IOC Report
MDE_File_Sample_1c09362164fb3ef8a127eeaf3e1386107eb12344.zip

loading gif

Files

File Path
Type
Category
Malicious
MDE_File_Sample_1c09362164fb3ef8a127eeaf3e1386107eb12344.zip
Zip archive data, at least v2.0 to extract, compression method=deflate
initial sample
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 06:01:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 06:01:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 06:01:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 06:01:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 06:01:21 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 120
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 121
data
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (5162), with no line terminators
downloaded
Chrome Cache Entry: 123
gzip compressed data, max compression, original size modulo 2^32 150329
downloaded
Chrome Cache Entry: 124
data
downloaded
Chrome Cache Entry: 125
data
downloaded
Chrome Cache Entry: 126
PNG image data, 128 x 128, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 128
gzip compressed data, original size modulo 2^32 18220
downloaded
Chrome Cache Entry: 129
data
downloaded
Chrome Cache Entry: 130
PGP Secret Sub-key -
downloaded
Chrome Cache Entry: 131
data
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (30926), with no line terminators
downloaded
Chrome Cache Entry: 133
data
downloaded
Chrome Cache Entry: 134
PNG image data, 128 x 128, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 136
data
downloaded
Chrome Cache Entry: 138
data
downloaded
Chrome Cache Entry: 139
PNG image data, 128 x 128, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 140
data
downloaded
Chrome Cache Entry: 141
data
downloaded
Chrome Cache Entry: 142
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
downloaded
Chrome Cache Entry: 143
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 144
data
downloaded
Chrome Cache Entry: 145
data
downloaded
Chrome Cache Entry: 146
HTML document, Unicode text, UTF-8 text, with very long lines (1831)
downloaded
Chrome Cache Entry: 147
data
downloaded
Chrome Cache Entry: 148
data
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (370), with no line terminators
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (22445), with no line terminators
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (1055)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (4518), with no line terminators
downloaded
Chrome Cache Entry: 153
HTML document, ASCII text
downloaded
Chrome Cache Entry: 154
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 155
data
downloaded
Chrome Cache Entry: 156
Web Open Font Format (Version 2), TrueType, length 15744, version 1.0
downloaded
Chrome Cache Entry: 157
data
downloaded
Chrome Cache Entry: 158
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 159
data
downloaded
Chrome Cache Entry: 160
data
downloaded
Chrome Cache Entry: 161
HTML document, ASCII text, with very long lines (5657)
downloaded
Chrome Cache Entry: 162
data
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (2287)
downloaded
Chrome Cache Entry: 164
data
downloaded
Chrome Cache Entry: 165
data
downloaded
Chrome Cache Entry: 166
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 167
data
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (2200)
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 171
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 172
data
downloaded
Chrome Cache Entry: 173
data
downloaded
Chrome Cache Entry: 175
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 176
data
downloaded
Chrome Cache Entry: 177
data
downloaded
Chrome Cache Entry: 178
Web Open Font Format (Version 2), TrueType, length 15860, version 1.0
downloaded
Chrome Cache Entry: 179
data
downloaded
Chrome Cache Entry: 180
data
downloaded
Chrome Cache Entry: 181
data
downloaded
Chrome Cache Entry: 182
ASCII text, with very long lines (12271)
downloaded
Chrome Cache Entry: 183
data
downloaded
Chrome Cache Entry: 184
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 185
PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 186
ASCII text, with very long lines (31150)
downloaded
Chrome Cache Entry: 187
data
downloaded
Chrome Cache Entry: 188
data
downloaded
Chrome Cache Entry: 189
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 190
HTML document, ASCII text, with very long lines (1559)
downloaded
Chrome Cache Entry: 191
data
downloaded
Chrome Cache Entry: 192
data
downloaded
Chrome Cache Entry: 193
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 194
PNG image data, 32 x 32, 8-bit grayscale, non-interlaced
downloaded
Chrome Cache Entry: 195
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop 24.1 (Macintosh), datetime=2023:11:27 18:05:20], baseline, precision 8, 728x90, components 3
downloaded
Chrome Cache Entry: 196
data
downloaded
Chrome Cache Entry: 197
ISO Media, AVIF Image
downloaded
Chrome Cache Entry: 198
data
downloaded
Chrome Cache Entry: 199
HTML document, Unicode text, UTF-8 text, with very long lines (58650)
downloaded
Chrome Cache Entry: 200
Web Open Font Format (Version 2), TrueType, length 15920, version 1.0
downloaded
Chrome Cache Entry: 201
data
downloaded
Chrome Cache Entry: 202
data
downloaded
There are 76 hidden files, click here to show them.

Domains

Name
IP
Malicious
securepubads.g.doubleclick.net
142.250.185.98
pagead-googlehosted.l.google.com
216.58.206.33
syndicatedsearch.goog
216.58.206.46
8proof.com
52.116.53.150
d1ykf07e75w7ss.cloudfront.net
18.173.210.128
push-sdk.com
157.90.33.72
tags.crwdcntrl.net
65.9.66.104
googleads.g.doubleclick.net
142.250.184.194
dns-tunnel-check.googlezip.net
216.239.34.159
tunnel.googlezip.net
216.239.34.157
www.google.com
142.250.186.132
cdn.cookielaw.org
104.18.87.42
swls.map.fastly.net
151.101.1.91
assets.dwncdn.net
unknown
c.amazon-adsystem.com
unknown
images.dwncdn.net
unknown
cdn-ima.33across.com
unknown
di-images.sftcdn.net
unknown
download.cnet.com
unknown
There are 9 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
52.116.53.150
8proof.com
United States
142.250.186.67
unknown
United States
142.250.185.228
unknown
United States
151.101.1.91
swls.map.fastly.net
United States
216.58.206.34
unknown
United States
192.168.2.16
unknown
unknown
216.58.206.33
pagead-googlehosted.l.google.com
United States
142.250.181.234
unknown
United States
18.173.210.128
d1ykf07e75w7ss.cloudfront.net
United States
74.125.206.84
unknown
United States
142.250.185.142
unknown
United States
142.250.186.131
unknown
United States
142.250.186.132
www.google.com
United States
142.250.186.99
unknown
United States
142.250.186.98
unknown
United States
142.250.184.202
unknown
United States
65.9.66.104
tags.crwdcntrl.net
United States
216.239.32.178
unknown
United States
142.250.185.66
unknown
United States
142.250.185.67
unknown
United States
142.250.184.196
unknown
United States
142.250.186.34
unknown
United States
104.18.87.42
cdn.cookielaw.org
United States
1.1.1.1
unknown
Australia
142.250.186.161
unknown
United States
142.250.184.194
googleads.g.doubleclick.net
United States
142.250.185.234
unknown
United States
172.64.152.89
unknown
United States
172.217.18.3
unknown
United States
142.250.185.232
unknown
United States
142.250.185.238
unknown
United States
157.90.33.72
push-sdk.com
United States
172.217.18.2
unknown
United States
216.58.206.46
syndicatedsearch.goog
United States
142.250.186.106
unknown
United States
142.250.181.225
unknown
United States
239.255.255.250
unknown
Reserved
192.168.2.13
unknown
unknown
192.168.2.14
unknown
unknown
151.101.193.91
unknown
United States
142.250.186.187
unknown
United States
216.58.212.163
unknown
United States
216.239.34.157
tunnel.googlezip.net
United States
142.250.185.98
securepubads.g.doubleclick.net
United States
There are 34 hidden IPs, click here to show them.