IOC Report
https://us-west-2.protection.sophos.com/?d=venmo.com&u=aHR0cHM6Ly92ZW5tby5jb20vaWRlbnRpdHkvdW5zdWJzY3JpYmU_dj0zJmNvZGU9MmI3MDFhZjQwYzc4NzMwYTYyMTFhNWFhMzQwYTRiMWYwNzk5ZDE1OGU4YzIxZGZlYWE2MjYzMDZlZDQ2YTE3MCZ1YT1maQ==&p=m&i=NjI3Mjc4OTk0MGU3YTAxM2U2ZWIxMDY3&t=bU1WbGVZYlp3UnR5S2JybzBreHV4dXRpaWFMV2M5Rks

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 11:20:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 11:20:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:05:01 2023, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 11:20:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 11:20:40 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Apr 26 11:20:39 2024, atime=Wed Sep 27 04:28:28 2023, length=1210144, window=hide
dropped
Chrome Cache Entry: 143
Unicode text, UTF-8 text, with very long lines (318)
downloaded
Chrome Cache Entry: 144
ASCII text, with very long lines (29584)
downloaded
Chrome Cache Entry: 145
Unicode text, UTF-8 text, with very long lines (844)
downloaded
Chrome Cache Entry: 147
ASCII text, with very long lines (1719), with no line terminators
downloaded
Chrome Cache Entry: 148
ASCII text, with very long lines (16759), with no line terminators
downloaded
Chrome Cache Entry: 150
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 151
ASCII text, with very long lines (15682)
downloaded
Chrome Cache Entry: 152
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 153
ASCII text
downloaded
Chrome Cache Entry: 154
ASCII text, with very long lines (5534), with no line terminators
downloaded
Chrome Cache Entry: 155
Web Open Font Format (Version 2), CFF, length 18320, version 1.6553
downloaded
Chrome Cache Entry: 156
ASCII text, with very long lines (10652), with no line terminators
downloaded
Chrome Cache Entry: 157
ASCII text, with very long lines (353), with no line terminators
downloaded
Chrome Cache Entry: 158
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (24178), with no line terminators
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (949)
downloaded
Chrome Cache Entry: 161
ASCII text, with very long lines (8581), with no line terminators
downloaded
Chrome Cache Entry: 162
ASCII text, with very long lines (23093), with no line terminators
downloaded
Chrome Cache Entry: 163
ASCII text, with very long lines (56412), with no line terminators
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (949)
downloaded
Chrome Cache Entry: 165
Unicode text, UTF-8 text, with very long lines (65518), with no line terminators
downloaded
Chrome Cache Entry: 166
ASCII text, with very long lines (2483), with no line terminators
downloaded
Chrome Cache Entry: 167
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 168
HTML document, ASCII text, with very long lines (29464), with no line terminators
downloaded
Chrome Cache Entry: 169
GIF image data, version 89a, 1 x 1
dropped
Chrome Cache Entry: 170
ASCII text, with very long lines (63869)
downloaded
Chrome Cache Entry: 172
ASCII text, with very long lines (5856)
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (58556), with no line terminators
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (23204), with no line terminators
downloaded
Chrome Cache Entry: 175
ASCII text, with very long lines (3868)
downloaded
Chrome Cache Entry: 176
ASCII text, with very long lines (9205)
downloaded
Chrome Cache Entry: 177
ASCII text, with very long lines (38457)
downloaded
Chrome Cache Entry: 178
Web Open Font Format, CFF, length 41894, version 1.0
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (58188), with no line terminators
downloaded
Chrome Cache Entry: 180
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 181
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 182
ASCII text
downloaded
Chrome Cache Entry: 183
JSON data
dropped
Chrome Cache Entry: 184
ASCII text, with very long lines (21249), with no line terminators
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (29698)
downloaded
Chrome Cache Entry: 189
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 190
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 191
HTML document, ASCII text, with very long lines (63464)
dropped
Chrome Cache Entry: 193
ASCII text, with very long lines (4867)
downloaded
Chrome Cache Entry: 194
ASCII text, with very long lines (5762)
downloaded
Chrome Cache Entry: 196
ASCII text, with very long lines (4179)
downloaded
Chrome Cache Entry: 197
ASCII text, with very long lines (2343)
downloaded
Chrome Cache Entry: 198
ASCII text, with very long lines (64534)
downloaded
Chrome Cache Entry: 199
ASCII text, with very long lines (949)
downloaded
Chrome Cache Entry: 200
ASCII text, with very long lines (4179)
downloaded
Chrome Cache Entry: 201
Unicode text, UTF-8 text, with very long lines (20103), with no line terminators
downloaded
Chrome Cache Entry: 203
ASCII text, with very long lines (62481)
downloaded
Chrome Cache Entry: 205
ASCII text, with very long lines (487), with no line terminators
downloaded
Chrome Cache Entry: 206
ASCII text, with very long lines (28467)
downloaded
Chrome Cache Entry: 207
ASCII text, with very long lines (461)
downloaded
Chrome Cache Entry: 208
ASCII text, with very long lines (36413), with no line terminators
downloaded
Chrome Cache Entry: 209
JSON data
dropped
Chrome Cache Entry: 210
HTML document, ASCII text
downloaded
Chrome Cache Entry: 211
ASCII text, with very long lines (4559)
downloaded
Chrome Cache Entry: 212
ASCII text, with very long lines (47731), with no line terminators
downloaded
Chrome Cache Entry: 213
Web Open Font Format (Version 2), CFF, length 18360, version 1.6553
downloaded
Chrome Cache Entry: 214
ASCII text, with very long lines (6668), with no line terminators
downloaded
Chrome Cache Entry: 215
ASCII text, with very long lines (52145), with no line terminators
downloaded
Chrome Cache Entry: 216
Unicode text, UTF-8 text, with very long lines (42469), with no line terminators
downloaded
Chrome Cache Entry: 217
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 218
ASCII text, with very long lines (62368)
downloaded
Chrome Cache Entry: 219
ASCII text, with very long lines (631)
downloaded
Chrome Cache Entry: 220
ASCII text, with very long lines (2757)
downloaded
There are 66 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://us-west-2.protection.sophos.com/?d=venmo.com&u=aHR0cHM6Ly92ZW5tby5jb20vaWRlbnRpdHkvdW5zdWJzY3JpYmU_dj0zJmNvZGU9MmI3MDFhZjQwYzc4NzMwYTYyMTFhNWFhMzQwYTRiMWYwNzk5ZDE1OGU4YzIxZGZlYWE2MjYzMDZlZDQ2YTE3MCZ1YT1maQ==&p=m&i=NjI3Mjc4OTk0MGU3YTAxM2U2ZWIxMDY3&t=bU1WbGVZYlp3UnR5S2JybzBreHV4dXRpaWFMV2M5RkszZUNMdWp2UkVaVT0=&h=4ce9b067fcbf486e8f27561ce3d3058e&s=AVNPUEhUT0NFTkNSWVBUSVaS8c9jSpZcrH9uvMBTWALM8OUVCaCMDIwUwmubUWsN9g
https://c.paypal.com/v1/r/d/i?js_src=https://c.paypal.com/da/r/fb.js
https://id.venmo.com/signin?country.x=US&locale.x=en&ctxId=AAFqUKczEO2Mzi6hqpJdn-Xx0dXM7bawZ5Fjg4OpBcOC-np1pt4kDmQfLr3i2QO6W-noUKfbwNF2PGao5AsbV98=
https://id.venmo.com/auth/recaptcha/grcenterprise_v3.html
about:blank
https://www.recaptcha.net/recaptcha/enterprise/anchor?ar=1&k=6LdCCOUUAAAAAHTE-Snr6hi4HJGtJk_d1_ce-gWB&co=aHR0cHM6Ly9pZC52ZW5tby5jb206NDQz&hl=en&v=V6_85qpc2Xf2sbe3xTnRte7m&size=invisible&cb=tnbgrglpioih
https://account.venmo.com/identity/unsubscribe?v=3&code=2b701af40c78730a6211a5aa340a4b1f0799d158e8c21dfeaa626306ed46a170&ua=fi
https://id.venmo.com/signin?country.x=US&locale.x=en&ctxId=AAFqUKczEO2Mzi6hqpJdn-Xx0dXM7bawZ5Fjg4OpBcOC-np1pt4kDmQfLr3i2QO6W-noUKfbwNF2PGao5AsbV98=#/lgn

Domains

Name
IP
Malicious
mparticle.map.fastly.net
151.101.2.133
paypal.map.fastly.net
151.101.2.133
dualstack.paypal-dynamic-2.map.fastly.net
151.101.1.35
paypal-dynamic-2.map.fastly.net
151.101.1.35
account.venmo.com
52.84.150.58
paypal-dynamic.map.fastly.net
151.101.65.21
www.recaptcha.net
192.178.50.35
slc.stats.paypal.com
34.106.92.18
d2t07dpvw9bt1v.cloudfront.net
99.84.252.113
venmo.com
52.84.150.50
www.google.com
142.250.64.164
jssdkcdns.mparticle.com
151.101.130.133
stats.glb.paypal.com
34.106.92.18
c.paypal.com
unknown
us-west-2.protection.sophos.com
unknown
c6.paypal.com
unknown
b.stats.paypal.com
unknown
id.venmo.com
unknown
www.paypal.com
unknown
cdn.optimizely.com
unknown
identity.mparticle.com
unknown
t.paypal.com
unknown
www.paypalobjects.com
unknown
There are 13 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.189.142
unknown
United States
151.101.193.35
unknown
United States
151.101.130.133
jssdkcdns.mparticle.com
United States
192.178.50.35
www.recaptcha.net
United States
52.84.150.50
venmo.com
United States
192.168.2.16
unknown
unknown
151.101.1.35
dualstack.paypal-dynamic-2.map.fastly.net
United States
192.168.2.4
unknown
unknown
142.250.64.164
www.google.com
United States
142.250.64.163
unknown
United States
142.251.35.238
unknown
United States
172.217.15.206
unknown
United States
142.251.162.84
unknown
United States
151.101.194.133
unknown
United States
151.101.193.21
unknown
United States
192.178.50.67
unknown
United States
1.1.1.1
unknown
Australia
142.250.217.227
unknown
United States
151.101.1.21
unknown
United States
99.84.252.113
d2t07dpvw9bt1v.cloudfront.net
United States
142.250.217.232
unknown
United States
52.84.150.58
account.venmo.com
United States
151.101.129.21
unknown
United States
142.250.217.174
unknown
United States
239.255.255.250
unknown
Reserved
151.101.2.133
mparticle.map.fastly.net
United States
151.101.65.21
paypal-dynamic.map.fastly.net
United States
184.84.136.157
unknown
United States
34.106.92.18
slc.stats.paypal.com
United States
142.250.217.170
unknown
United States
There are 20 hidden IPs, click here to show them.