IOC Report
https://url.uk.m.mimecastprotect.com/s/51OcCGvv9FyVlNmuKflFBfE2Q?domain=dlapiper-my.sharepoint.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:26:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:26:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:26:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:26:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:26:28 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 140
ASCII text, with very long lines (1061)
dropped
Chrome Cache Entry: 141
PNG image data, 64 x 29, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (1268)
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (6421)
dropped
Chrome Cache Entry: 145
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 146
gzip compressed data, max compression, truncated
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (65329), with CRLF line terminators
downloaded
Chrome Cache Entry: 148
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 149
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (7547), with no line terminators
downloaded
Chrome Cache Entry: 152
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 154
JSON data
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (543)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (3391)
downloaded
Chrome Cache Entry: 158
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 159
XML 1.0 document, Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (2914)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (593)
downloaded
Chrome Cache Entry: 162
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (6030)
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (625)
downloaded
Chrome Cache Entry: 168
ASCII text, with very long lines (4047), with no line terminators
downloaded
Chrome Cache Entry: 169
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 170
ASCII text
downloaded
Chrome Cache Entry: 172
ASCII text
downloaded
Chrome Cache Entry: 173
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 174
ASCII text, with very long lines (768)
dropped
Chrome Cache Entry: 175
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 64x21, components 3
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (6119)
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (3521)
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (1657)
downloaded
Chrome Cache Entry: 180
PNG image data, 106 x 5326, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (702)
dropped
Chrome Cache Entry: 182
Web Open Font Format (Version 2), TrueType, length 15436, version 1.0
downloaded
Chrome Cache Entry: 183
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 185
MPEG ADTS, layer III, v2, 64 kbps, 24 kHz, Monaural
downloaded
Chrome Cache Entry: 186
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 187
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 190
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (1885)
downloaded
Chrome Cache Entry: 194
PNG image data, 64 x 42, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 197
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (65531)
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (568)
downloaded
Chrome Cache Entry: 203
Web Open Font Format (Version 2), TrueType, length 24652, version 1.0
downloaded
Chrome Cache Entry: 204
ASCII text, with very long lines (501)
downloaded
Chrome Cache Entry: 206
HTML document, ASCII text, with very long lines (20800)
downloaded
Chrome Cache Entry: 207
PNG image data, 36 x 36, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (3962)
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (606)
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (39257), with CRLF line terminators
dropped
Chrome Cache Entry: 212
ASCII text, with very long lines (561)
downloaded
Chrome Cache Entry: 214
PNG image data, 226 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 216
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (17444)
dropped
Chrome Cache Entry: 219
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 64x64, components 3
downloaded
Chrome Cache Entry: 222
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 223
ASCII text, with very long lines (37521)
dropped
Chrome Cache Entry: 225
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (2773)
dropped
Chrome Cache Entry: 228
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 229
ASCII text, with very long lines (8343)
dropped
Chrome Cache Entry: 231
ASCII text, with very long lines (736)
dropped
Chrome Cache Entry: 232
ASCII text, with very long lines (5902), with no line terminators
downloaded
Chrome Cache Entry: 233
HTML document, ASCII text, with very long lines (20701)
downloaded
Chrome Cache Entry: 236
ASCII text, with very long lines (1159)
dropped
Chrome Cache Entry: 237
HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (501)
dropped
Chrome Cache Entry: 239
ASCII text, with very long lines (8245)
downloaded
Chrome Cache Entry: 242
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 245
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 247
ASCII text, with very long lines (2693)
dropped
Chrome Cache Entry: 248
ASCII text, with very long lines (1279)
dropped
Chrome Cache Entry: 254
PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (2287)
downloaded
Chrome Cache Entry: 258
PNG image data, 64 x 42, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 260
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 263
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (5162), with no line terminators
downloaded
Chrome Cache Entry: 265
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 267
MPEG ADTS, layer III, v2, 64 kbps, 24 kHz, Monaural
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (1143)
dropped
Chrome Cache Entry: 269
PNG image data, 32 x 32, 8-bit grayscale, non-interlaced
downloaded
Chrome Cache Entry: 271
ASCII text, with very long lines (625)
dropped
Chrome Cache Entry: 272
ASCII text
downloaded
Chrome Cache Entry: 273
ASCII text, with very long lines (3537)
downloaded
Chrome Cache Entry: 276
ASCII text, with very long lines (1165)
downloaded
Chrome Cache Entry: 278
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
There are 85 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://url.uk.m.mimecastprotect.com/s/51OcCGvv9FyVlNmuKflFBfE2Q?domain=dlapiper-my.sharepoint.com
https://www.google.com/search?q=at+sign&oq=AT+SIGN&gs_lcrp=EgZjaHJvbWUqDQgAEAAYgwEYsQMYgAQyDQgAEAAYgwEYsQMYgAQyBwgBEAAYgAQyBwgCEAAYgAQyBwgDEAAYgAQyBwgEEAAYgAQyBwgFEAAYgAQyBwgGEAAYgAQyBwgHEAAYgAQyBwgIEAAYgAQyBwgJEAAYgATSAQk2NjMyajBqMTWoAgCwAgA&sourceid=chrome&ie=UTF-8

Domains

Name
IP
Malicious
dual-spo-0005.spo-msedge.net
13.107.136.10
plus.l.google.com
142.250.186.78
i.ytimg.com
172.217.23.118
static.doubleclick.net
142.250.184.230
youtube-ui.l.google.com
142.250.185.110
url.uk.m.mimecastprotect.com
91.220.42.63
play.google.com
216.58.206.46
googleads.g.doubleclick.net
142.250.184.226
www3.l.google.com
142.250.181.238
dns-tunnel-check.googlezip.net
216.239.34.159
tunnel.googlezip.net
216.239.34.157
189528-ipv4v6.farm.dprodmgd104.aa-rt.sharepoint.com
52.105.37.27
www.google.com
142.250.186.164
ogs.google.com
unknown
m365cdn.nel.measure.office.net
unknown
dlapiper-my.sharepoint.com
unknown
www.youtube.com
unknown
apis.google.com
unknown
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
52.105.37.27
189528-ipv4v6.farm.dprodmgd104.aa-rt.sharepoint.com
United States
2.23.209.14
unknown
European Union
142.250.185.206
unknown
United States
2.23.209.11
unknown
European Union
13.107.136.10
dual-spo-0005.spo-msedge.net
United States
142.250.186.130
unknown
United States
142.250.186.174
unknown
United States
172.217.18.14
unknown
United States
192.168.2.16
unknown
unknown
216.58.206.35
unknown
United States
172.217.23.110
unknown
United States
142.250.181.238
www3.l.google.com
United States
142.250.184.226
googleads.g.doubleclick.net
United States
142.250.184.206
unknown
United States
142.250.186.74
unknown
United States
142.250.186.35
unknown
United States
142.250.185.67
unknown
United States
142.250.186.78
plus.l.google.com
United States
142.250.184.230
static.doubleclick.net
United States
1.1.1.1
unknown
Australia
91.220.42.63
url.uk.m.mimecastprotect.com
United Kingdom
74.125.133.84
unknown
United States
142.250.186.163
unknown
United States
172.217.23.118
i.ytimg.com
United States
172.217.18.3
unknown
United States
142.250.185.110
youtube-ui.l.google.com
United States
2.16.168.12
unknown
European Union
216.58.206.46
play.google.com
United States
142.250.181.226
unknown
United States
142.250.186.106
unknown
United States
142.250.185.170
unknown
United States
142.250.181.227
unknown
United States
239.255.255.250
unknown
Reserved
172.217.18.106
unknown
United States
142.250.186.164
www.google.com
United States
142.250.186.100
unknown
United States
142.250.186.166
unknown
United States
142.250.186.42
unknown
United States
172.217.16.195
unknown
United States
216.239.34.157
tunnel.googlezip.net
United States
There are 30 hidden IPs, click here to show them.