IOC Report
https://catalyst.everythingdisc.com/login?ac=JXGKRF4UR6

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:12:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:12:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:12:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:12:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 14:12:17 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 117
JSON data
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (64779)
downloaded
Chrome Cache Entry: 119
ASCII text, with very long lines (351), with no line terminators
downloaded
Chrome Cache Entry: 122
Unicode text, UTF-8 text, with very long lines (65510), with no line terminators
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (65473)
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (13994), with no line terminators
downloaded
Chrome Cache Entry: 126
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 127
ASCII text, with very long lines (547)
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 129
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 130
ASCII text, with very long lines (4469)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (1165), with no line terminators
downloaded
Chrome Cache Entry: 134
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 135
ASCII text, with very long lines (550)
downloaded
Chrome Cache Entry: 137
JSON data
downloaded
Chrome Cache Entry: 138
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (13395), with no line terminators
downloaded
Chrome Cache Entry: 141
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 144
HTML document, ASCII text
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (22432)
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (8842)
downloaded
Chrome Cache Entry: 147
ASCII text
dropped
Chrome Cache Entry: 148
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (28875)
downloaded
Chrome Cache Entry: 151
JSON data
dropped
Chrome Cache Entry: 152
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (1156), with no line terminators
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (2047)
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (13201), with no line terminators
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (626)
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (472)
dropped
Chrome Cache Entry: 159
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 161
Unicode text, UTF-8 text, with very long lines (63257)
downloaded
Chrome Cache Entry: 162
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (3312), with no line terminators
downloaded
Chrome Cache Entry: 165
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 166
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 167
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (8794), with no line terminators
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (547)
downloaded
Chrome Cache Entry: 170
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (8065)
downloaded
Chrome Cache Entry: 173
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (626)
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (566)
dropped
Chrome Cache Entry: 176
ASCII text, with very long lines (1165), with no line terminators
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (6627)
dropped
Chrome Cache Entry: 178
ASCII text, with very long lines (65310)
dropped
Chrome Cache Entry: 181
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (533)
dropped
Chrome Cache Entry: 184
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 185
HTML document, ASCII text, with very long lines (821)
downloaded
Chrome Cache Entry: 186
PNG image data, 192 x 192, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 189
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 190
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 194
Unicode text, UTF-8 text, with very long lines (17874), with no line terminators
downloaded
Chrome Cache Entry: 196
C source, ASCII text, with very long lines (754)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (64779)
downloaded
Chrome Cache Entry: 199
Unicode text, UTF-8 text, with very long lines (6902)
dropped
Chrome Cache Entry: 202
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 204
JSON data
downloaded
Chrome Cache Entry: 209
JSON data
downloaded
Chrome Cache Entry: 210
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 212
ASCII text
downloaded
Chrome Cache Entry: 213
MS Windows icon resource - 3 icons, 48x48, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 216
PNG image data, 36 x 36, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 217
JSON data
downloaded
Chrome Cache Entry: 219
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 220
ASCII text, with very long lines (571)
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (6798)
downloaded
Chrome Cache Entry: 223
ASCII text, with very long lines (1165), with no line terminators
downloaded
Chrome Cache Entry: 224
Unicode text, UTF-8 text, with very long lines (65510), with no line terminators
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (13467), with no line terminators
downloaded
Chrome Cache Entry: 226
SVG Scalable Vector Graphics image
downloaded
There are 72 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://catalyst.everythingdisc.com/login?ac=JXGKRF4UR6
https://catalyst.everythingdisc.com/login?ac=JXGKRF4UR6
https://catalyst.everythingdisc.com/password?ac=JXGKRF4UR6
https://catalyst.everythingdisc.com/register?ac=JXGKRF4UR6

Domains

Name
IP
Malicious
prod-default.lb.logrocket.network
104.198.23.205
usa778.sfdc-8tgtt5.salesforce.com
18.188.247.188
clientstream-ga.launchdarkly.com
3.33.235.18
events.launchdarkly.com
44.209.96.181
la1-core1.sfdc-8tgtt5.salesforceliveagent.com
3.14.183.176
st1.edge.sfdc-yzvdd4.edge2.salesforce.com
35.158.127.51
catalyst.everythingdisc.com
104.18.33.243
api.everythingdisc.com
104.18.33.243
cdn.pendo.io
34.36.213.229
cdn.logr-ingest.com
188.114.97.3
data.pendo.io
34.107.204.85
tattle.api.osano.com
18.213.175.73
d2gt2ux04o03l1.cloudfront.net
18.245.31.100
consent.api.osano.com
18.245.60.126
www.google.com
142.250.186.68
la4-c2-ia4.ia4.r.salesforceliveagent.com
13.109.190.224
location.l.force.com
160.8.234.10
zn6xdztfrqafbgppf-wiley.siteintercept.qualtrics.com
unknown
d.la1-core1.sfdc-8tgtt5.salesforceliveagent.com
unknown
clientstream.launchdarkly.com
unknown
app.launchdarkly.com
unknown
wiley-corp.my.salesforce-sites.com
unknown
siteintercept.qualtrics.com
unknown
d.la4-c2-ia4.salesforceliveagent.com
unknown
service.force.com
unknown
cmp.osano.com
unknown
wiley.secure.force.com
unknown
wiley-corp.my.salesforce.com
unknown
r.logr-ingest.com
unknown
There are 19 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
104.17.209.240
unknown
United States
192.168.2.16
unknown
unknown
34.36.213.229
cdn.pendo.io
United States
172.64.154.13
unknown
United States
13.109.190.224
la4-c2-ia4.ia4.r.salesforceliveagent.com
United States
3.33.235.18
clientstream-ga.launchdarkly.com
United States
3.86.172.24
unknown
United States
192.168.2.20
unknown
unknown
18.245.31.35
unknown
United States
160.8.232.16
unknown
Sweden
104.198.23.205
prod-default.lb.logrocket.network
United States
44.209.96.181
events.launchdarkly.com
United States
142.250.186.110
unknown
United States
160.8.234.10
location.l.force.com
Sweden
151.101.66.217
unknown
United States
142.250.74.195
unknown
United States
216.58.212.170
unknown
United States
18.245.60.126
consent.api.osano.com
United States
34.107.204.85
data.pendo.io
United States
1.1.1.1
unknown
Australia
74.125.133.84
unknown
United States
160.8.188.31
unknown
Sweden
18.188.247.188
usa778.sfdc-8tgtt5.salesforce.com
United States
142.250.185.238
unknown
United States
18.213.175.73
tattle.api.osano.com
United States
18.245.31.100
d2gt2ux04o03l1.cloudfront.net
United States
35.158.127.51
st1.edge.sfdc-yzvdd4.edge2.salesforce.com
United States
3.14.183.176
la1-core1.sfdc-8tgtt5.salesforceliveagent.com
United States
151.101.2.217
unknown
United States
239.255.255.250
unknown
Reserved
188.114.97.3
cdn.logr-ingest.com
European Union
142.250.185.131
unknown
United States
188.114.96.3
unknown
European Union
104.17.208.240
unknown
United States
104.18.33.243
catalyst.everythingdisc.com
United States
There are 26 hidden IPs, click here to show them.