IOC Report
https://email.email.pandadoc.net/c/eJxUkMtu2zAQRb9G3Dmghg-RCy2cxExQp4WLNCiQTTAihxH9EFWJVtN-fWGg6WM3GMwZnHtD22nRRcNC9ucTDeUlhfbb-GOyDzvX3zxunx_Pw_6jK58co7ZuwDZcW21Y3yqswRIJL41WFmVAHclyVKA8l1ax1AIHWXMQteEWmqsIBmMUmmQTa1K6kpxOmI5XIw4BQ_ZXAxWW5pcyoSfsjtSW6Uzs2PaljHMl1hW4ChyO41_E51MF7l2_ArdAJVzJBxoqcYu88

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 15:49:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 15:49:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 15:49:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 15:49:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Oct 24 15:49:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 107
ASCII text, with very long lines (51248)
dropped
Chrome Cache Entry: 108
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 109
Unicode text, UTF-8 text, with very long lines (13330), with no line terminators
downloaded
Chrome Cache Entry: 110
Web Open Font Format (Version 2), TrueType, length 32036, version 1.0
downloaded
Chrome Cache Entry: 111
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 112
Web Open Font Format (Version 2), TrueType, length 31852, version 1.0
downloaded
Chrome Cache Entry: 113
Web Open Font Format, TrueType, length 36060, version 0.0
downloaded
Chrome Cache Entry: 115
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 117
Web Open Font Format, CFF, length 32740, version 0.0
downloaded
Chrome Cache Entry: 119
Web Open Font Format, TrueType, length 59468, version 0.0
downloaded
Chrome Cache Entry: 120
Unicode text, UTF-8 text, with very long lines (2495)
dropped
Chrome Cache Entry: 123
Web Open Font Format, TrueType, length 92640, version 0.0
downloaded
Chrome Cache Entry: 124
Web Open Font Format, CFF, length 41212, version 0.0
downloaded
Chrome Cache Entry: 125
Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (29256), with no line terminators
downloaded
Chrome Cache Entry: 129
gzip compressed data, from Unix, original size modulo 2^32 537817
dropped
Chrome Cache Entry: 131
ASCII text, with very long lines (42611)
downloaded
Chrome Cache Entry: 132
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 133
Unicode text, UTF-8 text, with very long lines (10562), with no line terminators
dropped
Chrome Cache Entry: 134
Web Open Font Format, CFF, length 33916, version 0.0
downloaded
Chrome Cache Entry: 137
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 138
ASCII text
dropped
Chrome Cache Entry: 139
JSON data
dropped
Chrome Cache Entry: 140
JSON data
downloaded
Chrome Cache Entry: 141
Unicode text, UTF-8 text, with very long lines (2258)
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 143
Web Open Font Format, CFF, length 24840, version 0.0
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (1303), with no line terminators
downloaded
Chrome Cache Entry: 145
gzip compressed data, from Unix, original size modulo 2^32 7046
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (19217), with no line terminators
dropped
Chrome Cache Entry: 147
ASCII text, with very long lines (1568), with no line terminators
downloaded
Chrome Cache Entry: 148
TrueType Font data, 19 tables, 1st "BASE", 16 names, Macintosh, Copyright (c) Mark Simonson, 2001. All rights reserved.Regular400c721eab41fee0ef9c0868357cdc5a-V
downloaded
Chrome Cache Entry: 151
HTML document, ASCII text, with very long lines (1093)
downloaded
Chrome Cache Entry: 153
JSON data
downloaded
Chrome Cache Entry: 154
Web Open Font Format, TrueType, length 36604, version 0.0
downloaded
Chrome Cache Entry: 155
PNG image data, 192 x 192, 8-bit colormap, non-interlaced
dropped
There are 33 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://email.email.pandadoc.net/c/eJxUkMtu2zAQRb9G3Dmghg-RCy2cxExQp4WLNCiQTTAihxH9EFWJVtN-fWGg6WM3GMwZnHtD22nRRcNC9ucTDeUlhfbb-GOyDzvX3zxunx_Pw_6jK58co7ZuwDZcW21Y3yqswRIJL41WFmVAHclyVKA8l1ax1AIHWXMQteEWmqsIBmMUmmQTa1K6kpxOmI5XIw4BQ_ZXAxWW5pcyoSfsjtSW6Uzs2PaljHMl1hW4ChyO41_E51MF7l2_ArdAJVzJBxoqcYu88zFi3ShZS4LOaCsbC14Gi2S06oAboUOohGNDLikmjyXl4VIDcBmtFbRSgdNKNkQrNBBX2EkjgUOwXLI8veKQfv6BnrTBz9fXfXgzUjz0_UbfbO4km9olDWnusZL8MGQ64UWcTbSk-TepNvutfcrWPzdvX7ttcDuJqWGlfc_2z7gqOL3Sf5v5crG0wL7n6TCP6OnydL9f1l8m-tCtd026v9X3-U6R-xUAAP__azuhWA
https://app.pandadoc.com/document/v2?token=a0bcffa175414e2b8694792c4d9ae865b20836dd?

Domains

Name
IP
Malicious
d3m3a7p0ze7hmq.cloudfront.net
18.239.69.82
d31uqz37bvu6i7.cloudfront.net
13.32.118.196
x4whrmz.x.incapdns.net
45.223.20.103
prom-fe-gw.production.pandadoc.com
44.235.141.70
sentry.infrastructure.pandadoc.com
44.225.139.105
grafana-agent-faro.production.pandadoc.com
54.189.220.132
ax-0001.ax-msedge.net
150.171.28.10
bm2ydo9.impervadns.net
45.223.20.103
d296je7bbdd650.cloudfront.net
99.86.8.175
email.email.pandadoc.net
108.138.26.86
www.google.com
142.250.186.164
api.segment.io
54.69.251.6
ip2c.org
188.68.242.180
api.pandadoc.com
unknown
use.typekit.net
unknown
app.pandadoc.com
unknown
cdn.segment.com
unknown
p.typekit.net
unknown
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.67
unknown
United States
142.250.185.228
unknown
United States
54.189.220.132
grafana-agent-faro.production.pandadoc.com
United States
192.168.2.17
unknown
unknown
13.32.118.18
unknown
United States
2.19.126.206
unknown
European Union
143.204.215.126
unknown
United States
45.223.20.103
x4whrmz.x.incapdns.net
United States
142.250.185.142
unknown
United States
150.171.28.10
ax-0001.ax-msedge.net
United States
142.250.184.227
unknown
United States
188.68.242.180
ip2c.org
Poland
108.138.26.86
email.email.pandadoc.net
United States
142.250.186.99
unknown
United States
35.155.246.37
unknown
United States
172.217.16.200
unknown
United States
18.239.69.82
d3m3a7p0ze7hmq.cloudfront.net
United States
142.250.110.84
unknown
United States
1.1.1.1
unknown
Australia
13.32.118.196
d31uqz37bvu6i7.cloudfront.net
United States
54.69.251.6
api.segment.io
United States
2.19.126.211
unknown
European Union
44.235.141.70
prom-fe-gw.production.pandadoc.com
United States
44.225.139.105
sentry.infrastructure.pandadoc.com
United States
2.19.126.198
unknown
European Union
239.255.255.250
unknown
Reserved
142.250.185.174
unknown
United States
142.250.186.164
www.google.com
United States
99.86.8.175
d296je7bbdd650.cloudfront.net
United States
There are 19 hidden IPs, click here to show them.