IOC Report
https://google.so/url?hl=en&q=https://www.google.com/url?hl%3Den%26q%3Dhttps://google.com.au/url?sa%253Dt%2526q%253Dp2%2526rct%253DsI%2526esrc%253Dugsj%2526source%253Dgrg%2526cd%253DHMMA%2526cad%253DpAVyup%2526ved%253DzKj287AcWuEUbg%2526uact%253D837%2526url%253D%252561%25256D%252570%25252F%252567%25

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:06:55 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:06:55 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:06:55 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:06:55 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:06:54 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 101
ASCII text, with very long lines (1222), with no line terminators
downloaded
Chrome Cache Entry: 102
PNG image data, 48 x 48, 8-bit gray+alpha, non-interlaced
dropped
Chrome Cache Entry: 104
PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 107
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 109
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 110
PNG image data, 48 x 48, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 111
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 112
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 113
HTML document, ASCII text
dropped
Chrome Cache Entry: 114
Web Open Font Format (Version 2), TrueType, length 15340, version 1.0
downloaded
Chrome Cache Entry: 117
ASCII text, with very long lines (17572)
downloaded
Chrome Cache Entry: 118
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 119
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 450x450, components 3
downloaded
Chrome Cache Entry: 120
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 121
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 122
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 123
PNG image data, 48 x 48, 8-bit gray+alpha, non-interlaced
downloaded
Chrome Cache Entry: 130
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
downloaded
Chrome Cache Entry: 81
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
downloaded
Chrome Cache Entry: 82
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 300x300, components 3
downloaded
Chrome Cache Entry: 83
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 84
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 87
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 88
MS Windows icon resource - 2 icons, 16x16, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 90
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 91
ASCII text, with very long lines (56398), with no line terminators
downloaded
Chrome Cache Entry: 92
ASCII text, with very long lines (596)
downloaded
Chrome Cache Entry: 93
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 450x450, components 3
downloaded
Chrome Cache Entry: 94
JPEG image data, JFIF standard 1.02, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 100x100, components 3
dropped
Chrome Cache Entry: 98
ASCII text, with very long lines (786)
downloaded
There are 27 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://google.so/url?hl=en&q=https://www.google.com/url?hl%3Den%26q%3Dhttps://google.com.au/url?sa%253Dt%2526q%253Dp2%2526rct%253DsI%2526esrc%253Dugsj%2526source%253Dgrg%2526cd%253DHMMA%2526cad%253DpAVyup%2526ved%253DzKj287AcWuEUbg%2526uact%253D837%2526url%253D%252561%25256D%252570%25252F%252567%25256F%25256F%252567%25256C%252565%25252E%252561%252565%25252F%252561%25256D%252570%25252F%252574%252569%25256E%252579%252575%252572%25256C%25252E%252563%25256F%25256D%25252F%252533%252577%252532%25256B%25256E%252572%25257A%25256A%2526opi%253D3494519500038%2526usg%253DRzaOw6anlsFgBj?xls%253Dhofkubiam%2526gacx%253Duasuopw%2526ukjqp%253Dvkdlivuz%2526aqeoo%253Dqwyxpmzdh%2526ytbc%253Dpuphwlifc%2526dgbea%253Dzymqknaa%2526wxtq%253Dnhrzagdzh%2526aygmx%253Dedlswindx%2526eeud%253Dfogcopwgj%2526gkurn%253Dsphbjbgtp%2526igu%253Dqbplxohn%2526ecnts%253Djyiikbm%2526cjyu%253Dpfubqzc%2526yruis%253Dcenlyjz%2526vwssw%253Dbeqrosqw%26source%3Dgmail%26ust%3D1711716857165000%26usg%3DAOvVaw08MlsAU1JS58Z0tVZlqcEz&source=gmail&ust=1711716900794000&usg=AOvVaw0AWWetyXWif859JzWggAQ1
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=moV1mTgQ6S91nuTnmll4Y9yf&size=normal&s=36ooCK3Gj1ttxW1jd_w1dwlj8UnycEiNzZVMDlszDfK6UBxxDIw815z1xl36R3j_c2JmEnohCH1HoxIkOA4JuXF9i1dLzRXAB03gOX-6WjTWnu8zYmW_rgP_UKHvTC296sVLL5NHZWYFAOx5gA6A3UpuX-ev-yvx56kx5IdmD61RcmigCi_u7L-PQFhCV_nFTl7uGVz_F9GOuPp54ITVcEXSGwenD_wiPzOc_qwo2-ffBz8bURARRq5GtxL39KBcRghb7DAM9yc5lPtMlpXEdobWYodIARA&cb=9f73q6vsvnp
https://www.google.com/recaptcha/api2/anchor?ar=1&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b&co=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbTo0NDM.&hl=en&v=moV1mTgQ6S91nuTnmll4Y9yf&size=normal&s=5FoML11Jq29c_G65qn6woR4pC2vPwULpuqTgNNueHOG60ih_InIf4yDY8DP4Sdin_E23o84R-NLOuAQv71NYdka9GHEwzl0yY3cLJJV1rAu-qUmbVWNQQz2gifuaDRIpOZy-AgV2VwNkXq9-Ypo4rnCg2-VDpM67JyfFyYTMHisHHyLzLziBI29c2HBf4r6FqTrDEId3t4FaCKlYv5l316qrlm7mzcDJeuyrJ30gn5KJsNIevNoWcvSkvhqOCsKD12344zyNyuWOI_C_Y8Jn42u6lU0gSGM&cb=q5wo6sssuqtf
https://www.google.com/recaptcha/api2/bframe?hl=en&v=moV1mTgQ6S91nuTnmll4Y9yf&k=6LfwuyUTAAAAAOAmoS0fdqijC2PbbdH4kjq62Y1b
http://sb7q7yvjw.umuvnxwjwhzhy.buzz/XSLVSlA
24.144.68.200
https://www.google.com/sorry/index?continue=https://www.google.com.au/amp/google.ae/amp/tinyurl.com/3w2knrzj&q=EgRmpTArGIHzlbAGIjD7klv9Bq5P028Xq-57M7bpB9kHM7nPi-fnKSAJFJ6etg5t8Z0hWifabwm8ZEW4CT8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
about:blank
https://www.google.com/sorry/index?continue=https://google.ae/amp/tinyurl.com/3w2knrzj&q=EgRmpTArGJ_zlbAGIjAuTbAEsNAfp3buVTy2S5JsQVLWJyUy1XU9Nysvwl_SU37jHKyvezPG9ihAg-_wAIoyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM

Domains

Name
IP
Malicious
google.com.au
142.251.16.94
tinyurl.com
172.67.1.225
google.com
142.251.16.139
google.so
172.253.115.94
www.google.so
172.253.62.94
www.google.com
172.253.63.104
google.ae
142.251.167.94
www.google.com.au
142.251.111.94
www.google.ae
142.251.167.94
sb7q7yvjw.umuvnxwjwhzhy.buzz
24.144.68.200
0m3simmn5w1ri0cy.com
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.251.179.94
unknown
United States
1.1.1.1
unknown
Australia
142.250.31.101
unknown
United States
172.253.63.104
www.google.com
United States
192.168.2.17
unknown
unknown
172.253.62.94
www.google.so
United States
192.168.2.16
unknown
unknown
172.67.1.225
tinyurl.com
United States
24.144.68.200
sb7q7yvjw.umuvnxwjwhzhy.buzz
United States
142.251.111.94
www.google.com.au
United States
172.253.63.100
unknown
United States
172.253.122.84
unknown
United States
142.251.167.94
google.ae
United States
8.8.8.8
unknown
United States
239.255.255.250
unknown
Reserved
142.251.16.94
google.com.au
United States
142.251.167.99
unknown
United States
172.253.115.94
google.so
United States
142.251.163.95
unknown
United States
There are 9 hidden IPs, click here to show them.