IOC Report
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit?usp=drive_web

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:43:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:43:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Wed Oct 4 12:54:07 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:43:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:43:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Apr 16 12:43:18 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 113
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 114
Web Open Font Format (Version 2), TrueType, length 58012, version 1.0
downloaded
Chrome Cache Entry: 115
Web Open Font Format (Version 2), TrueType, length 129672, version 1.0
downloaded
Chrome Cache Entry: 116
Web Open Font Format (Version 2), TrueType, length 31456, version 1.0
downloaded
Chrome Cache Entry: 117
Web Open Font Format (Version 2), TrueType, length 72784, version 1.0
downloaded
Chrome Cache Entry: 118
Web Open Font Format (Version 2), TrueType, length 42132, version 1.0
downloaded
Chrome Cache Entry: 119
PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 120
Web Open Font Format (Version 2), TrueType, length 64068, version 1.0
downloaded
Chrome Cache Entry: 121
Web Open Font Format (Version 2), TrueType, length 45536, version 1.0
downloaded
Chrome Cache Entry: 122
Web Open Font Format (Version 2), TrueType, length 39708, version 1.0
downloaded
Chrome Cache Entry: 123
GIF image data, version 89a, 48 x 48
downloaded
Chrome Cache Entry: 124
Web Open Font Format (Version 2), TrueType, length 58892, version 1.0
downloaded
Chrome Cache Entry: 125
ASCII text
downloaded
Chrome Cache Entry: 126
Web Open Font Format (Version 2), TrueType, length 37488, version 1.0
downloaded
Chrome Cache Entry: 127
Web Open Font Format (Version 2), TrueType, length 64164, version 1.0
downloaded
Chrome Cache Entry: 128
Web Open Font Format (Version 2), TrueType, length 44316, version 1.0
downloaded
Chrome Cache Entry: 129
ASCII text, with very long lines (2124)
downloaded
Chrome Cache Entry: 130
ASCII text, with very long lines (2054)
downloaded
Chrome Cache Entry: 131
GIF image data, version 89a, 48 x 48
dropped
Chrome Cache Entry: 132
Web Open Font Format (Version 2), TrueType, length 60648, version 1.0
downloaded
Chrome Cache Entry: 133
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 134
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 135
Web Open Font Format (Version 2), TrueType, length 36840, version 1.0
downloaded
Chrome Cache Entry: 136
Web Open Font Format (Version 2), TrueType, length 41676, version 1.0
downloaded
Chrome Cache Entry: 137
ASCII text, with very long lines (538)
downloaded
Chrome Cache Entry: 138
Web Open Font Format (Version 2), TrueType, length 65812, version 1.0
downloaded
Chrome Cache Entry: 139
Web Open Font Format (Version 2), TrueType, length 40412, version 1.0
downloaded
Chrome Cache Entry: 140
Web Open Font Format (Version 2), TrueType, length 50476, version 1.0
downloaded
Chrome Cache Entry: 141
PNG image data, 21 x 21, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 142
Web Open Font Format (Version 2), TrueType, length 41284, version 1.0
downloaded
Chrome Cache Entry: 143
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 144
Web Open Font Format (Version 2), TrueType, length 25980, version 1.0
downloaded
Chrome Cache Entry: 145
ASCII text, with very long lines (779)
downloaded
Chrome Cache Entry: 146
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 147
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 148
Web Open Font Format (Version 2), TrueType, length 143084, version 1.0
downloaded
Chrome Cache Entry: 149
Web Open Font Format (Version 2), TrueType, length 46840, version 1.0
downloaded
Chrome Cache Entry: 150
PNG image data, 413 x 122, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 151
PNG image data, 239 x 211, 8-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 152
Web Open Font Format (Version 2), TrueType, length 55204, version 1.0
downloaded
Chrome Cache Entry: 153
Web Open Font Format (Version 2), TrueType, length 50664, version 1.0
downloaded
Chrome Cache Entry: 154
Web Open Font Format (Version 2), TrueType, length 39516, version 1.0
downloaded
Chrome Cache Entry: 155
Web Open Font Format (Version 2), TrueType, length 26936, version 1.0
downloaded
Chrome Cache Entry: 156
PNG image data, 129 x 129, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 157
Web Open Font Format (Version 2), TrueType, length 40184, version 1.0
downloaded
Chrome Cache Entry: 158
Web Open Font Format (Version 2), TrueType, length 57612, version 1.0
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (2114)
downloaded
Chrome Cache Entry: 160
Web Open Font Format (Version 2), TrueType, length 32644, version 1.0
downloaded
Chrome Cache Entry: 161
PNG image data, 129 x 129, 4-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 162
Web Open Font Format (Version 2), TrueType, length 58200, version 1.0
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (2249)
downloaded
Chrome Cache Entry: 164
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 165
Web Open Font Format (Version 2), TrueType, length 41288, version 1.0
downloaded
Chrome Cache Entry: 166
PNG image data, 21 x 21, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 167
ASCII text, with very long lines (1293)
downloaded
Chrome Cache Entry: 168
Web Open Font Format (Version 2), TrueType, length 99952, version 1.0
downloaded
Chrome Cache Entry: 169
PNG image data, 413 x 122, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 170
Web Open Font Format (Version 2), TrueType, length 50264, version 1.0
downloaded
Chrome Cache Entry: 171
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 172
ASCII text
downloaded
Chrome Cache Entry: 173
Web Open Font Format (Version 2), TrueType, length 64656, version 1.0
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (3383)
downloaded
Chrome Cache Entry: 175
PNG image data, 150 x 54, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 176
Web Open Font Format (Version 2), TrueType, length 41584, version 1.0
downloaded
Chrome Cache Entry: 177
Web Open Font Format (Version 2), TrueType, length 41220, version 1.0
downloaded
Chrome Cache Entry: 178
Web Open Font Format (Version 2), TrueType, length 100756, version 1.0
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (1562)
downloaded
Chrome Cache Entry: 180
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 181
Web Open Font Format (Version 2), TrueType, length 54324, version 1.0
downloaded
Chrome Cache Entry: 182
Web Open Font Format (Version 2), TrueType, length 84892, version 1.0
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 184
Web Open Font Format (Version 2), TrueType, length 126552, version 1.0
downloaded
Chrome Cache Entry: 185
PNG image data, 129 x 129, 4-bit colormap, non-interlaced
dropped
Chrome Cache Entry: 186
HTML document, ASCII text, with very long lines (540)
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (736)
downloaded
Chrome Cache Entry: 188
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 189
Web Open Font Format (Version 2), TrueType, length 37800, version 1.0
downloaded
Chrome Cache Entry: 190
ASCII text, with very long lines (785)
downloaded
Chrome Cache Entry: 191
Web Open Font Format (Version 2), TrueType, length 116720, version 1.0
downloaded
Chrome Cache Entry: 192
ASCII text, with very long lines (864)
downloaded
Chrome Cache Entry: 193
PNG image data, 239 x 211, 8-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 194
Web Open Font Format (Version 2), TrueType, length 57236, version 1.0
downloaded
Chrome Cache Entry: 195
Web Open Font Format (Version 2), TrueType, length 54776, version 1.0
downloaded
Chrome Cache Entry: 196
Web Open Font Format (Version 2), TrueType, length 37632, version 1.0
downloaded
Chrome Cache Entry: 197
Web Open Font Format (Version 2), TrueType, length 43772, version 1.0
downloaded
Chrome Cache Entry: 198
HTML document, Unicode text, UTF-8 text, with very long lines (1136)
dropped
Chrome Cache Entry: 199
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (2124)
downloaded
Chrome Cache Entry: 201
PNG image data, 129 x 129, 4-bit colormap, non-interlaced
downloaded
Chrome Cache Entry: 202
Web Open Font Format (Version 2), TrueType, length 15344, version 1.0
downloaded
Chrome Cache Entry: 203
Web Open Font Format (Version 2), TrueType, length 47364, version 1.0
downloaded
Chrome Cache Entry: 204
Web Open Font Format (Version 2), TrueType, length 72264, version 1.0
downloaded
Chrome Cache Entry: 205
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 206
Web Open Font Format (Version 2), TrueType, length 64888, version 1.0
downloaded
Chrome Cache Entry: 207
Web Open Font Format (Version 2), TrueType, length 50340, version 1.0
downloaded
Chrome Cache Entry: 208
MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
dropped
Chrome Cache Entry: 209
Web Open Font Format (Version 2), TrueType, length 105776, version 1.0
downloaded
Chrome Cache Entry: 210
Web Open Font Format (Version 2), TrueType, length 42296, version 1.0
downloaded
Chrome Cache Entry: 211
Web Open Font Format (Version 2), TrueType, length 44980, version 1.0
downloaded
There are 96 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2332 --field-trial-handle=2204,i,12912129332964351736,4633805721641026136,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit?usp=drive_web"

URLs

Name
IP
Malicious
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit?usp=drive_web
https://signaler-staging.sandbox.google.com
unknown
https://support.google.com/docs/answer/
unknown
https://feedback.googleusercontent.com/resources/annotator.css
unknown
https://apis.google.com/js/client.js
unknown
https://support.google.com
unknown
http://localhost.proxy.googlers.com/inapp/
unknown
https://stagingqual-feedback-pa-googleapis.sandbox.google.com
unknown
https://docs.google.com/static/drawings/client/css/3249440579-editor_css_ltr.css
74.125.136.101
https://support.google.com/a/?p=disable_docs#topic=4388346
unknown
https://docs.google.com/static/drawings/client/js/1986118873-editor_core.js
74.125.136.101
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/bind?id=1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE&sid=1b295fff611fbd35&includes_info_params=1&usp=drive_web&cros_files=false&VER=8&lsq=-1&u=ANONYMOUS_14143950788561711331&flr=0&gsi&ssfi=2&smv=9&smb=%5B9%2C%20%5D&cimpl=0&RID=66433&CVER=1&zx=7cd8g6j83z1k&t=1
74.125.136.101
https://policies.google.com/terms?hl=en-US
unknown
about:blank
https://support.google.com/docs/answer/7505592
unknown
https://workspace.google.com/upgrade/plus/welcome?eci=upsell
unknown
https://www.google.com/recaptcha/api.js?trustedtypes=true&render=
unknown
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit?usp=drive_web
https://support.mozilla.org/en-US/kb/disable-or-remove-add-ons
unknown
https://support.google.com/drive/?hl=en
unknown
https://contacts.google.com/contact/
unknown
https://pay.google.com/gp/v/widget/save
unknown
https://docs.google.com/static/drawings/client/js/379622454-editor_peoplehovercard.js
74.125.136.101
https://drive-thirdparty.googleusercontent.com/
unknown
https://content-googleapis-test.sandbox.google.com
unknown
https://www.google.com/shopping/customerreviews/optin?usegapi=1
unknown
https://asx-frontend-autopush.corp.google.co.uk/tools/feedback/
unknown
https://support.google.com/docs?p=add_encryption
unknown
https://workspace.google.com/upgrade/standard/welcome
unknown
https://hangouts.google.com/hangouts/_/
unknown
https://policies.google.com/terms?hl=en
unknown
https://www.google.com/tools/feedback
unknown
https://sandbox.google.com/inapp/%
unknown
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.dCBC8e6ENbg.O/m=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo8oB7UmguRctpg6togRivSNxNKjzQ/cb=gapi.loaded_0
142.250.105.113
https://support.google.com/docs?p=duet-help-me-visualize
unknown
https://apis.google.com/js/api.js
142.250.105.113
https://docs.google.com/picker
unknown
https://support.google.com/chrome/answer/187443
unknown
https://www.google.com/tools/feedback/
unknown
https://www.youtube.com/subscribe_embed?usegapi=1
unknown
https://contacts.google.com/_/scs/social-static/_/js/k=boq.SocialPeopleHovercardUi.en_US.Mj6jj1hrTuE.es5.O/ck=boq.SocialPeopleHovercardUi.3op5Ju_H1XA.L.B1.O/am=gImuAQ/d=1/exm=_b,_tp/excm=_b,_tp,hovercardwidget/ed=1/wt=2/ujg=1/rs=AGLTcCO8nnHC7efsXrx3vINF5CWJEqmf4Q/ee=EVNhjf:pw70Gc;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:SdcwHb;Me32dd:MEeYgc;NPKaK:SdcwHb;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SNUn3:ZwDk9d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:QIhFr;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:s39S4;oGtAuc:sOXFj;pXdRYb:MdUzUe;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;wR5FRb:O1Gjze;xqZiqf:wmnU7d;yxTchf:KUM7Z;zxnPse:GkRiKb/m=ws9Tlc,n73qwf,GkRiKb,e5qFLc,IZT63,UUJqVe,O1Gjze,byfTOb,lsjVmc,xUdipf,OTA3Ae,COQbmf,fKUV3e,aurFic,U0aPgd,ZwDk9d,V3dDOb,WO9ee,mI3LFb,Xg7Hl,O6y8ed,PrPYRd,MpJwZc,LEikZe,NwH0H,OmgaI,lazG7b,XVMNvd,L1AAkb,KUM7Z,Mlhmy,s39S4,lwddkf,gychg,w9hDv,EEDORb,RMhBfe,SdcwHb,aW3pY,pw70Gc,EFQ78c,Ulmmrd,ZfAoz,mdR7q,wmnU7d,xQtZb,JNoxi,kWgXee,MI6k7c,kjKdXe,BVgquf,QIhFr,ovKuLd,hKSk3e,yDVVkb,hc6Ubd,SpsfSb,KG2eXe,Z5uLle,MdUzUe,VwDzFe,zbML3c,A7fCU,zr1jrb,Uas9Hd,pjICDe
74.125.136.113
https://feedback2-test.corp.google.com/tools/feedback/%
unknown
https://punctual-dev.corp.google.com
unknown
http://support.google.com/docs?p=labs-privacy
unknown
https://support.google.com/docs?p=labs-privacy
unknown
https://plus.google.com
unknown
https://asx-frontend-autopush.corp.google.de/tools/feedback/
unknown
https://asx-frontend-autopush.corp.google.com/inapp/
unknown
https://feedback.googleusercontent.com/resources/render_frame2.html
unknown
https://sandbox.google.com/tools/feedback/%
unknown
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit
https://content-googleapis-staging.sandbox.google.com
unknown
https://docs.google.com/drivesharing/clientmodel?id=1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE&foreignService=drawings&authuser=0&origin=https%3A%2F%2Fdocs.google.com
74.125.136.101
https://play.google.com/work/embedded/search?usegapi=1&usegapi=1
unknown
https://policies.google.com/privacy
unknown
https://lh7-us.googleusercontent.com/drawings/AFUiIQ86c1TNhN5KbqdPGiyzBJbJ6YJATiEsN6F-tUwfal51OxqWPVtlstnBwDC4hwWdV0kWuhQQ7lLHzdRNxJ-57TwVocKxxnYfkUkVeBpJYpv4uVaC_Vw_G0qk6nX_YR0cGsf_KMXlctTZm4_ahi5-9Kd7k9A-xlEm7TMFCSgaP-A
142.250.9.132
https://support.google.com/docs?p=help-me-visualize
unknown
https://support.google.com/drive/?p=drive_only
unknown
https://policies.google.com/privacy?hl=en-US
unknown
https://calendar.google.com/event
unknown
https://lh7-us.googleusercontent.com/drawings/AFUiIQ_yjj2aiK5c2Tsupjf_3Hc2ZnwdYR5ZW5h5b-Hq_FvXl5D_JLiXnxulhcPvkMFi9ggu7q6BtsTybBoo_46lLZEtpf-yfFuOlvY9fP2o_TgKyJ_AX8QeUWDeDhm9SUsD_t74y47eTWTvnuD_ssyS0DDynOx_FVP1WMAIPsAY
142.250.9.132
https://support.google.com/docs/answer/13447609
unknown
https://support.google.com/drive?p=comment_troubleshoot
unknown
https://support.google.com/drive/answer/37603
unknown
https://calendar.google.com/calendar/embed
unknown
https://play.google.com
unknown
https://contacts.google.com/_/scs/social-static/_/js/k=boq.SocialPeopleHovercardUi.en_US.Mj6jj1hrTuE.es5.O/ck=boq.SocialPeopleHovercardUi.3op5Ju_H1XA.L.B1.O/am=gImuAQ/d=1/exm=A7fCU,BVgquf,COQbmf,EEDORb,EFQ78c,GkRiKb,IZT63,JNoxi,KG2eXe,KUM7Z,L1AAkb,LEikZe,MI6k7c,MdUzUe,Mlhmy,MpJwZc,NwH0H,O1Gjze,O6y8ed,OTA3Ae,OmgaI,PrPYRd,QIhFr,RMhBfe,SdcwHb,SpsfSb,U0aPgd,UUJqVe,Uas9Hd,Ulmmrd,V3dDOb,VwDzFe,WO9ee,XVMNvd,Xg7Hl,Z5uLle,ZfAoz,ZwDk9d,_b,_tp,aW3pY,aurFic,bm51tf,byfTOb,e5qFLc,fKUV3e,gychg,hKSk3e,hc6Ubd,kWgXee,kjKdXe,lazG7b,lsjVmc,lwddkf,mI3LFb,mdR7q,n73qwf,ovKuLd,pjICDe,pw70Gc,s39S4,w9hDv,wmnU7d,ws9Tlc,xQtZb,xUdipf,yDVVkb,zbML3c,zr1jrb/excm=_b,_tp,hovercardwidget/ed=1/wt=2/ujg=1/rs=AGLTcCO8nnHC7efsXrx3vINF5CWJEqmf4Q/ee=EVNhjf:pw70Gc;EmZ2Bf:zr1jrb;Erl4fe:FloWmf;JsbNhc:Xd8iUd;LBgRLc:SdcwHb;Me32dd:MEeYgc;NPKaK:SdcwHb;NSEoX:lazG7b;Oj465e:KG2eXe;Pjplud:EEDORb;QGR0gd:Mlhmy;SNUn3:ZwDk9d;a56pNe:JEfCwb;cEt90b:ws9Tlc;dIoSBb:SpsfSb;eBAeSb:zbML3c;iFQyKf:QIhFr;io8t5d:yDVVkb;kMFpHd:OTA3Ae;nAFL3:s39S4;oGtAuc:sOXFj;pXdRYb:MdUzUe;qddgKe:xQtZb;sP4Vbe:VwDzFe;uY49fb:COQbmf;ul9GGd:VDovNc;wR5FRb:O1Gjze;xqZiqf:wmnU7d;yxTchf:KUM7Z;zxnPse:GkRiKb/m=Wt6vjf,hhhU8,FCpbqb,WhJNk
74.125.136.113
https://www.google.com/log?format=json&hasfast=true
unknown
https://signaler-pa.youtube.com
unknown
https://support.google.com/inapp/%
unknown
http://support.google.com/drive/?hl=en&p=anonymous_users
unknown
https://support.google.com/docs?p=gemini-help-me-visualize
unknown
https://www.google.com/shopping/customerreviews/badge?usegapi=1
unknown
https://workspace.google.com/upgrade/standard/welcome?eci=upsell
unknown
https://support.google.com/docs/?p=
unknown
https://drive.google.com/savetodrivebutton?usegapi=1
unknown
https://support.google.com/docs/answer/190843
unknown
https://lh3.googleusercontent.com/a/default-user
unknown
https://support.google.com/inapp/
unknown
https://asx-frontend-autopush.corp.google.co.uk/inapp/
unknown
https://one.google.com/plans
unknown
https://inputtools.google.com
unknown
https://apis.google.com
unknown
https://contacts.google.com
unknown
https://asx-frontend-autopush.corp.youtube.com/tools/feedback/
unknown
https://domains.google.com/suggest/flow
unknown
https://apis.google.com/_/scs/abc-static/_/js/k=gapi.gapi.en.dCBC8e6ENbg.O/m=card/exm=gapi_iframes,googleapis_client/rt=j/sv=1/d=1/ed=1/am=AAAC/rs=AHpOoo8oB7UmguRctpg6togRivSNxNKjzQ/cb=gapi.loaded_1
142.250.105.113
https://apps-drive-picker-dev.corp.google.com/picker/minpick/main
unknown
https://support.google.com/docs?p=slides-image-background-removal
unknown
https://feedback2-test.corp.google.com/inapp/%
unknown
https://signaler-pa.clients6.google.com
unknown
https://contacts.google.com/widget/companion?edit=true&contactId=
unknown
https://chrome.google.com/webstore/detail/
unknown
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/test?id=1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE&sid=1b295fff611fbd35&includes_info_params=1&usp=drive_web&cros_files=false&VER=8&lsq=-1&u=ANONYMOUS_14143950788561711331&flr=0&gsi&ssfi=0&smv=9&smb=%5B9%2C%20%5D&cimpl=0&MODE=init&zx=auoqwbi465r0&t=1
74.125.136.101
https://feedback2-test.corp.googleusercontent.com/inapp/%
unknown
https://calendar.google.com/calendar/r?eid=
unknown
https://www.google.cn/tools/feedback/
unknown
http://www.bohemiancoding.com/sketch/ns
unknown
https://play.google.com/log?format=json&hasfast=true&authuser=0
142.250.9.102
https://asx-frontend-autopush.corp.google.de/inapp/
unknown
https://uberproxy-pen-redirect.corp.google.com/uberproxy/pen?url=
unknown
There are 90 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
docs.google.com
74.125.136.101
play.google.com
142.250.9.102
plus.l.google.com
142.250.105.113
browserchannel-sites.l.google.com
64.233.176.189
www.google.com
64.233.185.147
googlehosted.l.googleusercontent.com
142.250.9.132
fp2e7a.wpc.phicdn.net
192.229.211.108
contacts.google.com
unknown
apis.google.com
unknown
lh7-us.googleusercontent.com
unknown
0.docs.google.com
unknown
There are 1 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.105.113
plus.l.google.com
United States
192.168.2.4
unknown
unknown
192.168.2.5
unknown
unknown
74.125.136.101
docs.google.com
United States
74.125.138.132
unknown
United States
142.250.9.132
googlehosted.l.googleusercontent.com
United States
74.125.138.99
unknown
United States
74.125.138.102
unknown
United States
172.253.124.139
unknown
United States
239.255.255.250
unknown
Reserved
64.233.176.189
browserchannel-sites.l.google.com
United States
142.250.9.102
play.google.com
United States
74.125.136.113
unknown
United States
74.125.138.101
unknown
United States
64.233.185.147
www.google.com
United States
142.251.15.138
unknown
United States
There are 6 hidden IPs, click here to show them.

DOM / HTML

URL
Malicious
about:blank
about:blank
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit
https://docs.google.com/drawings/d/1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE/edit?usp=drive_web
https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fdocs.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE%26foreignService%3Ddrawings%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdocs.google.com&followup=https%3A%2F%2Fdocs.google.com%2Fdrivesharing%2Fclientmodel%3Fid%3D1QGabMMfvpW-_XDDZi_686sw-7S89-HoKwOnS6UukgfE%26foreignService%3Ddrawings%26authuser%3D0%26origin%3Dhttps%3A%2F%2Fdocs.google.com&ifkv=ARZ0qKKJuhY8HzREbxk0Ne9UgbM_KSZ6CVOsmAUdxp-G4y4k5NO0VBrCnNUP4230C60PGk2SroxN5A&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-317854723%3A1713275006299108&theme=mn&ddm=0
https://contacts.google.com/widget/hovercard/v/2?origin=https%3A%2F%2Fdocs.google.com&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.gapi.en.dCBC8e6ENbg.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo8oB7UmguRctpg6togRivSNxNKjzQ%2Fm%3D__features__#id=__HC_94253229&_gfid=__HC_94253229&parent=https%3A%2F%2Fdocs.google.com&pfname=&rpctoken=90446534
https://contacts.google.com/widget/hovercard/v/2?origin=https%3A%2F%2Fdocs.google.com&usegapi=1&jsh=m%3B%2F_%2Fscs%2Fabc-static%2F_%2Fjs%2Fk%3Dgapi.gapi.en.dCBC8e6ENbg.O%2Fam%3DAAAC%2Fd%3D1%2Frs%3DAHpOoo8oB7UmguRctpg6togRivSNxNKjzQ%2Fm%3D__features__#id=__HC_94253229&_gfid=__HC_94253229&parent=https%3A%2F%2Fdocs.google.com&pfname=&rpctoken=90446534