IOC Report
https://dlapiper-my.sharepoint.com/:f:/p/lucy_stevens/EuoU6OvOyL9OuhIHkdC9OMQBex9HLiWuOXPp0kCtLg1gOg?e=5%3au3LlBN&at=9

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:29:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:29:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:29:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:29:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 09:29:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 141
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 142
gzip compressed data, max compression, truncated
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (6421)
downloaded
Chrome Cache Entry: 146
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (2684)
dropped
Chrome Cache Entry: 148
ASCII text
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (8163)
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (543)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (3537)
dropped
Chrome Cache Entry: 154
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 155
XML 1.0 document, Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 156
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 158
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (5858)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (561)
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (65329), with CRLF line terminators
dropped
Chrome Cache Entry: 163
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (1061)
dropped
Chrome Cache Entry: 166
JSON data
dropped
Chrome Cache Entry: 167
ASCII text
downloaded
Chrome Cache Entry: 168
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 170
ASCII text
downloaded
Chrome Cache Entry: 171
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 172
ASCII text, with very long lines (4047), with no line terminators
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (568)
dropped
Chrome Cache Entry: 174
Web Open Font Format (Version 2), TrueType, length 15436, version 1.0
downloaded
Chrome Cache Entry: 176
MPEG ADTS, layer III, v2, 64 kbps, 24 kHz, Monaural
downloaded
Chrome Cache Entry: 177
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 180
ASCII text, with very long lines (8361)
downloaded
Chrome Cache Entry: 181
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 183
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (1159)
downloaded
Chrome Cache Entry: 185
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 186
ASCII text, with very long lines (65531)
downloaded
Chrome Cache Entry: 187
HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 190
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 191
Web Open Font Format (Version 2), TrueType, length 24652, version 1.0
downloaded
Chrome Cache Entry: 192
ASCII text, with very long lines (501)
downloaded
Chrome Cache Entry: 195
PNG image data, 36 x 36, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (702)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (39257), with CRLF line terminators
dropped
Chrome Cache Entry: 198
ASCII text, with very long lines (1268)
downloaded
Chrome Cache Entry: 202
ASCII text
downloaded
Chrome Cache Entry: 204
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 207
ASCII text
dropped
Chrome Cache Entry: 209
ASCII text, with very long lines (17444)
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (37521)
dropped
Chrome Cache Entry: 213
ASCII text, with very long lines (593)
dropped
Chrome Cache Entry: 214
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 216
PNG image data, 32 x 32, 8-bit grayscale, non-interlaced
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (5902), with no line terminators
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (625)
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (1159)
dropped
Chrome Cache Entry: 222
HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 225
ASCII text, with very long lines (17823)
dropped
Chrome Cache Entry: 226
ASCII text, with very long lines (2693)
dropped
Chrome Cache Entry: 227
ASCII text, with very long lines (7547), with no line terminators
downloaded
Chrome Cache Entry: 228
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 229
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 233
HTML document, ASCII text, with very long lines (31343)
downloaded
Chrome Cache Entry: 234
PNG image data, 226 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 236
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 237
PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 238
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 239
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 240
ASCII text, with very long lines (846)
downloaded
Chrome Cache Entry: 241
ASCII text
dropped
Chrome Cache Entry: 242
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 244
ASCII text, with very long lines (3962)
dropped
Chrome Cache Entry: 245
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 246
ASCII text, with very long lines (5162), with no line terminators
downloaded
Chrome Cache Entry: 247
ASCII text, with very long lines (3391)
dropped
Chrome Cache Entry: 248
MPEG ADTS, layer III, v2, 64 kbps, 24 kHz, Monaural
downloaded
Chrome Cache Entry: 249
ASCII text, with very long lines (1143)
dropped
Chrome Cache Entry: 253
ASCII text
downloaded
There are 72 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://dlapiper-my.sharepoint.com/:f:/p/lucy_stevens/EuoU6OvOyL9OuhIHkdC9OMQBex9HLiWuOXPp0kCtLg1gOg?e=5%3au3LlBN&at=9
https://www.google.com/search?q=at+sign&oq=at+sign&gs_lcrp=EgZjaHJvbWUyBggAEEUYOdIBCDEyMTBqMGo3qAIAsAIA&sourceid=chrome&ie=UTF-8

Domains

Name
IP
Malicious
dual-spo-0005.spo-msedge.net
13.107.136.10
youtube-ui.l.google.com
172.217.18.14
play.google.com
172.217.18.14
googleads.g.doubleclick.net
172.217.18.98
dns-tunnel-check.googlezip.net
216.239.34.159
tunnel.googlezip.net
216.239.34.157
i.ytimg.com
142.250.185.182
189528-ipv4v6.farm.dprodmgd104.aa-rt.sharepoint.com
52.105.37.27
www.google.com
142.250.184.196
static.doubleclick.net
142.250.181.230
dlapiper-my.sharepoint.com
unknown
www.youtube.com
unknown
m365cdn.nel.measure.office.net
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.99
unknown
United States
52.105.37.27
189528-ipv4v6.farm.dprodmgd104.aa-rt.sharepoint.com
United States
142.250.186.67
unknown
United States
13.107.136.10
dual-spo-0005.spo-msedge.net
United States
172.217.18.14
youtube-ui.l.google.com
United States
192.168.2.17
unknown
unknown
216.58.206.34
unknown
United States
216.58.206.78
unknown
United States
142.250.181.230
static.doubleclick.net
United States
142.250.185.227
unknown
United States
2.23.209.37
unknown
European Union
2.19.126.146
unknown
European Union
142.250.185.182
i.ytimg.com
United States
2.16.164.49
unknown
European Union
142.250.185.163
unknown
United States
142.250.185.142
unknown
United States
142.250.184.228
unknown
United States
142.250.184.206
unknown
United States
172.217.18.98
googleads.g.doubleclick.net
United States
142.250.186.99
unknown
United States
142.250.184.196
www.google.com
United States
1.1.1.1
unknown
Australia
2.23.209.41
unknown
European Union
142.250.186.163
unknown
United States
172.217.18.3
unknown
United States
142.250.185.234
unknown
United States
142.250.185.110
unknown
United States
142.250.185.138
unknown
United States
142.251.173.84
unknown
United States
239.255.255.250
unknown
Reserved
142.250.185.174
unknown
United States
142.250.185.230
unknown
United States
142.250.185.131
unknown
United States
142.250.186.42
unknown
United States
142.250.185.74
unknown
United States
216.239.34.157
tunnel.googlezip.net
United States
142.250.185.98
unknown
United States
There are 27 hidden IPs, click here to show them.