IOC Report
https://links.twiliocdn.com/ls/click?upn=u001.s8B7Bdj-2BO6qOEbA-2BPKse2Z7fYxO9q1PAYKGQzEiFp-2FQBq-2BFpel8VkcfovM37GnWPMnODh7DjfGMugIPNcd8ltt5eAz3eLThOPRhxCnpkpwSoLZsid6F00t-2FjbyOU-2F93X804pv1CgFCLbmObbTHc4xs2oFf5JAweFiVi0KRXNOqc-3DGElV_ZsZNk9I-2BWKUMcOn-2FYMXK2VNILsetvczk0qkDBnt1Q-2Bg8MpLl8s0WAV-2B

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:16:54 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:16:54 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:16:54 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:16:54 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Mon Oct 7 16:16:54 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 104
JSON data
dropped
Chrome Cache Entry: 105
ASCII text, with very long lines (8002), with no line terminators
downloaded
Chrome Cache Entry: 106
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (65435)
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (64244)
downloaded
Chrome Cache Entry: 109
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 111
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 112
HTML document, Unicode text, UTF-8 text, with very long lines (4627)
downloaded
Chrome Cache Entry: 113
Unicode text, UTF-8 text, with very long lines (497)
dropped
Chrome Cache Entry: 115
ASCII text, with very long lines (24274), with no line terminators
dropped
Chrome Cache Entry: 117
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
downloaded
Chrome Cache Entry: 118
PNG image data, 450 x 178, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 120
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 121
ASCII text, with very long lines (404)
downloaded
Chrome Cache Entry: 122
data
downloaded
Chrome Cache Entry: 123
PNG image data, 450 x 248, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 125
ASCII text, with very long lines (64729)
downloaded
Chrome Cache Entry: 127
PNG image data, 450 x 278, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 87
PNG image data, 1026 x 594, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 89
ASCII text, with very long lines (633), with no line terminators
downloaded
Chrome Cache Entry: 91
ASCII text, with very long lines (8002), with no line terminators
dropped
Chrome Cache Entry: 92
ASCII text, with very long lines (32746)
downloaded
Chrome Cache Entry: 93
Unicode text, UTF-8 text, with very long lines (52402)
downloaded
Chrome Cache Entry: 94
Unicode text, UTF-8 text, with very long lines (9369)
downloaded
Chrome Cache Entry: 95
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 96
ASCII text, with very long lines (3712), with no line terminators
dropped
Chrome Cache Entry: 97
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
There are 24 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://links.twiliocdn.com/ls/click?upn=u001.s8B7Bdj-2BO6qOEbA-2BPKse2Z7fYxO9q1PAYKGQzEiFp-2FQBq-2BFpel8VkcfovM37GnWPMnODh7DjfGMugIPNcd8ltt5eAz3eLThOPRhxCnpkpwSoLZsid6F00t-2FjbyOU-2F93X804pv1CgFCLbmObbTHc4xs2oFf5JAweFiVi0KRXNOqc-3DGElV_ZsZNk9I-2BWKUMcOn-2FYMXK2VNILsetvczk0qkDBnt1Q-2Bg8MpLl8s0WAV-2BDTdcA1B04hx8sA-2BW0GxVYvh2qVpF6F65Gu9V4sDAY92xxVGKz5-2FPm7g3NnjmMHPLLko1n0yo8zXU96ib-2Fkd2UlSpKM7-2FtLOgBRnY6kYZKdEH0u7WVzj7SB1RusturLTNUo-2Fc2xD3-2Bue1X-2FXpLb7JXVjEC8KMHbkSDIFrk6iWY7B-2FVB2-2FJ2iI-3D
https://support.twilio.com/hc/en-us/articles/360022561474-How-to-Read-the-Twilio-Invoice-CSV-Supplement

Domains

Name
IP
Malicious
cdn.heapanalytics.com
13.32.27.5
a.nel.cloudflare.com
35.190.80.1
twilio.zendesk.com
216.198.54.1
external-svc-dal.swiftype.net
169.46.32.99
cf.zdassets.com
104.18.72.113
links.twiliocdn.com
104.22.58.219
heapanalytics.com
3.233.16.133
static.zdassets.com
104.18.72.113
d3hjue7omxs01q.cloudfront.net
18.66.92.169
s3.amazonaws.com
54.231.139.48
cdnjs.cloudflare.com
104.17.25.14
p5.zdassets.com
104.18.70.113
www.google.com
216.58.206.36
cloud.typography.com
unknown
s.swiftypecdn.com
unknown
assets.zendesk.com
unknown
cc.swiftype.com
unknown
support.twilio.com
unknown
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.46
unknown
United States
23.201.250.36
unknown
United States
34.239.64.171
unknown
United States
192.168.2.17
unknown
unknown
172.217.23.106
unknown
United States
169.46.32.99
external-svc-dal.swiftype.net
United States
192.168.2.18
unknown
unknown
216.58.206.36
www.google.com
United States
54.231.139.48
s3.amazonaws.com
United States
104.22.58.219
links.twiliocdn.com
United States
13.32.27.5
cdn.heapanalytics.com
United States
104.18.72.113
cf.zdassets.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
66.102.1.84
unknown
United States
1.1.1.1
unknown
Australia
3.233.16.133
heapanalytics.com
United States
18.66.92.169
d3hjue7omxs01q.cloudfront.net
United States
151.101.1.167
unknown
United States
169.63.31.198
unknown
United States
239.255.255.250
unknown
Reserved
104.18.70.113
p5.zdassets.com
United States
142.250.185.131
unknown
United States
216.198.54.1
twilio.zendesk.com
United States
13.32.27.116
unknown
United States
104.17.25.14
cdnjs.cloudflare.com
United States
There are 15 hidden IPs, click here to show them.