IOC Report
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 13:10:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 13:10:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 13:10:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 13:10:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 13:10:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 255
JSON data
downloaded
Chrome Cache Entry: 256
gzip compressed data, from Unix, original size modulo 2^32 1083
downloaded
Chrome Cache Entry: 257
ASCII text
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (487)
dropped
Chrome Cache Entry: 259
ASCII text
dropped
Chrome Cache Entry: 260
ASCII text, with very long lines (1075)
downloaded
Chrome Cache Entry: 261
Unicode text, UTF-8 text, with very long lines (65516), with no line terminators
dropped
Chrome Cache Entry: 262
gzip compressed data, from Unix, original size modulo 2^32 6985
downloaded
Chrome Cache Entry: 263
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (1460)
dropped
Chrome Cache Entry: 265
gzip compressed data, from Unix, original size modulo 2^32 43473
downloaded
Chrome Cache Entry: 266
gzip compressed data, original size modulo 2^32 29764
downloaded
Chrome Cache Entry: 267
gzip compressed data, truncated
dropped
Chrome Cache Entry: 268
gzip compressed data, from Unix, original size modulo 2^32 22516
downloaded
Chrome Cache Entry: 269
JSON data
dropped
Chrome Cache Entry: 270
gzip compressed data, from Unix, original size modulo 2^32 99410
downloaded
Chrome Cache Entry: 271
ASCII text, with very long lines (487)
downloaded
Chrome Cache Entry: 272
Unicode text, UTF-8 text, with very long lines (41169)
downloaded
Chrome Cache Entry: 273
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 274
ASCII text, with very long lines (39055)
downloaded
Chrome Cache Entry: 275
ASCII text
dropped
Chrome Cache Entry: 276
ASCII text
dropped
Chrome Cache Entry: 277
C source, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 278
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 279
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 280
ASCII text, with very long lines (521)
dropped
Chrome Cache Entry: 281
ASCII text
dropped
Chrome Cache Entry: 282
ASCII text, with very long lines (65454)
dropped
Chrome Cache Entry: 283
Web Open Font Format (Version 2), TrueType, length 53616, version 1.0
downloaded
Chrome Cache Entry: 284
gzip compressed data, original size modulo 2^32 8261
downloaded
Chrome Cache Entry: 285
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 286
ASCII text, with very long lines (939), with no line terminators
downloaded
Chrome Cache Entry: 287
ASCII text, with very long lines (65454)
downloaded
Chrome Cache Entry: 288
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 289
JSON data
dropped
Chrome Cache Entry: 290
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 291
HTML document, ASCII text
downloaded
Chrome Cache Entry: 292
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 293
Web Open Font Format (Version 2), TrueType, length 32836, version 1.0
downloaded
Chrome Cache Entry: 294
ASCII text
dropped
Chrome Cache Entry: 295
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 296
gzip compressed data, original size modulo 2^32 8261
dropped
Chrome Cache Entry: 297
ASCII text, with very long lines (57671), with no line terminators
dropped
Chrome Cache Entry: 298
JPEG image data, progressive, precision 8, 720x420, components 3
dropped
Chrome Cache Entry: 299
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 300
JSON data
downloaded
Chrome Cache Entry: 301
HTML document, ASCII text, with very long lines (2592), with no line terminators
dropped
Chrome Cache Entry: 302
Web Open Font Format (Version 2), TrueType, length 48556, version 1.0
downloaded
Chrome Cache Entry: 303
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (3969)
downloaded
Chrome Cache Entry: 305
Web Open Font Format (Version 2), TrueType, length 74316, version 1.0
downloaded
Chrome Cache Entry: 306
ASCII text, with very long lines (5552)
downloaded
Chrome Cache Entry: 307
gzip compressed data, from Unix, original size modulo 2^32 16860
downloaded
Chrome Cache Entry: 308
ASCII text, with very long lines (1617), with no line terminators
dropped
Chrome Cache Entry: 309
ASCII text, with very long lines (1696), with no line terminators
downloaded
Chrome Cache Entry: 310
gzip compressed data, original size modulo 2^32 29764
dropped
Chrome Cache Entry: 311
gzip compressed data, from Unix, original size modulo 2^32 43473
dropped
Chrome Cache Entry: 312
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 313
ASCII text, with very long lines (25733)
downloaded
Chrome Cache Entry: 314
gzip compressed data, from Unix, original size modulo 2^32 75876
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (9217)
downloaded
Chrome Cache Entry: 316
ASCII text
dropped
Chrome Cache Entry: 317
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 318
gzip compressed data, from Unix, original size modulo 2^32 69869
dropped
Chrome Cache Entry: 319
ASCII text, with very long lines (65450)
downloaded
Chrome Cache Entry: 320
JSON data
dropped
Chrome Cache Entry: 321
gzip compressed data, from Unix, original size modulo 2^32 178536
downloaded
Chrome Cache Entry: 322
JSON data
dropped
Chrome Cache Entry: 323
ASCII text, with very long lines (606)
downloaded
Chrome Cache Entry: 324
gzip compressed data, from Unix, original size modulo 2^32 9009115
dropped
Chrome Cache Entry: 325
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 326
gzip compressed data, from Unix, original size modulo 2^32 4660
dropped
Chrome Cache Entry: 327
Unicode text, UTF-8 text, with very long lines (3400)
downloaded
Chrome Cache Entry: 328
Unicode text, UTF-8 text, with very long lines (65516), with no line terminators
downloaded
Chrome Cache Entry: 329
gzip compressed data, from Unix, original size modulo 2^32 16860
dropped
Chrome Cache Entry: 330
Unicode text, UTF-8 text, with very long lines (16249)
downloaded
Chrome Cache Entry: 331
HTML document, ASCII text, with very long lines (2500), with no line terminators
downloaded
Chrome Cache Entry: 332
gzip compressed data, from Unix, original size modulo 2^32 178536
dropped
Chrome Cache Entry: 333
Web Open Font Format (Version 2), TrueType, length 49736, version 1.0
downloaded
Chrome Cache Entry: 334
gzip compressed data, from Unix, original size modulo 2^32 140978
downloaded
Chrome Cache Entry: 335
ASCII text
downloaded
Chrome Cache Entry: 336
ASCII text
dropped
Chrome Cache Entry: 337
ASCII text, with very long lines (18063)
dropped
Chrome Cache Entry: 338
ASCII text, with very long lines (25712)
downloaded
Chrome Cache Entry: 339
ASCII text
downloaded
Chrome Cache Entry: 340
C source, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 341
gzip compressed data, from Unix, original size modulo 2^32 1605
dropped
Chrome Cache Entry: 342
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 343
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 344
gzip compressed data, from Unix, original size modulo 2^32 89762
downloaded
Chrome Cache Entry: 345
ASCII text, with very long lines (521)
downloaded
Chrome Cache Entry: 346
RIFF (little-endian) data, Web/P image, VP8 encoding, 720x420, Scaling: [none]x[none], YUV color, decoders should clamp
downloaded
Chrome Cache Entry: 347
ASCII text, with very long lines (1696), with no line terminators
dropped
Chrome Cache Entry: 348
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 349
ASCII text, with very long lines (2343)
dropped
Chrome Cache Entry: 350
ASCII text, with very long lines (5945)
downloaded
Chrome Cache Entry: 351
JSON data
dropped
Chrome Cache Entry: 352
gzip compressed data, from Unix, original size modulo 2^32 20070
dropped
Chrome Cache Entry: 353
gzip compressed data, from Unix, original size modulo 2^32 4660
downloaded
Chrome Cache Entry: 354
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 355
Unicode text, UTF-8 text, with very long lines (65506), with no line terminators
dropped
Chrome Cache Entry: 356
JSON data
downloaded
Chrome Cache Entry: 357
ASCII text, with very long lines (39055)
dropped
Chrome Cache Entry: 358
ASCII text, with very long lines (18063)
downloaded
Chrome Cache Entry: 359
ASCII text, with very long lines (1054), with no line terminators
downloaded
Chrome Cache Entry: 360
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 361
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 362
ASCII text, with very long lines (715)
dropped
Chrome Cache Entry: 363
gzip compressed data, truncated
downloaded
Chrome Cache Entry: 364
ASCII text
dropped
Chrome Cache Entry: 365
HTML document, ASCII text, with very long lines (589)
downloaded
Chrome Cache Entry: 366
gzip compressed data, was "tmpwpxf9m60", last modified: Thu Sep 26 19:05:56 2024, max compression, original size modulo 2^32 43575
dropped
Chrome Cache Entry: 367
ASCII text, with very long lines (57671), with no line terminators
downloaded
Chrome Cache Entry: 368
Web Open Font Format (Version 2), TrueType, length 22832, version 1.0
downloaded
Chrome Cache Entry: 369
ASCII text
dropped
Chrome Cache Entry: 370
ASCII text
downloaded
Chrome Cache Entry: 371
gzip compressed data, was "tmpwmofo0_d", last modified: Thu Oct 17 18:07:45 2024, max compression, original size modulo 2^32 291442
dropped
Chrome Cache Entry: 372
JSON data
dropped
Chrome Cache Entry: 373
Unicode text, UTF-8 text, with very long lines (65442)
downloaded
Chrome Cache Entry: 374
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 375
gzip compressed data, from Unix, original size modulo 2^32 99410
dropped
Chrome Cache Entry: 376
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 377
ASCII text, with very long lines (2932), with no line terminators
downloaded
Chrome Cache Entry: 378
Unicode text, UTF-8 text, with very long lines (65506), with no line terminators
dropped
Chrome Cache Entry: 379
gzip compressed data, from Unix, original size modulo 2^32 3486
downloaded
Chrome Cache Entry: 380
ASCII text, with very long lines (1075)
dropped
Chrome Cache Entry: 381
ASCII text, with very long lines (1445)
downloaded
Chrome Cache Entry: 382
gzip compressed data, from Unix, original size modulo 2^32 140978
dropped
Chrome Cache Entry: 383
ASCII text, with very long lines (5552)
dropped
Chrome Cache Entry: 384
ASCII text, with very long lines (5072), with no line terminators
dropped
Chrome Cache Entry: 385
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 386
ASCII text, with very long lines (31995)
downloaded
Chrome Cache Entry: 387
ASCII text, with very long lines (715)
downloaded
Chrome Cache Entry: 388
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 389
JSON data
dropped
Chrome Cache Entry: 390
ASCII text, with very long lines (939), with no line terminators
dropped
Chrome Cache Entry: 391
ASCII text, with very long lines (33763)
dropped
Chrome Cache Entry: 392
gzip compressed data, from Unix, original size modulo 2^32 1605
downloaded
Chrome Cache Entry: 393
JSON data
dropped
Chrome Cache Entry: 394
HTML document, ASCII text, with very long lines (6613)
downloaded
Chrome Cache Entry: 395
gzip compressed data, was "tmpwpxf9m60", last modified: Thu Sep 26 19:05:56 2024, max compression, original size modulo 2^32 43575
downloaded
Chrome Cache Entry: 396
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 397
ASCII text, with very long lines (606)
dropped
Chrome Cache Entry: 398
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 399
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 401
JSON data
downloaded
Chrome Cache Entry: 402
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 403
Unicode text, UTF-8 text, with very long lines (65506), with no line terminators
downloaded
Chrome Cache Entry: 404
ASCII text, with very long lines (5796)
downloaded
Chrome Cache Entry: 405
JSON data
downloaded
Chrome Cache Entry: 406
gzip compressed data, from Unix, original size modulo 2^32 1426
dropped
Chrome Cache Entry: 407
JSON data
downloaded
Chrome Cache Entry: 408
JSON data
dropped
Chrome Cache Entry: 409
gzip compressed data, from Unix, original size modulo 2^32 69869
downloaded
Chrome Cache Entry: 410
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 411
Web Open Font Format (Version 2), TrueType, length 53196, version 1.0
downloaded
Chrome Cache Entry: 412
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 413
gzip compressed data, from Unix, original size modulo 2^32 6985
dropped
Chrome Cache Entry: 414
ASCII text, with very long lines (22096), with no line terminators
downloaded
Chrome Cache Entry: 415
gzip compressed data, from Unix, original size modulo 2^32 1426
downloaded
Chrome Cache Entry: 416
JSON data
downloaded
Chrome Cache Entry: 417
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
dropped
Chrome Cache Entry: 418
gzip compressed data, from Unix, original size modulo 2^32 5402
dropped
Chrome Cache Entry: 419
JSON data
dropped
Chrome Cache Entry: 420
ASCII text, with very long lines (1460)
downloaded
Chrome Cache Entry: 421
ASCII text, with very long lines (2932), with no line terminators
dropped
Chrome Cache Entry: 422
ASCII text, with very long lines (1384), with no line terminators
dropped
Chrome Cache Entry: 423
gzip compressed data, from Unix, original size modulo 2^32 3486
dropped
Chrome Cache Entry: 424
Unicode text, UTF-8 text, with very long lines (3400)
dropped
Chrome Cache Entry: 425
Unicode text, UTF-8 text, with very long lines (41169)
dropped
Chrome Cache Entry: 426
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 427
Unicode text, UTF-8 text, with very long lines (65442)
dropped
Chrome Cache Entry: 428
JSON data
downloaded
Chrome Cache Entry: 429
ASCII text, with very long lines (22096), with no line terminators
dropped
Chrome Cache Entry: 430
ASCII text, with very long lines (1617), with no line terminators
downloaded
Chrome Cache Entry: 431
JSON data
dropped
Chrome Cache Entry: 432
gzip compressed data, from Unix, original size modulo 2^32 325310
downloaded
Chrome Cache Entry: 433
JSON data
downloaded
Chrome Cache Entry: 434
ASCII text, with very long lines (5072), with no line terminators
downloaded
Chrome Cache Entry: 435
ASCII text
downloaded
Chrome Cache Entry: 436
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 437
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 438
ASCII text
dropped
Chrome Cache Entry: 439
JSON data
downloaded
Chrome Cache Entry: 440
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 441
ASCII text, with very long lines (715)
downloaded
Chrome Cache Entry: 442
ASCII text, with very long lines (33763)
downloaded
Chrome Cache Entry: 443
ASCII text
dropped
Chrome Cache Entry: 444
HTML document, Unicode text, UTF-8 text, with very long lines (27296)
downloaded
Chrome Cache Entry: 445
JSON data
downloaded
Chrome Cache Entry: 446
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 447
gzip compressed data, from Unix, original size modulo 2^32 5402
downloaded
Chrome Cache Entry: 448
JSON data
dropped
Chrome Cache Entry: 449
ASCII text, with very long lines (65450)
dropped
Chrome Cache Entry: 450
gzip compressed data, from Unix, original size modulo 2^32 22516
dropped
Chrome Cache Entry: 451
Unicode text, UTF-8 text, with very long lines (65506), with no line terminators
downloaded
Chrome Cache Entry: 452
JSON data
dropped
Chrome Cache Entry: 453
gzip compressed data, was "tmpwmofo0_d", last modified: Thu Oct 17 18:07:45 2024, max compression, original size modulo 2^32 291442
downloaded
Chrome Cache Entry: 454
gzip compressed data, from Unix, original size modulo 2^32 325310
dropped
Chrome Cache Entry: 455
ASCII text, with very long lines (9217)
dropped
Chrome Cache Entry: 456
ASCII text, with very long lines (3969)
dropped
Chrome Cache Entry: 457
ASCII text, with very long lines (1384), with no line terminators
downloaded
Chrome Cache Entry: 458
gzip compressed data, from Unix, original size modulo 2^32 9009115
downloaded
Chrome Cache Entry: 459
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 460
ASCII text, with very long lines (5945)
dropped
Chrome Cache Entry: 461
ASCII text, with very long lines (1058), with no line terminators
downloaded
Chrome Cache Entry: 462
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 463
JSON data
dropped
Chrome Cache Entry: 464
gzip compressed data, from Unix, original size modulo 2^32 89762
dropped
Chrome Cache Entry: 465
JSON data
dropped
Chrome Cache Entry: 466
gzip compressed data, from Unix, original size modulo 2^32 20070
downloaded
Chrome Cache Entry: 467
JSON data
downloaded
There are 209 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1616 --field-trial-handle=2040,i,16886515858095146127,10418092158726626576,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843"

URLs

Name
IP
Malicious
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843
malicious
https://cloud.elastic.co/registration)of
unknown
https://www.elastic.co/security-labs/update-to-the-REF2924-intrusion-set-and-related-campaigns)
unknown
https://github.com/imfiver/CVE-2022-0847)
unknown
https://help.okta.com/en-us/content/topics/security/network/network-zones.htm)
unknown
https://clearbit.com
unknown
https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_scheduled_task_t
unknown
https://help.okta.com/en-us/content/topics/apps/apps_single_logout.htm))
unknown
https://attack.mitre.org/techniques/T1015/).
unknown
https://www.elastic.co/security-labs/forget-vulnerable-drivers-admin-is-all-you-need)
unknown
https://attack.mitre.org/techniques/T1003/002/)
unknown
https://github.com/elastic/detection-rules/blob/6bdfddac8edea5e327bf28aed7e6dc4a7f701dc6/rules/windo
unknown
https://www.elastic.co/integrations/data-integrations)
unknown
https://cloud.google.com/vpc/docs/routes)
unknown
https://www.elastic.co/elastic-agent)
unknown
https://ampcid.google.com/v1/publisher:getClientId
unknown
https://w3-reporting-nel.reddit.com/reports
151.101.129.140
https://www.elastic.co/partners/aws?utm_campaign=Comp-Stack-Trials-AWSElasticsearch-AMER-NA-Exact&ut
unknown
https://px.ads.linkedin.com/collect?
unknown
https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_disable_uac_
unknown
https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/privilege_escalation_uac_b
unknown
https://hex-rays.com/IDA-pro/)
unknown
https://x.clearbitjs.com/v2/pk_ec27dac96e63040fe28d23ffcf4a8453/destinations.min.js
18.153.4.44
https://support.google.com/recaptcha/#6175971
unknown
https://www.elastic.co/endpoint-security/)
unknown
https://risk.clearbit.com
unknown
https://www.elastic.co/security-labs/dissecting-remcos-rat-part-two)
unknown
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows_VulnDriver_Mhyprot.yar
unknown
https://github.com/CCob/ThreadlessInject)
unknown
https://js.adsrvr.org/up_loader.1.1.0.js
18.172.103.101
https://github.com/rapid7/metasploit-framework/pull/16303
unknown
https://python-poetry.org/)
unknown
https://research.splunk.com/detections/)
unknown
https://support.google.com/recaptcha
unknown
https://attack.mitre.org/techniques/T1550/001/
unknown
https://github.com/elastic/detection-rules/blob/main/rules/windows/collection_winrar_encryption.toml
unknown
https://numpy.org/)
unknown
https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three)
unknown
https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/).
unknown
https://edge.fullstory.com/datalayer/v4/latest.js
35.201.112.186
https://cdn.iubenda.com/cookie_solution/iubenda_cs/1.68.0/core-
unknown
https://twitter.com/jellard8)
unknown
https://insight.adsrvr.org/track/pxl/?adv=bciceyi&ct=0:l8nmulj&fmt=3
3.33.220.150
https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_unusual_dns_service_fil
unknown
https://www.okta.com/resources/whitepaper/ad-architecture/).
unknown
https://www.todyl.com/blog/post/threat-advisory-3cx-softphone-telephony-campaign).
unknown
https://malpedia.caad.fkie.fraunhofer.de/details/win.darkvnc)
unknown
https://ela.st/gtr)
unknown
http://www.elastic.co/security)
unknown
https://hevodata.com/learn/google-bigquery-create-table/#b2)
unknown
https://www.elastic.co/blog/introducing-elastic-endpoint-security)
unknown
https://malpedia.caad.fkie.fraunhofer.de/details/win.formbook):
unknown
https://www.elastic.co/guide/en/ecs/current/ecs-process.html#field-process-args)
unknown
https://github.com/elastic/detection-rules/blob/main/rules/integrations/google_workspace/persistence
unknown
https://developers.google.com/apps-script/guides/services/authorization)
unknown
https://developers.marketo.com/MunchkinLicense.pdf
unknown
https://t.co/1/i/adsct?bci=4&eci=3&event=%7B%7D&event_id=f98fc1b5-b030-4ec9-9a57-b1666b52631b&integration=gtm&p_id=Twitter&p_user_id=0&pl_id=a2d3e356-f909-400c-bd56-2b3c8a0c6af3&tw_document_href=https%3A%2F%2Fwww.elastic.co%2Fsecurity-labs%2Felevate-your-threat-hunting%3Futm_source%3Dorganic-social%26utm_medium%3Dtwitter%26utm_campaign%3Desl%3A_threat_research_esl_blog_post%26utm_content%3D15000445268%26linkId%3D626315843&tw_iframe_status=0&txn_id=o50k2&type=javascript&version=2.3.30
172.66.0.227
https://github.com/elastic/labs-releases
unknown
https://attack.mitre.org/techniques/T1566/))
unknown
https://attack.mitre.org/techniques/T1547/001/):
unknown
https://datatracker.ietf.org/doc/html/rfc7644)
unknown
https://developers.google.com/workspace/guides/configure-oauth-consent)
unknown
https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_werf
unknown
https://scipy.org/)
unknown
https://www.welivesecurity.com/2020/05/26/agentbtz-comratv4-ten-year-journey/)
unknown
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows_Trojan_DoorMe.yar).
unknown
https://www.elastic.co/security/threat-hunting).
unknown
https://www.elastic.co/security-labs/pikabot-i-choose-you)
unknown
https://sysdig.com/blog/cve-2022-0847-dirty-pipe-sysdig
unknown
https://oasis-open.github.io/cti-documentation/stix/intro).
unknown
https://unifiedid.com/docs/sdks/client-side-identity#event-types-and-payload-details
unknown
https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_executable_tool_
unknown
https://attack.mitre.org/tactics/TA0003/)
unknown
https://workspace.google.com/features/)
unknown
https://github.com/KoenZomers/OneDriveAPI)
unknown
https://github.com/InteractiveAdvertisingBureau/Global-Privacy-Platform/blob/main/Core/CMP%20API%20S
unknown
https://www.elastic.co/guide/en/ecs/current/ecs-allowed-values-event-category.html#ecs-event-categor
unknown
https://www.elastic.co/guide/en/elasticsearch/reference/current/data-tiers.html#frozen-tier
unknown
https://developer.okta.com/docs/api/openapi/okta-management/management/tag/Session/)
unknown
https://sectigo.com/ssl-certificates-tls/code-signing).
unknown
https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla))
unknown
https://x.clearbitjs.com/v1/pk_ec27dac96e63040fe28d23ffcf4a8453/forms.js?page_path=
unknown
https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=cti)
unknown
https://rs.fullstory.com/rec/bundle?OrgId=o-1YRR3Q-na1&UserId=5991464404463616&SessionId=2263100182742291018&PageId=1181149337488990652&Seq=3&ClientTime=1729606232372&PageStart=1729606223354&PrevBundleTime=1729606230594&IsNewSession=true&SkipResponseBody=true
35.186.194.58
https://www.elastic.co/beats/winlogbeat)
unknown
https://developer.okta.com/docs/reference/core-okta-api/)
unknown
https://cdn.iubenda.com/cs/iubenda_cs.js
84.17.46.49
https://cloud.google.com/contact
unknown
https://lolbas-project.github.io/)
unknown
https://attack.mitre.org/techniques/T1036/008/)
unknown
https://global.prod.uidapi.com
unknown
https://twitter.com/_xDeJesus).
unknown
https://mh-nexus.de/en/hxd/)
unknown
https://www.elastic.co/integrations/).
unknown
https://twitter.com/jonasLyk)
unknown
https://tdsf.doubleclick.net/td/adfetch/gda?adg_id=166471558460
unknown
https://www.elastic.co/guide/en/elasticsearch/reference/master/eql.html)
unknown
https://visitor-scoring-new.marketlinc.com/visitor-scoring
34.192.69.139
https://twitter.com/pwntester)
unknown
https://js.adsrvr.org/uid2-sdk.js
unknown
https://www.facebook.com/tr/?id=1636465863246433&ev=PageView&dl=https%3A%2F%2Fwww.elastic.co%2Fsecurity-labs%2Felevate-your-threat-hunting%3Futm_source%3Dorganic-social%26utm_medium%3Dtwitter%26utm_campaign%3Desl%3A_threat_research_esl_blog_post%26utm_content%3D15000445268%26linkId%3D626315843&rl=&if=false&ts=1729606223540&cd[referrer]=&sw=1280&sh=1024&v=2.9.172&r=stable&ec=0&o=4126&fbp=fb.1.1729606223537.276108119418112473&ler=empty&cdl=API_unavailable&it=1729606220815&coo=false&rqm=GET
157.240.252.35
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
t.co
172.66.0.227
malicious
alb.reddit.com
unknown
malicious
static.ads-twitter.com
unknown
malicious
secure.adnxs.com
unknown
malicious
script.crazyegg.com
unknown
malicious
stun.services.mozilla.com
unknown
malicious
pixels.spotify.com
unknown
malicious
8fb3096e1c3e431cb988445dd1f7c1a7.apm.us-east-1.aws.cloud.es.io
unknown
malicious
q.quora.com
unknown
malicious
clientstream.launchdarkly.com
unknown
malicious
www.redditstatic.com
unknown
malicious
js.adsrvr.org
unknown
malicious
s.company-target.com
unknown
malicious
pixel.rubiconproject.com
unknown
malicious
px.ads.linkedin.com
unknown
malicious
connect.facebook.net
unknown
malicious
munchkin.marketo.net
unknown
malicious
partners.tremorhub.com
unknown
malicious
cs.iubenda.com
unknown
malicious
a.quora.com
unknown
malicious
x.clearbitjs.com
unknown
malicious
w3-reporting-nel.reddit.com
unknown
malicious
pixel-config.reddit.com
unknown
malicious
visitor-scoring-new.marketlinc.com
unknown
malicious
sjrtp2-cdn.marketo.com
unknown
malicious
www.facebook.com
unknown
malicious
app.launchdarkly.com
unknown
malicious
www.linkedin.com
unknown
malicious
play.vidyard.com
unknown
malicious
analytics.twitter.com
unknown
malicious
idb.iubenda.com
unknown
malicious
cdn.iubenda.com
unknown
malicious
snap.licdn.com
unknown
malicious
www.elastic.co
unknown
malicious
ib.adnxs.com
unknown
malicious
trk.techtarget.com
unknown
malicious
cloud.elastic.co
unknown
malicious
tag.clearbitscripts.com
18.245.46.79
s.dsp-prod.demandbase.com
34.96.71.22
pixel.byspotify.com
34.117.162.98
events.launchdarkly.com
52.206.204.68
cdn-iubenda.b-cdn.net
84.17.46.49
dg2iu7dxxehbo.cloudfront.net
18.172.103.101
fp2e7a.wpc.phicdn.net
192.229.221.95
platform.twitter.map.fastly.net
199.232.188.157
marketo.clearbit.com
3.127.196.46
stats.g.doubleclick.net
74.125.71.154
insight.adsrvr.org
35.71.131.137
tag.demandbase.com
18.245.46.44
scontent.xx.fbcdn.net
157.240.251.9
global-v4.clearbit.com
18.153.4.44
cm.g.doubleclick.net
142.250.185.226
www.google.com
142.250.186.68
app.clearbit.com
18.153.4.44
id.rlcdn.com
35.244.174.68
hits-iubenda.b-cdn.net
169.150.247.37
edge-web.dual-gslb.spotify.com
35.186.224.24
risk.clearbit.com
18.158.205.16
marketlinc-prod-2024.us-east-1.elasticbeanstalk.com
34.192.69.139
tag-logger.demandbase.com
18.173.205.104
match.adsrvr.org
52.223.40.198
star-mini.c10r.facebook.com
157.240.252.35
proxy-rr.us-east-1.aws.found.io
54.160.25.132
s.twitter.com
104.244.42.131
clientstream-ga.launchdarkly.com
76.223.31.44
edge.fullstory.com
35.201.112.186
ax-0001.ax-msedge.net
150.171.28.10
dualstack.reddit.map.fastly.net
151.101.1.140
rs.fullstory.com
35.186.194.58
reddit.map.fastly.net
151.101.1.140
dsum-sec.casalemedia.com
172.64.151.101
googleads.g.doubleclick.net
142.250.186.66
lift-ai-js.marketlinc.com
13.35.58.122
ibc-flow.techtarget.com
34.111.208.231
api.company-target.com
18.66.102.85
analytics.google.com
142.250.185.78
td.doubleclick.net
142.250.74.194
partners-alb-1113315349.us-east-1.elb.amazonaws.com
54.85.66.138
ib.anycast.adnxs.com
185.89.210.90
cs-iubenda.b-cdn.net
169.150.247.38
s-part-0032.t-0009.t-msedge.net
13.107.246.60
813-mam-392.mktoresp.com
134.213.193.62
There are 72 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.66.0.227
t.co
United States
malicious
142.250.186.68
www.google.com
United States
37.252.171.149
unknown
European Union
35.186.194.58
rs.fullstory.com
United States
18.66.102.127
unknown
United States
169.150.247.38
cs-iubenda.b-cdn.net
United States
142.250.185.226
cm.g.doubleclick.net
United States
192.168.2.5
unknown
unknown
169.150.247.37
hits-iubenda.b-cdn.net
United States
18.158.205.16
risk.clearbit.com
United States
151.101.65.140
unknown
United States
84.17.46.49
cdn-iubenda.b-cdn.net
United Kingdom
18.245.46.44
tag.demandbase.com
United States
35.71.131.137
insight.adsrvr.org
United States
3.33.220.150
unknown
United States
34.96.71.22
s.dsp-prod.demandbase.com
United States
104.244.42.131
s.twitter.com
United States
104.18.36.155
unknown
United States
34.233.88.180
unknown
United States
76.223.31.44
clientstream-ga.launchdarkly.com
United States
239.255.255.250
unknown
Reserved
3.127.196.46
marketo.clearbit.com
United States
185.89.211.84
unknown
Germany
134.213.193.62
813-mam-392.mktoresp.com
Ireland
84.17.46.53
unknown
United Kingdom
18.245.46.79
tag.clearbitscripts.com
United States
199.232.188.157
platform.twitter.map.fastly.net
United States
34.117.162.98
pixel.byspotify.com
United States
35.244.174.68
id.rlcdn.com
United States
52.223.40.198
match.adsrvr.org
United States
54.85.66.138
partners-alb-1113315349.us-east-1.elb.amazonaws.com
United States
142.250.185.78
analytics.google.com
United States
54.160.25.132
proxy-rr.us-east-1.aws.found.io
United States
74.125.71.154
stats.g.doubleclick.net
United States
18.172.103.101
dg2iu7dxxehbo.cloudfront.net
United States
172.64.151.101
dsum-sec.casalemedia.com
United States
64.233.184.157
unknown
United States
157.240.0.6
unknown
United States
34.111.208.231
ibc-flow.techtarget.com
United States
142.250.185.164
unknown
United States
150.171.28.10
ax-0001.ax-msedge.net
United States
142.250.74.194
td.doubleclick.net
United States
18.173.205.104
tag-logger.demandbase.com
United States
142.250.186.132
unknown
United States
13.35.58.40
unknown
United States
13.35.58.122
lift-ai-js.marketlinc.com
United States
157.240.252.35
star-mini.c10r.facebook.com
United States
18.66.102.85
api.company-target.com
United States
52.206.204.68
events.launchdarkly.com
United States
151.101.1.140
dualstack.reddit.map.fastly.net
United States
18.153.4.44
global-v4.clearbit.com
United States
35.186.224.24
edge-web.dual-gslb.spotify.com
United States
157.240.251.9
scontent.xx.fbcdn.net
United States
185.89.210.90
ib.anycast.adnxs.com
Germany
35.201.112.186
edge.fullstory.com
United States
142.250.185.130
unknown
United States
34.192.69.139
marketlinc-prod-2024.us-east-1.elasticbeanstalk.com
United States
151.101.129.140
unknown
United States
157.240.251.35
unknown
United States
142.250.186.66
googleads.g.doubleclick.net
United States
There are 50 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843
https://www.elastic.co/security-labs/elevate-your-threat-hunting?utm_source=organic-social&utm_medium=twitter&utm_campaign=esl:_threat_research_esl_blog_post&utm_content=15000445268&linkId=626315843
https://cloud.elastic.co/registration?cta=cloud-registration&tech=trial&plcmt=navigation&pg=security-labs
https://cloud.elastic.co/registration?cta=cloud-registration&tech=trial&plcmt=navigation&pg=security-labs
https://cloud.elastic.co/registration?cta=cloud-registration&tech=trial&plcmt=navigation&pg=security-labs
https://cloud.elastic.co/registration?cta=cloud-registration&tech=trial&plcmt=navigation&pg=security-labs
https://cloud.elastic.co/login?cta=cloud-registration&pg=security-labs&plcmt=navigation&tech=trial
https://cloud.elastic.co/login?cta=cloud-registration&pg=security-labs&plcmt=navigation&tech=trial
https://cloud.elastic.co/login?cta=cloud-registration&pg=security-labs&plcmt=navigation&tech=trial
There are 3 hidden doms, click here to show them.