IOC Report
https://disk.yandex.ru/d/5_kO6YxiUMQlTA

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 09:36:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 09:36:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 09:36:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 09:36:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Aug 30 09:36:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 116
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 119
HTML document, ASCII text, with very long lines (1180), with no line terminators
downloaded
Chrome Cache Entry: 121
HTML document, Unicode text, UTF-8 text, with very long lines (8278)
downloaded
Chrome Cache Entry: 122
JPEG image data, JFIF standard 1.01, resolution (DPCM), density 37x37, segment length 16, progressive, precision 8, 200x200, components 3
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (8813)
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (65491)
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (44546)
dropped
Chrome Cache Entry: 131
Web Open Font Format (Version 2), TrueType, length 26004, version 1.0
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (65496)
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (65491)
downloaded
Chrome Cache Entry: 136
RIFF (little-endian) data, Web/P image, VP8 encoding, 150x150, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 139
RIFF (little-endian) data, Web/P image, VP8 encoding, 200x200, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (1870)
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (65493)
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 145
Web Open Font Format (Version 2), TrueType, length 43112, version 1.0
downloaded
Chrome Cache Entry: 147
RIFF (little-endian) data, Web/P image, VP8 encoding, 267x150, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 148
RIFF (little-endian) data, Web/P image, VP8 encoding, 100x100, Suserng: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 150
Web Open Font Format (Version 2), TrueType, length 45100, version 1.0
downloaded
Chrome Cache Entry: 151
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 267x150, components 3
dropped
Chrome Cache Entry: 155
ASCII text, with very long lines (24511)
dropped
Chrome Cache Entry: 156
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (29299)
downloaded
Chrome Cache Entry: 158
Web Open Font Format (Version 2), TrueType, length 45284, version 1.0
downloaded
Chrome Cache Entry: 159
HTML document, ASCII text, with very long lines (1198), with no line terminators
downloaded
Chrome Cache Entry: 160
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (593)
downloaded
Chrome Cache Entry: 166
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 167
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 168
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 150x150, components 3
dropped
Chrome Cache Entry: 169
Unicode text, UTF-8 (with BOM) text, with very long lines (567)
downloaded
Chrome Cache Entry: 170
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 172
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (64781), with no line terminators
dropped
Chrome Cache Entry: 174
ASCII text, with very long lines (65493)
dropped
Chrome Cache Entry: 175
Unicode text, UTF-8 text, with very long lines (62084)
downloaded
Chrome Cache Entry: 176
HTML document, ASCII text, with very long lines (23297)
downloaded
Chrome Cache Entry: 177
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 178
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 179
ASCII text, with very long lines (33703), with no line terminators
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (543)
dropped
Chrome Cache Entry: 181
HTML document, Unicode text, UTF-8 text, with very long lines (8278)
downloaded
Chrome Cache Entry: 183
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
There are 40 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://disk.yandex.ru/d/5_kO6YxiUMQlTA
https://disk.yandex.ru/d/5_kO6YxiUMQlTA.
https://disk.yandex.ru/d/5_kO6YxiUMQlTA

Domains

Name
IP
Malicious
mc.yandex.ru
87.250.250.119
cmr.bidderstack.com
185.149.242.236
dr.yandex.net
93.158.134.242
eye.targetads.io
51.250.77.168
kimberlite.io
217.199.220.43
mitdmp.whiteboxdigital.ru
81.163.17.245
sync.dsp.solta.io
217.199.220.72
sync.gonet-ads.com
23.109.14.90
shopnetic.com
23.111.37.244
x01.aidata.io
89.108.120.68
4887777841725014198888.cm.a.mts.ru
185.65.149.228
dsp.mpartner.digital
84.38.189.213
sm.rtb.mts.ru
217.66.147.38
pixel.konnektu.ru
158.160.158.98
ssp-rtb.sape.ru
193.3.184.217
an.yandex.ru
93.158.134.90
ssp.adriver.ru
195.209.109.18
www.google.com
216.58.212.132
sync.bumlam.com
31.172.81.145
yastatic.net
178.154.131.215
csp.yandex.net
87.250.250.104
favicon.yandex.net
77.88.21.36
ssp.ads.betweendigital.com
188.42.191.196
yandex.ru
77.88.55.88
acint.net
193.3.184.139
dm.hybrid.ai
37.230.131.22
s.uuidksinc.net
31.220.27.135
cr.frontend.weborama.fr
34.111.129.221
cm.tns-counter.ru
194.226.130.229
dmg.digitaltarget.ru
185.15.175.130
vma.mts.ru
217.66.147.33
euw-ice.360yield.com
108.128.77.142
balancer.bidderstack.com
162.55.144.211
ads.adfox.ru
77.88.21.179
avatars.mds.yandex.net
87.250.247.183
px.arcspire.io
35.177.4.157
disk.yandex.ru
87.250.250.50
match.new-programmatic.com
217.65.2.150
cm.a.mts.ru
185.65.149.228
sync.upravel.com
unknown
fe4459bb-cc8c-4574-864d-395c3a9b9fe2.sync.upravel.com
unknown
rtb-eu-warsaw.intent.ai
unknown
yandex-sync.rutarget.ru
unknown
nr.bidderstack.com
unknown
px.adhigh.net
unknown
mc.yandex.com
unknown
exchange.buzzoola.com
unknown
sync.dmp.otm-r.com
unknown
ads.betweendigital.com
unknown
yandex-dmp-sync.rutarget.ru
unknown
56.126.166.20.in-addr.arpa
unknown
match.360yield.com
unknown
There are 42 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
87.250.250.119
mc.yandex.ru
Russian Federation
217.199.220.43
kimberlite.io
Russian Federation
31.220.27.135
s.uuidksinc.net
Netherlands
142.250.186.110
unknown
United States
87.250.251.119
unknown
Russian Federation
195.201.194.19
unknown
Germany
162.55.144.211
balancer.bidderstack.com
United States
142.250.186.35
unknown
United States
35.177.4.157
px.arcspire.io
United States
185.149.242.236
cmr.bidderstack.com
Russian Federation
1.1.1.1
unknown
Australia
23.111.37.244
shopnetic.com
Russian Federation
195.209.109.18
ssp.adriver.ru
Russian Federation
87.250.250.104
csp.yandex.net
Russian Federation
93.158.134.90
an.yandex.ru
Russian Federation
46.4.61.163
unknown
Germany
74.125.71.84
unknown
United States
77.88.21.90
unknown
Russian Federation
87.250.250.90
unknown
Russian Federation
87.250.247.182
unknown
Russian Federation
51.250.77.168
eye.targetads.io
United Kingdom
87.250.247.183
avatars.mds.yandex.net
Russian Federation
23.109.14.90
sync.gonet-ads.com
Netherlands
239.255.255.250
unknown
Reserved
87.250.250.50
disk.yandex.ru
Russian Federation
77.88.21.119
unknown
Russian Federation
34.240.120.53
unknown
United States
77.88.55.88
yandex.ru
Russian Federation
37.230.131.22
dm.hybrid.ai
Netherlands
217.66.147.38
sm.rtb.mts.ru
Russian Federation
195.209.109.19
unknown
Russian Federation
45.9.24.193
unknown
Russian Federation
188.42.191.196
ssp.ads.betweendigital.com
Luxembourg
217.66.147.33
vma.mts.ru
Russian Federation
217.65.2.150
match.new-programmatic.com
Russian Federation
93.158.134.242
dr.yandex.net
Russian Federation
213.180.204.90
unknown
Russian Federation
84.38.189.213
dsp.mpartner.digital
Russian Federation
89.108.120.68
x01.aidata.io
Russian Federation
192.168.2.16
unknown
unknown
31.172.81.145
sync.bumlam.com
Germany
158.160.158.98
pixel.konnektu.ru
Venezuela
178.154.131.217
unknown
Russian Federation
178.154.131.215
yastatic.net
Russian Federation
138.201.65.66
unknown
Germany
188.72.109.103
unknown
Netherlands
194.226.130.229
cm.tns-counter.ru
Russian Federation
216.58.212.132
www.google.com
United States
77.88.44.55
unknown
Russian Federation
34.111.129.221
cr.frontend.weborama.fr
United States
93.158.134.36
unknown
Russian Federation
193.232.150.43
unknown
Russian Federation
185.65.149.228
4887777841725014198888.cm.a.mts.ru
Russian Federation
108.128.77.142
euw-ice.360yield.com
United States
217.199.220.72
sync.dsp.solta.io
Russian Federation
81.163.17.245
mitdmp.whiteboxdigital.ru
Russian Federation
77.88.21.179
ads.adfox.ru
Russian Federation
193.3.184.217
ssp-rtb.sape.ru
Denmark
193.3.184.139
acint.net
Denmark
77.88.21.36
favicon.yandex.net
Russian Federation
52.19.47.217
unknown
United States
136.243.42.153
unknown
Germany
185.15.175.130
dmg.digitaltarget.ru
Russian Federation
There are 53 hidden IPs, click here to show them.