IOC Report
http://bhsd-hqqak.ondigitalocean.app

loading gif

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2132 --field-trial-handle=2004,i,3388246705185068811,9127368990878862355,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe" "http://bhsd-hqqak.ondigitalocean.app

URLs

Name
IP
Malicious
http://bhsd-hqqak.ondigitalocean.app
malicious
https://clients2.google.com/service/update2/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=chromecrx&prodchannel=&prodversion=117.0.5938.132&lang=en-US&acceptformat=crx3,puff&x=id%3Dnmmhkkegccagdldgiimedpiccmgmieda%26v%3D0.0.0.0%26installedby%3Dother%26uc%26brand%3DONGR%26ping%3Dr%253D-1%2526e%253D1
173.194.219.100
https://accounts.google.com/ListAccounts?gpsia=1&source=ChromiumBrowser&json=standard
64.233.185.84

Domains

Name
IP
Malicious
google.com
173.194.77.101
accounts.google.com
64.233.185.84
www.google.com
172.217.215.147
clients.l.google.com
173.194.219.100
clients2.google.com
unknown
bhsd-hqqak.ondigitalocean.app
unknown

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
172.217.215.147
www.google.com
United States
64.233.185.84
accounts.google.com
United States
173.194.219.100
clients.l.google.com
United States
192.168.2.4
unknown
unknown