IOC Report
https://goldstonemanagment-my.sharepoint.com/:o:/g/personal/sandrar_goldstonem_com/EsXLH__K8yxCuPDU0eDeoNIBDxttVTtWa08L1PYp5Mzc_w?e=5%3a0J1yd6&at=9

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 100
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 101
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
dropped
Chrome Cache Entry: 102
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 406986
downloaded
Chrome Cache Entry: 103
ASCII text, with very long lines (456), with no line terminators
downloaded
Chrome Cache Entry: 104
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 105
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 72
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
downloaded
Chrome Cache Entry: 73
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 74
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 102804
downloaded
Chrome Cache Entry: 75
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 3651
dropped
Chrome Cache Entry: 76
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113769
downloaded
Chrome Cache Entry: 77
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 190152
downloaded
Chrome Cache Entry: 78
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
downloaded
Chrome Cache Entry: 79
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 59293
downloaded
Chrome Cache Entry: 80
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
dropped
Chrome Cache Entry: 81
ASCII text, with very long lines (23437), with CRLF line terminators
downloaded
Chrome Cache Entry: 82
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 83
ASCII text, with very long lines (65536), with no line terminators
downloaded
Chrome Cache Entry: 84
ASCII text, with very long lines (46880)
downloaded
Chrome Cache Entry: 85
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 40329
downloaded
Chrome Cache Entry: 86
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 87
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1592
dropped
Chrome Cache Entry: 88
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 89
MS Windows icon resource - 6 icons, -128x-128, 16 colors, 72x72, 16 colors
downloaded
Chrome Cache Entry: 90
HTML document, ASCII text, with very long lines (64257), with CRLF, LF line terminators
downloaded
Chrome Cache Entry: 91
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
downloaded
Chrome Cache Entry: 92
GIF image data, version 89a, 352 x 3
dropped
Chrome Cache Entry: 93
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 459255
downloaded
Chrome Cache Entry: 94
ASCII text, with very long lines (35238), with no line terminators
downloaded
Chrome Cache Entry: 95
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 113424
downloaded
Chrome Cache Entry: 96
GIF image data, version 89a, 352 x 3
downloaded
Chrome Cache Entry: 97
ASCII text, with CRLF line terminators
downloaded
Chrome Cache Entry: 98
MS Windows icon resource - 3 icons, 32x32, 32 bits/pixel, 24x24, 32 bits/pixel
downloaded
Chrome Cache Entry: 99
gzip compressed data, max speed, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1864
dropped
There are 25 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --no-pre-read-main-dll --field-trial-handle=1948,i,14049268193459184991,7695379603295095455,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction --variations-seed-version=20250316-180048.776000 --mojo-platform-channel-handle=1756 /prefetch:11
C:\Windows\System32\appidpolicyconverter.exe
"C:\Windows\system32\appidpolicyconverter.exe"
C:\Windows\System32\conhost.exe
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://goldstonemanagment-my.sharepoint.com/:o:/g/personal/sandrar_goldstonem_com/EsXLH__K8yxCuPDU0eDeoNIBDxttVTtWa08L1PYp5Mzc_w?e=5%3a0J1yd6&at=9"

URLs

Name
IP
Malicious
https://goldstonemanagment-my.sharepoint.com/:o:/g/personal/sandrar_goldstonem_com/EsXLH__K8yxCuPDU0eDeoNIBDxttVTtWa08L1PYp5Mzc_w?e=5%3a0J1yd6&at=9
http://c.pki.goog/r/r4.crl
142.251.40.163
https://login.microsoftonline.com/14868b8a-936a-4437-8198-fd9fa4f69548/oauth2/authorize?client%5Fid=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&response%5Fmode=form%5Fpost&response%5Ftype=code%20id%5Ftoken&resource=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&scope=openid&nonce=CE2E5519F6C3FEFFB0ACFF29F2CEB805DEB5FB86ED78C639%2D19A748356579EB0DD834B8DD2337F923A05B9C03231BB41FEBA67846D6C4BA12&redirect%5Furi=https%3A%2F%2Fgoldstonemanagment%2Dmy%2Esharepoint%2Ecom%2F%5Fforms%2Fdefault%2Easpx&state=OD0w&claims=%7B%22id%5Ftoken%22%3A%7B%22xms%5Fcc%22%3A%7B%22values%22%3A%5B%22CP1%22%5D%7D%7D%7D&wsucxt=1&cobrandid=11bd8083%2D87e0%2D41b5%2Dbb78%2D0bc43c8a8e8a&client%2Drequest%2Did=e5cfa6a1%2De048%2D9000%2D00c3%2D6510b75557a4&sso_reload=true
http://c.pki.goog/r/r1.crl
142.251.40.163
http://knockoutjs.com/
unknown
http://www.opensource.org/licenses/mit-license.php)
unknown
https://goldstonemanagment-my.sharepoint.com/:o:/g/personal/sandrar_goldstonem_com/EsXLH__K8yxCuPDU0eDeoNIBDxttVTtWa08L1PYp5Mzc_w?e=5%3a0J1yd6&at=9
https://github.com/douglascrockford/JSON-js
unknown

Domains

Name
IP
Malicious
s-part-0012.t-0009.t-msedge.net
13.107.246.40
e329293.dscd.akamaiedge.net
23.216.132.21
s-part-0023.t-0009.t-msedge.net
13.107.246.51
a726.dscd.akamai.net
23.206.121.60
mira-ssc.tm-4.office.com
52.107.251.51
www.google.com
142.250.176.196
www.tm.a.prd.aadg.akadns.net
20.190.152.19
a1894.dscb.akamai.net
23.200.0.195
identity.nel.measure.office.net
unknown
aadcdn.msftauth.net
unknown
logincdn.msftauth.net
unknown
login.microsoftonline.com
unknown
goldstonemanagment-my.sharepoint.com
unknown
There are 3 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
52.107.251.51
mira-ssc.tm-4.office.com
United States
142.250.176.196
www.google.com
United States
13.107.246.40
s-part-0012.t-0009.t-msedge.net
United States
13.107.246.51
s-part-0023.t-0009.t-msedge.net
United States
23.216.132.21
e329293.dscd.akamaiedge.net
United States
23.206.121.60
a726.dscd.akamai.net
United States
23.200.0.195
a1894.dscb.akamai.net
United States
192.168.2.24
unknown
unknown
20.190.152.20
unknown
United States
52.107.252.9
unknown
United States
20.190.152.19
www.tm.a.prd.aadg.akadns.net
United States
There are 1 hidden IPs, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
FFF007E000
stack
page read and write
FFEFC9B000
stack
page read and write
275F4B82000
heap
page read and write
275F4AA0000
heap
page read and write
FFEFD9F000
stack
page read and write
FFF00FF000
stack
page read and write
275F4ED5000
heap
page read and write
275F49E0000
heap
page read and write
275F4B74000
heap
page read and write
275F4ED0000
heap
page read and write
275F4B70000
heap
page read and write
FFEFD1E000
stack
page read and write
275F4B30000
heap
page read and write
There are 3 hidden memdumps, click here to show them.

DOM / HTML

URL
Malicious
https://goldstonemanagment-my.sharepoint.com/:o:/g/personal/sandrar_goldstonem_com/EsXLH__K8yxCuPDU0eDeoNIBDxttVTtWa08L1PYp5Mzc_w?e=5%3a0J1yd6&at=9
https://login.microsoftonline.com/14868b8a-936a-4437-8198-fd9fa4f69548/oauth2/authorize?client%5Fid=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&response%5Fmode=form%5Fpost&response%5Ftype=code%20id%5Ftoken&resource=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&scope=openid&nonce=CE2E5519F6C3FEFFB0ACFF29F2CEB805DEB5FB86ED78C639%2D19A748356579EB0DD834B8DD2337F923A05B9C03231BB41FEBA67846D6C4BA12&redirect%5Furi=https%3A%2F%2Fgoldstonemanagment%2Dmy%2Esharepoint%2Ecom%2F%5Fforms%2Fdefault%2Easpx&state=OD0w&claims=%7B%22id%5Ftoken%22%3A%7B%22xms%5Fcc%22%3A%7B%22values%22%3A%5B%22CP1%22%5D%7D%7D%7D&wsucxt=1&cobrandid=11bd8083%2D87e0%2D41b5%2Dbb78%2D0bc43c8a8e8a&client%2Drequest%2Did=e5cfa6a1%2De048%2D9000%2D00c3%2D6510b75557a4&sso_reload=true
https://login.microsoftonline.com/14868b8a-936a-4437-8198-fd9fa4f69548/oauth2/authorize?client%5Fid=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&response%5Fmode=form%5Fpost&response%5Ftype=code%20id%5Ftoken&resource=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&scope=openid&nonce=CE2E5519F6C3FEFFB0ACFF29F2CEB805DEB5FB86ED78C639%2D19A748356579EB0DD834B8DD2337F923A05B9C03231BB41FEBA67846D6C4BA12&redirect%5Furi=https%3A%2F%2Fgoldstonemanagment%2Dmy%2Esharepoint%2Ecom%2F%5Fforms%2Fdefault%2Easpx&state=OD0w&claims=%7B%22id%5Ftoken%22%3A%7B%22xms%5Fcc%22%3A%7B%22values%22%3A%5B%22CP1%22%5D%7D%7D%7D&wsucxt=1&cobrandid=11bd8083%2D87e0%2D41b5%2Dbb78%2D0bc43c8a8e8a&client%2Drequest%2Did=e5cfa6a1%2De048%2D9000%2D00c3%2D6510b75557a4&sso_reload=true
https://login.microsoftonline.com/14868b8a-936a-4437-8198-fd9fa4f69548/oauth2/authorize?client%5Fid=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&response%5Fmode=form%5Fpost&response%5Ftype=code%20id%5Ftoken&resource=00000003%2D0000%2D0ff1%2Dce00%2D000000000000&scope=openid&nonce=CE2E5519F6C3FEFFB0ACFF29F2CEB805DEB5FB86ED78C639%2D19A748356579EB0DD834B8DD2337F923A05B9C03231BB41FEBA67846D6C4BA12&redirect%5Furi=https%3A%2F%2Fgoldstonemanagment%2Dmy%2Esharepoint%2Ecom%2F%5Fforms%2Fdefault%2Easpx&state=OD0w&claims=%7B%22id%5Ftoken%22%3A%7B%22xms%5Fcc%22%3A%7B%22values%22%3A%5B%22CP1%22%5D%7D%7D%7D&wsucxt=1&cobrandid=11bd8083%2D87e0%2D41b5%2Dbb78%2D0bc43c8a8e8a&client%2Drequest%2Did=e5cfa6a1%2De048%2D9000%2D00c3%2D6510b75557a4&sso_reload=true