IOC Report
https://tinyurl.com/yhntdrax?_k=vPtuG

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:03:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:03:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:03:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:03:22 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 12:03:21 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://tinyurl.com/yhntdrax?_k=vPtuG
https://stockx.com/
http://gov.winterpaymenko.top/?_k=vPtuG
172.67.161.241

Domains

Name
IP
Malicious
static.nl3.vip.prod.criteo.net
178.250.1.3
csm.nl3.vip.prod.criteo.net
178.250.1.25
eu-eb2.3lift.com
76.223.111.18
measurement-api.nl3.vip.prod.criteo.com
178.250.1.24
api.sardine.ai
34.120.14.251
gov.winterpaymenko.top
172.67.161.241
r.casalemedia.com
172.64.151.101
cm.g.doubleclick.net
142.250.185.66
idaas-ext.cph.liveintent.com
18.235.24.39
ds-pr-bh.ybp.gysm.yahoodns.net
34.243.94.39
www.google.com
142.250.185.132
dualstack.com.imgix.map.fastly.net
151.101.130.208
px.mountain.com
52.89.99.220
match.adsrvr.org
52.223.40.198
match.prod.bidr.io
52.208.224.133
nydc1.outbrain.org
70.42.32.191
mapixl.com
23.96.207.177
dx.mountain.com
34.238.149.65
trends.revcontent.com
34.243.99.253
pug-lhr-bc.pubmnet.com
185.64.191.210
stk.px-cloud.net
34.107.199.61
gs.mountain.com
52.12.117.226
euw-ice.360yield.com
52.19.150.135
k8s-gateways-gwlh3-73da476369-1123590489.us-east-1.elb.amazonaws.com
54.173.249.172
d1ykf07e75w7ss.cloudfront.net
108.138.6.136
googleads.g.doubleclick.net
142.250.186.66
challenges.cloudflare.com
104.18.95.41
api.cdp.stockx.com
54.186.34.49
web-assets.stockx.com
104.16.109.9
td.doubleclick.net
216.58.206.34
campaign.fbot.me
13.225.78.75
public.fbot.me
3.221.253.204
in-ftd-109.nl3.vip.prod.criteo.com
178.250.1.8
partners-alb-1113315349.us-east-1.elb.amazonaws.com
18.205.127.149
stun.l.google.com
74.125.250.129
cdn.cookielaw.org
104.18.86.42
widget.us5.vip.prod.criteo.com
74.119.117.16
collectorv.us.tvsquared.com
3.137.102.166
static.fbot.me
18.66.112.126
dart.l.doubleclick.net
142.250.186.134
static.cloudflareinsights.com
104.16.80.73
objeq4jkwkqdgqfkgvggfjkclhnltn1q.d.sardine.ai
34.120.14.251
stockx.com
104.16.110.9
cdn.quantummetric.com
104.18.11.213
adgcp.tpmn.co.kr
34.102.166.132
user-data-eu.bidswitch.net
35.214.136.108
adservice.google.com
216.58.206.34
collector-px16ud0kof.cl6.px-cloud.net
35.190.10.96
fledge.us5.vip.prod.criteo.com
74.119.117.20
contextual.media.net
88.221.168.23
k8s-gateways-gwlh2-8b9819a160-1697331022.us-east-1.elb.amazonaws.com
52.0.94.40
scontent.xx.fbcdn.net
157.240.0.6
widget.nl3.vip.prod.criteo.com
178.250.1.9
ara.paa-reporting-advertising.amazon
18.245.46.13
tapestry.tapad.com
34.111.113.62
images.stockx.com
104.16.110.9
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
52.18.245.132
sync.srv.stackadapt.com
3.210.235.75
browser-intake-datadoghq.com
3.233.158.24
am-vip001.taboola.com
141.226.228.48
rtb-csync-euw2.smartadserver.com
5.135.209.105
tinyurl.com
104.18.111.161
a.nel.cloudflare.com
35.190.80.1
cloudflareinsights.com
104.16.79.73
ax-0001.ax-dc-msedge.net
150.171.29.10
evs.cdp.stockx.com
18.66.147.110
ad.tpmn.io
34.102.166.132
s.amazon-adsystem.com
98.82.156.207
ad.doubleclick.net
172.217.18.6
imgsync-amsfpairbc.pubmnet.com
198.47.127.18
ax-0001.ax-msedge.net
150.171.28.10
exchange.mediavine.com
35.156.173.51
p.sardine.ai
34.67.241.53
getrockerbox.com
104.26.8.177
img.riskified.com
107.23.175.192
gum.nl3.vip.prod.criteo.com
178.250.1.11
s.ad.smaato.net
13.32.27.23
images-cs.stockx.com
104.16.110.9
pug-ams-bc.pubmnet.com
198.47.127.205
ib.anycast.adnxs.com
185.89.210.82
visitor-fra02.omnitagjs.com
185.255.84.153
geolocation.onetrust.com
104.18.32.137
rbidsna5.stockx.com
104.16.109.9
mw-emptypixel.eba-vdzmhv2f.eu-west-1.elasticbeanstalk.com
52.18.91.21
match-eu-central-1-ecs.sharethrough.com
18.184.119.72
siteintercept.qualtrics.com
unknown
ads.stickyadstv.com
unknown
dynamic.criteo.com
unknown
ad.tpmn.co.kr
unknown
jadserve.postrelease.com
unknown
sslwidget.criteo.com
unknown
dis.criteo.com
unknown
widget.us.criteo.com
unknown
zn4tqdz21wlnz4zv8-stockxcustomerres.siteintercept.qualtrics.com
unknown
static.criteo.net
unknown
measurement-api.criteo.com
unknown
pixel.rubiconproject.com
unknown
collector-40161.us.tvsquared.com
unknown
connect.facebook.net
unknown
1f2e7.v.fwmrm.net
unknown
There are 90 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.67
unknown
United States
3.221.253.204
public.fbot.me
United States
3.137.102.166
collectorv.us.tvsquared.com
United States
52.89.99.220
px.mountain.com
United States
104.18.111.161
tinyurl.com
United States
98.82.156.207
s.amazon-adsystem.com
United States
104.16.80.73
static.cloudflareinsights.com
United States
178.250.1.24
measurement-api.nl3.vip.prod.criteo.com
France
178.250.1.25
csm.nl3.vip.prod.criteo.net
France
99.84.9.13
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
198.47.127.205
pug-ams-bc.pubmnet.com
United States
104.16.109.9
web-assets.stockx.com
United States
204.79.197.237
unknown
United States
52.37.218.4
unknown
United States
104.18.87.42
unknown
United States
34.104.35.123
unknown
United States
1.1.1.1
unknown
Australia
52.18.245.132
dcs-public-edge-irl1-150041215.eu-west-1.elb.amazonaws.com
United States
216.58.206.40
unknown
United States
3.208.147.210
unknown
United States
172.67.161.241
gov.winterpaymenko.top
United States
54.186.203.89
unknown
United States
172.217.18.6
ad.doubleclick.net
United States
108.138.6.136
d1ykf07e75w7ss.cloudfront.net
United States
239.255.255.250
unknown
Reserved
51.178.195.217
unknown
France
178.250.1.11
gum.nl3.vip.prod.criteo.com
France
23.22.188.59
unknown
United States
5.135.209.105
rtb-csync-euw2.smartadserver.com
France
34.67.241.53
p.sardine.ai
United States
154.57.158.116
unknown
United States
18.235.24.39
idaas-ext.cph.liveintent.com
United States
185.255.84.153
visitor-fra02.omnitagjs.com
France
192.168.2.17
unknown
unknown
216.58.206.34
td.doubleclick.net
United States
142.250.185.168
unknown
United States
142.250.181.230
unknown
United States
52.0.94.40
k8s-gateways-gwlh2-8b9819a160-1697331022.us-east-1.elb.amazonaws.com
United States
3.69.181.183
unknown
United States
157.240.0.6
scontent.xx.fbcdn.net
United States
185.89.210.180
unknown
Germany
142.250.181.238
unknown
United States
52.18.91.21
mw-emptypixel.eba-vdzmhv2f.eu-west-1.elasticbeanstalk.com
United States
142.250.185.164
unknown
United States
23.96.207.177
mapixl.com
United States
141.226.228.48
am-vip001.taboola.com
Israel
54.186.34.49
api.cdp.stockx.com
United States
142.250.186.134
dart.l.doubleclick.net
United States
52.12.117.226
gs.mountain.com
United States
104.16.79.73
cloudflareinsights.com
United States
23.32.185.35
unknown
United States
178.250.1.8
in-ftd-109.nl3.vip.prod.criteo.com
France
178.250.1.9
widget.nl3.vip.prod.criteo.com
France
13.225.78.75
campaign.fbot.me
United States
13.32.27.23
s.ad.smaato.net
United States
178.250.1.3
static.nl3.vip.prod.criteo.net
France
151.101.2.208
unknown
United States
34.243.94.39
ds-pr-bh.ybp.gysm.yahoodns.net
United States
18.66.147.67
unknown
United States
70.42.32.159
unknown
United States
142.250.186.66
googleads.g.doubleclick.net
United States
3.233.158.24
browser-intake-datadoghq.com
United States
104.26.8.177
getrockerbox.com
United States
52.71.121.170
unknown
United States
23.38.98.201
unknown
United States
35.156.173.51
exchange.mediavine.com
United States
18.184.119.72
match-eu-central-1-ecs.sharethrough.com
United States
104.18.32.137
geolocation.onetrust.com
United States
34.120.14.251
api.sardine.ai
United States
154.54.250.80
unknown
United States
44.227.136.144
unknown
United States
142.250.184.226
unknown
United States
104.16.110.9
stockx.com
United States
142.250.186.35
unknown
United States
142.250.185.66
cm.g.doubleclick.net
United States
54.173.249.172
k8s-gateways-gwlh3-73da476369-1123590489.us-east-1.elb.amazonaws.com
United States
69.173.144.165
unknown
United States
18.66.112.126
static.fbot.me
United States
34.241.19.39
unknown
United States
13.107.21.237
unknown
United States
20.190.159.71
unknown
United States
104.18.95.41
challenges.cloudflare.com
United States
35.81.162.201
unknown
United States
172.64.155.119
unknown
United States
142.250.186.106
unknown
United States
34.243.99.253
trends.revcontent.com
United States
150.171.29.10
ax-0001.ax-dc-msedge.net
United States
198.47.127.18
imgsync-amsfpairbc.pubmnet.com
United States
142.250.186.40
unknown
United States
52.223.40.198
match.adsrvr.org
United States
104.17.208.240
unknown
United States
35.214.136.108
user-data-eu.bidswitch.net
United States
18.66.112.116
unknown
United States
35.190.10.96
collector-px16ud0kof.cl6.px-cloud.net
United States
104.17.209.240
unknown
United States
69.173.144.139
unknown
United States
185.64.191.210
pug-lhr-bc.pubmnet.com
United Kingdom
172.64.151.101
r.casalemedia.com
United States
70.42.32.191
nydc1.outbrain.org
United States
There are 90 hidden IPs, click here to show them.