IOC Report
https://news.claroty.com/e3t/Ctc/OR+113/d2n-4L04/VVPy5P46C_3pW8Pz7_V3LxM13W7TctdS5ltnG0N3hBC6F3lYMRW7Y8-PT6lZ3p8VDPSWB2hkr0xW1jSCJz5Tx0CbW4k0Gdy84cgR5W75xzbh3JYxzyN3dsPjKyk4Y1W4hFjjr44kS1nW2D8hxk5DxH7vW3g6xkn2qrb3vW2SpQp81dtr0GW7r7Q7L2FZ5vJW152Dy06dcx6xVX2VR38JqC9HW7zbbH-4kxdWFW4cdkc03qH46PW6zkfpv6b

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 14:25:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 14:25:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 14:25:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Sep 27 14:25:05 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 208
ASCII text, with very long lines (7370), with no line terminators
downloaded
Chrome Cache Entry: 209
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 211
HTML document, ASCII text, with very long lines (436), with no line terminators
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 213
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 1600x900, components 3
dropped
Chrome Cache Entry: 214
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 215
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 1600x900, components 3
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (18798)
downloaded
Chrome Cache Entry: 219
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 1600x900, components 3
downloaded
Chrome Cache Entry: 220
ASCII text, with very long lines (1382)
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (4345)
downloaded
Chrome Cache Entry: 225
JSON data
dropped
Chrome Cache Entry: 226
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 1600x900, components 3
dropped
Chrome Cache Entry: 228
PNG image data, 272 x 90, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 229
PNG image data, 16 x 16, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 236
ASCII text, with very long lines (4014)
dropped
Chrome Cache Entry: 237
ASCII text, with very long lines (4186), with no line terminators
downloaded
Chrome Cache Entry: 238
HTML document, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 239
ASCII text
downloaded
Chrome Cache Entry: 240
ASCII text
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (670)
dropped
Chrome Cache Entry: 243
ASCII text, with very long lines (4816)
downloaded
Chrome Cache Entry: 244
ASCII text, with very long lines (4345)
dropped
Chrome Cache Entry: 245
PNG image data, 300 x 600, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 246
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 200x200, components 3
dropped
Chrome Cache Entry: 247
ASCII text, with very long lines (3916)
dropped
Chrome Cache Entry: 248
ASCII text, with very long lines (20274)
downloaded
Chrome Cache Entry: 252
HTML document, ASCII text, with very long lines (877), with no line terminators
downloaded
Chrome Cache Entry: 253
HTML document, ASCII text
downloaded
Chrome Cache Entry: 254
PNG image data, 940 x 665, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 256
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 1600x900, components 3
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (2353)
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (3115)
dropped
Chrome Cache Entry: 259
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 261
ASCII text, with very long lines (2015)
downloaded
Chrome Cache Entry: 262
JSON data
downloaded
Chrome Cache Entry: 263
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 264
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 1920x1440, components 3
dropped
Chrome Cache Entry: 266
HTML document, ASCII text, with very long lines (8933), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 267
ASCII text, with very long lines (2946)
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (13479)
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (53605)
dropped
Chrome Cache Entry: 270
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 1600x900, components 3
dropped
Chrome Cache Entry: 271
HTML document, ASCII text, with very long lines (877), with no line terminators
downloaded
Chrome Cache Entry: 273
Web Open Font Format (Version 2), TrueType, length 18536, version 1.0
downloaded
Chrome Cache Entry: 274
ASCII text, with very long lines (3557)
dropped
Chrome Cache Entry: 275
ASCII text, with very long lines (37284), with no line terminators
downloaded
Chrome Cache Entry: 277
ASCII text, with very long lines (15752)
downloaded
Chrome Cache Entry: 279
ASCII text
downloaded
Chrome Cache Entry: 280
ASCII text, with very long lines (8098), with no line terminators
downloaded
Chrome Cache Entry: 281
ASCII text
downloaded
Chrome Cache Entry: 283
Web Open Font Format (Version 2), TrueType, length 48236, version 1.0
downloaded
Chrome Cache Entry: 284
ASCII text, with very long lines (832)
dropped
Chrome Cache Entry: 285
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 1600x900, components 3
downloaded
Chrome Cache Entry: 289
Web Open Font Format (Version 2), TrueType, length 18588, version 1.0
downloaded
Chrome Cache Entry: 290
Web Open Font Format, TrueType, length 24864, version 0.0
downloaded
Chrome Cache Entry: 292
C++ source, ASCII text, with very long lines (2873)
downloaded
Chrome Cache Entry: 293
ASCII text, with very long lines (2215)
downloaded
Chrome Cache Entry: 295
HTML document, Unicode text, UTF-8 text, with very long lines (1183)
downloaded
Chrome Cache Entry: 296
PNG image data, 48 x 48, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 297
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (378)
downloaded
Chrome Cache Entry: 299
PNG image data, 48 x 48, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 303
ASCII text, with very long lines (2079)
dropped
Chrome Cache Entry: 304
GIF image data, version 89a, 6 x 5
dropped
Chrome Cache Entry: 306
Web Open Font Format (Version 2), TrueType, length 7884, version 1.0
downloaded
Chrome Cache Entry: 307
ASCII text, with very long lines (7930), with no line terminators
dropped
Chrome Cache Entry: 309
ASCII text, with very long lines (11256), with no line terminators
downloaded
Chrome Cache Entry: 311
ASCII text, with very long lines (786)
dropped
Chrome Cache Entry: 313
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 464x128, components 3
downloaded
Chrome Cache Entry: 314
PNG image data, 272 x 90, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 315
Web Open Font Format (Version 2), TrueType, length 18596, version 1.0
downloaded
Chrome Cache Entry: 317
ASCII text, with very long lines (20398)
downloaded
Chrome Cache Entry: 318
C++ source, ASCII text, with very long lines (2037)
downloaded
Chrome Cache Entry: 319
ASCII text, with very long lines (4014)
downloaded
Chrome Cache Entry: 320
HTML document, ASCII text, with very long lines (829), with no line terminators
downloaded
Chrome Cache Entry: 322
ASCII text, with very long lines (3683), with no line terminators
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (1055)
downloaded
Chrome Cache Entry: 324
PNG image data, 928 x 90, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 326
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Google], baseline, precision 8, 728x90, components 3
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (52915)
dropped
Chrome Cache Entry: 329
ASCII text, with very long lines (57765)
downloaded
Chrome Cache Entry: 330
HTML document, ASCII text, with very long lines (2008)
downloaded
Chrome Cache Entry: 331
ASCII text, with very long lines (2090)
dropped
Chrome Cache Entry: 335
Web Open Font Format (Version 2), TrueType, length 38268, version 1.0
downloaded
Chrome Cache Entry: 337
ASCII text, with very long lines (566)
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (1994)
downloaded
There are 83 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://news.claroty.com/e3t/Ctc/OR+113/d2n-4L04/VVPy5P46C_3pW8Pz7_V3LxM13W7TctdS5ltnG0N3hBC6F3lYMRW7Y8-PT6lZ3p8VDPSWB2hkr0xW1jSCJz5Tx0CbW4k0Gdy84cgR5W75xzbh3JYxzyN3dsPjKyk4Y1W4hFjjr44kS1nW2D8hxk5DxH7vW3g6xkn2qrb3vW2SpQp81dtr0GW7r7Q7L2FZ5vJW152Dy06dcx6xVX2VR38JqC9HW7zbbH-4kxdWFW4cdkc03qH46PW6zkfpv6b7TyqW7xXcWC8200CKW3sff8w94k8jJN2NtC1BKs5HkN9kB4jVFTr3KW2Pl4Gd5kZ-8zW4psP_Z13trc2W5ggw2W7jyjZZW2Sq8vT2lr77MN29f9ChSYrrKW19xDX_1nRws8W8l47FX8MZS30f1xn1dn04
https://cybersecuritynews.com/critical-unauthenticated-rce-flaw/?utm_medium=email&_hsenc=p2ANqtz-_cEbv13FOKqZu77uVCZMI5Nikqw7ZIt3E4ePE3WTjgezuJ3dDluqV2zs5rzQ72zzo5LvbUfg9WOnqk-LcGAbluHbCVmMiBTvP7OEAXxTo4zKEhses&_hsmi=326603005&utm_content=326603005&utm_source=hs_email

Domains

Name
IP
Malicious
star-mini.c10r.facebook.com
157.240.0.35
stats.wp.com
192.0.76.3
secure.gravatar.com
192.0.73.2
a.nel.cloudflare.com
35.190.80.1
group29.sites.hscoscdn20.net
199.60.103.2
scontent.xx.fbcdn.net
157.240.0.6
cybersecuritynews.com
188.114.97.3
googleads.g.doubleclick.net
172.217.16.194
www3.l.google.com
142.250.186.142
pixel.wp.com
192.0.76.3
cdnjs.cloudflare.com
104.17.25.14
photos-ugc.l.googleusercontent.com
142.250.186.97
www.google.com
142.250.184.228
googlehosted.l.googleusercontent.com
172.217.18.1
www.facebook.com
unknown
fundingchoicesmessages.google.com
unknown
static.xx.fbcdn.net
unknown
news.claroty.com
unknown
1.bp.blogspot.com
unknown
blogger.googleusercontent.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
199.60.103.2
group29.sites.hscoscdn20.net
Canada
192.168.2.16
unknown
unknown
216.58.206.33
unknown
United States
142.250.181.234
unknown
United States
192.168.2.6
unknown
unknown
157.240.0.6
scontent.xx.fbcdn.net
United States
172.217.23.99
unknown
United States
142.250.185.163
unknown
United States
142.250.185.162
unknown
United States
142.250.184.227
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
142.250.184.228
www.google.com
United States
216.58.212.174
unknown
United States
172.217.18.110
unknown
United States
142.250.186.97
photos-ugc.l.googleusercontent.com
United States
142.250.186.99
unknown
United States
142.250.185.65
unknown
United States
142.250.186.35
unknown
United States
216.58.212.136
unknown
United States
142.250.186.34
unknown
United States
172.217.16.202
unknown
United States
34.104.35.123
unknown
United States
1.1.1.1
unknown
Australia
142.250.186.163
unknown
United States
157.240.0.35
star-mini.c10r.facebook.com
United States
192.0.76.3
stats.wp.com
United States
192.0.73.2
secure.gravatar.com
United States
142.250.185.238
unknown
United States
172.217.18.1
googlehosted.l.googleusercontent.com
United States
157.240.251.9
unknown
United States
142.250.185.170
unknown
United States
142.250.186.129
unknown
United States
64.233.167.84
unknown
United States
239.255.255.250
unknown
Reserved
188.114.97.3
cybersecuritynews.com
European Union
142.250.185.130
unknown
United States
172.217.23.100
unknown
United States
142.250.186.142
www3.l.google.com
United States
172.217.16.194
googleads.g.doubleclick.net
United States
142.250.184.238
unknown
United States
172.217.16.193
unknown
United States
142.250.184.232
unknown
United States
104.17.25.14
cdnjs.cloudflare.com
United States
142.250.185.97
unknown
United States
There are 34 hidden IPs, click here to show them.