IOC Report
https://airispharma1-my.sharepoint.com/:o:/g/personal/anagaraj_airispharma_com/EvmEpKGsyxtGnlrgsjVRxi4BOj2g3uhzHgNY6tXqx6wp5g?e=JtdJfI

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:42 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:42 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:42 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:42 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 13:46:42 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 195
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (54875)
downloaded
Chrome Cache Entry: 198
HTML document, ASCII text, with CRLF line terminators
dropped
Chrome Cache Entry: 200
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 201
Unicode text, UTF-8 text, with very long lines (65308), with no line terminators
downloaded
Chrome Cache Entry: 202
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 203
JSON data
downloaded
Chrome Cache Entry: 204
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 207
JSON data
downloaded
Chrome Cache Entry: 209
ASCII text, with very long lines (9327)
downloaded
Chrome Cache Entry: 211
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (1922), with no line terminators
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (14666), with no line terminators
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (3527), with no line terminators
downloaded
Chrome Cache Entry: 216
PNG image data, 948 x 419, 8-bit/color RGB, non-interlaced
dropped
Chrome Cache Entry: 217
ASCII text, with very long lines (11303), with no line terminators
downloaded
Chrome Cache Entry: 218
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
downloaded
Chrome Cache Entry: 219
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
dropped
Chrome Cache Entry: 221
ASCII text, with very long lines (20082), with no line terminators
downloaded
Chrome Cache Entry: 222
ASCII text, with very long lines (61584), with CRLF line terminators
downloaded
Chrome Cache Entry: 223
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 226
ASCII text, with very long lines (1328), with no line terminators
downloaded
Chrome Cache Entry: 227
ASCII text, with very long lines (673)
downloaded
Chrome Cache Entry: 228
PNG image data, 452 x 444, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 229
Web Open Font Format, TrueType, length 151924, version 0.0
downloaded
Chrome Cache Entry: 230
Unicode text, UTF-8 text, with very long lines (56875)
downloaded
Chrome Cache Entry: 231
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 232
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 233
ASCII text, with very long lines (582)
downloaded
Chrome Cache Entry: 235
ASCII text, with very long lines (30292)
downloaded
Chrome Cache Entry: 236
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 237
ASCII text, with very long lines (7381)
downloaded
Chrome Cache Entry: 238
ASCII text, with very long lines (65449)
downloaded
Chrome Cache Entry: 240
ASCII text, with very long lines (2995)
downloaded
Chrome Cache Entry: 241
ASCII text, with very long lines (30497), with no line terminators
downloaded
Chrome Cache Entry: 242
PNG image data, 155 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 244
ASCII text, with very long lines (32011), with CRLF line terminators
downloaded
Chrome Cache Entry: 245
ASCII text, with very long lines (64762), with CRLF line terminators
downloaded
Chrome Cache Entry: 246
Unicode text, UTF-8 text, with very long lines (12695)
downloaded
Chrome Cache Entry: 247
GIF image data, version 89a, 24 x 24
dropped
Chrome Cache Entry: 250
ASCII text, with very long lines (65457)
downloaded
Chrome Cache Entry: 251
PNG image data, 102 x 102, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 252
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 253
Unicode text, UTF-8 text, with very long lines (65530), with no line terminators
downloaded
Chrome Cache Entry: 254
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 255
JSON data
dropped
Chrome Cache Entry: 256
MS Windows cursor resource - 1 icon, 32x32, hotspot @16x16
dropped
Chrome Cache Entry: 257
ASCII text, with very long lines (960)
downloaded
Chrome Cache Entry: 258
JSON data
dropped
Chrome Cache Entry: 259
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 261
PNG image data, 96 x 96, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 262
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 263
ASCII text, with very long lines (698)
downloaded
Chrome Cache Entry: 264
ASCII text, with very long lines (41569), with no line terminators
downloaded
Chrome Cache Entry: 265
JSON data
downloaded
Chrome Cache Entry: 266
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 267
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 268
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 269
ASCII text, with very long lines (32014)
downloaded
Chrome Cache Entry: 271
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 272
Unicode text, UTF-8 text, with very long lines (65535), with no line terminators
downloaded
Chrome Cache Entry: 273
JSON data
downloaded
Chrome Cache Entry: 275
ASCII text, with very long lines (7762), with no line terminators
downloaded
Chrome Cache Entry: 276
Web Open Font Format, TrueType, length 6784, version 3.30147
downloaded
Chrome Cache Entry: 277
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 278
ASCII text, with very long lines (27024), with CRLF line terminators
downloaded
Chrome Cache Entry: 279
ASCII text, with very long lines (63603)
downloaded
Chrome Cache Entry: 280
Unicode text, UTF-8 text, with very long lines (65340), with no line terminators
downloaded
Chrome Cache Entry: 282
ASCII text, with very long lines (24306), with CRLF line terminators
downloaded
Chrome Cache Entry: 283
JSON data
dropped
Chrome Cache Entry: 284
ASCII text, with very long lines (64817)
downloaded
Chrome Cache Entry: 285
JSON data
dropped
Chrome Cache Entry: 286
ASCII text, with very long lines (37190), with no line terminators
downloaded
Chrome Cache Entry: 289
PNG image data, 82 x 258, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 292
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 293
ASCII text, with very long lines (5949), with no line terminators
downloaded
Chrome Cache Entry: 294
ASCII text, with very long lines (59958)
downloaded
Chrome Cache Entry: 295
Unicode text, UTF-8 text, with very long lines (65526), with no line terminators
downloaded
Chrome Cache Entry: 296
ASCII text, with very long lines (30188)
downloaded
Chrome Cache Entry: 298
ASCII text, with very long lines (42924)
downloaded
Chrome Cache Entry: 299
JSON data
dropped
Chrome Cache Entry: 300
JSON data
dropped
Chrome Cache Entry: 301
ASCII text, with very long lines (65394)
downloaded
Chrome Cache Entry: 302
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 303
ASCII text, with very long lines (50302)
downloaded
Chrome Cache Entry: 304
ASCII text, with very long lines (65443)
downloaded
Chrome Cache Entry: 305
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 306
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 307
ASCII text, with very long lines (59989)
downloaded
Chrome Cache Entry: 308
ASCII text, with very long lines (35347)
downloaded
Chrome Cache Entry: 309
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 310
ASCII text, with very long lines (65451)
downloaded
Chrome Cache Entry: 311
ASCII text, with very long lines (2224), with no line terminators
downloaded
Chrome Cache Entry: 312
ASCII text, with very long lines (20551), with no line terminators
downloaded
Chrome Cache Entry: 313
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 314
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 315
ASCII text, with very long lines (20946), with CRLF line terminators
downloaded
Chrome Cache Entry: 318
ASCII text, with very long lines (11667), with no line terminators
downloaded
Chrome Cache Entry: 319
ASCII text, with very long lines (22549), with no line terminators
downloaded
Chrome Cache Entry: 320
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 322
MS Windows cursor resource - 1 icon, 32x32, hotspot @16x21
dropped
Chrome Cache Entry: 323
Unicode text, UTF-8 text, with very long lines (34073)
downloaded
Chrome Cache Entry: 324
ASCII text, with very long lines (4422)
downloaded
Chrome Cache Entry: 325
ASCII text, with very long lines (41116)
downloaded
Chrome Cache Entry: 326
XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
Chrome Cache Entry: 327
PNG image data, 222 x 204, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 328
ASCII text, with very long lines (22115)
downloaded
Chrome Cache Entry: 329
ASCII text, with very long lines (1835)
downloaded
Chrome Cache Entry: 330
GIF image data, version 89a, 10 x 10
dropped
Chrome Cache Entry: 331
Unicode text, UTF-8 (with BOM) text, with very long lines (18992), with CRLF line terminators
downloaded
Chrome Cache Entry: 332
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 333
HTML document, ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 334
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 336
Web Open Font Format, TrueType, length 2944, version 4.30147
downloaded
Chrome Cache Entry: 337
ASCII text, with very long lines (35239), with CRLF line terminators
downloaded
Chrome Cache Entry: 338
ASCII text, with very long lines (20116), with no line terminators
downloaded
Chrome Cache Entry: 339
ASCII text, with very long lines (31038), with no line terminators
downloaded
There are 115 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://airispharma1-my.sharepoint.com/:o:/g/personal/anagaraj_airispharma_com/EvmEpKGsyxtGnlrgsjVRxi4BOj2g3uhzHgNY6tXqx6wp5g?e=JtdJfI
malicious
https://airispharma1-my.sharepoint.com/personal/anagaraj_airispharma_com/_layouts/15/Doc.aspx?sourcedoc={a1a484f9-cbac-461b-9e5a-e0b23551c62e}&action=view&wd=target%28Brett%20Smith%20GainsboroghHealthcare.one%7Cca0044ec-ce54-40c7-9504-00c63da6bb20%2FStatements%20and%20Proposal%20Reports%C2%A0Reg%20No%2010433373%7C0aba737f-9de2-4c19-a754-e6218b1cfb0a%2F%29&wdorigin=NavigationUrl
https://www.onenote.com/officeaddins/learningtools/?et=
https://airispharma1-my.sharepoint.com/:o:/g/personal/anagaraj_airispharma_com/EvmEpKGsyxtGnlrgsjVRxi4BOj2g3uhzHgNY6tXqx6wp5g?rtime=aXTK4TVP3Eg

Domains

Name
IP
Malicious
wac-0003.wac-msedge.net
52.108.8.12
cdnjs.cloudflare.com
104.17.25.14
196542-ipv4v6.farm.dprodmgd106.aa-rt.sharepoint.com
52.105.237.25
www.google.com
142.251.16.106
part-0012.t-0009.t-msedge.net
13.107.213.40
meilhannf.online
172.67.181.168
sni1gl.wpc.sigmacdn.net
152.195.19.97
js.monitor.azure.com
unknown
augloop.office.com
unknown
storage.live.com
unknown
ajax.aspnetcdn.com
unknown
m365cdn.nel.measure.office.net
unknown
airispharma1-my.sharepoint.com
unknown
onenoteonline.nel.measure.office.net
unknown
common.online.office.com
unknown
secure.aadcdn.microsoftonline-p.com
unknown
amcdn.msftauth.net
unknown
spoprod-a.akamaihd.net
unknown
www.onenote.com
unknown
messaging.engagement.office.com
unknown
There are 10 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
52.168.117.174
unknown
United States
13.107.6.156
unknown
United States
52.105.237.25
196542-ipv4v6.farm.dprodmgd106.aa-rt.sharepoint.com
United States
13.107.246.40
unknown
United States
192.168.2.17
unknown
unknown
152.195.19.97
sni1gl.wpc.sigmacdn.net
United States
23.48.203.197
unknown
United States
152.199.4.33
unknown
United States
52.111.230.11
unknown
United States
52.108.9.12
unknown
United States
142.251.167.94
unknown
United States
23.48.203.205
unknown
United States
142.251.167.95
unknown
United States
172.67.181.168
meilhannf.online
United States
20.135.1.0
unknown
United States
184.28.134.161
unknown
United States
23.61.11.21
unknown
United States
13.107.213.40
part-0012.t-0009.t-msedge.net
United States
13.105.221.39
unknown
United States
23.53.35.72
unknown
United States
23.215.0.235
unknown
United States
52.113.194.132
unknown
United States
1.1.1.1
unknown
Australia
13.105.221.2
unknown
United States
23.12.145.11
unknown
United States
20.189.173.24
unknown
United States
52.108.8.12
wac-0003.wac-msedge.net
United States
172.253.122.100
unknown
United States
142.251.16.106
www.google.com
United States
23.12.144.117
unknown
United States
239.255.255.250
unknown
Reserved
20.190.151.8
unknown
United States
184.28.130.71
unknown
United States
20.190.151.7
unknown
United States
52.111.229.20
unknown
United States
142.251.16.94
unknown
United States
104.17.25.14
cdnjs.cloudflare.com
United States
142.251.163.84
unknown
United States
13.89.179.8
unknown
United States
There are 29 hidden IPs, click here to show them.