Entry: 385
ASCII text, with very long lines (19837)
downloaded
Chrome Cache Entry: 386
HTML document, ASCII text, with very long lines (63842), with CRLF line terminators
downloaded
Chrome Cache Entry: 387
ASCII text, with very long lines (9562)
downloaded
Chrome Cache Entry: 388
ASCII text, with very long lines (14528)
downloaded
Chrome Cache Entry: 389
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 390
ASCII text, with very long lines (11120)
downloaded
Chrome Cache Entry: 391
Unicode text, UTF-8 text, with very long lines (4116)
downloaded
Chrome Cache Entry: 392
JSON data
downloaded
Chrome Cache Entry: 393
ASCII text, with very long lines (8905)
downloaded
Chrome Cache Entry: 394
ASCII text, with very long lines (10448)
downloaded
Chrome Cache Entry: 395
ASCII text, with very long lines (48338)
downloaded
Chrome Cache Entry: 396
ASCII text, with very long lines (4251)
downloaded
Chrome Cache Entry: 397
Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
downloaded
Chrome Cache Entry: 398
ASCII text, with very long lines (5354)
downloaded
Chrome Cache Entry: 399
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 400
ASCII text, with very long lines (12283)
downloaded
Chrome Cache Entry: 401
ASCII text, with very long lines (4069)
downloaded
Chrome Cache Entry: 402
Unicode text, UTF-8 (with BOM) text, with very long lines (59783), with CRLF line terminators
downloaded
Chrome Cache Entry: 403
ASCII text, with very long lines (12589)
downloaded
Chrome Cache Entry: 404
ASCII text, with very long lines (4893)
downloaded
Chrome Cache Entry: 406
ASCII text, with very long lines (7193)
downloaded
Chrome Cache Entry: 407
ASCII text, with very long lines (10184)
downloaded
Chrome Cache Entry: 408
PDF document, version 1.7, 1 pages
downloaded
Chrome Cache Entry: 409
ASCII text, with very long lines (9576)
downloaded
Chrome Cache Entry: 410
WebAssembly (wasm) binary module version 0x1 (MVP)
downloaded
Chrome Cache Entry: 411
PNG image data, 144 x 144, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 412
ASCII text, with very long lines (13882)
downloaded
Chrome Cache Entry: 413
ASCII text
downloaded
Chrome Cache Entry: 414
ASCII text, with very long lines (1249)
downloaded
Chrome Cache Entry: 416
ASCII text, with very long lines (10967)
downloaded
Chrome Cache Entry: 418
ASCII text, with very long lines (30855)
downloaded
Chrome Cache Entry: 419
ASCII text, with very long lines (3327)
downloaded
Chrome Cache Entry: 420
ASCII text, with very long lines (13476)
downloaded
Chrome Cache Entry: 421
ASCII text, with very long lines (1278)
downloaded
Chrome Cache Entry: 423
Unicode text, UTF-8 text, with very long lines (13485)
downloaded
Chrome Cache Entry: 424
ASCII text, with very long lines (13750)
downloaded
Chrome Cache Entry: 425
Web Open Font Format, TrueType, length 15564, version 1.3277
downloaded
Chrome Cache Entry: 426
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 427
Web Open Font Format, TrueType, length 15696, version 1.3277
downloaded
Chrome Cache Entry: 428
ASCII text, with very long lines (15711)
downloaded
Chrome Cache Entry: 429
Unicode text, UTF-8 (with BOM) text, with very long lines (65339), with CRLF line terminators
downloaded
Chrome Cache Entry: 431
ASCII text, with very long lines (65475)
downloaded
Chrome Cache Entry: 432
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 433
HTML document, ASCII text, with very long lines (3437), with CRLF line terminators
downloaded
Chrome Cache Entry: 434
ASCII text, with very long lines (8876)
downloaded
Chrome Cache Entry: 436
ASCII text, with very long lines (3586)
downloaded
Chrome Cache Entry: 437
ASCII text, with very long lines (1753)
downloaded
Chrome Cache Entry: 439
ASCII text, with very long lines (16689)
downloaded
Chrome Cache Entry: 440
Web Open Font Format, TrueType, length 11476, version 1.3277
downloaded
Chrome Cache Entry: 441
ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 442
ASCII text, with very long lines (25009)
downloaded
There are 167 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://1drv.ms/b/c/76a2f2769a0f2d92/EVBBlcPr69hPlwB4teIJkR8BhOEwtE3haDg1sSdukRfZrw?e=geYoLr
malicious
https://onedrive.live.com/?id=76A2F2769A0F2D92!sc3954150ebeb4fd8970078b5e209911f&resid=76A2F2769A0F2D92!sc3954150ebeb4fd8970078b5e209911f&cid=76a2f2769a0f2d92&ithint=file%2cpdf&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2IvYy83NmEyZjI3NjlhMGYyZDkyL0VWQkJsY1ByNjloUGx3QjR0ZUlKa1I4QmhPRXd0RTNoYURnMXNTZHVrUmZacnc_ZT1nZVlvTHI&migratedtospo=true
https://onedrive.live.com/?id=76A2F2769A0F2D92%21sc3954150ebeb4fd8970078b5e209911f&cid=76a2f2769a0f2d92&ithint=file%2Cpdf&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2IvYy83NmEyZjI3NjlhMGYyZDkyL0VWQkJsY1ByNjloUGx3QjR0ZUlKa1I4QmhPRXd0RTNoYURnMXNTZHVrUmZacnc%5FZT1nZVlvTHI
https://onedrive.live.com/?redeem=aHR0cHM6Ly8xZHJ2Lm1zL2IvYy83NmEyZjI3NjlhMGYyZDkyL0VWQkJsY1ByNjloUGx3QjR0ZUlKa1I4QmhPRXd0RTNoYURnMXNTZHVrUmZacnc%5FZT1nZVlvTHI&cid=76A2F2769A0F2D92&id=76A2F2769A0F2D92%21sc3954150ebeb4fd8970078b5e209911f&parId=root&o=OneUp
file:///C:/Users/user/Downloads/Kinetic%20Construction%20Quotation%20Request.pdf
about:blank
https://outlook.office365.com/owa/prefetch.aspx
https://onedrive.live.com/?id=76A2F2769A0F2D92%21sc3954150ebeb4fd8970078b5e209911f&resid=76A2F2769A0F2D92%21sc3954150ebeb4fd8970078b5e209911f&cid=76a2f2769a0f2d92&ithint=file%2Cpdf&redeem=aHR0cHM6Ly8xZHJ2Lm1zL2IvYy83NmEyZjI3NjlhMGYyZDkyL0VWQkJsY1ByNjloUGx3QjR0ZUlKa1I4QmhPRXd0RTNoYURnMXNTZHVrUmZacnc%5FZT1nZVlvTHI&migratedtospo=true&v=validatepermission

Domains

Name
IP
Malicious
weblinkdsafedoc.shop
5.230.41.194
malicious
dual-spov-0006.spov-msedge.net
13.107.137.11
dual-spo-0005.spo-msedge.net
13.107.136.10
sni1gl.wpc.alphacdn.net
152.199.21.175
s-part-0017.t-0009.t-msedge.net
13.107.246.45
sni1gl.wpc.omegacdn.net
152.199.21.175
www.google.com
142.250.185.132
HHN-efz.ms-acdc.office.com
52.98.241.178
s-part-0032.t-0009.t-msedge.net
13.107.246.60
1drv.ms
13.107.42.12
my.microsoftpersonalcontent.com
unknown
api-badgerp.svc.ms
unknown
r4.res.office365.com
unknown
aadcdn.msftauth.net
unknown
logincdn.msftauth.net
unknown
storage.live.com
unknown
m365cdn.nel.measure.office.net
unknown
spo.nel.measure.office.net
unknown
outlook.office365.com
unknown
onedrive.live.com
unknown
api.onedrive.com
unknown
p.sfx.ms
unknown
eastus1-mediap.svc.ms
unknown
acctcdn.msftauth.net
unknown
There are 14 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
5.230.41.194
weblinkdsafedoc.shop
Germany
malicious
52.168.117.174
unknown
United States
13.107.138.10
unknown
United States
13.107.136.10
dual-spo-0005.spo-msedge.net
United States
20.189.173.7
unknown
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
192.168.2.16
unknown
unknown
20.189.173.3
unknown
United States
40.126.31.71
unknown
United States
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States
142.250.185.106
unknown
United States
2.23.209.37
unknown
European Union
172.217.23.99
unknown
United States
51.105.104.217
unknown
United Kingdom
142.250.186.131
unknown
United States
2.19.97.32
unknown
European Union
13.104.208.164
unknown
United States
40.126.31.69
unknown
United States
52.98.241.178
HHN-efz.ms-acdc.office.com
United States
142.250.184.228
unknown
United States
216.58.212.174
unknown
United States
216.58.212.170
unknown
United States
52.113.194.132
unknown
United States
13.107.139.11
unknown
United States
20.101.246.164
unknown
United States
1.1.1.1
unknown
Australia
13.107.137.11
dual-spov-0006.spov-msedge.net
United States
74.125.133.84
unknown
United States
20.42.65.93
unknown
United States
142.250.185.132
www.google.com
United States
2.16.241.15
unknown
European Union
20.190.159.75
unknown
United States
216.58.206.46
unknown
United States
13.107.42.12
1drv.ms
United States
2.19.198.80
unknown
European Union
239.255.255.250
unknown
Reserved
152.199.21.175
sni1gl.wpc.alphacdn.net
United States
2.19.11.6
unknown
European Union
There are 28 hidden IPs, click here to show them.