Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 19:00:43 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 19:00:42 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 19:00:42 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 19:00:42 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Nov 19 19:00:42 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://u8411862.ct.sendgrid.net/ls/click?upn=u001.L4PK-2B0-2BuGt9pUFq-2FA3Op7Q-2F-2F9qb88t-2BRGAR6VDZa-2FLvCRsA1Ac7AajOPJIbQO7IP307a6xjNpvY8ZU7zRp9oyg-3D-3DE1Fg_CPebASiKsSpOAa3SLW44RsJxX9ZLglP0y4de2rxHefrHjZqY5SRIy9wKYZ9ERHf3zKK6o7ixiO4r4HIIwwj5RfSWrFWq-2FUbkZI-2FrBFl28oYsoQhEIuqeOt-2BjCiFlWuLC4rDomVqHzNhdvSab-2F-2Fw8d5IAtmQQI0BdCul9u12mfWcV4mFdLlsTdv9empaAUbuFjvZWnyaUm8GOERw44MojSA-3D-3D
|
|||
https://imsoidc.bentley.com/as/gMxxa/resume/as/authorization.ping
|
|||
https://imsoidc.bentley.com/connect/authorize?client_id=user-management&redirect_uri=https%3A%2F%2Fusermanagement.bentley.com%2Fsignin-oidc&response_type=code%20id_token&scope=openid%20profile%20email%20user-management%20bentley-admin-api%20notification-service-20%20entitlement-search-service-2576%20ulas-product-information-2727%20agreements-2354&response_mode=form_post&nonce=638676432446464491.YmFkZmFhY2UtYmU1NC00ZjY3LThhZGYtODBlMDJhZWQwYTczZTY4NTEwYjAtM2NmMi00MmViLTgyOGItNGVkNjMwNjQyMmVh&state=CfDJ8MKYeJ71b-9CueOVG07N9ivkk654DnU8_ToBsp41vINZlG9-FkWmB2bVtsDDqCROMDooA8OXWbIHfICL5YcfgafGkgdX0oSCqxq1DyINzkAzwKKoUWJIoZ_gTgT9xBqv6lUUVaYDK7EnzpCNRSk4nvcFJrI9G87rZjJIFk-wEi4euqVyY3y8kLKPpfP0m-dl0FBXHnImlxu7HVzxJj42A0Y_bMqLlgOIwxo4Kgi2G0C9SMI4ImjoWWajJn2SQAffb3ckBanhbjwwl9gu8CsZ6ZbDUTRj-exnF-xSf4z-T0_2onDJH6_0_dGbZs-YtdB2pg&x-client-SKU=ID_NETSTANDARD2_0&x-client-ver=5.6.0.0
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
prod.ims.bentley.proofidcloud.com
|
52.59.10.51
|
||
www.google.com
|
142.250.184.228
|
||
u8411862.ct.sendgrid.net
|
167.89.115.66
|
||
sni1gl.wpc.nucdn.net
|
152.199.21.175
|
||
imsoidc.bentley.com
|
unknown
|
||
connect-cdn.bentley.com
|
unknown
|
||
usermanagement.bentley.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
142.250.186.67
|
unknown
|
United States
|
||
34.104.35.123
|
unknown
|
United States
|
||
1.1.1.1
|
unknown
|
Australia
|
||
108.177.15.84
|
unknown
|
United States
|
||
192.168.2.16
|
unknown
|
unknown
|
||
142.250.185.106
|
unknown
|
United States
|
||
167.89.115.66
|
u8411862.ct.sendgrid.net
|
United States
|
||
142.250.185.202
|
unknown
|
United States
|
||
3.64.183.67
|
unknown
|
United States
|
||
216.58.206.46
|
unknown
|
United States
|
||
142.250.181.227
|
unknown
|
United States
|
||
20.105.232.11
|
unknown
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
52.59.10.51
|
prod.ims.bentley.proofidcloud.com
|
United States
|
||
142.250.185.174
|
unknown
|
United States
|
||
152.199.21.175
|
sni1gl.wpc.nucdn.net
|
United States
|
||
142.250.184.228
|
www.google.com
|
United States
|
There are 7 hidden IPs, click here to show them.