IOC Report
https://ss0.secu-net.com/fr/?code=2f627787a416f93889893c8d8587c58f

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:06 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://ss0.secu-net.com/fr/?code=2f627787a416f93889893c8d8587c58f
https://learning.sosafe.de/fr/?code=2f627787a416f93889893c8d8587c58f&forward=1
https://ss0.secu-net.com/fr/?code=2f627787a416f93889893c8d8587c58f
about:blank
https://sosafe-awareness.com/
https://consentcdn.cookiebot.com/sdk/bc-v4.min.html

Domains

Name
IP
Malicious
in.requestmetrics.com
51.161.119.93
ss0.secu-net.com
18.196.141.145
js.hs-analytics.net
104.16.76.186
storage.sosafe.de
52.29.243.220
scontent.xx.fbcdn.net
157.240.229.1
track.hubspot.com
104.19.155.83
cdn.matomo.cloud
3.162.125.80
www.google.com
172.253.63.147
sosafe-awareness.com
162.159.135.42
sentry.sosafe.de
18.196.56.76
js.hs-banner.com
104.18.34.229
star-mini.c10r.facebook.com
31.13.66.35
domain-proxy.sosafe.de
52.58.161.79
fonts.luna1.co
151.101.129.187
learning.sosafe.de
52.58.161.79
js.hsadspixel.net
104.17.230.163
api.sosafe.de
3.120.29.182
requestmetrics.b-cdn.net
37.19.207.34
dualstack.reddit.map.fastly.net
151.101.1.140
js-na1.hs-scripts.com
104.16.191.89
sosafeawareness.matomo.cloud
3.126.133.169
googleads.g.doubleclick.net
172.253.63.155
reddit.map.fastly.net
151.101.129.140
api.hubapi.com
104.17.200.204
sosafe.de
162.159.135.42
td.doubleclick.net
142.251.167.155
alb.reddit.com
unknown
cdn.requestmetrics.com
unknown
imgsct.cookiebot.com
unknown
consentcdn.cookiebot.com
unknown
www.facebook.com
unknown
www.redditstatic.com
unknown
consent.cookiebot.com
unknown
www.linkedin.com
unknown
px.ads.linkedin.com
unknown
connect.facebook.net
unknown
snap.licdn.com
unknown
There are 27 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
104.19.155.83
track.hubspot.com
United States
35.157.186.222
unknown
United States
104.17.230.163
js.hsadspixel.net
United States
204.79.197.200
unknown
United States
172.253.63.155
googleads.g.doubleclick.net
United States
142.251.16.139
unknown
United States
192.168.2.5
unknown
unknown
172.253.115.104
unknown
United States
151.101.193.140
unknown
United States
1.1.1.1
unknown
Australia
104.19.154.83
unknown
United States
172.253.122.105
unknown
United States
3.162.125.80
cdn.matomo.cloud
United States
142.251.111.95
unknown
United States
3.126.133.169
sosafeawareness.matomo.cloud
United States
23.48.104.112
unknown
United States
18.159.83.140
unknown
United States
172.253.122.95
unknown
United States
172.253.63.147
www.google.com
United States
172.253.122.94
unknown
United States
13.107.42.14
unknown
United States
239.255.255.250
unknown
Reserved
23.12.145.26
unknown
United States
51.161.119.93
in.requestmetrics.com
Canada
172.253.62.113
unknown
United States
18.185.173.228
unknown
United States
184.29.162.140
unknown
United States
192.168.2.17
unknown
unknown
52.29.171.86
unknown
United States
192.168.2.16
unknown
unknown
104.17.200.204
api.hubapi.com
United States
142.251.167.94
unknown
United States
37.19.207.34
requestmetrics.b-cdn.net
Ukraine
18.195.157.64
unknown
United States
142.251.163.97
unknown
United States
18.194.31.53
unknown
United States
104.17.201.204
unknown
United States
142.251.179.84
unknown
United States
52.58.161.79
domain-proxy.sosafe.de
United States
31.13.66.35
star-mini.c10r.facebook.com
Ireland
142.251.167.155
td.doubleclick.net
United States
104.18.34.229
js.hs-banner.com
United States
18.196.56.76
sentry.sosafe.de
United States
157.240.229.1
scontent.xx.fbcdn.net
United States
151.101.1.140
dualstack.reddit.map.fastly.net
United States
104.16.191.89
js-na1.hs-scripts.com
United States
18.196.141.145
ss0.secu-net.com
United States
52.29.243.220
storage.sosafe.de
United States
162.159.135.42
sosafe-awareness.com
United States
52.57.124.55
unknown
United States
3.120.29.182
api.sosafe.de
United States
18.158.129.130
unknown
United States
104.16.76.186
js.hs-analytics.net
United States
151.101.129.140
reddit.map.fastly.net
United States
151.101.129.187
fonts.luna1.co
United States
There are 45 hidden IPs, click here to show them.