IOC Report
https://na2.docusign.net/Signing/EmailStart.aspx?a=c9ecb8ea-b2b1-44a6-a484-9d091a5893cc&etti=24&acct=5a1b9816-6da5-4df9-bd97-2117ae60a146&er=1c061c54-2a9a-4176-bd31-3d7a21945a0e

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:09:03 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:09:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:09:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:09:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 13:09:02 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 146
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (6455)
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (21847)
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (16718)
downloaded
Chrome Cache Entry: 152
Unicode text, UTF-8 text, with very long lines (65452)
downloaded
Chrome Cache Entry: 155
PNG image data, 79 x 79, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (57931)
dropped
Chrome Cache Entry: 160
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (631), with no line terminators
downloaded
Chrome Cache Entry: 166
Unicode text, UTF-8 text, with very long lines (30984)
dropped
Chrome Cache Entry: 167
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (19766)
dropped
Chrome Cache Entry: 170
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 172
Unicode text, UTF-8 text, with very long lines (63087)
downloaded
Chrome Cache Entry: 174
Unicode text, UTF-8 text, with very long lines (16888)
downloaded
Chrome Cache Entry: 175
ASCII text
downloaded
Chrome Cache Entry: 176
Unicode text, UTF-8 text, with very long lines (65439)
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 178
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (12839)
downloaded
Chrome Cache Entry: 185
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 187
ASCII text, with very long lines (7965)
dropped
Chrome Cache Entry: 190
Unicode text, UTF-8 text, with very long lines (13863)
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 195
HTML document, ASCII text, with very long lines (334), with CRLF line terminators
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (65446)
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (17950)
downloaded
Chrome Cache Entry: 208
Web Open Font Format (Version 2), TrueType, length 29516, version 1.0
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (17329)
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (46070)
downloaded
Chrome Cache Entry: 214
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 215
Web Open Font Format (Version 2), TrueType, length 31468, version 1.0
downloaded
Chrome Cache Entry: 216
ASCII text, with very long lines (65440)
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (65448)
dropped
Chrome Cache Entry: 219
JSON data
dropped
Chrome Cache Entry: 221
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 225
ASCII text, with very long lines (27974)
downloaded
Chrome Cache Entry: 226
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 227
Unicode text, UTF-8 text, with very long lines (65169)
downloaded
Chrome Cache Entry: 228
Unicode text, UTF-8 text, with very long lines (65446)
dropped
Chrome Cache Entry: 229
Unicode text, UTF-8 text, with very long lines (65433)
downloaded
Chrome Cache Entry: 234
ASCII text
dropped
Chrome Cache Entry: 236
ASCII text, with very long lines (20560)
downloaded
Chrome Cache Entry: 237
GIF image data, version 89a, 145 x 60
dropped
Chrome Cache Entry: 238
ASCII text, with very long lines (9667)
downloaded
Chrome Cache Entry: 239
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 240
ASCII text, with very long lines (65438)
downloaded
Chrome Cache Entry: 242
ASCII text, with very long lines (9377)
downloaded
Chrome Cache Entry: 244
ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 245
ASCII text, with very long lines (52240)
downloaded
Chrome Cache Entry: 252
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 254
HTML document, ASCII text, with very long lines (65448)
downloaded
Chrome Cache Entry: 255
Web Open Font Format, TrueType, length 13780, version 1.0
downloaded
Chrome Cache Entry: 256
ASCII text, with very long lines (65447)
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (32844)
downloaded
Chrome Cache Entry: 259
ASCII text, with very long lines (30012)
dropped
Chrome Cache Entry: 260
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 262
Web Open Font Format, CFF, length 33752, version 0.0
downloaded
Chrome Cache Entry: 263
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 264
ASCII text, with very long lines (11612)
dropped
There are 61 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://na2.docusign.net/Signing/EmailStart.aspx?a=c9ecb8ea-b2b1-44a6-a484-9d091a5893cc&etti=24&acct=5a1b9816-6da5-4df9-bd97-2117ae60a146&er=1c061c54-2a9a-4176-bd31-3d7a21945a0e
https://na2.docusign.net/Signing/?ti=bea3fce18888407e9923b6302fe013bd

Domains

Name
IP
Malicious
cdn.optimizely.com
104.18.66.57
www.google.com
142.250.185.196
api.mixpanel.com
130.211.34.183
arya-1323461286.us-west-2.elb.amazonaws.com
34.223.160.188
a.docusign.com
unknown
docucdn-a.akamaihd.net
unknown
na2.docusign.net
unknown

IPs

IP
Domain
Country
Malicious
142.250.184.195
unknown
United States
142.250.74.202
unknown
United States
34.223.160.188
arya-1323461286.us-west-2.elb.amazonaws.com
United States
104.18.66.57
cdn.optimizely.com
United States
162.248.185.182
unknown
United States
1.1.1.1
unknown
Australia
130.211.34.183
api.mixpanel.com
United States
172.217.18.4
unknown
United States
192.168.2.16
unknown
unknown
142.250.185.238
unknown
United States
107.178.240.159
unknown
United States
239.255.255.250
unknown
Reserved
142.250.185.196
www.google.com
United States
2.19.126.140
unknown
European Union
172.217.18.110
unknown
United States
95.101.54.217
unknown
European Union
142.250.186.99
unknown
United States
66.102.1.84
unknown
United States
There are 8 hidden IPs, click here to show them.