IOC Report
https://www.google.com/url?q=https://applications.zoom.us/addon/invitation/detail?meetingUuid%3DwXriugcdSY%252BqAGyQ440%252Bfw%253D%253D%26signature%3D48ea33cc1f15c544aad4f3a29a13d9e53d0dee4178a5959250e94765749ba335%26v%3D1&sa=D&source=calendar&usg=AOvVaw3F9H9B9w02SkmuTB6qObxq

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\Unconfirmed 173067.crdownload
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (65450)
dropped
Chrome Cache Entry: 128
Unicode text, UTF-8 text, with very long lines (17898)
downloaded
Chrome Cache Entry: 129
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 131
JSON data
dropped
Chrome Cache Entry: 132
JSON data
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (22445)
dropped
Chrome Cache Entry: 134
Unicode text, UTF-8 text, with very long lines (17898)
dropped
Chrome Cache Entry: 135
ASCII text, with very long lines (1114)
dropped
Chrome Cache Entry: 136
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 137
ASCII text, with very long lines (20654), with no line terminators
dropped
Chrome Cache Entry: 138
JSON data
downloaded
Chrome Cache Entry: 139
ASCII text, with very long lines (65536), with no line terminators
dropped
Chrome Cache Entry: 140
JSON data
downloaded
Chrome Cache Entry: 141
PE32 executable (GUI) Intel 80386, for MS Windows
downloaded
Chrome Cache Entry: 142
ASCII text, with very long lines (65450)
downloaded
Chrome Cache Entry: 143
JSON data
dropped
Chrome Cache Entry: 144
HTML document, ASCII text, with very long lines (5171)
downloaded
Chrome Cache Entry: 145
HTML document, ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 146
Unicode text, UTF-8 text, with very long lines (31575)
downloaded
Chrome Cache Entry: 147
Unicode text, UTF-8 text, with very long lines (31575)
dropped
Chrome Cache Entry: 148
ASCII text, with very long lines (1114)
downloaded
Chrome Cache Entry: 149
JSON data
dropped
Chrome Cache Entry: 150
ASCII text, with very long lines (22445)
downloaded
Chrome Cache Entry: 151
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 152
JSON data
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (20654), with no line terminators
downloaded
Chrome Cache Entry: 154
HTML document, Unicode text, UTF-8 text
downloaded
Chrome Cache Entry: 155
JSON data
downloaded
Chrome Cache Entry: 156
JSON data
dropped
Chrome Cache Entry: 157
PNG image data, 240 x 54, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 158
PNG image data, 240 x 54, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 159
JSON data
dropped
There are 25 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2296 --field-trial-handle=2196,i,15998130285808565372,12342639290257781318,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://www.google.com/url?q=https://applications.zoom.us/addon/invitation/detail?meetingUuid%3DwXriugcdSY%252BqAGyQ440%252Bfw%253D%253D%26signature%3D48ea33cc1f15c544aad4f3a29a13d9e53d0dee4178a5959250e94765749ba335%26v%3D1&sa=D&source=calendar&usg=AOvVaw3F9H9B9w02SkmuTB6qObxq"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5820 --field-trial-handle=2196,i,15998130285808565372,12342639290257781318,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://www.google.com/url?q=https://applications.zoom.us/addon/invitation/detail?meetingUuid%3DwXriugcdSY%252BqAGyQ440%252Bfw%253D%253D%26signature%3D48ea33cc1f15c544aad4f3a29a13d9e53d0dee4178a5959250e94765749ba335%26v%3D1&sa=D&source=calendar&usg=AOvVaw3F9H9B9w02SkmuTB6qObxq
https://dev-zcb.zoomdev.us/static/resource/cci/
unknown
https://dev01campaign.zoomdev.us/
unknown
https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/v2/otPcCenter.json
104.18.87.42
https://formatjs.io/docs/react-intl/api#intlshape
unknown
https://github.com/zloirock/core-js
unknown
https://sa01cciapi.zoom.us/
unknown
http://momentjs.com/guides/#/warnings/add-inverted-param/
unknown
https://zoom-privacy.my.onetrust.com/request/v1/consentreceipts
104.18.32.137
https://us01ccistatic.zoom.us/us01cci/web-sdk/chat-client.js
52.84.151.43
https://miro.zoom.us/j/93051920785
170.114.52.2
https://support.zoom.us/hc/en-us/articles/201362003-Zoom-Video-Communications-Technical-Support
unknown
https://devcolocampaign.zoomdev.us/
unknown
https://devcoloapizva.zoomdev.us/
unknown
https://devoci-cdn-cci.zoomdev.us/n/idkx1lfgxgf7/b/dev-zcx/o/web-sdk/
unknown
https://us01cciapi.zoom.us/
unknown
https://gocampaign.zoom.us/
unknown
https://formatjs.io/docs/tooling/linter#enforce-id)
unknown
https://log-gateway.zoom.us/nws/join/logger/wjmf
170.114.65.138
https://cci.zoomgovdev.com/
unknown
https://goapizva.zoom.us/
unknown
https://aw1vaapplications.zoom.us/addon/images/zoom_logo_invitation.png
170.114.12.132
https://developers.google.com/web/updates/2017/01/scrolling-intervention
unknown
https://scheduler.zoom.us
unknown
https://eu01apizva.zoom.us/
unknown
https://qa01ccizpapi.zoomdev.us/
unknown
https://formatjs.io/docs/tooling/babel-plugin)
unknown
https://cdn.cookielaw.org/consent/b0bfa2ae-4058-4aef-8632-a5281ce4464a/018e6326-944c-770b-9e87-74eaf48b0e06/en.json
104.18.87.42
http://momentjs.com/guides/#/warnings/zone/
unknown
https://zcb.zoomdev.us/static/resource/cci/
unknown
https://zoom.com.cn/
unknown
https://cciapi.zoomgov.com/
unknown
https://zoom.us/
unknown
https://cdn.cookielaw.org/scripttemplates/6.21.0/otBannerSdk.js
104.18.87.42
https://support.zoom.us/hc/es/articles/201362023-System-Requirements
unknown
https://support.zoom.us/hc/zh-tw/articles/201362023-System-Requirements
unknown
https://applications.zoom.us/addon/invitation/detail?meetingUuid=wXriugcdSY%2BqAGyQ440%2Bfw%3D%3D&signature=48ea33cc1f15c544aad4f3a29a13d9e53d0dee4178a5959250e94765749ba335&v=1
https://qa01ccizp.zoomdev.us/
unknown
https://support.zoom.us/hc/ru/articles/201362023-System-Requirements
unknown
https://eu01cciapi.zoom.us/
unknown
https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/otFloatingFlat.json
104.18.87.42
https://github.com/karanlyons/murmurHash3.js)
unknown
https://st1.zoom.us/fe-static/launch-meeting/meeting.537a440d01fe8a0940ee.js
170.114.46.1
https://goccistatic.zoom.us/gocci/web-sdk/
unknown
https://zoom.us/https://zoom.com/https://zoom.com.cn/https://zoomgov.com/://https:///
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://support.zoom.us/hc/pt-br/articles/201362023-System-Requirements
unknown
https://github.com/zloirock/core-js/blob/v3.38.1/LICENSE
unknown
https://us01ccistatic.zoom.us/us01cci/web-sdk/
unknown
https://miro.zoom.us/j/93051920785#success
https://cci.zoomgov.com/
unknown
https://eu01cci.zoom.us/
unknown
https://zoom.us/phonesystem
unknown
https://ccizp.zoomdev.us/
unknown
https://sa01campaign.zoom.us/
unknown
http://momentjs.com/timezone/docs/#/data-loading/.
unknown
https://qa01apizva.zoomdev.us/
unknown
https://sa01cci.zoom.us/
unknown
https://zoom.com
unknown
https://devccistatic.zoomdev.us/web-sdk/
unknown
https://github.com/unjs/consola?tab=readme-ov-file#log-level
unknown
https://formatjs.io/docs/tooling/ts-transformer)
unknown
https://cdn.cookielaw.org/consent/b0bfa2ae-4058-4aef-8632-a5281ce4464a/b0bfa2ae-4058-4aef-8632-a5281ce4464a.json
104.18.87.42
https://cdn.cookielaw.org/scripttemplates/otSDKStub.js
104.18.87.42
http://momentjs.com/guides/#/warnings/min-max/
unknown
https://cciapi.zoomgovdev.com/
unknown
https://formatjs.io/docs/getting-started/message-distribution
unknown
https://ccistatic.zoomgovdev.com/web-sdk/
unknown
https://support.zoom.us/hc/zh-cn/articles/201362023-System-Requirements
unknown
https://ccistatic.zoomgov.com/web-sdk/
unknown
https://us01apizva.zoom.us/
unknown
https://dev01cciapi.zoomdev.us/
unknown
https://geolocation.onetrust.com/cookieconsentpub/v1/geo/location
172.64.155.119
https://cdn.cookielaw.org/scripttemplates/6.21.0/assets/otCommonStyles.css
104.18.87.42
https://miro.zoom.us/u/adlYKHswxd
unknown
https://support.zoom.us/hc/en-us/articles/201362003-Zoom-Video-Communications-Technical-Supportopens
unknown
https://us01cci.zoom.us/
unknown
https://campaign.zoomgov.com/
unknown
https://zoom.us
unknown
https://eu01campaign.zoom.us/
unknown
https://ccizpapi.zoomdev.us/
unknown
https://gocciapi.zoom.us/
unknown
https://applications.zoom.us/favicon.ico
170.114.52.74
https://github.com/focus-trap/tabbable/blob/master/LICENSE
unknown
http://momentjs.com/guides/#/warnings/js-date/
unknown
https://gocci.zoom.us/
unknown
https://devlog-gateway.zoomdev.us/nws/join/logger/zccfelog
unknown
https://log-gateway.zoom.us/nws/join/logger/zccfelog
unknown
https://fingerprintjs.com)
unknown
http://momentjs.com/guides/#/warnings/define-locale/
unknown
https://dev01apizva.zoomdev.us/
unknown
https://sa01apizva.zoom.us/
unknown
https://github.com/formatjs/formatjs/issues/1914
unknown
https://us01campaign.zoom.us/
unknown
https://st3.zoom.us/static/6.3.27088/js/lib/fingerprintjs-3.3.3.min.js
170.114.46.1
https://devcampaign.zoomdev.us/
unknown
https://us01ccistatic-cf.zoom.us/us01cci/web-sdk/
unknown
https://momentjs.com/timezone/docs/#/use-it/browser/
unknown
https://us01ccistatic.zoom.us/us01cci/web-sdk/cross-storage.html
52.84.151.43
https://reactjs.org/docs/error-decoder.html?invariant=
unknown
https://sa01ccistatic.zoom.us/sa01cci/web-sdk/
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
us01ccistatic.zoom.us
52.84.151.43
applications.zoom.us
170.114.52.74
www.zoom.us
170.114.52.2
zoom-privacy.my.onetrust.com
104.18.32.137
fp2e7a.wpc.phicdn.net
192.229.221.95
bg.microsoft.map.fastly.net
199.232.214.172
aw1vaapplications.zoom.us
170.114.12.132
edge-log-gateway-web-2f8111e8e5387748.elb.us-east-1.amazonaws.com
170.114.65.138
st1.zoom.us
170.114.46.1
www.google.com
142.250.186.68
edge-log-gateway-web-158ad3d115123922.elb.us-east-2.amazonaws.com
134.224.0.54
cdn.cookielaw.org
104.18.87.42
geolocation.onetrust.com
172.64.155.119
log-gateway.zoom.us
unknown
st3.zoom.us
unknown
miro.zoom.us
unknown
There are 6 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.186.68
www.google.com
United States
104.18.87.42
cdn.cookielaw.org
United States
170.114.52.2
www.zoom.us
United States
134.224.0.54
edge-log-gateway-web-158ad3d115123922.elb.us-east-2.amazonaws.com
United States
192.168.2.16
unknown
unknown
192.168.2.6
unknown
unknown
170.114.65.138
edge-log-gateway-web-2f8111e8e5387748.elb.us-east-1.amazonaws.com
United States
172.64.155.119
geolocation.onetrust.com
United States
52.84.151.49
unknown
United States
239.255.255.250
unknown
Reserved
104.18.32.137
zoom-privacy.my.onetrust.com
United States
52.84.151.43
us01ccistatic.zoom.us
United States
170.114.46.1
st1.zoom.us
United States
170.114.12.132
aw1vaapplications.zoom.us
United States
170.114.45.1
unknown
United States
170.114.52.74
applications.zoom.us
United States
104.18.86.42
unknown
United States
There are 7 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://www.google.com/url?q=https://applications.zoom.us/addon/invitation/detail?meetingUuid%3DwXriugcdSY%252BqAGyQ440%252Bfw%253D%253D%26signature%3D48ea33cc1f15c544aad4f3a29a13d9e53d0dee4178a5959250e94765749ba335%26v%3D1&sa=D&source=calendar&usg=AOvVaw3F9H9B9w02SkmuTB6qObxq
https://applications.zoom.us/addon/invitation/detail?meetingUuid=wXriugcdSY%2BqAGyQ440%2Bfw%3D%3D&signature=48ea33cc1f15c544aad4f3a29a13d9e53d0dee4178a5959250e94765749ba335&v=1
https://miro.zoom.us/j/93051920785#success
https://miro.zoom.us/j/93051920785#success
https://miro.zoom.us/j/93051920785#success