IOC Report
https://google.com.mx//url?ob=pglnk4shsljbM2dWBuuV7ic1KFgH&aw=f_rand_string_lowercase(8)n9QXkBk0w4OyBDvUpuk&sa=t&whi=f_rand_string_lowercase(8)zOPGXNRztppHiTbPIt5f&url=amp%2Fbraverygray.com/.dd/Kcxz0m1anE-SUREDANN-Y3NoYW5ub25Ac2tvcmJ1cmdjb21wYW55LmNvbQ==

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 20 18:21:23 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 20 18:21:23 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 20 18:21:23 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 20 18:21:23 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Dec 20 18:21:23 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
gzip compressed data, from Unix, original size modulo 2^32 57510
downloaded
Chrome Cache Entry: 101
gzip compressed data, original size modulo 2^32 3651
dropped
Chrome Cache Entry: 102
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 103
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 104
gzip compressed data, from Unix, original size modulo 2^32 190247
downloaded
Chrome Cache Entry: 105
gzip compressed data, original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 106
gzip compressed data, original size modulo 2^32 1864
dropped
Chrome Cache Entry: 78
gzip compressed data, from Unix, original size modulo 2^32 450747
downloaded
Chrome Cache Entry: 79
gzip compressed data, from Unix, original size modulo 2^32 407071
dropped
Chrome Cache Entry: 80
gzip compressed data, from Unix, original size modulo 2^32 3556
downloaded
Chrome Cache Entry: 81
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 82
gzip compressed data, from Unix, original size modulo 2^32 190247
dropped
Chrome Cache Entry: 83
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 84
HTML document, ASCII text
downloaded
Chrome Cache Entry: 85
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 86
gzip compressed data, from Unix, original size modulo 2^32 142353
dropped
Chrome Cache Entry: 87
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 88
gzip compressed data, original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 89
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 90
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 91
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 92
gzip compressed data, from Unix, original size modulo 2^32 113424
downloaded
Chrome Cache Entry: 93
gzip compressed data, from Unix, original size modulo 2^32 407071
downloaded
Chrome Cache Entry: 94
gzip compressed data, from Unix, original size modulo 2^32 57510
dropped
Chrome Cache Entry: 95
gzip compressed data, from Unix, original size modulo 2^32 450747
dropped
Chrome Cache Entry: 96
gzip compressed data, from Unix, original size modulo 2^32 26677
downloaded
Chrome Cache Entry: 97
gzip compressed data, from Unix, original size modulo 2^32 26677
dropped
Chrome Cache Entry: 98
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 99
gzip compressed data, from Unix, original size modulo 2^32 142353
downloaded
There are 26 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2064 --field-trial-handle=2020,i,11667800042035244623,12492529446862282351,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://google.com.mx//url?ob=pglnk4shsljbM2dWBuuV7ic1KFgH&aw=f_rand_string_lowercase(8)n9QXkBk0w4OyBDvUpuk&sa=t&whi=f_rand_string_lowercase(8)zOPGXNRztppHiTbPIt5f&url=amp%2Fbraverygray.com/.dd/Kcxz0m1anE-SUREDANN-Y3NoYW5ub25Ac2tvcmJ1cmdjb21wYW55LmNvbQ=="

URLs

Name
IP
Malicious
https://google.com.mx//url?ob=pglnk4shsljbM2dWBuuV7ic1KFgH&aw=f_rand_string_lowercase(8)n9QXkBk0w4OyBDvUpuk&sa=t&whi=f_rand_string_lowercase(8)zOPGXNRztppHiTbPIt5f&url=amp%2Fbraverygray.com/.dd/Kcxz0m1anE-SUREDANN-Y3NoYW5ub25Ac2tvcmJ1cmdjb21wYW55LmNvbQ==
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/images/favicon_a_eupayfgghqiai7k9sol6lg2.ico
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/js/BssoInterrupt_Core_zKox_QMcTIVut7mG_Z9Eew2.js
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/js/asyncchunk/convergedlogin_pcustomizationloader_27cef08ca792f8e8b149.js
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js
159.89.96.140
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/7fd541d7502147ce9bcdf37900bf1488/
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/images/marching_ants_986f40b5a9dc7d39ef8396797f61b323.gif
159.89.96.140
malicious
https://3d381eb0-7fd541d7.acmgs.com.au/OneCollector/1.0/?cors=true&content-type=application/x-json-stream&client-id=NO_AUTH&client-version=1DS-Web-JS-3.2.6&apikey=b0c252808e614e949086e019ae1cb300-e0c02060-e3b3-4965-bd7c-415e1a7a9fde-6951&upload-time=1734722554431&time-delta-to-apply-millis=use-collector-delta&w=0&NoResponseBody=true
159.89.96.140
malicious
https://80b0d227-7fd541d7.acmgs.com.au/api/report?catId=GW+estsfd+SEC
159.89.96.140
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/favicon.ico
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/images/microsoft_logo_564db913a7fa0ca42727161c6d031bef.svg
159.89.96.140
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/common/login
malicious
https://l1ve.acmgs.com.au/Me.htm?v=3
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/js/asyncchunk/convergedlogin_ppassword_b6632c4da67c72da7b92.js
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/images/backgrounds/2_11d9e3bcdfede9ce5ce5ace2d129f1c4.svg
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/ests/2.1/content/cdnbundles/ux.converged.login.strings-en.min_i8f-75gfk3tbsm8bmatnqa2.js
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/ests/2.1/content/cdnbundles/converged.v2.login.min_81imvbluez-v5hbzpkxfcg2.css
159.89.96.140
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com&sso_reload=true
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/js/ConvergedLogin_PCore_kAx9qZOSH4g90FNHstHMCA2.js
159.89.96.140
malicious
https://8a95b52b-7fd541d7.acmgs.com.au/Prefetch/Prefetch.aspx
159.89.96.140
malicious
https://0a9d60c7-7fd541d7.acmgs.com.au/shared/1.0/content/images/marching_ants_white_8257b0707cbe1d0bd2661b80068676fe.gif
159.89.96.140
malicious
https://img.icons8.com/emoji/48/check-mark-emoji.png
37.19.194.80
https://www.google.com.mx/url?ob=pglnk4shsljbM2dWBuuV7ic1KFgH&aw=f_rand_string_lowercase(8)n9QXkBk0w4OyBDvUpuk&sa=t&whi=f_rand_string_lowercase(8)zOPGXNRztppHiTbPIt5f&url=amp%2Fbraverygray.com/.dd/Kcxz0m1anE-SUREDANN-Y3NoYW5ub25Ac2tvcmJ1cmdjb21wYW55LmNvbQ==
142.250.181.67
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com
http://braverygray.com/favicon.ico
162.241.114.35
https://www.google.com.mx/amp/braverygray.com/.dd/Kcxz0m1anE-SUREDANN-Y3NoYW5ub25Ac2tvcmJ1cmdjb21wYW55LmNvbQ==
142.250.181.67
http://braverygray.com/.dd/Kcxz0m1anE-SUREDANN-Y3NoYW5ub25Ac2tvcmJ1cmdjb21wYW55LmNvbQ==
There are 16 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
80b0d227-7fd541d7.acmgs.com.au
159.89.96.140
malicious
l1ve.acmgs.com.au
159.89.96.140
malicious
0a9d60c7-7fd541d7.acmgs.com.au
159.89.96.140
malicious
fd33ba4f-7fd541d7.acmgs.com.au
159.89.96.140
malicious
0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au
159.89.96.140
malicious
3d381eb0-7fd541d7.acmgs.com.au
159.89.96.140
malicious
8a95b52b-7fd541d7.acmgs.com.au
159.89.96.140
malicious
1004834818.rsc.cdn77.org
37.19.194.80
www.google.com.mx
142.250.181.67
www.google.com
142.250.181.132
google.com.mx
216.58.208.227
braverygray.com
162.241.114.35
img.icons8.com
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
192.168.2.5
unknown
unknown
malicious
159.89.96.140
80b0d227-7fd541d7.acmgs.com.au
United States
malicious
142.250.181.132
www.google.com
United States
239.255.255.250
unknown
Reserved
142.250.181.67
www.google.com.mx
United States
37.19.194.80
1004834818.rsc.cdn77.org
Ukraine
162.241.114.35
braverygray.com
United States

DOM / HTML

URL
Malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com&sso_reload=true
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com&sso_reload=true
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com&sso_reload=true
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com&sso_reload=true
malicious
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/common/login
malicious
http://braverygray.com/.dd/Kcxz0m1anE-SUREDANN-Y3NoYW5ub25Ac2tvcmJ1cmdjb21wYW55LmNvbQ==
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/?777=cshannon%40skorburgcompany.com&sso_reload=true
https://0nlineactivations-0nlineactivations-0nlineactivations.acmgs.com.au/common/login