Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:14:16 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:14:16 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:14:16 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:14:16 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:14:16 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
Chrome Cache Entry: 100
|
ASCII text, with very long lines (1712)
|
downloaded
|
||
Chrome Cache Entry: 101
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 102
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 103
|
Web Open Font Format (Version 2), TrueType, length 168824, version 331.-31196
|
downloaded
|
||
Chrome Cache Entry: 104
|
HTML document, ASCII text, with very long lines (528)
|
downloaded
|
||
Chrome Cache Entry: 105
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 106
|
ASCII text, with very long lines (3861)
|
dropped
|
||
Chrome Cache Entry: 107
|
ASCII text, with very long lines (2242)
|
dropped
|
||
Chrome Cache Entry: 108
|
ASCII text, with very long lines (2242)
|
downloaded
|
||
Chrome Cache Entry: 109
|
PNG image data, 1 x 1, 8-bit gray+alpha, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 110
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 111
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 112
|
Unicode text, UTF-8 text, with very long lines (50869)
|
downloaded
|
||
Chrome Cache Entry: 113
|
MS Windows cursor resource - 1 icon, 32x32, 2 colors, hotspot @8x8
|
downloaded
|
||
Chrome Cache Entry: 114
|
ASCII text, with very long lines (65454)
|
dropped
|
||
Chrome Cache Entry: 115
|
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
|
downloaded
|
||
Chrome Cache Entry: 116
|
ASCII text, with very long lines (574)
|
dropped
|
||
Chrome Cache Entry: 117
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 118
|
ASCII text, with very long lines (10106)
|
downloaded
|
||
Chrome Cache Entry: 119
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 120
|
ASCII text, with very long lines (1572)
|
downloaded
|
||
Chrome Cache Entry: 121
|
PNG image data, 1 x 1, 8-bit gray+alpha, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 122
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 123
|
ASCII text, with very long lines (65536), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 124
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 125
|
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
|
downloaded
|
||
Chrome Cache Entry: 126
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 127
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 128
|
ASCII text, with very long lines (10034), with no line terminators
|
dropped
|
||
Chrome Cache Entry: 129
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 130
|
ASCII text, with very long lines (1384)
|
dropped
|
||
Chrome Cache Entry: 131
|
ASCII text, with very long lines (10034), with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 132
|
ASCII text, with very long lines (1712)
|
dropped
|
||
Chrome Cache Entry: 133
|
ASCII text, with very long lines (554)
|
downloaded
|
||
Chrome Cache Entry: 134
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 135
|
Unicode text, UTF-8 text, with very long lines (50869)
|
downloaded
|
||
Chrome Cache Entry: 136
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 137
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 138
|
JSON data
|
dropped
|
||
Chrome Cache Entry: 139
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 140
|
ASCII text, with very long lines (3861)
|
downloaded
|
||
Chrome Cache Entry: 141
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 142
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 143
|
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
|
dropped
|
||
Chrome Cache Entry: 144
|
ASCII text, with very long lines (1245)
|
dropped
|
||
Chrome Cache Entry: 145
|
ASCII text, with very long lines (574)
|
downloaded
|
||
Chrome Cache Entry: 146
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 147
|
ASCII text, with very long lines (1384)
|
downloaded
|
||
Chrome Cache Entry: 148
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 149
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 150
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 151
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 152
|
ASCII text, with very long lines (12264)
|
dropped
|
||
Chrome Cache Entry: 153
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 154
|
ASCII text, with very long lines (554)
|
dropped
|
||
Chrome Cache Entry: 155
|
PNG image data, 51 x 51, 8-bit colormap, interlaced
|
downloaded
|
||
Chrome Cache Entry: 156
|
ASCII text, with no line terminators
|
dropped
|
||
Chrome Cache Entry: 157
|
PNG image data, 400 x 787, 1-bit colormap, non-interlaced
|
downloaded
|
||
Chrome Cache Entry: 158
|
ASCII text, with very long lines (10106)
|
dropped
|
||
Chrome Cache Entry: 159
|
MS Windows cursor resource - 1 icon, 32x32, 2 colors, hotspot @8x8
|
dropped
|
||
Chrome Cache Entry: 160
|
JSON data
|
downloaded
|
||
Chrome Cache Entry: 161
|
PNG image data, 400 x 787, 1-bit colormap, non-interlaced
|
dropped
|
||
Chrome Cache Entry: 162
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 88
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 89
|
ASCII text
|
downloaded
|
||
Chrome Cache Entry: 90
|
ASCII text, with no line terminators
|
downloaded
|
||
Chrome Cache Entry: 91
|
PNG image data, 51 x 51, 8-bit colormap, interlaced
|
dropped
|
||
Chrome Cache Entry: 92
|
RIFF (little-endian) data, Web/P image
|
downloaded
|
||
Chrome Cache Entry: 93
|
ASCII text, with very long lines (1245)
|
downloaded
|
||
Chrome Cache Entry: 94
|
ASCII text, with very long lines (65454)
|
downloaded
|
||
Chrome Cache Entry: 95
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 96
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 97
|
ASCII text, with no line terminators
|
dropped
|
||
Chrome Cache Entry: 98
|
RIFF (little-endian) data, Web/P image
|
dropped
|
||
Chrome Cache Entry: 99
|
ASCII text, with very long lines (12264)
|
downloaded
|
There are 72 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US
--service-sandbox-type=none --mojo-platform-channel-handle=1720 --field-trial-handle=1996,i,14989227660149926635,2937037172085821424,262144
--disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction
/prefetch:8
|
||
C:\Program Files\Google\Chrome\Application\chrome.exe
|
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pckg.ai/X5KpCErF"
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://pckg.ai/X5KpCErF
|
|||
https://api.package.ai/dons/internal/v1/locations/deliveries/fqacXADiBJaGnxG
|
65.9.112.86
|
||
https://cdn.jsdelivr.net/npm/
|
unknown
|
||
https://app.package.ai/recipient/dons/app.css
|
108.158.75.94
|
||
https://app.package.ai/recipient/dons/static/fonts/fa-regular-400.33904a1..woff2
|
108.158.75.94
|
||
http://www.broofa.com
|
unknown
|
||
https://cdn.jsdelivr.net/npm/vuetify
|
unknown
|
||
https://api.package.ai/dons/internal/v1/media/logo?deliveryId=fqacXADiBJaGnxG
|
65.9.112.86
|
||
https://app.package.ai/recipient/dons/#/app/tracking?app=dons&deliveryId=fqacXADiBJaGnxG
|
|||
https://sockjs-mt1.pusher.com/pusher/app/6b646e1a5200e82bd076/890/635kq22b/xhr_streaming?protocol=7&client=js&version=8.3.0&t=1732133688210&n=1
|
44.217.82.191
|
||
http://g.co/dev/maps-no-account
|
unknown
|
||
https://packageai-static.s3.amazonaws.com/images/maps/markers-v2/general/recipient_address_flag.png
|
16.182.65.121
|
||
https://api.package.ai/dons/internal/v1/client/configuration/recipient
|
65.9.112.86
|
||
https://developers.google.com/maps/documentation/javascript/error-messages#
|
unknown
|
||
https://api.package.ai/dons/v1/auth2/delivery
|
65.9.112.86
|
||
https://developers.google.com/maps/documentation/javascript/error-messages#unsupported-browsers
|
unknown
|
||
https://goo.gle/js-open-now.
|
unknown
|
||
https://pckg.ai/X5KpCErF
|
65.9.112.54
|
||
https://sockjs-mt1.pusher.com/pusher/app/6b646e1a5200e82bd076/890/635kq22b/xhr_send?t=1732133717038&n=2
|
44.217.82.191
|
||
https://developers.google.com/maps/documentation/javascript/libraries
|
unknown
|
||
https://fontawesome.com
|
unknown
|
||
https://www.google.com
|
unknown
|
||
https://api.package.ai/dons/internal/v1/reports/deliveries/fqacXADiBJaGnxG/tracking
|
65.9.112.86
|
||
https://app.package.ai/recipient/dons/static/js/app.30b01b8aa99897197a87.js
|
108.158.75.94
|
||
https://developers.google.com/maps/documentation/javascript/error-messages
|
unknown
|
||
https://fengyuanchen.github.io/viewerjs
|
unknown
|
||
https://app.package.ai/recipient/dons/
|
108.158.75.94
|
||
https://packageai-media.s3.amazonaws.com/prod/account-gDLbULWuVQAD/logo/dons_logo.png
|
unknown
|
||
https://ws-mt1.pusher.com/app/6b646e1a5200e82bd076?protocol=7&client=js&version=8.3.0&flash=false
|
98.83.99.195
|
||
https://developers.google.com/maps/documentation/javascript/versions#beta-channel
|
unknown
|
||
https://fontawesome.com/license
|
unknown
|
||
https://cdn.jsdelivr.net/npm/@mdi/font@6.x/css/materialdesignicons.min.css
|
151.101.193.229
|
||
https://cdn.jsdelivr.net/npm/vuetify@2.x/dist/vuetify.min.css
|
151.101.193.229
|
||
https://goo.gle/js-open-now
|
unknown
|
||
https://goo.gle/js-api-loading
|
unknown
|
||
https://support.google.com/contributionpolicy/answer/7422880
|
unknown
|
||
https://app.package.ai/recipient/dons/version.txt?r=1732133672649
|
108.158.75.94
|
||
https://developer.mozilla.org/docs/Web/API/EventTarget/addEventListener
|
unknown
|
||
https://developers.google.com/maps/documentation/javascript/advanced-markers/migration
|
unknown
|
||
https://developers.google.com/maps/documentation/javascript/webgl/support
|
unknown
|
||
https://support.google.com/maps/answer/3092445
|
unknown
|
||
https://www.google.com/maps/dir/
|
unknown
|
||
https://packageai-media.s3.amazonaws.com/prod/defaults/driver/default-driver-photo.png
|
unknown
|
||
https://app.package.ai/recipient/dons/version.txt?r=1732133666539
|
108.158.75.94
|
||
https://developers.google.com/maps/documentation/javascript/styling#cloud_tooling
|
unknown
|
||
https://fonts.google.com/license/googlerestricted
|
unknown
|
||
https://app.package.ai/recipient/dons/static/favicon.png
|
108.158.75.94
|
||
https://support.google.com/fusiontables/answer/9185417).
|
unknown
|
||
https://developers.google.com/maps/deprecations
|
unknown
|
There are 38 hidden URLs, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
jsdelivr.map.fastly.net
|
151.101.193.229
|
||
s3-w.us-east-1.amazonaws.com
|
16.182.65.121
|
||
api.package.ai
|
65.9.112.86
|
||
api-js.mixpanel.com
|
130.211.34.183
|
||
app.package.ai
|
108.158.75.94
|
||
socket-mt1-ingress-1987402783.us-east-1.elb.amazonaws.com
|
98.83.99.195
|
||
www.google.com
|
142.250.181.100
|
||
pckg.ai
|
65.9.112.54
|
||
cdn.mxpnl.com
|
130.211.5.208
|
||
ingress-sticky-haproxy-mt1-912d8b7308f82d6c.elb.us-east-1.amazonaws.com
|
44.217.82.191
|
||
packageai-static.s3.amazonaws.com
|
unknown
|
||
cdn.jsdelivr.net
|
unknown
|
||
sockjs-mt1.pusher.com
|
unknown
|
||
ws-mt1.pusher.com
|
unknown
|
There are 4 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
130.211.34.183
|
api-js.mixpanel.com
|
United States
|
||
16.182.65.121
|
s3-w.us-east-1.amazonaws.com
|
United States
|
||
151.101.193.229
|
jsdelivr.map.fastly.net
|
United States
|
||
3.5.29.197
|
unknown
|
United States
|
||
192.168.2.5
|
unknown
|
unknown
|
||
142.250.181.100
|
www.google.com
|
United States
|
||
130.211.5.208
|
cdn.mxpnl.com
|
United States
|
||
108.158.75.94
|
app.package.ai
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
98.83.99.195
|
socket-mt1-ingress-1987402783.us-east-1.elb.amazonaws.com
|
United States
|
||
65.9.112.54
|
pckg.ai
|
United States
|
||
44.217.82.191
|
ingress-sticky-haproxy-mt1-912d8b7308f82d6c.elb.us-east-1.amazonaws.com
|
United States
|
||
65.9.112.86
|
api.package.ai
|
United States
|
There are 3 hidden IPs, click here to show them.
DOM / HTML
URL
|
Malicious
|
|
---|---|---|
https://app.package.ai/recipient/dons/#/app/tracking?app=dons&deliveryId=fqacXADiBJaGnxG
|
||
https://app.package.ai/recipient/dons/#/app/tracking?app=dons&deliveryId=fqacXADiBJaGnxG
|
||
https://app.package.ai/recipient/dons/#/app/tracking?app=dons&deliveryId=fqacXADiBJaGnxG
|