IOC Report
https://www.google.co.il/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/s%2Furl.us.m.mimecastprotect.com/s/4lucC82NvwFMjpGOhnfECyjGpA?domain=google.co.uk

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:03:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:03:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:03:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:03:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:03:59 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 133
Web Open Font Format (Version 2), TrueType, length 37608, version 1.0
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (1492), with no line terminators
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (1492), with no line terminators
downloaded
Chrome Cache Entry: 136
PNG image data, 300 x 107, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 138
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 139
PNG image data, 300 x 107, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 140
HTML document, ASCII text, with very long lines (4180)
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 142
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 143
JSON data
downloaded
Chrome Cache Entry: 144
HTML document, ASCII text
dropped
Chrome Cache Entry: 145
PNG image data, 278 x 28, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 147
PNG image data, 278 x 28, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 148
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 149
Web Open Font Format (Version 2), TrueType, length 137104, version 331.-31196
downloaded
Chrome Cache Entry: 150
JSON data
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (4422)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (65536), with no line terminators
dropped
There are 18 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2176 --field-trial-handle=1912,i,17459722688275995018,9549884425335363036,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.google.co.il/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/s%2Furl.us.m.mimecastprotect.com/s/4lucC82NvwFMjpGOhnfECyjGpA?domain=google.co.uk"

URLs

Name
IP
Malicious
https://www.google.co.il/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/s%2Furl.us.m.mimecastprotect.com/s/4lucC82NvwFMjpGOhnfECyjGpA?domain=google.co.uk
https://security-us.m.mimecastprotect.com/api/ttp/url/get-page-data
170.10.132.88
https://www.google.co.il/amp/s/url.us.m.mimecastprotect.com/s/4lucC82NvwFMjpGOhnfECyjGpA?domain=google.co.uk
142.250.181.227
https://security-us.m.mimecastprotect.com/ttpwp/resources/polyfills.5257ca6e429949972959.js
170.10.132.88
https://security-us.m.mimecastprotect.com/ttpwp/resources/images/mimecastlogo@2x.png
170.10.132.88
https://security-us.m.mimecastprotect.com/ttpwp/resources/mimecast-icons.bb1a2cd16db9345fc437.woff2?25417273
170.10.132.88
https://security-us.m.mimecastprotect.com/ttpwp/?tkn=3.366SikdTFMAy_TaEdvcV9GHcM0jj3dClYtnrvpDzbL5ZTSzhCRv8AOCS6_zdupT_lktVIsYg6yMAb6nItbRjJhN5jgGTDcVXrR37as__jmB-kGMos0GEzPdWSFHZXsyMuGEOa0gQn5KACOEcTv3Us_daiq-XAk0CW6nas8dM_gEKbWQM47dfyp7NWkJ5zhgZ.HXSzu7iEgmzrwUxf-KvnkA#/block?key=sQWSJDm0QP9zhFiiFttlhCGLnKk_45zZEE_qZO5dW3LxxjgqWgNlOD9HyVUNCedqLr4LnPoVC1m_XEO3KI3lDH4CSeWt8znEw064cNqjZ8AavSHAfLV0Sz5NRiGSTOpV
https://www.google.co.il/url?q=38pQvvq6xRyj7Y00xDjnlx9kIHOSozurMOiaAkImPuQJnOIWtJjqJLi6stjtDz3yh&rct=tTPSrMOiaAkImPuQJnOIWtJjqJLi6stjtFX08pQvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/s%2Furl.us.m.mimecastprotect.com/s/4lucC82NvwFMjpGOhnfECyjGpA?domain=google.co.uk
142.250.181.227
https://security-us.m.mimecastprotect.com/ttpwp/resources/languages/en.json
170.10.132.88
http://www.mimecast.com/
unknown
https://security-us.m.mimecastprotect.com/ttpwp?tkn=3.366SikdTFMAy_TaEdvcV9GHcM0jj3dClYtnrvpDzbL5ZTSzhCRv8AOCS6_zdupT_lktVIsYg6yMAb6nItbRjJhN5jgGTDcVXrR37as__jmB-kGMos0GEzPdWSFHZXsyMuGEOa0gQn5KACOEcTv3Us_daiq-XAk0CW6nas8dM_gEKbWQM47dfyp7NWkJ5zhgZ.HXSzu7iEgmzrwUxf-KvnkA
170.10.132.88
https://security-us.m.mimecastprotect.com/branding/247e11fef91c5004a353fa5232e56bec0394f500/style.css?tkn=3.366SikdTFMAy_TaEdvcV9GHcM0jj3dClYtnrvpDzbL5ZTSzhCRv8AOCS6_zdupT_lktVIsYg6yMAb6nItbRjJhN5jgGTDcVXrR37as__jmB-kGMos0GEzPdWSFHZXsyMuGEOa0gQn5KACOEcTv3Us_daiq-XAk0CW6nas8dM_gEKbWQM47dfyp7NWkJ5zhgZ.HXSzu7iEgmzrwUxf-KvnkA&originalContextPath=ttpwp
170.10.132.88
https://security-us.m.mimecastprotect.com/ttpwp/resources/runtime.5257ca6e429949972959.js
170.10.132.88
https://security-us.m.mimecastprotect.com/ttpwp/resources/styles.5257ca6e429949972959.js
170.10.132.88
https://security-us.m.mimecastprotect.com/ttpwp/resources/fa-solid-900.54dfc8f551be346014e4.woff2
170.10.132.88
https://security-us.m.mimecastprotect.com/branding/247e11fef91c5004a353fa5232e56bec0394f500/main-page-logo.png?tkn=3.366SikdTFMAy_TaEdvcV9GHcM0jj3dClYtnrvpDzbL5ZTSzhCRv8AOCS6_zdupT_lktVIsYg6yMAb6nItbRjJhN5jgGTDcVXrR37as__jmB-kGMos0GEzPdWSFHZXsyMuGEOa0gQn5KACOEcTv3Us_daiq-XAk0CW6nas8dM_gEKbWQM47dfyp7NWkJ5zhgZ.HXSzu7iEgmzrwUxf-KvnkA&originalContextPath=ttpwp
170.10.132.88
https://security-us.m.mimecastprotect.com/ttpwp/resources/main.5257ca6e429949972959.js
170.10.132.88
https://url.us.m.mimecastprotect.com/s/4lucC82NvwFMjpGOhnfECyjGpA
205.139.111.117
https://security-us.m.mimecastprotect.com/ttpwp/resources/images/favicon.ico
170.10.132.88
https://community.mimecast.com/docs/DOC-241
unknown
There are 9 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
url.us.m.mimecastprotect.com
205.139.111.117
security-us.m.mimecastprotect.com
170.10.132.88
www.google.com
142.250.184.228
www.google.co.il
142.250.181.227

IPs

IP
Domain
Country
Malicious
205.139.111.117
url.us.m.mimecastprotect.com
United States
192.168.2.16
unknown
unknown
170.10.132.89
unknown
United States
170.10.132.88
security-us.m.mimecastprotect.com
United States
142.250.181.227
www.google.co.il
United States
239.255.255.250
unknown
Reserved
142.250.186.100
unknown
United States
142.250.184.228
www.google.com
United States

DOM / HTML

URL
Malicious
https://security-us.m.mimecastprotect.com/ttpwp/?tkn=3.366SikdTFMAy_TaEdvcV9GHcM0jj3dClYtnrvpDzbL5ZTSzhCRv8AOCS6_zdupT_lktVIsYg6yMAb6nItbRjJhN5jgGTDcVXrR37as__jmB-kGMos0GEzPdWSFHZXsyMuGEOa0gQn5KACOEcTv3Us_daiq-XAk0CW6nas8dM_gEKbWQM47dfyp7NWkJ5zhgZ.HXSzu7iEgmzrwUxf-KvnkA#/block?key=sQWSJDm0QP9zhFiiFttlhCGLnKk_45zZEE_qZO5dW3LxxjgqWgNlOD9HyVUNCedqLr4LnPoVC1m_XEO3KI3lDH4CSeWt8znEw064cNqjZ8AavSHAfLV0Sz5NRiGSTOpV
https://security-us.m.mimecastprotect.com/ttpwp/?tkn=3.366SikdTFMAy_TaEdvcV9GHcM0jj3dClYtnrvpDzbL5ZTSzhCRv8AOCS6_zdupT_lktVIsYg6yMAb6nItbRjJhN5jgGTDcVXrR37as__jmB-kGMos0GEzPdWSFHZXsyMuGEOa0gQn5KACOEcTv3Us_daiq-XAk0CW6nas8dM_gEKbWQM47dfyp7NWkJ5zhgZ.HXSzu7iEgmzrwUxf-KvnkA#/block?key=sQWSJDm0QP9zhFiiFttlhCGLnKk_45zZEE_qZO5dW3LxxjgqWgNlOD9HyVUNCedqLr4LnPoVC1m_XEO3KI3lDH4CSeWt8znEw064cNqjZ8AavSHAfLV0Sz5NRiGSTOpV