IOC Report
https://www.eventcreate.com/e/11-7-24-raleigh-11th-hou-614158

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 19:48:12 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 19:48:12 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 19:48:12 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 19:48:12 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 23 19:48:12 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 129
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (398)
downloaded
Chrome Cache Entry: 133
JSON data
downloaded
Chrome Cache Entry: 134
Web Open Font Format (Version 2), TrueType, length 32272, version 1.0
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (26548)
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (4825), with no line terminators
dropped
Chrome Cache Entry: 140
ASCII text, with very long lines (390)
downloaded
Chrome Cache Entry: 141
ASCII text
downloaded
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 22052, version 1.0
downloaded
Chrome Cache Entry: 145
ASCII text
downloaded
Chrome Cache Entry: 147
ASCII text
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (2134)
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (18959)
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (390)
downloaded
Chrome Cache Entry: 154
Web Open Font Format (Version 2), CFF, length 34148, version 1.0
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (4808), with no line terminators
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (3969)
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (326)
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (11906), with no line terminators
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (4136)
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (5552)
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (1407), with no line terminators
dropped
Chrome Cache Entry: 164
Web Open Font Format (Version 2), TrueType, length 318036, version 770.256
downloaded
Chrome Cache Entry: 165
HTML document, ASCII text, with very long lines (32087)
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (10075)
dropped
Chrome Cache Entry: 168
Web Open Font Format (Version 2), TrueType, length 20040, version 1.0
downloaded
Chrome Cache Entry: 169
ASCII text
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (7726)
dropped
Chrome Cache Entry: 171
Web Open Font Format (Version 2), CFF, length 33364, version 1.0
downloaded
Chrome Cache Entry: 172
HTML document, Unicode text, UTF-8 text, with very long lines (9031)
downloaded
Chrome Cache Entry: 173
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (65401)
downloaded
Chrome Cache Entry: 177
ASCII text
downloaded
Chrome Cache Entry: 178
assembler source, ASCII text, with very long lines (302)
downloaded
Chrome Cache Entry: 179
ASCII text
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (32746)
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (63798)
downloaded
Chrome Cache Entry: 183
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1600x1067, components 3
downloaded
Chrome Cache Entry: 184
HTML document, ASCII text, with very long lines (2900), with no line terminators
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (4935), with no line terminators
downloaded
Chrome Cache Entry: 187
ASCII text
downloaded
Chrome Cache Entry: 190
ASCII text
downloaded
Chrome Cache Entry: 194
ASCII text
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (7726)
downloaded
Chrome Cache Entry: 196
Web Open Font Format (Version 2), TrueType, length 32972, version 1.0
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (4936), with no line terminators
dropped
Chrome Cache Entry: 203
Unicode text, UTF-8 text, with very long lines (516)
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (3969)
downloaded
Chrome Cache Entry: 208
JSON data
dropped
Chrome Cache Entry: 211
HTML document, ASCII text, with very long lines (2922), with no line terminators
downloaded
Chrome Cache Entry: 212
ASCII text
downloaded
Chrome Cache Entry: 213
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
dropped
Chrome Cache Entry: 214
Web Open Font Format (Version 2), TrueType, length 19780, version 1.0
downloaded
Chrome Cache Entry: 216
Web Open Font Format (Version 2), TrueType, length 31052, version 1.0
downloaded
Chrome Cache Entry: 219
HTML document, ASCII text, with very long lines (32087)
downloaded
Chrome Cache Entry: 220
ASCII text
downloaded
Chrome Cache Entry: 224
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 227
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 228
ASCII text, with very long lines (8136), with no line terminators
dropped
Chrome Cache Entry: 229
PNG image data, 1000 x 250, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 230
ASCII text, with very long lines (10635)
dropped
Chrome Cache Entry: 231
ASCII text, with very long lines (554)
dropped
Chrome Cache Entry: 233
Web Open Font Format (Version 2), TrueType, length 20144, version 1.0
downloaded
Chrome Cache Entry: 234
ASCII text
downloaded
Chrome Cache Entry: 237
ASCII text, with very long lines (9217)
dropped
Chrome Cache Entry: 238
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 239
ASCII text
downloaded
Chrome Cache Entry: 241
Web Open Font Format (Version 2), TrueType, length 18596, version 1.0
downloaded
Chrome Cache Entry: 242
ASCII text
downloaded
Chrome Cache Entry: 243
ASCII text
downloaded
Chrome Cache Entry: 245
ASCII text, with very long lines (10635)
downloaded
Chrome Cache Entry: 246
Web Open Font Format (Version 2), CFF, length 33156, version 1.0
downloaded
There are 69 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://www.eventcreate.com/e/11-7-24-raleigh-11th-hou-614158
https://checkout.eventcreate.com/11-7-24-raleigh-11th-hou-614158/register-details?oid=384e8ae7-a9d0-486d-91dd-3f11895a5308
https://www.eventcreate.com/e/11-7-24-raleigh-11th-hou-614158

Domains

Name
IP
Malicious
plausible.io
169.150.236.105
star-mini.c10r.facebook.com
157.240.0.35
scontent.xx.fbcdn.net
157.240.253.1
googleads.g.doubleclick.net
142.250.186.34
cdnjs.cloudflare.com
104.17.25.14
script.tapfiliate.com
13.32.121.127
www.google.com
216.58.206.36
td.doubleclick.net
142.250.185.162
checkout.eventcreate.com
104.18.13.16
s3-r-w.us-west-1.amazonaws.com
52.219.113.122
www.eventcreate.com
104.18.12.16
ax-0001.ax-msedge.net
150.171.27.10
eventcreate-v1.s3.us-west-1.amazonaws.com
unknown
use.typekit.net
unknown
res.cloudinary.com
unknown
www.facebook.com
unknown
connect.facebook.net
unknown
p.typekit.net
unknown
cdn-4.convertexperiments.com
unknown
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.32.121.127
script.tapfiliate.com
United States
216.58.212.142
unknown
United States
23.201.242.112
unknown
United States
169.150.247.38
unknown
United States
142.250.185.227
unknown
United States
142.250.185.106
unknown
United States
142.250.186.72
unknown
United States
104.18.13.16
checkout.eventcreate.com
United States
52.219.113.122
s3-r-w.us-west-1.amazonaws.com
United States
216.239.32.178
unknown
United States
142.250.184.195
unknown
United States
142.250.186.34
googleads.g.doubleclick.net
United States
142.250.184.196
unknown
United States
1.1.1.1
unknown
Australia
3.5.163.130
unknown
United States
157.240.0.35
star-mini.c10r.facebook.com
United States
169.150.236.105
plausible.io
United States
2.19.126.198
unknown
European Union
239.255.255.250
unknown
Reserved
142.250.185.196
unknown
United States
142.250.184.238
unknown
United States
104.18.12.16
www.eventcreate.com
United States
172.217.16.195
unknown
United States
104.17.25.14
cdnjs.cloudflare.com
United States
2.19.224.32
unknown
European Union
142.250.185.206
unknown
United States
216.58.206.74
unknown
United States
142.250.186.174
unknown
United States
142.250.186.130
unknown
United States
216.58.206.34
unknown
United States
192.168.2.16
unknown
unknown
216.58.206.36
www.google.com
United States
157.240.0.6
unknown
United States
18.239.36.116
unknown
United States
150.171.28.10
unknown
United States
142.250.185.162
td.doubleclick.net
United States
157.240.252.35
unknown
United States
142.250.186.136
unknown
United States
142.250.184.202
unknown
United States
142.250.110.84
unknown
United States
104.17.24.14
unknown
United States
216.58.212.132
unknown
United States
2.19.126.219
unknown
European Union
150.171.27.10
ax-0001.ax-msedge.net
United States
157.240.251.9
unknown
United States
142.250.185.170
unknown
United States
142.250.185.130
unknown
United States
157.240.253.1
scontent.xx.fbcdn.net
United States
157.240.251.35
unknown
United States
There are 39 hidden IPs, click here to show them.