IOC Report
https://indd.adobe.com/view/5e1a3ee1-0183-4614-933b-370638ff36d7

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\alfredo\Documents\Outlook Files\Outlook Data File - NoEmail.pst
data
dropped
Chrome Cache Entry: 158
ASCII text, with very long lines (65465)
downloaded
Chrome Cache Entry: 159
ASCII text, with very long lines (30828)
downloaded
Chrome Cache Entry: 160
ASCII text, with very long lines (1957)
downloaded
Chrome Cache Entry: 161
Unicode text, UTF-8 text, with very long lines (516)
downloaded
Chrome Cache Entry: 162
ASCII text
downloaded
Chrome Cache Entry: 163
Unicode text, UTF-8 text, with very long lines (65502), with no line terminators
downloaded
Chrome Cache Entry: 164
ASCII text, with very long lines (32065)
downloaded
Chrome Cache Entry: 165
ASCII text
downloaded
Chrome Cache Entry: 166
ASCII text
downloaded
Chrome Cache Entry: 167
PNG image data, 80 x 80, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 168
PNG image data, 3351 x 1679, 8-bit/color RGBA, non-interlaced
downloaded
Chrome Cache Entry: 169
PNG image data, 2597 x 1507, 8-bit/color RGBA, non-interlaced
dropped
Chrome Cache Entry: 170
Web Open Font Format (Version 2), CFF, length 63400, version 1.0
downloaded
Chrome Cache Entry: 171
ASCII text
downloaded
Chrome Cache Entry: 172
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 173
ASCII text, with very long lines (64886)
downloaded
Chrome Cache Entry: 174
ASCII text, with very long lines (32008)
downloaded
Chrome Cache Entry: 175
ASCII text, with no line terminators
downloaded
Chrome Cache Entry: 176
HTML document, ASCII text, with very long lines (27853), with CRLF line terminators
downloaded
Chrome Cache Entry: 177
MS Windows icon resource - 4 icons, 64x64, 32 bits/pixel, 32x32, 32 bits/pixel
downloaded
Chrome Cache Entry: 179
ASCII text, with very long lines (18530)
downloaded
Chrome Cache Entry: 181
HTML document, ASCII text, with very long lines (32086)
downloaded
Chrome Cache Entry: 182
HTML document, ASCII text, with very long lines (11084), with no line terminators
downloaded
Chrome Cache Entry: 183
ASCII text, with very long lines (32888)
downloaded
Chrome Cache Entry: 184
ASCII text, with very long lines (19015)
downloaded
Chrome Cache Entry: 185
ASCII text, with very long lines (32012)
downloaded
Chrome Cache Entry: 186
ASCII text, with very long lines (50758)
downloaded
Chrome Cache Entry: 187
ASCII text, with very long lines (48664)
downloaded
Chrome Cache Entry: 188
ASCII text, with very long lines (65325)
downloaded
Chrome Cache Entry: 189
ASCII text, with very long lines (3172), with no line terminators
downloaded
Chrome Cache Entry: 190
HTML document, ASCII text
downloaded
There are 23 hidden files, click here to show them.

URLs

Name
IP
Malicious
https://indd.adobe.com/view/5e1a3ee1-0183-4614-933b-370638ff36d7
malicious
https://subvencion.publianagrama.com/wp-content/plugins/orvpkqp//wee/Odrivex/
malicious

Domains

Name
IP
Malicious
star-mini.c10r.facebook.com
157.240.20.35
stackpath.bootstrapcdn.com
104.18.11.207
scontent.xx.fbcdn.net
157.240.20.19
subvencion.publianagrama.com
148.251.116.74
accounts.google.com
142.250.185.109
cdnjs.cloudflare.com
104.17.24.14
adobe.com.ssl.d1.sc.omtrdc.net
15.236.125.10
maxcdn.bootstrapcdn.com
104.18.10.207
www.google.com
142.250.186.100
clients.l.google.com
142.250.181.238
prod.adobeccstatic.com
54.192.111.83
fastly-tls12-bam-cell.nr-data.net
162.247.243.30
use.typekit.net
unknown
www.facebook.com
unknown
assets.adobedtm.com
unknown
js-agent.newrelic.com
unknown
connect.facebook.net
unknown
clients2.google.com
unknown
p.typekit.net
unknown
code.jquery.com
unknown
bam-cell.nr-data.net
unknown
There are 11 hidden domains, click here to show them.

IPs

IP
Domain
Country
Malicious
142.250.185.109
accounts.google.com
United States
192.168.2.1
unknown
unknown
104.18.10.207
maxcdn.bootstrapcdn.com
United States
148.251.116.74
subvencion.publianagrama.com
Germany
15.197.142.173
unknown
United States
2.19.126.68
unknown
European Union
142.250.185.100
unknown
United States
142.250.185.106
unknown
United States
151.101.130.137
unknown
United States
142.250.181.238
clients.l.google.com
United States
54.192.111.83
prod.adobeccstatic.com
United States
162.247.243.30
fastly-tls12-bam-cell.nr-data.net
United States
172.217.23.99
unknown
United States
92.123.124.221
unknown
European Union
2.19.126.91
unknown
European Union
69.16.175.10
unknown
United States
15.236.125.10
adobe.com.ssl.d1.sc.omtrdc.net
United States
142.250.186.138
unknown
United States
142.250.184.202
unknown
United States
104.17.24.14
cdnjs.cloudflare.com
United States
34.104.35.123
unknown
United States
216.58.212.131
unknown
United States
172.217.18.4
unknown
United States
172.217.18.3
unknown
United States
18.155.129.66
unknown
United States
104.18.11.207
stackpath.bootstrapcdn.com
United States
157.240.20.19
scontent.xx.fbcdn.net
United States
239.255.255.250
unknown
Reserved
52.109.8.45
unknown
United States
192.229.221.95
unknown
United States
157.240.20.35
star-mini.c10r.facebook.com
United States
52.109.76.141
unknown
United States
127.0.0.1
unknown
unknown
There are 23 hidden IPs, click here to show them.