IOC Report
https://drop.dor.state.ma.us/human.aspx?OrgID=2763&Arg12=message&Arg06=180947434&Arg08=6a6gy6fi61caub09

loading gif

Files

File Path
Type
Category
Malicious
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping5696_134408271\LICENSE
ASCII text
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping5696_134408271\_metadata\verified_contents.json
JSON data
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping5696_134408271\manifest.fingerprint
ASCII text, with no line terminators
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping5696_134408271\manifest.json
JSON data
dropped
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping5696_134408271\sets.json
JSON data
dropped
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (596)
downloaded
Chrome Cache Entry: 126
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
dropped
Chrome Cache Entry: 127
PNG image data, 2 x 23, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 128
HTML document, ASCII text, with very long lines (3450), with CRLF line terminators
downloaded
Chrome Cache Entry: 129
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 130
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (496)
downloaded
Chrome Cache Entry: 132
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 133
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 134
Unicode text, UTF-8 text, with very long lines (63906)
downloaded
Chrome Cache Entry: 135
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 303033
dropped
Chrome Cache Entry: 136
Web Open Font Format, TrueType, length 98780, version 1.1
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (512)
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (46090)
downloaded
Chrome Cache Entry: 139
gzip compressed data, from Unix, original size modulo 2^32 53065
dropped
Chrome Cache Entry: 140
Web Open Font Format, TrueType, length 96116, version 1.1
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (17796)
dropped
Chrome Cache Entry: 142
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1420x1200, components 3
downloaded
Chrome Cache Entry: 143
data
dropped
Chrome Cache Entry: 144
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 145
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 146
ASCII text, with very long lines (1434), with no line terminators
dropped
Chrome Cache Entry: 147
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 148
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CC 2017 (Macintosh), datetime=2017-07-28T14:18:49-04:00], baseline, precision 8, 280x60, components 3
downloaded
Chrome Cache Entry: 149
Unicode text, UTF-8 text, with very long lines (32057)
downloaded
Chrome Cache Entry: 150
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 151
Unicode text, UTF-8 text, with very long lines (50451)
downloaded
Chrome Cache Entry: 152
PNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 154
Unicode text, UTF-8 text, with very long lines (22804)
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (2054)
downloaded
Chrome Cache Entry: 156
ASCII text
downloaded
Chrome Cache Entry: 157
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 158
Unicode text, UTF-8 text, with very long lines (390)
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (65450), with CRLF line terminators
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (14782)
downloaded
Chrome Cache Entry: 161
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 162
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 163
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 164
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 165
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CC 2017 (Macintosh), datetime=2017-07-28T14:18:49-04:00], baseline, precision 8, 280x60, components 3
dropped
Chrome Cache Entry: 166
Unicode text, UTF-8 text, with very long lines (63906)
dropped
Chrome Cache Entry: 167
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (493)
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (65450), with CRLF line terminators
dropped
Chrome Cache Entry: 170
PNG image data, 27 x 20, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 171
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 172
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 173
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1420x1200, components 3
dropped
Chrome Cache Entry: 174
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 175
Unicode text, UTF-8 text, with very long lines (65071), with no line terminators
dropped
Chrome Cache Entry: 176
Unicode text, UTF-8 text, with very long lines (390)
downloaded
Chrome Cache Entry: 177
ASCII text
dropped
Chrome Cache Entry: 178
ASCII text, with very long lines (1508)
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (17796)
downloaded
Chrome Cache Entry: 180
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 181
PNG image data, 451 x 98, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 182
gzip compressed data, from Unix, original size modulo 2^32 53065
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (512)
dropped
Chrome Cache Entry: 184
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
downloaded
Chrome Cache Entry: 185
Unicode text, UTF-8 text, with very long lines (50451)
dropped
Chrome Cache Entry: 186
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 187
data
downloaded
Chrome Cache Entry: 188
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (64616)
downloaded
Chrome Cache Entry: 190
HTML document, ASCII text, with very long lines (3443), with CRLF line terminators
downloaded
Chrome Cache Entry: 191
PNG image data, 14 x 14, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 192
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 193
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 195
PNG image data, 27 x 20, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 196
ASCII text, with very long lines (1508)
dropped
Chrome Cache Entry: 197
ASCII text, with very long lines (45797)
dropped
Chrome Cache Entry: 198
gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 303033
downloaded
Chrome Cache Entry: 199
Web Open Font Format, TrueType, length 98024, version 4.7
downloaded
Chrome Cache Entry: 200
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 201
Unicode text, UTF-8 text, with very long lines (645)
downloaded
Chrome Cache Entry: 202
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 203
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 204
ASCII text, with very long lines (56359), with no line terminators
downloaded
Chrome Cache Entry: 205
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 206
ASCII text, with very long lines (64616)
dropped
Chrome Cache Entry: 207
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 208
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 209
PNG image data, 451 x 98, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 210
MS Windows icon resource - 8 icons, 256x256, 32 bits/pixel, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 211
ASCII text, with very long lines (2054)
dropped
Chrome Cache Entry: 212
MS Windows icon resource - 8 icons, 256x256, 32 bits/pixel, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 213
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (61177)
downloaded
Chrome Cache Entry: 215
PNG image data, 2 x 23, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (493)
downloaded
Chrome Cache Entry: 217
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 218
data
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (45797)
downloaded
Chrome Cache Entry: 220
assembler source, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 221
Unicode text, UTF-8 text, with very long lines (65071), with no line terminators
downloaded
Chrome Cache Entry: 222
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 223
ASCII text, with very long lines (1434), with no line terminators
downloaded
Chrome Cache Entry: 224
Unicode text, UTF-8 text, with very long lines (32057)
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 226
ASCII text, with very long lines (14782)
dropped
There are 98 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2404 --field-trial-handle=2144,i,11258294382138793620,3253914066803892311,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://drop.dor.state.ma.us/human.aspx?OrgID=2763&Arg12=message&Arg06=180947434&Arg08=6a6gy6fi61caub09"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=5492 --field-trial-handle=2144,i,11258294382138793620,3253914066803892311,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=6072 --field-trial-handle=2144,i,11258294382138793620,3253914066803892311,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://drop.dor.state.ma.us/human.aspx?OrgID=2763&Arg12=message&Arg06=180947434&Arg08=6a6gy6fi61caub09
https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/frameworksupport.min_oadrnc13magb009k4d20lg2.js
152.199.21.175
https://developers.google.com/recaptcha/docs/faq#localhost_support
unknown
https://wieistmeineip.de
unknown
https://mercadoshops.com.co
unknown
https://gliadomain.com
unknown
https://poalim.xyz
unknown
https://mercadolivre.com
unknown
https://reshim.org
unknown
https://nourishingpursuits.com
unknown
https://drop.dor.state.ma.us/js/dist/runtime.rbundle.js?v=13
170.63.114.195
https://drop.dor.state.ma.us/templates/en/pendoSnippet.js?v=13
170.63.114.195
https://medonet.pl
unknown
https://unotv.com
unknown
https://drop.dor.state.ma.us/fonts/open-sans-v13-cyrillic_latin_greek-700.woff2
170.63.114.195
https://mercadoshops.com.br
unknown
https://joyreactor.cc
unknown
https://drop.dor.state.ma.us/TSPD/08d5297073ab200030bd1d24201d6ce7b34e3839c15092c072197bf94be93c5c68a0af401d5bc91f?type=12
170.63.114.195
https://zdrowietvn.pl
unknown
https://johndeere.com
unknown
https://songstats.com
unknown
https://baomoi.com
unknown
https://supereva.it
unknown
https://elfinancierocr.com
unknown
https://aadcdn.msftauth.net/shared/1.0/content/js/BssoInterrupt_Core_JQnUxWSvwsd9FrpspQmznw2.js
152.199.21.175
https://bolasport.com
unknown
https://rws1nvtvt.com
unknown
https://desimartini.com
unknown
https://hearty.app
unknown
https://support.google.com/recaptcha/#6175971
unknown
https://hearty.gift
unknown
https://mercadoshops.com
unknown
https://heartymail.com
unknown
https://nlc.hu
unknown
https://p106.net
unknown
https://drop.dor.state.ma.us/TSPD/08d5297073ab2800710eadf25eb900357bc3f1da4e33e43e08ccdef2eef982d0fed113d75cf25d33cc0c271377745896?type=13
170.63.114.195
https://drop.dor.state.ma.us/images/keyboard.png
170.63.114.195
https://radio2.be
unknown
https://drop.dor.state.ma.us/fonts/open-sans-v13-cyrillic_latin_greek-regular.woff2
170.63.114.195
https://finn.no
unknown
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg06=180947434&arg08=6a6gy6fi61caub09&arg12=message&language=pl&OrgID=2763
https://hc1.com
unknown
https://kompas.tv
unknown
https://mystudentdashboard.com
unknown
https://songshare.com
unknown
https://smaker.pl
unknown
https://support.google.com/recaptcha
unknown
https://mercadopago.com.mx
unknown
https://drop.dor.state.ma.us/templates/bootstrap_custom.css?v=13
170.63.114.195
https://p24.hu
unknown
https://talkdeskqaid.com
unknown
https://24.hu
unknown
https://mercadopago.com.pe
unknown
https://cardsayings.net
unknown
https://aadcdn.msftauth.net/ests/2.1/content/cdnbundles/watson.min_q5ptmu8aniymd4ftuqdkda2.js
152.199.21.175
https://text.com
unknown
https://www.google.com/recaptcha/api2/webworker.js?hl=en&v=i7X0JrnYWy9Y_5EYdoFM79kV
142.250.184.228
https://drop.dor.state.ma.us/fonts/open-sans-v13-cyrillic_latin_greek-700.woff
170.63.114.195
https://mightytext.net
unknown
https://pudelek.pl
unknown
https://hazipatika.com
unknown
https://joyreactor.com
unknown
https://cookreactor.com
unknown
https://wildixin.com
unknown
https://drop.dor.state.ma.us/fonts/open-sans-v13-cyrillic_latin_greek-regular.woff
170.63.114.195
https://eworkbookcloud.com
unknown
https://cognitiveai.ru
unknown
https://github.com/douglascrockford/JSON-js
unknown
https://nacion.com
unknown
https://chennien.com
unknown
https://drimer.travel
unknown
https://drop.dor.state.ma.us/js/dist/jquery.min.js?v=13
170.63.114.195
https://drop.dor.state.ma.us/js/dist/vendors.rbundle.js?v=13
170.63.114.195
https://deccoria.pl
unknown
https://developers.google.com/recaptcha/docs/faq#my-computer-or-network-may-be-sending-automated-que
unknown
https://mercadopago.cl
unknown
https://aadcdn.msftauth.net/shared/1.0/content/js/oneDs_f2e0f4a029670f10d892.js
152.199.21.175
https://talkdeskstgid.com
unknown
https://login.microsoftonline.com/3e861d16-48b7-4a0e-9806-8c04d81b7b2a/saml2?sso_reload=true
https://naukri.com
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://interia.pl
unknown
https://bonvivir.com
unknown
https://carcostadvisor.be
unknown
https://aadcdn.msftauthimages.net/dbd5a2dd-c7zlfkglp1ilaaaboagc8uwptdihicybqmkqmw7vvm8/logintenantbranding/0/illustration?ts=636371074390964457
13.107.246.57
https://salemovetravel.com
unknown
https://sapo.io
unknown
https://wpext.pl
unknown
https://welt.de
unknown
https://poalim.site
unknown
https://drop.dor.state.ma.us/images/drag-drop-bg.svg
170.63.114.195
https://drimer.io
unknown
https://github.com/twbs/bootstrap/blob/master/LICENSE)
unknown
https://infoedgeindia.com
unknown
https://blackrockadvisorelite.it
unknown
https://cognitive-ai.ru
unknown
https://drop.dor.state.ma.us/images/favicon.ico
170.63.114.195
https://cafemedia.com
unknown
https://graziadaily.co.uk
unknown
https://thirdspace.org.au
unknown
https://drop.dor.state.ma.us/TSPD/08d5297073ab200030bd1d24201d6ce7b34e3839c15092c072197bf94be93c5c68a0af401d5bc91f?type=8
170.63.114.195
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
sni1gl.wpc.omegacdn.net
152.199.21.175
s-part-0017.t-0009.t-msedge.net
13.107.246.45
www.google.com
108.177.122.106
drop.dor.state.ma.us
170.63.114.195
fp2e7a.wpc.phicdn.net
192.229.221.95
s-part-0032.t-0009.t-msedge.net
13.107.246.60
s-part-0029.t-0009.t-msedge.net
13.107.246.57
autologon.microsoftazuread-sso.com
20.190.159.4
identity.nel.measure.office.net
unknown
aadcdn.msftauth.net
unknown
login.microsoftonline.com
unknown
aadcdn.msftauthimages.net
unknown
There are 2 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
192.168.2.4
unknown
unknown
13.107.246.60
s-part-0032.t-0009.t-msedge.net
United States
192.168.2.5
unknown
unknown
192.168.2.22
unknown
unknown
142.250.184.228
unknown
United States
142.250.9.99
unknown
United States
170.63.114.195
drop.dor.state.ma.us
United States
13.107.246.57
s-part-0029.t-0009.t-msedge.net
United States
108.177.122.106
www.google.com
United States
239.255.255.250
unknown
Reserved
142.250.186.164
unknown
United States
152.199.21.175
sni1gl.wpc.omegacdn.net
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://drop.dor.state.ma.us/human.aspx?OrgID=2763&Arg12=message&Arg06=180947434&Arg08=6a6gy6fi61caub09
https://drop.dor.state.ma.us/human.aspx?OrgID=2763&Arg12=message&Arg06=180947434&Arg08=6a6gy6fi61caub09
https://drop.dor.state.ma.us/human.aspx?OrgID=2763&Arg12=message&Arg06=180947434&Arg08=6a6gy6fi61caub09
https://drop.dor.state.ma.us/human.aspx?OrgID=2763&Arg12=message&Arg06=180947434&Arg08=6a6gy6fi61caub09
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg12=passchangerequest
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg12=passchangerequest
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg12=passchangerequest
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg12=passchangerequest
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg12=passchangerequest
https://login.microsoftonline.com/3e861d16-48b7-4a0e-9806-8c04d81b7b2a/saml2
https://login.microsoftonline.com/3e861d16-48b7-4a0e-9806-8c04d81b7b2a/saml2
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg12=infotech
https://login.microsoftonline.com/3e861d16-48b7-4a0e-9806-8c04d81b7b2a/saml2?sso_reload=true
https://login.microsoftonline.com/3e861d16-48b7-4a0e-9806-8c04d81b7b2a/saml2?sso_reload=true
https://login.microsoftonline.com/3e861d16-48b7-4a0e-9806-8c04d81b7b2a/saml2?sso_reload=true
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg06=180947434&arg08=6a6gy6fi61caub09&arg12=message&language=zh_tw&OrgID=2763
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg06=180947434&arg08=6a6gy6fi61caub09&arg12=message&language=zh_tw&OrgID=2763
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg06=180947434&arg08=6a6gy6fi61caub09&arg12=message&language=zh_cn&OrgID=2763
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg06=180947434&arg08=6a6gy6fi61caub09&arg12=message&language=ja&OrgID=2763
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg06=180947434&arg08=6a6gy6fi61caub09&arg12=message&language=pl&OrgID=2763
https://drop.dor.state.ma.us/human.aspx?r=5754865989&arg06=180947434&arg08=6a6gy6fi61caub09&arg12=message&language=pl&OrgID=2763
There are 11 hidden doms, click here to show them.