IOC Report
http://google-bard-ai.com

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 11:23:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 11:23:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 11:23:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 11:23:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Mar 29 11:23:36 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 121
Web Open Font Format (Version 2), TrueType, length 15552, version 1.0
downloaded
Chrome Cache Entry: 122
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 123
ASCII text, with very long lines (7329), with no line terminators
downloaded
Chrome Cache Entry: 124
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 125
ASCII text, with very long lines (15718)
downloaded
Chrome Cache Entry: 126
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 127
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 128
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 129
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=4, height=234, orientation=upper-left, width=930], baseline, precision 8, 930x234, components 3
dropped
Chrome Cache Entry: 130
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 131
ASCII text
downloaded
Chrome Cache Entry: 132
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 133
ASCII text, with very long lines (50719)
downloaded
Chrome Cache Entry: 134
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 68x68, components 3
dropped
Chrome Cache Entry: 135
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 136
PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 137
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 138
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 139
ASCII text, with very long lines (23196)
downloaded
Chrome Cache Entry: 140
GIF image data, version 89a, 6 x 5
dropped
Chrome Cache Entry: 141
Web Open Font Format (Version 2), TrueType, length 52280, version 1.0
downloaded
Chrome Cache Entry: 142
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 143
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (538)
downloaded
Chrome Cache Entry: 145
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 146
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1536x1536, components 3
downloaded
Chrome Cache Entry: 147
GIF image data, version 89a, 6 x 5
downloaded
Chrome Cache Entry: 148
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 149
ASCII text, with very long lines (57196)
downloaded
Chrome Cache Entry: 150
ASCII text
downloaded
Chrome Cache Entry: 151
ASCII text
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (2122)
downloaded
Chrome Cache Entry: 153
ASCII text, with very long lines (12366), with no line terminators
downloaded
Chrome Cache Entry: 154
HTML document, Unicode text, UTF-8 text, with very long lines (51485), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (11256), with no line terminators
downloaded
Chrome Cache Entry: 156
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=4, height=345, orientation=upper-left, width=1002], baseline, precision 8, 1002x345, components 3
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (562)
downloaded
Chrome Cache Entry: 158
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=4, height=345, orientation=upper-left, width=1002], baseline, precision 8, 1002x345, components 3
dropped
Chrome Cache Entry: 159
PNG image data, 410 x 1024, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 160
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 161
ASCII text, with very long lines (1981)
downloaded
Chrome Cache Entry: 162
ASCII text
downloaded
Chrome Cache Entry: 163
JSON data
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (6677)
downloaded
Chrome Cache Entry: 165
ASCII text, with very long lines (3383)
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (10149)
downloaded
Chrome Cache Entry: 167
JSON data
dropped
Chrome Cache Entry: 168
ASCII text, with very long lines (4186), with no line terminators
downloaded
Chrome Cache Entry: 169
Unicode text, UTF-8 text, with very long lines (537)
downloaded
Chrome Cache Entry: 170
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 68x68, components 3
downloaded
Chrome Cache Entry: 171
JPEG image data, Exif standard: [TIFF image data, big-endian, direntries=4, height=234, orientation=upper-left, width=930], baseline, precision 8, 930x234, components 3
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (40662)
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (3554)
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (10970)
downloaded
Chrome Cache Entry: 175
PNG image data, 1314 x 1314, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 176
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1280x720, components 3
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (58205), with no line terminators
downloaded
Chrome Cache Entry: 178
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1600x1000, components 3
dropped
Chrome Cache Entry: 179
ASCII text, with very long lines (1143)
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (21646), with no line terminators
downloaded
Chrome Cache Entry: 181
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 182
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1600x1000, components 3
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (5955)
downloaded
Chrome Cache Entry: 184
PNG image data, 1314 x 1314, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 185
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 186
ASCII text, with very long lines (51673)
downloaded
Chrome Cache Entry: 187
PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 188
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 189
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1280x720, components 3
dropped
Chrome Cache Entry: 190
ASCII text, with very long lines (3391)
downloaded
Chrome Cache Entry: 191
ASCII text, with very long lines (682)
downloaded
Chrome Cache Entry: 192
PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 193
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 1536x1536, components 3
dropped
Chrome Cache Entry: 194
ASCII text, with very long lines (2121)
downloaded
Chrome Cache Entry: 195
ASCII text, with very long lines (555)
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (3537)
downloaded
There are 73 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2108 --field-trial-handle=2012,i,6306501201398663448,17464830673683512825,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://google-bard-ai.com"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --mojo-platform-channel-handle=6012 --field-trial-handle=2012,i,6306501201398663448,17464830673683512825,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=5916 --field-trial-handle=2012,i,6306501201398663448,17464830673683512825,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8

URLs

Name
IP
Malicious
http://google-bard-ai.com
https://drive-thirdparty.googleusercontent.com/64/type/application/vnd.google-apps.document
unknown
https://signaler-staging.sandbox.google.com
unknown
https://stats.g.doubleclick.net/g/collect
unknown
https://feedback.googleusercontent.com/resources/annotator.css
unknown
https://ogp.me/ns#
unknown
https://redux.js.org/tutorials/fundamentals/part-4-store#creating-a-store-with-enhancers
unknown
https://apis.google.com/js/client.js
unknown
https://support.google.com/accounts/answer/3118687
unknown
https://support.google.com
unknown
https://www.youtube.com/embed/
unknown
http://g.co/dev/maps-no-account
unknown
http://localhost.proxy.googlers.com/inapp/
unknown
https://gemini.google.com
unknown
https://myactivity.google.com/product/gemini
unknown
https://stagingqual-feedback-pa-googleapis.sandbox.google.com
unknown
https://google-bard-ai.com/wp-content/uploads/2023/04/cropped-20230411_145012-192x192.jpg
unknown
https://policies.google.com/terms#toc-withdrawal-form
unknown
https://admin.youtube.com
unknown
https://google-bard-ai.com/wp-content/plugins/ultimate-blocks/dist/blocks.style.build.css?ver=6605cc
unknown
https://www.youtube.com/youtubei/v1/log_event?alt=json&key=AIzaSyAO_FJ2SlqU8Q4STEHLGCilw_Y9_11qcW8
172.253.62.93
https://goo.gle/js-api-loading
unknown
https://support.google.com/gemini
unknown
https://redux.js.org/tutorials/fundamentals/part-4-store#middleware
unknown
https://asx-frontend-autopush.corp.google.co.uk/tools/feedback/
unknown
https://drive-thirdparty.googleusercontent.com/64/type/application/vnd.google-apps.spreadsheet
unknown
https://googleads.g.doubleclick.net/pagead/id?slf_rd=1
142.251.16.157
https://openjsf.org/
unknown
https://developers.google.com/maps/documentation/javascript/styling#cloud_tooling
unknown
https://google-bard-ai.com/wp-content/plugins/ultimate-blocks/src/blocks/content-toggle/front.build.js?ver=3.1.5
82.180.143.126
https://www.youtube.com/channel/UC
unknown
https://google-bard-ai.com/wp-content/uploads/2023/04/cropped-20230411_145012-180x180.jpg
unknown
https://yurt.corp.google.com
unknown
https://support.google.com/fusiontables/answer/9185417).
unknown
https://www.google.com/tools/feedback
unknown
https://www.google.com/maps/companion
unknown
https://yt3.ggpht.com/rhqKhfZPaVKRfPi1UvaoekFcSVkipICyGmshnUT9SYMR2JMI8G40YqtaOqz94Ao5rdu_NE0nAw=s68-c-k-c0x00ffffff-no-rj
172.253.62.132
https://google-bard-ai.com/wp-content/uploads/2023/04/cropped-20230411_145012-300x300.jpg
unknown
https://google-bard-ai.com/wp-content/plugins/stackable-ultimate-gutenberg-blocks/dist/frontend_blocks.css?ver=3.12.13
82.180.143.126
https://www.youtube.com/generate_204?cpn=
unknown
https://google-bard-ai.com/terms-conditions/
unknown
https://sandbox.google.com/inapp/%
unknown
https://pixel.wp.com/g.gif?v=ext&blog=217866744&post=714&tz=5&srv=google-bard-ai.com&j=1%3A13.2.2&host=google-bard-ai.com&ref=&fcp=7316&rand=0.20128415738929117
192.0.76.3
https://apis.google.com/js/api.js
unknown
https://bard.google.com
unknown
https://google-bard-ai.com/author/ak1139378gmail-com/
unknown
https://www.google.com/tools/feedback/
unknown
https://takeout.google.com/
unknown
https://support.google.com/bard
unknown
https://google-bard-ai.com/wp-includes/js/mediaelement/wp-mediaelement.min.css?ver=6.4.3
82.180.143.126
https://schema.org
unknown
https://feedback2-test.corp.google.com/tools/feedback/%
unknown
https://punctual-dev.corp.google.com
unknown
http://mathiasbynens.be/
unknown
https://play.google.com/intl/en_us/badges/static/images/badges/en_badge_web_generic.png
unknown
https://plus.google.com
unknown
https://gemini.google.com/
172.253.115.113
https://policies.google.com/terms/definitions#toc-terms-consumer
unknown
http://underscorejs.org/LICENSE
unknown
https://asx-frontend-autopush.corp.google.de/tools/feedback/
unknown
https://asx-frontend-autopush.corp.google.com/inapp/
unknown
https://schema.org/WPHeader
unknown
https://feedback.googleusercontent.com/resources/render_frame2.html
unknown
https://sandbox.google.com/tools/feedback/%
unknown
https://google-bard-ai.com/#webpage
unknown
http://tools.ietf.org/html/rfc1950
unknown
https://google-bard-ai.com/wp-content/uploads/2023/05/bard-1024x576.jpg
82.180.143.126
https://google-bard-ai.com/privacy-policy/
unknown
https://quilljs.com/
unknown
https://stats.g.doubleclick.net/g/collect?v=2&
unknown
https://policies.google.com/privacy
unknown
https://forms.gle/YJJdSVYpJ9V3Jjng7
unknown
https://www.youtube.com/s/player/3b96d06c/player_ias.vflset/en_US/base.js
172.253.62.93
https://google-bard-ai.com/wp-content/themes/astra/assets/js/minified/flexibility.min.js?ver=4.6.9
unknown
https://bard.google.com/
142.251.163.138
https://npms.io/search?q=ponyfill.
unknown
https://google-bard-ai.com/?s=
unknown
https://g.co/gemini/share
unknown
https://support.google.com/websearch/answer/179386?p=device_location&rd=1#device_location&zippy=%2Cy
unknown
https://www.youtube.com/s/player/3b96d06c/player_ias.vflset/en_US/embed.js
172.253.62.93
https://g.co/gemini/sparkle
unknown
https://play.google.com
unknown
https://google-bard-ai.com/wp-content/plugins/stackable-ultimate-gutenberg-blocks/dist/frontend_bloc
unknown
https://signaler-pa.youtube.com
unknown
https://support.google.com/inapp/%
unknown
https://support.google.com/youtube/?p=report_playback
unknown
https://gemini.google.com/_/BardChatUi/data/batchexecute?rpcids=K4WWud&source-path=%2F&bl=boq_assistant-bard-web-server_20240327.10_p2&f.sid=-3706632272670216316&hl=en&_reqid=48264&rt=c
172.253.115.113
https://developers.google.com/maps/documentation/javascript/error-messages#unsupported-browsers
unknown
https://www.youtube.com/static?template=terms
unknown
http://youtube.com/streaming/metadata/segment/102015
unknown
https://developers.google.com/maps/documentation/javascript/libraries
unknown
https://youtu.be/
unknown
http://schema.org
unknown
https://g.co/ng/security#xss)
unknown
https://www.youtube.com/embed/63NfEkYCLz0?feature=oembed
http://google-bard-ai.com
unknown
http://mths.be/fromcodepoint
unknown
https://github.com/
unknown
https://google-bard-ai.com/wp-content/uploads/2023/04/cropped-20230411_145012-32x32.jpg
unknown
https://rankmath.com/
unknown
https://workspace.google.com/solutions/ai/?utm_source=geminiforbusiness&utm_medium=et&utm_campaign=G
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
stats.wp.com
192.0.76.3
bard.google.com
142.251.163.138
plus.l.google.com
172.253.115.101
i.ytimg.com
172.253.63.119
google-bard-ai.com
82.180.143.126
static.doubleclick.net
172.253.115.148
fp2e7a.wpc.phicdn.net
192.229.211.108
bg.microsoft.map.fastly.net
199.232.210.172
youtube-ui.l.google.com
172.253.62.93
ogads-pa.clients6.google.com
172.253.122.95
waa-pa.clients6.google.com
172.253.62.95
googleads.g.doubleclick.net
142.251.16.157
play.google.com
172.253.122.138
pixel.wp.com
192.0.76.3
photos-ugc.l.googleusercontent.com
172.253.62.132
www.google.com
142.251.163.99
gemini.google.com
172.253.115.113
googlehosted.l.googleusercontent.com
142.251.16.132
yt3.ggpht.com
unknown
lh3.googleusercontent.com
unknown
www.youtube.com
unknown
apis.google.com
unknown
There are 12 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
172.253.62.132
photos-ugc.l.googleusercontent.com
United States
172.253.63.119
i.ytimg.com
United States
142.251.16.132
googlehosted.l.googleusercontent.com
United States
172.253.62.93
youtube-ui.l.google.com
United States
142.251.163.101
unknown
United States
142.251.16.157
googleads.g.doubleclick.net
United States
192.168.2.5
unknown
unknown
172.253.115.148
static.doubleclick.net
United States
172.253.115.101
plus.l.google.com
United States
142.251.163.99
www.google.com
United States
172.253.122.93
unknown
United States
172.253.62.100
unknown
United States
82.180.143.126
google-bard-ai.com
Denmark
142.251.16.103
unknown
United States
192.0.76.3
stats.wp.com
United States
142.250.31.119
unknown
United States
142.251.163.138
bard.google.com
United States
239.255.255.250
unknown
Reserved
172.253.115.113
gemini.google.com
United States
172.253.115.132
unknown
United States
There are 10 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
https://google-bard-ai.com/
https://www.youtube.com/embed/63NfEkYCLz0?feature=oembed
https://gemini.google.com/?hl=en
https://gemini.google.com/?hl=en
https://gemini.google.com/?hl=en
https://gemini.google.com/?hl=en
https://gemini.google.com/?hl=en
https://gemini.google.com/_/bscframe