IOC Report
https://mandrillapp.com/track/click/30581239/drive.google.com?p=eyJzIjoiVGJ1am1fRjlFa0xQZUJDblRjUEc2bmEtMi13IiwidiI6MSwicCI6IntcInVcIjozMDU4MTIzOSxcInZcIjoxLFwidXJsXCI6XCJodHRwczpcXFwvXFxcL2RyaXZlLmdvb2dsZS5jb21cXFwvZHJpdmVcXFwvZm9sZGVyc1xcXC8xNVkwTVk5RWJKMnFEWC03anJWNU5mX0l4Yk1iZDBPckY_dXNwPXNoYXJp

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:11:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:11:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:11:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:11:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:11:07 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (940)
dropped
Chrome Cache Entry: 167
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 526x681, components 3
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (503)
dropped
Chrome Cache Entry: 173
JSON data
dropped
Chrome Cache Entry: 174
ASCII text, with very long lines (609)
dropped
Chrome Cache Entry: 177
ASCII text, with very long lines (2328)
dropped
Chrome Cache Entry: 179
ASCII text, with very long lines (2052)
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (518)
dropped
Chrome Cache Entry: 183
ASCII text, with very long lines (2426)
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (672)
downloaded
Chrome Cache Entry: 186
JSON data
dropped
Chrome Cache Entry: 187
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 636x813, components 3
downloaded
Chrome Cache Entry: 193
JSON data
dropped
Chrome Cache Entry: 194
ASCII text, with very long lines (2051)
downloaded
Chrome Cache Entry: 195
JSON data
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (1515)
dropped
Chrome Cache Entry: 197
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 745x907, components 3
dropped
Chrome Cache Entry: 200
JSON data
dropped
Chrome Cache Entry: 204
ASCII text, with very long lines (3528)
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (591)
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (5162), with no line terminators
downloaded
Chrome Cache Entry: 209
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 632x227, components 3
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (733)
dropped
Chrome Cache Entry: 214
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 216
ASCII text, with very long lines (524)
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (1885)
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (1441)
downloaded
Chrome Cache Entry: 220
JSON data
downloaded
Chrome Cache Entry: 221
Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
downloaded
Chrome Cache Entry: 224
ASCII text, with very long lines (14909)
downloaded
Chrome Cache Entry: 225
JSON data
dropped
Chrome Cache Entry: 227
Web Open Font Format (Version 2), TrueType, length 15436, version 1.0
downloaded
Chrome Cache Entry: 228
ASCII text, with very long lines (773)
downloaded
Chrome Cache Entry: 229
JSON data
dropped
Chrome Cache Entry: 237
ASCII text, with very long lines (604)
dropped
Chrome Cache Entry: 238
JSON data
downloaded
Chrome Cache Entry: 239
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 241
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 242
JSON data
downloaded
Chrome Cache Entry: 244
ASCII text, with very long lines (1251)
dropped
Chrome Cache Entry: 245
ASCII text, with very long lines (1299)
dropped
Chrome Cache Entry: 246
JSON data
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (1928)
downloaded
Chrome Cache Entry: 251
ASCII text, with very long lines (1325)
downloaded
Chrome Cache Entry: 254
HTML document, ASCII text
downloaded
Chrome Cache Entry: 256
ASCII text
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (531)
downloaded
Chrome Cache Entry: 258
ASCII text, with very long lines (648)
dropped
Chrome Cache Entry: 259
ASCII text
downloaded
Chrome Cache Entry: 260
ASCII text, with very long lines (2051)
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (508)
dropped
Chrome Cache Entry: 268
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 671x684, components 3
dropped
Chrome Cache Entry: 269
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 271
ASCII text
downloaded
Chrome Cache Entry: 272
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 685x736, components 3
dropped
Chrome Cache Entry: 273
JSON data
downloaded
Chrome Cache Entry: 275
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 278
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 279
ASCII text
downloaded
Chrome Cache Entry: 282
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 711x741, components 3
downloaded
Chrome Cache Entry: 284
PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 285
ASCII text, with very long lines (721)
downloaded
Chrome Cache Entry: 286
JSON data
downloaded
Chrome Cache Entry: 288
ASCII text, with very long lines (506)
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (1885)
dropped
Chrome Cache Entry: 292
ASCII text, with very long lines (3817)
dropped
Chrome Cache Entry: 293
ASCII text, with very long lines (2287)
dropped
Chrome Cache Entry: 294
ASCII text
downloaded
Chrome Cache Entry: 295
ASCII text, with very long lines (3374)
dropped
Chrome Cache Entry: 296
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 300
ASCII text, with very long lines (1885)
dropped
Chrome Cache Entry: 301
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 303
ASCII text
dropped
Chrome Cache Entry: 306
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=1, software=Picasa], baseline, precision 8, 708x907, components 3
downloaded
Chrome Cache Entry: 307
ASCII text, with very long lines (526)
dropped
Chrome Cache Entry: 310
JSON data
dropped
Chrome Cache Entry: 313
ASCII text, with very long lines (2242)
dropped
Chrome Cache Entry: 315
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 701x755, components 3
downloaded
Chrome Cache Entry: 316
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 777x615, components 3
downloaded
Chrome Cache Entry: 318
JSON data
downloaded
Chrome Cache Entry: 320
ASCII text, with very long lines (948)
dropped
Chrome Cache Entry: 321
ASCII text, with very long lines (887)
dropped
Chrome Cache Entry: 324
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 326
ASCII text, with very long lines (493)
dropped
Chrome Cache Entry: 327
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 328
ASCII text, with very long lines (737)
downloaded
Chrome Cache Entry: 333
JSON data
dropped
Chrome Cache Entry: 334
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 335
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 337
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 338
JSON data
dropped
Chrome Cache Entry: 341
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 342
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 526x681, components 3
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (539)
downloaded
Chrome Cache Entry: 344
JSON data
downloaded
Chrome Cache Entry: 345
ASCII text, with very long lines (460)
downloaded
Chrome Cache Entry: 350
Web Open Font Format (Version 2), TrueType, length 35060, version 1.0
downloaded
Chrome Cache Entry: 351
JSON data
downloaded
Chrome Cache Entry: 352
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 353
ASCII text
downloaded
Chrome Cache Entry: 354
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 355
PNG image data, 192 x 192, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 356
JSON data
downloaded
Chrome Cache Entry: 357
JSON data
downloaded
Chrome Cache Entry: 358
JSON data
dropped
Chrome Cache Entry: 360
ASCII text, with very long lines (1961)
dropped
Chrome Cache Entry: 362
ASCII text, with very long lines (455)
dropped
Chrome Cache Entry: 363
ASCII text, with very long lines (339)
downloaded
Chrome Cache Entry: 364
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 365
JSON data
dropped
Chrome Cache Entry: 366
JSON data
downloaded
Chrome Cache Entry: 367
JSON data
dropped
There are 109 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://mandrillapp.com/track/click/30581239/drive.google.com?p=eyJzIjoiVGJ1am1fRjlFa0xQZUJDblRjUEc2bmEtMi13IiwidiI6MSwicCI6IntcInVcIjozMDU4MTIzOSxcInZcIjoxLFwidXJsXCI6XCJodHRwczpcXFwvXFxcL2RyaXZlLmdvb2dsZS5jb21cXFwvZHJpdmVcXFwvZm9sZGVyc1xcXC8xNVkwTVk5RWJKMnFEWC03anJWNU5mX0l4Yk1iZDBPckY_dXNwPXNoYXJpbmdcIixcImlkXCI6XCIyZmY0MmQwNmUxOTg0MmExYjFmNThlYTE2ZWQ4M2E4N1wiLFwidXJsX2lkc1wiOltcIjgyNDEzNDhhMjdhMmIyOWRhMDQ3NGQxYzRkZGI5MGI0MGYzYjE4NDdcIl19In0
https://drive.google.com/drive/folders/15Y0MY9EbJ2qDX-7jrV5Nf_IxbMbd0OrF

Domains

Name
IP
Malicious
blobcomments-pa.clients6.google.com
142.250.74.202
mandrillapp.com
76.223.125.47
plus.l.google.com
142.250.185.238
play.google.com
172.217.23.110
drivefrontend-pa.clients6.google.com
172.217.16.138
drive.google.com
172.217.23.110
www.google.com
216.58.206.36
people-pa.clients6.google.com
142.250.186.106
peoplestackwebexperiments-pa.clients6.google.com
172.217.16.202
googlehosted.l.googleusercontent.com
142.250.185.97
contacts.google.com
unknown
clients6.google.com
unknown
lh3.googleusercontent.com
unknown
apis.google.com
unknown
There are 4 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.74.202
blobcomments-pa.clients6.google.com
United States
142.250.185.78
unknown
United States
142.250.185.206
unknown
United States
172.217.16.138
drivefrontend-pa.clients6.google.com
United States
216.58.212.142
unknown
United States
142.250.186.174
unknown
United States
192.168.2.17
unknown
unknown
216.58.206.78
unknown
United States
172.217.23.106
unknown
United States
192.168.2.16
unknown
unknown
192.168.2.18
unknown
unknown
216.58.206.36
www.google.com
United States
142.250.185.202
unknown
United States
216.58.206.35
unknown
United States
172.217.23.110
play.google.com
United States
142.250.185.163
unknown
United States
76.223.125.47
mandrillapp.com
United States
142.250.184.206
unknown
United States
172.217.18.10
unknown
United States
142.250.186.74
unknown
United States
142.250.186.99
unknown
United States
142.250.184.195
unknown
United States
142.250.186.35
unknown
United States
142.250.186.78
unknown
United States
172.217.16.202
peoplestackwebexperiments-pa.clients6.google.com
United States
1.1.1.1
unknown
Australia
108.177.15.84
unknown
United States
142.250.185.138
unknown
United States
142.250.185.238
plus.l.google.com
United States
142.250.186.106
people-pa.clients6.google.com
United States
142.250.185.193
unknown
United States
142.250.181.227
unknown
United States
239.255.255.250
unknown
Reserved
142.250.184.238
unknown
United States
172.217.16.196
unknown
United States
142.250.186.42
unknown
United States
172.217.16.195
unknown
United States
142.250.185.97
googlehosted.l.googleusercontent.com
United States
There are 28 hidden IPs, click here to show them.