IOC Report
http://drnavingupta.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 18:44:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 18:44:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 18:44:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 18:44:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Mar 28 18:44:50 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 100
ASCII text
downloaded
Chrome Cache Entry: 101
Web Open Font Format (Version 2), TrueType, length 34852, version 1.0
downloaded
Chrome Cache Entry: 104
JPEG image data, JFIF standard 1.01, resolution (DPI), density 300x300, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=13, manufacturer=NIKON CORPORATION, model=NIKON D7000, orientation=upper-left, xresolution=200, yresolution=208, resolutionunit=2, software=Ver.1.03 , datetime=2018:01:14 15:25:25], baseline, precision 8, 1000x662, components 3
dropped
Chrome Cache Entry: 105
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 32x32, components 3
dropped
Chrome Cache Entry: 107
gzip compressed data, from Unix, original size modulo 2^32 69
downloaded
Chrome Cache Entry: 108
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 800x506, components 3
downloaded
Chrome Cache Entry: 109
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 110
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 800x600, components 3
dropped
Chrome Cache Entry: 111
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 627x464, components 3
downloaded
Chrome Cache Entry: 112
gzip compressed data, from Unix, original size modulo 2^32 1889
downloaded
Chrome Cache Entry: 113
JPEG image data, JFIF standard 1.01, resolution (DPI), density 600x600, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=15], baseline, precision 8, 1536x672, components 1
dropped
Chrome Cache Entry: 114
JPEG image data, JFIF standard 1.02, resolution (DPI), density 72x72, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=12, manufacturer=Panasonic, model=DMC-FZ18, orientation=upper-left, xresolution=177, yresolution=185, resolutionunit=2, software=Adobe Photoshop 7.0, datetime=2009:07:12 06:51:02], baseline, precision 8, 800x644, components 3
downloaded
Chrome Cache Entry: 117
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 119
JPEG image data, JFIF standard 1.01, resolution (DPI), density 180x180, segment length 16, Exif Standard: [TIFF image data, little-endian, direntries=8, description= , manufacturer=Canon, model=Canon PowerShot A3100 IS, datetime=2011:02:21 13:53:31], baseline, precision 8, 1024x534, components 3
dropped
Chrome Cache Entry: 120
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 800x462, components 3
dropped
Chrome Cache Entry: 122
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 123
gzip compressed data, from Unix, original size modulo 2^32 2979
downloaded
Chrome Cache Entry: 125
gzip compressed data, from Unix, original size modulo 2^32 49414
downloaded
Chrome Cache Entry: 126
Web Open Font Format (Version 2), TrueType, length 29752, version 1.0
downloaded
Chrome Cache Entry: 127
gzip compressed data, from Unix, original size modulo 2^32 21462
downloaded
Chrome Cache Entry: 128
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, comment: "CREATOR: gd-jpeg v1.0 (using IJG JPEG v62), quality = 90", baseline, precision 8, 1024x757, components 3
dropped
Chrome Cache Entry: 83
gzip compressed data, from Unix, original size modulo 2^32 18692
downloaded
Chrome Cache Entry: 84
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, baseline, precision 8, 800x600, components 3
dropped
Chrome Cache Entry: 87
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 800x533, components 3
downloaded
Chrome Cache Entry: 88
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 685x392, components 3
dropped
Chrome Cache Entry: 93
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 94
JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 772x591, components 3
downloaded
Chrome Cache Entry: 96
gzip compressed data, from Unix, original size modulo 2^32 110147
downloaded
Chrome Cache Entry: 97
gzip compressed data, from Unix, original size modulo 2^32 42220
downloaded
Chrome Cache Entry: 99
JPEG image data, JFIF standard 1.01, resolution (DPI), density 72x72, segment length 16, progressive, precision 8, 1200x674, components 3
downloaded
There are 27 hidden files, click here to show them.

URLs

Name
IP
Malicious
http://drnavingupta.com
http://drnavingupta.com/wp-content/plugins/wp-plugin-hostgator/vendor/newfold-labs/wp-module-patterns/assets/build/utilities.js?ver=0.1.8
192.185.52.89
http://drnavingupta.com/wp-content/themes/iconic-one/style.css?ver=2.4
192.185.52.89
http://drnavingupta.com/wp-content/themes/iconic-one/js/selectnav.js?ver=1.0
192.185.52.89
http://drnavingupta.com/wp-content/plugins/wp-plugin-hostgator/vendor/newfold-labs/wp-module-patterns/assets/build/utilities.css?ver=0.1.8
192.185.52.89
http://drnavingupta.com/wp-content/themes/iconic-one/img/linkedin.png
192.185.52.89
http://drnavingupta.com/wp-content/uploads/2020/01/phaco-training3.jpg
192.185.52.89
http://drnavingupta.com/wp-includes/css/dist/block-library/style.min.css?ver=6.4.3
192.185.52.89
http://drnavingupta.com/wp-content/uploads/2017/05/cropped-Hematology-Doctors-in-Dubai-32x32.jpg
192.185.52.89
http://drnavingupta.com/wp-content/themes/iconic-one/img/facebook.png
192.185.52.89
http://drnavingupta.com/wp-content/themes/iconic-one/img/instagram.png
192.185.52.89
http://drnavingupta.com/wp-content/uploads/2017/05/Hematology-Doctors-in-Dubai-1.jpg
192.185.52.89
http://drnavingupta.com/wp-content/themes/iconic-one/custom.css?ver=6.4.3
192.185.52.89
http://drnavingupta.com/wp-content/uploads/2020/01/phaco-training2-1-1536x672.jpg
192.185.52.89
http://drnavingupta.com/
http://drnavingupta.com/wp-includes/js/wp-emoji-release.min.js?ver=6.4.3
192.185.52.89
There are 5 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
drnavingupta.com
192.185.52.89
www.google.com
142.251.16.106
web.archive.org
207.241.237.3

IPs

IP
Domain
Country
Malicious
1.1.1.1
unknown
Australia
239.255.255.250
unknown
Reserved
142.251.16.100
unknown
United States
172.253.63.95
unknown
United States
207.241.237.3
web.archive.org
United States
192.168.2.16
unknown
unknown
172.253.63.94
unknown
United States
192.185.52.89
drnavingupta.com
United States
172.253.62.84
unknown
United States
142.251.16.113
unknown
United States
142.251.163.94
unknown
United States
142.251.16.106
www.google.com
United States
There are 2 hidden IPs, click here to show them.