IOC Report
https://app.glorify.com/file/1193241?format=90

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 18:28:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 18:28:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 1 18:28:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://app.glorify.com/file/1193241?format=90
malicious
https://app.glorify.com/file/1193241?format=90
malicious
https://gjsre.corelassetremitquo.sbs/

Domains

Name
IP
Malicious
gjsre.corelassetremitquo.sbs
172.233.121.253
malicious
admin-storage.glorify.com
188.114.96.3
l1ve.corelassetremitquo.sbs
172.233.121.253
a.nel.cloudflare.com
35.190.80.1
api-js.mixpanel.com
130.211.34.183
2a8e2144-db883b8f.corelassetremitquo.sbs
172.233.121.253
widget.intercom.io
108.138.199.116
script.tapfiliate.com
108.157.194.51
cdn.amplitude.com
13.249.9.95
k8s-clusterwidealb-98a78844ee-237907544.us-west-2.elb.amazonaws.com
54.245.204.30
api-iam.intercom.io
3.208.66.7
app.glorify.com
188.114.96.3
a4c7a881-db883b8f.corelassetremitquo.sbs
172.233.121.253
4f0540db-db883b8f.corelassetremitquo.sbs
172.233.121.253
api2.amplitude.com
35.95.222.172
clippingmagic.com
52.84.174.91
0ffice.corelassetremitquo.sbs
172.233.121.253
js.userpilot.io
104.18.17.155
www.google.com
142.250.186.68
find.userpilot.io
104.18.16.155
cdn.mxpnl.com
130.211.5.208
storage.glorify.com
188.114.96.3
9d857cf6-db883b8f.corelassetremitquo.sbs
172.233.121.253
js.intercomcdn.com
3.162.38.19
analytex.userpilot.io
unknown
15.164.165.52.in-addr.arpa
unknown
analytics.tiktok.com
unknown
There are 17 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.233.121.253
l1ve.corelassetremitquo.sbs
United States
malicious
142.250.186.68
www.google.com
United States
142.250.186.46
unknown
United States
172.217.16.136
unknown
United States
35.186.241.51
unknown
United States
130.211.34.183
api-js.mixpanel.com
United States
2.18.64.26
unknown
European Union
108.157.194.51
script.tapfiliate.com
United States
54.245.204.30
k8s-clusterwidealb-98a78844ee-237907544.us-west-2.elb.amazonaws.com
United States
52.43.154.49
unknown
United States
192.168.2.16
unknown
unknown
104.18.17.155
js.userpilot.io
United States
52.222.149.33
unknown
United States
192.168.2.4
unknown
unknown
13.249.9.95
cdn.amplitude.com
United States
130.211.5.208
cdn.mxpnl.com
United States
34.209.165.7
unknown
United States
104.18.16.155
find.userpilot.io
United States
142.250.186.110
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
3.208.66.7
api-iam.intercom.io
United States
35.95.222.172
api2.amplitude.com
United States
142.250.186.138
unknown
United States
142.250.185.67
unknown
United States
108.138.199.116
widget.intercom.io
United States
1.1.1.1
unknown
Australia
2.18.64.15
unknown
European Union
216.58.212.131
unknown
United States
13.32.121.7
unknown
United States
44.242.121.227
unknown
United States
52.37.221.204
unknown
United States
74.125.71.84
unknown
United States
3.162.38.19
js.intercomcdn.com
United States
52.84.174.91
clippingmagic.com
United States
35.190.25.25
unknown
United States
239.255.255.250
unknown
Reserved
188.114.97.3
unknown
European Union
142.250.185.174
unknown
United States
188.114.96.3
admin-storage.glorify.com
European Union
172.217.23.100
unknown
United States
142.250.186.40
unknown
United States
108.139.243.32
unknown
United States
216.58.212.163
unknown
United States
18.165.140.57
unknown
United States
142.250.186.42
unknown
United States
3.162.38.70
unknown
United States
18.165.122.48
unknown
United States
There are 37 hidden IPs, click here to show them.