IOC Report
https://ipfs.io/ipfs/QmNRd2YnNadczqweR7UkjNBG3cvGj4th37n2oBP7ZKKPD8#test@kghm.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 09:00:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 09:00:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 09:00:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 09:00:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 28 09:00:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (32012)
downloaded
Chrome Cache Entry: 122
RIFF (little-endian) data, Web/P image, VP8 encoding, 1000x627, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 123
PNG image data, 7 x 7, 1-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 125
RIFF (little-endian) data, Web/P image, VP8 encoding, 1920x1080, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (30837)
downloaded
Chrome Cache Entry: 132
Unicode text, UTF-8 text, with very long lines (1122)
downloaded
Chrome Cache Entry: 133
PNG image data, 7 x 7, 1-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (19015)
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (3152), with no line terminators
dropped
Chrome Cache Entry: 141
HTML document, ASCII text, with very long lines (624)
downloaded
Chrome Cache Entry: 144
TrueType Font data, digitally signed, 18 tables, 1st "DSIG", 28 names, Macintosh, Copyright 2011 The Montserrat Project Authors (https://github.com/JulietaUla/Montserrat)Montserr
downloaded
Chrome Cache Entry: 145
PNG image data, 1169 x 318, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 147
Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 148
ASCII text
dropped
Chrome Cache Entry: 150
assembler source, Unicode text, UTF-8 text, with very long lines (29919)
downloaded
Chrome Cache Entry: 151
PNG image data, 15 x 16, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 153
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (5478)
dropped
Chrome Cache Entry: 156
RIFF (little-endian) data, Web/P image, VP8 encoding, 380x241, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 157
PNG image data, 13 x 13, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 158
PNG image data, 190 x 59, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (53175)
dropped
Chrome Cache Entry: 163
HTML document, ASCII text, with very long lines (1510)
dropped
Chrome Cache Entry: 164
ASCII text, with very long lines (50758)
dropped
Chrome Cache Entry: 165
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 75", baseline, precision 8, 1200x188, components 3
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (2550)
downloaded
Chrome Cache Entry: 167
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (633)
downloaded
Chrome Cache Entry: 170
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (388)
dropped
Chrome Cache Entry: 173
PNG image data, 13 x 13, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 174
Web Open Font Format (Version 2), TrueType, length 78268, version 331.-31196
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (360)
downloaded
Chrome Cache Entry: 176
Web Open Font Format (Version 2), TrueType, length 44856, version 1.0
downloaded
Chrome Cache Entry: 177
RIFF (little-endian) data, Web/P image, VP8 encoding, 1657x932, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 178
HTML document, Unicode text, UTF-8 text, with very long lines (587)
downloaded
Chrome Cache Entry: 179
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 180
Web Open Font Format (Version 2), TrueType, length 31320, version 1.0
downloaded
Chrome Cache Entry: 182
RIFF (little-endian) data, Web/P image, VP8 encoding, 1917x1079, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 184
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 190
Web Open Font Format (Version 2), TrueType, length 76736, version 331.-31196
downloaded
Chrome Cache Entry: 192
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 193
HTML document, ASCII text, with very long lines (65520), with CRLF line terminators
downloaded
Chrome Cache Entry: 194
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 196
TrueType Font data, digitally signed, 18 tables, 1st "DSIG", 26 names, Macintosh, Copyright 2011 The Montserrat Project Authors (https://github.com/JulietaUla/Montserrat)Montserr
downloaded
Chrome Cache Entry: 198
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 199
ASCII text
dropped
Chrome Cache Entry: 200
ASCII text, with very long lines (1006)
dropped
Chrome Cache Entry: 203
ASCII text
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (65463)
downloaded
Chrome Cache Entry: 207
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1200x801, components 3
downloaded
Chrome Cache Entry: 208
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 800x800, components 3
downloaded
Chrome Cache Entry: 209
Web Open Font Format (Version 2), TrueType, length 13224, version 331.-31196
downloaded
Chrome Cache Entry: 211
PNG image data, 804 x 383, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 212
ASCII text, with very long lines (371)
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (52011)
downloaded
Chrome Cache Entry: 216
PNG image data, 19 x 19, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 217
JSON data
downloaded
Chrome Cache Entry: 219
RIFF (little-endian) data, Web/P image, VP8 encoding, 1920x875, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 224
ASCII text, with very long lines (59119)
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (1718)
dropped
Chrome Cache Entry: 228
JSON data
dropped
Chrome Cache Entry: 229
RIFF (little-endian) data, Web/P image, VP8 encoding, 380x241, Suserng: [none]x[none], YUV color, decoders should clamp
dropped
Chrome Cache Entry: 231
JSON data
downloaded
Chrome Cache Entry: 232
RIFF (little-endian) data, Web/P image, VP8 encoding, 380x241, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 234
PNG image data, 20 x 15, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 236
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 237
ASCII text, with very long lines (23577)
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (530)
dropped
Chrome Cache Entry: 239
PNG image data, 24 x 12, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 240
TrueType Font data, digitally signed, 18 tables, 1st "DSIG", 26 names, Macintosh, Copyright 2011 The Montserrat Project Authors (https://github.com/JulietaUla/Montserrat)Montserr
downloaded
Chrome Cache Entry: 242
Unicode text, UTF-8 text, with very long lines (38578)
dropped
Chrome Cache Entry: 245
ASCII text, with very long lines (65362)
dropped
Chrome Cache Entry: 246
MS Windows icon resource - 1 icon, 48x48, 32 bits/pixel
downloaded
Chrome Cache Entry: 247
MS Windows icon resource - 1 icon, 64x64, 32 bits/pixel
downloaded
Chrome Cache Entry: 248
ASCII text, with very long lines (32030)
downloaded
Chrome Cache Entry: 251
ASCII text, with very long lines (48664)
dropped
Chrome Cache Entry: 256
PNG image data, 18 x 12, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (33268), with no line terminators
downloaded
There are 76 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://ipfs.io/ipfs/QmNRd2YnNadczqweR7UkjNBG3cvGj4th37n2oBP7ZKKPD8#test@kghm.com
malicious
https://ipfs.io/ipfs/QmNRd2YnNadczqweR7UkjNBG3cvGj4th37n2oBP7ZKKPD8#test@kghm.com
malicious
https://kghm.com/pl

Domains

Name
IP
Malicious
kghm.com
62.87.254.208
malicious
ipfs.io
209.94.90.1
malicious
stackpath.bootstrapcdn.com
104.18.11.207
cs837.wac.edgecastcdn.net
192.229.133.221
server.mailxlsxpdfauth.com
198.23.159.37
maxcdn.bootstrapcdn.com
104.18.10.207
d26p066pn2w0s0.cloudfront.net
13.32.27.44
ipapi.co
172.67.69.226
code.jquery.com
151.101.66.137
cdnjs.cloudflare.com
104.17.25.14
static.addtoany.com
104.22.71.197
www.google.com
142.250.186.68
webmail.supremecluster.com
94.136.171.57
www.w3schools.com
unknown
logo.clearbit.com
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
209.94.90.1
ipfs.io
United States
malicious
62.87.254.208
kghm.com
Poland
malicious
142.250.186.68
www.google.com
United States
104.26.8.44
unknown
United States
142.250.186.46
unknown
United States
104.18.10.207
maxcdn.bootstrapcdn.com
United States
172.217.16.138
unknown
United States
13.32.27.77
unknown
United States
173.194.76.84
unknown
United States
192.168.2.16
unknown
unknown
142.250.185.202
unknown
United States
172.67.39.148
unknown
United States
104.22.71.197
static.addtoany.com
United States
142.250.185.163
unknown
United States
94.136.171.57
webmail.supremecluster.com
Germany
151.101.66.137
code.jquery.com
United States
198.23.159.37
server.mailxlsxpdfauth.com
United States
142.250.186.74
unknown
United States
142.250.186.99
unknown
United States
172.67.69.226
ipapi.co
United States
142.250.184.202
unknown
United States
104.17.24.14
unknown
United States
1.1.1.1
unknown
Australia
13.32.27.44
d26p066pn2w0s0.cloudfront.net
United States
142.250.185.138
unknown
United States
192.229.133.221
cs837.wac.edgecastcdn.net
United States
104.18.11.207
stackpath.bootstrapcdn.com
United States
151.101.2.137
unknown
United States
239.255.255.250
unknown
Reserved
104.17.25.14
cdnjs.cloudflare.com
United States
There are 20 hidden IPs, click here to show them.