IOC Report
https://fromsmash.com/MpkdmxBnzc-et

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 09:27:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 09:27:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 09:27:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 09:27:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 25 09:27:16 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 122
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 124
ASCII text, with very long lines (28514)
downloaded
Chrome Cache Entry: 125
JSON data
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (23108)
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 128
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (64651)
dropped
Chrome Cache Entry: 130
Web Open Font Format (Version 2), TrueType, length 39124, version 1.0
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (16978)
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (65441), with CRLF line terminators
downloaded
Chrome Cache Entry: 133
JSON data
dropped
Chrome Cache Entry: 134
ASCII text, with very long lines (25868)
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (4445)
dropped
Chrome Cache Entry: 136
ASCII text, with very long lines (16978)
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (35057)
downloaded
Chrome Cache Entry: 138
JSON data
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (35057)
dropped
Chrome Cache Entry: 140
MS Windows icon resource - 1 icon, 100x102, 32 bits/pixel
dropped
Chrome Cache Entry: 141
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 143
C source, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 144
JSON data
dropped
Chrome Cache Entry: 145
MS Windows icon resource - 1 icon, 100x102, 32 bits/pixel
downloaded
Chrome Cache Entry: 146
Unicode text, UTF-8 text, with very long lines (65441), with CRLF line terminators
dropped
Chrome Cache Entry: 147
ASCII text, with very long lines (16729)
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (28514)
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (11852)
dropped
Chrome Cache Entry: 150
PNG image data, 140 x 140, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 151
HTML document, Unicode text, UTF-8 text, with very long lines (31370)
downloaded
Chrome Cache Entry: 152
JSON data
downloaded
Chrome Cache Entry: 153
JSON data
downloaded
Chrome Cache Entry: 154
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (38158)
dropped
Chrome Cache Entry: 157
Web Open Font Format (Version 2), TrueType, length 18436, version 1.0
downloaded
Chrome Cache Entry: 158
JSON data
downloaded
Chrome Cache Entry: 159
PNG image data, 140 x 140, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (38158)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (24605)
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (13063)
dropped
Chrome Cache Entry: 164
ASCII text, with very long lines (23108)
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (11852)
downloaded
Chrome Cache Entry: 166
C source, ASCII text, with very long lines (19478)
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (16729)
dropped
Chrome Cache Entry: 168
C source, ASCII text, with very long lines (19478)
dropped
Chrome Cache Entry: 169
ASCII text, with very long lines (64651)
downloaded
Chrome Cache Entry: 170
C source, ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 171
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (25868)
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (4445)
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 175
ASCII text, with very long lines (24605)
dropped
Chrome Cache Entry: 176
ASCII text, with very long lines (13063)
downloaded
Chrome Cache Entry: 177
C source, ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 178
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 179
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 180
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 181
TrueType Font data, 11 tables, 1st "OS/2", 14 names, Macintosh, type 1 string, Smash
downloaded
Chrome Cache Entry: 182
C source, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (65536), with no line terminators
downloaded
There are 59 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2116 --field-trial-handle=1948,i,1687054215402430912,5073662369833793211,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://fromsmash.com/MpkdmxBnzc-et"

URLs

Name
IP
Malicious
https://fromsmash.com/MpkdmxBnzc-et
https://www.linkedin.com/posts/romaric-gouedard-comte_jo2024-smash-madeinfrance-activity-72221515153
unknown
https://theme.fromsmash.co/processed/Managed/eec10e0b-44b5-4356-a3a4-eb81e68367b3/24fc1540-97ed-4f22
unknown
https://stats.g.doubleclick.net/g/collect
unknown
https://europeanlab.com/
unknown
https://theme.fromsmash.co/processed/Managed/e013ece2-5744-4402-8503-cfba58719652/3be805a6-1390-4b9c
unknown
https://fromsmash.com/styles.49978e8bc97b4972.css
18.245.86.61
https://theme.fromsmash.co/processed/Managed/e013ece2-5744-4402-8503-cfba58719652/6925bdb2-f35b-4b95
unknown
https://theme.fromsmash.co/processed/Managed/0172c091-d3e0-4b6e-9948-9c3e8250fc1e/97604905-419e-42bb
unknown
https://theme.fromsmash.co/processed/Managed/22caf38c-9675-4849-9ef9-110436eb71c3/c1235a02-0b70-491f
unknown
https://vimeo.com/989540415
unknown
https://fromsmash.com
unknown
https://theme.fromsmash.co/processed/Managed/19040487-fe21-4dde-acd4-aa7ffa96b9cd/b86aae3d-8740-4e4e
unknown
https://faq.fromsmash.com/article/146-file-type-preview-downloading
unknown
https://fromsmash.com/assets/img/smash-logo/smash_transfert_de_fichiers.jpg
unknown
https://theme.fromsmash.co/processed/Managed/27ac1b1a-2709-4907-b4de-8a87ed653ce0/9e56ef9f-0f96-4710
unknown
https://fromsmash.com/1407.cf20e2b5b492e1d7.js
18.245.86.61
https://theme.fromsmash.co/processed/Managed/c9608af8-225d-42b7-b04a-605da60a2da5/3be3fc47-6347-4b58
unknown
https://faq.fromsmash.com
unknown
https://theme.fromsmash.co/processed/Managed/afa6018e-5437-4156-bfc6-8cd484b685bd/481ff73a-222a-4f0d
unknown
https://theme.fromsmash.co/processed/Managed/fbcf7119-c0b7-404e-82ae-99670e6accc0/7053b7d0-7758-42de
unknown
https://www.linkedin.com/posts/romaric-gouedard-comte_newpreviewsmash-feature-filetransfer-activity-
unknown
https://theme.fromsmash.co/processed/Managed/9fa70b46-d2fb-4320-aa42-9cc85c48deef/83e371e5-d41d-49c9
unknown
https://github.com/microsoft/clarity
unknown
https://www.fetedeslumieres.lyon.fr/fr
unknown
https://theme.fromsmash.co/processed/Managed/9f584c40-2bab-4cdb-b259-fa1a3c35dbce/49968dcf-3d03-44b1
unknown
https://domain.fromsmash.co
unknown
https://theme.fromsmash.co/processed/Managed/fbcf7119-c0b7-404e-82ae-99670e6accc0/04f04e61-22fd-4c07
unknown
https://download.us-east-1.fromsmash.co/transfer/MpkdmxBnzc-et/file/2fcba712f1926194008f459059df95f9
unknown
https://fromsmash.com/8376.95157516f4f4fa3a.js
18.245.86.61
https://fromsmash.com/assets/img/smash-logo/favicon.ico
18.245.86.61
https://theme.fromsmash.co/processed/Managed/65f20c25-af78-4587-8ff9-54657c1a065a/3ed52480-8041-44c3
unknown
https://offre.strategies.fr/landing-page/cis0PRrI9f/6878?utm_source=smash&utm_medium=cpc&utm_campaig
unknown
https://theme.fromsmash.co/processed/Managed/6fe77280-8276-43ac-ba5c-df77a8ae5a8a/eb7fab9c-9482-4ddc
unknown
https://discovery.fromsmash.co/namespace/public/services?version=02-2023
3.74.252.121
https://fromsmash.com?utm_source=smash&utm_medium=promo&utm_content=you-re-just-one-click-away-to-se
unknown
https://vimeo.com/1019867487
unknown
https://fromsmash.com/de/special-deal?utm_source=smash&utm_medium=autumn
unknown
https://fromsmash.com?utm_source=smash&utm_medium=promo&utm_content=your-turn-to-try-smash
unknown
https://theme.fromsmash.co/processed/Managed/3d3106d2-05e9-4ef8-acb1-be732bd66ee7/6cd184c1-2007-4f17
unknown
https://download.us-east-1.fromsmash.co/transfer/MpkdmxBnzc-et/customization/background/images/optim
unknown
https://download.us-east-1.fromsmash.co/transfer/MpkdmxBnzc-et/customization/background/images/thumb
unknown
https://vimeo.com/1011283710
unknown
https://www.linkedin.com/posts/romaric-gouedard-comte_insmashwetrust-activity-7203658311651508225-aH
unknown
https://fromsmash.com/5120.c14f86f2e2b4b4b6.js
18.245.86.61
https://vimeo.com/1017013251
unknown
https://fromsmash.com/de?utm_source=smash&utm_medium=promo&utm_content=your-turn-to-try-smash
unknown
https://theme.fromsmash.co/processed/Managed/3a282db1-4a5e-430c-940b-728516e9e5df/bf8f8fad-aa05-4299
unknown
https://theme.fromsmash.co/processed/Managed/a84b73f4-24f1-4f85-9bb9-d3e5613b7b3b/b471a8ff-f2d8-4049
unknown
https://twitter.com/fromsmash
unknown
https://theme.fromsmash.co/processed/Managed/0ad8b7cc-f1ed-4b87-a1a5-950905482bed/0929467f-ef61-4539
unknown
https://theme.fromsmash.co/processed/Managed/e59f41ef-ece4-4aa5-a3a7-39d6ef63273e/def2f4ab-65b5-462b
unknown
https://theme.fromsmash.co/processed/Managed/b31736c8-8159-44e4-98c4-77e32bcf42b1/22f68684-a6ba-46ce
unknown
https://www.clarity.ms/tag/hglpx7p7f2
13.107.246.67
https://fromsmash.com/fr/discover-smash/pro?utm_source=smash&utm_medium=promo&utm_content=embelir-vo
unknown
https://theme.fromsmash.co/processed/Managed/a84b73f4-24f1-4f85-9bb9-d3e5613b7b3b/2005bd2a-466c-4893
unknown
https://theme.fromsmash.co/processed/Managed/d0ddf5e4-ba3a-435c-9a0a-0429edc483f2/3fa9c690-43e5-4732
unknown
https://theme.fromsmash.co/processed/Managed/e3ee566d-8cc2-4c75-87d5-29b7a5413adb/deb65b89-b55e-46ec
unknown
https://theme.fromsmash.co/processed/Managed/6fe77280-8276-43ac-ba5c-df77a8ae5a8a/6423a25c-a016-4f4b
unknown
https://theme.fromsmash.co/processed/Managed/3d18c01b-609c-4da8-b8d2-d16f327cab8c/3b61463e-2fae-4d2f
unknown
https://theme.fromsmash.co/processed/Managed/59db4bda-000b-431d-9c01-670900e4aba9/32d4d82b-2986-4030
unknown
https://journeesdupatrimoine.culture.gouv.fr/actualites/a-la-decouverte-de-l-histoire-de-l-aviation
unknown
https://fromsmash.com/de/special-deal?utm_source=smash&utm_medium=promo&utm_content=summer-deal
unknown
https://fromsmash.com/9436.42c8079092cf24fe.js
18.245.86.61
https://theme.fromsmash.co/processed/Managed/f8163bba-ebf6-4a56-affa-d041ce1d9e28/4fd75de1-e0e4-4d29
unknown
https://vimeo.com/989540347
unknown
https://youtu.be/ltTLKFUykSg
unknown
https://www.fetedeslumieres.lyon.fr/
unknown
https://theme.fromsmash.co/processed/Managed/215cb376-9f0d-4c89-92cb-b0c7830c4c04/f525cfe0-e735-42d8
unknown
https://fromsmash.com/2174.609ace230044bee7.js
18.245.86.61
https://theme.fromsmash.co/processed/Managed/5e26d272-47ed-46ed-95a6-b6973320c7a0/9afe4536-9ffe-4e04
unknown
https://fromsmash.com/it
unknown
https://theme.fromsmash.co/processed/Managed/23d1faab-0af1-4f72-9021-5149c7885c17/6d897881-c30c-4fc8
unknown
https://fromsmash.com/5674.bf1e5706ae5acab1.js
18.245.86.61
https://fromsmash.com/it/special-deal?utm_source=smash&utm_medium=promo&utm_content=back-to-school
unknown
https://fromsmash.com/discover-smash
unknown
https://www.linkedin.com/posts/romaric-gouedard-comte_on-peut-dire-que-les-smashs-de-leroy-merlin-ac
unknown
https://fromsmash.com/pt/special-deal?utm_source=smash&utm_medium=promo&utm_content=back-to-school
unknown
https://fromsmash.com/common.bad16ab3ee05250e.js
18.245.86.61
https://ad.doubleclick.net/ddm/trackclk/N448205.5141287SMASH/B31643274.389550521;dc_trk_aid=58100783
unknown
https://theme.fromsmash.co/processed/Managed/79700d97-8e3b-476c-af57-5f7975dc6a62/4556b58c-b0b4-4c36
unknown
https://ad.doubleclick.net/ddm/trackclk/N448205.5141287SMASH/B31643274.389552564;dc_trk_aid=58101007
unknown
https://fromsmash.com/pt/special-deal?utm_source=smash&utm_medium=promo&utm_content=summer-deal
unknown
https://theme.fromsmash.co/processed/Managed/23d1faab-0af1-4f72-9021-5149c7885c17/746fe7c5-5a0e-4563
unknown
https://fromsmash.com/es?utm_source=smash&utm_medium=promo&utm_content=your-turn-to-try-smash
unknown
https://fromsmash.com/es/special-deal?utm_source=smash&utm_medium=promo&utm_content=summer-deal
unknown
https://fromsmash.com/de/special-deal?utm_source=smash&utm_medium=promo&utm_content=back-to-school
unknown
https://theme.fromsmash.co/processed/Managed/f8163bba-ebf6-4a56-affa-d041ce1d9e28/983bc045-2b6f-481c
unknown
https://vimeo.com/989540432
unknown
https://theme.fromsmash.co/processed/Managed/65f20c25-af78-4587-8ff9-54657c1a065a/3c2170a5-cfb9-45f4
unknown
https://fromsmash.com/pt/special-deal?utm_source=smash&utm_medium=autumn
unknown
https://fromsmash.com/pt?utm_source=smash&utm_medium=promo&utm_content=your-turn-to-try-smash
unknown
https://fromsmash.com/fr/essential/ask-for-a-demo?utm_source=smash&utm_medium=promo&utm_content=ask-
unknown
https://transfer.us-east-1.fromsmash.co/transfer/MpkdmxBnzc-et/files/preview?limit=9&version=01-2024
143.204.215.114
https://fromsmash.com/special-deal?utm_source=smash&utm_medium=promo&utm_content=summer-deal
unknown
https://td.doubleclick.net
unknown
https://theme.fromsmash.co/processed/Managed/ce293643-554d-426e-a6fb-a4663a47b0b0/340abd73-f1f5-4871
unknown
https://fromsmash.com/8291.971dabd2ce8f8f96.js
18.245.86.61
https://download.us-east-1.fromsmash.co/transfer/MpkdmxBnzc-et?identity=88b6ca95e81b0f21ef20299d6f39
unknown
https://theme.fromsmash.co/processed/Managed/07841653-740a-43cc-833b-2914d2aa9132/82b0bb38-0bd3-4270
unknown
https://theme.fromsmash.co/processed/Managed/b31736c8-8159-44e4-98c4-77e32bcf42b1/f595512d-9ff2-49d9
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
domain.fromsmash.co
18.66.102.36
s-part-0016.t-0009.t-msedge.net
13.107.246.44
fromsmash.com
18.245.86.61
link.fromsmash.co
18.66.102.92
s-part-0039.t-0009.t-msedge.net
13.107.246.67
d-sf2dau09ng.execute-api.eu-central-1.amazonaws.com
3.74.252.121
stats.g.doubleclick.net
64.233.166.155
scitylana.fromsmash.co
13.35.58.83
analytics-alv.google.com
216.239.38.181
discovery.eu-central-1.fromsmash.co
18.172.112.45
iam.eu-central-1.fromsmash.co
18.245.86.101
www.google.com
142.250.186.132
theme.fromsmash.co
18.239.69.2
td.doubleclick.net
216.58.206.66
transfer.us-east-1.fromsmash.co
143.204.215.114
www.clarity.ms
unknown
u.clarity.ms
unknown
discovery.fromsmash.co
unknown
analytics.google.com
unknown
c.clarity.ms
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
18.245.86.61
fromsmash.com
United States
18.66.102.36
domain.fromsmash.co
United States
3.74.252.121
d-sf2dau09ng.execute-api.eu-central-1.amazonaws.com
United States
13.107.246.67
s-part-0039.t-0009.t-msedge.net
United States
18.66.102.15
unknown
United States
13.107.246.44
s-part-0016.t-0009.t-msedge.net
United States
216.239.38.181
analytics-alv.google.com
United States
192.168.2.5
unknown
unknown
142.250.186.132
www.google.com
United States
108.138.26.66
unknown
United States
13.35.58.83
scitylana.fromsmash.co
United States
18.239.69.2
theme.fromsmash.co
United States
18.245.86.101
iam.eu-central-1.fromsmash.co
United States
216.58.206.66
td.doubleclick.net
United States
18.245.86.106
unknown
United States
18.172.112.45
discovery.eu-central-1.fromsmash.co
United States
143.204.215.114
transfer.us-east-1.fromsmash.co
United States
64.233.166.155
stats.g.doubleclick.net
United States
239.255.255.250
unknown
Reserved
18.66.102.92
link.fromsmash.co
United States
There are 10 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://fromsmash.com/MpkdmxBnzc-et
https://fromsmash.com/MpkdmxBnzc-et
https://fromsmash.com/MpkdmxBnzc-et
https://fromsmash.com/MpkdmxBnzc-et
https://fromsmash.com/MpkdmxBnzc-et
https://fromsmash.com/MpkdmxBnzc-et
https://fromsmash.com/MpkdmxBnzc-et