IOC Report
https://form.jotform.com/243186396374063

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 18:51:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 18:51:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 18:51:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 18:51:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 18:51:26 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 103
Web Open Font Format (Version 2), TrueType, length 103152, version 3.1245
downloaded
Chrome Cache Entry: 104
HTML document, ASCII text, with very long lines (5642)
downloaded
Chrome Cache Entry: 107
ASCII text
downloaded
Chrome Cache Entry: 108
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 109
Unicode text, UTF-8 text, with very long lines (6048)
downloaded
Chrome Cache Entry: 110
ASCII text, with very long lines (397)
downloaded
Chrome Cache Entry: 111
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (469)
dropped
Chrome Cache Entry: 113
very short file (no magic)
downloaded
Chrome Cache Entry: 116
HTML document, ASCII text, with very long lines (32193), with CRLF line terminators
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (2768)
dropped
Chrome Cache Entry: 120
Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (522)
dropped
Chrome Cache Entry: 122
PNG image data, 3396 x 1920, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 123
HTML document, ASCII text, with very long lines (738)
downloaded
Chrome Cache Entry: 124
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (5693)
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (570)
downloaded
Chrome Cache Entry: 129
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 130
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 131
ASCII text
downloaded
Chrome Cache Entry: 137
Web Open Font Format (Version 2), TrueType, length 111740, version 3.1245
downloaded
Chrome Cache Entry: 138
Web Open Font Format (Version 2), TrueType, length 111192, version 3.1245
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (761)
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (3968)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (1436)
dropped
Chrome Cache Entry: 145
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (557)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (2199)
downloaded
Chrome Cache Entry: 149
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (404)
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (533)
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 155
ASCII text
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (680)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (3168), with no line terminators
downloaded
Chrome Cache Entry: 159
PNG image data, 288 x 288, 8-bit colormap, non-interlaced
dropped
There are 34 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://form.jotform.com/243186396374063
malicious
https://form.jotform.com/243186396374063
malicious
https://s6m5.gwckpfsj.ru/MdmjiH0/
malicious

Domains

Name
IP
Malicious
cdn01.jotfor.ms
104.22.73.81
docs.google.com
142.250.185.174
a.nel.cloudflare.com
35.190.80.1
cdn.jotfor.ms
104.22.72.81
www.jotform.com
104.19.128.105
sheets.google.com
142.250.184.206
go.lb.jotform.com
35.201.118.58
code.jquery.com
151.101.130.137
www3.l.google.com
216.58.206.46
play.google.com
142.250.185.206
submit.jotform.com
104.19.128.105
cdn03.jotfor.ms
104.22.72.81
www.google.com
142.250.186.68
api.jotform.com
104.19.129.105
s6m5.gwckpfsj.ru
188.114.96.3
cdn02.jotfor.ms
172.67.7.107
u0i80kuuob1iy6zegcwamjpmstb0jwt7jfjtna3zvl06tsuf2wys.ndshalox.com
172.67.191.170
events.jotform.com
104.19.129.105
files.jotform.com
34.54.32.121
googlehosted.l.googleusercontent.com
216.58.206.65
form.jotform.com
unknown
accounts.youtube.com
unknown
blogger.googleusercontent.com
unknown
There are 13 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
142.250.185.206
play.google.com
United States
104.19.129.105
api.jotform.com
United States
192.168.2.16
unknown
unknown
142.250.185.227
unknown
United States
142.250.185.202
unknown
United States
151.101.130.137
code.jquery.com
United States
104.19.128.105
www.jotform.com
United States
142.250.185.163
unknown
United States
142.250.186.110
unknown
United States
151.101.194.137
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.184.206
sheets.google.com
United States
142.250.184.228
unknown
United States
142.250.186.99
unknown
United States
104.22.73.81
cdn01.jotfor.ms
United States
142.250.185.67
unknown
United States
1.1.1.1
unknown
Australia
108.177.15.84
unknown
United States
172.217.16.206
unknown
United States
142.250.184.193
unknown
United States
35.201.118.58
go.lb.jotform.com
United States
172.217.18.3
unknown
United States
216.58.206.65
googlehosted.l.googleusercontent.com
United States
142.250.185.110
unknown
United States
34.54.32.121
files.jotform.com
United States
172.67.7.107
cdn02.jotfor.ms
United States
216.58.206.46
www3.l.google.com
United States
142.251.173.84
unknown
United States
142.250.185.170
unknown
United States
172.67.191.170
u0i80kuuob1iy6zegcwamjpmstb0jwt7jfjtna3zvl06tsuf2wys.ndshalox.com
United States
239.255.255.250
unknown
Reserved
142.250.185.174
docs.google.com
United States
188.114.96.3
s6m5.gwckpfsj.ru
European Union
104.22.72.81
cdn.jotfor.ms
United States
There are 25 hidden IPs, click here to show them.