IOC Report
http://116.198.42.183/uqcjjj

loading gif

Files

File Path
Type
Category
Malicious
C:\Users\user\Downloads\29643d19-78c3-4869-af3d-3c05fa150004.tmp
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Downloads\uqcjjj (copy)
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Users\user\Downloads\uqcjjj.crdownload
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
Chrome Cache Entry: 45
PE32 executable (GUI) Intel 80386, for MS Windows
downloaded
malicious

Processes

Path
Cmdline
Malicious
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2356 --field-trial-handle=2252,i,13112198063180453466,5375323552459012381,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
C:\Program Files\Google\Chrome\Application\chrome.exe
"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://116.198.42.183/uqcjjj"

URLs

Name
IP
Malicious
http://116.198.42.183/uqcjjj
malicious
http://116.198.42.183/uqcjjj
116.198.42.183
malicious
https://dl.360safe.com/netunion/20140425/360safe
unknown
https://dl.360safe.com/netunion/20140425/MarketSetup_243988.exeXC:
unknown
https://dl.360safe.com/netunion/20140425/360sd_243988.exe$PalmInputGuard.exe.
unknown
https://dl.360safe.com/netunion/20140425/360zip_yqlm_243988.exe
unknown
https://dl.360safe.com/netunion/20140425/360se
unknown
http://api.ipify.org(https://ipinfo.io/ip&https://jsonip.com/ParseJson
unknown

Domains

Name
IP
Malicious
www.google.com
142.251.167.103

IPs

IP
Domain
Country
Malicious
239.255.255.250
unknown
Reserved
116.198.42.183
unknown
China
142.251.167.103
www.google.com
United States
192.168.2.8
unknown
unknown
192.168.2.4
unknown
unknown