IOC Report
https://aka.ms/JoinTeamsMeeting?omkt=en-US

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 117
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 118
PNG image data, 481 x 447, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 119
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
dropped
Chrome Cache Entry: 120
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 121
PNG image data, 700 x 247, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 122
XML 1.0 document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 123
ASCII text, with very long lines (3637)
downloaded
Chrome Cache Entry: 124
PNG image data, 700 x 258, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (61463)
dropped
Chrome Cache Entry: 126
HTML document, ASCII text, with very long lines (3450), with CRLF line terminators
downloaded
Chrome Cache Entry: 127
JSON data
downloaded
Chrome Cache Entry: 128
PNG image data, 481 x 447, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 129
Unicode text, UTF-8 text, with very long lines (64241)
downloaded
Chrome Cache Entry: 130
Unicode text, UTF-8 text, with very long lines (64241)
downloaded
Chrome Cache Entry: 131
PNG image data, 700 x 242, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 132
PNG image data, 700 x 247, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 133
ASCII text, with very long lines (2824)
downloaded
Chrome Cache Entry: 134
PNG image data, 700 x 166, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 135
Unicode text, UTF-8 (with BOM) text, with very long lines (5167), with no line terminators
downloaded
Chrome Cache Entry: 136
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 137
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 138
PNG image data, 700 x 266, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 139
ASCII text, with very long lines (2674)
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (503)
downloaded
Chrome Cache Entry: 141
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 142
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 143
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 141866
downloaded
Chrome Cache Entry: 144
JSON data
dropped
Chrome Cache Entry: 145
ASCII text, with very long lines (65398)
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (65398)
dropped
Chrome Cache Entry: 147
Unicode text, UTF-8 text, with very long lines (45900)
downloaded
Chrome Cache Entry: 148
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 149
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 17287
downloaded
Chrome Cache Entry: 150
PNG image data, 20 x 17, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (2230), with no line terminators
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (11631)
downloaded
Chrome Cache Entry: 153
PNG image data, 1920 x 1080, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 154
PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 155
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 156
ASCII text, with very long lines (65394)
dropped
Chrome Cache Entry: 157
ASCII text, with very long lines (3637)
dropped
Chrome Cache Entry: 158
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 159
PNG image data, 297 x 166, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 160
PNG image data, 700 x 242, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 161
JSON data
dropped
Chrome Cache Entry: 162
ASCII text, with very long lines (52565)
dropped
Chrome Cache Entry: 163
Unicode text, UTF-8 (with BOM) text, with very long lines (65513), with no line terminators
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (4873), with no line terminators
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (65460)
dropped
Chrome Cache Entry: 166
ASCII text, with very long lines (2824)
dropped
Chrome Cache Entry: 167
Unicode text, UTF-8 text, with very long lines (45900)
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (34235), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 169
PNG image data, 297 x 166, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 170
PNG image data, 17 x 15, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 171
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 172
JSON data
dropped
Chrome Cache Entry: 173
JSON data
dropped
Chrome Cache Entry: 174
Web Open Font Format (Version 2), TrueType, length 36748, version 0.0
downloaded
Chrome Cache Entry: 175
Unicode text, UTF-8 (with BOM) text, with very long lines (26071), with no line terminators
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (65460)
downloaded
Chrome Cache Entry: 177
Unicode text, UTF-8 (with BOM) text, with very long lines (10387), with no line terminators
downloaded
Chrome Cache Entry: 178
ASCII text, with very long lines (52565)
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (1789), with no line terminators
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (4370), with no line terminators
downloaded
Chrome Cache Entry: 181
PNG image data, 17 x 15, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 182
ASCII text, with very long lines (2974), with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (65451)
dropped
Chrome Cache Entry: 184
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 185
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 186
Unicode text, UTF-8 (with BOM) text, with very long lines (12305), with no line terminators
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (11631)
dropped
Chrome Cache Entry: 188
PNG image data, 32 x 32, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (65394)
downloaded
Chrome Cache Entry: 190
PNG image data, 216 x 46, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (2674)
dropped
Chrome Cache Entry: 192
ASCII text, with very long lines (30237)
dropped
Chrome Cache Entry: 193
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 194
JSON data
dropped
Chrome Cache Entry: 195
ASCII text, with very long lines (6125), with no line terminators
downloaded
Chrome Cache Entry: 196
PNG image data, 1920 x 1080, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 197
ASCII text, with very long lines (780), with no line terminators
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (42133)
downloaded
Chrome Cache Entry: 199
PNG image data, 700 x 266, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 200
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 201
JSON data
dropped
Chrome Cache Entry: 202
JSON data
dropped
Chrome Cache Entry: 203
Unicode text, UTF-8 text, with very long lines (61463)
downloaded
Chrome Cache Entry: 204
PNG image data, 262 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 205
PNG image data, 594 x 332, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 206
PNG image data, 700 x 166, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 207
Web Open Font Format (Version 2), TrueType, length 29888, version 0.0
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (503)
dropped
Chrome Cache Entry: 209
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 17287
dropped
Chrome Cache Entry: 210
PNG image data, 700 x 258, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 211
JSON data
dropped
Chrome Cache Entry: 212
PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 213
Web Open Font Format, TrueType, length 26288, version 0.0
downloaded
Chrome Cache Entry: 214
PNG image data, 20 x 17, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 215
JSON data
dropped
Chrome Cache Entry: 216
PNG image data, 262 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (30237)
downloaded
Chrome Cache Entry: 218
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 219
ASCII text, with very long lines (42133)
dropped
Chrome Cache Entry: 220
ASCII text, with very long lines (34235), with CRLF, LF line terminators
dropped
Chrome Cache Entry: 221
ASCII text, with very long lines (3385), with no line terminators
downloaded
There are 96 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2436 --field-trial-handle=2396,i,7882780584959775941,9591664147972054668,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://aka.ms/JoinTeamsMeeting?omkt=en-US"

URLs

Name
IP
Malicious
https://aka.ms/JoinTeamsMeeting?omkt=en-US
https://mem.gfx.ms/meversion?partner=SMCConvergence&market=en-us&uhf=1
13.107.253.45
http://knockoutjs.com/
unknown
https://login.microsoftonline.com
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://github.com/douglascrockford/JSON-js
unknown
https://login.windows-ppe.net
unknown
https://mem.gfx.ms/scripts/me/MeControl/10.24228.4/en-US/meCore.min.js
13.107.253.45
https://aka.ms/JoinTeamsMeeting?omkt=en-US
104.119.110.121
http://github.com/requirejs/almond/LICENSE
unknown
https://mem.gfx.ms/scripts/me/MeControl/10.24228.4/en-US/meBoot.min.js
13.107.253.45
https://aadcdn.msftauth.net/shared/1.0/content/js/FetchSessions_Core_9mEr1-U6IfYSYEIq9V-gwA2.js
152.199.21.175
https://js.monitor.azure.com/scripts/c/ms.shared.analytics.mectrl-3.gbl.min.js
13.107.253.45
There are 2 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
s-part-0016.t-0009.t-msedge.net
13.107.246.44
bg.microsoft.map.fastly.net
199.232.214.172
s-part-0044.t-0009.fb-t-msedge.net
13.107.253.72
s-part-0023.t-0009.t-msedge.net
13.107.246.51
sni1gl.wpc.alphacdn.net
152.199.21.175
s-part-0017.t-0009.fb-t-msedge.net
13.107.253.45
s-part-0017.t-0009.t-msedge.net
13.107.246.45
sni1gl.wpc.omegacdn.net
152.199.21.175
www.google.com
172.217.16.196
aka.ms
104.119.110.121
s-part-0039.t-0009.fb-t-msedge.net
13.107.253.67
fp2e7a.wpc.phicdn.net
192.229.221.95
js.monitor.azure.com
unknown
support.office.com
unknown
c.s-microsoft.com
unknown
support.content.office.net
unknown
aadcdn.msftauth.net
unknown
logincdn.msftauth.net
unknown
login.microsoftonline.com
unknown
acctcdn.msftauth.net
unknown
mem.gfx.ms
unknown
There are 11 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.107.246.45
s-part-0017.t-0009.t-msedge.net
United States
13.107.246.44
s-part-0016.t-0009.t-msedge.net
United States
104.119.110.121
aka.ms
United States
192.168.2.4
unknown
unknown
13.107.246.51
s-part-0023.t-0009.t-msedge.net
United States
13.107.253.45
s-part-0017.t-0009.fb-t-msedge.net
United States
13.107.253.67
s-part-0039.t-0009.fb-t-msedge.net
United States
13.107.253.72
s-part-0044.t-0009.fb-t-msedge.net
United States
239.255.255.250
unknown
Reserved
192.168.2.13
unknown
unknown
192.168.2.14
unknown
unknown
152.199.21.175
sni1gl.wpc.alphacdn.net
United States
172.217.16.196
www.google.com
United States
There are 3 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/join-a-meeting-in-microsoft-teams-1613bb53-f3fa-431e-85a9-d6a91e3468c9?omkt=en-us&ui=en-us&rs=en-us&ad=us
https://support.microsoft.com/en-us/office/i-can-t-join-a-meeting-in-microsoft-teams-85f8eb98-b815-4007-90c9-0c56b87e288d
https://support.microsoft.com/en-us/office/i-can-t-join-a-meeting-in-microsoft-teams-85f8eb98-b815-4007-90c9-0c56b87e288d
https://support.microsoft.com/en-us/office/i-can-t-join-a-meeting-in-microsoft-teams-85f8eb98-b815-4007-90c9-0c56b87e288d
https://support.microsoft.com/en-us/office/i-can-t-join-a-meeting-in-microsoft-teams-85f8eb98-b815-4007-90c9-0c56b87e288d
https://support.microsoft.com/en-us/office/i-can-t-join-a-meeting-in-microsoft-teams-85f8eb98-b815-4007-90c9-0c56b87e288d
https://support.microsoft.com/en-us/office/i-can-t-join-a-meeting-in-microsoft-teams-85f8eb98-b815-4007-90c9-0c56b87e288d
https://support.microsoft.com/en-us/office/i-can-t-join-a-meeting-in-microsoft-teams-85f8eb98-b815-4007-90c9-0c56b87e288d
https://support.microsoft.com/en-us/office/how-to-log-in-to-microsoft-teams-ea4b1443-d11b-4791-8ae1-9977e7723055
https://support.microsoft.com/en-us/office/how-to-log-in-to-microsoft-teams-ea4b1443-d11b-4791-8ae1-9977e7723055
https://support.microsoft.com/en-us/office/how-to-log-in-to-microsoft-teams-ea4b1443-d11b-4791-8ae1-9977e7723055
https://support.microsoft.com/en-us/office/how-to-log-in-to-microsoft-teams-ea4b1443-d11b-4791-8ae1-9977e7723055
https://support.microsoft.com/en-us/office/how-to-log-in-to-microsoft-teams-ea4b1443-d11b-4791-8ae1-9977e7723055
https://support.microsoft.com/en-us/office/how-to-log-in-to-microsoft-teams-ea4b1443-d11b-4791-8ae1-9977e7723055
There are 12 hidden doms, click here to show them.