IOC Report
https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ff

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:58:13 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:58:13 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:58:13 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:58:13 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:58:13 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 133
JSON data
dropped
Chrome Cache Entry: 140
ASCII text, with very long lines (6416)
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 32036, version 1.0
downloaded
Chrome Cache Entry: 145
Web Open Font Format (Version 2), TrueType, length 31852, version 1.0
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 149
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 151
JSON data
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (63670)
downloaded
Chrome Cache Entry: 156
Web Open Font Format (Version 2), CFF, length 35648, version 1.0
downloaded
Chrome Cache Entry: 157
Unicode text, UTF-8 text, with very long lines (2495)
dropped
Chrome Cache Entry: 158
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 160
JSON data
downloaded
Chrome Cache Entry: 161
Web Open Font Format (Version 2), TrueType, length 50436, version 1.0
downloaded
Chrome Cache Entry: 162
Web Open Font Format (Version 2), CFF, length 33448, version 1.0
downloaded
Chrome Cache Entry: 163
Unicode text, UTF-8 text, with very long lines (13330), with no line terminators
dropped
Chrome Cache Entry: 164
ASCII text, with very long lines (41360), with no line terminators
downloaded
Chrome Cache Entry: 165
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 166
JSON data
downloaded
Chrome Cache Entry: 167
JSON data
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (4740), with no line terminators
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (1490)
dropped
Chrome Cache Entry: 170
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
downloaded
Chrome Cache Entry: 172
gzip compressed data, from Unix, original size modulo 2^32 3516
downloaded
Chrome Cache Entry: 174
Web Open Font Format (Version 2), TrueType, length 47828, version 1.0
downloaded
Chrome Cache Entry: 175
JSON data
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (21589), with no line terminators
dropped
Chrome Cache Entry: 178
ASCII text, with very long lines (51248)
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (22445)
downloaded
Chrome Cache Entry: 180
JSON data
dropped
Chrome Cache Entry: 181
JSON data
downloaded
Chrome Cache Entry: 182
ASCII text, with very long lines (4740), with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (29256), with no line terminators
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (42611)
dropped
Chrome Cache Entry: 186
ASCII text, with very long lines (1303), with no line terminators
dropped
Chrome Cache Entry: 187
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (42611)
downloaded
Chrome Cache Entry: 189
Web Open Font Format (Version 2), TrueType, length 32424, version 1.0
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (1568), with no line terminators
dropped
Chrome Cache Entry: 192
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 196
JSON data
dropped
Chrome Cache Entry: 197
JSON data
downloaded
Chrome Cache Entry: 198
JSON data
downloaded
Chrome Cache Entry: 199
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
downloaded
Chrome Cache Entry: 200
JSON data
downloaded
Chrome Cache Entry: 203
Web Open Font Format (Version 2), TrueType, length 31936, version 1.0
downloaded
Chrome Cache Entry: 204
Web Open Font Format (Version 2), TrueType, length 79792, version 1.0
downloaded
Chrome Cache Entry: 207
Unicode text, UTF-8 text, with very long lines (10562), with no line terminators
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (723)
downloaded
Chrome Cache Entry: 211
JSON data
dropped
Chrome Cache Entry: 212
ASCII text, with very long lines (902), with no line terminators
dropped
Chrome Cache Entry: 214
Unicode text, UTF-8 text, with very long lines (2258)
downloaded
Chrome Cache Entry: 215
HTML document, ASCII text, with very long lines (1093)
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (9198)
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 218
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 219
gzip compressed data, max compression, from Unix, original size modulo 2^32 71723
dropped
Chrome Cache Entry: 221
Unicode text, UTF-8 text, with very long lines (18223)
downloaded
Chrome Cache Entry: 225
JSON data
downloaded
Chrome Cache Entry: 226
Web Open Font Format (Version 2), TrueType, length 43516, version 1.0
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 228
ASCII text, with very long lines (64749)
downloaded
Chrome Cache Entry: 229
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 231
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 232
ASCII text, with very long lines (19217), with no line terminators
dropped
Chrome Cache Entry: 235
HTML document, ASCII text, with very long lines (815)
downloaded
Chrome Cache Entry: 236
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 237
JSON data
downloaded
Chrome Cache Entry: 239
JSON data
downloaded
Chrome Cache Entry: 240
Web Open Font Format (Version 2), CFF, length 24260, version 1.0
downloaded
Chrome Cache Entry: 241
HTML document, ASCII text, with very long lines (1419), with no line terminators
downloaded
Chrome Cache Entry: 242
JSON data
dropped
Chrome Cache Entry: 251
Web Open Font Format (Version 2), CFF, length 31448, version 1.0
downloaded
Chrome Cache Entry: 252
JSON data
downloaded
Chrome Cache Entry: 254
JSON data
downloaded
Chrome Cache Entry: 255
HTML document, ASCII text, with very long lines (794), with no line terminators
downloaded
Chrome Cache Entry: 257
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 258
JSON data
dropped
There are 76 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ff
https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ff

Domains

Name
IP
Malicious
js.hs-banner.com
104.18.40.240
d3m3a7p0ze7hmq.cloudfront.net
143.204.215.126
dart.l.doubleclick.net
172.217.18.6
d31uqz37bvu6i7.cloudfront.net
13.32.118.196
x4whrmz.x.incapdns.net
45.223.20.103
prom-fe-gw.production.pandadoc.com
44.225.186.56
sentry.infrastructure.pandadoc.com
44.236.119.144
ad.doubleclick.net
172.217.16.198
grafana-agent-faro.production.pandadoc.com
52.11.53.144
js.hs-analytics.net
104.17.175.201
adservice.google.com
142.250.186.130
ax-0001.ax-msedge.net
150.171.28.10
bm2ydo9.impervadns.net
45.223.20.103
d296je7bbdd650.cloudfront.net
99.86.8.175
js-na1.hs-scripts.com
104.16.139.209
track.hubspot.com
104.16.118.116
googleads.g.doubleclick.net
142.250.185.130
www.google.com
172.217.16.196
td.doubleclick.net
142.250.185.226
api.segment.io
35.81.90.104
cdn.cookielaw.org
104.18.87.42
geolocation.onetrust.com
104.18.32.137
ip2c.org
188.68.242.180
api.pandadoc.com
unknown
use.typekit.net
unknown
app.pandadoc.com
unknown
cdn.segment.com
unknown
12370631.fls.doubleclick.net
unknown
There are 18 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.130
adservice.google.com
United States
142.250.185.200
unknown
United States
192.168.2.16
unknown
unknown
142.251.116.97
unknown
United States
2.19.126.206
unknown
European Union
142.250.185.226
td.doubleclick.net
United States
104.16.139.209
js-na1.hs-scripts.com
United States
44.225.186.56
prom-fe-gw.production.pandadoc.com
United States
104.16.118.116
track.hubspot.com
United States
143.204.215.126
d3m3a7p0ze7hmq.cloudfront.net
United States
104.18.40.240
js.hs-banner.com
United States
104.18.32.137
geolocation.onetrust.com
United States
142.250.185.163
unknown
United States
45.223.20.103
x4whrmz.x.incapdns.net
United States
52.11.53.144
grafana-agent-faro.production.pandadoc.com
United States
150.171.28.10
ax-0001.ax-msedge.net
United States
188.68.242.180
ip2c.org
Poland
142.250.186.136
unknown
United States
142.250.186.78
unknown
United States
104.18.87.42
cdn.cookielaw.org
United States
1.1.1.1
unknown
Australia
142.250.186.36
unknown
United States
172.217.18.6
dart.l.doubleclick.net
United States
13.32.118.196
d31uqz37bvu6i7.cloudfront.net
United States
13.32.118.174
unknown
United States
142.250.185.238
unknown
United States
172.217.18.2
unknown
United States
34.223.74.168
unknown
United States
172.64.155.119
unknown
United States
104.17.175.201
js.hs-analytics.net
United States
2.19.126.198
unknown
European Union
239.255.255.250
unknown
Reserved
143.204.215.81
unknown
United States
142.250.185.130
googleads.g.doubleclick.net
United States
142.250.185.196
unknown
United States
104.16.141.209
unknown
United States
64.233.184.84
unknown
United States
35.81.90.104
api.segment.io
United States
99.86.8.175
d296je7bbdd650.cloudfront.net
United States
44.236.119.144
sentry.infrastructure.pandadoc.com
United States
172.217.16.196
www.google.com
United States
172.217.16.195
unknown
United States
172.217.16.198
ad.doubleclick.net
United States
There are 33 hidden IPs, click here to show them.