IOC Report
https://go.assentportal.com/08570000-aa10-1293-daab-08dc655e3717/08570000-aa10-1293-6906-08dc655e4976/629a4d3f-9467-457d-9a3a-c2244c4791ed/en

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 19:16:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 19:16:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 19:16:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 19:16:41 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Thu Apr 25 19:16:40 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 109
JSON data
dropped
Chrome Cache Entry: 110
JSON data
dropped
Chrome Cache Entry: 111
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 112
JSON data
downloaded
Chrome Cache Entry: 113
JSON data
downloaded
Chrome Cache Entry: 114
ASCII text
downloaded
Chrome Cache Entry: 118
ASCII text, with very long lines (550)
downloaded
Chrome Cache Entry: 119
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 120
ASCII text, with very long lines (10187), with no line terminators
downloaded
Chrome Cache Entry: 122
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 123
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 125
ASCII text, with no line terminators
dropped
Chrome Cache Entry: 127
ASCII text, with very long lines (19254), with no line terminators
downloaded
Chrome Cache Entry: 129
JSON data
downloaded
Chrome Cache Entry: 131
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 133
ASCII text
downloaded
Chrome Cache Entry: 134
ASCII text, with very long lines (547)
downloaded
Chrome Cache Entry: 136
ASCII text
downloaded
Chrome Cache Entry: 137
JSON data
downloaded
Chrome Cache Entry: 138
ASCII text, with very long lines (472)
downloaded
Chrome Cache Entry: 139
HTML document, ASCII text, with very long lines (520)
downloaded
Chrome Cache Entry: 140
ASCII text, with very long lines (351), with no line terminators
downloaded
Chrome Cache Entry: 144
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 145
JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 171x50, components 3
downloaded
Chrome Cache Entry: 146
JSON data
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (626)
downloaded
Chrome Cache Entry: 148
JSON data
downloaded
Chrome Cache Entry: 149
Unicode text, UTF-8 text, with very long lines (5392), with no line terminators
dropped
Chrome Cache Entry: 151
JSON data
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (1601)
downloaded
Chrome Cache Entry: 153
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 154
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 155
ASCII text, with very long lines (21229)
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (65307)
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (37922)
downloaded
Chrome Cache Entry: 158
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 159
ASCII text, with very long lines (547)
downloaded
Chrome Cache Entry: 160
JSON data
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (65455)
downloaded
Chrome Cache Entry: 164
C source, ASCII text, with very long lines (754)
downloaded
Chrome Cache Entry: 165
JSON data
dropped
Chrome Cache Entry: 166
Unicode text, UTF-8 text, with very long lines (17152), with no line terminators
downloaded
Chrome Cache Entry: 167
ASCII text
downloaded
Chrome Cache Entry: 168
ASCII text
downloaded
Chrome Cache Entry: 169
JSON data
downloaded
Chrome Cache Entry: 170
Unicode text, UTF-8 text, with very long lines (10161), with no line terminators
dropped
Chrome Cache Entry: 172
JSON data
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (4179)
downloaded
Chrome Cache Entry: 174
GIF image data, version 89a, 1 x 1
downloaded
Chrome Cache Entry: 175
JSON data
dropped
Chrome Cache Entry: 176
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 179
JSON data
downloaded
Chrome Cache Entry: 181
JSON data
dropped
Chrome Cache Entry: 182
ASCII text, with very long lines (2600), with no line terminators
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (571)
downloaded
Chrome Cache Entry: 186
HTML document, ASCII text, with very long lines (908), with no line terminators
downloaded
Chrome Cache Entry: 188
HTML document, ASCII text
downloaded
Chrome Cache Entry: 189
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 190
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 192
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 193
ASCII text, with very long lines (566)
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (65310)
downloaded
Chrome Cache Entry: 200
HTML document, ASCII text
downloaded
Chrome Cache Entry: 201
ASCII text, with very long lines (533)
downloaded
Chrome Cache Entry: 202
ASCII text, with very long lines (626)
downloaded
Chrome Cache Entry: 203
JSON data
dropped
Chrome Cache Entry: 204
JSON data
downloaded
Chrome Cache Entry: 205
JSON data
downloaded
Chrome Cache Entry: 209
Web Open Font Format (Version 2), TrueType, length 14584, version 2.0
downloaded
Chrome Cache Entry: 212
Web Open Font Format (Version 2), TrueType, length 11820, version 2.0
downloaded
Chrome Cache Entry: 213
ASCII text, with very long lines (8794), with no line terminators
downloaded
Chrome Cache Entry: 214
PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 216
JSON data
downloaded
Chrome Cache Entry: 217
ASCII text
downloaded
Chrome Cache Entry: 218
Unicode text, UTF-8 text, with very long lines (2123)
downloaded
There are 72 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://go.assentportal.com/08570000-aa10-1293-daab-08dc655e3717/08570000-aa10-1293-6906-08dc655e4976/629a4d3f-9467-457d-9a3a-c2244c4791ed/en
https://service.force.com/embeddedservice/5.0/esw.html?parent=https://supplierportal.assentcompliance.com/app/main/629a4d3f-9467-457d-9a3a-c2244c4791ed
https://supplierportal.assentcompliance.com/629a4d3f-9467-457d-9a3a-c2244c4791ed/en
about:blank
https://supplierportal.assentcompliance.com/app/main/629a4d3f-9467-457d-9a3a-c2244c4791ed

Domains

Name
IP
Malicious
a.nel.cloudflare.com
35.190.80.1
s3.us-east-1.amazonaws.com
16.182.36.112
supplierportal.assentcompliance.com
52.86.168.240
cf.zdassets.com
104.18.72.113
go.assentportal.com
3.221.101.153
api.assentcompliance.com
18.215.206.118
app.pendo.io
34.107.204.85
la1-core1.sfdc-58ktaz.salesforceliveagent.com
3.97.95.115
static.zdassets.com
104.18.72.113
assentcompliance.zendesk.com
162.159.128.7
googleads.g.doubleclick.net
142.250.9.154
cdn.pendo.io
34.36.213.229
api.feedback.us.pendo.io
34.96.121.46
track.assentcompliance.com
3.214.158.0
ekr.zdassets.com
104.18.70.113
td.doubleclick.net
64.233.185.155
www.google.com
108.177.122.105
la5-c1-ia4.ia4.r.salesforceliveagent.com
13.110.248.220
location.l.force.com
136.146.17.5
cdn.cookielaw.org
104.19.177.52
geolocation.onetrust.com
172.64.155.119
d33ktkbcgcjarp.cloudfront.net
3.161.193.68
d.la5-c1-ia4.salesforceliveagent.com
unknown
mop.assentcompliance.com
unknown
service.force.com
unknown
assets.zendesk.com
unknown
d.la1-core1.sfdc-58ktaz.salesforceliveagent.com
unknown
There are 17 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
3.221.101.153
go.assentportal.com
United States
104.19.177.52
cdn.cookielaw.org
United States
3.214.158.0
track.assentcompliance.com
United States
192.168.2.17
unknown
unknown
16.182.36.112
s3.us-east-1.amazonaws.com
United States
162.159.128.7
assentcompliance.zendesk.com
United States
34.36.213.229
cdn.pendo.io
United States
18.215.206.118
api.assentcompliance.com
United States
64.233.185.155
td.doubleclick.net
United States
54.231.196.72
unknown
United States
104.18.32.137
unknown
United States
142.250.9.94
unknown
United States
104.18.72.113
cf.zdassets.com
United States
35.190.80.1
a.nel.cloudflare.com
United States
3.97.95.115
la1-core1.sfdc-58ktaz.salesforceliveagent.com
United States
142.251.15.207
unknown
United States
136.146.17.5
location.l.force.com
United States
142.250.9.154
googleads.g.doubleclick.net
United States
172.217.215.95
unknown
United States
3.96.121.93
unknown
United States
34.107.204.85
app.pendo.io
United States
172.253.124.97
unknown
United States
1.1.1.1
unknown
Australia
142.250.105.94
unknown
United States
142.250.9.139
unknown
United States
3.161.193.68
d33ktkbcgcjarp.cloudfront.net
United States
172.64.155.119
geolocation.onetrust.com
United States
173.194.219.84
unknown
United States
172.253.124.95
unknown
United States
239.255.255.250
unknown
Reserved
104.18.70.113
ekr.zdassets.com
United States
52.86.168.240
supplierportal.assentcompliance.com
United States
13.110.62.209
unknown
United States
13.110.248.220
la5-c1-ia4.ia4.r.salesforceliveagent.com
United States
108.138.128.107
unknown
United States
3.225.210.1
unknown
United States
108.177.122.105
www.google.com
United States
142.251.15.113
unknown
United States
64.233.185.99
unknown
United States
34.96.121.46
api.feedback.us.pendo.io
United States
64.233.185.103
unknown
United States
There are 31 hidden IPs, click here to show them.