IOC Report
https://www.gmsactg.com/upgrade-database-request/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 17:21:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 17:21:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 17:21:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 17:21:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 11 17:21:31 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 263
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1024x316, components 3
downloaded
Chrome Cache Entry: 267
gzip compressed data, from Unix, original size modulo 2^32 24138
dropped
Chrome Cache Entry: 268
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 269
gzip compressed data, from Unix, original size modulo 2^32 102567
dropped
Chrome Cache Entry: 273
ASCII text
downloaded
Chrome Cache Entry: 277
gzip compressed data, from Unix, original size modulo 2^32 3626
downloaded
Chrome Cache Entry: 279
gzip compressed data, from Unix, original size modulo 2^32 2643
downloaded
Chrome Cache Entry: 280
PNG image data, 63 x 63, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 282
gzip compressed data, from Unix, original size modulo 2^32 790
downloaded
Chrome Cache Entry: 283
ASCII text, with very long lines (1572)
downloaded
Chrome Cache Entry: 284
gzip compressed data, from Unix, original size modulo 2^32 415904
dropped
Chrome Cache Entry: 286
gzip compressed data, from Unix, original size modulo 2^32 109998
dropped
Chrome Cache Entry: 287
gzip compressed data, from Unix, original size modulo 2^32 108619
dropped
Chrome Cache Entry: 288
gzip compressed data, from Unix, original size modulo 2^32 21464
dropped
Chrome Cache Entry: 289
gzip compressed data, from Unix, original size modulo 2^32 9141
downloaded
Chrome Cache Entry: 290
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 291
gzip compressed data, from Unix, original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 292
gzip compressed data, from Unix, original size modulo 2^32 43229
dropped
Chrome Cache Entry: 293
gzip compressed data, from Unix, original size modulo 2^32 15605
downloaded
Chrome Cache Entry: 295
gzip compressed data, from Unix, original size modulo 2^32 121434
downloaded
Chrome Cache Entry: 296
gzip compressed data, from Unix, original size modulo 2^32 29543
dropped
Chrome Cache Entry: 297
gzip compressed data, from Unix, original size modulo 2^32 18420
dropped
Chrome Cache Entry: 298
ASCII text, with very long lines (1829)
dropped
Chrome Cache Entry: 300
gzip compressed data, from Unix, original size modulo 2^32 6934
downloaded
Chrome Cache Entry: 301
gzip compressed data, from Unix, original size modulo 2^32 4186
downloaded
Chrome Cache Entry: 303
gzip compressed data, from Unix, original size modulo 2^32 58327
downloaded
Chrome Cache Entry: 304
gzip compressed data, from Unix, original size modulo 2^32 158005
downloaded
Chrome Cache Entry: 306
ASCII text, with very long lines (2363)
downloaded
Chrome Cache Entry: 309
gzip compressed data, from Unix, original size modulo 2^32 1179
downloaded
Chrome Cache Entry: 311
gzip compressed data, from Unix, original size modulo 2^32 151890
downloaded
Chrome Cache Entry: 312
gzip compressed data, from Unix, original size modulo 2^32 5520
downloaded
Chrome Cache Entry: 313
JPEG image data, Exif standard: [TIFF image data, little-endian, direntries=0], baseline, precision 8, 1200x1200, components 3
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (30903)
downloaded
Chrome Cache Entry: 318
gzip compressed data, from Unix, original size modulo 2^32 10885
downloaded
Chrome Cache Entry: 320
ASCII text
downloaded
Chrome Cache Entry: 322
gzip compressed data, from Unix, original size modulo 2^32 18726
downloaded
Chrome Cache Entry: 323
Web Open Font Format (Version 2), TrueType, length 16268, version 1.0
downloaded
Chrome Cache Entry: 324
gzip compressed data, from Unix, original size modulo 2^32 64234
downloaded
Chrome Cache Entry: 328
PNG image data, 108 x 75, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 329
gzip compressed data, from Unix, original size modulo 2^32 10332
downloaded
Chrome Cache Entry: 330
gzip compressed data, from Unix, original size modulo 2^32 57925
dropped
Chrome Cache Entry: 331
ASCII text, with very long lines (18641)
downloaded
Chrome Cache Entry: 332
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 333
gzip compressed data, from Unix, original size modulo 2^32 16780
downloaded
Chrome Cache Entry: 334
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 335
gzip compressed data, from Unix, original size modulo 2^32 24140
downloaded
Chrome Cache Entry: 337
gzip compressed data, from Unix, original size modulo 2^32 3428
dropped
Chrome Cache Entry: 339
gzip compressed data, from Unix, original size modulo 2^32 59016
downloaded
Chrome Cache Entry: 340
gzip compressed data, from Unix, original size modulo 2^32 3381
downloaded
Chrome Cache Entry: 341
gzip compressed data, from Unix, original size modulo 2^32 2981
downloaded
Chrome Cache Entry: 342
gzip compressed data, from Unix, original size modulo 2^32 21704
dropped
Chrome Cache Entry: 344
PNG image data, 405 x 175, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 345
gzip compressed data, from Unix, original size modulo 2^32 87394
downloaded
Chrome Cache Entry: 346
gzip compressed data, from Unix, original size modulo 2^32 1426
downloaded
Chrome Cache Entry: 347
gzip compressed data, from Unix, original size modulo 2^32 13288
dropped
Chrome Cache Entry: 349
gzip compressed data, from Unix, original size modulo 2^32 18099
dropped
Chrome Cache Entry: 351
gzip compressed data, from Unix, original size modulo 2^32 12528
dropped
Chrome Cache Entry: 352
HTML document, ASCII text, with very long lines (8856), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 353
gzip compressed data, from Unix, original size modulo 2^32 18833
downloaded
Chrome Cache Entry: 354
gzip compressed data, from Unix, original size modulo 2^32 25504
downloaded
Chrome Cache Entry: 355
gzip compressed data, from Unix, original size modulo 2^32 298930
downloaded
Chrome Cache Entry: 358
gzip compressed data, from Unix, original size modulo 2^32 42825
downloaded
Chrome Cache Entry: 360
gzip compressed data, from Unix, original size modulo 2^32 3039
dropped
Chrome Cache Entry: 361
gzip compressed data, from Unix, original size modulo 2^32 197427
downloaded
Chrome Cache Entry: 362
gzip compressed data, from Unix, original size modulo 2^32 459949
downloaded
Chrome Cache Entry: 363
gzip compressed data, from Unix, original size modulo 2^32 112427
downloaded
Chrome Cache Entry: 364
gzip compressed data, from Unix, original size modulo 2^32 2116
dropped
Chrome Cache Entry: 365
gzip compressed data, from Unix, original size modulo 2^32 11256
downloaded
Chrome Cache Entry: 366
Web Open Font Format (Version 2), TrueType, length 16216, version 1.0
downloaded
Chrome Cache Entry: 367
gzip compressed data, from Unix, original size modulo 2^32 1435
dropped
Chrome Cache Entry: 368
gzip compressed data, from Unix, original size modulo 2^32 8802
downloaded
Chrome Cache Entry: 369
gzip compressed data, from Unix, original size modulo 2^32 1023
downloaded
Chrome Cache Entry: 370
Web Open Font Format (Version 2), TrueType, length 33092, version 1.0
downloaded
Chrome Cache Entry: 371
gzip compressed data, from Unix, original size modulo 2^32 7236
dropped
Chrome Cache Entry: 374
ASCII text, with very long lines (65384)
downloaded
Chrome Cache Entry: 377
PNG image data, 100 x 43, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 379
gzip compressed data, from Unix, original size modulo 2^32 58935
downloaded
Chrome Cache Entry: 380
gzip compressed data, from Unix, original size modulo 2^32 12550
downloaded
Chrome Cache Entry: 381
gzip compressed data, from Unix, original size modulo 2^32 17478
dropped
Chrome Cache Entry: 383
gzip compressed data, from Unix, original size modulo 2^32 4308
dropped
Chrome Cache Entry: 385
ASCII text, with very long lines (27639), with no line terminators
downloaded
Chrome Cache Entry: 386
gzip compressed data, from Unix, original size modulo 2^32 94498
downloaded
Chrome Cache Entry: 387
gzip compressed data, from Unix, original size modulo 2^32 13778
dropped
Chrome Cache Entry: 388
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 389
gzip compressed data, from Unix, original size modulo 2^32 156720
dropped
Chrome Cache Entry: 390
gzip compressed data, from Unix, original size modulo 2^32 2358
dropped
Chrome Cache Entry: 391
gzip compressed data, from Unix, original size modulo 2^32 6061
downloaded
Chrome Cache Entry: 392
gzip compressed data, from Unix, original size modulo 2^32 36748
downloaded
Chrome Cache Entry: 393
gzip compressed data, from Unix, original size modulo 2^32 4307
downloaded
Chrome Cache Entry: 394
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 395
gzip compressed data, from Unix, original size modulo 2^32 74584
downloaded
Chrome Cache Entry: 396
gzip compressed data, from Unix, original size modulo 2^32 11689
downloaded
Chrome Cache Entry: 397
gzip compressed data, from Unix, original size modulo 2^32 101488
downloaded
Chrome Cache Entry: 398
ASCII text, with very long lines (634)
downloaded
Chrome Cache Entry: 399
gzip compressed data, from Unix, original size modulo 2^32 87553
downloaded
Chrome Cache Entry: 401
gzip compressed data, from Unix, original size modulo 2^32 10355
downloaded
Chrome Cache Entry: 403
gzip compressed data, from Unix, original size modulo 2^32 20766
downloaded
Chrome Cache Entry: 404
gzip compressed data, from Unix, original size modulo 2^32 1107
dropped
Chrome Cache Entry: 405
Web Open Font Format, TrueType, length 83760, version 1.0
downloaded
Chrome Cache Entry: 407
gzip compressed data, from Unix, original size modulo 2^32 46417
downloaded
Chrome Cache Entry: 409
gzip compressed data, from Unix, original size modulo 2^32 6036
downloaded
Chrome Cache Entry: 410
gzip compressed data, from Unix, original size modulo 2^32 44208
downloaded
Chrome Cache Entry: 411
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 412
ASCII text, with very long lines (6215), with no line terminators
downloaded
Chrome Cache Entry: 414
ASCII text
downloaded
Chrome Cache Entry: 415
ASCII text, with very long lines (634)
downloaded
Chrome Cache Entry: 418
ASCII text, with very long lines (13479)
dropped
Chrome Cache Entry: 425
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 427
gzip compressed data, from Unix, original size modulo 2^32 9009
downloaded
Chrome Cache Entry: 430
gzip compressed data, from Unix, original size modulo 2^32 17818
downloaded
Chrome Cache Entry: 437
ASCII text, with very long lines (15605), with no line terminators
dropped
Chrome Cache Entry: 438
Web Open Font Format (Version 2), TrueType, length 15240, version 1.0
downloaded
Chrome Cache Entry: 439
gzip compressed data, from Unix, original size modulo 2^32 13577
downloaded
Chrome Cache Entry: 440
gzip compressed data, from Unix, original size modulo 2^32 11984
downloaded
Chrome Cache Entry: 441
gzip compressed data, from Unix, original size modulo 2^32 1191
downloaded
Chrome Cache Entry: 442
ASCII text
downloaded
Chrome Cache Entry: 445
gzip compressed data, from Unix, original size modulo 2^32 97075
downloaded
Chrome Cache Entry: 446
ASCII text, with very long lines (13165)
dropped
Chrome Cache Entry: 447
gzip compressed data, from Unix, original size modulo 2^32 60456
downloaded
Chrome Cache Entry: 449
gzip compressed data, from Unix, original size modulo 2^32 19093
dropped
Chrome Cache Entry: 450
ASCII text, with very long lines (4217), with no line terminators
downloaded
Chrome Cache Entry: 451
gzip compressed data, from Unix, original size modulo 2^32 4854
dropped
Chrome Cache Entry: 452
gzip compressed data, from Unix, original size modulo 2^32 2171
downloaded
Chrome Cache Entry: 453
PNG image data, 80 x 13, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 454
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 458
ASCII text, with very long lines (1957)
dropped
Chrome Cache Entry: 459
PNG image data, 405 x 175, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 460
ASCII text, with very long lines (517)
downloaded
Chrome Cache Entry: 461
gzip compressed data, from Unix, original size modulo 2^32 2544
downloaded
Chrome Cache Entry: 462
gzip compressed data, from Unix, original size modulo 2^32 12058
dropped
Chrome Cache Entry: 463
gzip compressed data, from Unix, original size modulo 2^32 457
downloaded
Chrome Cache Entry: 464
gzip compressed data, from Unix, original size modulo 2^32 49976
downloaded
Chrome Cache Entry: 465
gzip compressed data, from Unix, original size modulo 2^32 20522
downloaded
Chrome Cache Entry: 466
gzip compressed data, from Unix, original size modulo 2^32 165339
dropped
Chrome Cache Entry: 467
Web Open Font Format (Version 2), TrueType, length 16612, version 1.0
downloaded
Chrome Cache Entry: 470
gzip compressed data, from Unix, original size modulo 2^32 22620
downloaded
Chrome Cache Entry: 472
gzip compressed data, from Unix, original size modulo 2^32 458836
downloaded
Chrome Cache Entry: 473
gzip compressed data, from Unix, original size modulo 2^32 7281
downloaded
Chrome Cache Entry: 475
ASCII text, with very long lines (1957)
downloaded
Chrome Cache Entry: 477
gzip compressed data, from Unix, original size modulo 2^32 214989
downloaded
Chrome Cache Entry: 478
gzip compressed data, from Unix, original size modulo 2^32 3543
dropped
Chrome Cache Entry: 479
gzip compressed data, from Unix, original size modulo 2^32 129321
dropped
Chrome Cache Entry: 480
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 482
ASCII text, with very long lines (65447)
dropped
There are 141 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://www.gmsactg.com/upgrade-database-request/
https://www.gmsactg.com/upgrade-database-request/

Domains

Name
IP
Malicious
gmsactg.com
74.220.219.94
scontent.xx.fbcdn.net
157.240.0.6
chimpstatic.com
104.102.19.45
www.google.com
142.250.186.36
unpkg.com
104.17.245.203
www.gmsactg.com
74.220.219.94
connect.facebook.net
unknown

IPs

IP
Domain
Country
Malicious
216.58.212.168
unknown
United States
142.250.185.206
unknown
United States
192.168.2.16
unknown
unknown
104.102.19.45
chimpstatic.com
United States
192.168.2.4
unknown
unknown
157.240.0.6
scontent.xx.fbcdn.net
United States
74.125.206.84
unknown
United States
104.17.245.203
unpkg.com
United States
142.250.185.163
unknown
United States
142.250.185.142
unknown
United States
142.250.186.72
unknown
United States
157.240.252.13
unknown
United States
142.250.186.74
unknown
United States
74.220.219.94
gmsactg.com
United States
104.17.246.203
unknown
United States
142.250.185.67
unknown
United States
172.217.16.202
unknown
United States
1.1.1.1
unknown
Australia
34.104.35.123
unknown
United States
142.250.186.36
www.google.com
United States
216.58.212.131
unknown
United States
172.217.16.206
unknown
United States
142.250.186.106
unknown
United States
239.255.255.250
unknown
Reserved
127.0.0.1
unknown
unknown
There are 15 hidden IPs, click here to show them.