Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 14:40:32 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 14:40:32 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 14:40:32 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 14:40:32 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command
line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 14:40:32 2024, atime=Wed Sep 27 04:28:28
2023, length=1210144, window=hide
|
dropped
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://email.wantyourfeedback.com/ls/click?upn=u001.PD4nPnyJUo8oiEzSkSGLgaBNAMtLp9U5nstWElDmnpXtySPOXSs4GxXhEZNYegDWlOpy_1gt1aDjd5mPVItYgazWgABkVm-2FZUH6kt1lIvkdtkRWsfoyQV18ixDvOX-2B0tU4ZH6SMN7PC0YJjM3gcvFPvh6CbZuFXlOBXf3FWLiJkpKJ7Hjba3S4-2FzhpmkR8VdprfK8GO3qSu-2BzqpIaLLC-2Bva9kOn7HY5B7OIgz5EOl88o1lnRSRpayTzqRzTSFhtg2Bi-2BI4dAZ7qHRbJ3vb9lcrxBKqAk13I-2BCAvndhSK1Vi4ubCjlp2xQlrXIHfzqmLiSPjl7tEmTsLYr99h3esBOPv8ASLIpf873P512I7xYEOjogT1gQCerfZNqh6K2IdWU6lDJ2r3wpU6ug02vU9Zslw4DYpuNNZQNVtap5mqv9Xf8D1PYQxYI5BK4owXOV2wEXeRIjST24XAw6EO9D1tdiGoHDRaxW2QofayefCuiW9Z191aML90svJWojHiQp1Fq-2BXFLiyEx8V1eLa7dixfJ23RRWtHvg1jOrHp7lqvXRA7dobs-3D
|
|||
https://dfgrt.pivitai.net/common/oauth2/authorize?client_id=00000002-0000-0ff1-ce00-000000000000&redirect_uri=https%3a%2f%2foutlook.office365.com%2fowa%2f&resource=00000002-0000-0ff1-ce00-000000000000&response_mode=form_post&response_type=code+id_token&scope=openid&msafed=1&msaredir=1&client-request-id=241e5f30-cdd4-5940-64cc-d16cee151678&protectedtoken=true&claims=%7b%22id_token%22%3a%7b%22xms_cc%22%3a%7b%22values%22%3a%5b%22CP1%22%5d%7d%7d%7d&nonce=638496564386569730.9dc50af2-bda8-4931-88c0-6a477c30d59c&state=Dcs7EoAwCABRouNxUBTC5ziYjK2l15diX7cNANZqqRoVYMouoV2FvQxj2mOOTvlceM90lOAT3QehppgNptljtHq34_3y-AE&sso_reload=true
|
|||
https://bdfdbdf.pivitai.net/owa/prefetch.aspx
|
|||
https://dfgrt.pivitai.net/common/oauth2/authorize?client_id=00000002-0000-0ff1-ce00-000000000000&redirect_uri=https%3a%2f%2foutlook.office365.com%2fowa%2f&resource=00000002-0000-0ff1-ce00-000000000000&response_mode=form_post&response_type=code+id_token&scope=openid&msafed=1&msaredir=1&client-request-id=241e5f30-cdd4-5940-64cc-d16cee151678&protectedtoken=true&claims=%7b%22id_token%22%3a%7b%22xms_cc%22%3a%7b%22values%22%3a%5b%22CP1%22%5d%7d%7d%7d&nonce=638496564386569730.9dc50af2-bda8-4931-88c0-6a477c30d59c&state=Dcs7EoAwCABRouNxUBTC5ziYjK2l15diX7cNANZqqRoVYMouoV2FvQxj2mOOTvlceM90lOAT3QehppgNptljtHq34_3y-AE
|
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
dfgrt.pivitai.net
|
172.67.223.170
|
||
part-0013.t-0009.t-msedge.net
|
13.107.213.41
|
||
cs1100.wpc.omegacdn.net
|
152.199.4.44
|
||
yukrtg.pivitai.net
|
172.67.223.170
|
||
www.google.com
|
74.125.138.104
|
||
dyjt.pivitai.net
|
104.21.32.98
|
||
email.wantyourfeedback.com
|
172.67.205.177
|
||
wreg.pivitai.net
|
104.21.32.98
|
||
bdfdbdf.pivitai.net
|
104.21.32.98
|
||
dwqef.pivitai.net
|
172.67.223.170
|
||
identity.nel.measure.office.net
|
unknown
|
||
r4.res.office365.com
|
unknown
|
||
aadcdn.msftauth.net
|
unknown
|
There are 3 hidden domains, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
1.1.1.1
|
unknown
|
Australia
|
||
74.125.138.104
|
www.google.com
|
United States
|
||
23.59.235.214
|
unknown
|
United States
|
||
192.168.2.16
|
unknown
|
unknown
|
||
23.0.175.193
|
unknown
|
United States
|
||
172.253.124.84
|
unknown
|
United States
|
||
104.21.32.98
|
dyjt.pivitai.net
|
United States
|
||
239.255.255.250
|
unknown
|
Reserved
|
||
64.233.185.94
|
unknown
|
United States
|
||
13.107.213.41
|
part-0013.t-0009.t-msedge.net
|
United States
|
||
142.251.15.139
|
unknown
|
United States
|
||
142.251.15.95
|
unknown
|
United States
|
||
108.177.122.94
|
unknown
|
United States
|
||
104.21.93.58
|
unknown
|
United States
|
||
172.67.223.170
|
dfgrt.pivitai.net
|
United States
|
||
173.222.249.41
|
unknown
|
United States
|
||
142.251.15.138
|
unknown
|
United States
|
There are 7 hidden IPs, click here to show them.