IOC Report
https://urlshortener.teams.cloud.microsoft/8DC65F1626550D3-1-1

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 56
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 57
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 58
HTML document, Unicode text, UTF-8 text, with very long lines (16913), with no line terminators
downloaded
Chrome Cache Entry: 59
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 60
JSON data
dropped
Chrome Cache Entry: 61
ASCII text, with very long lines (4212)
downloaded
Chrome Cache Entry: 62
SVG Scalable Vector Graphics image
downloaded
Chrome Cache Entry: 63
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
downloaded
Chrome Cache Entry: 64
ASCII text, with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 65
SVG Scalable Vector Graphics image
dropped
Chrome Cache Entry: 66
ASCII text, with very long lines (65449)
downloaded
Chrome Cache Entry: 67
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 68
MS Windows icon resource - 8 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
dropped
Chrome Cache Entry: 69
JSON data
dropped
Chrome Cache Entry: 70
JSON data
dropped
There are 6 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2492 --field-trial-handle=2488,i,5596698943673808519,4703168147859055955,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://urlshortener.teams.cloud.microsoft/8DC65F1626550D3-1-1"

URLs

Name
IP
Malicious
https://urlshortener.teams.cloud.microsoft/8DC65F1626550D3-1-1
https://urlshortener.teams.cloud.microsoft/8DC65F1626550D3-1-1
52.123.129.14
https://teams.live.com/dl/launcher/launcher.html?url=%2F_%23%2Fl%2Fchat%2F19%3Auni01_hwqyajis52lhbwhhort3bchwjsah7ugopu6ankkekjxscrbwtaka%40thread.v2%2Fconversations%3FtenantId%3D9188040d-6c67-4c5b-b112-36a304b66dad%26launchAgent%3DES%26laEntry%3DMAE%26v%3DMAE5%26lm%3Ddeeplink%26lmsrc%3Demail%26emltid%3D6d58df1f-2a83-46df-9008-d8bdd89ec852%26linkpos%3D1%26emltype%3DNew_Activities_TFL%26linktype%3DNew_ChatActivity_TFL&type=chat&deeplinkId=2b273fac-8de0-4932-839e-a2f6bc23be94&directDl=true&msLaunch=true&enableMobilePage=true&suppressPrompt=true
https://statics.teams.cdn.live.net
unknown
https://statics.teams.cdn.live.net/hashedjs-launcher/polyfills.1f5a03d113c6ac7b91f5.js
unknown
http://creativecommons.org/publicdomain/zero/1.0/
unknown
https://statics.teams.cdn.live.net/hashedjs-launcher/launcher.3c5b23498b3a051ad013.js
unknown
http://underscorejs.org/
unknown
https://js.foundation/
unknown
https://teams.live.com/dl/launcher/attribution.txt
https://github.com/lodash/lodash
unknown
https://statics.teams.cdn.live.net/hashedcss-launcher/launcher.d6cd10b8b26b2130799c.css
unknown
There are 1 hidden URLs, click here to show them.

Domains

Name
IP
Malicious
www.google.com
142.250.189.132
s-0005.dual-s-msedge.net
52.123.129.14
fp2e7a.wpc.phicdn.net
192.229.211.108
urlshortener.teams.cloud.microsoft
unknown
statics.teams.cdn.live.net
unknown
teams.live.com
unknown

IPs

IP
Domain
Country
Malicious
142.250.189.132
www.google.com
United States
52.123.129.14
s-0005.dual-s-msedge.net
United States
192.168.2.4
unknown
unknown
239.255.255.250
unknown
Reserved
192.168.2.14
unknown
unknown

DOM / HTML

URL
Malicious
https://teams.live.com/dl/launcher/launcher.html?url=%2F_%23%2Fl%2Fchat%2F19%3Auni01_hwqyajis52lhbwhhort3bchwjsah7ugopu6ankkekjxscrbwtaka%40thread.v2%2Fconversations%3FtenantId%3D9188040d-6c67-4c5b-b112-36a304b66dad%26launchAgent%3DES%26laEntry%3DMAE%26v%3DMAE5%26lm%3Ddeeplink%26lmsrc%3Demail%26emltid%3D6d58df1f-2a83-46df-9008-d8bdd89ec852%26linkpos%3D1%26emltype%3DNew_Activities_TFL%26linktype%3DNew_ChatActivity_TFL&type=chat&deeplinkId=2b273fac-8de0-4932-839e-a2f6bc23be94&directDl=true&msLaunch=true&enableMobilePage=true&suppressPrompt=true
https://teams.live.com/dl/launcher/attribution.txt