IOC Report
https://sso.godaddy.com/invitations/accept-invite?nonce=1_8JHrhcKSjkRGWAdfY8HNcX_5GT42mUuy&app=commerce&path=/home?storeId%3Db8e2b12c-368c-4e68-a882-4e65fd5f6f93

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:39:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:39:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:39:37 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:39:38 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 19:39:37 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (60994)
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (15306), with no line terminators
downloaded
Chrome Cache Entry: 102
ASCII text, with very long lines (2345)
downloaded
Chrome Cache Entry: 103
Web Open Font Format (Version 2), CFF, length 38559, version 1.66
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (64024)
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (3467), with no line terminators
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (6913), with no line terminators
downloaded
Chrome Cache Entry: 109
HTML document, ASCII text
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (12532), with no line terminators
dropped
Chrome Cache Entry: 113
JSON data
downloaded
Chrome Cache Entry: 114
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 115
ASCII text, with very long lines (3237), with no line terminators
dropped
Chrome Cache Entry: 116
ASCII text, with very long lines (15670)
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (16476), with no line terminators
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 119
ASCII text, with very long lines (65467)
downloaded
Chrome Cache Entry: 120
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (2528)
dropped
Chrome Cache Entry: 122
Web Open Font Format (Version 2), CFF, length 40132, version 1.66
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (15670)
dropped
Chrome Cache Entry: 124
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 125
ASCII text, with very long lines (804), with no line terminators
dropped
Chrome Cache Entry: 126
ASCII text, with very long lines (9813), with no line terminators
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (804), with no line terminators
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (12532), with no line terminators
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (15212), with no line terminators
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (3722), with no line terminators
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (5006), with no line terminators
dropped
Chrome Cache Entry: 132
ASCII text, with very long lines (60994)
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (6913), with no line terminators
dropped
Chrome Cache Entry: 134
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 135
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (65467)
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (3237), with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (65464)
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (15212), with no line terminators
dropped
Chrome Cache Entry: 141
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (16476), with no line terminators
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (2756), with no line terminators
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (2528)
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (5006), with no line terminators
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (2345)
dropped
Chrome Cache Entry: 148
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 149
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (65464)
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (3722), with no line terminators
dropped
Chrome Cache Entry: 152
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 153
ASCII text, with very long lines (9813), with no line terminators
dropped
Chrome Cache Entry: 154
Web Open Font Format (Version 2), TrueType, length 103388, version 1.0
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (3467), with no line terminators
dropped
Chrome Cache Entry: 156
Unicode text, UTF-8 text, with very long lines (65529), with no line terminators
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (15306), with no line terminators
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (2756), with no line terminators
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (64024)
downloaded
There are 57 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2320 --field-trial-handle=2224,i,7561922483486209830,15164113277520460846,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://sso.godaddy.com/invitations/accept-invite?nonce=1_8JHrhcKSjkRGWAdfY8HNcX_5GT42mUuy&app=commerce&path=/home?storeId%3Db8e2b12c-368c-4e68-a882-4e65fd5f6f93"

URLs

Name
IP
Malicious
https://sso.godaddy.com/invitations/accept-invite?nonce=1_8JHrhcKSjkRGWAdfY8HNcX_5GT42mUuy&app=commerce&path=/home?storeId%3Db8e2b12c-368c-4e68-a882-4e65fd5f6f93
https://sso.godaddy.com/?realm=idp&path=%2Finvitations%2Faccept-invite%3Fnonce%3D1_8JHrhcKSjkRGWAdfY8HNcX_5GT42mUuy%26app%3Dcommerce%26path%3D%252Fhome%253FstoreId%253Db8e2b12c-368c-4e68-a882-4e65fd5f6f93&app=sso&auth_reason=1&status=32
malicious
https://www.google.com
unknown
https://www.youtube.com/iframe_api
unknown
https://www.godaddy.com/legal/agreements/cookie-policy
https://feross.org
unknown
https://unpkg.com/@elastic/apm-rum@5.16.1/dist/bundles/elastic-apm-rum.umd.min.js
104.17.248.203
https://stats.g.doubleclick.net/g/collect
unknown
https://td.doubleclick.net
unknown
https://g.sst.godaddy.com/csp/collect
75.2.17.153
https://reporting.cdndex.io/error
13.32.99.44
https://www.merchant-center-analytics.goog
unknown
https://cct.google/taggy/agent.js
unknown
https://adservice.google.com/pagead/regclk?
unknown
There are 3 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
g.sst.godaddy.com
75.2.17.153
proxy-nlb-prod-us-west-2-v5-ac4e52c97755301b.elb.us-west-2.amazonaws.com
54.212.23.110
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
142.250.74.196
reporting.cdndex.io
13.32.99.44
unpkg.com
104.17.248.203
fp2e7a.wpc.phicdn.net
192.229.221.95
img1.wsimg.com
unknown
sso.godaddy.com
unknown
cca039482a104d5d9b04bd2e20f6bb64.apm.us-west-2.aws.found.io
unknown
www.godaddy.com
unknown
img6.wsimg.com
unknown
gui.godaddy.com
unknown
csp.godaddy.com
unknown
_9243._https.cca039482a104d5d9b04bd2e20f6bb64.apm.us-west-2.aws.found.io
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
54.212.23.110
proxy-nlb-prod-us-west-2-v5-ac4e52c97755301b.elb.us-west-2.amazonaws.com
United States
75.2.17.153
g.sst.godaddy.com
United States
104.17.248.203
unpkg.com
United States
13.32.99.44
reporting.cdndex.io
United States
192.168.2.5
unknown
unknown
239.255.255.250
unknown
Reserved
104.17.245.203
unknown
United States
142.250.74.196
www.google.com
United States

DOM / HTML

URL
Malicious
https://sso.godaddy.com/?realm=idp&path=%2Finvitations%2Faccept-invite%3Fnonce%3D1_8JHrhcKSjkRGWAdfY8HNcX_5GT42mUuy%26app%3Dcommerce%26path%3D%252Fhome%253FstoreId%253Db8e2b12c-368c-4e68-a882-4e65fd5f6f93&app=sso&auth_reason=1&status=32
https://sso.godaddy.com/?realm=idp&path=%2Finvitations%2Faccept-invite%3Fnonce%3D1_8JHrhcKSjkRGWAdfY8HNcX_5GT42mUuy%26app%3Dcommerce%26path%3D%252Fhome%253FstoreId%253Db8e2b12c-368c-4e68-a882-4e65fd5f6f93&app=sso&auth_reason=1&status=32
https://www.godaddy.com/legal/agreements/cookie-policy