IOC Report
http://162.210.192.5

loading gif

Files

File Path
Type
Category
Malicious
Chrome Cache Entry: 41
JSON data
downloaded

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2060 --field-trial-handle=1968,i,14816306953808709516,10788157252375864809,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "http://162.210.192.5

URLs

Name
IP
Malicious
http://162.210.192.5
http://162.210.192.5/
162.210.192.5
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1
172.253.122.138
https://algolia.net/1/404
149.202.84.123
https://www.algolia.com/doc/rest-api/search/
unknown
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
142.250.31.84
https://algolia.net/favicon.ico
149.202.84.123
https://algolia.net/1/404

Domains

Name
IP
Malicious
accounts.google.com
142.250.31.84
algolia.net
149.202.84.123
www.google.com
142.251.111.105
clients.l.google.com
172.253.122.138
clients2.google.com
unknown

IPs

IP
Domain
Country
Malicious
172.253.122.138
clients.l.google.com
United States
239.255.255.250
unknown
Reserved
162.210.192.5
unknown
United States
149.202.84.123
algolia.net
France
192.168.2.4
unknown
unknown
142.250.31.84
accounts.google.com
United States
142.251.111.105
www.google.com
United States
192.168.2.5
unknown
unknown

DOM / HTML

URL
Malicious
https://algolia.net/1/404