IOC Report
https://forms.gle/uegGMX3eHYKZmZss5

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 14:24:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 14:24:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 14:24:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 14:24:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 14:24:29 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 122
Web Open Font Format (Version 2), TrueType, length 58012, version 1.0
downloaded
Chrome Cache Entry: 123
Web Open Font Format (Version 2), TrueType, length 1360, version 1.0
downloaded
Chrome Cache Entry: 124
PNG image data, 624 x 380, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 125
Web Open Font Format (Version 2), TrueType, length 129672, version 1.0
downloaded
Chrome Cache Entry: 126
Web Open Font Format (Version 2), TrueType, length 31456, version 1.0
downloaded
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 72784, version 1.0
downloaded
Chrome Cache Entry: 128
Web Open Font Format (Version 2), TrueType, length 42132, version 1.0
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (1719)
downloaded
Chrome Cache Entry: 130
Web Open Font Format (Version 2), TrueType, length 4196, version 1.0
downloaded
Chrome Cache Entry: 131
Web Open Font Format (Version 2), TrueType, length 64068, version 1.0
downloaded
Chrome Cache Entry: 132
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 133
Web Open Font Format (Version 2), TrueType, length 1756, version 1.0
downloaded
Chrome Cache Entry: 134
HTML document, ASCII text, with very long lines (682)
downloaded
Chrome Cache Entry: 135
Web Open Font Format (Version 2), TrueType, length 1664, version 1.0
downloaded
Chrome Cache Entry: 136
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 137
Web Open Font Format (Version 2), TrueType, length 45536, version 1.0
downloaded
Chrome Cache Entry: 138
Web Open Font Format (Version 2), TrueType, length 39708, version 1.0
downloaded
Chrome Cache Entry: 139
Web Open Font Format (Version 2), TrueType, length 58892, version 1.0
downloaded
Chrome Cache Entry: 140
Web Open Font Format (Version 2), TrueType, length 37488, version 1.0
downloaded
Chrome Cache Entry: 141
Web Open Font Format (Version 2), TrueType, length 64164, version 1.0
downloaded
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 44316, version 1.0
downloaded
Chrome Cache Entry: 143
Web Open Font Format (Version 2), TrueType, length 2568, version 1.0
downloaded
Chrome Cache Entry: 144
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 145
Web Open Font Format (Version 2), TrueType, length 60648, version 1.0
downloaded
Chrome Cache Entry: 146
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 147
Web Open Font Format (Version 2), TrueType, length 36840, version 1.0
downloaded
Chrome Cache Entry: 148
Web Open Font Format (Version 2), TrueType, length 41676, version 1.0
downloaded
Chrome Cache Entry: 149
Web Open Font Format (Version 2), TrueType, length 2484, version 1.0
downloaded
Chrome Cache Entry: 150
Web Open Font Format (Version 2), TrueType, length 65812, version 1.0
downloaded
Chrome Cache Entry: 151
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 152
Web Open Font Format (Version 2), TrueType, length 40412, version 1.0
downloaded
Chrome Cache Entry: 153
Web Open Font Format (Version 2), TrueType, length 50476, version 1.0
downloaded
Chrome Cache Entry: 154
Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
downloaded
Chrome Cache Entry: 155
Web Open Font Format (Version 2), TrueType, length 41284, version 1.0
downloaded
Chrome Cache Entry: 156
Web Open Font Format (Version 2), TrueType, length 1416, version 1.0
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (4199)
downloaded
Chrome Cache Entry: 158
Web Open Font Format (Version 2), TrueType, length 25980, version 1.0
downloaded
Chrome Cache Entry: 159
Web Open Font Format (Version 2), TrueType, length 1516, version 1.0
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (1719)
dropped
Chrome Cache Entry: 161
Web Open Font Format (Version 2), TrueType, length 143084, version 1.0
downloaded
Chrome Cache Entry: 162
Web Open Font Format (Version 2), TrueType, length 46840, version 1.0
downloaded
Chrome Cache Entry: 163
Web Open Font Format (Version 2), TrueType, length 3576, version 1.0
downloaded
Chrome Cache Entry: 164
Web Open Font Format (Version 2), TrueType, length 55204, version 1.0
downloaded
Chrome Cache Entry: 165
Web Open Font Format (Version 2), TrueType, length 50664, version 1.0
downloaded
Chrome Cache Entry: 166
Web Open Font Format (Version 2), TrueType, length 26936, version 1.0
downloaded
Chrome Cache Entry: 167
Web Open Font Format (Version 2), TrueType, length 40184, version 1.0
downloaded
Chrome Cache Entry: 168
Web Open Font Format (Version 2), TrueType, length 2708, version 1.0
downloaded
Chrome Cache Entry: 169
ASCII text, with very long lines (777)
downloaded
Chrome Cache Entry: 170
Web Open Font Format (Version 2), TrueType, length 57612, version 1.0
downloaded
Chrome Cache Entry: 171
Web Open Font Format (Version 2), TrueType, length 32644, version 1.0
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (1631)
downloaded
Chrome Cache Entry: 173
Web Open Font Format (Version 2), TrueType, length 58200, version 1.0
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (405)
downloaded
Chrome Cache Entry: 175
Web Open Font Format (Version 2), TrueType, length 41288, version 1.0
downloaded
Chrome Cache Entry: 176
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 177
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 178
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 179
Web Open Font Format (Version 2), TrueType, length 3640, version 1.0
downloaded
Chrome Cache Entry: 180
Web Open Font Format (Version 2), TrueType, length 4344, version 1.0
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (512)
downloaded
Chrome Cache Entry: 182
Web Open Font Format (Version 2), TrueType, length 99952, version 1.0
downloaded
Chrome Cache Entry: 183
Web Open Font Format (Version 2), TrueType, length 50264, version 1.0
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (1719)
dropped
Chrome Cache Entry: 185
Web Open Font Format (Version 2), TrueType, length 64656, version 1.0
downloaded
Chrome Cache Entry: 186
Web Open Font Format (Version 2), TrueType, length 1528, version 1.0
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (3383)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (2360)
downloaded
Chrome Cache Entry: 189
Web Open Font Format (Version 2), TrueType, length 41584, version 1.0
downloaded
Chrome Cache Entry: 190
Web Open Font Format (Version 2), TrueType, length 41220, version 1.0
downloaded
Chrome Cache Entry: 191
Web Open Font Format (Version 2), TrueType, length 100756, version 1.0
downloaded
Chrome Cache Entry: 192
Web Open Font Format (Version 2), TrueType, length 54324, version 1.0
downloaded
Chrome Cache Entry: 193
Web Open Font Format (Version 2), TrueType, length 84892, version 1.0
downloaded
Chrome Cache Entry: 194
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 195
Web Open Font Format (Version 2), TrueType, length 126552, version 1.0
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (1299)
downloaded
Chrome Cache Entry: 197
PNG image data, 624 x 380, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 198
ASCII text, with very long lines (1719)
downloaded
Chrome Cache Entry: 199
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 200
Web Open Font Format (Version 2), TrueType, length 37800, version 1.0
downloaded
Chrome Cache Entry: 201
Web Open Font Format (Version 2), TrueType, length 116720, version 1.0
downloaded
Chrome Cache Entry: 202
Web Open Font Format (Version 2), TrueType, length 57236, version 1.0
downloaded
Chrome Cache Entry: 203
Web Open Font Format (Version 2), TrueType, length 54776, version 1.0
downloaded
Chrome Cache Entry: 204
Web Open Font Format (Version 2), TrueType, length 34108, version 1.0
downloaded
Chrome Cache Entry: 205
Web Open Font Format (Version 2), TrueType, length 1260, version 1.0
downloaded
Chrome Cache Entry: 206
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 207
Web Open Font Format (Version 2), TrueType, length 37632, version 1.0
downloaded
Chrome Cache Entry: 208
Web Open Font Format (Version 2), TrueType, length 43772, version 1.0
downloaded
Chrome Cache Entry: 209
Web Open Font Format (Version 2), TrueType, length 5044, version 1.0
downloaded
Chrome Cache Entry: 210
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 211
ASCII text, with very long lines (609)
dropped
Chrome Cache Entry: 212
Web Open Font Format (Version 2), TrueType, length 15744, version 1.0
downloaded
Chrome Cache Entry: 213
ASCII text
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (609)
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (467)
downloaded
Chrome Cache Entry: 216
ASCII text
downloaded
Chrome Cache Entry: 217
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 218
Web Open Font Format (Version 2), TrueType, length 47364, version 1.0
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (656)
downloaded
Chrome Cache Entry: 220
Web Open Font Format (Version 2), TrueType, length 72264, version 1.0
downloaded
Chrome Cache Entry: 221
Web Open Font Format (Version 2), TrueType, length 64888, version 1.0
downloaded
Chrome Cache Entry: 222
Web Open Font Format (Version 2), TrueType, length 35060, version 1.0
downloaded
Chrome Cache Entry: 223
ASCII text
downloaded
Chrome Cache Entry: 224
ASCII text, with very long lines (693)
downloaded
Chrome Cache Entry: 225
Web Open Font Format (Version 2), TrueType, length 50340, version 1.0
downloaded
Chrome Cache Entry: 226
Web Open Font Format (Version 2), TrueType, length 4280, version 1.0
downloaded
Chrome Cache Entry: 227
Web Open Font Format (Version 2), TrueType, length 105776, version 1.0
downloaded
Chrome Cache Entry: 228
Web Open Font Format (Version 2), TrueType, length 42296, version 1.0
downloaded
Chrome Cache Entry: 229
Web Open Font Format (Version 2), TrueType, length 1420, version 1.0
downloaded
Chrome Cache Entry: 230
PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 231
Web Open Font Format (Version 2), TrueType, length 44980, version 1.0
downloaded
Chrome Cache Entry: 232
ASCII text, with very long lines (17242)
downloaded
There are 108 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://forms.gle/uegGMX3eHYKZmZss5
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1980,i,6190785327670335455,15667986563799497857,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
https://forms.gle/uegGMX3eHYKZmZss5
https://play.google/intl/
unknown
http://localhost.corp.google.com/inapp/
unknown
https://families.google.com/intl/
unknown
https://feedback.googleusercontent.com/resources/annotator.css
unknown
https://youtube.com/embed/?rel=0
unknown
https://apis.google.com/js/client.js
unknown
https://feedback2-test.corp.googleusercontent.com/tools/feedback/%
unknown
https://policies.google.com/technologies/location-data
unknown
https://support.google.com
unknown
https://play.google.com
unknown
https://youtube.com/embed/
unknown
http://localhost.proxy.googlers.com/inapp/
unknown
https://stagingqual-feedback-pa-googleapis.sandbox.google.com
unknown
https://support.google.com/inapp/%
unknown
https://asx-help-frontend-autopush.corp.youtube.com/inapp/
unknown
https://play.google.com/work/enroll?identifier=
unknown
https://policies.google.com/terms/service-specific
unknown
https://g.co/recover
unknown
https://support.google.com/websearch/answer/4358949?hl=ko&ref_topic=3285072
unknown
https://help.youtube.com/tools/feedback/
unknown
https://policies.google.com/technologies/cookies
unknown
https://policies.google.com/terms
unknown
https://asx-frontend-staging.corp.google.com/tools/feedback/
unknown
https://support.google.com/
unknown
https://www.google.com
unknown
https://csp.withgoogle.com/csp/report-to/gse_qebhlk
172.253.122.141
https://www.youtube.com/t/terms?chromeless=1&hl=
unknown
https://scone-pa.clients6.google.com
unknown
https://support.google.com/inapp/
unknown
https://asx-frontend-autopush.corp.google.co.uk/inapp/
unknown
https://asx-frontend-autopush.corp.google.co.uk/tools/feedback/
unknown
https://asx-frontend-autopush.corp.google.com/tools/feedback/
unknown
https://asx-frontend-autopush.corp.youtube.com/tools/feedback/
unknown
https://support.google.com/accounts?p=new-si-ui
unknown
https://apis.google.com/js/rpc:shindig_random.js?onload=credentialservice.postMessage
unknown
https://feedback2-test.corp.google.com/inapp/%
unknown
https://www.google.com/tools/feedback
unknown
https://forms.gle/uegGMX3eHYKZmZss5
199.36.158.100
https://youtube.com/t/terms?gl=
unknown
https://sandbox.google.com/inapp/%
unknown
https://www.google.com/intl/
unknown
https://apis.google.com/js/api.js
unknown
https://feedback2-test.corp.googleusercontent.com/inapp/%
unknown
https://localhost.proxy.googlers.com/inapp/
unknown
https://policies.google.com/privacy/google-partners
unknown
https://www.google.com/tools/feedback/
unknown
https://www.google.cn/tools/feedback/
unknown
https://policies.google.com/privacy/additional
unknown
https://play.google.com/log?format=json&hasfast=true&authuser=0
172.253.63.113
https://asx-frontend-autopush.corp.google.de/inapp/
unknown
https://www.google.cn/tools/feedback/%
unknown
https://feedback2-test.corp.google.com/tools/feedback/%
unknown
https://www.google.com/tools/feedback/help_panel_binary.js
unknown
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/viewform
https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
unknown
https://asx-frontend-autopush.corp.google.de/tools/feedback/
unknown
https://sandbox.google.com/inapp/
unknown
https://test-scone-pa-googleapis.sandbox.google.com
unknown
https://asx-help-frontend-autopush.corp.youtube.com/tools/feedback/
unknown
https://play.google.com/log?format=json&hasfast=true
unknown
https://asx-frontend-autopush.corp.google.com/inapp/
unknown
https://feedback.googleusercontent.com/resources/render_frame2.html
unknown
https://policies.google.com/privacy/additional/embedded?gl=kr
unknown
https://sandbox.google.com/tools/feedback/%
unknown
https://policies.google.com/terms/location/embedded
unknown
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/viewform?usp=send_form
172.253.115.101
https://sandbox.google.com/tools/feedback/
unknown
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/font/getmetadata
172.253.115.101
https://localhost.corp.google.com/inapp/
unknown
https://support.google.com/accounts?hl=
unknown
https://asx-frontend-autopush.corp.youtube.com/inapp/
unknown
https://policies.google.com/privacy
unknown
https://feedback-pa.clients6.google.com
unknown
https://asx-frontend-staging.corp.google.com/inapp/
unknown
https://www.google.com/tools/feedback/%
unknown
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/formResponse
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/naLogImpressions
172.253.115.101
https://fonts.google.com/license/googlerestricted
unknown
There are 68 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
docs.google.com
172.253.115.101
csp.withgoogle.com
172.253.122.141
play.google.com
172.253.63.113
www3.l.google.com
142.251.111.100
forms.gle
199.36.158.100
www.google.com
142.251.163.103
accounts.youtube.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.31.100
unknown
United States
192.168.2.16
unknown
unknown
192.168.2.7
unknown
unknown
172.253.122.141
csp.withgoogle.com
United States
142.251.163.103
www.google.com
United States
172.253.63.113
play.google.com
United States
199.36.158.100
forms.gle
United States
172.253.115.138
unknown
United States
239.255.255.250
unknown
Reserved
172.253.115.101
docs.google.com
United States

DOM / HTML

URL
Malicious
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/viewform
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/formResponse
https://docs.google.com/forms/d/e/1FAIpQLSfjStKBev-KZoDUt77zXrQzLhhnzBWfQE4iQVduo99aAn6DMQ/formResponse