IOC Report
https://email.email.pandadoc.net/c/eJxUkE9r4zwQxj-NdUuQR5ItHXQobfwG3rLQsmHbXspIGjeqE8m1FYfm0y-B7f65DcP8ht_zBOsa4XrNQvanI6XyGoPN-f7_7ilGN8iYdk8Pn-dxt_vOyNYtmMZwDpztLRpXK45GaGy9C943vK2NJgTDG-WQRQscZM1B1AJaztfS904pGYLuOTQtVZLTEeNhPWIKGLJfJyoszq9lQk_oDmTLdCJ2sPtSxrkSNxV0FXQ4jn8Qn48VdF_6FXQLVKIreaBUiTvSz

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:49:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:49:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:49:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:49:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 14:49:56 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 182
JSON data
dropped
Chrome Cache Entry: 184
Unicode text, UTF-8 text, with very long lines (18223)
dropped
Chrome Cache Entry: 189
JSON data
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 191
Web Open Font Format (Version 2), TrueType, length 32036, version 1.0
downloaded
Chrome Cache Entry: 192
ASCII text, with very long lines (4733), with no line terminators
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (4877), with no line terminators
downloaded
Chrome Cache Entry: 199
Web Open Font Format (Version 2), TrueType, length 31852, version 1.0
downloaded
Chrome Cache Entry: 203
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 204
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 206
ASCII text, with very long lines (4765), with no line terminators
downloaded
Chrome Cache Entry: 209
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 210
Web Open Font Format (Version 2), CFF, length 35648, version 1.0
downloaded
Chrome Cache Entry: 211
JSON data
downloaded
Chrome Cache Entry: 212
Unicode text, UTF-8 text, with very long lines (2495)
dropped
Chrome Cache Entry: 213
ASCII text, with very long lines (52618), with no line terminators
dropped
Chrome Cache Entry: 216
JSON data
downloaded
Chrome Cache Entry: 217
Web Open Font Format (Version 2), TrueType, length 50436, version 1.0
downloaded
Chrome Cache Entry: 218
Web Open Font Format (Version 2), CFF, length 33448, version 1.0
downloaded
Chrome Cache Entry: 219
Unicode text, UTF-8 text, with very long lines (13330), with no line terminators
dropped
Chrome Cache Entry: 223
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (17508), with no line terminators
downloaded
Chrome Cache Entry: 226
JSON data
dropped
Chrome Cache Entry: 228
ASCII text, with very long lines (1490)
dropped
Chrome Cache Entry: 229
ASCII text, with very long lines (63670)
dropped
Chrome Cache Entry: 232
JSON data
dropped
Chrome Cache Entry: 233
Web Open Font Format (Version 2), TrueType, length 47828, version 1.0
downloaded
Chrome Cache Entry: 235
JSON data
downloaded
Chrome Cache Entry: 236
JSON data
downloaded
Chrome Cache Entry: 237
JSON data
dropped
Chrome Cache Entry: 238
ASCII text, with very long lines (11231)
dropped
Chrome Cache Entry: 239
ASCII text, with very long lines (22445)
downloaded
Chrome Cache Entry: 242
JSON data
downloaded
Chrome Cache Entry: 244
Web Open Font Format (Version 2), TrueType, length 48348, version 1.0
downloaded
Chrome Cache Entry: 245
ASCII text, with very long lines (29256), with no line terminators
downloaded
Chrome Cache Entry: 246
JSON data
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (42611)
dropped
Chrome Cache Entry: 249
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
downloaded
Chrome Cache Entry: 250
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 254
ASCII text, with very long lines (42611)
downloaded
Chrome Cache Entry: 255
Web Open Font Format (Version 2), TrueType, length 32424, version 1.0
downloaded
Chrome Cache Entry: 256
ASCII text, with very long lines (1568), with no line terminators
dropped
Chrome Cache Entry: 257
JSON data
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (902), with no line terminators
downloaded
Chrome Cache Entry: 261
JSON data
dropped
Chrome Cache Entry: 263
ASCII text, with very long lines (4877), with no line terminators
dropped
Chrome Cache Entry: 265
JSON data
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (9198)
downloaded
Chrome Cache Entry: 268
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (926), with no line terminators
downloaded
Chrome Cache Entry: 270
Web Open Font Format (Version 2), TrueType, length 31936, version 1.0
downloaded
Chrome Cache Entry: 271
Web Open Font Format (Version 2), TrueType, length 79792, version 1.0
downloaded
Chrome Cache Entry: 273
HTML document, ASCII text, with very long lines (1419), with no line terminators
downloaded
Chrome Cache Entry: 275
Unicode text, UTF-8 text, with very long lines (8327), with no line terminators
downloaded
Chrome Cache Entry: 277
Unicode text, UTF-8 text, with very long lines (10562), with no line terminators
downloaded
Chrome Cache Entry: 278
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 279
ASCII text, with very long lines (723)
downloaded
Chrome Cache Entry: 280
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 283
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
downloaded
Chrome Cache Entry: 284
HTML document, ASCII text, with very long lines (788), with no line terminators
downloaded
Chrome Cache Entry: 285
JSON data
dropped
Chrome Cache Entry: 286
ASCII text, with very long lines (4733), with no line terminators
dropped
Chrome Cache Entry: 287
JSON data
dropped
Chrome Cache Entry: 288
Unicode text, UTF-8 text, with very long lines (2258)
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 292
ASCII text, with very long lines (5164), with no line terminators
downloaded
Chrome Cache Entry: 293
Unicode text, UTF-8 text, with very long lines (52737), with no line terminators
dropped
Chrome Cache Entry: 296
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 298
JSON data
dropped
Chrome Cache Entry: 300
Unicode text, UTF-8 text, with very long lines (30151), with no line terminators
downloaded
Chrome Cache Entry: 303
HTML document, ASCII text, with very long lines (1093)
downloaded
Chrome Cache Entry: 306
ASCII text, with very long lines (1303), with no line terminators
downloaded
Chrome Cache Entry: 307
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
dropped
Chrome Cache Entry: 310
JSON data
downloaded
Chrome Cache Entry: 311
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 312
Web Open Font Format (Version 2), TrueType, length 43516, version 1.0
downloaded
Chrome Cache Entry: 313
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 315
ASCII text, with very long lines (64749)
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 320
JSON data
dropped
Chrome Cache Entry: 322
HTML document, ASCII text, with very long lines (815)
downloaded
Chrome Cache Entry: 324
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 325
HTML document, ASCII text, with very long lines (833), with no line terminators
downloaded
Chrome Cache Entry: 326
ASCII text, with very long lines (4765), with no line terminators
dropped
Chrome Cache Entry: 327
JSON data
downloaded
Chrome Cache Entry: 328
JSON data
downloaded
Chrome Cache Entry: 330
Web Open Font Format (Version 2), CFF, length 24260, version 1.0
downloaded
Chrome Cache Entry: 335
JSON data
dropped
Chrome Cache Entry: 337
ASCII text, with very long lines (19217), with no line terminators
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 339
JSON data
dropped
Chrome Cache Entry: 341
gzip compressed data, max compression, from Unix, original size modulo 2^32 71723
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (51248)
downloaded
Chrome Cache Entry: 345
gzip compressed data, from Unix, original size modulo 2^32 3516
dropped
Chrome Cache Entry: 346
HTML document, ASCII text, with very long lines (787), with no line terminators
downloaded
Chrome Cache Entry: 347
JSON data
downloaded
Chrome Cache Entry: 349
Web Open Font Format (Version 2), CFF, length 31448, version 1.0
downloaded
Chrome Cache Entry: 351
HTML document, ASCII text, with very long lines (1419), with no line terminators
downloaded
Chrome Cache Entry: 352
ASCII text, with very long lines (3457)
dropped
Chrome Cache Entry: 353
JSON data
downloaded
Chrome Cache Entry: 354
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 357
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 359
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 360
ASCII text, with very long lines (41360), with no line terminators
dropped
There are 102 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://email.email.pandadoc.net/c/eJxUkE9r4zwQxj-NdUuQR5ItHXQobfwG3rLQsmHbXspIGjeqE8m1FYfm0y-B7f65DcP8ht_zBOsa4XrNQvanI6XyGoPN-f7_7ilGN8iYdk8Pn-dxt_vOyNYtmMZwDpztLRpXK45GaGy9C943vK2NJgTDG-WQRQscZM1B1AJaztfS904pGYLuOTQtVZLTEeNhPWIKGLJfJyoszq9lQk_oDmTLdCJ2sPtSxrkSNxV0FXQ4jn8Qn48VdF_6FXQLVKIreaBUiTvSzgiJNQeJqLDhSoJpBAanJYFWrZO1kb6uRMdSLrGPHkvM6VqDaxuBBtpVCyBWEkW9wkbTCsko1-galQ4sT2-Y4uU39N85y5jEfDMn83C50P6beDlv2WTDe040V5K702Ggj9NhvKqziZY4_2J_iM3H6W67XV7Uop9j2dyq0D-yYr_S_TWuCk5v9M9mvl4sFtg5T8M8oqfrU_W4od1nvwdHIdy798HfDs_6ZwAAAP__1K2kLg
https://app.pandadoc.com/document/v2?token=e8b934a1024aa5a60542963adb84e2857b4194c1?

Domains

Name
IP
Malicious
dart.l.doubleclick.net
142.250.185.134
d31uqz37bvu6i7.cloudfront.net
13.32.118.18
js.hs-analytics.net
104.16.160.168
adservice.google.com
172.217.16.194
k8s-externalalb-25648c9733-463465099.us-west-2.elb.amazonaws.com
34.218.165.218
d296je7bbdd650.cloudfront.net
99.86.8.175
track.hubspot.com
104.16.118.116
bkugwjn.impervadns.net
45.223.20.103
email.email.pandadoc.net
108.138.26.88
www.google.com
142.250.186.36
api.segment.io
54.203.25.147
js.hs-banner.com
104.18.40.240
d3m3a7p0ze7hmq.cloudfront.net
143.204.215.126
a.nel.cloudflare.com
35.190.80.1
x4whrmz.x.incapdns.net
45.223.20.103
ygbgw94.impervadns.net
45.223.20.103
prom-fe-gw.production.pandadoc.com
54.201.195.227
sentry.infrastructure.pandadoc.com
35.162.177.163
ad.doubleclick.net
172.217.18.102
grafana-agent-faro.production.pandadoc.com
44.225.74.212
ax-0001.ax-msedge.net
150.171.28.10
bm2ydo9.impervadns.net
45.223.20.103
js-na1.hs-scripts.com
104.16.139.209
googleads.g.doubleclick.net
142.250.185.98
td.doubleclick.net
142.250.186.66
cdn.cookielaw.org
104.18.86.42
geolocation.onetrust.com
104.18.32.137
ip2c.org
188.68.242.180
cdn.segment.com
unknown
signup.pandadoc.com
unknown
websocket.pandadoc.com
unknown
api.pandadoc.com
unknown
use.typekit.net
unknown
websocket-reserved.pandadoc.com
unknown
app.pandadoc.com
unknown
p.typekit.net
unknown
12370631.fls.doubleclick.net
unknown
There are 27 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.228
unknown
United States
2.19.126.206
unknown
European Union
104.16.139.209
js-na1.hs-scripts.com
United States
142.250.185.226
unknown
United States
104.16.118.116
track.hubspot.com
United States
143.204.215.126
d3m3a7p0ze7hmq.cloudfront.net
United States
104.18.40.240
js.hs-banner.com
United States
104.18.32.137
geolocation.onetrust.com
United States
142.250.184.226
unknown
United States
104.16.138.209
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
188.68.242.180
ip2c.org
Poland
142.250.186.74
unknown
United States
13.32.118.85
unknown
United States
35.162.177.163
sentry.infrastructure.pandadoc.com
United States
143.204.215.75
unknown
United States
1.1.1.1
unknown
Australia
142.250.186.36
www.google.com
United States
172.217.18.4
unknown
United States
172.217.18.3
unknown
United States
34.223.74.168
unknown
United States
104.17.175.201
unknown
United States
2.19.126.198
unknown
European Union
239.255.255.250
unknown
Reserved
142.250.185.196
unknown
United States
104.16.141.209
unknown
United States
172.217.18.102
ad.doubleclick.net
United States
99.86.8.175
d296je7bbdd650.cloudfront.net
United States
172.217.16.194
adservice.google.com
United States
142.250.185.72
unknown
United States
142.250.186.104
unknown
United States
143.204.215.16
unknown
United States
142.250.185.206
unknown
United States
44.225.74.212
grafana-agent-faro.production.pandadoc.com
United States
54.201.195.227
prom-fe-gw.production.pandadoc.com
United States
13.32.118.18
d31uqz37bvu6i7.cloudfront.net
United States
192.168.2.16
unknown
unknown
142.250.181.230
unknown
United States
172.217.23.110
unknown
United States
44.240.52.117
unknown
United States
45.223.20.103
bkugwjn.impervadns.net
United States
150.171.28.10
ax-0001.ax-msedge.net
United States
172.64.147.16
unknown
United States
104.16.160.168
js.hs-analytics.net
United States
54.203.25.147
api.segment.io
United States
108.138.26.88
email.email.pandadoc.net
United States
142.250.184.200
unknown
United States
142.250.186.162
unknown
United States
142.250.185.134
dart.l.doubleclick.net
United States
216.58.206.66
unknown
United States
2.19.126.219
unknown
European Union
142.250.185.132
unknown
United States
13.32.118.174
unknown
United States
34.218.165.218
k8s-externalalb-25648c9733-463465099.us-west-2.elb.amazonaws.com
United States
150.171.27.10
unknown
United States
142.250.181.227
unknown
United States
2.19.126.211
unknown
European Union
64.233.167.84
unknown
United States
44.225.139.105
unknown
United States
142.250.185.130
unknown
United States
35.81.90.104
unknown
United States
34.211.201.77
unknown
United States
104.18.86.42
cdn.cookielaw.org
United States
104.16.117.116
unknown
United States
142.250.186.66
td.doubleclick.net
United States
142.250.185.98
googleads.g.doubleclick.net
United States
There are 56 hidden IPs, click here to show them.