IOC Report
FW_ _MARKETING_ New Class Announced for 2025.msg

loading gif

Files

File Path
Type
Category
Malicious
FW_ _MARKETING_ New Class Announced for 2025.msg
CDFV2 Microsoft Outlook Message
initial sample
C:\Users\user\AppData\Local\Microsoft\FORMS\FRMCACHE.DAT
data
dropped
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CatalogCacheMetaData.xml
XML 1.0 document, ASCII text, with very long lines (2008), with no line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\FontCache\4\CloudFonts\Ubuntu\34113265213.ttf
TrueType Font data, digitally signed, 21 tables, 1st "DSIG", 24 names, Macintosh, Copyright 2011 Canonical Ltd. Licensed under the Ubuntu Font Licence 1.0UbuntuRegular0.83;DAMA;
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\outlook.exe.db-shm
data
dropped
C:\Users\user\AppData\Local\Microsoft\Office\OTele\outlook.exe.db-wal
SQLite Write-Ahead Log, version 3007000
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.MSO\FF8B1901.dat
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 100x100, components 3
dropped
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\Content.Word\~WRS{280EFAB8-B402-43E7-9A51-625C3CFAD266}.tmp
data
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1727885371461552800_C1503D08-FCF8-47AF-AF41-67D3356D60B6.log
ASCII text, with very long lines (28775), with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\Diagnostics\OUTLOOK\App1727885371462229100_C1503D08-FCF8-47AF-AF41-67D3356D60B6.log
data
dropped
C:\Users\user\AppData\Local\Temp\Outlook Logging\OUTLOOK_16_0_16827_20130-20241002T1209310175-5816.etl
data
modified
C:\Users\user\AppData\Local\Temp\~DFBF50CE18D54FABDA.TMP
data
dropped
C:\Users\user\AppData\Roaming\Microsoft\Office\MSO3072.acl
data
modified
C:\Users\user\AppData\Roaming\Microsoft\Outlook\NoEmail.srs
Composite Document File V2 Document, Cannot read section info
dropped
C:\Users\user\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC
Unicode text, UTF-16, little-endian text, with CRLF line terminators
modified
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:10:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:10:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 09:23:19 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:10:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:10:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 2 15:10:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\Documents\Outlook Files\Outlook Data File - NoEmail.pst
Microsoft Outlook email folder (>=2003)
dropped
C:\Users\user\Documents\Outlook Files\~Outlook Data File - NoEmail.pst.tmp
data
dropped
Chrome Cache Entry: 213
JSON data
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (2246)
dropped
Chrome Cache Entry: 216
Unicode text, UTF-8 text, with very long lines (31659), with no line terminators
dropped
Chrome Cache Entry: 217
PNG image data, 99 x 76, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 219
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 221
ASCII text, with very long lines (5260), with no line terminators
downloaded
Chrome Cache Entry: 222
ASCII text, with very long lines (5579)
dropped
Chrome Cache Entry: 223
ASCII text
downloaded
Chrome Cache Entry: 226
Web Open Font Format (Version 2), TrueType, length 24560, version 1.0
downloaded
Chrome Cache Entry: 227
JSON data
dropped
Chrome Cache Entry: 228
ASCII text, with very long lines (23295)
downloaded
Chrome Cache Entry: 230
JSON data
downloaded
Chrome Cache Entry: 231
ASCII text, with very long lines (42454)
dropped
Chrome Cache Entry: 232
ASCII text, with very long lines (29949)
dropped
Chrome Cache Entry: 234
ASCII text, with very long lines (10746)
dropped
Chrome Cache Entry: 238
JSON data
downloaded
Chrome Cache Entry: 239
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (4936)
dropped
Chrome Cache Entry: 244
ASCII text, with very long lines (5069), with no line terminators
dropped
Chrome Cache Entry: 245
ASCII text, with very long lines (50765)
downloaded
Chrome Cache Entry: 246
ASCII text, with very long lines (5231), with no line terminators
dropped
Chrome Cache Entry: 247
ASCII text, with very long lines (7316)
downloaded
Chrome Cache Entry: 254
ASCII text, with very long lines (17797)
downloaded
Chrome Cache Entry: 255
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 256
Web Open Font Format (Version 2), TrueType, length 23456, version 1.0
downloaded
Chrome Cache Entry: 257
ASCII text, with very long lines (1810)
dropped
Chrome Cache Entry: 258
ASCII text
dropped
Chrome Cache Entry: 261
ASCII text, with very long lines (5074)
downloaded
Chrome Cache Entry: 263
JSON data
dropped
Chrome Cache Entry: 264
ASCII text, with very long lines (608)
downloaded
Chrome Cache Entry: 266
HTML document, ASCII text
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (25009)
dropped
Chrome Cache Entry: 268
ASCII text, with very long lines (342)
dropped
Chrome Cache Entry: 269
ASCII text, with very long lines (432)
downloaded
Chrome Cache Entry: 273
Unicode text, UTF-8 text, with very long lines (29331)
downloaded
Chrome Cache Entry: 274
ASCII text, with very long lines (40700)
downloaded
Chrome Cache Entry: 279
JSON data
dropped
Chrome Cache Entry: 280
JSON data
dropped
Chrome Cache Entry: 282
ASCII text, with very long lines (4269)
dropped
Chrome Cache Entry: 284
ASCII text, with very long lines (12415)
downloaded
Chrome Cache Entry: 285
ASCII text, with very long lines (868)
dropped
Chrome Cache Entry: 286
ASCII text
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (4143)
dropped
Chrome Cache Entry: 290
ASCII text, with very long lines (5050), with no line terminators
downloaded
Chrome Cache Entry: 292
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 294
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 296
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 297
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 303
ASCII text, with very long lines (684)
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (16202)
downloaded
Chrome Cache Entry: 305
ASCII text, with very long lines (707)
downloaded
Chrome Cache Entry: 309
exported SGML document, ASCII text, with very long lines (2487)
dropped
Chrome Cache Entry: 313
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 314
ASCII text, with very long lines (39414)
dropped
Chrome Cache Entry: 315
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (5260), with no line terminators
dropped
Chrome Cache Entry: 318
ASCII text, with very long lines (6946), with no line terminators
downloaded
Chrome Cache Entry: 320
ASCII text, with very long lines (64393)
downloaded
Chrome Cache Entry: 322
ASCII text, with very long lines (800)
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (5319), with no line terminators
dropped
Chrome Cache Entry: 324
ASCII text, with very long lines (638)
downloaded
Chrome Cache Entry: 326
Unicode text, UTF-8 text, with very long lines (65516), with no line terminators
dropped
Chrome Cache Entry: 330
JSON data
downloaded
Chrome Cache Entry: 331
ASCII text
dropped
Chrome Cache Entry: 332
Web Open Font Format (Version 2), TrueType, length 17216, version 1.0
downloaded
Chrome Cache Entry: 335
JSON data
downloaded
Chrome Cache Entry: 337
JSON data
downloaded
Chrome Cache Entry: 338
HTML document, ASCII text, with very long lines (21342)
downloaded
Chrome Cache Entry: 339
ASCII text, with very long lines (20327), with no line terminators
downloaded
Chrome Cache Entry: 340
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 341
ASCII text, with very long lines (2754)
dropped
Chrome Cache Entry: 342
ASCII text, with very long lines (606)
downloaded
Chrome Cache Entry: 345
ASCII text, with very long lines (36602)
dropped
Chrome Cache Entry: 346
ASCII text, with very long lines (2521)
downloaded
Chrome Cache Entry: 347
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 348
ASCII text, with very long lines (3505)
dropped
Chrome Cache Entry: 349
ASCII text, with very long lines (47313)
dropped
Chrome Cache Entry: 352
ASCII text, with very long lines (6010)
dropped
Chrome Cache Entry: 353
ASCII text, with very long lines (769)
downloaded
Chrome Cache Entry: 354
JSON data
dropped
Chrome Cache Entry: 355
ASCII text, with very long lines (639)
dropped
Chrome Cache Entry: 358
ASCII text, with very long lines (1983)
dropped
Chrome Cache Entry: 359
ASCII text, with very long lines (17493), with no line terminators
dropped
Chrome Cache Entry: 360
ASCII text, with very long lines (34014)
downloaded
Chrome Cache Entry: 363
Unicode text, UTF-8 text
dropped
Chrome Cache Entry: 364
ASCII text, with very long lines (2475)
dropped
Chrome Cache Entry: 366
ASCII text, with very long lines (5724)
downloaded
Chrome Cache Entry: 367
ASCII text, with very long lines (4269)
downloaded
Chrome Cache Entry: 369
JSON data
downloaded
Chrome Cache Entry: 371
ASCII text, with very long lines (748)
dropped
Chrome Cache Entry: 375
ASCII text, with very long lines (40233)
dropped
Chrome Cache Entry: 376
ASCII text, with very long lines (3707)
dropped
Chrome Cache Entry: 377
Web Open Font Format (Version 2), TrueType, length 24844, version 1.0
downloaded
Chrome Cache Entry: 379
ASCII text, with very long lines (19959)
dropped
Chrome Cache Entry: 380
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 381
JSON data
downloaded
Chrome Cache Entry: 386
JSON data
downloaded
Chrome Cache Entry: 387
JSON data
dropped
Chrome Cache Entry: 389
ASCII text, with very long lines (391)
downloaded
Chrome Cache Entry: 391
JSON data
downloaded
Chrome Cache Entry: 392
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 393
ASCII text, with very long lines (5320), with no line terminators
downloaded
Chrome Cache Entry: 394
ASCII text, with very long lines (41026)
downloaded
Chrome Cache Entry: 395
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 396
JSON data
downloaded
Chrome Cache Entry: 398
ASCII text, with very long lines (875)
dropped
Chrome Cache Entry: 399
ASCII text, with very long lines (3757)
downloaded
Chrome Cache Entry: 400
ASCII text, with very long lines (41939)
downloaded
Chrome Cache Entry: 402
JSON data
dropped
Chrome Cache Entry: 406
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 407
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 408
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 409
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 410
ASCII text, with very long lines (25475)
dropped
Chrome Cache Entry: 411
ASCII text, with very long lines (21334)
downloaded
Chrome Cache Entry: 416
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 418
ASCII text, with very long lines (548)
downloaded
Chrome Cache Entry: 421
JSON data
dropped
Chrome Cache Entry: 423
ASCII text, with very long lines (5219), with no line terminators
dropped
Chrome Cache Entry: 425
ASCII text, with very long lines (1042)
dropped
Chrome Cache Entry: 427
ASCII text, with very long lines (4166)
dropped
Chrome Cache Entry: 432
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 433
ASCII text, with very long lines (2333)
dropped
Chrome Cache Entry: 434
ASCII text
dropped
Chrome Cache Entry: 439
ASCII text, with very long lines (58183)
downloaded
Chrome Cache Entry: 440
ASCII text, with very long lines (9752)
downloaded
Chrome Cache Entry: 442
ASCII text, with very long lines (13401)
dropped
Chrome Cache Entry: 446
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 447
ASCII text, with very long lines (18447), with no line terminators
downloaded
Chrome Cache Entry: 448
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 449
ASCII text, with very long lines (909)
dropped
Chrome Cache Entry: 451
ASCII text, with very long lines (33399)
dropped
Chrome Cache Entry: 453
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 455
JSON data
downloaded
Chrome Cache Entry: 457
JSON data
downloaded
Chrome Cache Entry: 459
ASCII text, with very long lines (3174)
downloaded
Chrome Cache Entry: 460
ASCII text, with very long lines (49040)
downloaded
Chrome Cache Entry: 462
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=6, orientation=upper-left, xresolution=86, yresolution=94, resolutionunit=2], progressive, precision 8, 1263x360, components 3
dropped
Chrome Cache Entry: 463
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 464
ASCII text, with very long lines (5218), with no line terminators
downloaded
Chrome Cache Entry: 466
ASCII text, with very long lines (32405)
downloaded
Chrome Cache Entry: 467
Web Open Font Format (Version 2), TrueType, length 24044, version 1.0
downloaded
Chrome Cache Entry: 469
ASCII text, with very long lines (3315)
downloaded
Chrome Cache Entry: 470
JSON data
downloaded
Chrome Cache Entry: 475
Unicode text, UTF-8 text, with very long lines (1444)
downloaded
Chrome Cache Entry: 476
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 477
ASCII text, with very long lines (2621)
dropped
Chrome Cache Entry: 479
ASCII text, with very long lines (29949)
downloaded
Chrome Cache Entry: 483
ASCII text, with very long lines (12523)
downloaded
Chrome Cache Entry: 484
HTML document, ASCII text
dropped
Chrome Cache Entry: 485
ASCII text
downloaded
Chrome Cache Entry: 486
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 487
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 488
ASCII text, with very long lines (49370)
downloaded
Chrome Cache Entry: 489
ASCII text, with very long lines (460)
downloaded
Chrome Cache Entry: 491
JSON data
downloaded
Chrome Cache Entry: 493
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 494
ASCII text, with very long lines (53625)
downloaded
Chrome Cache Entry: 496
HTML document, ASCII text, with very long lines (20929)
downloaded
Chrome Cache Entry: 497
ASCII text, with very long lines (11458)
dropped
Chrome Cache Entry: 498
ASCII text, with very long lines (2996), with no line terminators
downloaded
Chrome Cache Entry: 499
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 500
ASCII text, with very long lines (22707)
dropped
Chrome Cache Entry: 501
JSON data
dropped
Chrome Cache Entry: 502
Web Open Font Format (Version 2), TrueType, length 14736, version 1.0
downloaded
Chrome Cache Entry: 503
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 504
ASCII text, with very long lines (4387)
dropped
Chrome Cache Entry: 506
ASCII text, with very long lines (945)
downloaded
Chrome Cache Entry: 508
ASCII text, with very long lines (6687)
downloaded
Chrome Cache Entry: 512
ASCII text, with very long lines (3757)
downloaded
Chrome Cache Entry: 513
JSON data
downloaded
Chrome Cache Entry: 514
ASCII text, with very long lines (4292)
dropped
Chrome Cache Entry: 517
JSON data
downloaded
Chrome Cache Entry: 523
ASCII text, with very long lines (5748)
dropped
Chrome Cache Entry: 524
ASCII text, with very long lines (39027)
dropped
Chrome Cache Entry: 527
ASCII text, with very long lines (31535)
downloaded
Chrome Cache Entry: 528
ASCII text, with very long lines (5232), with no line terminators
downloaded
Chrome Cache Entry: 529
ASCII text
downloaded
Chrome Cache Entry: 530
ASCII text, with very long lines (41569)
dropped
Chrome Cache Entry: 532
ASCII text, with very long lines (16209)
dropped
Chrome Cache Entry: 535
ASCII text, with very long lines (33688)
downloaded
Chrome Cache Entry: 540
ASCII text, with very long lines (40188)
dropped
There are 195 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://www.spgsecure.com/booking-form?referral=service_details_widget&utm_campaign=7d5db205-7b5b-4eb8-b534-7c4f15498431&utm_source=so&utm_medium=mail&cid=a6f16482-31af-4108-b833-2500c91c831e
https://www.spgsecure.com/service-page/advanced-icd-705-training-course-ca?referral=service_list_widget&utm_campaign=7d5db205-7b5b-4eb8-b534-7c4f15498431&utm_source=so&utm_medium=mail&cid=a6f16482-31af-4108-b833-2500c91c831e

Domains

Name
IP
Malicious
google.com
142.250.185.78
glb-editor.wix.com
34.149.206.255
googleads.g.doubleclick.net
172.217.16.130
nam04.safelinks.eop-tm2.outlook.com
104.47.73.156
spgsecure.com
185.230.63.186
td-static-34-49-229-81.parastorage.com
34.49.229.81
d1cq301dpr7fww.cloudfront.net
18.245.86.101
cdn.ravenjs.com
151.101.2.217
www.google.com
142.250.185.132
td.doubleclick.net
142.250.186.130
td-ccm-neg-87-45.wixdns.net
34.149.87.45
bi-flogger-alb-ext-343643057.us-east-1.elb.amazonaws.com
3.214.242.45
static.wixstatic.com
unknown
siteassets.parastorage.com
unknown
nam04.safelinks.protection.outlook.com
unknown
ecom.wixapps.net
unknown
panorama.wixapps.net
unknown
www.spgsecure.com
unknown
frog.wix.com
unknown
static.parastorage.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.78
google.com
United States
142.250.185.206
unknown
United States
216.58.206.72
unknown
United States
142.250.186.130
td.doubleclick.net
United States
192.168.2.18
unknown
unknown
151.101.130.217
unknown
United States
142.251.168.84
unknown
United States
52.111.243.41
unknown
United States
34.149.87.45
td-ccm-neg-87-45.wixdns.net
United States
142.250.184.228
unknown
United States
3.214.242.45
bi-flogger-alb-ext-343643057.us-east-1.elb.amazonaws.com
United States
34.149.206.255
glb-editor.wix.com
United States
52.113.194.132
unknown
United States
142.250.186.78
unknown
United States
142.250.184.196
unknown
United States
1.1.1.1
unknown
Australia
18.245.86.101
d1cq301dpr7fww.cloudfront.net
United States
142.250.184.194
unknown
United States
216.58.206.67
unknown
United States
35.171.58.3
unknown
United States
185.230.63.186
spgsecure.com
Israel
142.250.185.132
www.google.com
United States
34.49.229.81
td-static-34-49-229-81.parastorage.com
United States
18.245.86.91
unknown
United States
142.250.185.138
unknown
United States
142.250.185.136
unknown
United States
20.189.173.27
unknown
United States
151.101.2.217
cdn.ravenjs.com
United States
239.255.255.250
unknown
Reserved
184.28.90.27
unknown
United States
104.47.73.156
nam04.safelinks.eop-tm2.outlook.com
United States
172.217.16.130
googleads.g.doubleclick.net
United States
There are 22 hidden IPs, click here to show them.