IOC Report
http://1qm32p.axshare.com/id=jxmnwg&p=files_-_view&g=1

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 12:18:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 12:18:21 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 12:18:21 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 12:18:21 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 12:18:21 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (12586)
downloaded
Chrome Cache Entry: 105
ASCII text, with very long lines (354)
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (6187)
downloaded
Chrome Cache Entry: 107
Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 108
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 109
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (55203)
downloaded
Chrome Cache Entry: 111
HTML document, Unicode text, UTF-8 text, with very long lines (32769)
dropped
Chrome Cache Entry: 112
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 64x64, components 3
downloaded
Chrome Cache Entry: 113
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 119
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 120
HTML document, ASCII text, with very long lines (8047), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 122
ASCII text, with very long lines (12586)
downloaded
Chrome Cache Entry: 123
Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 125
ASCII text
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 14892, version 1.0
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (65191)
dropped
Chrome Cache Entry: 129
ASCII text, with very long lines (65270)
dropped
Chrome Cache Entry: 130
ASCII text
downloaded
Chrome Cache Entry: 131
HTML document, Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (1264)
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (12586)
dropped
Chrome Cache Entry: 140
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 142
ASCII text
downloaded
Chrome Cache Entry: 143
ASCII text, with very long lines (65274)
dropped
Chrome Cache Entry: 144
Web Open Font Format (Version 2), TrueType, length 14824, version 1.0
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 146
HTML document, ASCII text
downloaded
Chrome Cache Entry: 147
Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 148
ASCII text
dropped
Chrome Cache Entry: 151
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 152
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 155
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (539)
downloaded
Chrome Cache Entry: 159
ASCII text
downloaded
Chrome Cache Entry: 160
Java source, ASCII text, with very long lines (786)
dropped
Chrome Cache Entry: 162
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (12586)
downloaded
Chrome Cache Entry: 165
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 166
HTML document, ASCII text
downloaded
Chrome Cache Entry: 167
HTML document, ASCII text
downloaded
Chrome Cache Entry: 169
Web Open Font Format (Version 2), TrueType, length 48444, version 1.0
downloaded
Chrome Cache Entry: 170
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
downloaded
Chrome Cache Entry: 172
ASCII text
dropped
Chrome Cache Entry: 173
ASCII text
downloaded
There are 45 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://1qm32p.axshare.com/id=jxmnwg&p=files_-_view&g=1
https://1qm32p.axshare.com/id=jxmnwg&p=files_-_view&g=1
malicious
https://app.axure.cloud/app/
https://accounts.axure.com/app/login?redirect=https%3A%2F%2Fapp.axure.cloud%2Fuser%2Faxureauth%3Fredirect%3Dhttps%253A%252F%252Fapp.axure.cloud%252Fapp%252Flogin%253Fauth%253Dtrue%2526redirect%253D%25252Ffs%25252Fmanage

Domains

Name
IP
Malicious
js.hs-banner.com
172.64.147.16
accounts.axure.com
54.175.98.240
ax-0001.ax-dc-msedge.net
150.171.29.10
js.hsadspixel.net
104.17.128.172
js.hs-analytics.net
104.17.175.201
ax-0001.ax-msedge.net
150.171.27.10
app.axure.cloud
54.156.155.152
stats.g.doubleclick.net
142.251.168.155
1qm32p.axshare.com
52.57.229.137
www.axure.com
34.204.121.204
js.hs-scripts.com
104.16.138.209
www.google.com
142.250.186.68
analytics.google.com
142.250.185.238
td.doubleclick.net
142.250.184.194
js.hscollectedforms.net
104.16.111.254
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
74.125.133.155
unknown
United States
142.250.185.206
unknown
United States
34.204.121.204
www.axure.com
United States
216.58.206.72
unknown
United States
192.168.2.17
unknown
unknown
142.250.185.200
unknown
United States
192.168.2.18
unknown
unknown
192.168.2.4
unknown
unknown
142.250.185.106
unknown
United States
52.57.229.137
1qm32p.axshare.com
United States
192.168.2.6
unknown
unknown
54.156.155.152
app.axure.cloud
United States
3.124.181.203
unknown
United States
192.168.2.22
unknown
unknown
150.171.28.10
unknown
United States
172.64.147.16
js.hs-banner.com
United States
142.250.186.131
unknown
United States
104.16.111.254
js.hscollectedforms.net
United States
104.16.138.209
js.hs-scripts.com
United States
142.250.184.227
unknown
United States
142.250.184.206
unknown
United States
104.17.128.172
js.hsadspixel.net
United States
172.217.16.202
unknown
United States
1.1.1.1
unknown
Australia
172.217.16.206
unknown
United States
142.250.184.194
td.doubleclick.net
United States
142.251.168.155
stats.g.doubleclick.net
United States
216.58.206.67
unknown
United States
104.16.137.209
unknown
United States
142.250.185.234
unknown
United States
142.250.185.238
analytics.google.com
United States
142.251.173.84
unknown
United States
150.171.27.10
ax-0001.ax-msedge.net
United States
54.175.98.240
accounts.axure.com
United States
142.250.181.227
unknown
United States
104.17.175.201
js.hs-analytics.net
United States
239.255.255.250
unknown
Reserved
142.250.185.174
unknown
United States
52.22.148.188
unknown
United States
150.171.29.10
ax-0001.ax-dc-msedge.net
United States
172.217.16.194
unknown
United States
142.250.186.40
unknown
United States
104.17.223.152
unknown
United States
34.200.95.216
unknown
United States
142.250.184.234
unknown
United States
172.217.16.131
unknown
United States
There are 37 hidden IPs, click here to show them.