IOC Report
https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ff

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:13:47 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:13:47 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:13:47 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:13:47 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 12:13:47 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 143
JSON data
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 146
JSON data
dropped
Chrome Cache Entry: 147
Unicode text, UTF-8 text, with very long lines (18223)
dropped
Chrome Cache Entry: 148
Unicode text, UTF-8 text, with very long lines (13330), with no line terminators
downloaded
Chrome Cache Entry: 149
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (3457)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 153
Web Open Font Format (Version 2), TrueType, length 32036, version 1.0
downloaded
Chrome Cache Entry: 155
JSON data
dropped
Chrome Cache Entry: 156
Web Open Font Format (Version 2), TrueType, length 31852, version 1.0
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 160
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 165
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 166
Web Open Font Format (Version 2), CFF, length 35648, version 1.0
downloaded
Chrome Cache Entry: 167
Unicode text, UTF-8 text, with very long lines (2495)
dropped
Chrome Cache Entry: 168
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
dropped
Chrome Cache Entry: 170
ASCII text, with very long lines (4712), with no line terminators
downloaded
Chrome Cache Entry: 171
Web Open Font Format (Version 2), TrueType, length 50436, version 1.0
downloaded
Chrome Cache Entry: 172
Web Open Font Format (Version 2), CFF, length 33448, version 1.0
downloaded
Chrome Cache Entry: 175
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 177
JSON data
dropped
Chrome Cache Entry: 178
ASCII text, with very long lines (1490)
dropped
Chrome Cache Entry: 181
JSON data
dropped
Chrome Cache Entry: 182
Web Open Font Format (Version 2), TrueType, length 47828, version 1.0
downloaded
Chrome Cache Entry: 183
JSON data
downloaded
Chrome Cache Entry: 184
JSON data
dropped
Chrome Cache Entry: 185
ASCII text, with very long lines (11231)
dropped
Chrome Cache Entry: 186
ASCII text, with very long lines (51248)
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (22445)
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (29256), with no line terminators
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (42611)
dropped
Chrome Cache Entry: 195
ASCII text, with very long lines (4730), with no line terminators
dropped
Chrome Cache Entry: 197
ASCII text, with very long lines (42611)
downloaded
Chrome Cache Entry: 198
Web Open Font Format (Version 2), TrueType, length 32424, version 1.0
downloaded
Chrome Cache Entry: 204
JSON data
dropped
Chrome Cache Entry: 208
JSON data
downloaded
Chrome Cache Entry: 209
Unicode text, UTF-8 text, with very long lines (10562), with no line terminators
dropped
Chrome Cache Entry: 211
Web Open Font Format (Version 2), TrueType, length 31936, version 1.0
downloaded
Chrome Cache Entry: 212
Web Open Font Format (Version 2), TrueType, length 79792, version 1.0
downloaded
Chrome Cache Entry: 214
JSON data
downloaded
Chrome Cache Entry: 216
HTML document, ASCII text, with very long lines (1419), with no line terminators
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 219
JSON data
dropped
Chrome Cache Entry: 220
ASCII text, with very long lines (902), with no line terminators
dropped
Chrome Cache Entry: 222
Unicode text, UTF-8 text, with very long lines (2258)
downloaded
Chrome Cache Entry: 223
HTML document, ASCII text, with very long lines (1093)
downloaded
Chrome Cache Entry: 224
ASCII text, with very long lines (9198)
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 226
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 227
gzip compressed data, max compression, from Unix, original size modulo 2^32 71723
dropped
Chrome Cache Entry: 228
JSON data
downloaded
Chrome Cache Entry: 230
HTML document, ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 231
ASCII text, with very long lines (1303), with no line terminators
downloaded
Chrome Cache Entry: 232
Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
dropped
Chrome Cache Entry: 233
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 234
JSON data
downloaded
Chrome Cache Entry: 235
Web Open Font Format (Version 2), TrueType, length 43516, version 1.0
downloaded
Chrome Cache Entry: 236
ASCII text, with very long lines (3835)
dropped
Chrome Cache Entry: 237
ASCII text, with very long lines (64749)
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (3835)
downloaded
Chrome Cache Entry: 240
ASCII text, with very long lines (19217), with no line terminators
dropped
Chrome Cache Entry: 241
JSON data
dropped
Chrome Cache Entry: 242
ASCII text, with very long lines (1568), with no line terminators
downloaded
Chrome Cache Entry: 244
JSON data
downloaded
Chrome Cache Entry: 245
JSON data
downloaded
Chrome Cache Entry: 246
JSON data
downloaded
Chrome Cache Entry: 247
Web Open Font Format (Version 2), CFF, length 24260, version 1.0
downloaded
Chrome Cache Entry: 251
JSON data
dropped
Chrome Cache Entry: 252
HTML document, ASCII text, with very long lines (794), with no line terminators
downloaded
Chrome Cache Entry: 257
gzip compressed data, from Unix, original size modulo 2^32 3516
dropped
Chrome Cache Entry: 258
ASCII text, with very long lines (63670)
dropped
Chrome Cache Entry: 260
Web Open Font Format (Version 2), CFF, length 31448, version 1.0
downloaded
Chrome Cache Entry: 261
JSON data
downloaded
Chrome Cache Entry: 263
JSON data
downloaded
Chrome Cache Entry: 267
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 268
ASCII text, with very long lines (41360), with no line terminators
dropped
There are 74 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ff
https://app.pandadoc.com/document/v2?token=69b8ae0059c2551a9a27ed1b65653c1a0b5ee1ff

Domains

Name
IP
Malicious
js.hs-banner.com
104.18.40.240
d3m3a7p0ze7hmq.cloudfront.net
143.204.215.16
dart.l.doubleclick.net
142.250.184.198
d31uqz37bvu6i7.cloudfront.net
13.32.118.85
x4whrmz.x.incapdns.net
45.223.20.103
ax-0001.ax-dc-msedge.net
150.171.30.10
prom-fe-gw.production.pandadoc.com
34.211.201.77
sentry.infrastructure.pandadoc.com
35.162.177.163
ad.doubleclick.net
142.250.184.230
grafana-agent-faro.production.pandadoc.com
54.189.220.132
js.hs-analytics.net
104.17.175.201
adservice.google.com
142.250.186.130
ax-0001.ax-msedge.net
150.171.27.10
bm2ydo9.impervadns.net
45.223.20.103
d296je7bbdd650.cloudfront.net
99.86.8.175
js-na1.hs-scripts.com
104.16.137.209
track.hubspot.com
104.16.117.116
googleads.g.doubleclick.net
216.58.206.34
www.google.com
142.250.186.164
td.doubleclick.net
142.250.185.226
api.segment.io
34.223.74.168
cdn.cookielaw.org
104.18.86.42
geolocation.onetrust.com
172.64.155.119
ip2c.org
188.68.242.180
api.pandadoc.com
unknown
use.typekit.net
unknown
app.pandadoc.com
unknown
cdn.segment.com
unknown
12370631.fls.doubleclick.net
unknown
There are 19 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
143.204.215.16
d3m3a7p0ze7hmq.cloudfront.net
United States
216.58.212.168
unknown
United States
142.250.186.68
unknown
United States
18.245.175.26
unknown
United States
54.189.220.132
grafana-agent-faro.production.pandadoc.com
United States
142.250.186.130
adservice.google.com
United States
192.168.2.17
unknown
unknown
216.58.206.34
googleads.g.doubleclick.net
United States
13.32.118.18
unknown
United States
2.19.126.206
unknown
European Union
142.250.185.226
td.doubleclick.net
United States
74.125.206.84
unknown
United States
142.250.181.238
unknown
United States
104.18.40.240
js.hs-banner.com
United States
104.18.32.137
unknown
United States
45.223.20.103
x4whrmz.x.incapdns.net
United States
150.171.30.10
ax-0001.ax-dc-msedge.net
United States
172.217.23.98
unknown
United States
104.16.160.168
unknown
United States
188.68.242.180
ip2c.org
Poland
142.250.186.136
unknown
United States
13.32.118.85
d31uqz37bvu6i7.cloudfront.net
United States
35.162.177.163
sentry.infrastructure.pandadoc.com
United States
35.155.246.37
unknown
United States
142.250.184.230
ad.doubleclick.net
United States
104.18.87.42
unknown
United States
1.1.1.1
unknown
Australia
142.250.184.198
dart.l.doubleclick.net
United States
104.16.137.209
js-na1.hs-scripts.com
United States
34.223.74.168
api.segment.io
United States
172.64.155.119
geolocation.onetrust.com
United States
150.171.27.10
ax-0001.ax-msedge.net
United States
104.17.175.201
js.hs-analytics.net
United States
239.255.255.250
unknown
Reserved
142.250.185.196
unknown
United States
104.16.141.209
unknown
United States
142.250.185.195
unknown
United States
142.250.186.164
www.google.com
United States
99.86.8.175
d296je7bbdd650.cloudfront.net
United States
34.211.201.77
prom-fe-gw.production.pandadoc.com
United States
104.18.86.42
cdn.cookielaw.org
United States
172.217.16.195
unknown
United States
104.16.117.116
track.hubspot.com
United States
172.217.16.198
unknown
United States
There are 34 hidden IPs, click here to show them.