IOC Report
https://epocerd.co.jp.thevaultoutlet.com/Xapz

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 45
ASCII text, with very long lines (3287)
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2364 --field-trial-handle=2016,i,895955035969360923,12941824471286432544,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument http:///
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2028 --field-trial-handle=1980,i,4362510208015532424,406885491728431157,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "https://epocerd.co.jp.thevaultoutlet.com/Xapz"

URLs

Name
IP
Malicious
https://epocerd.co.jp.thevaultoutlet.com/Xapz
malicious
https://epocerd.co.jp.thevaultoutlet.com/Xapz
43.130.239.48
malicious
https://www.google.com/async/ddljson?async=ntp:2
142.250.191.164
https://www.google.com/async/newtab_promos
142.250.191.164
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_ogb%3Fhl%3Den-US%26async%3Dfixed:0&hl=en-US&q=EgRRtT5aGJq9u7EGIjCi3dslZJWyU_71x7ixSNsMxL_ldNl9U9luTCLFCz8mLyISk9N-l9BLlFuaw1eydf8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.191.164
https://www.google.com/sorry/index?continue=https://www.google.com/async/ddljson%3Fasync%3Dntp:2&q=EgRRtT5aGJq9u7EGIjB1dTPldUCLAFb1lmZJUgipSywL2JRVOHFSkVq0Vn8mXYsxL0RJudvWuSc7bVTSUQIyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.191.164
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&oft=1&pgcl=20&gs_rn=42&sugkey=AIzaSyBOti4mM-6x9WDnZIjIeyEU21OpBXqWBgw
142.250.191.164
https://www.google.com/async/newtab_ogb?hl=en-US&async=fixed:0
142.250.191.164
https://www.google.com/sorry/index?continue=https://www.google.com/async/newtab_promos&q=EgRRtT5aGJq9u7EGIjB4d9zPTLM2jhMTzyBlkqqd1LghsSMSSPAqVi0NfDbthOqgI2dPu7sS3DakPK3MDdkyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM
142.250.191.164

Domains

Name
IP
Malicious
www.google.com
142.250.191.164
epocerd.co.jp.thevaultoutlet.com
43.130.239.48

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
43.130.239.48
epocerd.co.jp.thevaultoutlet.com
Japan
192.168.2.4
unknown
unknown
142.250.191.164
www.google.com
United States
127.0.0.1
unknown
unknown