IOC Report
https://view.flodesk.com/emails/671a6d1f7ce9f793bb70518a

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 18:11:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 18:11:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 18:11:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 18:11:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 18:11:49 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://view.flodesk.com/emails/671a6d1f7ce9f793bb70518a
malicious
https://maggart.epdfonline.info/&redirect=22cbcae7c6c01bc7789d26be305d450f4d698e07main&uid=f253efe302d32ab264a76e0ce65be769671a9c1685c8e
malicious
https://view.flodesk.com/emails/671a6d1f7ce9f793bb70518a
https://maggart.epdfonline.info/
https://maggart.epdfonline.info/?__cf_chl_rt_tk=XIhaNuCPDDnZoHa8Ow8nmcsrkbWrYMlGUSuVpClS6Z4-1729797117-1.0.1.1-z_QF__kh5GgxKeFkqbbUxzS7buRYSRKioqL.JopT_wg

Domains

Name
IP
Malicious
maggart.epdfonline.info
172.67.198.56
malicious
d24ja5rr2ru810.cloudfront.net
13.32.27.60
a.nel.cloudflare.com
35.190.80.1
challenges.cloudflare.com
104.18.94.41
www.google.com
142.250.74.196
flodesk.com
104.18.18.100
drjpqllaq6nvc.cloudfront.net
3.160.150.117
d19bko3sd5yxe1.cloudfront.net
18.245.46.106
usercontent.flodesk.com
unknown
view.flodesk.com
unknown
assets.flodesk.com
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.67.198.56
maggart.epdfonline.info
United States
malicious
13.32.27.60
d24ja5rr2ru810.cloudfront.net
United States
142.250.186.35
unknown
United States
142.250.184.195
unknown
United States
104.21.44.88
unknown
United States
1.1.1.1
unknown
Australia
18.245.46.106
d19bko3sd5yxe1.cloudfront.net
United States
142.250.74.206
unknown
United States
3.160.150.117
drjpqllaq6nvc.cloudfront.net
United States
104.18.94.41
challenges.cloudflare.com
United States
192.168.2.16
unknown
unknown
13.32.27.27
unknown
United States
104.18.95.41
unknown
United States
142.250.185.106
unknown
United States
104.18.18.100
flodesk.com
United States
239.255.255.250
unknown
Reserved
192.168.2.23
unknown
unknown
142.250.186.142
unknown
United States
64.233.184.84
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.74.196
www.google.com
United States
There are 11 hidden IPs, click here to show them.