IOC Report
https://1drv.ms/o/c/3e563d3fb2a98d1c/Emlo5KUbYYNEvKtIF-7SS0EBYSeT3hOOGuv_MbeT-n2y4g?e=HPjqUn

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 11:09:46 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 11:09:46 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 11:09:46 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 11:09:46 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 11:09:45 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 254
ASCII text, with very long lines (5949), with no line terminators
downloaded
Chrome Cache Entry: 256
ASCII text, with very long lines (38617), with no line terminators
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (31803)
dropped
Chrome Cache Entry: 259
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 264
JSON data
downloaded
Chrome Cache Entry: 268
HTML document, ASCII text, with very long lines (337), with CRLF line terminators
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (57788)
dropped
Chrome Cache Entry: 272
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 273
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 277
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 279
ASCII text, with very long lines (60197)
dropped
Chrome Cache Entry: 280
JSON data
downloaded
Chrome Cache Entry: 282
PNG image data, 222 x 204, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 284
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 287
ASCII text, with very long lines (29173), with no line terminators
dropped
Chrome Cache Entry: 288
PNG image data, 102 x 102, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 289
ASCII text, with very long lines (32038)
dropped
Chrome Cache Entry: 292
JSON data
downloaded
Chrome Cache Entry: 293
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 296
Unicode text, UTF-8 text, with very long lines (28488)
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (27024), with CRLF line terminators
downloaded
Chrome Cache Entry: 299
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 304
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 307
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 309
ASCII text, with very long lines (63604)
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (616)
downloaded
Chrome Cache Entry: 316
ASCII text, with very long lines (41569), with no line terminators
downloaded
Chrome Cache Entry: 318
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 320
ASCII text, with very long lines (35936), with CRLF line terminators
downloaded
Chrome Cache Entry: 322
Unicode text, UTF-8 text, with very long lines (65340), with no line terminators
dropped
Chrome Cache Entry: 324
XML 1.0 document, ASCII text
downloaded
Chrome Cache Entry: 328
JSON data
dropped
Chrome Cache Entry: 330
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 331
ASCII text, with very long lines (3527), with no line terminators
downloaded
Chrome Cache Entry: 333
ASCII text, with very long lines (627)
dropped
Chrome Cache Entry: 335
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 337
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 340
ASCII text, with very long lines (64817)
downloaded
Chrome Cache Entry: 341
ASCII text, with very long lines (50758)
dropped
Chrome Cache Entry: 343
ASCII text, with very long lines (1922), with no line terminators
dropped
Chrome Cache Entry: 344
JSON data
downloaded
Chrome Cache Entry: 345
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 346
ASCII text, with very long lines (61584), with CRLF line terminators
dropped
Chrome Cache Entry: 350
Unicode text, UTF-8 text, with very long lines (58392)
downloaded
Chrome Cache Entry: 353
ASCII text, with very long lines (672)
dropped
Chrome Cache Entry: 354
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 355
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 359
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 360
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 363
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 364
JSON data
dropped
Chrome Cache Entry: 368
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 374
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 376
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 379
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 380
Unicode text, UTF-8 (with BOM) text, with very long lines (18992), with CRLF line terminators
dropped
Chrome Cache Entry: 381
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 385
PNG image data, 452 x 444, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 386
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 387
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 388
PNG image data, 31 x 70, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 389
ASCII text, with very long lines (47531)
dropped
Chrome Cache Entry: 392
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 395
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
dropped
Chrome Cache Entry: 396
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
dropped
Chrome Cache Entry: 397
ASCII text, with very long lines (59425)
downloaded
Chrome Cache Entry: 398
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
Chrome Cache Entry: 400
ASCII text, with very long lines (1917), with no line terminators
downloaded
Chrome Cache Entry: 401
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 402
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 403
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 407
ASCII text, with very long lines (58562)
dropped
Chrome Cache Entry: 408
Unicode text, UTF-8 text, with very long lines (56385)
dropped
Chrome Cache Entry: 409
ASCII text, with very long lines (64762), with CRLF line terminators
downloaded
Chrome Cache Entry: 411
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 417
ASCII text, with very long lines (1837)
downloaded
Chrome Cache Entry: 418
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 425
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
dropped
Chrome Cache Entry: 426
Web Open Font Format, TrueType, length 3052, version 4.-22282
downloaded
Chrome Cache Entry: 427
ASCII text, with very long lines (4615)
dropped
Chrome Cache Entry: 429
PNG image data, 1920 x 1080, 8-bit/color RGB, non-interlaced
downloaded
Chrome Cache Entry: 430
Web Open Font Format, TrueType, length 151924, version 0.0
downloaded
Chrome Cache Entry: 434
PNG image data, 82 x 258, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 438
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 439
ASCII text, with very long lines (6620), with no line terminators
downloaded
Chrome Cache Entry: 440
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 442
ASCII text, with very long lines (6068), with no line terminators
downloaded
Chrome Cache Entry: 446
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 450
JSON data
dropped
Chrome Cache Entry: 451
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 453
ASCII text, with very long lines (2936)
downloaded
Chrome Cache Entry: 457
ASCII text, with very long lines (20082), with no line terminators
downloaded
Chrome Cache Entry: 460
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 462
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 463
ASCII text, with very long lines (11252)
downloaded
Chrome Cache Entry: 466
ASCII text, with very long lines (20946), with CRLF line terminators
downloaded
Chrome Cache Entry: 467
ASCII text, with very long lines (24306), with CRLF line terminators
downloaded
Chrome Cache Entry: 469
ASCII text, with very long lines (33654)
dropped
Chrome Cache Entry: 470
ASCII text, with very long lines (14666), with no line terminators
dropped
Chrome Cache Entry: 472
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 473
ASCII text, with very long lines (3379)
downloaded
Chrome Cache Entry: 474
ASCII text, with very long lines (65437)
downloaded
Chrome Cache Entry: 477
ASCII text, with very long lines (8369), with no line terminators
downloaded
Chrome Cache Entry: 479
ASCII text, with very long lines (22010)
dropped
Chrome Cache Entry: 480
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 485
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 486
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 487
ASCII text, with very long lines (11667), with no line terminators
downloaded
Chrome Cache Entry: 488
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 489
ASCII text, with very long lines (65447)
downloaded
Chrome Cache Entry: 492
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 493
Unicode text, UTF-8 text, with very long lines (12695)
dropped
Chrome Cache Entry: 496
Unicode text, UTF-8 text, with very long lines (1592)
downloaded
Chrome Cache Entry: 497
HTML document, ASCII text, with very long lines (5060)
downloaded
Chrome Cache Entry: 499
ASCII text, with very long lines (20116), with no line terminators
dropped
Chrome Cache Entry: 501
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 502
ASCII text, with very long lines (7694)
downloaded
Chrome Cache Entry: 506
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 507
ASCII text, with very long lines (14762)
downloaded
Chrome Cache Entry: 509
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 510
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 511
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 512
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 513
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 516
PNG image data, 280 x 60, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 518
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 523
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 524
ASCII text, with very long lines (41116)
downloaded
Chrome Cache Entry: 527
ASCII text, with very long lines (30497), with no line terminators
downloaded
Chrome Cache Entry: 529
MS Windows cursor resource - 1 icon, 32x32, hotspot @16x16
downloaded
Chrome Cache Entry: 531
HTML document, Unicode text, UTF-8 (with BOM) text, with very long lines (4207), with CRLF line terminators
dropped
Chrome Cache Entry: 532
ASCII text, with very long lines (2224), with no line terminators
dropped
Chrome Cache Entry: 535
ASCII text, with very long lines (65457)
dropped
Chrome Cache Entry: 538
PNG image data, 2 x 2, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 539
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 540
ASCII text, with very long lines (32011), with CRLF line terminators
dropped
Chrome Cache Entry: 541
JSON data
dropped
Chrome Cache Entry: 543
ASCII text, with very long lines (7708)
downloaded
There are 136 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://1drv.ms/o/c/3e563d3fb2a98d1c/Emlo5KUbYYNEvKtIF-7SS0EBYSeT3hOOGuv_MbeT-n2y4g?e=HPjqUn
malicious
https://mohrhydrokultur.adaradocumentfolder.top/&redirect=106a29b3e748b6cd676b5dfdea5376c1sec&uid=f253efe302d32ab264a76e0ce65be769671a39630f4bd
malicious
https://onedrive.live.com/personal/3e563d3fb2a98d1c/_layouts/15/Doc.aspx?sourcedoc=%7Ba5e46869-611b-4483-bcab-4817eed24b41%7D&action=default&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy8zZTU2M2QzZmIyYTk4ZDFjL0VtbG81S1ViWVlORXZLdElGLTdTUzBFQllTZVQzaE9PR3V2X01iZVQtbjJ5NGc_ZT1IUGpxVW4&slrid=ba095da1-10b3-a000-2020-f8c86b0ebf8e&originalPath=aHR0cHM6Ly8xZHJ2Lm1zL28vYy8zZTU2M2QzZmIyYTk4ZDFjL0VtbG81S1ViWVlORXZLdElGLTdTUzBFQllTZVQzaE9PR3V2X01iZVQtbjJ5NGc_cnRpbWU9QmY3LXdDVDAzRWc&CID=41ae2d81-d6a2-4d5a-bc24-bef3a325b0a4&_SRM=0:G:39
malicious
https://mohrhydrokultur.adaradocumentfolder.top/&step=f253efe302d32ab264a76e0ce65be769671a397785458verify&uid=671a39778547a
malicious
https://mohrhydrokultur.adaradocumentfolder.top/&redirect=d9e0656dd064d478791a812104e166b4c7e5a6d4main&uid=f253efe302d32ab264a76e0ce65be769671a3949b9c98
malicious
https://mohrhydrokultur.adaradocumentfolder.top/
https://onedrive.live.com/view.aspx?resid=3E563D3FB2A98D1C!sa5e46869611b4483bcab4817eed24b41&migratedtospo=true&redeem=aHR0cHM6Ly8xZHJ2Lm1zL28vYy8zZTU2M2QzZmIyYTk4ZDFjL0VtbG81S1ViWVlORXZLdElGLTdTUzBFQllTZVQzaE9PR3V2X01iZVQtbjJ5NGc_ZT1IUGpxVW4&wd=target%28Quick%20Notes.one%7C087bc1e6-1071-4924-97c8-9c06613cae25%2FMohr%20HYDROKULTUR%7Ca61e7bae-8de5-48ea-9575-302832b9824d%2F%29&wdorigin=NavigationUrl

Domains

Name
IP
Malicious
mohrhydrokultur.adaradocumentfolder.top
104.21.45.155
malicious
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
a.nel.cloudflare.com
35.190.80.1
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
s-part-0017.t-0009.t-msedge.net
13.107.246.45
wac-0003.wac-dc-msedge.net
52.108.10.12
s-part-0039.t-0009.t-msedge.net
13.107.246.67
1drv.ms
13.107.42.12
s-part-0029.t-0009.t-msedge.net
13.107.246.57
dual-spov-0006.spov-msedge.net
13.107.139.11
wac-0003.wac-msedge.net
52.108.9.12
bg.microsoft.map.fastly.net
199.232.214.172
code.jquery.com
151.101.66.137
sni1gl.wpc.upsiloncdn.net
152.199.21.175
challenges.cloudflare.com
104.18.95.41
www.google.com
142.250.185.196
sni1gl.wpc.sigmacdn.net
152.199.21.175
fa000000012.resources.office.net
unknown
fa000000111.resources.office.net
unknown
fa000000128.resources.office.net
unknown
augloop.office.com
unknown
ajax.aspnetcdn.com
unknown
m365cdn.nel.measure.office.net
unknown
fa000000110.resources.office.net
unknown
onenoteonline.nel.measure.office.net
unknown
aadcdn.msauthimages.net
unknown
common.online.office.com
unknown
fa000000138.resources.office.net
unknown
onedrive.live.com
unknown
westeurope-pa00.augloop.office.com
unknown
login.microsoftonline.com
unknown
www.onenote.com
unknown
spoprod-a.akamaihd.net
unknown
messaging.engagement.office.com
unknown
fa000000096.resources.office.net
unknown
There are 25 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.21.45.155
mohrhydrokultur.adaradocumentfolder.top
United States
malicious
13.107.6.156
unknown
United States
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
192.168.2.7
unknown
unknown
192.168.2.4
unknown
unknown
192.168.2.6
unknown
unknown
52.108.9.12
wac-0003.wac-msedge.net
United States
151.101.130.137
unknown
United States
192.168.2.5
unknown
unknown
52.108.10.12
wac-0003.wac-dc-msedge.net
United States
52.109.89.117
unknown
United States
151.101.66.137
code.jquery.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
23.38.98.97
unknown
United States
23.38.98.96
unknown
United States
13.107.139.11
dual-spov-0006.spov-msedge.net
United States
1.1.1.1
unknown
Australia
104.18.95.41
challenges.cloudflare.com
United States
52.111.236.4
unknown
United States
142.250.185.238
unknown
United States
20.190.159.75
unknown
United States
13.107.42.12
1drv.ms
United States
13.107.253.72
s-part-0044.t-0009.fb-t-msedge.net
United States
40.126.31.73
unknown
United States
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
152.199.21.175
sni1gl.wpc.upsiloncdn.net
United States
52.111.243.13
unknown
United States
172.67.216.102
unknown
United States
184.28.90.96
unknown
United States
152.199.19.160
unknown
United States
216.58.206.74
unknown
United States
40.126.32.140
unknown
United States
23.38.98.102
unknown
United States
13.107.246.67
s-part-0039.t-0009.t-msedge.net
United States
142.250.186.174
unknown
United States
23.38.98.104
unknown
United States
192.168.2.17
unknown
unknown
104.18.94.41
unknown
United States
52.111.236.17
unknown
United States
172.217.23.106
unknown
United States
52.182.143.211
unknown
United States
64.233.166.84
unknown
United States
2.16.164.49
unknown
European Union
2.19.126.143
unknown
European Union
20.42.73.28
unknown
United States
142.250.186.132
unknown
United States
104.102.55.235
unknown
United States
23.38.98.111
unknown
United States
104.208.16.95
unknown
United States
52.113.194.132
unknown
United States
13.107.246.57
s-part-0029.t-0009.t-msedge.net
United States
142.250.186.163
unknown
United States
216.58.206.67
unknown
United States
13.107.253.45
s-part-0017.t-0009.fb-t-msedge.net
United States
20.42.65.94
unknown
United States
2.16.168.12
unknown
European Union
52.108.8.12
unknown
United States
52.108.11.12
unknown
United States
192.168.2.10
unknown
unknown
184.28.89.164
unknown
United States
88.221.110.248
unknown
European Union
There are 52 hidden IPs, click here to show them.