IOC Report
Quarantined Messages(9).zip

loading gif

Files

File Path
Type
Category
Malicious
Quarantined Messages(9).zip
Zip archive data, at least v4.5 to extract, compression method=deflate
initial sample
C:\Users\user\AppData\Local\Microsoft\FORMS\FRMCACHE.DAT
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\E8870E4F-8B6C-4496-8C17-656501B90D19
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\outlook.exe.db-journal
SQLite Rollback Journal
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\MSO3072.acl
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:59:23 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 09:23:19 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:59:23 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 14:59:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 76
HTML document, ASCII text, with very long lines (1195), with no line terminators
downloaded
Chrome Cache Entry: 77
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 78
PNG image data, 9 x 100, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 79
PNG image data, 54 x 54, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 80
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 81
ASCII text, with very long lines (24050)
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (47261)
downloaded
Chrome Cache Entry: 84
HTML document, ASCII text, with very long lines (5949)
downloaded
Chrome Cache Entry: 87
ASCII text, with very long lines (8045), with no line terminators
downloaded
Chrome Cache Entry: 88
ASCII text, with very long lines (8052), with no line terminators
dropped
There are 9 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://clientportal65265.org/salimre/agg.php
http://maoe.is-a-player.com/
132.226.118.109

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
clientportal65265.org
172.67.148.116
maoe.is-a-player.com
132.226.118.109
challenges.cloudflare.com
104.18.95.41
www.google.com
142.250.184.196

IPs

IP
Domain
Country
Malicious
52.113.194.132
unknown
United States
142.250.184.196
www.google.com
United States
1.1.1.1
unknown
Australia
52.109.89.18
unknown
United States
104.18.94.41
unknown
United States
192.168.2.18
unknown
unknown
104.18.95.41
challenges.cloudflare.com
United States
142.251.168.84
unknown
United States
142.250.181.238
unknown
United States
239.255.255.250
unknown
Reserved
52.109.28.47
unknown
United States
2.19.126.160
unknown
European Union
172.67.148.116
clientportal65265.org
United States
142.250.186.164
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
132.226.118.109
maoe.is-a-player.com
United States
172.217.16.195
unknown
United States
20.50.201.205
unknown
United States
There are 8 hidden IPs, click here to show them.