drive.usercontent.google.com
Classification: Whitelisted
drive.usercontent.google.com is a whitelisted (trusted) hostname. Reported by 6 threat sources, last seen 2026-08-22.
Current activity
- Offline β no longer resolving. Last online 2026-08-22 18:55:34.
- Command & Control server β Used by cybercriminals to control victim computers.
- Malware distribution β This indicator is distributing malware.
MITRE ATT&CK associations
Malware families: ASYNCRAT (S1087) JRAT (S0283)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Suspicious URL | Triage | 2026-08-22 18:43:29 | 2026-08-22 18:43:29 | anomalous-activity | |
| Malware Download | URLhaus Abuse.ch | 2023-10-22 18:18:06 | 2026-07-23 05:23:08 | malicious-activity malware | |
| Matched whitelist source: Misp_google_domain | Maltiverse | 2026-06-04 01:06:29 | 2026-06-04 01:06:29 | benign | |
| Adwind | Triage | 2026-06-03 14:05:19 | 2026-06-03 14:05:19 | malicious-activity | S0283 jRAT |
| Malicious URL | Triage | 2026-02-02 10:50:42 | 2026-04-20 06:33:50 | malicious-activity | |
| Top Popularity Site | Cisco Umbrella | 2023-07-22 02:49:17 | 2026-03-20 15:54:19 | benign | |
| Asyncrat | Triage | 2026-03-17 15:31:26 | 2026-03-17 15:31:26 | malicious-activity | S1087 AsyncRAT |
| Vidar | Triage | 2026-02-04 20:08:51 | 2026-02-04 20:08:51 | malicious-activity | |
| DISGOMOJI | ThreatFox Abuse.ch | 2025-06-10 12:17:08 | 2025-06-10 12:17:08 | malicious-activity | |
| Malicious URL | Hybrid-Analysis | 2024-01-05 17:45:04 | 2024-01-11 04:45:04 |
Tags
9824 9842 agenttesla cloudeye encrypted none dropped-by-privateloader freesoft mrpcgamess2024 1231 pw-022024 browser-extension guloader dbatloader encoded 1234 spynote 2024 payloads 1889 1220 crackpass 3329 5576 2476 4389 loki 904163065 asyncrat hta 202413 02165 6188 975128101 config favor-ydns-eu phishing external24 clickfix extension crx 2511 xworm apt36 disgomoji transparenttribe phantomstealer c2:198.23.177.196:2404 adware defense_evasion discovery spyware vidar execution persistence privilege_escalation stealer trojan 16-03-p rat installer ransomware pyinstaller adwindIP addresses resolved by this hostname
- 74.125.139.132 (2024-07-09 01:48:11)
- 172.217.13.97 (2023-07-22 02:49:17)
- 142.250.69.65 (2025-11-08 21:53:41)
- 2607:f8b0:4020:801::2001 (2025-11-08 21:53:41)
- 64.233.178.132 (2026-04-29 09:51:50)
- 2607:f8b0:4020:c07::84 (2026-04-29 09:51:50)
- 2607:f8b0:4020:800::2001 (2026-06-04 01:06:28)
- 142.250.69.33 (2026-06-04 01:06:28)
Whois information
- AS name
- AS15169 Google Inc.
- Domain
- google.com
- TLD
- com
- DNSSEC
- ['unsigned']
- Nameservers
- NS1.GOOGLE.COM, NS2.GOOGLE.COM, NS3.GOOGLE.COM, NS4.GOOGLE.COM, ns1.google.com, ns2.google.com, ns3.google.com, ns4.google.com
- Registrant
- MarkMonitor, Inc.
- State
- CA
- Country
- US β United States πΊπΈ
- Contact email
- [email protected], [email protected]
- Domain created
- 1997-09-15 04:00:00
- Domain expires
- 2028-09-14 04:00:00
- First indexed
- 2023-07-22 02:49:17
- Last updated
- 2026-08-22 18:55:34