IOC Report
https://tracking.groovesell.com:443/t/1c336171327d66d10a047ef8cbabb880

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:21:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:21:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:21:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:21:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Sep 30 12:21:41 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 191
ASCII text, with very long lines (58391)
dropped
Chrome Cache Entry: 198
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 199
Web Open Font Format (Version 2), TrueType, length 20848, version 1.0
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (1879)
downloaded
Chrome Cache Entry: 201
JSON data
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (65472)
downloaded
Chrome Cache Entry: 208
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 209
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 210
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 211
HTML document, ASCII text, with very long lines (13127)
downloaded
Chrome Cache Entry: 212
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 216
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 217
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (58391)
downloaded
Chrome Cache Entry: 220
JSON data
downloaded
Chrome Cache Entry: 221
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 222
ASCII text, with very long lines (21215)
downloaded
Chrome Cache Entry: 223
Unicode text, UTF-8 text, with very long lines (65533), with no line terminators
downloaded
Chrome Cache Entry: 224
Web Open Font Format (Version 2), TrueType, length 20920, version 1.0
downloaded
Chrome Cache Entry: 225
JSON data
downloaded
Chrome Cache Entry: 227
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 228
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 229
HTML document, Unicode text, UTF-8 text, with very long lines (15458)
downloaded
Chrome Cache Entry: 232
JSON data
downloaded
Chrome Cache Entry: 236
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 238
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 239
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 240
Unicode text, UTF-8 text, with very long lines (15336)
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (390), with no line terminators
downloaded
Chrome Cache Entry: 245
MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 248
HTML document, ASCII text, with very long lines (1559)
downloaded
Chrome Cache Entry: 256
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 257
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 258
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 260
Unicode text, UTF-8 text, with very long lines (34989)
dropped
Chrome Cache Entry: 263
ASCII text, with very long lines (65476)
downloaded
Chrome Cache Entry: 265
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 266
JSON data
downloaded
Chrome Cache Entry: 267
JSON data
dropped
Chrome Cache Entry: 268
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 273
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 274
Web Open Font Format, TrueType, length 35241, version 0.0
downloaded
Chrome Cache Entry: 275
Unicode text, UTF-8 text, with very long lines (43034), with no line terminators
downloaded
Chrome Cache Entry: 276
Unicode text, UTF-8 text, with very long lines (21099)
dropped
Chrome Cache Entry: 277
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 279
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 280
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 282
Unicode text, UTF-8 text, with very long lines (24974)
downloaded
Chrome Cache Entry: 283
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 284
HTML document, ASCII text, with very long lines (736)
downloaded
Chrome Cache Entry: 286
JSON data
dropped
Chrome Cache Entry: 287
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 289
JSON data
downloaded
Chrome Cache Entry: 291
HTML document, ASCII text, with very long lines (13103)
downloaded
Chrome Cache Entry: 292
JSON data
downloaded
Chrome Cache Entry: 293
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 296
Unicode text, UTF-8 text, with very long lines (34190)
downloaded
Chrome Cache Entry: 297
JSON data
dropped
Chrome Cache Entry: 299
JSON data
downloaded
Chrome Cache Entry: 300
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (1650), with no line terminators
downloaded
Chrome Cache Entry: 305
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 306
ASCII text, with very long lines (1879)
downloaded
Chrome Cache Entry: 307
ASCII text
dropped
Chrome Cache Entry: 309
ASCII text, with very long lines (45764), with no line terminators
dropped
Chrome Cache Entry: 311
JSON data
dropped
Chrome Cache Entry: 313
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 315
ASCII text
dropped
Chrome Cache Entry: 318
HTML document, ASCII text
downloaded
Chrome Cache Entry: 319
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 320
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 322
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 323
PNG image data, 48 x 48, 4-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 324
HTML document, ASCII text, with very long lines (28875), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 325
ASCII text, with very long lines (1879)
dropped
Chrome Cache Entry: 326
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 327
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 328
JSON data
downloaded
Chrome Cache Entry: 329
Web Open Font Format (Version 2), TrueType, length 18128, version 1.0
downloaded
Chrome Cache Entry: 330
ASCII text, with very long lines (6995), with no line terminators
dropped
Chrome Cache Entry: 334
ASCII text, with very long lines (4176)
dropped
Chrome Cache Entry: 335
ASCII text, with very long lines (32003)
downloaded
Chrome Cache Entry: 336
JSON data
downloaded
Chrome Cache Entry: 337
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 338
ASCII text, with very long lines (390), with no line terminators
dropped
Chrome Cache Entry: 339
Unicode text, UTF-8 text, with very long lines (26057)
downloaded
Chrome Cache Entry: 341
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 342
JSON data
downloaded
Chrome Cache Entry: 343
JSON data
dropped
Chrome Cache Entry: 346
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 348
Web Open Font Format (Version 2), TrueType, length 26336, version 1.0
downloaded
Chrome Cache Entry: 349
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 350
JSON data
downloaded
Chrome Cache Entry: 352
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 353
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 354
ASCII text, with very long lines (65450)
dropped
Chrome Cache Entry: 355
JSON data
dropped
Chrome Cache Entry: 358
HTML document, Unicode text, UTF-8 text, with very long lines (22787)
downloaded
There are 95 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://tracking.groovesell.com:443/t/1c336171327d66d10a047ef8cbabb880
malicious
https://mediamastrspro.com/?caf=1&bpt=345&query=Sail+Boat&afdToken=ChMI1MLVweHqiAMVkoP9Bx0BPhBpEmcBlLqpj_MDC9wEf4D8o7u63G2bykP-fHeRtM2HXHAnIfXjJgb0kiEinXnFz4Rd0S9ZoQ1DuhfO2rXWWeezOGsgYEl4Oxlzyu7j9M1nVOHC8g4qqGhiRrCszot_Heo-dA3j7SGqREsR&pcsa=false&nb=0&rurl=https%3A%2F%2Ftracking.groovesell.com%2F&nm=13&nx=335&ny=58&is=700x480&clkt=132
malicious
https://mediamastrspro.com/6LoLPq0qmCMx283MeYm0Fwd0yFrj0rnfJ11
malicious
https://mediamastrspro.com/?caf=1&bpt=345&query=Artificial+General+Intelligence+Training&afdToken=ChMIjqC-seHqiAMVZ4T9Bx11mThvEmwBlLqpj101jP7DXrRiLphj_Lf-K6Pe75Kjk8qI4vnFJUUVtbh3BWLVan3Aa2o_5rmc9smQm0vQA0jY9WATLHaveY_CZpxzjkGil-rkLjfHAC1aKKdbCSa0QpSJ-H3CwikE6jeqmHB4UaIZTrY&pcsa=false&nb=0&rurl=https%3A%2F%2Ftracking.groovesell.com%2F&nm=30&nx=349&ny=72&is=700x480&clkt=205
malicious
https://www.namecheap.com/domains/registration/results/?domain=mediamastrspro.com
malicious
https://tracking.groovesell.com/t/1c336171327d66d10a047ef8cbabb880

Domains

Name
IP
Malicious
mediamastrspro.com
unknown
malicious
d2bhsbhm5ibqfe.cloudfront.net
52.222.232.4
d15bldec5peplf.cloudfront.net
18.66.112.85
d3n2zv395ut2nb.cloudfront.net
18.66.147.57
syndicatedsearch.goog
142.250.185.174
js-agent.newrelic.com
162.247.243.39
parking3.parklogic.com
45.79.244.209
d35me0b6y0ihk6.cloudfront.net
52.222.214.87
fastly-tls12-bam-cell.nr-data.net
162.247.243.30
pagestates-tracking.crazyegg.com
18.245.175.49
d1dijnkjnmzy2z.cloudfront.net
18.173.206.133
googleads.g.doubleclick.net
142.250.185.66
77980.bodis.com
199.59.243.227
assets-tracking.crazyegg.com
18.244.28.44
www.google.com
142.250.186.164
d.impactradius-event.com
35.186.249.72
d2zeu5rztnogwi.cloudfront.net
18.245.86.125
googlehosted.l.googleusercontent.com
142.250.186.33
cdn.cookielaw.org
104.18.86.42
geolocation.onetrust.com
104.18.32.137
tracking.groovesell.com
104.17.142.116
tracking.crazyegg.com
52.213.31.162
www.namecheap.com
unknown
rtb.namecheapapi.com
unknown
script.crazyegg.com
unknown
domains-ws.revved.com
unknown
cdn.engagement.ai
unknown
embed.typeform.com
unknown
bam-cell.nr-data.net
unknown
domains.revved.com
unknown
static.nc-img.com
unknown
afs.googleusercontent.com
unknown
chat.engagement.ai
unknown
There are 23 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.16.99.56
unknown
United States
142.250.185.100
unknown
United States
104.18.172.57
unknown
United States
52.213.31.162
tracking.crazyegg.com
United States
142.250.185.104
unknown
United States
104.18.32.137
geolocation.onetrust.com
United States
18.244.28.44
assets-tracking.crazyegg.com
United States
142.250.184.225
unknown
United States
45.79.244.209
parking3.parklogic.com
United States
142.250.186.33
googlehosted.l.googleusercontent.com
United States
142.250.185.66
googleads.g.doubleclick.net
United States
104.18.87.42
unknown
United States
1.1.1.1
unknown
Australia
34.104.35.123
unknown
United States
199.59.243.227
77980.bodis.com
United States
74.125.71.84
unknown
United States
142.250.185.232
unknown
United States
104.19.148.8
unknown
United States
142.250.185.238
unknown
United States
18.173.206.133
d1dijnkjnmzy2z.cloudfront.net
United States
18.66.112.85
d15bldec5peplf.cloudfront.net
United States
52.222.214.87
d35me0b6y0ihk6.cloudfront.net
United States
239.255.255.250
unknown
Reserved
172.217.23.100
unknown
United States
172.217.16.194
unknown
United States
52.222.232.4
d2bhsbhm5ibqfe.cloudfront.net
United States
216.58.212.164
unknown
United States
18.245.86.82
unknown
United States
18.245.175.49
pagestates-tracking.crazyegg.com
United States
216.58.206.78
unknown
United States
192.168.2.16
unknown
unknown
142.250.185.202
unknown
United States
142.250.181.238
unknown
United States
52.222.214.10
unknown
United States
162.247.243.30
fastly-tls12-bam-cell.nr-data.net
United States
52.208.177.25
unknown
United States
18.66.147.57
d3n2zv395ut2nb.cloudfront.net
United States
162.247.243.39
js-agent.newrelic.com
United States
142.250.74.195
unknown
United States
18.245.86.125
d2zeu5rztnogwi.cloudfront.net
United States
104.17.142.116
tracking.groovesell.com
United States
18.239.18.125
unknown
United States
104.17.141.116
unknown
United States
142.250.186.163
unknown
United States
162.247.241.2
unknown
United States
104.19.147.8
unknown
United States
216.58.206.68
unknown
United States
142.250.185.174
syndicatedsearch.goog
United States
35.186.249.72
d.impactradius-event.com
United States
52.222.232.30
unknown
United States
142.250.186.164
www.google.com
United States
104.18.86.42
cdn.cookielaw.org
United States
104.18.22.177
unknown
United States
There are 43 hidden IPs, click here to show them.