IOC Report
https://pub.marq.com/85a7a798-1e8a-4840-a35f-5f0e9afd9543/

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:00:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:00:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:00:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:00:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 30 19:00:32 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://pub.marq.com/85a7a798-1e8a-4840-a35f-5f0e9afd9543/
https://pub.marq.com/85a7a798-1e8a-4840-a35f-5f0e9afd9543/#_0
malicious
https://paddlefish-rhino-kh78.squarespace.com/

Domains

Name
IP
Malicious
performance.squarespace.com
35.186.236.0
cdn-cashy-static-assets.marq.com
18.245.60.30
analytics-pub.marq.com
54.204.91.219
static.squarespace.map.fastly.net
151.101.128.237
www.google.com
142.250.185.228
paddlefish-rhino-kh78.squarespace.com
198.185.159.177
d3v04nmt9jknbk.cloudfront.net
18.245.253.65
app.marq.com
3.93.140.3
squarespace.map.fastly.net
151.101.0.238
prod.squarespace.map.fastly.net
151.101.0.238
analytics-pub.app.marq.com
184.73.95.66
stats.g.doubleclick.net
74.125.206.156
use.typekit.net
unknown
images.squarespace-cdn.com
unknown
assets.squarespace.com
unknown
pub.marq.com
unknown
static1.squarespace.com
unknown
p.typekit.net
unknown
There are 8 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
3.93.140.3
app.marq.com
United States
142.250.186.67
unknown
United States
142.250.185.228
www.google.com
United States
18.245.60.30
cdn-cashy-static-assets.marq.com
United States
64.233.167.157
unknown
United States
151.101.64.238
unknown
United States
18.245.253.65
d3v04nmt9jknbk.cloudfront.net
United States
54.204.91.219
analytics-pub.marq.com
United States
192.168.2.16
unknown
unknown
151.101.0.237
unknown
United States
2.19.126.206
unknown
European Union
74.125.206.156
stats.g.doubleclick.net
United States
151.101.0.238
squarespace.map.fastly.net
United States
151.101.128.237
static.squarespace.map.fastly.net
United States
184.73.95.66
analytics-pub.app.marq.com
United States
142.250.186.110
unknown
United States
142.250.186.72
unknown
United States
172.217.18.10
unknown
United States
142.250.184.200
unknown
United States
172.217.16.200
unknown
United States
142.250.186.78
unknown
United States
1.1.1.1
unknown
Australia
74.125.133.84
unknown
United States
172.217.16.206
unknown
United States
151.101.192.238
unknown
United States
216.58.206.67
unknown
United States
2.19.126.219
unknown
European Union
2.19.126.211
unknown
European Union
198.185.159.177
paddlefish-rhino-kh78.squarespace.com
United States
2.19.126.198
unknown
European Union
239.255.255.250
unknown
Reserved
18.245.46.14
unknown
United States
142.250.186.40
unknown
United States
142.250.184.238
unknown
United States
35.186.236.0
performance.squarespace.com
United States
There are 25 hidden IPs, click here to show them.