IOC Report
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 8 16:50:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 8 16:50:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 8 16:50:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 8 16:50:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Jul 8 16:50:57 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 101
JSON data
dropped
Chrome Cache Entry: 102
JSON data
downloaded
Chrome Cache Entry: 103
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 68
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 69
OpenType font data
downloaded
Chrome Cache Entry: 70
JSON data
downloaded
Chrome Cache Entry: 71
JSON data
dropped
Chrome Cache Entry: 72
data
dropped
Chrome Cache Entry: 73
PNG image data, 116 x 116, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 74
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 75
JSON data
dropped
Chrome Cache Entry: 76
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 77
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 78
data
dropped
Chrome Cache Entry: 79
data
downloaded
Chrome Cache Entry: 80
ASCII text
downloaded
Chrome Cache Entry: 81
data
dropped
Chrome Cache Entry: 82
Unicode text, UTF-8 text, with no line terminators
downloaded
Chrome Cache Entry: 83
PNG image data, 116 x 116, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 84
HTML document, ASCII text, with very long lines (11440), with no line terminators
downloaded
Chrome Cache Entry: 85
data
downloaded
Chrome Cache Entry: 86
data
downloaded
Chrome Cache Entry: 87
JSON data
dropped
Chrome Cache Entry: 88
HTML document, ASCII text
downloaded
Chrome Cache Entry: 89
HTML document, ASCII text, with very long lines (530)
downloaded
Chrome Cache Entry: 90
JSON data
downloaded
Chrome Cache Entry: 91
ASCII text
downloaded
Chrome Cache Entry: 92
data
dropped
Chrome Cache Entry: 93
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 94
ASCII text
downloaded
Chrome Cache Entry: 95
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 96
JSON data
downloaded
Chrome Cache Entry: 97
JSON data
downloaded
Chrome Cache Entry: 98
JSON data
dropped
Chrome Cache Entry: 99
data
dropped
There are 33 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1884 --field-trial-handle=1956,i,9439631370590086316,199388582780943592,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
malicious
https://lcolmuacvi.ezutubek.info/call/jxhohdpaqd
104.21.93.18
https://links.us1.defend.egress.com/_blazor?id=nMeXvhnhZYlyrair5GEe-g&_=1720461090883
99.83.228.139
https://links.us1.defend.egress.com/_framework/blazor.server.js
99.83.228.139
https://agitationfourthplug.com/favicon.ico
192.243.59.12
https://links.us1.defend.egress.com/_blazor/negotiate?negotiateVersion=1
99.83.228.139
https://links.us1.defend.egress.com/_framework/blazor.polyfill.min.js
99.83.228.139
https://links.us1.defend.egress.com/fonts/AvenirLTStd-Book_0.otf
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=OcP1CEtffnutIfw-9yozUw&_=1720461137221
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=toTYSEG6AL9X-EIBOcZkbA&_=1720461060204
99.83.228.139
https://links.us1.defend.egress.com/_blazor/disconnect
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=EkSnBsfn9XZA3r7CM66AYQ
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=N_tCeQTw6VgXxhBa3E5K7Q&_=1720461106607
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=o6uEjSPvXVFoeNaVmLBIBg&_=1720461144448
99.83.228.139
https://links.us1.defend.egress.com/js/JsInteropFuncions.js?v=8ZRc1sGeVrPBx4lD717BgRaQekyh78QKV9SKsdt638U
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=7gtLAi8y986CJC3xmPDq3g&_=1720461126884
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=lHorztA_KwiYbv5A0V3PqQ&_=1720461067250
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=AiobawV_otbCYUjRpvyRKw&_=1720461115534
99.83.228.139
http://www.linotype.com0
unknown
https://links.us1.defend.egress.com/images/egress-logo-dark.svg
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=AiobawV_otbCYUjRpvyRKw
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=OcP1CEtffnutIfw-9yozUw&_=1720461137857
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=SnDaSj9SZJ__4Sz4AMWIBQ&_=1720461168348
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=lHorztA_KwiYbv5A0V3PqQ
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=sbi0_wXs4K4_52g4xYJqgg
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=dxR48vWYOtDYHWVfc7Z-Lw
99.83.228.139
https://www.google.com/url?rct=j&sa=t&url=https://lcolmuacvi.ezutubek.info/call/jxhohdpaqd&ct=ga&cd=CAEYAioSOTI5Nzk0MjU4Mjc2NjI4MjA5Mho3NGYzZGRlMTU1YWQ5ZTMzOmNvbTplbjpVUw&usg=AOvVaw01A1xlICSsI0pQcUvHHTI0
142.250.186.164
https://links.us1.defend.egress.com/_blazor?id=7gtLAi8y986CJC3xmPDq3g
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=7gtLAi8y986CJC3xmPDq3g&_=1720461128097
99.83.228.139
https://links.us1.defend.egress.com/_blazor/initializers
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=toTYSEG6AL9X-EIBOcZkbA
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=OcP1CEtffnutIfw-9yozUw&_=1720461136625
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=7gtLAi8y986CJC3xmPDq3g&_=1720461128732
99.83.228.139
https://links.us1.defend.egress.com/images/egress-icon.png
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=N_tCeQTw6VgXxhBa3E5K7Q&_=1720461107191
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=OcP1CEtffnutIfw-9yozUw&_=1720461138452
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=eMoP-fvLJ0Pl8L9tCc8YUQ
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=toTYSEG6AL9X-EIBOcZkbA&_=1720461060799
99.83.228.139
https://links.us1.defend.egress.com/css/site.css?v=3_7xBUVF7AMmqCChOMZj_vfG2g8ZfedUIPQTnu-5_qA
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=lHorztA_KwiYbv5A0V3PqQ&_=1720461066330
99.83.228.139
https://www.google.com/url?rct=j&sa=t&url=https://lcolmuacvi.ezutubek.info/call/jxhohdpaqd&ct=ga&cd=
unknown
https://links.us1.defend.egress.com/_blazor?id=o6uEjSPvXVFoeNaVmLBIBg
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=N_tCeQTw6VgXxhBa3E5K7Q&_=1720461107916
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=OcP1CEtffnutIfw-9yozUw
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=nMeXvhnhZYlyrair5GEe-g&_=1720461090277
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=yOMQDwoxSRYqvZckdxxm_w
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=H8K-La5bOR1bnTz6eLg9wg
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=nMeXvhnhZYlyrair5GEe-g
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=7gtLAi8y986CJC3xmPDq3g&_=1720461127473
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=toTYSEG6AL9X-EIBOcZkbA&_=1720461059604
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=dFo2J0KjmrPisx6XctqXxA
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=G_ySy0QGe5x9HCxKZDoNhg
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=uArg-MmOm4ZwnvcgElHDUg
99.83.228.139
https://www.google.com/url?rct=j
unknown
https://links.us1.defend.egress.com/_blazor?id=N_tCeQTw6VgXxhBa3E5K7Q
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=o6uEjSPvXVFoeNaVmLBIBg&_=1720461143841
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=AiobawV_otbCYUjRpvyRKw&_=1720461116161
99.83.228.139
https://links.us1.defend.egress.com/_blazor?id=N_tCeQTw6VgXxhBa3E5K7Q&_=1720461109544
99.83.228.139
There are 47 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
agitationfourthplug.com
192.243.59.12
s4.histats.com
54.39.128.117
www.google.com
142.250.186.164
lcolmuacvi.ezutubek.info
104.21.93.18
links.us1.defend.egress.com
99.83.228.139
s10.histats.com
unknown

IPs

IP
Domain
Country
Malicious
75.2.120.244
unknown
United States
192.168.2.16
unknown
unknown
192.168.2.4
unknown
unknown
99.83.228.139
links.us1.defend.egress.com
United States
239.255.255.250
unknown
Reserved
192.243.59.12
agitationfourthplug.com
Dominica
54.39.128.117
s4.histats.com
Canada
142.250.186.164
www.google.com
United States
104.21.93.18
lcolmuacvi.ezutubek.info
United States

DOM / HTML

URL
Malicious
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://links.us1.defend.egress.com/Warning?crId=668c13f0107db9b66b77d74e&Domain=lcatterton.com&Lang=en&Base64Url=eNo1i0FvgyAYQP8NR9FtXpaQhjRNywFNW3TRG6JT6WdhCtL46-elp5eXvDc4Z5dvjEMIUW9MD12kzIT9DIdZOaLRIolDu5J3CcrA5KVax6jbvPNN94jG56_BSgJg_RrM0Fr516J97yVSLTnSU0VHc88FS7PtEXNdfHGtPjLNdtKUD-YzO1dbfb4BF0VS_VzTWvAtn7K1ERYabcsiIL_0hOZrKUOc0OQF7HhfWGyvqlgvF8HifyPiRzE%3D&@OriginalLink=www.google.com
https://agitationfourthplug.com/api/users?token=L2lqNnNrN3MxP2tleT01NWYxN2E5ZmVlNjhlYTFiNmY0Y2NmYTJkOTZlY2Y2ZQ==##call
There are 1 hidden doms, click here to show them.