IOC Report
https://sharing.clickup.com/9011385758/t/h/868a15nvk/VTTN7SYFPHZE3IT

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:52:11 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:52:11 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:52:11 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 17:52:11 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 312
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 314
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 316
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 318
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 320
JSON data
dropped
Chrome Cache Entry: 322
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (1263), with no line terminators
downloaded
Chrome Cache Entry: 324
C source, ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 326
ASCII text, with very long lines (8660), with no line terminators
downloaded
Chrome Cache Entry: 327
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 330
gzip compressed data, original size modulo 2^32 3651
dropped
Chrome Cache Entry: 331
Unicode text, UTF-8 text, with very long lines (65512), with no line terminators
dropped
Chrome Cache Entry: 332
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
downloaded
Chrome Cache Entry: 333
gzip compressed data, from Unix, original size modulo 2^32 3513
downloaded
Chrome Cache Entry: 335
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 337
ASCII text, with very long lines (5821), with no line terminators
downloaded
Chrome Cache Entry: 340
Unicode text, UTF-8 text, with very long lines (65516), with no line terminators
downloaded
Chrome Cache Entry: 341
Unicode text, UTF-8 text, with very long lines (65524), with no line terminators
downloaded
Chrome Cache Entry: 343
ASCII text, with very long lines (1617), with no line terminators
downloaded
Chrome Cache Entry: 345
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 346
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
downloaded
Chrome Cache Entry: 347
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 349
Unicode text, UTF-8 text, with very long lines (65492), with no line terminators
downloaded
Chrome Cache Entry: 350
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 352
Unicode text, UTF-8 text, with very long lines (38935)
downloaded
Chrome Cache Entry: 353
ASCII text, with very long lines (51398)
downloaded
Chrome Cache Entry: 354
JSON data
dropped
Chrome Cache Entry: 355
Unicode text, UTF-8 text, with very long lines (56429)
dropped
Chrome Cache Entry: 359
Unicode text, UTF-8 text, with very long lines (26100)
downloaded
Chrome Cache Entry: 360
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 362
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 363
ASCII text, with very long lines (32013), with no line terminators
dropped
Chrome Cache Entry: 364
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 366
Unicode text, UTF-8 text, with very long lines (65524), with no line terminators
downloaded
Chrome Cache Entry: 367
JSON data
downloaded
Chrome Cache Entry: 369
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 370
Unicode text, UTF-8 text, with very long lines (65518), with no line terminators
downloaded
Chrome Cache Entry: 371
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 373
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 374
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 377
JSON data
dropped
Chrome Cache Entry: 378
Unicode text, UTF-8 text, with very long lines (35408)
downloaded
Chrome Cache Entry: 379
ASCII text, with very long lines (20664), with no line terminators
downloaded
Chrome Cache Entry: 380
gzip compressed data, original size modulo 2^32 1864
dropped
Chrome Cache Entry: 383
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 385
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
downloaded
Chrome Cache Entry: 387
gzip compressed data, original size modulo 2^32 1592
dropped
Chrome Cache Entry: 389
Unicode text, UTF-8 text, with very long lines (65532), with no line terminators
downloaded
Chrome Cache Entry: 391
GIF image data, version 89a, 300 x 300
dropped
Chrome Cache Entry: 393
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 394
Unicode text, UTF-8 text, with very long lines (58858)
downloaded
Chrome Cache Entry: 395
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 396
ASCII text, with very long lines (10937), with no line terminators
downloaded
Chrome Cache Entry: 397
gzip compressed data, from Unix, original size modulo 2^32 141817
dropped
Chrome Cache Entry: 398
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 402
Unicode text, UTF-8 text, with very long lines (65516), with no line terminators
dropped
Chrome Cache Entry: 404
Unicode text, UTF-8 text, with very long lines (52301)
downloaded
Chrome Cache Entry: 407
Unicode text, UTF-8 text, with very long lines (65492), with no line terminators
downloaded
Chrome Cache Entry: 410
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 411
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 415
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 416
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 417
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 418
ASCII text, with very long lines (4149), with no line terminators
downloaded
Chrome Cache Entry: 419
Unicode text, UTF-8 text, with very long lines (18824), with no line terminators
downloaded
Chrome Cache Entry: 420
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 423
Unicode text, UTF-8 text, with very long lines (39223)
downloaded
Chrome Cache Entry: 424
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
downloaded
Chrome Cache Entry: 425
JSON data
dropped
Chrome Cache Entry: 427
Unicode text, UTF-8 text, with very long lines (65488), with no line terminators
downloaded
Chrome Cache Entry: 428
gzip compressed data, from Unix, original size modulo 2^32 407064
downloaded
Chrome Cache Entry: 432
Unicode text, UTF-8 text, with very long lines (30190)
downloaded
Chrome Cache Entry: 433
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
dropped
Chrome Cache Entry: 434
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
downloaded
Chrome Cache Entry: 435
ASCII text
downloaded
Chrome Cache Entry: 436
gzip compressed data, from Unix, original size modulo 2^32 113401
downloaded
Chrome Cache Entry: 437
ASCII text, with very long lines (4171)
downloaded
Chrome Cache Entry: 439
Unicode text, UTF-8 text, with very long lines (39223)
downloaded
Chrome Cache Entry: 440
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 442
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 443
Unicode text, UTF-8 text, with very long lines (43141)
dropped
Chrome Cache Entry: 445
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
dropped
Chrome Cache Entry: 446
Unicode text, UTF-8 text, with very long lines (47821)
dropped
Chrome Cache Entry: 448
JSON data
dropped
Chrome Cache Entry: 449
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 451
Unicode text, UTF-8 text, with very long lines (9703), with no line terminators
downloaded
Chrome Cache Entry: 452
JSON data
downloaded
Chrome Cache Entry: 453
JSON data
dropped
Chrome Cache Entry: 458
Unicode text, UTF-8 text, with very long lines (26431)
downloaded
Chrome Cache Entry: 461
ASCII text, with very long lines (955), with no line terminators
downloaded
Chrome Cache Entry: 462
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 463
gzip compressed data, from Unix, original size modulo 2^32 3013
downloaded
Chrome Cache Entry: 465
Unicode text, UTF-8 text, with very long lines (65496), with no line terminators
dropped
Chrome Cache Entry: 466
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 467
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 468
ASCII text, with very long lines (2130), with no line terminators
downloaded
Chrome Cache Entry: 469
Unicode text, UTF-8 text, with very long lines (65508), with no line terminators
downloaded
Chrome Cache Entry: 470
gzip compressed data, from Unix, original size modulo 2^32 449659
dropped
Chrome Cache Entry: 471
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 473
Unicode text, UTF-8 text, with very long lines (26100)
dropped
Chrome Cache Entry: 474
gzip compressed data, from Unix, original size modulo 2^32 57443
dropped
Chrome Cache Entry: 476
Unicode text, UTF-8 text, with very long lines (58858)
dropped
Chrome Cache Entry: 477
Unicode text, UTF-8 text, with very long lines (61616)
dropped
Chrome Cache Entry: 478
ASCII text, with very long lines (8803), with no line terminators
downloaded
Chrome Cache Entry: 480
JSON data
downloaded
Chrome Cache Entry: 481
Unicode text, UTF-8 text, with very long lines (54676)
dropped
Chrome Cache Entry: 482
Audio file with ID3 version 2.4.0, contains: MPEG ADTS, layer III, v1, 64 kbps, 44.1 kHz, Stereo
downloaded
Chrome Cache Entry: 483
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 484
gzip compressed data, max compression, from Unix, original size modulo 2^32 71723
dropped
Chrome Cache Entry: 485
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 486
PNG image data, 555 x 150, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 487
Unicode text, UTF-8 text, with very long lines (65500), with no line terminators
downloaded
Chrome Cache Entry: 489
MS Windows icon resource - 6 icons, 16x16 with PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 24x24 with PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 493
PNG image data, 545 x 140, 8-bit/color RGBA, non-interlaced
dropped
There are 111 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://sharing.clickup.com/9011385758/t/h/868a15nvk/VTTN7SYFPHZE3IT
malicious
https://pfishipyardofficelogin.aiugc.cloud/?PhkM=61&sso_reload=true
malicious
https://sharing.clickup.com/9011385758/t/h/868a15nvk/VTTN7SYFPHZE3IT
https://pfishipyardofficelogin.aiugc.cloud/?PhkM=61

Domains

Name
IP
Malicious
pfishipyardofficelogin.aiugc.cloud
172.233.46.10
malicious
63b310f6-ee184c46.aiugc.cloud
172.233.46.10
1a46d781-ee184c46.aiugc.cloud
172.233.46.10
l1ve.aiugc.cloud
172.233.46.10
sharing.clickup.com
18.173.205.70
app-cdn.clickup.com
13.225.78.8
split.map.fastly.net
151.101.195.9
events.split.io
44.212.163.116
t9011385758.p.clickup-attachments.com
18.66.112.20
prod-us-west-2-2.clickup.com
54.187.214.37
d296je7bbdd650.cloudfront.net
99.86.8.175
id.app.clickup.com
52.213.71.227
pacificfishermen.com
67.20.70.239
www.google.com
142.250.184.196
8d8f5b26-ee184c46.aiugc.cloud
172.233.46.10
sharing-cdn.clickup.com
18.245.60.96
ebbd454f-ee184c46.aiugc.cloud
172.233.46.10
www.pacificfishermen.com
unknown
sdk.split.io
unknown
cdn.segment.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.233.46.10
63b310f6-ee184c46.aiugc.cloud
United States
malicious
18.245.60.96
sharing-cdn.clickup.com
United States
18.66.112.18
unknown
United States
18.66.147.61
unknown
United States
192.168.2.16
unknown
unknown
18.173.205.70
sharing.clickup.com
United States
67.20.70.239
pacificfishermen.com
United States
52.213.71.227
id.app.clickup.com
United States
142.250.186.110
unknown
United States
142.250.186.99
unknown
United States
18.245.60.78
unknown
United States
44.233.197.203
unknown
United States
142.250.184.196
www.google.com
United States
1.1.1.1
unknown
Australia
142.250.186.163
unknown
United States
13.225.78.8
app-cdn.clickup.com
United States
13.225.78.37
unknown
United States
142.250.185.232
unknown
United States
151.101.3.9
unknown
United States
142.251.173.84
unknown
United States
18.66.112.20
t9011385758.p.clickup-attachments.com
United States
44.212.163.116
events.split.io
United States
239.255.255.250
unknown
Reserved
18.245.60.2
unknown
United States
142.250.185.174
unknown
United States
172.217.18.106
unknown
United States
151.101.195.9
split.map.fastly.net
United States
99.86.8.175
d296je7bbdd650.cloudfront.net
United States
54.187.214.37
prod-us-west-2-2.clickup.com
United States
142.250.184.234
unknown
United States
There are 20 hidden IPs, click here to show them.