IOC Report
http://www.hvacplus.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 16:26:51 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 16:26:51 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 16:26:51 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 16:26:51 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Aug 29 16:26:51 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 193
ASCII text
dropped
Chrome Cache Entry: 199
ASCII text
dropped
Chrome Cache Entry: 202
PNG image data, 73 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 204
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 343x35, components 3
dropped
Chrome Cache Entry: 209
ASCII text
downloaded
Chrome Cache Entry: 210
ASCII text
downloaded
Chrome Cache Entry: 211
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 212
PNG image data, 73 x 48, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 213
JPEG image data, JFIF standard 1.02, aspect ratio, density 100x100, segment length 16, baseline, precision 8, 214x167, components 3
dropped
Chrome Cache Entry: 214
ASCII text
downloaded
Chrome Cache Entry: 215
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 216
Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 217
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 218
ASCII text, with very long lines (540)
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 221
ASCII text
downloaded
Chrome Cache Entry: 222
ASCII text
dropped
Chrome Cache Entry: 223
ASCII text
downloaded
Chrome Cache Entry: 225
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 226
GIF image data, version 89a, 20 x 21
downloaded
Chrome Cache Entry: 228
ASCII text, with very long lines (32036)
dropped
Chrome Cache Entry: 229
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 231
assembler source, ASCII text
downloaded
Chrome Cache Entry: 232
HTML document, ISO-8859 text, with very long lines (13773)
downloaded
Chrome Cache Entry: 236
ASCII text, with very long lines (32038)
dropped
Chrome Cache Entry: 237
ASCII text
dropped
Chrome Cache Entry: 238
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 226x102, components 3
dropped
Chrome Cache Entry: 239
JSON data
dropped
Chrome Cache Entry: 242
ASCII text
downloaded
Chrome Cache Entry: 244
ASCII text
downloaded
Chrome Cache Entry: 245
ASCII text
downloaded
Chrome Cache Entry: 247
ASCII text
downloaded
Chrome Cache Entry: 248
PNG image data, 73 x 48, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 251
ASCII text, with very long lines (1305)
dropped
Chrome Cache Entry: 255
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 256
PNG image data, 73 x 48, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 257
ASCII text
downloaded
Chrome Cache Entry: 258
ASCII text
dropped
Chrome Cache Entry: 259
data
dropped
Chrome Cache Entry: 260
ASCII text, with very long lines (12080), with no line terminators
downloaded
Chrome Cache Entry: 263
ASCII text, with very long lines (32003)
dropped
Chrome Cache Entry: 267
ASCII text
downloaded
Chrome Cache Entry: 268
ASCII text
downloaded
Chrome Cache Entry: 269
Algol 68 source, ASCII text, with very long lines (479)
downloaded
Chrome Cache Entry: 270
Web Open Font Format (Version 2), TrueType, length 66624, version 4.262
downloaded
Chrome Cache Entry: 273
ASCII text, with very long lines (27303)
downloaded
Chrome Cache Entry: 275
ASCII text
dropped
There are 44 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://www.hvacplus.com
https://www.hvacplus.com/

Domains

Name
IP
Malicious
app.purechat.com
13.32.121.25
server.iad.liveperson.net
162.252.72.215
www.google.com
142.250.186.68
hvacplus.com
209.87.159.219
api-prod.eba-bnrzyg4w.us-east-2.elasticbeanstalk.com
3.140.97.7
www.hvacplus.com
unknown
hits-cache.com
unknown
widgetapi.purechat.com
unknown
a.mouseflow.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
142.250.186.78
unknown
United States
172.217.16.136
unknown
United States
34.104.35.123
unknown
United States
1.1.1.1
unknown
Australia
142.250.186.163
unknown
United States
192.168.2.17
unknown
unknown
3.15.255.72
unknown
United States
216.58.206.42
unknown
United States
162.252.72.215
server.iad.liveperson.net
United States
142.251.173.84
unknown
United States
216.58.206.46
unknown
United States
239.255.255.250
unknown
Reserved
3.140.97.7
api-prod.eba-bnrzyg4w.us-east-2.elasticbeanstalk.com
United States
13.32.121.25
app.purechat.com
United States
142.250.184.227
unknown
United States
209.87.159.219
hvacplus.com
United States
142.250.186.42
unknown
United States
142.250.186.136
unknown
United States
142.250.186.99
unknown
United States
65.9.86.59
unknown
United States
There are 11 hidden IPs, click here to show them.