IOC Report
https://bioaquatictesting-my.sharepoint.com/:f:/g/personal/securedocument_bio-aquatic_com/Eu0LAzG4abJJn1FmlYYk6C0Bm-68IB0eiVR_FSTw6lLEjw?e=pg8DKY

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 127
ASCII text, with very long lines (42915)
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (3820)
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (3820)
downloaded
Chrome Cache Entry: 130
Unicode text, UTF-8 text, with very long lines (62786), with no line terminators
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (65461)
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (65308), with no line terminators
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (5394)
dropped
Chrome Cache Entry: 134
ASCII text, with very long lines (945)
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (59425)
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (45506)
dropped
Chrome Cache Entry: 137
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 138
ASCII text, with very long lines (16803)
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (65461)
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (63604)
dropped
Chrome Cache Entry: 141
ASCII text
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (65461)
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (52343)
dropped
Chrome Cache Entry: 144
ASCII text, with very long lines (12946)
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (59425)
downloaded
Chrome Cache Entry: 146
Unicode text, UTF-8 text, with very long lines (41526)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (4715)
dropped
Chrome Cache Entry: 148
Unicode text, UTF-8 text, with very long lines (5314)
downloaded
Chrome Cache Entry: 149
JSON data
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (59425)
dropped
Chrome Cache Entry: 151
OpenPGP Public Key
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (9848)
dropped
Chrome Cache Entry: 153
Unicode text, UTF-8 text, with very long lines (18772)
dropped
Chrome Cache Entry: 154
ASCII text, with very long lines (5436)
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (45506)
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (911)
dropped
Chrome Cache Entry: 157
JSON data
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (5436)
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (45506)
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (63604)
downloaded
Chrome Cache Entry: 161
data
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (6757)
dropped
Chrome Cache Entry: 163
ASCII text, with very long lines (911)
downloaded
Chrome Cache Entry: 164
Unicode text, UTF-8 text, with very long lines (5314)
dropped
Chrome Cache Entry: 165
ASCII text, with very long lines (24799)
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (4715)
downloaded
Chrome Cache Entry: 167
HTML document, ASCII text, with very long lines (56751), with CRLF line terminators
downloaded
Chrome Cache Entry: 168
Unicode text, UTF-8 text, with very long lines (7518)
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (6882)
dropped
Chrome Cache Entry: 170
Unicode text, UTF-8 text, with very long lines (41526)
dropped
Chrome Cache Entry: 171
ASCII text, with very long lines (52343)
downloaded
Chrome Cache Entry: 172
C source, ASCII text, with very long lines (11725)
dropped
Chrome Cache Entry: 173
ASCII text, with very long lines (12946)
dropped
Chrome Cache Entry: 174
ASCII text, with very long lines (30298)
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (59425)
downloaded
Chrome Cache Entry: 176
data
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (16803)
dropped
Chrome Cache Entry: 179
ASCII text, with very long lines (6882)
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (12946)
downloaded
Chrome Cache Entry: 181
Unicode text, UTF-8 text, with very long lines (3748)
downloaded
Chrome Cache Entry: 182
ASCII text, with very long lines (17029)
downloaded
Chrome Cache Entry: 183
ASCII text
dropped
Chrome Cache Entry: 184
Unicode text, UTF-8 text, with very long lines (10524)
dropped
Chrome Cache Entry: 185
data
dropped
Chrome Cache Entry: 186
Unicode text, UTF-8 text, with very long lines (62786), with no line terminators
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (4829)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (63604)
dropped
Chrome Cache Entry: 189
C source, ASCII text, with very long lines (11725)
downloaded
Chrome Cache Entry: 190
Unicode text, UTF-8 text, with very long lines (3748)
dropped
Chrome Cache Entry: 191
ASCII text, with very long lines (15442)
dropped
Chrome Cache Entry: 192
C source, ASCII text, with very long lines (11725)
downloaded
Chrome Cache Entry: 193
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (45506)
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (8158)
downloaded
Chrome Cache Entry: 196
Unicode text, UTF-8 text, with very long lines (18772)
downloaded
Chrome Cache Entry: 197
data
dropped
Chrome Cache Entry: 198
ASCII text, with very long lines (15442)
downloaded
Chrome Cache Entry: 199
Unicode text, UTF-8 text, with very long lines (7518)
dropped
Chrome Cache Entry: 200
ASCII text, with very long lines (7031)
dropped
Chrome Cache Entry: 201
Unicode text, UTF-8 text, with very long lines (10524)
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (24799)
downloaded
Chrome Cache Entry: 203
Unicode text, UTF-8 text, with very long lines (18772)
dropped
Chrome Cache Entry: 204
ASCII text, with very long lines (7296)
downloaded
Chrome Cache Entry: 205
data
dropped
Chrome Cache Entry: 206
ASCII text, with very long lines (9848)
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (7031)
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (6757)
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (5394)
downloaded
Chrome Cache Entry: 210
JSON data
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (4829)
dropped
Chrome Cache Entry: 212
ASCII text, with very long lines (48338)
dropped
Chrome Cache Entry: 213
ASCII text, with very long lines (48338)
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (8158)
dropped
Chrome Cache Entry: 215
ASCII text, with very long lines (945)
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (65457)
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (30298)
downloaded
Chrome Cache Entry: 218
ASCII text, with very long lines (17029)
dropped
Chrome Cache Entry: 219
C source, ASCII text, with very long lines (11725)
dropped
Chrome Cache Entry: 220
JSON data
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (63604)
downloaded
Chrome Cache Entry: 222
ASCII text, with very long lines (7296)
dropped
There are 87 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2184 --field-trial-handle=2000,i,6586907310135038613,8812970272619200833,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://bioaquatictesting-my.sharepoint.com/:f:/g/personal/securedocument_bio-aquatic_com/Eu0LAzG4abJJn1FmlYYk6C0Bm-68IB0eiVR_FSTw6lLEjw?e=pg8DKY"

URLs

Name
IP
Malicious
https://bioaquatictesting-my.sharepoint.com/:f:/g/personal/securedocument_bio-aquatic_com/Eu0LAzG4abJJn1FmlYYk6C0Bm-68IB0eiVR_FSTw6lLEjw?e=pg8DKY
malicious
https://bioaquatictesting-my.sharepoint.com/:f:/g/personal/securedocument_bio-aquatic_com/Eu0LAzG4abJJn1FmlYYk6C0Bm-68IB0eiVR_FSTw6lLEjw?e=pg8DKY
13.107.136.10
malicious
https://livefilestore.com/
unknown
https://substrate.office.com
unknown
http://www.opensource.org/licenses/mit-license.php
unknown
https://portal.office.com/
unknown
https://shellppe.msocdn.com
unknown
https://onedrive.cloud.microsoft
unknown
https://shellprod.msocdn.com
unknown
https://bioaquatictesting-my.sharepoint.com/personal/securedocument_bio-aquatic_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fsecuredocument%5Fbio%2Daquatic%5Fcom%2FDocuments%2FThe%20Nutrition%20Group&ga=1
http://www.contoso.com
unknown
https://northcentralus1-medias.svc.ms
unknown
https://support.office.com/en-us/article/Manage-lists-and-libraries-with-many-items-b8588dae-9387-48
unknown
https://reactjs.org/docs/error-decoder.html?invariant=
unknown
https://clients.config.office.net/user/v1.0/web/policies
unknown
https://centralus1-mediad.svc.ms
unknown
https://onedrive.live.com/?gologin=1
unknown
http://fb.me/use-check-prop-types
unknown
https://onedrive.dev.cloud.microsoft
unknown
https://www.office.com/login?ru=%2Flaunch%2Fonedrive
unknown
https://spoprod-a.akamaihd.net/files/odsp-common-library-prod_2019-02-15_20190219.002/require.js
unknown
https://1drv.com/
unknown
https://www.office.com/login?prompt=select_account&ru=%2Flaunch%2Fonedrive
unknown
https://bioaquatictesting-my.sharepoint.com/_layouts/15/images/odbfavicon.ico?rev=47
13.107.136.10
https://reactjs.org/link/react-polyfills
unknown
There are 14 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
dual-spo-0005.spo-msedge.net
13.107.136.10
www.google.com
142.250.185.196
fp2e7a.wpc.phicdn.net
192.229.221.95
s-part-0032.t-0009.t-msedge.net
13.107.246.60
sni1gl.wpc.sigmacdn.net
152.199.21.175
bioaquatictesting-my.sharepoint.com
unknown
m365cdn.nel.measure.office.net
unknown
spo.nel.measure.office.net
unknown

IPs

IP
Domain
Country
Malicious
13.107.136.10
dual-spo-0005.spo-msedge.net
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
152.199.21.175
sni1gl.wpc.sigmacdn.net
United States

DOM / HTML

URL
Malicious
https://bioaquatictesting-my.sharepoint.com/personal/securedocument_bio-aquatic_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fsecuredocument%5Fbio%2Daquatic%5Fcom%2FDocuments%2FThe%20Nutrition%20Group&ga=1
https://bioaquatictesting-my.sharepoint.com/personal/securedocument_bio-aquatic_com/_layouts/15/onedrive.aspx?id=%2Fpersonal%2Fsecuredocument%5Fbio%2Daquatic%5Fcom%2FDocuments%2FThe%20Nutrition%20Group&ga=1