IOC Report
http://url9772.onlinedatareports.com/ls/click?upn=u001.ixzAc7ho4QPh1ym7GP1v7N8jbteRIgHYy3r13L-2Bxr-2BGNizhKtAWG4WsSaJnHYPG80577_3SwlBiW7haPbr-2F-2BqkjZhZHoWqX-2BW8wdxT8icvQSk-2FNptP5BEOKfRY-2B1Rds5JxogEjAzYGQuo7CfOLZ4FJOOusEyXQcaDvPBy8PXt9nDzeHOGiBNUeTQpW36n1snQjTedeEOPOZpIgHlJcHKc7PWmbriqEzgflRnimC

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 11:28:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 11:28:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 11:28:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 11:28:04 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 11:28:03 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 106
ASCII text, with very long lines (65397)
downloaded
Chrome Cache Entry: 107
ASCII text, with very long lines (432)
downloaded
Chrome Cache Entry: 108
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 109
ASCII text
dropped
Chrome Cache Entry: 110
ASCII text, with very long lines (20033)
downloaded
Chrome Cache Entry: 111
ASCII text, with very long lines (65462)
downloaded
Chrome Cache Entry: 113
C++ source, ASCII text
downloaded
Chrome Cache Entry: 114
C++ source, ASCII text
downloaded
Chrome Cache Entry: 115
Unicode text, UTF-8 text, with very long lines (11177), with no line terminators
downloaded
Chrome Cache Entry: 116
C++ source, ASCII text
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (481)
downloaded
Chrome Cache Entry: 119
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 120
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 121
C++ source, ASCII text
downloaded
Chrome Cache Entry: 122
ASCII text, with very long lines (65462)
downloaded
Chrome Cache Entry: 123
gzip compressed data, was "tmpc32vauyc", last modified: Mon Mar 25 18:18:55 2024, max compression, original size modulo 2^32 258414
downloaded
Chrome Cache Entry: 124
gzip compressed data, original size modulo 2^32 4263
dropped
Chrome Cache Entry: 125
JSON data
dropped
Chrome Cache Entry: 126
Java source, ASCII text
downloaded
Chrome Cache Entry: 127
C++ source, ASCII text
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (6667)
downloaded
Chrome Cache Entry: 129
C++ source, ASCII text
downloaded
Chrome Cache Entry: 131
ASCII text, with very long lines (5955)
downloaded
Chrome Cache Entry: 133
C++ source, ASCII text
downloaded
Chrome Cache Entry: 135
C++ source, ASCII text
downloaded
Chrome Cache Entry: 136
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 137
data
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (32087)
downloaded
Chrome Cache Entry: 141
JSON data
dropped
Chrome Cache Entry: 142
JSON data
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (419), with no line terminators
downloaded
Chrome Cache Entry: 144
C++ source, ASCII text
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 146
ASCII text, with very long lines (7471), with no line terminators
downloaded
Chrome Cache Entry: 147
HTML document, ASCII text, with very long lines (8911), with no line terminators
downloaded
Chrome Cache Entry: 148
JSON data
downloaded
Chrome Cache Entry: 149
PNG image data, 192 x 192, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (38062)
downloaded
Chrome Cache Entry: 151
C++ source, ASCII text
downloaded
Chrome Cache Entry: 152
C++ source, ASCII text
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (5557)
downloaded
Chrome Cache Entry: 154
MS Windows icon resource - 5 icons, 16x16, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 155
C++ source, ASCII text
downloaded
There are 40 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://url9772.onlinedatareports.com/ls/click?upn=u001.ixzAc7ho4QPh1ym7GP1v7N8jbteRIgHYy3r13L-2Bxr-2BGNizhKtAWG4WsSaJnHYPG80577_3SwlBiW7haPbr-2F-2BqkjZhZHoWqX-2BW8wdxT8icvQSk-2FNptP5BEOKfRY-2B1Rds5JxogEjAzYGQuo7CfOLZ4FJOOusEyXQcaDvPBy8PXt9nDzeHOGiBNUeTQpW36n1snQjTedeEOPOZpIgHlJcHKc7PWmbriqEzgflRnimClKO-2BzMDAZrQsD-2BTLH7O1eEkGpGPahzhBfByMr9XRQw-2FfEC-2FscM2A-3D-3D
https://secure.livechatinc.com/customer/action/open_chat?license_id=7139371&group=0&embedded=1&widget_version=3&unique_groups=0
https://www.onlinedatareports.com/

Domains

Name
IP
Malicious
jsdelivr.map.fastly.net
151.101.1.229
rs.fullstory.com
35.186.194.58
sendgrid.net
167.89.115.150
www.google.com
142.251.16.104
posthog-ingress-prod-us-256455477.us-east-1.elb.amazonaws.com
52.2.56.108
edge.fullstory.com
35.201.112.186
www.onlinedatareports.com
99.84.108.109
b2723a579581.38f2a8b0.us-east-1.token.awswaf.com
18.173.219.112
unpkg.com
104.16.122.175
www.woopra.com
162.55.95.218
url9772.onlinedatareports.com
unknown
us.i.posthog.com
unknown
cdn.jsdelivr.net
unknown
secure.livechatinc.com
unknown
api.livechatinc.com
unknown
app.posthog.com
unknown
accounts.livechatinc.com
unknown
cdn.livechatinc.com
unknown
static.woopra.com
unknown
cdn-4.convertexperiments.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
13.249.39.126
unknown
United States
104.16.122.175
unpkg.com
United States
142.251.111.101
unknown
United States
162.55.95.218
www.woopra.com
United States
23.222.79.202
unknown
United States
99.84.108.109
www.onlinedatareports.com
United States
35.186.194.58
rs.fullstory.com
United States
151.101.1.91
unknown
United States
192.168.2.17
unknown
unknown
172.253.62.94
unknown
United States
23.48.203.199
unknown
United States
52.2.56.108
posthog-ingress-prod-us-256455477.us-east-1.elb.amazonaws.com
United States
99.84.108.90
unknown
United States
172.253.122.113
unknown
United States
167.89.115.150
sendgrid.net
United States
142.251.16.138
unknown
United States
142.251.167.94
unknown
United States
172.253.62.97
unknown
United States
99.84.108.111
unknown
United States
142.251.163.95
unknown
United States
151.101.1.229
jsdelivr.map.fastly.net
United States
23.222.79.139
unknown
United States
3.211.0.126
unknown
United States
23.61.11.170
unknown
United States
167.89.115.120
unknown
United States
142.251.16.104
www.google.com
United States
52.203.3.42
unknown
United States
18.173.219.112
b2723a579581.38f2a8b0.us-east-1.token.awswaf.com
United States
23.53.35.104
unknown
United States
172.253.63.102
unknown
United States
23.53.35.106
unknown
United States
184.31.74.253
unknown
United States
35.201.112.186
edge.fullstory.com
United States
239.255.255.250
unknown
Reserved
99.84.108.106
unknown
United States
23.48.104.108
unknown
United States
23.222.79.177
unknown
United States
172.253.115.84
unknown
United States
There are 28 hidden IPs, click here to show them.