IOC Report
phish_alert_iocp_v1.4.48 (15).eml

loading gif

Files

File Path
Type
Category
Malicious
phish_alert_iocp_v1.4.48 (15).eml
RFC 822 mail, ASCII text, with very long lines (347), with CRLF line terminators
initial sample
C:\Users\user\Documents\Outlook Files\Outlook Data File - NoEmail.pst
Microsoft Outlook email folder (>=2003)
dropped
malicious
C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
data
dropped
malicious
C:\Users\user\AppData\Local\Microsoft\FORMS\FRMCACHE.DAT
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\8CAAF780-57B3-4A6C-B004-E3D3DE55EA28
XML 1.0 document, ASCII text, with CRLF line terminators
modified
C:\Users\user\AppData\Local\Microsoft\Office\OTele\outlook.exe.db-shm
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\outlook.exe.db-wal
SQLite Write-Ahead Log, version 3007000
modified
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{EF0F9F4E-EE28-499F-AC43-176226F19F42}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1728062814679630900_7E2A3281-6157-4F73-A6E4-515429C84690.log
ASCII text, with very long lines (28762), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1728062814681001400_7E2A3281-6157-4F73-A6E4-515429C84690.log
data
dropped
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241004T1326540480-6816.etl
data
modified
C:\Users\user\AppData\Roaming\Microsoft\Office\MSO3072.acl
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 16:27:08 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 16:27:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 16:27:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 16:27:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 4 16:27:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 173
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 174
PNG image data, 39 x 105, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 175
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 177
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (4938)
downloaded
Chrome Cache Entry: 180
Web Open Font Format (Version 2), CFF, length 41556, version 1.0
downloaded
Chrome Cache Entry: 181
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 183
PNG image data, 1020 x 1320, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 184
Web Open Font Format (Version 2), CFF, length 29752, version 1.0
downloaded
Chrome Cache Entry: 185
Web Open Font Format (Version 2), CFF, length 29980, version 1.0
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (60557)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (5632)
downloaded
Chrome Cache Entry: 190
Unicode text, UTF-8 text, with very long lines (2258)
dropped
Chrome Cache Entry: 191
PNG image data, 13 x 13, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 192
ASCII text, with very long lines (1215)
downloaded
Chrome Cache Entry: 193
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 194
Unicode text, UTF-8 text, with very long lines (52838)
downloaded
Chrome Cache Entry: 198
PNG image data, 700 x 300, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 201
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 206
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 208
PNG image data, 21 x 21, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 209
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 210
Web Open Font Format (Version 2), CFF, length 29924, version 1.0
downloaded
Chrome Cache Entry: 211
PNG image data, 353 x 60, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 214
PNG image data, 9 x 5, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 216
Unicode text, UTF-8 text, with very long lines (39523)
dropped
Chrome Cache Entry: 217
Unicode text, UTF-8 text, with very long lines (39221)
downloaded
Chrome Cache Entry: 219
GIF image data, version 89a, 1 x 1
downloaded
There are 37 hidden files, click here to show them.

Domains

Name
IP
Malicious
clicktime.cloud.postoffice.net
165.212.65.140
secure.na2dc2.echosign.com
44.234.124.143
www.google.com
142.250.186.68
federalreservebanks.na2.adobesign.com
44.234.124.143
use.typekit.net
unknown
p.typekit.net
unknown
secure.na2.echocdn.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
52.113.194.132
unknown
United States
142.250.184.195
unknown
United States
1.1.1.1
unknown
Australia
34.104.35.123
unknown
United States
192.168.2.17
unknown
unknown
2.19.126.219
unknown
European Union
2.19.126.206
unknown
European Union
142.250.185.227
unknown
United States
216.58.206.46
unknown
United States
165.212.65.140
clicktime.cloud.postoffice.net
United States
74.125.206.84
unknown
United States
142.250.181.238
unknown
United States
2.19.126.211
unknown
European Union
95.101.54.218
unknown
European Union
20.189.173.25
unknown
United States
239.255.255.250
unknown
Reserved
52.109.28.46
unknown
United States
44.234.124.143
secure.na2dc2.echosign.com
United States
142.250.184.234
unknown
United States
There are 10 hidden IPs, click here to show them.