IOC Report
https://britanniapackaging-my.sharepoint.com/:o:/p/julie_heffernan/EmFralHMLyJEuryYIQRN2SQB5JNE1sJUqp62sHRoD11Z7w?e=5%3a1RABUG&at=9

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 13:23:30 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 13:23:30 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 13:23:30 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 13:23:30 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 29 13:23:30 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 140
ASCII text, with very long lines (5162), with no line terminators
downloaded
Chrome Cache Entry: 141
ASCII text, with very long lines (20568)
dropped
Chrome Cache Entry: 143
HTML document, ASCII text, with very long lines (20675)
downloaded
Chrome Cache Entry: 144
gzip compressed data, max compression, truncated
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (2667)
downloaded
Chrome Cache Entry: 146
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 147
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 148
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 150
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 151
ASCII text, with very long lines (1745)
dropped
Chrome Cache Entry: 152
ASCII text, with very long lines (2287)
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (1074)
dropped
Chrome Cache Entry: 154
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 155
Unicode text, UTF-8 text, with very long lines (767)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (14137)
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (625)
downloaded
Chrome Cache Entry: 163
ASCII text
downloaded
Chrome Cache Entry: 166
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 167
ASCII text, with very long lines (800)
downloaded
Chrome Cache Entry: 168
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 169
HTML document, Unicode text, UTF-8 text, with very long lines (33915)
dropped
Chrome Cache Entry: 172
ASCII text, with very long lines (8324)
dropped
Chrome Cache Entry: 173
HTML document, ASCII text, with very long lines (1010)
dropped
Chrome Cache Entry: 174
Web Open Font Format (Version 2), TrueType, length 15436, version 1.0
downloaded
Chrome Cache Entry: 175
MPEG ADTS, layer III, v2, 64 kbps, 24 kHz, Monaural
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (613)
downloaded
Chrome Cache Entry: 177
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
dropped
Chrome Cache Entry: 178
ASCII text, with very long lines (771)
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (5718), with no line terminators
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (1159)
downloaded
Chrome Cache Entry: 182
HTML document, ASCII text, with very long lines (1010)
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (3391)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (671)
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (846)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (39257), with CRLF line terminators
dropped
Chrome Cache Entry: 190
ASCII text, with very long lines (65531)
downloaded
Chrome Cache Entry: 192
Web Open Font Format (Version 2), TrueType, length 24652, version 1.0
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (501)
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (1302)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (866)
dropped
Chrome Cache Entry: 198
ASCII text, with very long lines (65531)
downloaded
Chrome Cache Entry: 199
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 202
HTML document, ASCII text, with very long lines (31438)
downloaded
Chrome Cache Entry: 204
ASCII text
downloaded
Chrome Cache Entry: 206
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (4047), with no line terminators
downloaded
Chrome Cache Entry: 208
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 209
ASCII text, with very long lines (6682)
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (17444)
dropped
Chrome Cache Entry: 212
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 213
HTML document, Unicode text, UTF-8 text, with very long lines (65503)
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (561)
downloaded
Chrome Cache Entry: 216
RIFF (little-endian) data, Web/P image
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (1295)
dropped
Chrome Cache Entry: 218
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 219
PNG image data, 32 x 32, 8-bit grayscale, non-interlaced
dropped
Chrome Cache Entry: 220
JSON data
dropped
Chrome Cache Entry: 222
HTML document, Unicode text, UTF-8 text, with very long lines (65503)
dropped
Chrome Cache Entry: 223
ASCII text, with very long lines (10857), with no line terminators
dropped
Chrome Cache Entry: 224
PNG image data, 36 x 36, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 226
Unicode text, UTF-8 text, with very long lines (65534), with no line terminators
downloaded
Chrome Cache Entry: 227
ASCII text
dropped
Chrome Cache Entry: 228
PNG image data, 226 x 48, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 229
ASCII text, with very long lines (65329), with CRLF line terminators
dropped
Chrome Cache Entry: 231
HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 232
HTML document, ASCII text, with very long lines (30522), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 233
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 234
ASCII text, with very long lines (543)
downloaded
Chrome Cache Entry: 237
ASCII text, with very long lines (8308)
downloaded
Chrome Cache Entry: 239
ASCII text, with very long lines (37337)
downloaded
Chrome Cache Entry: 242
PNG image data, 24 x 24, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 245
HTML document, Unicode text, UTF-8 text, with very long lines (33915)
downloaded
Chrome Cache Entry: 247
XML 1.0 document, Unicode text, UTF-8 (with BOM) text
downloaded
Chrome Cache Entry: 251
ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 254
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 255
MPEG ADTS, layer III, v2, 64 kbps, 24 kHz, Monaural
downloaded
Chrome Cache Entry: 256
ASCII text, with very long lines (1143)
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (568)
downloaded
Chrome Cache Entry: 261
ASCII text
downloaded
Chrome Cache Entry: 263
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (3537)
downloaded
Chrome Cache Entry: 265
RIFF (little-endian) data, Web/P image
dropped
Chrome Cache Entry: 267
ASCII text, with very long lines (65531)
dropped
Chrome Cache Entry: 268
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 270
ASCII text, with very long lines (523)
downloaded
There are 82 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://britanniapackaging-my.sharepoint.com/:o:/p/julie_heffernan/EmFralHMLyJEuryYIQRN2SQB5JNE1sJUqp62sHRoD11Z7w?e=5%3a1RABUG&at=9
https://britanniapackaging-my.sharepoint.com/personal/julie_heffernan_britanniapackaging_com/_layouts/15/guestaccess.aspx?e=5%3a1RABUG&at=9&share=EmFralHMLyJEuryYIQRN2SQB5JNE1sJUqp62sHRoD11Z7w
https://www.google.com/search?q=at+sign&oq=at+sign&gs_lcrp=EgZjaHJvbWUyBggAEEUYOdIBCTIxMThqMGoxNagCALACAA&sourceid=chrome&ie=UTF-8
https://britanniapackaging-my.sharepoint.com/:o:/p/julie_heffernan/EmFralHMLyJEuryYIQRN2SQB5JNE1sJUqp62sHRoD11Z7w?e=5%3a1RABUG&at=9

Domains

Name
IP
Malicious
dual-spo-0005.spo-msedge.net
13.107.136.10
youtube-ui.l.google.com
142.250.181.238
plus.l.google.com
172.217.16.206
play.google.com
216.58.206.46
googleads.g.doubleclick.net
142.250.184.194
dns-tunnel-check.googlezip.net
216.239.34.159
tunnel.googlezip.net
216.239.34.157
i.ytimg.com
142.250.185.118
id.google.com
172.217.18.3
www.google.com
142.250.186.100
static.doubleclick.net
172.217.23.102
britanniapackaging-my.sharepoint.com
unknown
www.youtube.com
unknown
apis.google.com
unknown
m365cdn.nel.measure.office.net
unknown
There are 5 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.78
unknown
United States
142.250.186.67
unknown
United States
13.107.136.10
dual-spo-0005.spo-msedge.net
United States
23.38.98.103
unknown
United States
216.58.206.74
unknown
United States
172.217.18.14
unknown
United States
216.58.206.78
unknown
United States
192.168.2.16
unknown
unknown
142.250.185.100
unknown
United States
192.168.2.4
unknown
unknown
142.250.181.238
youtube-ui.l.google.com
United States
142.250.186.131
unknown
United States
142.250.184.226
unknown
United States
142.250.186.134
unknown
United States
172.217.18.10
unknown
United States
142.250.186.74
unknown
United States
142.250.186.99
unknown
United States
172.217.16.142
unknown
United States
142.250.185.67
unknown
United States
142.250.185.118
i.ytimg.com
United States
1.1.1.1
unknown
Australia
216.58.212.138
unknown
United States
74.125.133.84
unknown
United States
172.217.16.206
plus.l.google.com
United States
142.250.184.194
googleads.g.doubleclick.net
United States
216.58.206.67
unknown
United States
172.217.18.3
id.google.com
United States
142.250.185.234
unknown
United States
142.250.185.238
unknown
United States
216.58.206.46
play.google.com
United States
2.19.126.84
unknown
European Union
142.250.181.227
unknown
United States
239.255.255.250
unknown
Reserved
142.250.185.131
unknown
United States
172.217.23.102
static.doubleclick.net
United States
23.38.98.67
unknown
United States
142.250.186.100
www.google.com
United States
142.250.184.238
unknown
United States
23.38.98.69
unknown
United States
216.58.212.163
unknown
United States
172.217.16.130
unknown
United States
95.101.54.226
unknown
European Union
216.239.34.157
tunnel.googlezip.net
United States
There are 33 hidden IPs, click here to show them.