IOC Report
https://tracker.club-os.com/campaign/click?msgId=f8ea317d963149a518aa35e03e5541f797badf3c&target=splendidanimations.com%2F%40%2FC2educate/aEFQv26188aEFQv26188aEFQv/anVsaWUubG9uZ2lub0BjMmVkdWNhdGUuY29t

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 12:44:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 12:44:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 12:44:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 12:44:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 18 12:44:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped

URLs

Name
IP
Malicious
https://tracker.club-os.com/campaign/click?msgId=f8ea317d963149a518aa35e03e5541f797badf3c&target=splendidanimations.com%2F%40%2FC2educate/aEFQv26188aEFQv26188aEFQv/anVsaWUubG9uZ2lub0BjMmVkdWNhdGUuY29t
malicious
https://faccln.com/d740c10c7b9cf800d441f265844201e1662123da3e85cPASd740c10c7b9cf800d441f265844201e1662123da3e85f
malicious
https://challenges.cloudflare.com/cdn-cgi/challenge-platform/h/g/turnstile/if/ov2/av0/rcv0/0/wdh5o/0x4AAAAAAADnPIDROrmt1Wwj/light/normal
https://faccln.com/Tjulie.longino@c2educate.com
https://splendidanimations.com/@/C2educate/aEFQv26188aEFQv26188aEFQv/anVsaWUubG9uZ2lub0BjMmVkdWNhdGUuY29t

Domains

Name
IP
Malicious
splendidanimations.com
192.185.104.70
a.nel.cloudflare.com
35.190.80.1
sni1gl.wpc.upsiloncdn.net
152.195.19.97
tracker.club-os.com
54.166.130.75
challenges.cloudflare.com
104.17.2.184
www.google.com
142.250.105.105
unpkg.com
104.17.247.203
faccln.com
104.21.80.170
aadcdn.msauthimages.net
unknown

IPs

IP
Domain
Country
Malicious
1.1.1.1
unknown
Australia
104.21.80.170
faccln.com
United States
172.217.215.101
unknown
United States
64.233.176.95
unknown
United States
54.166.130.75
tracker.club-os.com
United States
192.168.2.17
unknown
unknown
152.195.19.97
sni1gl.wpc.upsiloncdn.net
United States
172.67.152.51
unknown
United States
142.250.105.105
www.google.com
United States
172.253.124.94
unknown
United States
104.17.3.184
unknown
United States
239.255.255.250
unknown
Reserved
64.233.177.113
unknown
United States
104.17.247.203
unpkg.com
United States
64.233.185.94
unknown
United States
64.233.185.84
unknown
United States
35.190.80.1
a.nel.cloudflare.com
United States
104.17.2.184
challenges.cloudflare.com
United States
192.185.104.70
splendidanimations.com
United States
There are 9 hidden IPs, click here to show them.