IOC Report
https://pckg.ai/X5KpCErF

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:25:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:25:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:25:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:25:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Nov 20 19:25:24 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 102
ASCII text, with very long lines (10034), with no line terminators
dropped
Chrome Cache Entry: 104
ASCII text, with very long lines (1712)
downloaded
Chrome Cache Entry: 106
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 107
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 108
Web Open Font Format (Version 2), TrueType, length 168824, version 331.-31196
downloaded
Chrome Cache Entry: 109
HTML document, ASCII text, with very long lines (528)
downloaded
Chrome Cache Entry: 110
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (3861)
dropped
Chrome Cache Entry: 113
ASCII text, with very long lines (2242)
dropped
Chrome Cache Entry: 114
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 118
Unicode text, UTF-8 text, with very long lines (50869)
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (65454)
dropped
Chrome Cache Entry: 121
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (574)
dropped
Chrome Cache Entry: 123
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 126
JSON data
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 129
PNG image data, 1 x 1, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 132
ASCII text
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (554)
downloaded
Chrome Cache Entry: 143
Unicode text, UTF-8 text, with very long lines (50869)
downloaded
Chrome Cache Entry: 144
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 145
JSON data
dropped
Chrome Cache Entry: 147
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 148
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 151
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 152
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 154
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 155
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 156
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (1384)
downloaded
Chrome Cache Entry: 159
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 161
JSON data
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (12264)
dropped
Chrome Cache Entry: 165
PNG image data, 51 x 51, 8-bit colormap, interlaced
downloaded
Chrome Cache Entry: 166
PNG image data, 400 x 787, 1-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (10106)
dropped
Chrome Cache Entry: 168
MS Windows cursor resource - 1 icon, 32x32, 2 colors, hotspot @8x8
dropped
Chrome Cache Entry: 169
JSON data
downloaded
Chrome Cache Entry: 96
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 97
ASCII text
downloaded
Chrome Cache Entry: 99
ASCII text, with very long lines (1245)
downloaded
There are 40 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://pckg.ai/X5KpCErF
https://app.package.ai/recipient/dons/#/app/tracking?app=dons&deliveryId=fqacXADiBJaGnxG

Domains

Name
IP
Malicious
jsdelivr.map.fastly.net
151.101.65.229
s3-w.us-east-1.amazonaws.com
52.217.86.124
api.package.ai
52.84.45.89
api-js.mixpanel.com
130.211.34.183
app.package.ai
108.158.75.46
socket-mt1-ingress-1987402783.us-east-1.elb.amazonaws.com
18.214.171.71
www.google.com
142.250.181.100
pckg.ai
65.9.112.89
cdn.mxpnl.com
35.186.235.23
ingress-sticky-haproxy-mt1-912d8b7308f82d6c.elb.us-east-1.amazonaws.com
34.201.239.212
packageai-static.s3.amazonaws.com
unknown
cdn.jsdelivr.net
unknown
sockjs-mt1.pusher.com
unknown
ws-mt1.pusher.com
unknown
There are 4 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.217.19.206
unknown
United States
130.211.34.183
api-js.mixpanel.com
United States
172.217.17.67
unknown
United States
192.168.2.17
unknown
unknown
216.58.208.227
unknown
United States
108.158.75.46
app.package.ai
United States
107.178.240.159
unknown
United States
52.55.106.120
unknown
United States
172.217.19.170
unknown
United States
172.217.21.35
unknown
United States
34.201.239.212
ingress-sticky-haproxy-mt1-912d8b7308f82d6c.elb.us-east-1.amazonaws.com
United States
52.84.45.12
unknown
United States
35.186.235.23
cdn.mxpnl.com
United States
172.217.19.238
unknown
United States
1.1.1.1
unknown
Australia
65.9.112.89
pckg.ai
United States
172.217.17.35
unknown
United States
151.101.65.229
jsdelivr.map.fastly.net
United States
18.214.171.71
socket-mt1-ingress-1987402783.us-east-1.elb.amazonaws.com
United States
142.250.181.100
www.google.com
United States
216.58.208.234
unknown
United States
64.233.165.84
unknown
United States
52.217.86.124
s3-w.us-east-1.amazonaws.com
United States
239.255.255.250
unknown
Reserved
52.84.45.89
api.package.ai
United States
172.217.19.10
unknown
United States
There are 16 hidden IPs, click here to show them.