IOC Report
https://pkg.go.dev/vuln/GO-2020-0046

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 21:22:58 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 21:22:58 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 5 08:59:33 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 21:22:58 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 21:22:58 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 10 21:22:58 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text, with very long lines (12123)
dropped
Chrome Cache Entry: 101
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 102
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 103
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 104
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 105
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 106
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 107
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 108
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 109
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 110
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 111
ASCII text, with very long lines (1450)
downloaded
Chrome Cache Entry: 112
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 113
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 114
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 115
MS Windows icon resource - 2 icons, 32x32, 32 bits/pixel, 16x16, 8 bits/pixel
downloaded
Chrome Cache Entry: 116
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 117
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 118
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 119
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (12016)
downloaded
Chrome Cache Entry: 121
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 122
ASCII text, with very long lines (12123)
downloaded
Chrome Cache Entry: 123
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 124
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 125
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 126
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 127
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 128
ASCII text, with very long lines (12016)
dropped
Chrome Cache Entry: 129
HTML document, Unicode text, UTF-8 text, with very long lines (629)
downloaded
Chrome Cache Entry: 74
ASCII text, with very long lines (32409)
downloaded
Chrome Cache Entry: 75
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 76
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 77
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 78
ASCII text, with very long lines (454)
downloaded
Chrome Cache Entry: 79
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 80
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 81
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 82
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 83
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 84
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 85
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 86
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 87
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 88
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 89
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 90
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 91
ASCII text
dropped
Chrome Cache Entry: 92
ASCII text
downloaded
Chrome Cache Entry: 93
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 94
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 95
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 96
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 97
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 98
ASCII text, with very long lines (2343)
dropped
Chrome Cache Entry: 99
SVG Scalable Vector Graphics image
downloaded
There are 53 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2100 --field-trial-handle=2016,i,9498157712959724750,17769625876929464240,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://pkg.go.dev/vuln/GO-2020-0046"

URLs

Name
IP
Malicious
https://pkg.go.dev/vuln/GO-2020-0046
https://pkg.go.dev/static/shared/icon/arrow_drop_down_gm_grey_24dp.svg
34.149.140.181
https://pkg.go.dev/static/shared/icon/search_gm_grey_24dp.svg
34.149.140.181
https://stats.g.doubleclick.net/g/collect
unknown
https://go.dev/learn/
unknown
http://www.google.com/intl/en/policies/privacy/
unknown
https://pkg.go.dev/static/shared/logo/social/google-groups.svg
34.149.140.181
https://go.dev/solutions#use-cases
unknown
https://pkg.go.dev/static/frontend/frontend.js
34.149.140.181
https://www.cve.org/CVERecord?id=CVE-2020-7711
unknown
https://pkg.go.dev/static/shared/logo/social/twitter.svg
34.149.140.181
https://play.golang.org
unknown
https://vuln.go.dev/ID/GO-2020-0046.json
unknown
https://pkg.go.dev/static/frontend/vuln/entry/entry.min.css?version=prod-frontend-00090-vzc
34.149.140.181
https://github.com/golang/vulndb/issues/new?assignees=&labels=Needs
unknown
https://go.dev/solutions
unknown
https://pkg.go.dev/static/shared/icon/navigate_next_gm_grey_24dp.svg
34.149.140.181
https://go.dev/
unknown
https://go.dev/copyright
unknown
https://ampcid.google.com/v1/publisher:getClientId
unknown
https://pkg.go.dev/std
unknown
https://github.com/golang
unknown
https://pkg.go.dev/static/shared/icon/keyboard_grey_24dp.svg
34.149.140.181
https://pkg.go.dev/static/frontend/frontend.min.css?version=prod-frontend-00090-vzc
34.149.140.181
https://policies.google.com/technologies/cookies
unknown
https://pkg.go.dev/static/shared/icon/light_mode_gm_grey_24dp.svg
34.149.140.181
https://www.google.com
unknown
https://pkg.go.dev/static/shared/logo/social/slack.svg
34.149.140.181
https://go.dev/conduct
unknown
https://pkg.go.dev/static/shared/icon/favicon.ico
34.149.140.181
https://www.reddit.com/r/golang/
unknown
http://meyerweb.com/eric/tools/css/reset/
unknown
https://pkg.go.dev/vuln/GO-2020-0046
https://pkg.go.dev/static/shared/icon/brightness_6_gm_grey_24dp.svg
34.149.140.181
https://go.dev/tos
unknown
https://pkg.go.dev/static/shared/gopher/pilot-bust-1431x901.svg
34.149.140.181
https://stats.g.doubleclick.net/j/collect
unknown
https://go.dev/talks/
unknown
https://reddit.com/r/golang
unknown
https://github.com/russellhaering/goxmldsig/issues/48
unknown
https://pkg.go.dev/static/shared/logo/social/reddit.svg
34.149.140.181
https://pkg.go.dev/static/frontend/vuln/vuln.min.css?version=prod-frontend-00090-vzc
34.149.140.181
https://github.com/golang/go/wiki/Conferences
unknown
https://github.com/advisories/GHSA-gq5r-cc4w-g8xf
unknown
https://go.dev/help
unknown
https://go.dev/solutions#case-studies
unknown
https://pkg.go.dev/static/shared/logo/google-white.svg
34.149.140.181
https://github.com/advisories/GHSA-prjq-f4q3-fvfr
unknown
https://twitter.com/golang
unknown
https://go.dev/doc/devel/release
unknown
https://invite.slack.golangbridge.org/
unknown
https://pkg.go.dev/static/shared/logo/social/stack-overflow.svg
34.149.140.181
https://github.com/advisories/GHSA-mqqv-chpx-vq25
unknown
https://pkg.go.dev/static/shared/logo/go-white.svg
34.149.140.181
https://pkg.go.dev/static/shared/logo/social/github.svg
34.149.140.181
https://go.dev/security/policy/
unknown
https://pkg.go.dev/static/shared/logo/go-blue.svg
34.149.140.181
https://pkg.go.dev/static/shared/icon/close_gm_grey_24dp.svg
34.149.140.181
https://pkg.go.dev/about
unknown
https://www.cve.org/CVERecord?id=CVE-2020-7731
unknown
https://blog.golang.org/go-brand
unknown
https://googleads.g.doubleclick.net
unknown
https://tagassistant.google.com/
unknown
https://learn.go.dev/
unknown
https://pkg.go.dev/static/shared/icon/launch_gm_grey_24dp.svg
34.149.140.181
https://go.dev/blog
unknown
https://go.dev/s/pkgsite-feedback
unknown
https://stackoverflow.com/collectives/go
unknown
https://cct.google/taggy/agent.js
unknown
https://groups.google.com/g/golang-nuts
unknown
https://www.twitter.com/golang
unknown
https://github.com/golang/go/issues
unknown
https://go.dev/doc/
unknown
https://golangweekly.com/
unknown
https://www.google.com/ads/ga-audiences
unknown
https://pkg.go.dev
unknown
https://www.google.%/ads/ga-audiences
unknown
https://stackoverflow.com/questions/tagged/go?tab=Newest
unknown
https://td.doubleclick.net
unknown
https://www.merchant-center-analytics.goog
unknown
https://pkg.go.dev/static/shared/icon/brightness_2_gm_grey_24dp.svg
34.149.140.181
https://tour.golang.org
unknown
https://go.dev/doc/effective_go
unknown
https://pkg.go.dev/third_party/dialog-polyfill/dialog-polyfill.js
34.149.140.181
https://github.com/GoogleChrome/dialog-polyfill/#stacking-context
unknown
https://google.com
unknown
https://pkg.go.dev/static/shared/icon/navigate_before_gm_grey_24dp.svg
34.149.140.181
https://github.com/russellhaering/gosaml2/issues/59
unknown
https://go.dev/project
unknown
https://adservice.google.com/pagead/regclk?
unknown
https://go.dev/dl/
unknown
https://www.meetup.com/pro/go
unknown
https://go.dev/doc/devel/release.html
unknown
There are 82 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
bg.microsoft.map.fastly.net
199.232.210.172
pkg.go.dev
34.149.140.181
www.google.com
142.250.185.100

IPs

IP
Domain
Country
Malicious
34.149.140.181
pkg.go.dev
United States
142.250.185.100
www.google.com
United States
192.168.2.10
unknown
unknown
239.255.255.250
unknown
Reserved
142.250.186.100
unknown
United States

DOM / HTML

URL
Malicious
https://pkg.go.dev/vuln/GO-2020-0046
https://pkg.go.dev/vuln/GO-2020-0046
https://pkg.go.dev/vuln/GO-2020-0046