IOC Report
https://email.email.pandadoc.net/c/eJxUkE9r4zwQxj-NdUuQR5ItHXQobfwG3rLQsmHbXspIGjeqE8m1FYfm0y-B7f65DcP8ht_zBOsa4XrNQvanI6XyGoPN-f7_7ilGN8iYdk8Pn-dxt_vOyNYtmMZwDpztLRpXK45GaGy9C943vK2NJgTDG-WQRQscZM1B1AJaztfS904pGYLuOTQtVZLTEeNhPWIKGLJfJyoszq9lQk_oDmTLdCJ2sPtSxrkSNxV0FXQ4jn8Qn48VdF_6FXQLVKIreaBUiTvSz

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:40:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:40:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:40:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:40:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:40:25 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 178
JSON data
dropped
Chrome Cache Entry: 179
Unicode text, UTF-8 text, with very long lines (18223)
dropped
Chrome Cache Entry: 180
Unicode text, UTF-8 text, with very long lines (13330), with no line terminators
downloaded
Chrome Cache Entry: 181
JSON data
downloaded
Chrome Cache Entry: 182
ASCII text, with very long lines (3457)
downloaded
Chrome Cache Entry: 183
JSON data
downloaded
Chrome Cache Entry: 184
JSON data
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 186
Web Open Font Format (Version 2), TrueType, length 32036, version 1.0
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (5164), with no line terminators
dropped
Chrome Cache Entry: 188
ASCII text, with very long lines (22445)
dropped
Chrome Cache Entry: 189
JSON data
dropped
Chrome Cache Entry: 190
Web Open Font Format (Version 2), TrueType, length 31852, version 1.0
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 194
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 196
Unicode text, UTF-8 text, with very long lines (2495)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (1490)
downloaded
Chrome Cache Entry: 198
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 199
Web Open Font Format (Version 2), CFF, length 35648, version 1.0
downloaded
Chrome Cache Entry: 200
JSON data
downloaded
Chrome Cache Entry: 203
ASCII text, with very long lines (52618), with no line terminators
downloaded
Chrome Cache Entry: 204
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 206
Web Open Font Format (Version 2), TrueType, length 50436, version 1.0
downloaded
Chrome Cache Entry: 207
Web Open Font Format (Version 2), CFF, length 33448, version 1.0
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (41360), with no line terminators
downloaded
Chrome Cache Entry: 214
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (17508), with no line terminators
downloaded
Chrome Cache Entry: 217
JSON data
dropped
Chrome Cache Entry: 222
JSON data
dropped
Chrome Cache Entry: 223
Web Open Font Format (Version 2), TrueType, length 47828, version 1.0
downloaded
Chrome Cache Entry: 225
JSON data
downloaded
Chrome Cache Entry: 226
JSON data
downloaded
Chrome Cache Entry: 227
JSON data
dropped
Chrome Cache Entry: 228
ASCII text, with very long lines (11231)
dropped
Chrome Cache Entry: 229
ASCII text, with very long lines (4705), with no line terminators
downloaded
Chrome Cache Entry: 232
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
dropped
Chrome Cache Entry: 234
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
dropped
Chrome Cache Entry: 235
Web Open Font Format (Version 2), TrueType, length 48348, version 1.0
downloaded
Chrome Cache Entry: 237
JSON data
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (42611)
dropped
Chrome Cache Entry: 242
ASCII text, with very long lines (1303), with no line terminators
dropped
Chrome Cache Entry: 243
HTML document, ASCII text, with very long lines (788), with no line terminators
downloaded
Chrome Cache Entry: 245
Unicode text, UTF-8 text, with very long lines (52737), with no line terminators
downloaded
Chrome Cache Entry: 246
ASCII text, with very long lines (42611)
downloaded
Chrome Cache Entry: 247
Web Open Font Format (Version 2), TrueType, length 32424, version 1.0
downloaded
Chrome Cache Entry: 248
ASCII text, with very long lines (1568), with no line terminators
dropped
Chrome Cache Entry: 251
ASCII text, with very long lines (902), with no line terminators
downloaded
Chrome Cache Entry: 254
JSON data
dropped
Chrome Cache Entry: 256
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
downloaded
Chrome Cache Entry: 257
JSON data
downloaded
Chrome Cache Entry: 258
Unicode text, UTF-8 text, with very long lines (10562), with no line terminators
dropped
Chrome Cache Entry: 260
ASCII text, with very long lines (926), with no line terminators
downloaded
Chrome Cache Entry: 261
Web Open Font Format (Version 2), TrueType, length 31936, version 1.0
downloaded
Chrome Cache Entry: 262
Web Open Font Format (Version 2), TrueType, length 79792, version 1.0
downloaded
Chrome Cache Entry: 264
Unicode text, UTF-8 text, with very long lines (8327), with no line terminators
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 268
ASCII text, with very long lines (723)
downloaded
Chrome Cache Entry: 269
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 272
ASCII text
dropped
Chrome Cache Entry: 273
ASCII text, with very long lines (4754), with no line terminators
dropped
Chrome Cache Entry: 275
JSON data
dropped
Chrome Cache Entry: 277
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 279
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (9198)
dropped
Chrome Cache Entry: 285
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 289
Unicode text, UTF-8 text, with very long lines (30151), with no line terminators
downloaded
Chrome Cache Entry: 292
HTML document, ASCII text, with very long lines (1093)
downloaded
Chrome Cache Entry: 293
ASCII text, with very long lines (4755), with no line terminators
downloaded
Chrome Cache Entry: 296
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 297
JSON data
downloaded
Chrome Cache Entry: 298
JSON data
downloaded
Chrome Cache Entry: 300
Web Open Font Format (Version 2), TrueType, length 43516, version 1.0
downloaded
Chrome Cache Entry: 301
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 303
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 307
JSON data
dropped
Chrome Cache Entry: 309
HTML document, ASCII text, with very long lines (815)
downloaded
Chrome Cache Entry: 313
ASCII text, with very long lines (4723), with no line terminators
dropped
Chrome Cache Entry: 314
JSON data
downloaded
Chrome Cache Entry: 315
JSON data
downloaded
Chrome Cache Entry: 316
JSON data
downloaded
Chrome Cache Entry: 317
Web Open Font Format (Version 2), CFF, length 24260, version 1.0
downloaded
Chrome Cache Entry: 318
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 320
HTML document, ASCII text, with very long lines (1419), with no line terminators
downloaded
Chrome Cache Entry: 321
JSON data
dropped
Chrome Cache Entry: 322
Unicode text, UTF-8 text, with very long lines (2258)
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (19217), with no line terminators
downloaded
Chrome Cache Entry: 324
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 326
JSON data
dropped
Chrome Cache Entry: 327
ASCII text, with very long lines (29256), with no line terminators
dropped
Chrome Cache Entry: 328
gzip compressed data, max compression, from Unix, original size modulo 2^32 71723
downloaded
Chrome Cache Entry: 329
ASCII text, with very long lines (51248)
downloaded
Chrome Cache Entry: 330
ASCII text, with very long lines (64749)
dropped
Chrome Cache Entry: 331
gzip compressed data, from Unix, original size modulo 2^32 3516
dropped
Chrome Cache Entry: 332
HTML document, ASCII text, with very long lines (788), with no line terminators
downloaded
Chrome Cache Entry: 333
JSON data
downloaded
Chrome Cache Entry: 335
Web Open Font Format (Version 2), CFF, length 31448, version 1.0
downloaded
Chrome Cache Entry: 337
ASCII text, with very long lines (63670)
dropped
Chrome Cache Entry: 341
JSON data
downloaded
Chrome Cache Entry: 345
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 346
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
There are 97 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://email.email.pandadoc.net/c/eJxUkE9r4zwQxj-NdUuQR5ItHXQobfwG3rLQsmHbXspIGjeqE8m1FYfm0y-B7f65DcP8ht_zBOsa4XrNQvanI6XyGoPN-f7_7ilGN8iYdk8Pn-dxt_vOyNYtmMZwDpztLRpXK45GaGy9C943vK2NJgTDG-WQRQscZM1B1AJaztfS904pGYLuOTQtVZLTEeNhPWIKGLJfJyoszq9lQk_oDmTLdCJ2sPtSxrkSNxV0FXQ4jn8Qn48VdF_6FXQLVKIreaBUiTvSzgiJNQeJqLDhSoJpBAanJYFWrZO1kb6uRMdSLrGPHkvM6VqDaxuBBtpVCyBWEkW9wkbTCsko1-galQ4sT2-Y4uU39N85y5jEfDMn83C50P6beDlv2WTDe040V5K702Ggj9NhvKqziZY4_2J_iM3H6W67XV7Uop9j2dyq0D-yYr_S_TWuCk5v9M9mvl4sFtg5T8M8oqfrU_W4od1nvwdHIdy798HfDs_6ZwAAAP__1K2kLg
https://app.pandadoc.com/document/v2?token=e8b934a1024aa5a60542963adb84e2857b4194c1?

Domains

Name
IP
Malicious
dart.l.doubleclick.net
142.250.184.198
d31uqz37bvu6i7.cloudfront.net
13.32.118.18
js.hs-analytics.net
104.17.175.201
adservice.google.com
172.217.16.194
k8s-externalalb-25648c9733-463465099.us-west-2.elb.amazonaws.com
35.161.240.127
d296je7bbdd650.cloudfront.net
99.86.8.175
track.hubspot.com
104.16.117.116
bkugwjn.impervadns.net
45.223.20.103
email.email.pandadoc.net
108.138.26.86
www.google.com
142.250.186.68
api.segment.io
35.81.90.104
js.hs-banner.com
172.64.147.16
d3m3a7p0ze7hmq.cloudfront.net
143.204.215.16
x4whrmz.x.incapdns.net
45.223.20.103
ygbgw94.impervadns.net
45.223.20.103
prom-fe-gw.production.pandadoc.com
54.201.195.227
sentry.infrastructure.pandadoc.com
44.225.139.105
ad.doubleclick.net
142.250.186.166
grafana-agent-faro.production.pandadoc.com
44.225.74.212
ax-0001.ax-msedge.net
150.171.27.10
bm2ydo9.impervadns.net
45.223.20.103
js-na1.hs-scripts.com
104.16.137.209
googleads.g.doubleclick.net
216.58.206.66
td.doubleclick.net
216.58.206.66
cdn.cookielaw.org
104.18.86.42
geolocation.onetrust.com
172.64.155.119
ip2c.org
188.68.242.180
cdn.segment.com
unknown
signup.pandadoc.com
unknown
websocket.pandadoc.com
unknown
api.pandadoc.com
unknown
use.typekit.net
unknown
websocket-reserved.pandadoc.com
unknown
app.pandadoc.com
unknown
p.typekit.net
unknown
12370631.fls.doubleclick.net
unknown
There are 26 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
142.250.185.99
unknown
United States
142.250.74.206
unknown
United States
2.19.126.206
unknown
European Union
142.250.185.226
unknown
United States
44.225.186.56
unknown
United States
143.204.215.126
unknown
United States
104.18.32.137
unknown
United States
142.250.186.110
unknown
United States
188.68.242.180
ip2c.org
Poland
143.204.215.75
unknown
United States
35.162.177.163
unknown
United States
35.155.246.37
unknown
United States
104.18.87.42
unknown
United States
1.1.1.1
unknown
Australia
142.250.184.198
dart.l.doubleclick.net
United States
216.58.206.40
unknown
United States
142.250.186.38
unknown
United States
172.217.18.4
unknown
United States
104.16.137.209
js-na1.hs-scripts.com
United States
52.12.47.65
unknown
United States
172.217.18.2
unknown
United States
142.251.173.84
unknown
United States
172.64.155.119
geolocation.onetrust.com
United States
54.69.251.6
unknown
United States
104.17.175.201
js.hs-analytics.net
United States
2.19.126.198
unknown
European Union
239.255.255.250
unknown
Reserved
142.250.185.196
unknown
United States
142.250.185.230
unknown
United States
99.86.8.175
d296je7bbdd650.cloudfront.net
United States
172.217.16.194
adservice.google.com
United States
143.204.215.16
d3m3a7p0ze7hmq.cloudfront.net
United States
2.16.164.105
unknown
European Union
44.225.74.212
grafana-agent-faro.production.pandadoc.com
United States
54.201.195.227
prom-fe-gw.production.pandadoc.com
United States
142.250.185.200
unknown
United States
13.32.118.18
d31uqz37bvu6i7.cloudfront.net
United States
192.168.2.16
unknown
unknown
142.250.185.166
unknown
United States
35.161.240.127
k8s-externalalb-25648c9733-463465099.us-west-2.elb.amazonaws.com
United States
45.223.20.103
bkugwjn.impervadns.net
United States
192.168.2.23
unknown
unknown
150.171.28.10
unknown
United States
172.64.147.16
js.hs-banner.com
United States
104.16.160.168
unknown
United States
108.138.26.86
email.email.pandadoc.net
United States
142.250.186.162
unknown
United States
216.58.206.66
googleads.g.doubleclick.net
United States
2.19.126.219
unknown
European Union
150.171.27.10
ax-0001.ax-msedge.net
United States
2.19.126.211
unknown
European Union
44.225.139.105
sentry.infrastructure.pandadoc.com
United States
142.250.185.131
unknown
United States
35.81.90.104
api.segment.io
United States
142.250.186.166
ad.doubleclick.net
United States
142.250.186.168
unknown
United States
104.18.86.42
cdn.cookielaw.org
United States
104.16.117.116
track.hubspot.com
United States
There are 49 hidden IPs, click here to show them.